Data processing agreement

Effective 5 August 2026

This agreement applies wherever we process personal data on your behalf, and forms part of the terms of service. A countersigned copy on your paper is available , request it from our contact form and tell us which entity is contracting.

1 · Roles

For your account data, who your users are, what they configured: we are the controller. For your visitors' conversations we are the processor and you are the controller. You decide what the assistant is told, what it is allowed to do, and how long its conversations are kept. We act on those instructions.

2 · Subject matter and duration

We process conversation content and the technical data listed in the privacy policy, for the purpose of operating the assistant, for as long as your account is open and until you delete it or apply the retention period you have configured.

3 · Your instructions

Your configuration is your instruction: the retention period, the tools you enable, the origins you allowlist, the model tier. We will not process visitor data for any other purpose, and specifically we will not use it to train models, ours or anyone else's. If an instruction appears to us to breach data protection law, we will tell you rather than quietly carry it out.

4 · Confidentiality

Access to production data is limited to personnel who need it to operate or support the service, requires multi-factor authentication, is logged, and is subject to confidentiality obligations that survive their employment.

5 · Security

The measures we take are described on the security page, which also states plainly what we have not certified. In summary: encryption in transit and at rest, workspace-scoped queries, an origin allowlist on the widget, encrypted tool credentials, and logged production access. We will not describe those measures as a certification, because they are not one.

6 · Sub-processors

You authorise the sub-processors listed on the sub-processor page. We will give at least 30 days' notice before a new one starts processing, and you may object within that window; where we cannot accommodate an objection you may terminate the affected service and receive a refund of the unused remainder.

7 · International transfers

Storage is in India. Generating an answer transfers conversation content to a model provider that may process it in the United States. Where the transferred data concerns individuals in the EEA or the UK, that transfer is made under the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable. We name this transfer rather than describing ourselves as single-region, because a reviewer will find it either way.

8 · Assisting you

We will help you respond to a data subject's request to access, correct, export or delete their data, and the console can export or delete a conversation directly. We will assist with a data protection impact assessment on request, and provide what we hold to support it.

9 · Personal data breach

We will notify you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your data, with what we know, what we are doing, and what we recommend you do. We will not wait until the investigation is complete to make the first contact.

10 · Audit

We will answer a security questionnaire and provide documentation on request. Until an independent audit report exists, that is what we can offer, and we would rather say so than point you at a certification page that does not describe us.

11 · Deletion and return

On termination you may export your content from the console. We delete customer content 30 days after an account closes, except where law requires us to keep a record, and will confirm deletion in writing on request.

12 · Liability

The limitations in the terms of service apply to this agreement. Nothing here limits either party's obligations under applicable data protection law.