Skip to content

Data Processing Agreement

Version 2.3 · Updated 1st September 2026 · Effective 1st October 2026

Governing every Principal Agreement — Beta Access Agreements of every version, and the Terms and Conditions

How this document works. This Data Processing Agreement (“DPA”) is incorporated by reference into the Principal Agreement — the Beta Access Agreement for Beta customers, regardless of version, and otherwise Breezee AI’s Terms and Conditions. It does not need to be accepted separately: by accepting the Principal Agreement, the Customer agrees to be bound by these standard DPA terms. This document is published and maintained by Breezee AI Limited and applies uniformly to all Customers. References to the “Controller” mean the Customer under the Principal Agreement. References to the “Processor” mean Breezee AI Limited (Company No. SC857320). References to the “Principal Agreement” are as defined in Clause 1. Capitalised terms used but not defined in this DPA have the meanings in the Principal Agreement.

This DPA incorporates the requirements of the UK General Data Protection Regulation and the Data Protection Act 2018.

1. Definitions

In this DPA, the following terms have the meanings set out below. Terms defined in the UK GDPR have the meanings given there.

“Anonymised Platform Data” means conversation data, interaction patterns, and aggregated usage statistics derived from the Controller’s use of the Platform that have been irreversibly anonymised such that they cannot reasonably be used to identify the Controller, its personnel, or any Data Subject.

“Data Protection Law” means all applicable UK data protection and privacy legislation, including the UK General Data Protection Regulation (“UK GDPR”) as defined in section 3(10) of the Data Protection Act 2018, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any binding guidance or decisions of the Information Commissioner’s Office (“ICO”), each as amended from time to time.

“Data Subject” means an identified or identifiable natural person whose Personal Data is processed by the Processor under this DPA, including the Controller’s employees and website visitors or prospects who interact with the sAIlsbot agent.

“IDTA” means the International Data Transfer Agreement issued by the ICO under section 119A of the Data Protection Act 2018, as updated from time to time.

“Personal Data” means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Principal Agreement.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by the Processor.

“Principal Agreement” means the agreement between the parties under which the Processor provides the Platform to the Controller, and into which this DPA is incorporated: the Beta Access Agreement for Controllers participating in the Beta Programme, and otherwise Breezee AI’s Terms and Conditions at https://www.breezee.ai/terms-and-conditions. Where a Controller joined the Beta Programme by signing a Beta Confirmation Letter before that document was discontinued, the Principal Agreement includes that letter.

“Restricted Transfer” means a transfer of Personal Data from the United Kingdom to a country or territory not subject to a UK adequacy decision under Data Protection Law.

“Sub-processor” means any third-party processor engaged by the Processor to carry out processing of Personal Data on behalf of the Controller.

“Technical and Organisational Measures” means (or “TOMs”) the security measures implemented by the Processor to protect Personal Data, as described in Annex C.

“UK Addendum” means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the ICO pursuant to s.119A of the Data Protection Act 2018 (version B.1.0), as updated from time to time.

2. Scope and Relationship of the Parties

2.1 Processor Role

The Processor processes Personal Data only on behalf of, and in accordance with the documented instructions of, the Controller, as a data processor within the meaning of Article 4(8) UK GDPR. The Controller determines the purposes and means of processing. The Processor processes Personal Data solely to provide the services described in the Principal Agreement.

2.2 Processing Details

The subject matter, nature, purpose, and duration of processing, together with the types of Personal Data and categories of Data Subjects, are set out in Annex A.

2.3 Controller Obligations

The Controller warrants that:

(a) it has a valid legal basis under Data Protection Law for each category of Personal Data provided to the Processor;

(b) Personal Data has been collected and shared in compliance with Data Protection Law;

(c) it will provide Data Subjects with all required privacy information regarding the processing carried out under this DPA; and

(d) it has a lawful basis under Data Protection Law for any Personal Data contained in web pages it nominates or documents it uploads for knowledge base ingestion, and it will not provide such content containing, or configure the Platform to solicit, special category Personal Data (Article 9 UK GDPR) without the Processor’s prior written agreement.

2.4 Instructions

The Processor shall process Personal Data only in accordance with the Controller’s documented instructions, as set out in this DPA and the Principal Agreement. If the Processor is required by applicable law to process Personal Data otherwise, it shall notify the Controller before doing so, to the extent permitted by law.

2.5 Unlawful Instructions

If the Processor considers that any instruction of the Controller infringes Data Protection Law, it shall promptly inform the Controller and shall not be obliged to follow any instruction it reasonably considers unlawful.

3. Processor Obligations

3.1 Confidentiality

The Processor shall ensure that personnel with access to Personal Data are subject to binding confidentiality obligations, and that such access is limited to those who need it to perform their duties.

3.2 Technical and Organisational Measures

The Processor shall implement and maintain the TOMs described in Annex C. The Processor may update these measures from time to time, provided that such updates do not materially reduce the overall level of protection afforded to Personal Data.

3.3 Assistance with Data Subject Rights

The Processor shall, taking into account the nature of the processing and information available to it, provide the Controller with reasonable assistance to enable the Controller to fulfil its obligations in respect of: (a) Data Subject rights under Chapter III UK GDPR (including access, rectification, erasure, restriction, portability, and objection); (b) data protection impact assessments and prior consultations; and (c) security, breach notification, and confidentiality obligations.

3.4 Response Times

The Processor shall respond to reasonable requests for assistance within a timeframe that enables the Controller to meet its own legal deadlines. Where the Controller receives a Data Subject request relating to Personal Data processed by the Processor, the Processor shall respond with the relevant information within five (5) business days.

3.5 Deletion or Return of Data

On termination or expiry of the Principal Agreement, the Processor shall, at the Controller’s written election: (a) securely delete or destroy all Personal Data processed on the Controller’s behalf within thirty (30) days; or (b) return a copy of such Personal Data in a commonly used, machine-readable format within ten (10) business days of a written request; or (c) migrate all Personal Data to the Controller’s General Availability account, where the Controller continues on a paid subscription. For the avoidance of doubt, Anonymised Platform Data is not Personal Data and is not subject to deletion or return obligations under this Clause.

3.6 Records of Processing

The Processor shall maintain records of all categories of processing activities carried out on behalf of the Controller as required by Article 30(2) UK GDPR, and shall make such records available to the ICO on request.

3.7 No Sale of Personal Data

The Processor shall not sell, rent, or otherwise make Personal Data available to any third party for that third party’s own marketing, commercial, or other independent purposes.

4. Sub-processing

4.1 General Authorisation

By accepting the Principal Agreement, the Controller grants the Processor general authorisation to engage the Sub-processors listed in Annex B. The Controller’s acceptance of the Principal Agreement constitutes its prior written consent to those Sub-processors, subject to the conditions in this Clause 4.

4.2 Conditions for Sub-processing

When engaging any Sub-processor, the Processor shall: (a) carry out appropriate due diligence on the Sub-processor’s data protection practices before engagement; (b) ensure a written agreement is in place imposing data protection obligations at least equivalent to those in this DPA; and (c) remain fully liable to the Controller for the acts and omissions of each Sub-processor as if they were its own.

4.3 New Sub-processors

Before engaging a new Sub-processor, the Processor shall give the Controller no less than fourteen (14) days’ written notice, including the Sub-processor’s name, country, and the nature of the processing. The Processor will maintain an up-to-date sub-processor list at https://www.breezee.ai/sub-processors and notify Controllers of changes by email. If the Controller objects on reasonable data protection grounds within fourteen (14) days, the Parties shall discuss in good faith. If no agreement is reached within a further fourteen (14) days, the Controller may terminate the Principal Agreement on written notice, and the Processor shall refund any fees paid in advance for the period after termination.

5. Personal Data Breaches

5.1 Notification Timing

In the event of a Personal Data Breach affecting Personal Data processed on behalf of the Controller, the Processor shall notify the Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach, to enable the Controller to meet its own notification obligations to the ICO and affected Data Subjects where required.

5.2 Notification Content

The Processor’s breach notification shall, to the extent known at the time, include: (a) a description of the breach, including categories and approximate number of Data Subjects and records affected; (b) the name and contact details of the Processor’s data protection contact; (c) likely consequences; (d) measures taken or proposed to address the breach; and (e) such other information as the Controller reasonably requires. Information not available at the time of initial notification will be provided as soon as it becomes available.

5.3 Breach Response

Following notification, the Processor shall promptly investigate, contain, and remediate the breach, and shall co-operate fully with the Controller in its own investigation and any regulatory inquiry.

5.4 No Admission

A breach notification under this Clause 5 does not constitute an admission of liability or fault by the Processor.

6. International Data Transfers

6.1 General Restriction

The Processor shall not carry out or permit any Restricted Transfer of Personal Data except as authorised under this Clause 6 and in compliance with Data Protection Law.

6.2 Authorised Transfers

Some Sub-processors listed in Annex B are established in countries not subject to a UK adequacy decision (at the date of this version, the United States). The Processor shall ensure that any Restricted Transfer to a Sub-processor is governed by one of the following safeguards:

IDTA: the transfer is governed by the International Data Transfer Agreement issued by the ICO; or

UK Addendum: the transfer is governed by the EU Standard Contractual Clauses (Controller-to-Processor or Processor-to-Processor modules as applicable) together with the UK Addendum (version B.1.0).

6.3 Transfer Impact Assessments

The Processor shall carry out, and make available to the Controller on request, a transfer impact assessment in respect of each Restricted Transfer, assessing whether the law and practice of the destination country impairs the applicable transfer mechanism. Where a material risk is identified, the Processor shall apply appropriate supplementary measures.

6.4 EEA Transfers

Transfers to countries subject to a UK adequacy decision (including EEA member states) are not Restricted Transfers and do not require the safeguards in Clause 6.2.

7. Audit Rights

7.1 Information Requests

The Processor shall make available to the Controller, on reasonable written request, information reasonably necessary to demonstrate compliance with its obligations under this DPA. The Processor shall respond within fifteen (15) business days.

7.2 Audit Procedure

Where information provided under Clause 7.1 is insufficient, the Controller may request a formal audit. The following procedure applies:

Step 1 — Questionnaire: the Controller submits a written data protection compliance questionnaire; the Processor responds fully within fifteen (15) business days;

Step 2 — Third-party audit report: if concerns remain, the Processor shall share a summary of a relevant independent audit report (e.g. ISO 27001 certification or SOC 2 report) where one exists; and

Step 3 — Physical audit: if concerns are unresolved after Steps 1 and 2, the Controller (or an approved independent auditor) may carry out a physical audit on no less than thirty (30) business days’ prior written notice, during normal business hours, in a manner that does not unreasonably disrupt the Processor’s operations.

7.3 Conditions

Physical audits: (a) shall occur no more than once per year (unless a Personal Data Breach has occurred); (b) are at the Controller’s cost; (c) are subject to the Processor’s third-party confidentiality obligations; and (d) shall not extend to information relating to other clients or commercially sensitive information not relevant to the Controller’s processing.

7.4 Regulatory Access

Nothing in this Clause 7 limits any right of the ICO or other supervisory authority to access the Processor’s premises, records, or personnel in the exercise of its regulatory functions.

8. Anonymised Platform Data and AI Training

8.1 Not Personal Data

Anonymised Platform Data does not constitute Personal Data for the purposes of UK GDPR or this DPA. Accordingly, the obligations and restrictions applicable to Personal Data under this DPA do not apply to Anonymised Platform Data.

8.2 Permitted Uses

The Controller instructs the Processor to produce Anonymised Platform Data from Personal Data in accordance with Clause 8.3, that instruction forming part of the Controller’s documented instructions under Clause 2.4, and authorises (in the Principal Agreement and in this Clause) the Processor’s use of the resulting Anonymised Platform Data for:

(a) training, fine-tuning, and improving the Processor’s AI models, algorithms, and the Platform’s sales intelligence capabilities;

(b) developing new products and features;

(c) generating aggregated statistical analysis and benchmarks; and

(d) internal research and product development.

8.3 Anonymisation Standard

Before producing any Anonymised Platform Data, the Processor shall document an anonymisation methodology designed to meet the standard set out in the ICO’s anonymisation guidance, such that the risk of re-identification is sufficiently remote that the data cannot reasonably be used to identify any individual, and shall maintain that documentation and make it available to the Controller on request. At the date of this version the Processor does not produce Anonymised Platform Data.

8.4 Separation

The Processor shall maintain clear technical and procedural separation between processes that handle Personal Data (subject to this DPA) and processes that handle Anonymised Platform Data. The Processor shall not anonymise data in a manner that circumvents the Controller’s rights under this DPA.

9. Duration

9.1 Term

This DPA applies for so long as the Processor processes Personal Data on behalf of the Controller under the Principal Agreement, and terminates automatically on termination or expiry of the Principal Agreement.

9.2 Survival

Clauses 1, 3.5, 5 (in respect of breaches occurring during the term), 8, and 10 survive termination of this DPA.

10. General

10.1 Governing Law

This DPA is governed by and construed in accordance with the law of Scotland. The parties submit to the exclusive jurisdiction of the Scottish courts.

10.2 Priority

In the event of any conflict between this DPA and the Principal Agreement on matters of data protection, this DPA shall prevail. In all other respects, the Principal Agreement prevails.

10.3 Updates

Breezee AI may update this DPA from time to time to reflect changes in Data Protection Law, ICO guidance, or binding regulatory decisions. Where an update materially affects the Controller’s rights or the Processor’s obligations, Breezee AI will give no less than thirty (30) days’ written notice to Controllers before the update takes effect. The current version of this DPA is always available at https://www.breezee.ai/data-processing-agreement. Continued use of the Platform after the effective date of an update constitutes acceptance of the updated DPA.

10.4 Version Control

The version number of this DPA, and the date on which it was last modified, are shown at the head of this page; every previous version is published and linked at its foot. Breezee AI maintains that version history at https://www.breezee.ai/data-processing-agreement.

10.5 Liability

The liability of the parties under this DPA is subject to the limitations and exclusions in the Principal Agreement, save to the extent prohibited by applicable Data Protection Law.

Annex A — Details of Processing

This Annex describes the processing carried out by Breezee AI Limited as Processor on behalf of each Controller under the Principal Agreement.

Subject matter

The provision of the Breezee AI platform and its sAIlsbot sales agent, including knowledge base ingestion, AI-driven sales conversations across digital channels (including web and, as the platform develops, messaging platforms such as WhatsApp), lead qualification, prospect management, analytics, and related services.

Duration

For the term of the Principal Agreement, and thereafter only for so long as Clause 3.5 requires.

Nature of processing

Collection, storage, retrieval, analysis, use, disclosure, transmission, and deletion of Personal Data. Automated processing using large language models and machine learning to generate AI-driven sales agent conversations and lead qualification outcomes.

Purpose of processing

(a) Operating the sAIlsbot AI agent on and across the Controller’s digital channels to conduct AI-driven sales conversations with visitors and prospects; (b) capturing prospect contact information and qualifying leads; (c) maintaining prospect records, conversation histories, and session analytics; (d) generating reports and insights for the Controller; and (e) enabling the Controller to configure and manage its AI sales agent via the dashboard.

Categories of Personal Data

(a) Prospect and visitor data: name, email address, company name, job title, telephone number, and any other personal information voluntarily shared during an agent conversation; (b) conversation content: chat transcripts and session records; (c) behavioural data: session metadata, engagement signals, and lead scoring data. Account data of the Controller’s authorised users — names, email addresses, login credentials and activity within the dashboard — is processed by Breezee AI as an independent controller, to provide, secure, support and bill for the Platform, and is governed by Breezee AI’s Privacy Policy rather than this DPA.

Special categories of Personal Data

None anticipated. The sAIlsbot is designed for B2B sales conversations. Controllers must not configure the Platform to solicit or process special category personal data (Article 9 UK GDPR) without prior written agreement with Breezee AI.

Categories of Data Subjects

Prospects and visitors who interact with the sAIlsbot agent.

Controller’s legal basis

To be identified and documented by each Controller. Likely bases include: Legitimate Interests (Article 6(1)(f) UK GDPR) for prospect profiling and lead scoring; Contract (Article 6(1)(b)) for processing relating to existing customers; Consent (Article 6(1)(a)) where collected via the agent. Each Controller is solely responsible for identifying and maintaining the appropriate legal basis.

Annex B — Approved Sub-Processors

The approved Sub-processors are those listed at https://www.breezee.ai/sub-processors, which forms part of this Annex. That page names each Sub-processor, the country in which it is established, the purpose for which it processes Personal Data, and the transfer safeguard that applies to it.

The list is maintained there rather than reproduced here so that there is one authoritative record and no possibility of the two disagreeing. It is updated only in accordance with Clause 4.3: the Processor gives the Controller no less than fourteen (14) days' written notice before engaging a new Sub-processor, and the Controller may object within that period on reasonable data protection grounds.

A copy of the list as at any given date is available on request from privacy@breezee.ai.

Customer-connected integrations are not Sub-processors. Where the Controller connects an account it holds with a third-party service — a CRM or a scheduling tool, for example — the Processor transmits Personal Data to that service on the Controller’s instruction. That service is engaged by the Controller under the Controller’s own agreement with it, is the Controller’s processor rather than the Processor’s Sub-processor, and is not covered by Clause 4.2(c). The sub-processor page lists these integrations separately so that the distinction is visible.

Annex C — Technical and Organisational Measures

This Annex describes the Technical and Organisational Measures implemented by Breezee AI Limited to protect Personal Data processed in connection with the Platform. These measures are reviewed and strengthened as the Platform develops.

Access Control and Authentication. Access to Personal Data is restricted on the principle of least privilege. The Platform enforces data isolation at the database level using Row-Level Security (RLS) via Supabase, ensuring each organisation’s data is segregated from other tenants. Dashboard access requires authenticated login. API routes implement independent authentication checks. Credentials are not stored in plaintext.

Encryption. Data in transit is encrypted using TLS 1.2 or higher across all connections. Data at rest is encrypted by Supabase’s underlying infrastructure. OAuth integration tokens are stored using AES-256-GCM encryption. Widget authentication uses short-lived HMAC tokens (5-minute TTL) to reduce session hijacking risk.

Data Minimisation and Pseudonymisation. The Platform is designed to collect only the Personal Data necessary for delivery of the sAIlsbot services. Website visitors are assigned a pseudonymous prospect identifier generated client-side before any contact information is captured. AI observability traces have PII masking (email address and telephone number patterns) applied before export to Langfuse.

Infrastructure and Availability. The Platform is hosted on Vercel (application layer) and Supabase (database, authentication, edge functions, and file storage), both operating enterprise-grade infrastructure with built-in redundancy. Content processing uses asynchronous message queues and scheduled functions, reducing data loss risk from processing failures.

Organisational Measures. Access to production systems and Personal Data is restricted to Breezee AI personnel who require it for their duties. All such personnel are subject to binding confidentiality obligations. Breezee AI maintains internal policies governing the use of production data, AI training data, and Sub-processor engagement. Credentials are managed via environment variables through GitHub Secrets, synced to Vercel and Supabase via CI/CD pipelines, and are not stored in source code.

Anonymisation for AI Training. Before any conversation data is used for AI model training or platform improvement, it will undergo an anonymisation process designed to remove all direct and indirect personal identifiers, documented as Clause 8.3 requires. Anonymised Platform Data will be processed separately from Personal Data. No such processing takes place at the date of this version.

Incident Response. Breezee AI maintains an internal incident response process for identifying, classifying, and responding to Personal Data Breaches. Suspected breaches are escalated immediately to the founding team. Post-incident reviews are conducted to identify and address root causes. The Processor commits to the 72-hour notification timeline in Clause 5.1 of this DPA.

Updates. These TOMs will be reviewed and strengthened as the Platform moves toward General Availability. Breezee AI will notify Controllers of any material reduction in the level of protection in advance of implementing such a change.

Breezee AI Limited — Company No. SC857320 — Registered office: 10/1 Woodcroft Road, Edinburgh EH10 4FD