Data Processing Addendum
Last updated 11 August 2026
This DPA forms part of the Terms of Service and applies whenever DigitAIse processes personal data of third parties (your customers, suppliers, contacts) on your behalf. It is an early-access draft — please have it reviewed by a solicitor before relying on it. Capitalised terms not defined here have the meaning given in the Terms.
1. Roles
For End-Customer Data, you are the Controller and DigitAIse is the Processor. The sub-processors listed below act as our sub-processors. Each party will comply with UK GDPR and the Data Protection Act 2018.
2. Subject-matter & details of processing
| Subject matter | Providing the DigitAIse Service to you. |
| Duration | For the term of your subscription plus any deletion period. |
| Nature & purpose | Ingesting, extracting, storing, analysing and acting on data you connect, so agents can draft communications, schedule, respond to reviews/mentions, and surface insights. |
| Categories of data | Contact details (names, emails, phone numbers), transactional/financial data from documents, correspondence content, and any other personal data you choose to submit. |
| Data subjects | Your customers, suppliers, employees and contacts. |
3. Our obligations as Processor
- Process End-Customer Data only on your documented instructions (including via your use of the Service), unless required by law.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 5).
- Assist you, taking into account the nature of processing, with data subject requests, security, breach notification and DPIAs.
- On termination, delete or return End-Customer Data on your instruction (Section 7).
- Make available information reasonably necessary to demonstrate compliance, and allow for audits as described in Section 8.
4. Your obligations as Controller
- Ensure you have a lawful basis and any required notices/consents to submit End-Customer Data and to instruct the processing.
- Your use of the Service is your instruction for processing.
5. Security measures
- Per-tenant database schema isolation; sensitive fields encrypted with a per-tenant key; encryption in transit (TLS).
- Access controls, two-factor authentication for sensitive actions, and audit logging.
- Uploaded-file safety checks; least-privilege service architecture; UK-based hosting.
- Human-in-the-loop approval before agents take outward-facing actions.
6. Sub-processors
You authorise us to engage the sub-processors below. We will give notice before adding or replacing a sub-processor so you can object on reasonable data-protection grounds. We remain responsible for their performance.
| Sub-processor | Purpose |
|---|---|
| OVHcloud (UK) | Hosting infrastructure |
| Anthropic | AI model processing |
| Stripe | Payments |
| Brevo | Email delivery |
| Twilio | Voice telephony |
| Meta | WhatsApp messaging (when enabled) |
| Cloudflare | Edge network |
7. Return & deletion
On termination, or on your written request, we will delete or return End-Customer Data within 30 days, save where retention is required by law. Deletion permanently removes your tenant's data and files.
8. Audit
On reasonable notice and no more than once a year (unless required by a regulator), we will provide information reasonably necessary to demonstrate compliance with this DPA.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting End-Customer Data, and provide the information you reasonably need to meet your own notification obligations.
10. International transfers
Primary processing and hosting are in the UK. Where a sub-processor processes data outside the UK, an appropriate transfer mechanism (UK adequacy regulations or the International Data Transfer Agreement / standard contractual clauses) will apply.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.