Data processing agreement
Last updated 4 October 2026
Draft, to be reviewed by a solicitor before launch. This page is a
working draft and is not yet a binding document.
This agreement forms part of the terms of service between your business and [Company name] Ltd, trading as Threadkite. It applies to personal data we process on your behalf.
Roles
You are the controller of your customers’ personal data. We are the processor and act only on your documented instructions, which are the terms, this agreement and your use of the product.
What we process
- Data subjects: your customers and prospects, and your staff.
- Data: names, contact details, messages, call recordings and transcripts, notes, and details of items they are interested in.
- Purpose: to provide the Threadkite service to you.
Our commitments
- Keep the data confidential and limit access to staff who need it.
- Store it in your organisation’s data region (the UK for UK accounts).
- Protect it with appropriate technical and organisational measures, including encryption in transit and at rest, access control and audit logging.
- Help you respond to requests from your customers, including erasure and export.
- Tell you without undue delay if we become aware of a personal data breach.
- Use only the sub-processors we list, and tell you before adding new ones.
- Delete or return the data when you close your account, after a 30-day grace period.
Providers you connect
Providers you connect yourself, such as Twilio, Meta or RingCentral, act on your behalf under your own agreement with them. They are not our sub-processors.
[To be completed by a solicitor: audit rights, international transfer mechanisms (UK IDTA or addendum), liability, and the full description of security measures.]