Data Processing Agreement (Article 28 GDPR)

Last updated: 2026-09-17

This Data Processing Agreement ("DPA") forms part of, and supplements, the agreement between SARL Proxymis Multimedia ("Proxymis", "Processor", "we") and the customer operating an account on the html5-chat.com hosted chat product ("Customer", "Controller", "you"), for the processing of personal data of Customer's end users ("Users") through the embedded chat widget. It applies to the free and paid hosted plans. It does not apply to the self-hosted/source-code product: once the software is deployed on Customer's own infrastructure, Proxymis does not process Users' personal data and is not a processor under this DPA for that deployment.

1. Roles of the parties

For the personal data of Users described in Section 3, the Customer is the Controller and Proxymis is the Processor, acting only on the Customer's documented instructions (including those given through the product's configuration options, such as roles, JWT/SSO integration fields, and moderation actions).

For a narrow set of platform-wide security functions that Proxymis operates identically across all customer accounts for its own legal and legitimate-interest purposes — shared VPN/Tor abuse-detection lists, DDoS/WAF mitigation, and legally mandated CSAM detection and reporting — Proxymis acts as an independent controller. These datasets are not customer-specific and are not used to build a profile of any User.

For Customer's own account and billing data (company details, subscription and payment identifiers), Proxymis is the controller of that separate business relationship.

2. Subject matter and duration

Subject matter: hosting and operating the embedded chat widget (messaging, presence, moderation, and WebRTC-based audio/video/webcam features) on Customer's website. Duration: for as long as the Customer's account is active, plus the retention periods described in Section 5 and the deletion procedure in Section 8.

3. Nature, purpose and categories of data

Category of dataNature / purpose of processing
IP address, browser/device user-agent, client-side device fingerprint Connecting and maintaining the chat session; anti-flood/rate-limiting; ban enforcement and ban-evasion detection; VPN/Tor/proxy detection; DDoS/WAF mitigation.
Username, avatar, role, gender field, room ID, JWT/SSO integration fields Rendering the widget and enforcing the room/role permissions configured by the Customer; single sign-on handoff from the Customer's site.
Public and private messages, attachments, message metadata Delivering and displaying chat/history; enabling Customer's moderators to moderate and investigate abuse.
Login/authentication events, presence, moderation actions, bans, admin-access and security logs Operating the service, moderation, account security, abuse/attack detection and response.
WebRTC signalling (SDP/ICE); live audio/video streams; moderator-triggered webcam snapshots Establishing peer connections and relaying media through Proxymis's self-hosted media server; temporary safety review of a flagged room. Streams are not recorded or persistently stored.

Categories of data subjects: visitors and registered end users of the Customer's website who use the embedded chat widget, and, where applicable, the Customer's own moderators/administrators.

4. Processor obligations

Proxymis shall:

5. Retention

DataRetention
Public/private messages30 days from send date, capped at ~100 retained messages per account; messages flagged deleted are purged on the next daily cleanup (within 24h).
Uploaded attachments / video clips7 days from upload.
Session/login tokens10 minutes.
Temporary mutesRemoved on expiry; mute history kept 30 days.
Bans (IP/user/fingerprint)Duration of the ban plus a 12-month rolling history for repeat-offender detection; a shorter period can be applied per account on request.
Admin-login and security/audit logs12-month rolling retention.
Webcam moderation snapshots5 days from capture.
Inactive accountsNo fixed term; deleted on request or account closure (Section 8).
BackupsDaily full backup; each day's backup is superseded and unrecoverable roughly 24 hours after the next one is taken, except any subset retained under a specific legal obligation (e.g. a filed CSAM report).

6. Technical and organisational measures (TOMs)

7. Sub-processors

The Customer provides general authorisation for Proxymis to engage the following sub-processors, and Proxymis will inform the Customer of any intended change (addition or replacement) so the Customer may object on reasonable grounds.

Sub-processorLocationPurpose
OVH SASFrance (EU)Hosting, database, backup storage, outbound email relay.
Cloudflare, Inc.US / global networkCDN, DDoS mitigation, Web Application Firewall.
Intuition Machines, Inc. (hCaptcha)USBot / abuse-prevention challenge on certain forms.
ipinfo.appUSIP-reputation lookup for VPN/proxy/anonymizer detection (IP address only).
Google LLC (Google Fonts)USWeb font delivery.
Stripe / PayPalUS / EUPayment processing for account subscriptions and, where enabled, User-initiated payments (PPV/tipping).

Where a sub-processor is located outside the EEA, the transfer is safeguarded by that provider's Standard Contractual Clauses and/or EU-US Data Privacy Framework certification.

8. Deletion / return on termination

On termination of the Customer's account, Proxymis will, at the Customer's request made within 30 days of termination, make available an export of the Customer's account data (messages, attachments, account and configuration records). Proxymis will then delete this data from production systems and from the next backup rotation cycle, normally within 30 days of termination, except for any minimal subset it is legally required to retain (for example, a filed CSAM report).

9. Assistance with data-subject requests

Requests to retrieve, correct, export or delete a specific User's data can be sent to [email protected], identifying the account and the User (username, user ID, or IP/fingerprint). Proxymis will action such requests, generally within a few business days and in any event within the 30-day period required by the GDPR.

10. Personal data breach notification

Proxymis will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the Customer's User data, and will provide the information reasonably necessary for the Customer to meet its own notification obligations, along with the corrective measures taken.

11. Contact / Data Protection Officer

Proxymis Multimedia – DPO, chmielewski
24 rue de la cité, 59800 Lille, France
[email protected]

See also our general GDPR / privacy policy. For a countersigned copy of this DPA referencing your specific account, please contact us using the details above.