This Data Processing Agreement ("DPA") forms part of the HelpJet Terms of Service between you (the "Customer") and Heroic Media Ltd, trading as HelpJet, a company registered in England and Wales with company number 08589870, whose registered office is at The Glades, Festival Way, Stoke-on-Trent, ST1 5SQ ("HelpJet", "we", "us").
You accept this DPA when you accept the Terms of Service. You do not need to sign it.
1. Definitions
1.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018 and, where it applies to your processing, the EU GDPR.
1.2 Customer Personal Data means personal data in Customer Data, and personal data of End Users that HelpJet processes through your bots, as described in Annex 1.
1.3 End Users means the people who use your bots, for example visitors to your website who chat with your bot.
1.4 Sub-processor means a third party that we engage to process Customer Personal Data.
1.5 Personal Data Breach means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
1.6 Other terms, such as controller, processor, personal data and processing, have the meanings given in Data Protection Law. Capitalised terms not defined here have the meanings given in the Terms of Service.
2. Scope and priority
2.1 This DPA applies when we process Customer Personal Data to provide HelpJet to you.
2.2 If this DPA and the Terms of Service conflict on the protection of personal data, this DPA applies.
2.3 This DPA does not apply to personal data that we process as a controller, such as account, billing and marketing data about you and your team. Our Privacy Policy describes that processing.
3. Roles of the parties
3.1 You are the controller of Customer Personal Data and we are your processor.
3.2 You are responsible for:
- having a lawful basis for the processing you ask us to do;
- giving End Users any information that Data Protection Law requires, for example in your privacy notice;
- not using HelpJet to process special category data, criminal offence data or children's data, unless we have agreed this with you in writing; and
- making sure your instructions to us comply with Data Protection Law.
4. Your instructions
4.1 We will process Customer Personal Data only on your documented instructions, unless the law requires us to do something else. If the law requires this, we will tell you before we process the data, unless the law does not allow us to tell you.
4.2 Your documented instructions are: the Terms of Service; this DPA; the settings and features you use in HelpJet; and any other written instructions that we both agree.
4.3 We will tell you promptly if we think an instruction from you breaks Data Protection Law.
5. AI models and use of your data
5.1 HelpJet uses third-party AI models to create answers, summaries and search embeddings. The providers of these models are Sub-processors and are listed on our sub-processors page.
5.2 We may create anonymised or aggregated information from your use of HelpJet, for example message counts or answer rates. This information does not identify you, your End Users or any other person. We may use it to operate, secure and improve HelpJet. Once data is anonymised, it is no longer Customer Personal Data.
6. Confidentiality
6.1 We will make sure that everyone we authorise to process Customer Personal Data has agreed to keep it confidential or is under a legal duty of confidentiality.
7. Security
7.1 We will put in place and maintain appropriate technical and organisational measures to protect Customer Personal Data, as Article 32 of the UK GDPR requires. Annex 2 describes these measures.
8. Sub-processors
8.1 You give us general written authorisation to engage Sub-processors. Our current Sub-processors are listed at helpjet.com/legal/subprocessors.
8.2 Before a Sub-processor processes Customer Personal Data, we will make a written contract with it. The contract will contain data protection obligations that give at least the same protection as this DPA.
8.3 We will update our sub-processors page before we add or replace a Sub-processor, and email anyone who has asked to receive these notices at privacy@helpjet.com. You can object by email to privacy@helpjet.com. If we cannot address your objection, you can end your subscription before the change takes effect.
8.4 We remain responsible to you for the acts and omissions of our Sub-processors.
9. Transfers outside the UK
9.1 Some Sub-processors process Customer Personal Data outside the UK, mainly in the United States. Our sub-processors page lists where.
9.2 For each such transfer we use a transfer mechanism that Data Protection Law allows: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework), or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
10. Requests from End Users
10.1 If an End User contacts us to exercise their rights (for example, to access or delete their data), we will send the request to you and will not answer it ourselves, unless you tell us to.
10.2 We will help you to respond to these requests. You can view conversations in your HelpJet dashboard. If you need us to export or delete specific conversations, we will do so as described in section 13.
11. Other help we give you
11.1 Taking into account the nature of the processing and the information available to us, we will give you reasonable help with: security of processing; Personal Data Breach notifications; data protection impact assessments; and prior consultation with the Information Commissioner's Office or another supervisory authority.
12. Personal Data Breaches
12.1 We will tell you without undue delay after we become aware of a Personal Data Breach.
12.2 We will give you the information you reasonably need to meet your own obligations, as far as it is available. This includes the nature of the breach, the types and approximate number of people and records affected, the likely consequences, and what we have done or plan to do. We will send further information as we find it.
13. Retention and deletion
13.1 We keep Customer Personal Data for as long as you keep it in your HelpJet account. You decide how long to keep it.
13.2 You can ask us in writing to delete conversations, for example all conversations older than a set number of months, or all conversations for one bot. Send the request to privacy@helpjet.com from the email address of an account owner or administrator. We will delete the data without undue delay and confirm to you when we have done so.
13.3 When your account is closed, we will delete Customer Personal Data, or return it to you if you ask us to before the account is closed, unless the law requires us to keep it. Copies in backups are deleted when the backups expire.
14. Information and audits
14.1 On request, we will give you the information you reasonably need to show that we comply with this DPA and Article 28 of the UK GDPR.
14.2 If that information is not enough to show compliance, you, or an independent auditor that you appoint and that has agreed to keep our information confidential, can audit our compliance with this DPA. You must give us at least 30 days' written notice. Audits are limited to once in any 12-month period, unless a supervisory authority requires an audit or there has been a Personal Data Breach. You pay your own costs of the audit.
15. Liability
15.1 Each party's liability under this DPA is subject to the limits and exclusions of liability in the Terms of Service.
16. Term and law
16.1 This DPA stays in force for as long as we process Customer Personal Data for you, including after your account is closed.
16.2 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: Details of the processing
Item | Details |
|---|---|
Subject matter | Providing HelpJet: AI chatbots that answer End User questions from the knowledge base content the Customer provides |
Duration | While we provide HelpJet to the Customer, plus the time needed to delete or return Customer Personal Data under section 13. |
Nature and purpose | Storing and searching training content; receiving End User messages; creating answers with AI models; storing conversations so the Customer can view and analyse them; summaries and reporting; support and security |
Categories of data subjects | End Users of the Customer's bots (for example, visitors to the Customer's website). People named in the training content the Customer provides. |
Types of personal data: End Users | The content of messages, including any personal data an End User types. A random session ID kept in the End User's browser. IP address. Approximate location (country, city, time zone) derived from the IP address. Browser, operating system, device type, screen size and language. The page and referring URL, and campaign (UTM) tags. Answer ratings. Conversation summaries |
Types of personal data: training content | Any personal data in the web pages, files, text and help desk conversations the Customer chooses to add |
Special category data | None intended. Section 3.2 applies |
Retention | As in section 13 |
Annex 2: Security measures
We use technical and organisational measures that are appropriate to the risk, as Article 32 of the UK GDPR requires. These include encryption of data in transit and at rest, access controls for customers and staff, and confidentiality duties for everyone who can access Customer Personal Data. We will give you more detail on request.