Data Processing Addendum
Draft. This document is published for review and is not yet in force. Details in square brackets are still to be completed, and the text has not yet been reviewed by a lawyer. Questions to support@boldagents.co.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“you”, the controller) and [Legal entity name], trading as Bold Agent Kit (“we”, the processor). It applies wherever we process personal data on your behalf that is protected by the EU General Data Protection Regulation, the UK GDPR, the Swiss FADP or a similar law (“Data Protection Law”). Terms used here have the meaning Data Protection Law gives them. If you need a signed copy, email support@boldagents.co and we will countersign this text.
1. The processing
| Subject matter | Operating AI agents that send and receive messages, place and answer calls, and book appointments, on channels and accounts you connect. |
|---|---|
| Duration | The life of your account, plus the deletion period in section 9. |
| Nature and purpose | Storing your contacts and conversations; generating replies from your knowledge base through the AI provider on your key; sending and receiving through your connected accounts; recording events and outcomes; reporting. |
| Types of personal data | Names, email addresses, phone numbers, social account identifiers, browser identifiers, the content of messages and calls (including recordings and transcripts), page visits on your website, bookings, purchase and CRM data you connect, and anything else you or your contacts put into a conversation. |
| Data subjects | Your leads, customers, contacts and their representatives; your staff and clients who use the Service. |
| Special categories | None are intended. You must not configure an agent to collect them. If a data subject volunteers such data in a conversation, it is stored like any other message content. |
2. Your instructions
We process personal data only on your documented instructions, which are: the Terms, this DPA, the way you configure the Service, and any further written instruction you give us. If we believe an instruction breaks Data Protection Law we will tell you. You are responsible for the lawfulness of the processing you instruct, including the lawful basis for contacting each data subject and for any recording of calls.
3. Confidentiality
The people we allow to process personal data are bound by confidentiality obligations and are limited to those who need access to run and support the Service.
4. Security
We implement appropriate technical and organisational measures, taking into account the state of the art, the costs, and the risks, including: encryption in transit; encryption at rest of credentials and API keys; salted password hashing; access to production limited to the people who operate it; client logins scoped to one agent with everything else denied by default; logging of administrative access; backups; and a process for testing and improving these measures. Annex 1 lists them.
5. Subprocessors
You authorise us to use the subprocessors listed on the Subprocessors page. We will give you at least 30 days’ notice by email before adding or replacing one. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected part of the Service and we will refund any prepaid fees for the period after termination. We impose data protection obligations on each subprocessor equivalent to this DPA and remain responsible for their performance.
The AI model provider, mailbox provider, carrier, telephony provider, social platforms, calendar and CRM you connect are not our subprocessors: you contract with them directly, on your own accounts, and we send data to them only because you configured the Service to.
6. Data subject rights
The Service lets you access, correct, export and delete a contact’s data and honour opt-outs. If a data subject contacts us directly, we will pass the request to you promptly and will not respond on your behalf except as you instruct. We will give you reasonable assistance with requests that the Service cannot satisfy on its own.
7. Assistance
Taking into account the nature of the processing and the information available to us, we will assist you with data protection impact assessments, prior consultation with a supervisory authority, and your security obligations under Data Protection Law. We may charge a reasonable fee for assistance that goes beyond what the Service already provides.
8. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your personal data, with the information we have at the time and the rest as it becomes available: the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. We will cooperate with you in your notifications to authorities and data subjects.
9. Deletion and return
You can export your contacts and conversations from the Service at any time. When your account closes we delete all personal data we hold for you within 30 days, except what we must keep under law, which stays only for as long as that law requires and is processed for no other purpose. Backups are overwritten in the ordinary cycle.
10. Audit
On request, no more than once a year unless a breach or a supervisory authority requires otherwise, we will make available the information necessary to demonstrate compliance with this DPA: our security documentation, the results of any independent assessments we hold, and written answers to reasonable questions. If that is not sufficient, you or an auditor you appoint and we approve may audit our relevant systems, on 30 days’ notice, during business hours, under confidentiality, at your cost.
11. International transfers
We process personal data at [Hosting provider and region] and at the locations of our subprocessors. Where a transfer of personal data protected by the EU GDPR to a country without an adequacy decision is involved, the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA with you as data exporter and us as data importer, with the options set out in Annex 2. For the UK GDPR, the UK International Data Transfer Addendum to those clauses is incorporated on the same basis. For Switzerland, the clauses are adapted as the FADP requires.
12. Liability and precedence
Our liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow it. Where this DPA conflicts with the Terms, this DPA governs the processing of personal data. Where the Standard Contractual Clauses conflict with this DPA, the Clauses govern.
Annex 1: Technical and organisational measures
- Transport encryption (TLS) on every connection to the Service and to connected providers.
- Encryption at rest of API keys, passwords for connected accounts, and other credentials; salted hashing of user passwords.
- Access control: named accounts, least privilege, production access limited to operating staff, client logins scoped to a single agent and deny-by-default.
- Isolation: one agent’s knowledge base and content is never used to generate output for another.
- Logging of administrative actions and sign-ins; rate limiting of authentication.
- Regular backups of the database, with restoration tested.
- Vulnerability and dependency updates applied as part of routine deployment.
- Data subject tooling: per-contact deletion, export, opt-out enforcement across channels.
- Incident response: a documented procedure with the notification commitment in section 8.
Annex 2: Standard Contractual Clauses options
- Module Two: controller to processor.
- Clause 7 (docking): included.
- Clause 9 (subprocessors): Option 2, general written authorisation, with the notice period in section 5.
- Clause 11 (redress): the optional independent dispute resolution body is not included.
- Clause 13 and Clause 17: the supervisory authority and governing law are those of the EU member state in which you are established, or, if you are not established in the EU, Ireland.
- Clause 18: the courts of that member state.
- Annex I to the Clauses: the parties and the processing are as described in section 1 and in the Terms. Annex II: as in Annex 1 above. Annex III: the Subprocessors page.
Contact
[Legal entity name], [Registered address]. Data protection enquiries: support@boldagents.co.
Related documents. Terms of Service · Privacy Policy · Acceptable Use Policy · Subprocessors
