Data Processing Agreement

Last updated: 18 September 2026

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between FrontDesk AI (“we”, “us”, the “Processor”) and the business that uses the Service (“you”, the “Customer”, the “Controller”). It governs our processing of personal data contained in the conversations and customer records handled through your account (“Customer Personal Data”), where you act as the controller and we act as your processor under the General Data Protection Regulation (GDPR) and equivalent data protection laws.

For your own account, billing and website-usage data, we act as the controller; that processing is described in our Privacy Policy. This DPA concerns only the Customer Personal Data we process on your behalf.

1. Subject matter and duration

We process Customer Personal Data for the purpose of providing the Service for the duration of your subscription. On termination or expiry of your subscription, we retain Customer Personal Data for a short wind-down window and then permanently delete it 30 days after cancellation, except for the limited billing records we are legally required to keep.

2. Nature and purpose of processing

We process Customer Personal Data to operate the AI receptionist on your behalf: to receive and respond to messages from your customers, capture leads and booking requests, and make that information available to you in your dashboard. Processing consists of collection, storage, organisation, use, transmission to our sub-processors for AI responses, and deletion.

3. Types of personal data

The Customer Personal Data we process on your behalf may include:

  • identifiers such as names, email addresses and phone numbers your customers provide;
  • lead records created from conversations with the AI receptionist (name and contact details);
  • booking, appointment and enquiry details captured in those conversations, and the knowledge base you configure. The message-by-message conversation is processed to create these records but is not retained as a stored transcript.

4. Categories of data subjects

The data subjects are the individuals who interact with your AI receptionist or whose details you or your customers enter into the Service — typically your customers, prospective customers and other people who contact your business.

5. Our obligations as processor

We will:

  • process Customer Personal Data only on your documented instructions, including as set out in the Terms, this DPA and your use of the Service, unless required to do otherwise by law (in which case we will inform you, unless the law prohibits it);
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (see section 6);
  • engage sub-processors only in line with section 8;
  • taking into account the nature of the processing, assist you with appropriate measures to respond to requests from data subjects exercising their rights;
  • assist you with your obligations around security, breach notification, data protection impact assessments and prior consultation with supervisory authorities;
  • at your choice, delete or return all Customer Personal Data at the end of the provision of the Service, and delete existing copies unless legally required to keep them;
  • make available the information necessary to demonstrate compliance with these obligations and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint no more than once per year and on reasonable prior notice (or more often following a personal data breach or where required by a supervisory authority).

6. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • account passwords are stored only as a one-way hash, never in a form we can read;
  • payment card details never touch our servers — they are entered directly into Stripe's secure systems;
  • access to your data is restricted to your authenticated account, enforced on every request to our systems;
  • data is encrypted in transit using TLS (HTTPS) across the Service.

7. Personal data breach

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it, and will provide the information you reasonably need to meet your own notification obligations.

8. Sub-processors

You give us general authorisation to engage sub-processors to help provide the Service. Our current sub-processors are listed at frontdeskai.art/subprocessors. We will give you at least 30 days notice before adding or replacing a sub-processor. If you reasonably object to a new sub-processor on data protection grounds, you may raise it with us and we will work with you in good faith to resolve it; if we cannot, you may terminate your subscription and receive a pro-rata refund of any prepaid, unused fees. We remain responsible for our sub-processors' compliance with the obligations in this DPA.

9. International transfers

Where we or our sub-processors process Customer Personal Data outside the European Economic Area, we rely on appropriate safeguards for the transfer, such as the European Commission's Standard Contractual Clauses.

10. Order of precedence

This DPA forms part of the Terms of Service. In the event of any conflict between this DPA and the rest of the Terms on the subject of the processing of Customer Personal Data, this DPA prevails.

Contact

Questions about this DPA? Email us at [email protected].