Last updated 02/09/2026
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the b2blead.ai Terms of Service, an order form, or another agreement between the client (“Controller”) and VIMI Co., Ltd. (“Processor”) when VIMI processes personal data on the client's behalf. It is intended to address Thailand PDPA section 40 and, where applicable, GDPR Article 28.
1. Scope, roles, and instructions
The client determines the purposes and essential means of processing customer personal data and acts as controller. VIMI acts as processor, except for account, billing, security, and other data for which the Privacy Notice identifies VIMI as controller. VIMI will process customer personal data only on documented instructions in the agreement, the client's feature configuration and authorized use, support requests, and other written instructions, unless applicable law requires processing. If law permits, VIMI will notify the client before legally required processing.
The client warrants that its instructions comply with applicable law and that it has provided required notices and established a lawful basis. VIMI will promptly inform the client if, in its reasonable opinion, an instruction infringes applicable data-protection law and may suspend that instruction while the parties resolve it.
2. Confidentiality and personnel
VIMI will limit access to personnel who need customer personal data to provide or secure the service. Those personnel are subject to confidentiality obligations and receive appropriate privacy and security guidance. VIMI remains responsible for their compliance with this DPA.
3. Security measures
Taking account of the state of the art, implementation cost, processing context, and risk, VIMI will maintain appropriate technical and organizational measures. Current measures include encrypted transport; role-based and tenant-scoped access; private storage; encryption of stored OAuth refresh tokens; service-role separation; audit and security logging; secrets management; vulnerability and dependency review; backup/recovery controls; incident handling; and data-minimization and retention workflows. Measures may evolve without materially reducing overall protection.
4. Subprocessors
The client gives general authorization for the subprocessors in the current Subprocessor Register. VIMI will impose data-protection obligations appropriate to the services each subprocessor performs and remains responsible for its subprocessor's processing to the extent required by applicable law.
VIMI will provide reasonable advance notice of a material new subprocessor where practicable. A client may object in writing on reasonable data-protection grounds within 15 days. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected service and the client will receive a refund of prepaid unused fees for that affected service.
5. Data-subject requests and compliance assistance
Taking account of the nature of processing, VIMI will provide reasonable assistance for access, correction, deletion, restriction, objection, portability, consent withdrawal, and other data-subject requests. VIMI will not independently respond to a request concerning client-controlled data except on client instruction or as required by law. VIMI will also provide reasonable information and assistance for security obligations, breach notifications, data-protection impact assessments, and regulator consultations, considering the information available to VIMI.
6. Personal data breaches
VIMI will notify the client without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach affecting customer personal data. As information becomes available, notice will describe the nature of the incident, likely consequences, affected data and individuals where known, containment or remediation, and a contact point. VIMI will take reasonable steps to contain, investigate, and mitigate the breach. Notification is not an admission of fault. The client is responsible for controller notifications unless law assigns that duty to VIMI.
7. Return, deletion, and retention
During the service, the client may export available customer data using product features or a reasonable support request. On termination or written instruction, VIMI will return or delete customer personal data, at the client's choice where reasonably practicable, unless law requires retention. Data in backups will be isolated from ordinary use and deleted through the applicable backup cycle. VIMI may retain non-content security, audit, billing, and legal records where required, subject to continuing confidentiality and access controls.
8. International transfers
The client authorizes transfers to the countries identified in the Subprocessor Register. VIMI will use an applicable lawful transfer mechanism and supplementary safeguards where required. For transfers governed by the GDPR or UK GDPR, the applicable EU Standard Contractual Clauses and UK Addendum are incorporated where the recipient country lacks an adequacy decision and another exemption does not apply. The parties will complete required annex information and cooperate on transfer risk assessments. Transfers governed by Thai PDPA will use applicable adequate-protection, contractual, consent, or statutory mechanisms.
9. AI processing and model training
VIMI may use only approved AI subprocessors to perform the client-configured service. VIMI will not use, and will not authorize an AI subprocessor to use, customer personal data to train or improve a general or shared model without the client's prior written authorization. Provider abuse-monitoring or security retention must be governed by the approved provider terms and account settings and does not permit general model training.
10. Records, information, and audits
VIMI will maintain records required of a processor and make information reasonably necessary to demonstrate compliance available to the client. VIMI may satisfy audit requests with current third-party reports, certifications, questionnaires, and security documentation. If those are insufficient, the client may conduct one reasonable audit per year, and additional audits after a material breach or regulator request, on advance notice, during business hours, without accessing other customers' data or unreasonably disrupting operations. The requesting client bears its audit costs unless the audit identifies a material breach by VIMI.
11. Processing details
- Subject matter and purpose: providing and securing AI chat, embedded forms, CRM, knowledge, reporting, messaging, integration, support, and related services configured by the client.
- Duration: the agreement plus the return/deletion and legally required retention period.
- Data subjects: client personnel, website visitors, prospects, leads, customers, correspondents, form submitters, integration users, and persons appearing in client content.
- Personal data: identity and business contact data; chat and message content; form fields and files; CRM activity; account roles; device, network, location, source, and interaction metadata; knowledge documents; email and Google integration data; consent and preference records; and support/audit data.
- Sensitive data: not intentionally required for the standard service. The client must not submit sensitive data unless necessary, lawful, appropriately protected, and expressly approved for the use case.
- Frequency and operations: collection, receipt, recording, organization, hosting, retrieval, consultation, analysis, generation, embedding, transmission, synchronization, restriction, export, anonymization, and deletion as continuously or periodically instructed by enabled features.
12. Order of precedence and contact
If this DPA conflicts with the agreement on personal-data processing, this DPA controls. A signed negotiated DPA controls over this online version. Liability under this DPA is subject to the agreement's liability provisions except where applicable law requires otherwise. Notices and signed-DPA requests may be sent to privacy@b2blead.ai.