1. The DPA is included in your subscription
Article 28 GDPR requires a written contract between the controller (your school) and its processor (Qaptivo). Good news: it is automatically entered into upon subscription, with no form and no handwritten signature.
The Qaptivo DPA is public and incorporated by reference into the Terms of Sale. Accepting the Terms and Conditions at the time of subscription constitutes full and complete acceptance of the DPA : this is the mechanism recognised by the GDPR (article 28(9): "the contract shall be in writing, including in electronic form") and used by every serious B2B SaaS (Stripe, Linear, Vercel, Chatbase, etc.). No legal back-and-forth, no friction.
To file the DPA in your internal compliance records, you can read it online, print it or save it as a PDF in one click from that same page.
Good to know: the Qaptivo DPA is governed by Portuguese law (registered office of Navescale, Lda in Lisbon) and refers to the standard contractual clauses of the European Commission (Decision 2021/914) to govern sub-processors outside the EU (Anthropic, OpenAI, Cloudflare, Stripe, Sentry, Giphy). Any substantial change is notified by email with 30 days' notice.
2. Paragraph to add to your privacy policy
Add this paragraph to the "Processors" or "Data collected" section of your privacy policy. It informs your visitors that their conversations are processed by Qaptivo as a processor.
3. Paragraph to add to your cookie banner
Good news: the Qaptivo widget sets no cookie and no local identifier until the visitor clicks the bubble to open the chat. You are therefore not required to request prior consent to load the widget. If you would nonetheless like to mention it in your cookie banner for the sake of transparency, here is a short paragraph to add:
4. Mention in your legal notice (optional)
If your legal notice lists the website's publishers and processors, you can add Qaptivo to the list:
5. Compliance FAQ
Are my prospects protected?
Yes. Qaptivo applies GDPR standards: HTTPS encryption, data isolation per school (each school only sees its own prospects), automatic deletion of conversations after 12 months, primary hosting in Germany (Hetzner Frankfurt), Data Privacy Framework agreements and standard contractual clauses for any processing outside the EU.
What happens in the event of a request from the CNIL or the CNPD?
As a processor, Qaptivo undertakes to assist you within 72 hours for any request for access, rectification, erasure or portability, as well as in the event of an audit or a request from a supervisory authority. The details of these commitments are in the DPA.
Isn't the lead score a prohibited automated decision?
No. The Qaptivo score (0 to 100) is used solely to help your human team prioritise its follow-up calls. It produces no legal effects concerning the data subject and does not result in any automated decision on admission, refusal or funding (article 22 GDPR complied with).
Can I delete a prospect / a lead on request?
Yes, from your dashboard or by contacting Qaptivo. Deletion is cascading: conversation, lead, score and history are permanently erased. Backups are purged within 30 days.
Do Anthropic and OpenAI use our conversations to train their models?
No. Data sent to Anthropic and OpenAI through their API is not used to train the models. This is their public contractual commitment, and it is also the one Qaptivo passes on in its DPA.
Do I need a DPIA (Data Protection Impact Assessment) before deploying Qaptivo?
For most schools, no: the processing does not fall within the cases where the CNIL or the CNPD require a mandatory DPIA (no large-scale profiling, no sensitive data within the meaning of art. 9, no systematic evaluation). If in doubt (public university, predominantly under-age audience, etc.), Qaptivo provides you free of charge with the technical elements required for your DPIA on simple request.
Any questions?
Our DPO replies within 48 working hours: [email protected].