Assay is provided by Ferrolo, referred to here as “we”, “us” and “our”. Questions about this document go to assay@ferrolo.com.
1. Scope and roles
This agreement forms part of our terms of service. It applies to personal data in Customer Data that we process for you through Assay (“Customer Personal Data”). You are the controller and we are your processor. Terms not defined here have the meaning given in the UK GDPR, and the EU GDPR where it applies.
2. Your instructions
We process Customer Personal Data only on your documented instructions. By using Assay you instruct us to process it to provide, secure, support and improve the service as described in our terms, including creating aggregated and de-identified data, and to follow the settings and integrations you choose.
We will tell you if we believe an instruction breaks data protection law, and may refuse it. We may process Customer Personal Data where the law requires us to, and will tell you first unless the law forbids it.
3. Details of the processing
- Subject matter and purpose: checking conversations against your rules, showing results and evidence, review, reporting, coaching, integrations, and improving the service.
- Duration: for as long as you use the service, and until deletion under section 10.
- Data subjects: your customers and other people in your conversations, your agents and staff, and your users.
- Types of data: names, contact details, account references and anything else said or written in the conversations you send, plus reviews, notes and reasons your users add.
- Special category data: not intended. If it appears in a conversation, you are responsible for having a lawful basis to share it.
4. Our people
Everyone we authorise to process Customer Personal Data is bound by confidentiality, and only those who need access for their work have it.
5. Security
We keep appropriate technical and organisational measures in place, and may improve them over time without lowering overall protection. They include:
- encryption in transit and at rest;
- each organisation’s data kept apart and every request checked against the organisation it belongs to;
- role-based access, two-factor sign-in and passkeys;
- an audit trail of changes and of every decision on a result;
- backups, monitoring and a process for handling incidents.
6. Sub-processors
You give general authorisation for us to use sub-processors. Current categories are hosting and databases, file storage, AI processing, email delivery and payments. We will give you the current list on request.
We tell you about intended changes to our sub-processors by updating that list. You may object on reasonable data protection grounds; if we can’t address the objection, your only remedy is to cancel your plan, which ends at the end of the period you have paid for.
Each sub-processor is bound by data protection terms at least as protective as these. We remain responsible for their performance. AI processing providers are not permitted to use Customer Personal Data to train their models.
7. International transfers
Where Customer Personal Data is transferred outside the UK or EEA, we rely on an adequacy decision or on the UK International Data Transfer Addendum or EU standard contractual clauses, which you authorise us to enter into on your behalf where needed.
8. Helping you
Taking into account the nature of the processing, we will reasonably help you respond to requests from data subjects and with impact assessments and consultations with regulators. Most requests can be handled with Assay’s own tools, such as deleting a conversation. We may charge reasonable costs for help that goes beyond this.
9. Personal data breaches
We will tell you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your own obligations, and will take reasonable steps to contain it.
10. Return and deletion
When the agreement ends you may ask us to export Customer Personal Data within 30 days. After that we delete it within 90 days, except where the law requires us to keep it. Copies in backups are deleted as the backups expire. Aggregated and de-identified data is not Customer Personal Data and is not deleted.
11. Information and audits
We will make available the information reasonably needed to show we meet this agreement, starting with our security overview and answers to reasonable questionnaires. If that is not enough, or a regulator requires it, you may carry out an audit once a year, with 30 days’ notice, during business hours, at your cost, and under confidentiality.
12. Liability and precedence
The limits and exclusions of liability in our terms of service apply to this agreement. On matters of personal data, this agreement takes precedence over the terms of service.
We may update this agreement at any time. The updated version applies from when it is published here, and will always meet what data protection law requires of a processor.