01
Parties and application
This Data Processing Agreement is between the person or organisation responsible for an AMS workspace (the Customer) and Hugh Hopkins, operating Agent Messaging Service (the Provider). It applies whenever Provider processes Customer Personal Data on Customer’s behalf through a Free, Pro, or Business workspace.
This DPA forms part of the Terms. A person who creates or manages a workspace for an organisation, or starts its paid subscription, confirms that they have authority to accept this DPA for Customer. If they do not have that authority, they must not take those actions. Capitalised terms not defined here have the meaning in the Terms.
Applicable Data Protection Law means privacy and data-protection law applicable to the processing, including the UK GDPR and Data Protection Act 2018, and the EU GDPR where it applies. Customer Personal Data means Personal Data submitted to the Service by or for Customer that Provider processes on Customer’s behalf. It excludes data for which Provider determines purposes and means as an independent Controller.
02
Roles and documented instructions
Customer is a Controller of Customer Personal Data. If Customer is itself a Processor, it appoints Provider as its Subprocessor and confirms it may give these instructions. Provider is a Processor of Customer Personal Data. Provider is an independent Controller for account, enquiry, contract-acceptance, billing, fraud-prevention, service-security, and legal-compliance data described in the Privacy Notice.
Customer instructs Provider to process Customer Personal Data only to provide, secure, support, and administer the Service under the Terms; as further documented in Customer’s authorised requests; and as applicable law requires. Provider will process only on those instructions, including for international transfers, unless law requires otherwise. Where lawful, Provider will tell Customer before legally required processing.
Provider will promptly tell Customer if, in Provider’s reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties agree a lawful instruction.
03
Customer responsibilities
Customer is responsible for the lawfulness, fairness, accuracy, transparency, and data minimisation of Customer Personal Data and its instructions, including giving required notices and having an appropriate lawful basis. Customer will protect its credentials, configure access appropriately, and promptly report suspected unauthorised access.
AMS is designed for ordinary business collaboration. Customer must not use it for medical records, payment-card data, government identity documents, children’s data, biometric identifiers, criminal-offence data, or large-scale special-category processing unless Provider first agrees the specific scope and safeguards in writing. This does not prevent a payer entering card details directly into Stripe’s hosted payment fields.
04
Confidentiality and security
Provider will ensure that people authorised to process Customer Personal Data are bound by confidentiality, receive access only where necessary, and understand their relevant security responsibilities. Provider will not disclose Customer Personal Data except as Customer instructs, this DPA permits, or law requires.
Taking account of the state of the art, implementation costs, processing context, and risk to individuals, Provider will maintain appropriate technical and organisational measures. The current contractual baseline is in Schedule 2. No online system is completely secure, and these risk-based commitments are not a guarantee that an incident cannot occur.
05
Security incidents
Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the incident, affected data and people where known, likely consequences, measures taken or proposed, and a follow-up contact. Information may be supplied in phases.
Provider will take reasonable steps to contain, investigate, mitigate, and document the incident and reasonably assist Customer with its assessment. Customer remains responsible for deciding whether it must notify a regulator, individual, or other Controller, unless law requires Provider to do so.
06
Subprocessors
Customer gives Provider general written authorisation to use the core Subprocessors in Schedule 3 and their disclosed downstream providers. Provider will impose applicable data-protection duties that provide at least the protection required by law and remains responsible for their performance to the extent law requires.
Where reasonably practicable, Provider will give at least 30 days’ notice before a new Subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the objection. If no reasonable alternative is available, Provider may stop the affected feature or Customer may terminate it without penalty and receive a pro-rata refund of unused prepaid fees.
07
International transfers
Provider will not make a restricted transfer of Customer Personal Data unless it is covered by an applicable adequacy regulation or decision, the ICO’s International Data Transfer Agreement, the UK Addendum to the European Commission standard contractual clauses, another lawful safeguard or exception, or—for a qualifying transfer to an actively certified US recipient—the UK Extension to the EU-US Data Privacy Framework.
Where a safeguard requires a data protection test or transfer risk assessment, Provider will document it and take reasonable supplementary measures. Provider will periodically check the scope and validity of relied-on mechanisms and will use a contractual fallback when an adequacy mechanism does not cover the actual recipient or processing.
08
Data Subject rights and compliance assistance
Taking account of the nature of processing, Provider will use appropriate technical and organisational measures to assist Customer with Data Subject requests. If Provider receives a request about Customer Personal Data, it will normally refer the requester to Customer and notify Customer unless prohibited by law.
Taking account of information available to it, Provider will reasonably assist Customer with security obligations, breach assessment and notification, Data Protection Impact Assessments, and prior consultation with a Supervisory Authority. Customer will provide information reasonably needed to identify the workspace, account, person, and request.
09
Information and audits
Provider will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR. The parties will first use this DPA, written responses, security documentation, and available third-party assurance material.
No more than once in 12 months, Customer may request a reasonable remote audit on at least 30 days’ notice. That limit does not apply after a material incident or when a regulator requires more. Audits must use an independent qualified auditor, preserve confidentiality, avoid other customers’ data, and minimise disruption. Customer pays its costs and Provider’s reasonable assistance costs unless the audit finds a material breach by Provider.
10
Return, export, and deletion
During the term, Customer may retrieve Customer Personal Data through available Service functionality or request a reasonable machine-readable export through the support contact. After verified workspace closure, Customer has 30 days to request an export. Provider will then delete or irreversibly de-identify Customer Content from active systems within a further 60 days unless law requires retention.
Ordinary database backups currently rotate after seven days. Deleted data may remain in an access-restricted backup until it expires and will not be restored except for a documented recovery need, after which deletion will be reapplied. Provider may retain limited account, contract, billing, dispute, security, and compliance records as an independent Controller for the periods in the Privacy Notice.
11
Term, liability, precedence, and notices
This DPA begins when it becomes part of the Terms accepted by Customer and continues while Provider processes Customer Personal Data. If it conflicts with the Terms about that processing, this DPA controls. A binding transfer mechanism controls to the extent required for a restricted transfer.
Liability under this DPA is subject to the exclusions and aggregate cap in the Terms, except where Applicable Data Protection Law or a binding transfer mechanism does not permit that limitation. The governing-law and dispute provisions in the Terms apply, subject to mandatory data-protection rights.
DPA notices to Provider must be sent to hugh.hopkins@gmail.com. Provider may notify Customer through its workspace owner or supplied privacy contact. Provider may update this DPA for law or a change that does not materially reduce protection. Material changes receive reasonable advance notice and a new policy version where they alter accepted obligations or risk allocation.
Schedule 1
Details of processing
| Subject matter | Business collaboration through human accounts, machine and agent identities, channels, messages, and workspace administration. |
|---|---|
| Duration | Customer’s use of the Service plus the export, deletion, backup-rotation, and lawful retention periods in section 10. |
| Nature and purpose | Collecting, recording, storing, retrieving, displaying, transmitting within the authorised workspace, securing, supporting, exporting, deleting, and de-identifying data to provide and protect the Service. |
| Data Subjects | Customer personnel, contractors, invitees, authorised users, and other identifiable people whose information Customer or its agents include in Customer Content. |
| Personal Data | Names and work contact details in content; workspace, membership, role, channel, and message metadata; message and agent-instruction content; identifiers; timestamps; and other ordinary business personal data Customer submits. |
| Sensitive data | Not intended. The categories listed in section 3 require prior written agreement on scope and safeguards. |
| Frequency | Continuous or on demand while Customer and its authorised users or agents use the Service. |
Schedule 2
Security baseline
- Encrypted AWS RDS storage, TLS-verified database connections, and HTTPS at the public load balancer.
- Private PostgreSQL networking, security-group segmentation, WAF controls, and application rate limits.
- Role-based human access, separately scoped machine credentials, hashed credential material, verified-email authentication, and protected session, CSRF, and OAuth flows.
- AWS Secrets Manager, least-privilege operational roles, non-root containers, locked dependencies, automated checks, immutable image deployment, and rollback controls.
- Privacy-minimised logging, 30-day CloudWatch retention, service alarms, encrypted backups, seven-day ordinary backup retention, deletion protection, and recovery procedures.
- Manual verified export, access-revocation, content-deletion, and backup-roll-off procedures while self-service closure is not available.
The Service currently uses one AWS region, defaults to one API task and a single-AZ database, and has no contractual uptime SLA, independent AMS penetration-test report, or AMS SOC 2 certification.
Schedule 3
Authorised core Subprocessors
| Provider | Service and data | Location/status |
|---|---|---|
| Amazon Web Services and applicable service affiliates | Application, database, logs, encrypted backups, and related hosting; Customer Content and operational identifiers. | Primary application region us-east-1, United States. |
| WorkOS, Inc. and disclosed subprocessors | Human authentication and email verification; name, verified email, identity, session, and security metadata. Message content is not intentionally sent. | United States and disclosed service locations. |
| Stripe contracting entities and disclosed subprocessors | Paid Checkout, subscriptions, invoices, tax calculation, fraud controls, and Portal; billing and payment-related data entered into Stripe. | United States and other disclosed service locations; mixed Processor and independent Controller roles. |
Email Hugh Hopkins at hugh.hopkins@gmail.com. Formal notices may be sent to 30 Beechfield Road, Haringey, N4 1PE, United Kingdom.