Data processing addendum

Last updated 13 September 2026

This addendum forms part of the terms of service and applies where we process personal data on your behalf. Where it conflicts with the terms, this addendum wins on data protection.

Roles

For personal data in the conversations your agent has, and in the content you give it, you are the controller and we are the processor. You decide what is collected and why; we act on your documented instructions, which are the terms, this addendum and your use of the platform.

We will tell you if we believe an instruction breaches data-protection law, rather than carrying it out quietly.

What we process

Subject matter: providing the Gemerald platform. Duration: the life of your subscription, plus the deletion window below.

  • Categories of data subject: your customers, prospects, and the people on your team who use the platform.
  • Categories of personal data: identifiers and contact details, conversation content, order and transaction references, and technical data such as IP address.
  • Special-category data: not requested by the platform. If your customers volunteer it in a conversation, it is processed as part of that conversation — consider that before pointing an agent at a context where it is likely.

Security measures

  • Encryption of personal data in transit and at rest.
  • Access control: production access is restricted to those who need it, individually authenticated, and logged.
  • Segregation of customer data, so one account cannot reach another’s.
  • Change management: changes are reviewed before they reach production.
  • Backup and restoration procedures, tested rather than assumed.
  • Confidentiality obligations on every person with access.

Sub-processors

You authorise us to use sub-processors for hosting, AI model inference, messaging-channel delivery, payment processing, email delivery and monitoring. Each is engaged under a written contract imposing obligations no weaker than these, and we remain responsible to you for what they do.

The current list is available on request. We will give you notice before adding a new one, and a reasonable period to object.

International transfers

Personal data may be processed outside the country you are in and outside the EEA. Where it is, the transfer is made under an adequacy decision or under Standard Contractual Clauses with appropriate supplementary measures.

We will tell you, specifically and in writing, which mechanism applies to your account and where your data is processed. If your organisation has a residency requirement, raise it before you sign — it is a question with a real answer, not a formality.

Helping you meet your obligations

  • Data subject requests: the platform lets you find, export and delete a person’s data yourself. Where you need more, we will help.
  • Breach notification: we will notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time.
  • Impact assessments: we will give you the information you reasonably need to complete a DPIA.
  • Audit: we will provide the information needed to demonstrate compliance, and accept a reasonable audit on reasonable notice.

Return and deletion

On termination you may export your data. After a reasonable window we delete it, except where law requires us to keep a copy — in which case we keep only that, and only for as long as required.

Questions about this document? Email team@gemerald.ai and a person will answer.