Tweely

Business & Widget Terms

Last updated: 28 September 2026

These terms apply when you use Tweely for a business, organisation or professional purpose: business pages, team members, chat links, the AI front desk, intake cards, stickers, and the Tweely chat widget on your own website (together, "Business Features"). They add to our Terms of Service. Part B is a Data Processing Addendum (DPA). "You" or "Customer" means the business. "Tweely", "we" or "us" means OneVault LLC.

In short: for the chats with your own customers and website visitors, you are the controller and Tweely is your processor. You must tell your visitors about Tweely in your privacy notice, get any consent your laws require, keep the AI label visible, and not collect sensitive data in chat. We protect the data, use it only to provide the service, and help you meet your legal duties.

Part A: Business terms

A1. Business use

A2. The chat widget

A3. AI front desk

A4. Data you must not collect

Unless we agree in writing, do not use Tweely to collect or store: payment card numbers or bank details; passwords; government ID numbers (such as SSNs or passport numbers); health information (Tweely is not HIPAA compliant and we do not sign business associate agreements); biometric data; data about children under 18; or other special category or sensitive personal data. If a visitor sends such data, delete it from the chat.

A5. Messages and marketing

A6. Fees

Business plans, seats, storage and AI credits are billed yearly or as bought, under sections 9 and 10 of the Terms of Service. You are responsible for all taxes, except taxes on our income. If you give us a VAT or GST number, reverse charge may apply.

A7. Suspension

We may suspend Business Features, the widget or AI replies at once if you break these terms, if there is a security risk, if payment is overdue, or if the law requires it. Where practical, we will tell you first and give you a chance to fix the problem.

A8. Your indemnity

You will defend and pay for any claim, fine or loss brought against us by a third party or authority arising from: your content and AI knowledge; your website and how you installed the widget; your messages to people; your failure to give notices or get consents you are required to; or your breach of these terms or the law.

A9. Our liability to businesses

For business customers, as far as the law allows: (a) neither side is liable for indirect, incidental, special, consequential or punitive damages, or lost profits, revenue or data; and (b) each side's total liability for all claims under these terms and the DPA is limited to the amounts you paid us in the 12 months before the event that caused the claim. These limits do not apply to your payment duties, your indemnity, or liability that cannot be limited by law.

A10. Order of precedence

If documents conflict, this order applies: (1) the Standard Contractual Clauses (where they apply), (2) the DPA in Part B, (3) Part A, (4) the Terms of Service, (5) other policies.

Part B: Data Processing Addendum

B1. Roles

B2. Details of processing

ItemDetails
Subject matter and purposeProviding chat, widget, AI front desk, intake and inbox features to you
Nature of processingCollecting, storing, displaying, sending to AI providers to create replies, routing to your team, notifying you, deleting
Data subjectsYour website visitors, customers, leads and other people who chat with you
Types of dataNames, contact details they choose to give, message content, attachments, intake answers, chat timestamps, country and device type, hashed identifiers
Sensitive dataNone intended (see A4)
DurationFor the term of your use of Business Features, plus the deletion period in B9

B3. Our duties as processor

We will:

  1. process Customer Personal Data only on your documented instructions. These terms, your settings and your use of the features are your instructions. We will tell you if we believe an instruction breaks data protection law;
  2. not sell or share Customer Personal Data, not use it for targeted advertising, not use it to train AI models, and not keep, use or disclose it for any purpose other than providing the service, except as the law allows a processor or service provider to do;
  3. not combine it with personal data from other sources, except as the law allows (for example, for security and fraud prevention);
  4. make sure our staff and contractors who can access it are bound by confidentiality;
  5. keep appropriate technical and organisational security measures (B6);
  6. help you, taking into account the nature of the processing, to respond to data subject requests, carry out data protection impact assessments, and consult authorities;
  7. tell you if we can no longer meet our obligations under the CCPA or other applicable law, and let you take reasonable steps to stop unauthorised use;
  8. make available the information needed to show we meet this DPA (B8).

B4. Your duties as controller

B5. Sub-processors

B6. Security

Our measures include: encryption in transit (HTTPS/TLS); access limited to staff who need it; hashing of visitor and network identifiers; rate limits, bot checks and abuse monitoring; separation of private contact details; logging of access to private details; backups with limited retention; and regular updates. We may improve these measures over time, but will not reduce overall security.

B7. Personal data breaches

If we become aware of a breach affecting Customer Personal Data, we will tell you without undue delay, and where possible within 48 hours. We will share what we know about the nature of the breach, the data and people affected, likely consequences, and the steps we are taking, and update you as we learn more. This helps you meet deadlines such as 72 hours under the GDPR and India's DPDP Rules. Telling you about a breach is not an admission of fault.

B8. Audits

On request, not more than once a year (or after a breach or an authority's request), we will answer a reasonable written security questionnaire and share relevant summaries of our controls and our sub-processors' certifications (such as SOC 2 or ISO 27001 reports). If this is not enough to meet a legal requirement, you may carry out an audit at your cost, with 30 days' notice, during business hours, by an independent auditor under confidentiality, in a way that does not put other customers' data at risk.

B9. Return and deletion

You can delete chats in the app at any time, and ask us for an export. When your Business Features end, you have 30 days to ask for an export of your data. We then delete Customer Personal Data within 60 days, and from backups within a further 35 days, unless the law requires us to keep it. Data kept for legal reasons, or for a pending dispute or investigation, stays protected under this DPA and is used only for that reason.

B10. International transfers

B11. Government requests

If an authority asks us for Customer Personal Data, we will try to redirect it to you. If we must respond, we will tell you first unless the law forbids it, and disclose only what is legally required.

B12. Term

This DPA lasts as long as we process Customer Personal Data for you. It is accepted when you use Business Features. If you need a signed copy, email [legal@tweely.app].

Contact

OneVault LLC, [OneVault LLC registered address]. Privacy and DPA questions: [privacy@tweely.app]. Security issues: [security@tweely.app].