Data Processing Addendum
On this page
Last updated:
This Data Processing Addendum (DPA) forms part of the Terms of Service or other written service agreement between the customer and AssistLoop, LLC (“AssistLoop”). It applies when AssistLoop processes personal data on the customer’s behalf in providing the Services.
At a glance
- You control the customer data you submit and the purposes for using it.
- We process that data to deliver the service under your instructions.
- We support your privacy obligations, including rights requests and deletion.
This overview is for readability. The terms and annexes below govern processing.
1. Scope and definitions
“Agreement” means the contract governing your use of AssistLoop. “Customer Data” means personal data submitted to, collected through, or otherwise processed by the Services on your behalf. “Services” means AssistLoop’s AI support agents, chat widget, human handoff, ticketing, knowledge sources, and related features provided under the Agreement. A “Subprocessor” is a provider appointed by AssistLoop to process Customer Data.
“Applicable Law” means the data protection laws applicable to the processing, including, where relevant, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss FADP, California CCPA as amended by the CPRA, and applicable privacy laws in Canada, Brazil, and Australia. Terms such as controller, processor, personal data, and processing have the meanings assigned by the applicable law.
2. Each party’s responsibilities
You act as controller of Customer Data, or as a processor authorized by the relevant controller. AssistLoop acts as your processor or subprocessor. You determine the lawful purposes of processing and are responsible for required notices, permissions, consents, and the accuracy and lawfulness of the data and instructions you provide.
This DPA does not govern information AssistLoop processes as an independent controller for its own account administration, billing, or website operations. Those practices are described in the Privacy Policy.
3. Processing instructions and AI features
AssistLoop will process Customer Data only on your documented instructions, including your use of the Services, workspace settings, enabled integrations, and further instructions agreed in writing. Processing is limited to delivering, maintaining, securing, and supporting the Services, unless applicable law requires otherwise. We will inform you of such a legal requirement before processing unless the law prohibits notice.
Your instructions may include indexing knowledge sources, retrieving relevant content, generating AI responses, routing conversations to your team, and performing actions you configure. We will not use Customer Data to train general-purpose AI models for our own independent purposes, sell it, or use it for cross-context behavioral advertising. If an instruction infringes Applicable Law, we will inform you immediately and suspend the affected activity until it can lawfully proceed.
4. Confidentiality
We will restrict access to Customer Data to authorized people who need access for their work. Anyone authorized to process it must be subject to contractual confidentiality obligations or an equivalent legal duty. Those obligations continue after their access ends.
5. Security safeguards
AssistLoop will implement and maintain technical and organizational safeguards appropriate to the processing risks, taking account of the nature of the data, available technology, and the potential impact on individuals. Annex B describes the safeguards covered by this DPA. Changes to our safeguards will not materially reduce their overall protection.
You are responsible for securing your credentials, assigning appropriate workspace permissions, configuring integrations, and limiting submitted data to what is needed for your use of the Services.
6. Subprocessor engagement
You provide general written authorization for AssistLoop to engage Subprocessors to deliver the Services. Our providers are listed on the Subprocessors page. We will provide further details relevant to your configuration on request and give advance written notice of proposed additions or replacements, allowing at least 15 days for you to raise a reasoned data protection objection before the new provider begins processing your data.
Before processing begins, we will require written data protection obligations from each Subprocessor that provide equivalent protection for the processing assigned to it. AssistLoop remains responsible for its Subprocessors’ performance of those obligations. We will work with you to resolve an objection; if no reasonable solution is available, you may terminate the affected Services before the proposed processing begins.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a security breach involving the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. Notice will go to your designated account or security contact.
As information becomes available, we will describe the breach, affected data and individuals, likely consequences, mitigation measures, and a contact for follow-up. We may provide information in stages without delaying the initial notice. We will take appropriate containment and remediation steps and assist with your notification obligations. You remain responsible for deciding and making any notifications required of you by law.
8. Requests from individuals
Taking account of the processing, we will assist you through appropriate technical and organizational measures with requests to access, correct, restrict, export, object to processing, or delete Customer Data. Where available, you may use workspace controls; otherwise, contact us for assistance.
If an individual sends us a request concerning data we process for you, we will refer the request to you and will not independently act on it except on your instructions or where legally required.
9. Assessments and verification
We will provide information reasonably necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by you or an independent auditor you appoint. Parties will coordinate reasonable notice, confidentiality, scope, and measures to protect other customers’ information. These arrangements will not prevent an audit required by Applicable Law or a supervisory authority.
We will assist with data protection impact assessments, prior consultation with regulators, and your security obligations, taking account of the processing and information available to us.
10. Processing across borders
Customer Data may be processed in countries where AssistLoop and its authorized Subprocessors operate, subject to Applicable Law. We will use an applicable adequacy decision or another lawful transfer safeguard before making a restricted international transfer.
Where standard contractual clauses are required, the parties will complete and enter into the applicable clauses before the transfer: the European Commission’s Decision 2021/914 with the appropriate controller-to-processor or processor-to-processor module; the UK International Data Transfer Addendum or Agreement for UK transfers; and appropriate adaptations for Swiss law. The relevant party details, processing locations, competent authority, annexes, and any necessary supplementary measures must be recorded in the transfer documentation. This page alone does not complete that documentation.
We will provide reasonable assistance with transfer assessments and suspend or use a lawful alternative for affected transfers if the existing safeguard no longer provides the required protection.
11. Return, deletion, and retention
At the end of the Services, we will, at your choice, return or delete Customer Data and delete existing copies, unless applicable law requires retention. Contact us before account closure to arrange a return. Consistent with our Terms of Service, deletion will be completed within 30 days of termination, except for data whose retention is legally required.
Data retained by legal requirement will remain protected, isolated from ordinary service use, and processed only for that requirement until it can be deleted. We will confirm completion of deletion on request.
12. Deidentified information
Where we use aggregated or deidentified information to understand service performance, we will apply measures intended to prevent identification of individuals, maintain the information in that form, and not attempt to reidentify it except where legally permitted to verify the effectiveness of deidentification. Information that remains personal data continues to be subject to this DPA.
13. California service provider terms
Where the CCPA applies, AssistLoop acts as a service provider or contractor for the business purposes specified in this DPA. We will not sell or share Customer Data, retain, use, or disclose it outside those purposes or our direct business relationship, or combine it with personal information from other sources except as the CCPA permits.
We will provide the protection required by the CCPA, inform you if we can no longer meet these obligations, and permit reasonable steps to verify compliance and stop and remediate unauthorized use. AssistLoop understands and will comply with these restrictions.
14. Legally required disclosures
If we receive a binding demand for Customer Data, we will review its legal validity, disclose only what is legally required, and notify you unless prohibited by law. Where appropriate, we will seek permission to notify you and challenge unlawful or disproportionate demands using available legal remedies.
15. Duration, priority, and liability
This DPA takes effect with the Agreement and remains in force while AssistLoop processes Customer Data on your behalf. For conflicts about data protection, mandatory transfer clauses take precedence, followed by this DPA and then the Agreement. A separately signed data processing agreement takes precedence over this DPA to the extent expressly provided in that agreement.
The Agreement’s liability provisions apply to this DPA only to the extent permitted by Applicable Law and any applicable transfer clauses. Nothing limits an individual’s statutory rights or a party’s liability that cannot lawfully be limited. Material changes to these terms will be communicated before taking effect.
16. Governing terms and contact
The Agreement’s governing law and dispute provisions apply except where mandatory data protection law or applicable transfer clauses require otherwise. For this DPA, privacy requests, or transfer documentation, email [email protected].
Annex A — Processing details
- Subject and purpose: providing customer support automation and human support workflows under the Agreement and your configuration.
- Activities: receiving, storing, organizing, indexing, retrieving, transmitting to authorized providers, generating responses from, and deleting Customer Data.
- Individuals: your website visitors, customers, leads, support contacts, and authorized team members whose data you submit.
- Data categories: names, contact details, visitor identifiers, conversation and ticket content, knowledge-source content, submitted attachments, and associated technical information such as timestamps and device or browser details. The actual categories depend on your configuration and submissions.
- Sensitive data: do not submit special-category data, payment card details, government identifiers, or similarly sensitive information unless expressly agreed in writing with appropriate safeguards.
- Frequency and duration: ongoing processing during service use and the return or deletion period in section 11.
- Customer instructions: the Agreement, workspace settings, enabled features, and additional lawful written instructions agreed by the parties.
Annex B — Technical and organizational measures
- Data protection: encryption in transit and at rest, including protection of stored integration credentials and supported bring-your-own-provider API keys.
- Access management: role-based workspace permissions, scoped and expiring API keys, and access limited to authorized personnel.
- Visitor identity: optional or required verified visitor identity, with rotatable secrets, for configured authenticated support workflows.
- Data control: controls for deleting conversations and leads, supplemented by assistance with data requests.
- Operational safeguards: risk-appropriate measures for availability, recovery, incident handling, and regular evaluation of security effectiveness.
- Organizational safeguards: confidentiality requirements, provider data protection agreements, and procedures for handling customer instructions and rights requests.
Annex C — Regional requirements
EEA, United Kingdom, and Switzerland. The parties will meet the obligations applicable to their respective roles, including processor-contract requirements and lawful transfers under section 10. Mandatory local protections and supervisory authority powers remain unaffected.
Canada. Where Canadian federal or provincial privacy law applies, the parties will cooperate to provide the required protection for transferred information. You are responsible for applicable notices and assessments, including assessments required for transfers under Quebec law; we will provide reasonable information to assist.
Brazil. Where the LGPD applies, processing will follow your lawful instructions and applicable individual rights requirements. Transfers requiring an approved mechanism will use a valid mechanism, including completed ANPD standard contractual clauses where applicable, before transfer.
Australia. Where the Privacy Act 1988 and Australian Privacy Principles apply, the parties will comply with the obligations applicable to them, including cross-border disclosure requirements and assistance with applicable breach notifications.