Skip to content

Legal

Data Processing Agreement

Last updated: October 2026

Data Processing Agreement

01About this agreement

This Data Processing Agreement ("DPA") is part of the PageFox Terms of Service. It applies whenever PageFox processes personal data for you while running the Service on your website. You accept it by using PageFox under the Terms. No separate signature is needed.

If your company needs a countersigned copy for its records, write to legal@pagefox.co and we will send one with the same text.

If this DPA and the Terms disagree about personal data, this DPA wins.

02Who does what

You are the customer that installs PageFox on its website. You decide why and how visitor data is used. Under the GDPR you are the controller, under India's Digital Personal Data Protection Act 2023 ("DPDP Act") the Data Fiduciary, and under US state privacy laws the business.

PageFox is operated by Palanisamy Krishnan, a sole proprietorship registered in India, trading as Kaiaan Labs. For the data we process on your website, PageFox is your processor (GDPR), Data Processor (DPDP Act) and service provider (US state laws).

PageFox is a separate controller only for its own account, billing and security records, which the Privacy Policy covers.

03What we process

  • Purpose: to run the Service for you: record visits to your site, estimate which organisation's network a visit came from where we can, answer chat questions from your own site content, score leads and send them to you.
  • People: visitors to your website, people who chat or fill a form on it, and your own team members who use PageFox.
  • Data: pages viewed and when, referrer and campaign tags, browser and device type, IP address, an approximate location from the IP address, a random browser ID where consent allows it, chat messages, and any name, email or other details a visitor chooses to type into a chat or form.
  • Not wanted: health, religious, financial account, government ID or other sensitive data. The Service is not built for it and you should not collect it through PageFox.
  • How long: for as long as you use PageFox. Visit records are kept for 90 days and company matches for 180 days, unless you delete them sooner or a law requires us to keep them longer.

04Your instructions

We process personal data only on your documented instructions. Your instructions are the Terms, this DPA, and the settings you choose in PageFox. We will not use your visitors' data for any other purpose.

If we believe an instruction breaks a data protection law, we will tell you and may pause that processing until it is resolved. If a law requires us to process data in another way, we will tell you first unless that law forbids it.

05Confidentiality

Everyone at PageFox who can access your data is bound to keep it confidential and may access it only to run, support or secure the Service.

06Security

We keep reasonable security measures that fit the risk, and we review them as the Service changes. They include:

  • encryption of data in transit, and encryption at rest by our hosting providers;
  • access limited to the people who need it, with database rules that keep each customer's data separate;
  • logs of access to production systems, kept so that misuse can be found and investigated;
  • backups, and a tested way to restore them;
  • secrets kept out of source code, and rotated when exposure is suspected.

These measures are meant to meet the reasonable security safeguards the DPDP Act and its Rules require, and Art. 32 of the GDPR.

07Sub-processors

You give general permission for PageFox to use sub-processors. The current list is at pagefox.co/subprocessors.

  • Each sub-processor is bound by written data protection terms at least as protective as this DPA.
  • We tell you at least 30 days before we add or replace a sub-processor, by email to your account owner and on the list page.
  • You may object on reasonable data protection grounds within that time. If we cannot address the objection, you may end the affected part of the Service and get a pro-rata refund of prepaid fees for it.
  • PageFox stays responsible to you for the work of its sub-processors.

08Help with rights requests

If a person asks us directly to access, correct, delete or stop the use of their data held for you, we will send the request to you and will not answer it ourselves unless you ask us to.

We will help you answer such requests, using the tools in the product where they exist and by hand where they do not. Opt-out and deletion requests can also be made at pagefox.co/privacy/opt-out.

09Data breaches

If we become aware of a breach of security that affects your personal data, we will tell you without undue delay, and in any case within 72 hours of becoming aware of it.

We will tell you what happened, what data and how many people are likely affected, what we are doing about it, and who to contact. We will give you what you reasonably need to notify a regulator, such as the Data Protection Board of India or an EU supervisory authority, and the people affected. Where the facts are not all known yet, we will send them as we learn them.

10Deletion at the end

When your account ends, we delete your personal data within 30 days, or return it to you first if you ask before then. Copies in backups are deleted when those backups expire. We keep data longer only where a law requires it, and then only for that purpose.

11Information and audits

We will give you the information reasonably needed to show that we keep this DPA, including answers to security questionnaires. If that is not enough, you may audit our compliance once a year, with 30 days' notice, during business hours, at your cost, and under a confidentiality agreement. A regulator's request is not limited to once a year.

12International transfers

PageFox is run from India and uses sub-processors in other countries. Where we move personal data across borders, we do so lawfully.

  • From the EU or EEA: the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Module Two (controller to processor), apply between you as data exporter and PageFox as data importer and form part of this DPA. Clause 7 (docking) applies, Clause 9 option 2 (general authorisation, 30 days) applies, the Clause 11 option does not, and Clauses 17 and 18 choose the law and courts of Ireland. The details of processing are in "What we process" above and the security measures in "Security".
  • From the UK: the UK International Data Transfer Addendum to those clauses applies.
  • From India: transfers follow section 16 of the DPDP Act and any restriction the Government of India notifies under it.

13US state privacy laws

Where the California Consumer Privacy Act or a similar US state law applies, PageFox acts as your service provider or processor and:

  • does not sell or share your personal data, as those laws define those words;
  • does not keep, use or disclose it for any purpose other than providing the Service to you;
  • does not keep, use or disclose it outside our direct business relationship with you;
  • does not combine it with personal data we receive from or for any other customer, or collect ourselves, except as those laws allow;
  • follows the same laws and gives the same level of privacy protection they require;
  • tells you if we can no longer meet these duties, and lets you take reasonable steps to stop and fix any unauthorised use.

14India DPDP Act

For personal data covered by the DPDP Act, this DPA is the valid contract under section 8(2) under which PageFox processes data for you as your Data Processor. PageFox will:

  • process data only to provide the Service and on your instructions;
  • keep the security safeguards described above;
  • tell you about a personal data breach as set out above so you can inform the Board and the people affected;
  • erase data when you instruct us, when consent is withdrawn and you tell us, or when the purpose is served;
  • keep logs of processing for as long as the DPDP Rules require.

15Your duties

You agree that you will:

  • tell your visitors about PageFox in your own privacy notice (ready-made text is in our help pages), and get consent where a law requires it, for example through your cookie banner;
  • not install PageFox on websites directed at children, or on websites about health, religion, sexuality or other sensitive subjects;
  • not try to find out who an individual visitor is from the data PageFox shows you;
  • use PageFox for business-to-business purposes only.

16Data from other sources

Some company and contact details shown in PageFox come from licensed third-party data sources. You may use them inside PageFox for your own business. You agree that you will not:

  • resell, sublicense or give others access to that data, or to anything built from it;
  • copy a substantial part of it out of PageFox, or give anyone programmatic access to a substantial part of it;
  • build a product that competes with the data source;
  • use it to decide anyone's eligibility for credit, insurance, employment, housing, a licence or a government benefit;
  • use it in any way a data protection law forbids.

17Liability and changes

The limits of liability in the Terms apply to this DPA. Nothing in this DPA limits a right that a person has under a data protection law.

We may update this DPA when the law or the Service changes. We will post the new version here and tell you by email at least 30 days before a change that reduces your protection takes effect.

18Contact

Privacy questions go to privacy@pagefox.co, and security reports to security@pagefox.co. Postal notices go to Kaiaan Labs, 13/47A, Pallapalayam, Irugur, Coimbatore, Tamil Nadu 641103, India.

PageFox is operated by Palanisamy Krishnan under the trade name Kaiaan Labs, a sole proprietorship registered in India. Registered address: Kaiaan Labs, 13/47A, Pallapalayam, Irugur, Coimbatore, Tamil Nadu 641103, India.