Maison Labs, Inc.
Updated Jun 13, 2025
The following Data Processing Agreement (“DPA”) shall govern Client’s use of Maison Labs services as set forth below.
“Agreement” means the Master Service Agreement entered into between Client and Maison Labs governing Client’s use of the Services.
“Client” means the entity utilizing the Services,
“Client Data” means any data, content, or information submitted by or on behalf of Client to the Services, including personal data as defined under applicable law.
“Data Protection Laws” means all applicable data protection and privacy laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), and any other applicable laws governing the processing of personal data.
“Services” means the services provided by Maison Labs pursuant to the Agreement.
“Subprocessor” means any third party engaged by Maison Labs to process Client Data on its behalf.
“ToS” means Terms of Service as set forth in the Terms of Service Exhibit in the Agreement.
“Users” means individuals submitting data through Client’s websites or other portals utilizing the Services.
Client acts as the data controller (or equivalent under applicable law) and Maison Labs acts as the data processor with respect to Client Data processed through the Services.
Maison Labs will process Client Data solely for the purposes of providing, maintaining, and improving the Services, as described in the Agreement and ToS, and in accordance with Client’s documented instructions.
Maison Labs will, to the extent possible and legally permitted, assist Client in responding to requests from Users using the Services to exercise their rights under any applicable data protection laws or regulations., including access, rectification, erasure, restriction, objection, and data portability.
Maison Labs may engage Subprocessors to process Client Data, provided such Subprocessors are subject to data protection obligations substantially similar to those set forth in this DPA. Maison Labs will maintain a current list of Subprocessors at https://maison.cx/subprocessors and will notify Client of any material changes. Client may object to a new subprocessor on reasonable grounds relating to data protection.
Maison Labs will use best efforts to implement and maintain appropriate technical and organizational measures to protect Client Data against unauthorized or unlawful processing, accidental loss, destruction, or damage, as further described at https://maison.cx/security.
If Maison Labs transfers Client Data within the European Economic Area, United Kingdom, California or other jurisdiction requiring data transfer safeguards, it will use best efforts to ensure such transfers are made in compliance with any corresponding Data Protection Laws, including the use of standard contractual clauses or other appropriate safeguards.
Maison Labs will promptly notify Client without undue delay after becoming aware of a confirmed personal data breach affecting Client Data. Maison Labs will provide information regarding the nature of the breach, affected data, and mitigation steps, and will cooperate with Client in investigating and responding to the breach.
Upon termination or expiration of the Agreement, Maison Labs will, at Client’s written request, return or securely delete all Client Data in its possession, except as required by law. Maison Labs will certify deletion upon request.
Maison Labs will make available to Client all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by Client or its designated auditor, subject to reasonable notice, confidentiality, and frequency limitations (no more than once per year unless required by law or following a confirmed data breach).
Upon written request, Maison Labs will provide Client with a copy of Client Data in a commonly used machine-readable format within thirty (30) days, subject to applicable law and Section 9 of this DPA.
Nature and Purpose of Processing: Provision of chatbot and automation services, including hosting, storage, analysis, and support.
Types of Personal Data: As determined and submitted by Client, e.g., User names, contact details, chat transcripts, etc.
Categories of Data Subjects: Users, customers, employees, or other individuals whose data is submitted to the Services.
This DPA is incorporated by reference into the Agreement and ToS. In the event of a conflict between this DPA and the Agreement or ToS, this DPA, as updated, shall control with respect to the processing of Client Data. Maison Labs reserves the right to update this DPA periodically and this DPA will be subject to any updated terms in future DPA’s as necessary.