Business & Widget Terms
Last updated: 28 September 2026
These terms apply when you use Tweely for a business, organisation or professional purpose: business pages, team members, chat links, the AI front desk, intake cards, stickers, and the Tweely chat widget on your own website (together, "Business Features"). They add to our Terms of Service. Part B is a Data Processing Addendum (DPA). "You" or "Customer" means the business. "Tweely", "we" or "us" means OneVault LLC.
Part A: Business terms
A1. Business use
- You confirm you are acting for a business, not as a consumer, and that the person accepting these terms has authority to bind the business.
- You are responsible for your team members (owners, admins, editors and agents) and for everything done on your pages. Remove access promptly when someone leaves.
A2. The chat widget
- Install the widget only on websites and domains you own or control, and add those domains to your allowed list. Do not change the widget code to hide Tweely's notices, the AI label, or reporting tools.
- You are responsible for your website, including its cookie banner and privacy notice. If your laws require consent before the widget loads (for example under the EU ePrivacy rules), you must get it first.
- We may stop the widget from loading on a website that breaks these terms or the Acceptable Use Policy.
A3. AI front desk
- The AI front desk always tells visitors they are talking to AI, as the EU AI Act and similar laws require. You must not remove, hide or contradict that notice, or tell visitors that the AI is a person.
- You control the knowledge the AI uses. You are responsible for its accuracy and for prices, offers, bookings and promises the AI makes based on it. Review it regularly.
- Do not use the AI front desk to make decisions with legal or similarly significant effects on people (for example, about credit, jobs, housing, insurance or healthcare), or for any "high-risk" use under the EU AI Act.
- Offer a way to reach a human, and answer escalations in a reasonable time.
A4. Data you must not collect
Unless we agree in writing, do not use Tweely to collect or store: payment card numbers or bank details; passwords; government ID numbers (such as SSNs or passport numbers); health information (Tweely is not HIPAA compliant and we do not sign business associate agreements); biometric data; data about children under 18; or other special category or sensitive personal data. If a visitor sends such data, delete it from the chat.
A5. Messages and marketing
- Only message people who contacted you or agreed to hear from you. You are responsible for following anti-spam, marketing and telemarketing laws (such as the TCPA, CAN-SPAM, GDPR and ePrivacy rules) for messages you send.
- Do not add people to groups or broadcast lists without their permission.
A6. Fees
Business plans, seats, storage and AI credits are billed yearly or as bought, under sections 9 and 10 of the Terms of Service. You are responsible for all taxes, except taxes on our income. If you give us a VAT or GST number, reverse charge may apply.
A7. Suspension
We may suspend Business Features, the widget or AI replies at once if you break these terms, if there is a security risk, if payment is overdue, or if the law requires it. Where practical, we will tell you first and give you a chance to fix the problem.
A8. Your indemnity
You will defend and pay for any claim, fine or loss brought against us by a third party or authority arising from: your content and AI knowledge; your website and how you installed the widget; your messages to people; your failure to give notices or get consents you are required to; or your breach of these terms or the law.
A9. Our liability to businesses
For business customers, as far as the law allows: (a) neither side is liable for indirect, incidental, special, consequential or punitive damages, or lost profits, revenue or data; and (b) each side's total liability for all claims under these terms and the DPA is limited to the amounts you paid us in the 12 months before the event that caused the claim. These limits do not apply to your payment duties, your indemnity, or liability that cannot be limited by law.
A10. Order of precedence
If documents conflict, this order applies: (1) the Standard Contractual Clauses (where they apply), (2) the DPA in Part B, (3) Part A, (4) the Terms of Service, (5) other policies.
Part B: Data Processing Addendum
B1. Roles
- You are the controller (also "business" under the CCPA, "data fiduciary" under India's DPDP Act, and "controller" under Sri Lanka's PDPA) of Customer Personal Data.
- Tweely is your processor (also "service provider" under the CCPA and "data processor" under the DPDP Act and PDPA).
- "Customer Personal Data" means personal data about your website visitors, customers and contacts that Tweely processes for you through Business Features: chats, widget conversations, intake card answers, visitor details they send, and AI front desk conversations.
- Tweely is an independent controller for your account and team member data, billing, safety and abuse prevention (including hashed network identifiers, reports and moderation records), legal compliance, and aggregated, de-identified statistics. The Privacy Policy covers those.
B2. Details of processing
| Item | Details |
|---|---|
| Subject matter and purpose | Providing chat, widget, AI front desk, intake and inbox features to you |
| Nature of processing | Collecting, storing, displaying, sending to AI providers to create replies, routing to your team, notifying you, deleting |
| Data subjects | Your website visitors, customers, leads and other people who chat with you |
| Types of data | Names, contact details they choose to give, message content, attachments, intake answers, chat timestamps, country and device type, hashed identifiers |
| Sensitive data | None intended (see A4) |
| Duration | For the term of your use of Business Features, plus the deletion period in B9 |
B3. Our duties as processor
We will:
- process Customer Personal Data only on your documented instructions. These terms, your settings and your use of the features are your instructions. We will tell you if we believe an instruction breaks data protection law;
- not sell or share Customer Personal Data, not use it for targeted advertising, not use it to train AI models, and not keep, use or disclose it for any purpose other than providing the service, except as the law allows a processor or service provider to do;
- not combine it with personal data from other sources, except as the law allows (for example, for security and fraud prevention);
- make sure our staff and contractors who can access it are bound by confidentiality;
- keep appropriate technical and organisational security measures (B6);
- help you, taking into account the nature of the processing, to respond to data subject requests, carry out data protection impact assessments, and consult authorities;
- tell you if we can no longer meet our obligations under the CCPA or other applicable law, and let you take reasonable steps to stop unauthorised use;
- make available the information needed to show we meet this DPA (B8).
B4. Your duties as controller
- Have a lawful basis for the processing and give all required notices. Your privacy notice must say that you use Tweely (and our AI providers) to handle chats.
- Get any consent required for cookies, local storage or messages on your website.
- Make sure your instructions follow the law, and handle requests from your visitors. We will pass any request we receive about your data to you.
B5. Sub-processors
- You give us general authorisation to use sub-processors. Our current sub-processors are listed in the Privacy Policy (section 5): Amazon Web Services, Cloudflare, Google, OpenAI, [SMS provider(s)] and OneVault. Stripe processes billing data as an independent controller.
- We put written terms in place with each sub-processor that protect data at least as well as this DPA, and we remain responsible for them.
- We will give at least 30 days' notice (by email or in the app) before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that time. If we cannot address the objection, you may end the affected features and get a pro-rata refund of prepaid fees for them.
B6. Security
Our measures include: encryption in transit (HTTPS/TLS); access limited to staff who need it; hashing of visitor and network identifiers; rate limits, bot checks and abuse monitoring; separation of private contact details; logging of access to private details; backups with limited retention; and regular updates. We may improve these measures over time, but will not reduce overall security.
B7. Personal data breaches
If we become aware of a breach affecting Customer Personal Data, we will tell you without undue delay, and where possible within 48 hours. We will share what we know about the nature of the breach, the data and people affected, likely consequences, and the steps we are taking, and update you as we learn more. This helps you meet deadlines such as 72 hours under the GDPR and India's DPDP Rules. Telling you about a breach is not an admission of fault.
B8. Audits
On request, not more than once a year (or after a breach or an authority's request), we will answer a reasonable written security questionnaire and share relevant summaries of our controls and our sub-processors' certifications (such as SOC 2 or ISO 27001 reports). If this is not enough to meet a legal requirement, you may carry out an audit at your cost, with 30 days' notice, during business hours, by an independent auditor under confidentiality, in a way that does not put other customers' data at risk.
B9. Return and deletion
You can delete chats in the app at any time, and ask us for an export. When your Business Features end, you have 30 days to ask for an export of your data. We then delete Customer Personal Data within 60 days, and from backups within a further 35 days, unless the law requires us to keep it. Data kept for legal reasons, or for a pending dispute or investigation, stays protected under this DPA and is used only for that reason.
B10. International transfers
- Tweely is hosted in the United States. Where Customer Personal Data from the EU/EEA is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor) are incorporated into this DPA by reference, with you as data exporter and us as data importer. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, 30 days' notice) applies; the optional wording in Clause 11 does not apply; Clauses 17 and 18 use the law and courts of [EU member state for SCCs]. Annex I is B2 and Annex II is B6.
- For UK data, the UK International Data Transfer Addendum to the SCCs applies. For Swiss data, the SCCs apply with the changes required by Swiss law.
- For India and Sri Lanka, we follow any transfer restrictions the government sets under the DPDP Act and the PDPA.
B11. Government requests
If an authority asks us for Customer Personal Data, we will try to redirect it to you. If we must respond, we will tell you first unless the law forbids it, and disclose only what is legally required.
B12. Term
This DPA lasts as long as we process Customer Personal Data for you. It is accepted when you use Business Features. If you need a signed copy, email [legal@tweely.app].
Contact
OneVault LLC, [OneVault LLC registered address]. Privacy and DPA questions: [privacy@tweely.app]. Security issues: [security@tweely.app].