Last updated: 2026-08-01
This addendum ("DPA") explains how we handle the personal data you trust us with when your customers chat with your assistant. It is written to meet Article 28 of the UK GDPR, in plain English, so you can rely on it without negotiating a bespoke contract.
This DPA is between you, our business customer ("you"), and BotSquirrel Ltd, trading as BotSquirrel, a company registered in England and Wales (company number 17364331) with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("we", "us"). It applies automatically to every business customer as part of our Terms of Service from the moment you start using the service — there is nothing to sign and nothing to send back. It applies for as long as we process personal data on your behalf.
It sits alongside our Privacy Policy and our Security & data protection page, which describes the technical measures referred to below. "UK GDPR", "Data Protection Act 2018", "personal data", "processing", "controller", "processor" and "data subject" have the meanings given in UK data protection law.
For the conversations your customers have with your assistant, you are the controller and we are the processor. You decide why and how that data is used; we process it only to run the service for you.
Separately, we are a controller for your own account data — the details you give us to sign up, log in, contact you and bill you. That processing is described in our Privacy Policy, not in this DPA.
| Subject matter | Processing personal data contained in conversations and enquiries handled by your AI assistant. |
|---|---|
| Duration | The term of your subscription, plus the short deletion window in section 4. |
| Nature and purpose | Operating the AI assistant on your behalf: receiving messages from WhatsApp and website live chat, generating replies, storing conversation history so your team can follow up, and capturing enquiry and lead details in your dashboard. |
| Categories of data subjects | Your end customers and enquirers, and your own staff who use the dashboard. |
| Categories of personal data | Names, phone numbers and other contact details, message content, enquiry details, and appointment or booking details. |
| Special category data | The service is not designed for special category data (for example health, religion or biometric data) or criminal offence data. You should not configure your assistant to ask for it, and you should not direct it into the chat. |
Documented instructions. We process your customers' personal data only on your documented instructions. Your instructions are: these Terms, this DPA, and the settings and business information you configure in your dashboard. If we ever believe an instruction breaks UK data protection law, we will tell you. If the law requires us to process data for another reason, we will tell you first unless the law forbids it.
Confidentiality. Everyone we allow to access the data is bound by confidentiality obligations and only gets the access their role needs.
Security. We keep appropriate technical and organisational measures in place under Article 32 — UK hosting, encryption in transit, tenant isolation, role-based access and audit logging. Rather than repeat them here, see Security & data protection, which we keep current.
Helping with data-subject requests. If one of your customers contacts us directly to access, correct, delete or restrict their data, we will not respond on your behalf — we will pass it to you promptly. We will help you answer it, using the export and deletion tools available in the service.
Helping you meet your own obligations. Taking into account what we know and the nature of the processing, we will give you reasonable help with security, breach notification, data protection impact assessments and prior consultation with the ICO.
Deletion or return at the end. When your subscription ends you can ask us for an export of your data in a usable format. After that, we delete or anonymise conversation history and enquiry records within 90 days, except where the law requires us to keep something (for example billing records). This matches the retention promise in section 6 of our Privacy Policy. Encrypted backups age out on their own cycle within 30 days.
Demonstrating compliance. We will make available the information you reasonably need to show that we meet these obligations. Audit rights are satisfied in the first instance by that documentation — our security page, this DPA and written answers to your questions. If that genuinely is not enough for your regulator, we will agree a proportionate audit with you, no more than once a year, at reasonable notice and cost.
You give us general written authorisation to use the sub-processors listed below to help deliver the service. Each one is bound by a written contract with data protection terms at least as protective as this DPA, and we stay responsible to you for their performance.
| Sub-processor | What it does | Where |
|---|---|---|
| Amazon Web Services | Application hosting, database, file storage | United Kingdom (London, eu-west-2) |
| OpenAI | Generating assistant replies and embeddings from your business information | United States |
| Meta Platforms | Delivering WhatsApp messages (WhatsApp Business Cloud API) | Global infrastructure |
| Paddle | Subscription billing and payments as Merchant of Record — listed for completeness; it handles your billing data, not your customers' conversations | United Kingdom / European Union |
If we add or replace a sub-processor, we will update this page at least 30 days before the change takes effect. If you reasonably object on data protection grounds within that period, tell us and we will try to find a workaround; if we can't, you may cancel the affected part of the service without penalty.
Your data is stored in the United Kingdom (AWS London, eu-west-2). The one routine transfer outside the UK is to OpenAI in the United States, which happens when a message is sent to the model to generate a reply or an embedding. That transfer is covered by OpenAI's data processing addendum, which includes the EU Standard Contractual Clauses with the UK International Data Transfer Addendum. Meta processes WhatsApp messages on its global infrastructure under its own transfer terms.
Under OpenAI's API policy, data submitted through the API is not used to train its models. We do not use your data, or your customers' data, to train any model.
If there is a personal data breach affecting the data we process for you, we will notify you without undue delay after becoming aware of it, with the detail you need to meet your own 72-hour reporting duty to the ICO — what happened, who is likely affected, what the likely consequences are, and what we are doing about it. We will keep you updated as we learn more.
This DPA forms part of the Terms of Service. If there is a conflict on data protection specifically, this DPA wins; on everything else, the Terms win. Each party's liability under this DPA is subject to the limitation of liability in section 9 of the Terms of Service — this DPA does not create a separate or higher cap. Nothing here limits any liability that cannot be limited by law, including a data subject's rights under the UK GDPR.
This DPA is governed by the laws of England & Wales, subject to the non-exclusive jurisdiction of its courts.
Email: hello@botsquirrel.com · WhatsApp: +44 7472 323783
Formal notices under this DPA: BotSquirrel Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, or by email to hello@botsquirrel.com.