Data Processing Agreement

1. Definitions

"Controller" means the entity which determines the purposes and means of the processing of Personal Data (you, the Customer).
"Processor" means the entity which processes Personal Data on behalf of the Controller (BotDesk).
"Sub-processor" means any third party engaged by BotDesk to assist in fulfilling its obligations with respect to providing the Services.

2. Processing of Personal Data

BotDesk will process Personal Data only to the extent necessary to provide the Services in accordance with the Agreement and your instructions.

Nature of Processing: Storage, retrieval, use for AI response generation, and deletion.
Categories of Data Subjects: Your end-users, employees, and anyone engaging with your chatbot.
Types of Personal Data: Name, contact details, message content, and metadata.

3. Confidentiality & Security

We ensure that all personnel accessing Personal Data are bound by confidentiality agreements. We implement industry-standard technical measures, including:

  • Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Access Control: Strict role-based access control (RBAC) and MFA for our internal staff.
  • Physical Security: We use top-tier cloud providers (AWS/Vercel) with strictly controlled data centers.

4. Sub-processors

You authorize us to engage sub-processors to store and process data. We maintain a list of current sub-processors, which includes:

  • OpenAI / Anthropic: For LLM inference (Enterprise agreements with zero-retention policies where applicable).
  • Vercel / AWS: For hosting and database infrastructure.
  • Stripe: For payment processing.

We remain fully liable for the acts and omissions of our sub-processors.

5. Data Subject Rights

To the extent you cannot access the data yourself via the dashboard, we will provide reasonable assistance to help you respond to requests from individuals exercising their rights.

6. Personal Data Breach

In the event of a Personal Data Breach, we will notify you without undue delay (within 72 hours of becoming aware) and provide sufficient information.

7. Contact & Signatures

This DPA is incorporated into our Terms of Service. If you require a countersigned version for your records, please email us.

DPA Contact: dpa@botdesk.co

Free 7-Day Trial · No Credit Card Required

Stop Drowning In Tickets. Start Resolving Them Instantly.

Join 200+ companies using BotDesk to automate 80% of customer questions while keeping a human touch.

Data Encryption
Secure
Human Support Included
Setup in < 10 min
Cancel Anytime