1. Requesting a DPA
Email legal@chartbuddy.io with your legal entity name, registered address, and the surfaces you plan to use. We will send our standard Data Processing Addendum for signature, normally within two business days. There is no charge, and you do not need to be on a particular plan to ask for one.
If your organization requires us to sign your own DPA instead, send it with your request. We will review it and come back with any comments.
2. When you need one
You need a DPA where Chartbuddy processes personal data on your behalf and you are the controller of that data. In practice this means you have a Chartbuddy account, or your organization does.
You do not need a DPA to use Chartbuddy Embed. Embed requires no account, and charts render entirely in the browser, so no chart content or spreadsheet data ever reaches us. Where you self-host the package or install it from npm, we receive nothing at all. Where a page loads the package from a Chartbuddy address, we see only the standard technical information accompanying that one file request, including an IP address, which we use to serve the file and guard against abuse. Either way we are not your processor for chart rendering. If you ship Embed inside your own product, you are the controller for your end users and we are not in that chain of processing.
3. What the DPA covers
Our standard DPA is drafted as a controller to processor agreement under Article 28 GDPR. It covers:
- The subject matter, nature, purpose, and duration of processing, described per surface
- The categories of personal data and data subjects involved
- Our obligation to process only on your documented instructions
- Technical and organizational security measures
- Confidentiality obligations on our personnel
- Subprocessor authorization, our current list, notice of changes, and your right to object
- Assistance with data subject requests, impact assessments, and consultations with supervisory authorities
- Audit rights, including documentation of controls on request
- Personal data breach notification without undue delay
- Return and deletion of personal data on termination
- Data transfer mechanisms, including the European Commission's Standard Contractual Clauses where relevant
4. What we process, by surface
Because our surfaces handle data differently, the DPA describes each one separately. In summary:
- Chartbuddy Embed: no chart content processed by Chartbuddy. Charts render on the viewer's own device. See Section 2 for the one exception, which is package delivery from a Chartbuddy address.
- Chartbuddy Hub: account and authentication data, software update checks, crash reports, and technical telemetry. Your charts stay on your own device and we do not receive them.
- Chartbuddy Google Slides: account and authentication data, Google Workspace document IDs for the presentations you select, and a chart image held for approximately two seconds during insertion where you use our managed storage. Chart content and spreadsheet data are processed in your browser.
- Chartbuddy PowerPoint: account and authentication data. This surface launches September 2026 and the DPA will be updated when it does.
Full detail is in our Privacy Policy and our Subprocessors page.
5. Enterprise agreements
If you sign a Master Subscription Agreement with us, the DPA is included as an exhibit and you do not need to request it separately. Where you have executed such an agreement, it governs in place of any conflicting provision in our Terms of Use.
6. Security documentation
Alongside a DPA we can provide, under NDA, our security overview, a completed security questionnaire, and our certificate of insurance. Our Security page describes our controls on each surface. To report a vulnerability, email security@chartbuddy.io.
7. Contact
- DPA requests and legal: legal@chartbuddy.io
- Data protection contact: tim@chartbuddy.io
- Security: security@chartbuddy.io