Skip to content

Data processing agreement

How we process personal data in your conversations, on your behalf.

Assay is provided by Ferrolo, referred to here as “we”, “us” and “our”. Questions about this document go to assay@ferrolo.com.

1. Scope and roles

This agreement forms part of our terms of service. It applies to personal data in Customer Data that we process for you through Assay (“Customer Personal Data”). You are the controller and we are your processor. Terms not defined here have the meaning given in the UK GDPR, and the EU GDPR where it applies.

2. Your instructions

We process Customer Personal Data only on your documented instructions. By using Assay you instruct us to process it to provide, secure, support and improve the service as described in our terms, including creating aggregated and de-identified data, and to follow the settings and integrations you choose.

We will tell you if we believe an instruction breaks data protection law, and may refuse it. We may process Customer Personal Data where the law requires us to, and will tell you first unless the law forbids it.

3. Details of the processing

  • Subject matter and purpose: checking conversations against your rules, showing results and evidence, review, reporting, coaching, integrations, and improving the service.
  • Duration: for as long as you use the service, and until deletion under section 10.
  • Data subjects: your customers and other people in your conversations, your agents and staff, and your users.
  • Types of data: names, contact details, account references and anything else said or written in the conversations you send, plus reviews, notes and reasons your users add.
  • Special category data: not intended. If it appears in a conversation, you are responsible for having a lawful basis to share it.

4. Our people

Everyone we authorise to process Customer Personal Data is bound by confidentiality, and only those who need access for their work have it.

5. Security

We keep appropriate technical and organisational measures in place, and may improve them over time without lowering overall protection. They include:

  • encryption in transit and at rest;
  • each organisation’s data kept apart and every request checked against the organisation it belongs to;
  • role-based access, two-factor sign-in and passkeys;
  • an audit trail of changes and of every decision on a result;
  • backups, monitoring and a process for handling incidents.

6. Sub-processors

You give general authorisation for us to use sub-processors. Current categories are hosting and databases, file storage, AI processing, email delivery and payments. We will give you the current list on request.

We tell you about intended changes to our sub-processors by updating that list. You may object on reasonable data protection grounds; if we can’t address the objection, your only remedy is to cancel your plan, which ends at the end of the period you have paid for.

Each sub-processor is bound by data protection terms at least as protective as these. We remain responsible for their performance. AI processing providers are not permitted to use Customer Personal Data to train their models.

7. International transfers

Where Customer Personal Data is transferred outside the UK or EEA, we rely on an adequacy decision or on the UK International Data Transfer Addendum or EU standard contractual clauses, which you authorise us to enter into on your behalf where needed.

8. Helping you

Taking into account the nature of the processing, we will reasonably help you respond to requests from data subjects and with impact assessments and consultations with regulators. Most requests can be handled with Assay’s own tools, such as deleting a conversation. We may charge reasonable costs for help that goes beyond this.

9. Personal data breaches

We will tell you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your own obligations, and will take reasonable steps to contain it.

10. Return and deletion

When the agreement ends you may ask us to export Customer Personal Data within 30 days. After that we delete it within 90 days, except where the law requires us to keep it. Copies in backups are deleted as the backups expire. Aggregated and de-identified data is not Customer Personal Data and is not deleted.

11. Information and audits

We will make available the information reasonably needed to show we meet this agreement, starting with our security overview and answers to reasonable questionnaires. If that is not enough, or a regulator requires it, you may carry out an audit once a year, with 30 days’ notice, during business hours, at your cost, and under confidentiality.

12. Liability and precedence

The limits and exclusions of liability in our terms of service apply to this agreement. On matters of personal data, this agreement takes precedence over the terms of service.

We may update this agreement at any time. The updated version applies from when it is published here, and will always meet what data protection law requires of a processor.