Data processing agreement
How we process your customers' data on your behalf (Article 28).
Draft — to be reviewed by a qualified UK solicitor before taking paying customers. Bracketed items still need completing.
Last updated 8 October 2026
Scope
This agreement forms part of our Terms of service. When we process personal data on behalf of a customer (the controller), [Legal entity name to be confirmed] acts as processor, as required by Article 28 UK GDPR.
Details of processing
- Subject matter: hosting the customer's website and providing the AI assistant, booking, confirmation texts and (optionally) AI telephone receptionist.
- Duration: for the term of the subscription, then deletion or return of data within 30 days unless law requires us to keep it.
- Data subjects: the customer's website visitors, enquirers, callers and customers.
- Types of data: names, contact details, postcodes, booking details, messages, chat transcripts, call recordings and transcripts.
- No special category data is intended; customers must not use the service to collect it.
Our obligations as processor
- Process personal data only on the customer's documented instructions (these terms and the configuration of their service).
- Ensure everyone with access is bound by confidentiality.
- Apply appropriate technical and organisational security measures (see our Privacy notice and security practices).
- Engage sub-processors only under written terms giving equivalent protection; the current list is on our Sub-processors page, and we'll give 30 days' notice of changes so the customer can object.
- Help the customer respond to data-subject requests and meet their security, breach-notification and impact-assessment obligations.
- Notify the customer without undue delay (and within 48 hours) after becoming aware of a personal data breach affecting their data.
- Delete or return personal data at the end of the service.
- Make available information needed to demonstrate compliance, and allow reasonable audits on 30 days' notice.
International transfers
Where a sub-processor processes data outside the UK, transfers are protected by an adequacy decision, the UK–US Data Bridge, or the UK International Data Transfer Addendum.
Signed copies
Customers who need a countersigned copy can request one from privacy@digifront.example.