Legal

Data Processing Agreement

Last updated: 2026-09-09

This Data Processing Agreement (the “Agreement” or “DPA”) governs the processing of personal data that GoHyppo carries out on the Customer’s behalf when providing the Services. It forms part of our Terms and Conditions and is complemented by our Privacy Policy.

The parties are the Customer, as data controller, and the Contracting Entity — GoHyppo LLC or Voxtur Ltd, as identified in the contract, service order or invoice — as data processor. Capitalized terms not defined here have the meaning given to them in the Terms and Conditions.

To execute a countersigned copy of this Agreement, write to it@hyppo.io. Unless a different version is signed, this is the applicable version.

1. Roles and subject matter

2. The Customer’s instructions

3. The Customer’s obligations and warranties

The Customer represents and warrants that:

The Customer will indemnify and hold GoHyppo harmless against any claim, penalty or damage arising from a breach of this clause or from instructions that infringe applicable law.

4. Personnel confidentiality

We limit access to Customer Data to the personnel who need it to provide the Services. That personnel is bound by confidentiality obligations no less protective than those in this Agreement, which survive the end of their relationship with us, and receives the training their role requires.

5. Security measures

6. Sub-processors

7. International transfers

Customer Data may be processed in the countries listed in the Privacy Policy. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to third countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, which are deemed incorporated into this Agreement by reference. The Customer authorizes us to enter into those clauses with our sub-processors on its behalf, and to perform the exporter’s obligations in respect of that chain.

8. Data subject rights

9. Security incidents

10. Audit and information

11. Return and deletion

12. Liability

The parties’ liability under this Agreement is subject to the exclusions and liability caps set out in clause 17 of the Terms and Conditions or, where one exists, in the signed contract. This Agreement does not increase those caps, and all claims relating to the processing of personal data count towards the same aggregate cap, without stacking. The twelve (12) month window for bringing claims set out in that clause also applies to this Agreement.

13. Term

This Agreement takes effect together with the Services and remains in force for as long as we process Customer Data. Obligations that by their nature must survive — confidentiality, deletion, liability — continue after it ends.

14. Precedence and changes

15. Governing law

This Agreement is governed by the law and subject to the jurisdiction set out in clause 21 of the Terms and Conditions or, where one exists, in the signed contract.

Annex A — Details of the processing

Subject matterThe provision of the Services to the Customer, under the Terms and Conditions and the signed contract, where one exists.
DurationThe term of the Services, plus the periods in clause 11.
Nature and purposeHosting, storage, transmission, retrieval, organization, analysis and deletion of Customer Data, for the purpose of operating the messaging channels, conversational agents, human support, automations, analytics and integrations the Customer configures.
Categories of data subjectsThe Customer’s End Users — its customers, prospects and contacts — and the users the Customer enables in its Workspace.
Categories of dataIdentification and contact data (name, phone number, email address, messaging platform identifiers); conversation content across all connected channels, including files, images, voice notes, location and shared contacts; call recordings, transcripts and automatically generated summaries, where the Customer enables those features; commerce data (orders, checkouts, amounts, status); custom attributes and tags the Customer defines; data the Customer imports or syncs from its own systems.
Special categoriesNot envisaged. The Customer must not upload them unless specifically agreed in writing.
Sub-processorsThose published in section 7 of the Privacy Policy.
TransfersTo the countries listed in section 8 of the Privacy Policy, with the safeguards in clause 7 of this Agreement.

Annex B — Technical and organizational measures

The measures we apply, appropriate to the risk of the processing, include:

These measures describe our security programme and may evolve with technology. The certifications mentioned in our materials belong to the infrastructure providers we use, and not to GoHyppo LLC or Voxtur Ltd, as set out in clause 13 of the Terms and Conditions.

Contact

Questions about this Agreement and requests to execute it: it@hyppo.io

×
Hi! 👋

How can we help you today?

Please write a message first.