Legal
Data Processing Agreement
Last updated: 24 September 2026
1. Parties and scope
This Data Processing Agreement ("DPA") is between:
- the customer that accepted the Andy Partner Terms of Service ("Customer"), as controller; and
- Andesphere Ltd, company number 16350517, registered office 169 Westbourne Grove, Westcliff-on-Sea SS0 9TX, United Kingdom ("Andesphere"), as processor.
It forms part of the Terms of Service ("Terms"). It applies when Andesphere processes Customer Personal Data to provide Andy Partner. If this DPA and the Terms conflict on data protection, this DPA wins.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and, where they apply to the Customer, the EU GDPR and other national data protection laws. "Customer Personal Data" means personal data that Andesphere processes for the Customer under the Terms. Other terms (such as "controller", "processor", "personal data breach" and "data subject") have the meanings given in the UK GDPR.
This DPA does not cover data Andesphere controls itself, such as account holder data, billing records and security logs. The Privacy Notice covers that data.
2. Andesphere's obligations (UK GDPR Article 28(3))
Andesphere will:
- Instructions. Process Customer Personal Data only on the Customer's documented instructions, including for transfers outside the UK, unless the law requires otherwise. If so, Andesphere will tell the Customer first, unless the law forbids it. The Terms, this DPA and the Customer's settings and use of the service are the Customer's instructions. Andesphere will tell the Customer if it thinks an instruction breaks Data Protection Law.
- Confidentiality. Make sure anyone it authorises to process Customer Personal Data is bound by confidentiality.
- Security. Take the measures required by UK GDPR Article 32, including those in Annex 2.
- Sub-processors. Follow section 3.
- Data subject rights. Taking into account the nature of the processing, help the Customer, by appropriate technical and organisational measures, to respond to data subject requests. If Andesphere receives a request directly, it will pass it to the Customer and will not answer it except on the Customer's instructions.
- Other help. Help the Customer meet its duties under UK GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Andesphere.
- Deletion or return. When the Terms end, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless the law requires Andesphere to keep them. See section 6.
- Information and audits. Make available the information needed to show compliance with this section, and allow for and contribute to audits, including inspections, by the Customer or an auditor it appoints. See section 7.
No other use. Andesphere will not use Customer Personal Data to train AI models, will not use it in any other Andesphere product, and will not sell it.
3. Sub-processors
- General authorisation. The Customer gives general authorisation for Andesphere to engage sub-processors. The current list is on the sub-processors page.
- Notice of changes. Andesphere will give at least 30 days' notice before adding or replacing a sub-processor. It will update the list and email the Customer's account owner.
- Objection. The Customer may object on reasonable data protection grounds within those 30 days by emailing support@andesphere.com. The parties will discuss it in good faith. If they cannot resolve it, the Customer may end the Terms and get a pro-rata refund of prepaid fees for the rest of its term.
- Flow-down. Andesphere will impose data protection obligations on each sub-processor that give the same level of protection as this DPA. Andesphere remains liable to the Customer for its sub-processors' performance.
- Emergency changes. If Andesphere must replace a sub-processor urgently for security or continuity, it will give notice as soon as it can.
4. Personal data breaches
Andesphere will tell the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. It will give the information the Customer reasonably needs to meet its own duties, as it becomes available. It will take reasonable steps to contain the breach and reduce its effects.
5. International transfers
Andesphere may transfer Customer Personal Data outside the UK to its sub-processors. Where the destination has no UK adequacy regulations, Andesphere will make sure a valid safeguard is in place: the UK Extension to the EU-US Data Privacy Framework, the ICO's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
6. Deletion and retention
- During the Terms, the Customer can delete agents, conversations and documents in the app. A deleted agent is removed permanently 7 days after deletion, with its documents, recordings, messages, leads and related records.
- Conversations, contacts and leads have no fixed maximum period. They stay while the agent exists, unless the Customer deletes them sooner.
- When the Customer deletes its account, the workspaces it owns alone are archived, not deleted. Nothing deletes archived workspaces automatically. To end processing for good, the Customer emails support@andesphere.com and asks Andesphere to delete, or return a copy of, the Customer Personal Data. Andesphere completes the deletion within 30 days of verifying the request.
- Copies in providers' backups are deleted in their normal backup cycles.
- Andesphere may keep data where the law requires, and anonymised statistics that no longer identify anyone.
7. Audits
Andesphere will answer reasonable written questions about its compliance. The Customer may carry out an audit, or have an independent auditor do so, no more than once a year, with 30 days' notice, during business hours and at its own cost. Extra audits are allowed after a personal data breach or where a regulator requires one. Auditors must sign a confidentiality agreement.
8. Liability
Each party's liability under this DPA is subject to the limits in the Terms.
9. WhatsApp Direct
If the Customer connects WhatsApp Direct, Andy links the Customer's number the way WhatsApp Web links a device, using third-party open-source software. WhatsApp Direct is unofficial and Meta has not approved it. WhatsApp may restrict or permanently ban a number connected this way, without warning. Section 8 of the Terms sets out these risks, which the Customer accepts by choosing this connection. Customer Personal Data carried over WhatsApp Direct is processed under this DPA like data from any other channel. The bridge that runs it is listed on the sub-processors page.
10. Duration, law and courts
This DPA lasts as long as Andesphere processes Customer Personal Data. It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: Details of processing
Subject matter. Providing Andy Partner: AI agents that answer the Customer's end customers across messaging and voice channels, capture leads, book appointments and hand conversations to the Customer's team.
Duration. The term of the Terms, plus the deletion period in section 6.
Nature of processing. Collection through connected channels, storage, organisation, retrieval, analysis by AI models to generate replies, conversation titles and insights, transcription of voice notes and calls, transmission of replies, calendar booking, notifications to the Customer's team, and deletion.
Purpose. To provide the service to the Customer under the Terms and the Customer's instructions.
Data subjects.
- The Customer's end customers and prospects who message or call the Customer's agents.
- Visitors to the Customer's website who use the chat widget.
- People named in the Customer's knowledge documents, calendar events or uploaded files.
- The Customer's staff who take part in conversations or handoffs.
Categories of personal data.
- Contact and identity data: name, phone number, email address, company, WhatsApp name and profile picture, Instagram username, name and profile picture.
- Message content: text, voice notes and their transcripts, images and files sent in conversations.
- Voice call audio and transcripts, where the Customer turns on voice and recording.
- Lead data: interest level, notes, status, source and a summary of the conversation.
- Appointment data: date, time, service and attendee details.
- Technical data of widget visitors: approximate location from IP address, device, operating system, browser, language.
- Any other personal data end customers choose to share in a conversation.
Special category data. Not intended. End customers may still share it in messages without being asked. The Customer must not set up agents to collect it unless the law allows it (see section 7 of the Terms).
Frequency. Continuous, while the Customer's agents are active.
Retention. See section 6 and the Privacy Notice.
Annex 2: Security measures
These measures are in place today. Andesphere holds no security certification.
- Encrypted credentials. Channel access tokens and integration secrets (WhatsApp, Instagram, Slack) are stored encrypted with AES-256-GCM.
- WhatsApp Direct bridge. Session keys and messages waiting for delivery are encrypted with AES-256-GCM. Queued messages are deleted after delivery. The bridge runs in the Netherlands, and its hosting provider keeps backups of its database.
- Authentication. Account sign-in is handled by a dedicated authentication provider (Clerk).
- Access control. Data is separated by workspace. Server functions check workspace membership and role before reading or changing an agent's data.
- API keys. Stored as hashes, not in plain text. Keys are revoked when their workspace is archived.
- Webhook verification. Incoming webhooks from Meta (WhatsApp and Instagram), Slack, Clerk and ElevenLabs are checked against the provider's signature.
- Rate limiting. Server-side rate limits protect against abuse.
- Short-lived event data. Raw incoming channel events are deleted after 24 hours.
- Monitoring with privacy defaults. Error monitoring does not send default personal data. Error session replays hide all text and inputs and block media. Product analytics recordings hide on-screen text.
- Transport. The app and API are served over HTTPS.
Annex 3: Sub-processors
See the sub-processors page.