Article 28 agreement
Data Processing Agreement.
This DPA forms part of the Worka Service Terms whenever Asistu processes personal data on a customer’s behalf.
Parties
The Customer identified in the Order is the “Controller”. Asistu Ltd, company number 13279968, is the “Processor”. This DPA is accepted with the Order and requires no separate signature.
1. Definitions and scope
“Data Protection Laws” means the UK GDPR, Data Protection Act 2018, PECR and other UK law applying to the processing. “Customer Personal Data” means personal data processed by Asistu on the Customer’s behalf through Worka. “Data Subject”, “Personal Data Breach”, “process”, “processor” and “controller” have the meanings in Data Protection Laws.
This DPA applies only where Asistu acts as processor. Asistu acts as controller for its own account, billing, security, legal and relationship records as explained in the Privacy Notice.
2. Roles and instructions
The Customer is controller and Asistu is processor. The Customer determines the purpose and lawful basis of Customer Personal Data and is responsible for notices, rights and the lawfulness of instructions. Asistu will process Customer Personal Data only:
- to provide, secure, support and terminate Worka under the Order and Service Terms;
- on documented instructions given through the Order, configuration, approved Worka actions, support requests or other written communication; or
- where required by UK law, in which case Asistu will inform the Customer before processing unless law prohibits it.
Asistu will immediately inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws, and may suspend that instruction while the parties address it.
3. Processing details
| Subject matter | Providing a configured AI assistant that receives instructions and content, prepares outputs, manages approved or scheduled jobs, communicates through supported channels and supplies related hosting, monitoring, support and deletion. |
|---|---|
| Duration | The contract term plus the deletion period in section 11. |
| Nature and purpose | Collection, receipt, storage, organisation, retrieval, analysis, transcription, generation, consultation, transmission, restriction, export and deletion as necessary to perform the Customer’s configured Worka jobs. |
| Data subjects | Customer personnel and authorised users; the Customer’s customers, prospects, suppliers, contractors and business contacts; people mentioned in Customer Content. |
| Personal data | Names, roles, business contact details, message identifiers, communications, correspondence, voice recordings/transcripts, files, quotes, invoices, appointment and service details, preferences, interaction history, technical and audit information, and other data chosen by the Customer. |
| Restricted data | No special-category, criminal-offence or children’s data is intended. Processing requires prior written agreement, documented necessity and added safeguards. |
| Controller rights | To determine purposes and instructions, receive compliance information, exercise audit rights, object to a new sub-processor on reasonable grounds, and request return or deletion at the end. |
4. Confidentiality and personnel
Asistu will ensure that people authorised to process Customer Personal Data are bound by contractual or statutory confidentiality, receive appropriate data-protection and security guidance, and access data only where needed for their role.
5. Security
Taking account of the state of the art, implementation cost, processing context and risk, Asistu will maintain appropriate technical and organisational measures, including where appropriate:
- logical separation of each customer runtime and data from other customers;
- least-privilege administrative access, authentication controls and managed secrets;
- encryption in transit and encryption at rest where supported by the relevant system;
- logging, monitoring, vulnerability and security-patch processes;
- backup, recovery and secure deletion procedures;
- supplier assessment, confidentiality controls and incident response;
- regular review and testing proportionate to the service risk.
The Customer is responsible for secure devices, channel accounts, access management, appropriate instructions and reviewing approved actions.
6. Sub-processors
The Customer gives general written authorisation for Asistu to use the sub-processors in the provider register. Asistu will impose data-protection terms offering materially equivalent protection and remains responsible for each sub-processor’s performance of its data-protection obligations.
Asistu will give at least 14 days’ notice of a new sub-processor that will process Customer Personal Data, normally by updating the register and emailing active customers. The Customer may object during that period on reasonable, evidenced data-protection grounds. The parties will try to resolve the concern; if no reasonable alternative is available, either party may terminate the affected feature or service without penalty, with a pro-rata refund of unused prepaid fees.
7. International transfers
Asistu will not make a restricted transfer of Customer Personal Data outside the UK except on the Customer’s documented instruction or using a lawful safeguard. Safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with a transfer risk assessment and supplementary measures where required. The Customer authorises transfers inherent in using approved sub-processors and customer-selected channels.
8. Assistance and data-subject requests
Taking account of the processing, Asistu will use appropriate measures to help the Customer respond to requests to exercise data-subject rights. If Asistu receives a request relating to Customer Personal Data, it will not respond substantively except on the Customer’s instruction or where legally required, and will forward it where reasonably identifiable.
Taking account of available information and the nature of processing, Asistu will reasonably assist the Customer with security, breach notifications, data-protection impact assessments and prior consultation with the ICO. Routine assistance is included; substantial bespoke work may be charged at a reasonable rate agreed in advance unless required because of Asistu’s breach.
9. Personal Data Breaches
Asistu will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where reasonably possible, within 48 hours. Notification will include available information about the nature of the breach, likely consequences, affected data and people, contact point and measures taken or proposed. Information may be supplied in phases. Asistu will take reasonable steps to contain, investigate and mitigate the breach.
Notification is not an admission of fault. The Customer is responsible for deciding whether to notify the ICO or data subjects, with Asistu’s required assistance.
10. Compliance information and audits
Asistu will provide information reasonably necessary to demonstrate compliance with Article 28. It may first satisfy an audit request with current security documentation, questionnaires, summaries or independent reports.
If reasonably necessary, the Customer may conduct one audit in any 12-month period on at least 20 working days’ notice, during normal hours, without accessing another customer’s information or compromising security. Additional audits are allowed following a relevant breach or regulator request. The Customer bears its audit costs unless the audit identifies a material breach by Asistu. Auditors must be independent, suitably qualified, non-competitive and bound by confidentiality.
11. Return and deletion
Before termination takes effect, the Customer may request a reasonable export of Customer Personal Data in a commonly used format where technically available. At the Customer’s choice, Asistu will then delete or return Customer Personal Data and delete existing copies, unless UK law requires retention. If no choice is communicated, Asistu will delete it.
Active customer environments will be destroyed promptly after the service ends. Residual copies in disaster-recovery backups will expire within 30 days and remain protected and unavailable for ordinary use until deletion. Asistu may retain data it holds as controller under its Privacy Notice.
12. Liability, priority and changes
The liability provisions in the Service Terms apply to this DPA. If this DPA conflicts with the Service Terms on processing Customer Personal Data, this DPA prevails. We may update this DPA where necessary to reflect Data Protection Laws, provided the update does not materially reduce protection; material changes will be notified under the Service Terms.