Terms of Service, Privacy Notice & Data Processing Agreement
Last updated: August 2026
1. Terms of Service
Use of Service
AskVio ("Service", "we", "us") provides an AI‑powered site search widget for website owners ("Customer", "you"). By accessing or using the Service you agree to these Terms. You may use the Service to index your own content and to offer search capabilities to your users. You are responsible for the content you provide and for compliance with all applicable laws. You must not misuse the Service or interfere with its normal operation.
Accounts and Payments
Purchases and subscriptions are processed by Dodo Payments, our Merchant of Record, which handles billing and taxes on our behalf. You agree to provide accurate account and payment information and to keep this information up to date.
Disclaimer and Liability
The Service is provided "as is" without warranties of any kind. To the fullest extent permitted by law we disclaim all liability for any damages or losses arising from your use of the Service.
Governing Law
These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict of law provisions. Where mandatory local consumer-protection or data-protection law applies (including EU/EEA law), those provisions take precedence over this clause to the extent required by law.
2. Privacy Notice
This notice explains how AskVio collects and uses information about Customers (website owners who use our platform). For information about how data from your website's end-users is handled, see the Data Processing Agreement below.
What we collect about Customers
We collect information you provide when creating an account (name, email address), payment information processed on our behalf by Dodo Payments, and usage data about your use of the AskVio dashboard. We do not sell this data.
How we use it
We use your account data to operate the Service, send transactional communications (receipts, support replies), and comply with legal obligations. Aggregated, non-identifiable usage data may be used to improve the Service.
Your rights
Under GDPR and equivalent laws you have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact support@askvio.app. We will respond within 30 days.
Cookies
The AskVio dashboard uses only functional cookies required for authentication. The widget embedded on your website sets a single pseudonymous identifier in localStorage (or a cookie as fallback) to count unique visitors. No cross-site tracking or advertising cookies are used.
3. Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the agreement between AskVio ("Processor") and the Customer ("Controller") and governs all processing of personal data of the Controller's end-users carried out by AskVio in connection with the Service. It applies automatically upon acceptance of these Terms and satisfies the requirements of Art. 28 GDPR and equivalent provisions of the UK GDPR, Swiss DPA, and CCPA (where applicable).
3.1 Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in Regulation (EU) 2016/679 (GDPR). "End-user" means any natural person who interacts with the AskVio widget embedded on the Controller's website.
3.2 Subject Matter and Purpose of Processing
AskVio processes personal data solely to provide the Services described in the Terms: delivering AI-powered chat responses to end-users, generating anonymised analytics for the Controller's dashboard, and improving answer quality. AskVio acts as a Processor and processes personal data only on the Controller's documented instructions (these Terms and the Controller's Service configuration).
3.3 Categories of Personal Data and Data Subjects
Data subjects: end-users (visitors) of the Controller's website who interact with the AskVio widget.
Personal data processed:
- User-generated chat messages, which may contain personal identifiers typed by the end-user
- A pseudonymous visitor identifier (a UUID generated client-side and stored in
localStorageor a cookie) - The URL of the page on which the widget was opened
- Session metadata: timestamps, message lengths, response times
AskVio does not intentionally collect special categories of personal data (Art. 9 GDPR). Chat messages are processed through an automated PII-detection and redaction layer before storage and before being passed to AI sub-processors.
3.4 Processor Obligations
AskVio shall:
- Process personal data only on the documented instructions of the Controller, unless required to do so by applicable law (in which case AskVio shall inform the Controller of that legal requirement before processing, unless prohibited by law).
- Ensure that all persons authorised to process the personal data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures, including automated PII redaction before storage, encryption at rest, and access controls.
- Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting end-user data.
- Assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law, taking into account the nature of the processing.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, upon reasonable written notice.
- Upon termination of the Service, delete all personal data within 30 days unless applicable law requires longer retention.
3.5 Controller Responsibilities
The Controller is responsible for:
- Establishing and documenting a valid lawful basis for processing end-user data (e.g. legitimate interests under Art. 6(1)(f) GDPR to provide customer support, or end-user consent where required).
- Informing end-users about the use of AskVio in the Controller's own privacy policy, including the categories of data processed and the presence of AI-based processing.
- Handling Data Subject access, correction, erasure, and portability requests, with AskVio's assistance as set out in §3.4 above.
3.6 Sub-Processors
The Controller grants general authorisation for AskVio to engage the following sub-processors. AskVio shall ensure each sub-processor is bound by data protection obligations at least equivalent to those in this DPA. AskVio will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
| Sub-Processor | Role | Processing location | Transfer safeguard |
|---|---|---|---|
| OpenAI, L.L.C. | AI model inference — query processing, answer generation, conversation analytics, PII redaction | United States | Standard Contractual Clauses (SCCs) via OpenAI's Data Processing Addendum |
| Google Cloud / Firebase (Google LLC) | Cloud Functions compute, Firestore data storage, authentication | EU and United States | Google Cloud DPA with SCCs; EU region selected where available |
| Supabase, Inc. | Vector database for content retrieval (stores indexed content, not end-user messages) | EU | Supabase DPA; EU region |
3.7 International Data Transfers
Some processing described above involves transferring personal data to the United States. AskVio relies on Standard Contractual Clauses (SCCs, Commission Decision 2021/914) as the transfer mechanism for all transfers to sub-processors in third countries. Copies of the relevant SCCs are available on request at support@askvio.app.
3.8 Data Retention
| Data category | Retention period | Rationale |
|---|---|---|
| Raw chat query text (after PII redaction) | 90 days from creation | Short-term analytics; automatically deleted via Firestore TTL |
| Widget open and click events | 90 days from creation | Session analytics; automatically deleted via Firestore TTL |
| Conversation analysis (intent, mood, topic — no raw text) | 24 months from creation | Long-term trend analytics; contains no personal identifiers |
| Customer account data | Duration of subscription + 90 days | Billing and legal obligations |
3.9 Security Measures
AskVio implements the following technical and organisational measures:
- PII redaction: all end-user messages are processed through an automated redaction pipeline (regex patterns + LLM-based scan) before being stored or passed to AI sub-processors.
- Encryption at rest: all data stored in Firestore and Supabase is encrypted at rest using AES-256.
- Encryption in transit: all API calls use TLS 1.2 or higher.
- Access control: access to production data is limited to authorised personnel on a need-to-know basis.
- Automatic deletion: Firestore TTL policies enforce the retention periods in §3.8.
4. Refund Policy
If you are not satisfied with the Service, you may request a refund within 14 days of your initial purchase or renewal. To request a refund, contact support@askvio.app with your order information. Refunds are issued at our discretion and may be denied if the Service has been substantially used.
For questions about these terms, please contact support@askvio.app.