1. About this agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer") and The Disruption Laboratory Ltd (company number 08716850, registered office 27 Park Lane, Chippenham, Wiltshire, SN15 1LT) ("Deskee"). It applies whenever Deskee processes Customer Personal Data on your behalf, and sets out the terms required by Article 28 of the UK GDPR and, where it applies, the EU GDPR (together, "Data Protection Law"). Where this DPA and the Terms of Service conflict on data protection, this DPA takes priority.
2. Roles
For personal data that you or your visitors put into the Service through your chatbots, channels and service desk ("Customer Personal Data"), you are the controller and Deskee is your processor. For personal data we use to run our own business — such as account, billing and sign-in details about you and your teammates — Deskee is a controller, and our Privacy Policy applies instead.
3. Details of the processing
- Subject matter and duration — providing the Service under the Terms of Service, for as long as you use it and until deletion under section 10.
- Nature and purpose — hosting, storing, transmitting and processing messages and related data so your chatbots can answer visitors, hand conversations to your team, send notifications and emails, book appointments, translate and transcribe messages, and report on usage — as you configure them.
- Data subjects — visitors and other people who interact with your chatbots or contact you through a connected channel, and people named in the content you add.
- Types of personal data — whatever visitors choose to share in conversations, such as names, email addresses, phone numbers, messages, voice recordings and appointment details; email and messaging metadata for connected channels; and technical data such as browser type, page address and approximate location derived from IP address.
- Special category data — the Service isn't designed for special category or criminal offence data. Don't configure your chatbots to request it unless you have a lawful basis and have assessed the risk.
4. Processing on your instructions
We'll process Customer Personal Data only on your documented instructions. Those instructions are the Terms of Service, this DPA and the way you configure and use the Service. If we're legally required to process it in some other way, we'll tell you first unless the law prevents us. We'll let you know if we believe an instruction breaks Data Protection Law.
5. Confidentiality and security
Everyone at Deskee authorised to process Customer Personal Data is bound by a duty of confidentiality. We maintain appropriate technical and organisational measures to protect it, including:
- encryption of data in transit using TLS;
- encryption at rest of the credentials you give us, including AI provider keys, calendar tokens and website sign-in details;
- access restricted to authorised personnel who need it, with authenticated sign-in to the dashboard;
- logical separation of each customer's data within the Service;
- monitoring, logging and regular review of our infrastructure and these measures.
6. Sub-processors
You give general authorisation for us to use sub-processors. We impose data protection obligations on each one that are no less protective than this DPA, and remain responsible for their performance. Our current sub-processors are:
- Amazon Web Services — hosting, database and storage — United Kingdom;
- OpenAI — built-in AI responses, speech-to-text and text-to-speech — United States;
- DreamHost — delivery of notification and transcript emails — United States.
We'll give at least 30 days' notice by email to the account owner before adding or replacing a sub-processor. If you object on reasonable data protection grounds, tell us within that period; if we can't address your objection, you may cancel the affected service and we'll refund any prepaid fees for the rest of your billing period.
Services you connect yourself — such as your own AI model provider, Telegram, Google Calendar, your email server, or APIs and webhooks you configure — are not our sub-processors. Data sent to them is sent on your instructions and under your agreement with them.
7. International transfers
Where we or our sub-processors transfer Customer Personal Data outside the UK or European Economic Area, we'll make sure it's protected by an appropriate safeguard, such as an adequacy decision or data bridge (including the UK Extension to the EU-US Data Privacy Framework), the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses.
8. Helping you meet your obligations
Taking into account the nature of the processing, we'll help you respond to requests from people exercising their data protection rights, and — as reasonably required — with security, data protection impact assessments and consultations with regulators. If we receive a request directly from one of your visitors, we'll pass it to you rather than respond ourselves.
9. Personal data breaches
We'll notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We'll give you the information we have that you reasonably need to meet your own notification obligations, update you as we learn more, and take reasonable steps to contain it and limit its effects.
10. Deletion and return
You can ask us at any time to provide a copy of, or delete, Customer Personal Data by emailing hello@deskee.io. When your account closes, we'll delete Customer Personal Data within 90 days, unless the law requires us to keep it. Deletion from backups happens as they expire in the normal course.
11. Information and audits
We'll make available the information reasonably necessary to show we're meeting this DPA. If that isn't enough, you or an independent auditor you appoint may audit our compliance, no more than once a year, on at least 30 days' written notice, during business hours, at your cost and subject to reasonable confidentiality commitments — unless a regulator requires otherwise or following a personal data breach.
12. Your responsibilities
You're responsible for having a lawful basis for the processing you ask us to carry out, for giving your visitors any privacy information required by law (for example, a privacy notice on your website that covers your chatbot), and for the accuracy of the instructions and content you give us.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law doesn't allow it to be limited.
14. Contact us
Questions about this DPA, or requests for a signed copy, can be sent to hello@deskee.io.