Legal
Data processing addendum
Last updated
Scope and roles
This addendum applies wherever the privacy policy describes us as your processor: your end customers' conversations with the assistant you configured, and anything else you or your customers put into the platform on your instructions. For your own account and workspace data (who signs in, what you configure, your usage) we are the controller in our own right, as the privacy policy already explains, and this addendum does not change that. Terms not defined here have the meaning the privacy policy gives them.
Processing instructions
We process end-customer data only on your documented instructions: the assistant answers, acts and reaches only the systems, connectors and knowledge sources you configure for your workspace in the Console. We do not use your customers' conversations to train our own models or anyone else's, and we do not use them for any purpose of our own. If we believe an instruction would break the law, we tell you before carrying it out.
Sub-processors
The sub-processors are the same list the privacy policy publishes and keeps current: Supabase (database, auth, storage, functions), DigitalOcean (hosting and DNS), the AI model providers you enable per workspace (Anthropic, OpenAI, xAI, or your own OpenAI-compatible or self-hosted endpoint), Stripe (billing, where a plan is paid), Twilio (voice, where enabled), Telegram (hand-off, where connected), and Apple/Google (app distribution and push). Adding a sub-processor that touches conversation content is a change to that same published list; watch the privacy policy for updates, or ask us to notify you directly.
Security measures
Every conversation, published version and permission belongs to one workspace, enforced by row-level security in the database itself, not only by the application — one workspace cannot read another's rows even if a request asks for them. Credentials you give us for your own systems are write-only: once set, nobody, including us, can read them back. Before the assistant connects to a new address we check that address cannot reach anything internal. Full detail is on our security page (busymate.ai/security).
Data subject requests
If your customer contacts us directly about their data, we forward the request to you as the controller and confirm that we have, rather than acting on it ourselves. We give you the tools to fulfil a request yourself — you control the workspace's connectors and knowledge sources, and its retention setting — and we assist you with anything only we can do (for example, deleting conversation content held in our systems), consistent with the nature of the processing.
International transfers
Our primary infrastructure runs in the European Union and the United Kingdom. Where a sub-processor you enable (a model provider you choose, Stripe, Apple, Google) processes data in the United States, that transfer relies on the European Commission's Standard Contractual Clauses together with that provider's own supplementary measures. If your workspace needs transfers restricted further, choose a model provider and connectors that match your requirement — the allowed list is yours to set per workspace.
Deletion and return
Conversation data follows the retention period you set for your workspace; where you have not set one, we keep it for as long as the workspace exists so you can keep answering your own customers. Deleting your account or workspace removes its data from our live systems immediately, and backups roll off within 30 days as they naturally expire. You can export what your workspace holds at any time through the Console or the REST/MCP API rather than waiting for an off-boarding request.
Audits
We have not commissioned a third-party audit or certification (SOC 2, ISO 27001, or similar) and do not claim one. What we can show today is what is on the security page — the access controls, the isolation model, and the standards our identity and connector protocols actually implement — and a live authorization-server metadata excerpt that page reads at request time rather than typing out. For a vendor or security review beyond that, use the "Vendor / security review" reason on the contact page.