← AccessBot

Data Processing Agreement

Last updated: 17 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer") and AccessBot ("AccessBot", "we", "us"), operator of the Service, and applies where AccessBot processes personal data about the Customer's members on the Customer's behalf. It reflects the requirements of Article 28 of the GDPR/UK GDPR and equivalent data-protection laws that apply to the parties.

1. Roles

For personal data about the Customer's members processed through the Service, the Customer is the data controller and AccessBot is the data processor. The Customer is responsible for having a lawful basis and appropriate notices for that data. (AccessBot is the controller for the Customer's own account data, as described in our Privacy Policy.)

2. Scope & instructions

AccessBot processes member personal data only to provide and support the Service, and only on the Customer's documented instructions (including as given through the Service's features and configuration), unless required to act otherwise by applicable law — in which case AccessBot will inform the Customer where legally permitted.

3. Confidentiality

AccessBot ensures that personnel authorised to process the data are bound by confidentiality and process the data only as necessary to provide the Service.

4. Security

AccessBot implements appropriate technical and organisational measures, including: encryption in transit (TLS) and encryption of sensitive stored credentials; strict per-tenant isolation enforced at the database level (row-level security); hashed passwords; access controls; and regular, encrypted backups. These measures are described further in our Privacy Policy.

5. Sub-processors

The Customer authorises AccessBot to engage the sub-processors listed in our Privacy Policy (currently our cloud hosting provider, DNS/CDN provider, email-delivery provider, an AI provider used for content screening and the optional support assistant, and Telegram) to help provide the Service. AccessBot imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains responsible for their performance. We will give reasonable notice of any new sub-processor; if the Customer reasonably objects on data-protection grounds, the Customer may terminate the affected Service. Payment providers the Customer connects act under their own terms and are not AccessBot sub-processors.

6. Assistance to the Customer

Taking into account the nature of the processing, AccessBot will provide reasonable assistance to enable the Customer to: (a) respond to data-subject requests (access, rectification, erasure, restriction, portability, objection); and (b) meet its obligations regarding security, breach notification, and, where required, data protection impact assessments. Where AccessBot receives a request directly from a member, it will refer that member to the Customer.

7. Personal-data breaches

AccessBot will notify the Customer without undue delay after becoming aware of a personal-data breach affecting member data, with the information reasonably available to help the Customer meet its notification obligations to the relevant supervisory authority and affected individuals.

8. International transfers

Where processing member data involves a transfer across borders, AccessBot relies on appropriate safeguards — such as standard contractual clauses and each sub-processor's compliance framework — as required by applicable data-protection law.

9. Deletion & return

On termination of the Service, or at the Customer's request, AccessBot will delete or return member personal data within a limited period, except where retention is required by law. The Customer can also export or delete workspace data through the Service at any time.

10. Audit & information

AccessBot will make available information reasonably necessary to demonstrate compliance with this DPA and, subject to confidentiality and reasonable notice, will allow for audits by the Customer or an independent auditor to the extent required by applicable law.

11. General

This DPA follows the Terms of Service, including their disputes section, and does not displace any mandatory data-protection law that applies to you. If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails.