Version 519a37b8 - first version
Data Processing Agreement
This agreement applies where we process personal data on your behalf. It forms part of the Terms of
Service. It is a draft prepared by the build and is subject to review and acceptance by the owner
and their counsel; the version hash on the page identifies exactly which text you are reading.
1. Roles
You are the controller of the personal data you load into your workspace and of the personal data
your own use of the platform generates about your customers. We are the processor of that data. We
process it only on your documented instructions, of which your configuration of the platform and
these terms are part.
Where you are yourself a processor for another controller, we are a sub-processor, and the
obligations below apply to us in that position.
2. Subject matter, duration, nature and purpose
The subject matter is the operation of a customer-relationship and messaging platform. The duration
is the term of your subscription plus the wind-down window described in section 8. The nature and
purpose are storing contact and conversation records, sending and receiving messages and calls on
your instruction, scheduling appointments, running the automations you build, and reporting on the
result.
3. Categories of data and data subjects
Data subjects: your staff who hold accounts, and the individuals whose records you load - your
customers, leads and contacts.
Categories: identifiers and contact details, message and call content, call recordings and
transcripts where you enable them, appointment and pipeline records, consent records including when
and how consent was captured, and the technical metadata that carries all of it.
You determine whether special-category data enters your workspace. The platform does not require it,
and if your use case involves it you are responsible for the additional obligations that attach.
4. Our obligations
- We process personal data only on your instructions, and we tell you if an instruction appears to
us to breach applicable data protection law.
- Everyone we authorise to process the data is bound by a duty of confidence.
- We implement the technical and organisational measures described in section 6.
- We assist you, taking into account the nature of the processing, with data subject requests, with
security incidents, and with impact assessments where one is required.
- We make available the information needed to demonstrate compliance with this agreement and allow
for audits as described in section 9.
5. Sub-processors
You give general authorisation for the sub-processors listed below. We will give notice before
adding or replacing one, and you may object on reasonable data protection grounds before the change
takes effect.
- Database and application hosting - stores workspace content and runs the application.
- Messaging carrier - transmits messages and calls you send, and returns delivery receipts.
- Email sending provider - transmits the email you send and returns delivery events.
- Voice and transcription provider - places the calls your voice automations make and returns
recordings and transcripts, where you enable those features.
- Payment processor - handles your billing details. It receives your billing data, not your
workspace content.
- Error and performance monitoring - receives operational telemetry, scrubbed of message bodies
and contact identifiers.
Each is engaged under terms no less protective than this agreement, and each remains our
responsibility to you.
6. Security measures
- Workspace isolation enforced at the database layer, so that a defect in application code cannot
return another workspace's rows.
- Encryption of data in transit, and at rest at the storage layer.
- Authentication with a second factor available on every account, and required for staff access to
production.
- Least-privilege access, logged, and reviewed.
- Staff access into a customer workspace that is time-boxed, recorded, and visible to that customer.
- Backups, with restoration exercised rather than assumed.
- Change control through version-controlled migrations, with a tested reverse for each.
7. Incidents
We will notify you without undue delay after becoming aware of a personal data breach affecting your
data, with the information we have at the time and updates as we learn more. We will not delay a
notification in order to make it complete.
8. Deletion and return
On termination you may export your data for the duration of the wind-down window stated in the
Terms. After it ends we delete the data from live systems, and from backups on the ordinary backup
rotation, unless the law requires us to keep it. We will confirm deletion in writing on request.
9. Audit
We will respond to a reasonable written request for information about our processing, and will make
available the current reports and certifications we hold. Where that is not sufficient for your own
obligations, we will agree a proportionate audit on reasonable notice, no more than once a year
absent an incident, and subject to confidentiality.
10. Transfers
Where personal data is transferred outside the region selected for your workspace, the transfer is
made under an approved transfer mechanism, identified for each sub-processor on request.
11. Precedence
Where this agreement and the Terms of Service conflict on the processing of personal data, this
agreement governs. Where either conflicts with a marketing statement, the document governs.