Login Get started

Data Processing Agreement #

Last updated: 17 October 2025
This DPA forms part of the Agreement between Hay Labs LDA ("Processor" or "Hay") and the Customer ("Controller") for the hosted Service.

1) Subject Matter, Duration, Nature, Purpose #

  • Subject Matter: Processing of personal data submitted to the Service by Controller for customer-support automation/orchestration.
  • Duration: Term of the Agreement plus deletion/anonymization period.
  • Nature/Purpose: Storage, retrieval, transmission, analysis (including via LLMs), and output generation to assist support workflows.

2) Roles & Instructions #

Controller determines the purposes and means of processing and instructs Hay to process personal data solely to provide the Service. Hay will not process personal data for its own purposes.

3) Categories of Data & Data Subjects #

  • Data subjects: Controller's end-users/customers; Controller's staff who use the Service.
  • Data categories: Identifiers (name, email, phone, user IDs), chat content and attachments, conversation metadata, support artifacts, system logs (IP, user-agent). Controller may input additional categories via integrations.

4) Confidentiality #

Hay ensures persons authorized to process personal data are bound by confidentiality obligations.

5) Security Measures #

Hay implements technical and organizational measures appropriate to risk (Annex B), including TLS, RBAC, audit logging, and secure key management. Controller is responsible for configuration within its tenancy (roles, policies, IP allowlists).

6) Subprocessors #

Controller authorizes Hay to engage subprocessors listed in the Subprocessors List (updated online). Hay will impose data-protection obligations on subprocessors no less protective than this DPA and will notify Controller of material changes, allowing reasonable objection or termination rights where required.

7) International Transfers #

Where subprocessors are outside the EEA/UK, Hay will ensure appropriate safeguards (e.g., SCCs, DPF). Upon request, Hay will provide information about transfer mechanisms for the current subprocessors.

8) Assistance with Data Subject Requests #

Taking into account the nature of processing, Hay will assist Controller by providing appropriate technical/organizational measures to respond to requests under Arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection), including available self-service tools or support channels. Hay does not respond directly to data subjects unless legally required and then only after notice to Controller (unless prohibited).

9) Breach Notification #

Hay will notify Controller without undue delay after becoming aware of a personal-data breach, providing information reasonably available to assist Controller's obligations under Arts. 33-34 GDPR.

10) Audits & Compliance Information #

Upon reasonable request, Hay will provide information necessary to demonstrate compliance and will allow audits by Controller or an independent auditor under confidentiality, at reasonable times, without disrupting operations unduly. Third-party audit reports or security summaries may satisfy this obligation.

11) Deletion/Return #

Upon termination or at Controller's written request, Hay will delete or irreversibly anonymize personal data in active systems and, where feasible, return requested exports. Deleted data may persist in backups until overwritten by scheduled rotation; Hay will protect backups and prevent further processing.

12) Retention #

Unless otherwise instructed, Hay will apply the following defaults:

  • End-user conversations: retained until 90 days of end-user inactivity, then irreversibly anonymized;
  • LLM usage logs: up to 90 days;
  • Audit/security logs: up to 7 years.
    Controller may request different periods where supported.

13) Liability #

Each party's liability under this DPA follows the Agreement's limitation of liability, except where prohibited by law.

14) Governing Law; Venue #

This DPA is governed by Portuguese law with exclusive jurisdiction in Lisbon, Portugal.

Annexes #

This DPA incorporates the following annexes by reference: