Data Processing Agreement
Last updated: 9 September 2026
Parties and scope
This DPA forms part of the Terms between the Business as controller (and, where applicable, processor for another controller) and [Operator legal name required] as processor. It covers customer names, phone numbers, job information, private feedback, prepared messages, permission attestations, and review-link activity processed to provide DoneAsk for the account term plus the deletion period.
Instructions
DoneAsk will process customer data only to provide, secure, support, and delete the service under the Business’s documented instructions, unless law requires otherwise. The Business instructs DoneAsk through product use and settings. DoneAsk will inform the Business if an instruction appears unlawful where legally permitted.
Business obligations
The Business determines purposes, lawful basis, notices, data accuracy, customer eligibility, and WhatsApp permission; handles requests as controller; avoids unnecessary or sensitive data; and uses review requests without gating or manipulation.
Confidentiality and security
People authorized to process customer data are bound to confidentiality. DoneAsk maintains measures appropriate to risk, including access control, password hashing, HTTPS, credential restriction, tenant separation, log redaction, recovery procedures, and periodic review. The Business must secure its own account and devices.
Subprocessors and transfers
Current categories are hosting/database infrastructure and the configured AI provider. A launch-ready subprocessor list with legal names, locations, purpose, transfer mechanism, and change-notice method must be published before real use. The Business gives general authorization for listed subprocessors and may object on reasonable data-protection grounds. DoneAsk remains responsible for processor obligations it delegates.
Requests, incidents and audits
DoneAsk will reasonably assist with data-subject requests, security obligations, impact assessments, regulator consultations, and breach notices, considering the nature of processing and information available. DoneAsk will notify the Business without undue delay after becoming aware of a personal-data breach affecting its customer data. On reasonable request, DoneAsk will provide compliance information and permit proportionate audits subject to confidentiality and security limits.
Return and deletion
On instruction or account deletion, DoneAsk deletes or returns customer data unless law requires retention. A minimal suppression record may be retained on instruction to prevent renewed contact. Backup deletion timing must be documented before launch.
Restricted transfers
If EEA or UK transfer rules apply and no adequacy basis covers a transfer, the applicable EU Standard Contractual Clauses or UK transfer addendum/agreement is incorporated as required. The parties will complete transfer details and safeguards before such processing begins.
Priority
This DPA controls over conflicting Terms for processing customer personal data. Contact: [Privacy email required].