1. About this agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer") and The Disruption Laboratory Ltd (company number 08716850, registered office 27 Park Lane, Chippenham, Wiltshire, SN15 1LT) ("Deskee"). It applies whenever Deskee processes Customer Personal Data on your behalf, and sets out the terms required by Article 28 of the UK GDPR and, where it applies, the EU GDPR (together, "Data Protection Law"). Where this DPA and the Terms of Service conflict on data protection, this DPA takes priority.

2. Roles

For personal data that you or your visitors put into the Service through your chatbots, channels and service desk ("Customer Personal Data"), you are the controller and Deskee is your processor. For personal data we use to run our own business — such as account, billing and sign-in details about you and your teammates — Deskee is a controller, and our Privacy Policy applies instead.

3. Details of the processing

4. Processing on your instructions

We'll process Customer Personal Data only on your documented instructions. Those instructions are the Terms of Service, this DPA and the way you configure and use the Service. If we're legally required to process it in some other way, we'll tell you first unless the law prevents us. We'll let you know if we believe an instruction breaks Data Protection Law.

5. Confidentiality and security

Everyone at Deskee authorised to process Customer Personal Data is bound by a duty of confidentiality. We maintain appropriate technical and organisational measures to protect it, including:

6. Sub-processors

You give general authorisation for us to use sub-processors. We impose data protection obligations on each one that are no less protective than this DPA, and remain responsible for their performance. Our current sub-processors are:

We'll give at least 30 days' notice by email to the account owner before adding or replacing a sub-processor. If you object on reasonable data protection grounds, tell us within that period; if we can't address your objection, you may cancel the affected service and we'll refund any prepaid fees for the rest of your billing period.

Services you connect yourself — such as your own AI model provider, Telegram, Google Calendar, your email server, or APIs and webhooks you configure — are not our sub-processors. Data sent to them is sent on your instructions and under your agreement with them.

7. International transfers

Where we or our sub-processors transfer Customer Personal Data outside the UK or European Economic Area, we'll make sure it's protected by an appropriate safeguard, such as an adequacy decision or data bridge (including the UK Extension to the EU-US Data Privacy Framework), the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses.

8. Helping you meet your obligations

Taking into account the nature of the processing, we'll help you respond to requests from people exercising their data protection rights, and — as reasonably required — with security, data protection impact assessments and consultations with regulators. If we receive a request directly from one of your visitors, we'll pass it to you rather than respond ourselves.

9. Personal data breaches

We'll notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We'll give you the information we have that you reasonably need to meet your own notification obligations, update you as we learn more, and take reasonable steps to contain it and limit its effects.

10. Deletion and return

You can ask us at any time to provide a copy of, or delete, Customer Personal Data by emailing hello@deskee.io. When your account closes, we'll delete Customer Personal Data within 90 days, unless the law requires us to keep it. Deletion from backups happens as they expire in the normal course.

11. Information and audits

We'll make available the information reasonably necessary to show we're meeting this DPA. If that isn't enough, you or an independent auditor you appoint may audit our compliance, no more than once a year, on at least 30 days' written notice, during business hours, at your cost and subject to reasonable confidentiality commitments — unless a regulator requires otherwise or following a personal data breach.

12. Your responsibilities

You're responsible for having a lawful basis for the processing you ask us to carry out, for giving your visitors any privacy information required by law (for example, a privacy notice on your website that covers your chatbot), and for the accuracy of the instructions and content you give us.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law doesn't allow it to be limited.

14. Contact us

Questions about this DPA, or requests for a signed copy, can be sent to hello@deskee.io.