Legal

Data Processing Agreement

Last updated: July 9, 2026

Draft — for review by your solicitor before launch.

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the terms of service and applies whenever Just Agents processes personal data on your behalf under GDPR, UK GDPR, or similar laws. For that data — principally the communications your agents handle (emails, call transcripts and recordings, chat messages, reviews, invoices, booking details) — you are the controller and we are the processor. For our own account, billing, and usage data we act as an independent controller under the privacy policy.

2. Details of processing

Subject matter: operation of AI agents for business communication and administration. Duration: the term of your subscription plus the 30-day export window. Nature and purpose: receiving, analysing, drafting, sending, and logging business communications; building and querying your knowledge base. Data subjects: your customers, prospects, suppliers, and staff. Categories of data: contact details, communication content and metadata, booking and transaction details, voice recordings and transcripts where you enable the phone channel. The service is not designed for special-category data.

3. Our obligations as processor

  • Process personal data only on your documented instructions — given through your configuration of the service — unless law requires otherwise, in which case we tell you first where permitted.
  • Ensure everyone with access is bound by confidentiality.
  • Apply the technical and organisational measures in section 6.
  • Assist you, taking into account the nature of processing, with data-subject requests, security, breach notification, and DPIAs.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notifications.
  • Delete or return personal data at the end of the engagement (30-day export window, then deletion; backups roll off within a further 35 days).
  • Make available the information necessary to demonstrate compliance and allow audits, initially satisfied by documentation and third-party reports; on-site audits by agreement, at your cost, no more than annually.

4. Subprocessors

You give general written authorisation for the subprocessors below. We will give at least 30 days’ notice (by email to account owners) before adding or replacing one; if you reasonably object on data-protection grounds and we cannot accommodate you, you may cancel the affected service with a pro-rata refund of prepaid fees. Each subprocessor is bound by data-protection terms at least as protective as this DPA.

SubprocessorPurposeLocationTransfer safeguard
AnthropicAI model inference (drafting, triage, answers)United StatesSCCs + UK Addendum; no training on customer content
SupabaseDatabase, authentication, file storageEU / US (region-pinned)SCCs + UK Addendum
StripePayments, subscriptions, invoicingUnited States / IrelandSCCs; PCI-DSS Level 1
ResendTransactional email deliveryUnited StatesSCCs + UK Addendum
TwilioTelephony and SMS (Echo voice channel)United StatesSCCs + UK Addendum; Binding Corporate Rules
VapiVoice AI orchestration (Echo voice channel)United StatesSCCs + UK Addendum
VercelApplication hosting and content deliveryUnited States (global edge)SCCs + UK Addendum

5. International transfers

Where processing involves a transfer outside the UK or EEA, the parties rely on adequacy regulations where available and otherwise on the EU Standard Contractual Clauses (Module 2, controller-to- processor) and the UK International Data Transfer Addendum, which are incorporated by reference and executed between us and each relevant subprocessor.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Per-tenant isolation enforced with database row-level security.
  • Role-based access control, least-privilege internal access, and audit logging of administrative actions.
  • Secrets management, dependency scanning, and environment separation between production and development.
  • No AI-model training on customer content; prompt-injection defences on untrusted inbound content.
  • Documented incident-response and backup/restore procedures.

7. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the terms of service, except where data protection law does not permit such limits. If this DPA conflicts with the terms, this DPA prevails for data-protection matters. Questions and signed-copy requests: privacy@justagents.co.