Cloei AI Limited

Data Processing Agreement

Version 1.0 ·

This Data Processing Agreement sets out how Cloei handles personal data on behalf of its business customers. It incorporates the terms required by Article 28 of the UK GDPR and forms part of every customer agreement.

1. Scope and structure

This DPA is between CLOEI AI LIMITED (company number 16688827) and the customer named on the Order Form, and forms part of the customer agreement. It applies to all processing of personal data carried out by Cloei on the customer's behalf.

Where this DPA conflicts with any other part of the agreement in relation to personal data, this DPA prevails. Terms defined in the applicable Services Agreement between Cloei and the customer have the same meaning here. "Controller", "Processor", "Personal Data", "Data Subject", "processing" and "Personal Data Breach" have the meanings given in the UK GDPR.

2. Roles of the parties

The customer is the Controller and Cloei is the Processor in respect of end-user personal data processed through the services.

The customer determines the purposes and means of processing. Cloei processes personal data only on the customer's documented instructions, which comprise this DPA including Annex 1, the Order Form, the configuration the customer has approved, and any further written instruction. The configuration constitutes a documented instruction.

Cloei acts as an independent Controller only for its own business data — account administration, billing, service security, and aggregated or anonymised platform analytics. That processing is governed by our Privacy Policy.

Cloei will tell the customer without undue delay if, in its opinion, an instruction infringes data protection law, and may suspend the affected processing until the instruction is withdrawn, confirmed or amended.

3. Customer obligations as Controller

The customer warrants that it has a valid lawful basis for the processing it instructs; has provided the transparency information required by Articles 13 and 14 UK GDPR, including about the use of automated systems; that the personal data it provides is accurate and lawfully obtained; that it has completed a data protection impact assessment where Article 35 requires one; that it has complied with PECR including consent, preference service screening and suppression; and that its instructions comply with data protection law.

4. Cloei's obligations as Processor

Cloei will:

  • process personal data only on the customer's documented instructions;
  • ensure everyone authorised to process personal data is bound by confidentiality and appropriately trained;
  • implement and maintain the technical and organisational measures in Annex 2, and keep them under review as Article 32 requires;
  • engage sub-processors only in accordance with section 6;
  • provide reasonable assistance enabling the customer to respond to data subject requests;
  • provide reasonable assistance with the customer's obligations under Articles 32 to 36;
  • delete or return personal data at the end of the services, as set out in section 11;
  • make available the information necessary to demonstrate Article 28 compliance, and contribute to audits; and
  • maintain a record of processing as Article 30(2) requires.

5. AI, de-identification and training

The customer instructs Cloei to process personal data using the AI models supplied by the model providers listed in Annex 3.

5.2 Model providers

Cloei does not permit model providers to use personal data processed under this DPA to train, retrain or fine-tune their models. Cloei contracts with model providers on terms that exclude such use, and configures its integrations accordingly.

5.3 Identifiable data

Cloei does not use identifiable personal data processed under this DPA to train its own models, except on the customer's specific written instruction and solely for that customer's own deployment.

5.4 De-identification and platform improvement

The customer instructs Cloei to de-identify conversation data and to use the de-identified output to improve the Cloei platform. Specifically:

  • Cloei processes conversation data so that data subjects can no longer reasonably be identified. Direct identifiers are removed and free-text content is scanned and redacted to remove identifying detail. Cloei retains no key enabling re-identification.
  • De-identification takes place within 30 days of a conversation ending.
  • Once de-identified, the output may be combined with de-identified data derived from other Cloei customers and used to train, evaluate and improve Cloei's models and services, including services provided to other customers.
  • The de-identification step is itself processing of personal data, carried out by Cloei as Processor on the customer's instruction under this section and Annex 1. Once complete, the output is not personal data and this DPA does not apply to its further use.

5.5 Opt-out

The customer may withdraw the instruction in 5.4 at any time by written notice. On receipt, Cloei will exclude conversation data originating from that customer's deployment from platform improvement within 30 days.

Withdrawal does not affect de-identified data already incorporated into a trained model, which cannot be isolated or reversed, and does not affect Cloei's use of aggregated statistical information.

5.6 Data minimisation

Cloei limits the personal data transmitted to model providers to what is necessary for the relevant conversation or function, and configures provider-side retention accordingly.

5.7 Automated decision-making

Where the configuration causes a decision producing legal or similarly significant effects to be taken without meaningful human involvement, the customer remains the Controller for the purposes of Articles 22A to 22D UK GDPR and is responsible for the safeguards required by Article 22C. Cloei will provide reasonable technical assistance, including making conversation records and decision inputs available.

6. Sub-processors

The customer gives general written authorisation for Cloei to engage sub-processors. Those authorised at the date of this DPA are listed in Annex 3 below.

Cloei imposes equivalent data protection obligations on each sub-processor by written contract, and remains fully liable for their performance.

Cloei gives the customer at least 30 days' written notice before appointing a new or replacement sub-processor.

A customer may object on reasonable data protection grounds within 30 days of notice. The parties will discuss the objection in good faith. If it cannot be resolved, the customer may terminate the affected services with a pro-rata refund of prepaid fees for the unexpired term.

7. Data Subject rights

Cloei notifies the customer without undue delay of any data subject request relating to personal data processed on the customer's behalf, and does not respond itself except to acknowledge the request and direct the person to the customer.

Cloei provides reasonable assistance enabling the customer to respond to requests for access, rectification, erasure, restriction, portability and objection.

Under Article 12A UK GDPR the response period does not begin until the Controller has the information reasonably required to identify the person and clarify the request, and a reasonable and proportionate search is required. Cloei's assistance is scoped accordingly.

Data subject rights do not extend to de-identified data produced under 5.4, which can no longer be linked to an individual. Where a request is received before de-identification, Cloei assists as set out above.

Where a customer receives a complaint under section 164A of the Data Protection Act 2018 concerning processing carried out by Cloei, Cloei provides the information reasonably required to respond within the statutory timescales.

Assistance is provided at no charge where routine and deliverable through standard platform functionality. Cloei may charge at its then-current rates for materially burdensome assistance, and will say so before doing it.

8. Personal Data Breach

Cloei notifies the customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting personal data processed on the customer's behalf.

The notification includes, so far as known and updated as more is learned: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a point of contact.

Cloei takes reasonable steps to contain, investigate and mitigate the breach, and preserves evidence.

The customer, as Controller, decides whether the breach is notifiable to the ICO or to data subjects and makes any such notification. Cloei will not notify on the customer's behalf unless instructed in writing.

Neither party will make a public statement identifying the other in connection with a breach without prior written consent, except where required by law or a regulator.

9. International transfers

The sub-processors in Annex 3 process personal data within the United Kingdom or the European Economic Area. Transfers to the EEA are covered by UK adequacy regulations, so no additional transfer mechanism is required.

Cloei will not transfer personal data to a country outside UK adequacy without first putting an appropriate mechanism in place — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism — together with a transfer risk assessment where required, and notifying customers under section 6.

10. Audit, information and regulatory access

Cloei makes available the information reasonably necessary to demonstrate Article 28 compliance, including current security documentation and any third-party audit reports or certifications it holds.

A customer may audit Cloei's compliance once in any 12-month period, on not less than 30 days' notice, during business hours, subject to confidentiality, and without unreasonably disrupting Cloei's business. Cloei may satisfy an audit request with a current independent audit report where that reasonably addresses the matters concerned.

The frequency limit does not apply where an audit follows a personal data breach affecting that customer, or is required by a regulator.

10.5 Regulatory access. Where the customer is authorised and regulated by the Financial Conduct Authority or the Prudential Regulation Authority, Cloei grants the customer, its auditors and its regulator effective access to the data, premises, equipment and personnel relating to the services, and cooperates with the regulator, as required by SYSC 8 of the FCA Handbook. This survives termination for as long as the customer must retain those rights.

Cloei notifies the customer without undue delay of any request from a regulator or law enforcement body relating to personal data processed on the customer's behalf, unless prohibited by law.

11. Retention, return and deletion

Cloei retains personal data processed on the customer's behalf only as long as necessary to provide the services, or for the period the customer instructs.

On termination, Cloei will — at the customer's written election made within 30 days — return the personal data in a commonly used machine-readable format, or delete it. If no election is made, Cloei deletes it.

Cloei may retain personal data where required by law, continuing to protect it under this DPA, and may retain backups until they expire in the ordinary course provided they are not accessed for any other purpose.

De-identified data produced under 5.4 is not personal data and is not subject to return or deletion. Cloei confirms deletion in writing on request.

12. Liability and general

Liability under this DPA is subject to the limitations in the applicable Services Agreement between Cloei and the customer, save that nothing limits or excludes either party's liability to a data subject or to the ICO under data protection law.

The parties acknowledge that Article 82 UK GDPR gives data subjects a direct right of action against both Controller and Processor, and that this DPA does not affect that right.

This DPA takes effect on the date of the Order Form and continues for as long as Cloei processes personal data on the customer's behalf. Cloei may update it on written notice where necessary to reflect a change in data protection law or regulatory guidance, provided the update does not materially reduce the protection afforded to data subjects.

This DPA is governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Annex 1 — Details of processing

ItemDetail
Subject matterProvision of AI-powered conversational communication services on the customer's behalf.
DurationThe term of the agreement, plus any retention period instructed by the customer and any period required by law. Conversation data is de-identified within 30 days of a conversation ending.
Nature of processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, analysis by AI models, generation of responses, de-identification, disclosure to the customer, erasure and destruction.
PurposeResponding to and initiating customer communications; understanding intent; collecting information; qualifying enquiries; providing information, options or quotes; arranging appointments and callbacks; escalating to human agents; recording outcomes; integrating results with the customer's systems; and de-identifying conversation data so the output may be used to improve the Cloei platform, including services provided to other customers, as set out in section 5.4.
Categories of data subjectThe customer's customers, prospective customers, enquirers and leads; and, where provided, the customer's own personnel who access or operate the services.
Types of personal dataName; contact details including email, mobile and telephone number, postal address and messaging identifiers; customer or account reference; date of birth where the service requires it; enquiry and application information; products or services held; conversation content; conversation metadata including timestamps, channel and outcome; AI-generated content; technical and log data.
Special category dataNot processed by default. Where a data subject volunteers such data during a conversation it may be incidentally recorded. The customer must configure its deployment to minimise this and identify an Article 9 condition where such data is processed. The de-identification process under 5.4 is designed to remove such detail before the output is used for platform improvement.
Criminal offence dataNot processed.
FrequencyContinuous for the duration of the agreement.

Annex 2 — Technical and organisational measures

A summary of the measures Cloei maintains under Article 32. Full documentation is available to customers and prospective customers on request.

  • Access control — role-based access on a least-privilege basis; multi-factor authentication for administrative and production access; access reviews on joining, role change and leaving; unique named accounts with no shared production credentials.
  • Encryption — personal data encrypted in transit using TLS 1.2 or above, and at rest in the production database and backups; secrets and API credentials held in a managed secrets store rather than in source code.
  • Infrastructure — hosted on Amazon Web Services in an EU region; production separated from development and test; no production personal data used in non-production environments.
  • Logging and monitoring — audit logging of administrative access and material data operations; monitoring and alerting for availability and security events; logs retained for 12 months.
  • De-identification — removal of direct identifiers and redaction of identifying detail from free-text content before conversation data is used for platform improvement; no retention of any re-identification key; periodic testing of output for residual identifiability.
  • Organisational — written information security and acceptable use policies; confidentiality obligations in all employment and contractor agreements; data protection and security training on joining and at least annually; documented incident response procedure; due diligence on sub-processors; secure development practices including code review before production deployment.

Annex 3 — Authorised sub-processors

Current at the date above. Cloei will give the customer's nominated contact at least 30 days' written notice before any change to this list.

Sub-processorPurposeLocationTransfer basis
Amazon Web ServicesCloud hosting and infrastructureEUUK adequacy
MongoDB AtlasDatabase infrastructureEUUK adequacy
TwilioSMS, messaging and telephony infrastructureEUUK adequacy
Meta Platforms Ireland LtdWhatsApp Business messaging channelEUUK adequacy
OpenAIAI language model servicesEUUK adequacy
AnthropicAI language model servicesEUUK adequacy
Microsoft Ireland Operations LtdEmail and business productivityUK / EUUK adequacy
NovemIT and technology support servicesUKNot a transfer

Cloei uses internal business tools, including messaging and knowledge management systems, that do not receive personal data processed on behalf of customers. Those tools are not sub-processors and are not listed here.

Request a signed copy

We will countersign this DPA for any customer or prospective customer, usually within two working days.

Email support@cloei.ai

Cloei AI Limited · Company number 16688827 · ICO registration ZC240937
Reedham House, 31 King Street West, Manchester, M3 2PJ