UK Pilot · Article 28 terms
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the Business AI Terms where a business uses Business AI to process personal data on its behalf. The business account holder is the Controller and the Business AI operator shown above is the Processor for the processing described below.
1. Processing details
Subject matter: customer enquiry handling and related lead, action, booking, Business Knowledge, support, optional marketing generation and connected-platform publishing workflows. Duration: while the Controller uses the service plus limited time required for secure return/deletion, backups and legal obligations. Nature and purpose: hosting, organising, retrieving, transmitting and otherwise processing Controller Personal Data to provide the configured Business AI service on documented instructions.
Data subjects
Customers and prospective customers of the Controller; authorised business users; and other people whose information the Controller lawfully submits to the service.
Types of personal data
Names, contact details, enquiry content, service/booking requirements, lead notes, communications, business-user identifiers, and other personal information the Controller chooses to submit. Businesses must not deliberately use Business AI to collect unnecessary special-category data, criminal-offence data or payment-card details.
2. Documented instructions
The Processor will process Controller Personal Data only on documented instructions from the Controller, including instructions expressed through authorised product settings and user actions, unless UK law requires otherwise. If a legal requirement requires processing outside those instructions, the Processor will inform the Controller before processing where legally permitted.
3. Confidentiality
The Processor will ensure that people authorised to process Controller Personal Data are subject to appropriate confidentiality obligations.
4. Security
The Processor will maintain measures appropriate to the risk, including authenticated tenant boundaries, role-based permissions, database row-level security, private storage, server-side secret handling, protected provider credentials, audit records, rate/usage controls and secure transport to providers. The Controller remains responsible for its user access, endpoints and lawful configuration.
5. Sub-processors
The Controller gives general written authorisation for the sub-processors listed in the Sub-processor Notice. The Processor will maintain that list and provide reasonable notice of material additions or replacements where appropriate. The Controller may raise a reasonable data-protection objection using the contact route shown above. The Processor will impose data-protection obligations on sub-processors that are appropriate to the services they provide and remains responsible for its Article 28 obligations.
6. Individual rights
Taking account of the nature of processing, the Processor will provide reasonable technical assistance to help the Controller respond to rights requests. The Pilot includes tenant-scoped export/anonymisation foundations for individual customer records.
7. Compliance assistance and incidents
Taking account of the processing and information available, the Processor will provide reasonable assistance with security obligations, personal-data-breach handling, data-protection impact assessments and regulator consultation where those duties apply. The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data and provide available information needed for the Controller's assessment and notifications.
8. International transfers
The Processor will not intentionally make a restricted transfer of Controller Personal Data unless a lawful UK transfer mechanism is available where required. The Controller authorises transfers inherent in the listed sub-processors subject to applicable safeguards and transfer assessment requirements.
9. Return and deletion
At the end of processor services, and at the Controller's choice, the Processor will delete or return Controller Personal Data and delete remaining copies unless UK law requires storage. Secure deletion may take a reasonable period across backups and provider systems.
10. Information, audits and inspections
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 and permit reasonable audits or inspections by the Controller or its appointed auditor, subject to confidentiality, security, proportionality and reasonable advance notice. Existing independent reports or provider documentation may be used where appropriate.
11. Controller obligations
The Controller is responsible for the lawfulness, fairness and transparency of its processing; the accuracy and necessity of submitted data; responding to individuals; selecting appropriate retention; maintaining required records; and ensuring its instructions comply with applicable law.
12. Priority and changes
If this DPA conflicts with the general Terms on the processing of Controller Personal Data, this DPA takes priority. Material changes are versioned and may require renewed owner acceptance.