
# Privacy Laws Outside the EU

Our privacy documentation is written around the GDPR, because that is the law we operate under. Customers in other countries regularly ask whether the same answers work for POPIA, the CCPA, HIPAA and similar regimes. This page gives the honest position for each of the ones we are asked about most.

**The commitments themselves do not change by country.** Wherever your business is, you get the same thing: your data stored on dedicated servers in Germany, a published sub-processor list with 14 days' notice before it changes, a contractual promise that your data is never used to train AI models and never sold, breach notification within 24 hours, and a published retention schedule. Those are set out in [Where Your Data Is Stored](data-hosting-and-retention.md).

---

## What We Can Give You, Whatever Your Jurisdiction

| What a reviewer usually asks for | Where to get it |
|---|---|
| A signed data processing agreement | [dmchamp.com/dpa](https://dmchamp.com/dpa): self-serve, with your own company name on it, in about a minute. See [Get a Signed DPA](data-processing-agreement.md) |
| The list of other companies that touch the data | [dmchamp.com/subprocessors](https://dmchamp.com/subprocessors), with locations and a change-notice subscription |
| Hosting, access control and backups | [dmchamp.com/security](https://dmchamp.com/security) |
| International transfers and retention periods | [dmchamp.com/privacy-policy](https://dmchamp.com/privacy-policy), Sections 7 and 8 |
| A portable copy of everything in the account | [Download Your Data](data-export.md): available at any time, and for 30 days after you cancel |

---

## GDPR and UK GDPR

Fully covered. The DPA is an Article 28 processor agreement, transfers outside the EEA run on the European Commission's Standard Contractual Clauses with the UK addendum where it applies, and the retention schedule is published. Section 14 of our Terms is itself a DPA and already applies to your account, so you are covered even before you download a signed copy.

---

## CCPA / CPRA (California)

The question behind this one is almost always "do you sell or share personal information?" **No.** We do not sell your data and we do not share it with anyone outside the published sub-processor list. That is a contractual commitment in our Terms, not a policy we can quietly change.

We act as a service provider processing data on your instructions. The same DPA, sub-processor list and security page are what your reviewer needs; we do not publish a separate California-specific addendum.

---

## POPIA (South Africa) and other national privacy laws

We do not publish country-specific addenda. There is one DPA, and it is written to GDPR standards, which is the strictest of the regimes we get asked about. In practice the substance a POPIA operator agreement or an equivalent national requirement asks for is what the DPA, the sub-processor list and the security page already document: where the data lives, who else processes it, how long it is kept, how breaches are reported, and that it is not used for anything else.

If your legal team needs specific wording added for a national requirement, email [support](mailto:hi@dmchamp.com) with the clause and we will tell you whether we can sign it.

---

## HIPAA (United States healthcare)

**The platform is not HIPAA compliant, and we do not sign Business Associate Agreements.**

This is not only our own position. The messaging channels themselves cannot be made HIPAA compliant: Meta does not sign BAAs for WhatsApp, Instagram or Messenger, so protected health information should not travel over those channels at all, regardless of which software sends it.

What healthcare customers do instead, and what we recommend:

- Use the platform for the top of the funnel only: answering enquiries, qualifying, and booking consultations.
- Keep protected health information out of the chat. Configure your Agent's instructions to move any clinical or record-keeping conversation into your own patient portal or records system.
- Pair the platform with a healthcare records system that is built for this, and let that system hold the clinical data.

---

## Certifications

**We are not SOC 2 or ISO 27001 certified.** Those are audit programmes a team our size has not undertaken, and we would rather say so than let a reviewer assume otherwise. Our [security page](https://dmchamp.com/security) says the same thing out loud, along with what we do have.

---

## Next Steps

- [Where Your Data Is Stored](data-hosting-and-retention.md): hosting, sub-processors, retention and breach notification.
- [Get a Signed DPA](data-processing-agreement.md): a counter-signed Article 28 agreement in about a minute.
- [Download Your Data](data-export.md): a portable copy of your account.
