Last updated: 2026-09-09
This Data Processing Agreement (the “Agreement” or “DPA”) governs the processing of personal data that GoHyppo carries out on the Customer’s behalf when providing the Services. It forms part of our Terms and Conditions and is complemented by our Privacy Policy.
The parties are the Customer, as data controller, and the Contracting Entity — GoHyppo LLC or Voxtur Ltd, as identified in the contract, service order or invoice — as data processor. Capitalized terms not defined here have the meaning given to them in the Terms and Conditions.
To execute a countersigned copy of this Agreement, write to it@hyppo.io. Unless a different version is signed, this is the applicable version.
1. Roles and subject matter
- The Customer is the data controller for its End Users’ personal data and for any other personal data it uploads or transmits through the Services (the “Customer Data”). It determines the purposes, the means and the lawfulness of the processing.
- GoHyppo acts as processor and processes Customer Data solely to provide the Services, in accordance with this Agreement and the Customer’s documented instructions.
- For data we process for our own purposes — account administration, billing, security, support and improvement of the Services — we act as controller, and that processing is governed by the Privacy Policy and not by this Agreement.
- The details of the processing — categories of data, categories of data subjects, purposes and duration — are set out in Annex A.
2. The Customer’s instructions
- The Customer’s instructions are: these Terms and Conditions, this Agreement, the signed contract if there is one, the configuration the Customer applies in the Platform, and any other instruction we accept in writing.
- We will process Customer Data in accordance with those instructions, unless applicable law requires otherwise. In that case we will inform the Customer, unless the law prohibits it.
- If in our reasonable judgement an instruction infringes applicable data protection law, we will say so and may suspend its execution until the Customer confirms, amends or withdraws it.
- Instructions that go beyond the ordinary provision of the Services — bespoke extractions, migrations, specific formats, assistance with audits or impact assessments — are met with reasonable effort and at the Customer’s cost, at our then-current rates.
3. The Customer’s obligations and warranties
The Customer represents and warrants that:
- it holds a valid legal basis for every processing activity it instructs, together with the consents and notices applicable law requires, including those relating to commercial communications and to call recording and transcription;
- it has informed its End Users as applicable law requires, and publishes and maintains its own privacy and cookie policy, including the cookie the webchat widget sets on its website;
- the Customer Data it uploads is accurate and relevant, and does not include special categories of personal data or children’s data, unless a specific written agreement between the parties provides for it;
- it is responsible for configuring the retention, permissions and access settings of its Workspace and of any storage it connects;
- it is the sole point of contact for its End Users exercising their rights.
The Customer will indemnify and hold GoHyppo harmless against any claim, penalty or damage arising from a breach of this clause or from instructions that infringe applicable law.
4. Personnel confidentiality
We limit access to Customer Data to the personnel who need it to provide the Services. That personnel is bound by confidentiality obligations no less protective than those in this Agreement, which survive the end of their relationship with us, and receives the training their role requires.
5. Security measures
- We apply technical and organizational measures appropriate to the risk, described in Annex B and in the security section of the Privacy Policy.
- Those measures may be updated over time as technology evolves. We will not degrade the overall level of security during the term of this Agreement.
- The Customer is responsible for the part of security within its own control: managing its credentials and its users’ access, configuring its Workspace, the permissions it grants to third-party integrations, and the security of any infrastructure it connects.
- No measure guarantees absolute security. This Agreement is not a warranty that incidents will not occur.
6. Sub-processors
- The Customer grants a general authorization for us to engage sub-processors in providing the Services. The current list is published in the Privacy Policy.
- With each sub-processor we enter into an agreement imposing data protection obligations substantially equivalent to those in this Agreement, to the extent applicable to its service.
- Before engaging a new sub-processor that will process Customer Data, we will update that list and notify the Customer at least fourteen (14) days in advance.
- The Customer may object within that period, on reasonable grounds based on data protection. If the objection is well-founded, we will seek a reasonable alternative. Where none exists, the Customer’s sole remedy is to terminate the affected Service, without penalty and without any right to a refund of periods already accrued. Failure to object within the period constitutes acceptance.
- We remain responsible for our sub-processors’ performance of their obligations to the same extent as for our own, subject to clause 12.
7. International transfers
Customer Data may be processed in the countries listed in the Privacy Policy. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to third countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, which are deemed incorporated into this Agreement by reference. The Customer authorizes us to enter into those clauses with our sub-processors on its behalf, and to perform the exporter’s obligations in respect of that chain.
8. Data subject rights
- The Platform lets the Customer access, export, correct and delete a contact’s data on its own, as described in the product documentation. That functionality is the mechanism provided for the Customer to handle the requests it receives.
- If we receive a request from one of the Customer’s End Users, we will not answer it directly: we will forward it to the Customer without undue delay.
- Where the Customer cannot fulfil a request with the available features, we will provide reasonable assistance, at its cost, under clause 2.
9. Security incidents
- We will notify the Customer without undue delay after becoming actually aware of a personal data breach affecting Customer Data, with the information reasonably available to us so that it can meet its own notification obligations.
- A notification may be preliminary and completed as the investigation progresses. It does not constitute an admission of fault or liability.
- We will take reasonable steps to contain and remediate the incident.
- Notifications to supervisory authorities and to affected data subjects are the Customer’s responsibility as controller. We will not make them on its behalf unless agreed in writing.
- We are not required to notify incidents that do not affect Customer Data, unsuccessful attempts, or events with no impact on the confidentiality, integrity or availability of that data.
10. Audit and information
- On the Customer’s request we will make available the information reasonably necessary to demonstrate compliance with this Agreement. That duty is satisfied, in the first instance, through the available documentation: this Agreement, the sub-processor list, Annex B, and the certifications or reports of our infrastructure providers where available.
- If that documentation is not sufficient, the Customer may carry out an audit once per calendar year, on at least thirty (30) days’ prior notice, during business hours, without interfering with operations, limited to the scope of this Agreement and at the Customer’s cost.
- The auditor may not be a competitor of ours and must sign a confidentiality undertaking. We will not give access to other customers’ information, to our third-party internal systems, or to data whose disclosure would breach confidentiality obligations.
- Where a competent supervisory authority requires greater frequency or scope, we will comply to the extent of that requirement.
11. Return and deletion
- When provision of the Services ends, the Customer’s Workspace enters read-only mode for thirty (30) days so that it can export Customer Data on its own.
- After that period, and at the Customer’s election made within it, we will return or delete Customer Data within the following thirty (30) days. Absent an election, we will delete it.
- Backups are purged in their normal rotation cycle. We may retain Customer Data to the extent applicable law requires, or where necessary to exercise or defend rights in a claim, keeping it subject to the obligations of this Agreement.
- The automatic trimming periods for conversation history during the term are published in the product documentation.
12. Liability
The parties’ liability under this Agreement is subject to the exclusions and liability caps set out in clause 17 of the Terms and Conditions or, where one exists, in the signed contract. This Agreement does not increase those caps, and all claims relating to the processing of personal data count towards the same aggregate cap, without stacking. The twelve (12) month window for bringing claims set out in that clause also applies to this Agreement.
13. Term
This Agreement takes effect together with the Services and remains in force for as long as we process Customer Data. Obligations that by their nature must survive — confidentiality, deletion, liability — continue after it ends.
14. Precedence and changes
- This Agreement prevails over the Terms and Conditions and the Privacy Policy on data protection matters only. In everything else, including scope, price, term, availability and liability, those documents and the signed contract govern.
- Where a signed data processing agreement exists between the parties, that instrument prevails over this published version.
- We may update this Agreement to reflect changes in law, in our sub-processors or in the Services. We will publish the current version on this page with its date. Where a change materially reduces the protections set out here, we will give reasonable advance notice.
15. Governing law
This Agreement is governed by the law and subject to the jurisdiction set out in clause 21 of the Terms and Conditions or, where one exists, in the signed contract.
Annex A — Details of the processing
| Subject matter | The provision of the Services to the Customer, under the Terms and Conditions and the signed contract, where one exists. |
| Duration | The term of the Services, plus the periods in clause 11. |
| Nature and purpose | Hosting, storage, transmission, retrieval, organization, analysis and deletion of Customer Data, for the purpose of operating the messaging channels, conversational agents, human support, automations, analytics and integrations the Customer configures. |
| Categories of data subjects | The Customer’s End Users — its customers, prospects and contacts — and the users the Customer enables in its Workspace. |
| Categories of data | Identification and contact data (name, phone number, email address, messaging platform identifiers); conversation content across all connected channels, including files, images, voice notes, location and shared contacts; call recordings, transcripts and automatically generated summaries, where the Customer enables those features; commerce data (orders, checkouts, amounts, status); custom attributes and tags the Customer defines; data the Customer imports or syncs from its own systems. |
| Special categories | Not envisaged. The Customer must not upload them unless specifically agreed in writing. |
| Sub-processors | Those published in section 7 of the Privacy Policy. |
| Transfers | To the countries listed in section 8 of the Privacy Policy, with the safeguards in clause 7 of this Agreement. |
Annex B — Technical and organizational measures
The measures we apply, appropriate to the risk of the processing, include:
- Encryption of data in transit, and encryption at rest for credentials and configuration data.
- Access control on a least-privilege basis, with periodic review of granted access and strong authentication on critical systems.
- Secrets management in a dedicated manager, with no credentials in code.
- Access logging and logging of relevant security events.
- Regular backups with a defined rotation cycle, and restoration procedures.
- Segregation of each customer’s data in its own Workspace or dataset.
- Prior assessment of the privacy and security practices of the sub-processors we engage.
- Confidentiality and training for personnel with access to Customer Data.
- Incident management with detection, containment, remediation and notification procedures.
These measures describe our security programme and may evolve with technology. The certifications mentioned in our materials belong to the infrastructure providers we use, and not to GoHyppo LLC or Voxtur Ltd, as set out in clause 13 of the Terms and Conditions.
Contact
Questions about this Agreement and requests to execute it: it@hyppo.io