This Data Processing Addendum (“DPA”) forms part of the FansChat Terms of Service between:
As a Creator, you are the controller of personal data belonging to your subscribers (“fans”). FansChat processes this data solely on your behalf and under your instructions.
FansChat processes fan data for the following purposes only:
We will not process fan data for any purpose outside the scope of providing the Service to you.
FansChat applies a one-way SHA-256 hash to all fan identifiers received from connected platforms. We never store real fan names, usernames, or platform IDs in a recoverable form. This anonymisation is applied at the point of ingestion and cannot be reversed.
FansChat implements the following technical and organisational security measures:
We engage the following sub-processors to deliver the Service:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Anthropic | AI message generation | USA |
| Supabase | Database & auth | USA / AWS |
| Stripe | Payment processing | USA |
| Resend | Transactional email | USA |
| Sentry | Error monitoring | USA |
| Vercel | Application hosting | USA / Global |
All sub-processors are contractually bound to process data only as instructed and to implement adequate security measures. We will notify you of any material changes to our sub-processor list with at least 14 days' notice.
Upon termination or expiry of your FansChat subscription, we will delete all personal data processed on your behalf within 30 days, unless we are required to retain it by applicable law. You may request a certificate of deletion by contacting privacy@fanschat.app.
In the event of a personal data breach affecting data we process on your behalf, we will notify you without undue delay and within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories of data affected, and the measures taken or proposed.
This DPA is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation. By using FansChat you acknowledge and agree to the terms of this DPA as part of the overall Terms of Service.
For DPA enquiries: privacy@fanschat.app