Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Controller”) and ASTROX TECHNOLOGIES LTD (“Processor”), and sets out how we process personal data on your behalf in connection with the AstroX platform.
1. Definitions
In this DPA:
- “Controller” means you, the business customer who signs up for and uses the AstroX platform.
- “Processor” means ASTROX TECHNOLOGIES LTD, which processes personal data on behalf of the Controller.
- “Data Subjects” means your end-customers whose personal data is processed through the platform (e.g., shoppers who interact with your AI agent).
- “Personal Data” has the meaning given in UK GDPR.
- “Sub-processor” means any third-party service provider we engage to assist in processing personal data.
- “UK GDPR” means the UK General Data Protection Regulation as retained in UK law by the Data Protection Act 2018. Where personal data of data subjects in the European Economic Area is processed, references to UK GDPR include, where applicable, the EU GDPR.
2. Roles and relationship
You are the data controller for personal data relating to your end-customers. We are the data processor acting on your documented instructions. Each party is separately responsible for its own compliance with UK GDPR in respect of the data it controls.
For personal data we collect about you as a platform user (account data, billing, usage), we are the controller — see our Privacy Policy.
3. Details of processing
The following describes the processing we carry out on your behalf:
| Category | Details |
|---|---|
| Purpose | Providing the AstroX AI agent service: handling, storing, and processing customer conversations and related data on your behalf. |
| Nature | Receiving, storing, analysing, and transmitting personal data through the AI agent platform; generating AI responses; routing escalations to human agents. |
| Data types | Names, contact details (phone number, email, WhatsApp ID), order details, conversation content, and other data your customers share via the AI agent. |
| Data subjects | Your end-customers (individuals who interact with your AI agent). |
| Retention | Conversation and handoff logs are retained for the life of the subscription, then deleted after cancellation according to your plan: Starter and Growth within 30 days, Scale within 90 days, Enterprise within 365 days of cancellation, or such other period as agreed in writing in your order form, in each case no longer than necessary for the purposes of the processing in line with the storage-limitation principle, and except where a longer period is required by law, regulatory obligation, or an active dispute. |
4. Our obligations as processor
We will:
- Process personal data only on your documented instructions, including as described in the Terms of Service and this DPA, unless required by law to do otherwise.
- Ensure that our staff who access personal data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction (see Section 7).
- Not engage sub-processors without your prior general authorisation (granted by accepting these Terms) and subject to the requirements in Section 6.
- Provide reasonable assistance to you in responding to data subject requests, data protection impact assessments, and regulatory enquiries.
- Notify you without undue delay after becoming aware of a personal data breach affecting your end-customers' personal data and, where feasible, within 72 hours of becoming aware, with the information reasonably available to us at that time; further details will follow in phases as our investigation progresses. Our notification is not an admission of fault or liability.
- At your request, delete or return all personal data after the end of services, and delete existing copies unless retention is required by law.
- Provide you with information reasonably necessary to demonstrate our compliance with this DPA, including supporting audits conducted by you or an authorised auditor (subject to reasonable advance notice and confidentiality protections).
5. Your obligations as controller
You are responsible for:
- Ensuring you have a lawful basis for processing your end-customers' personal data through the platform.
- Providing your end-customers with appropriate privacy notices describing how their data is processed.
- Ensuring your instructions to us comply with applicable data protection law.
- Notifying us promptly of any data subject requests you receive that we need to assist with.
- Keeping your account credentials secure and restricting platform access to authorised users only.
6. Sub-processors
You authorise us to engage the following categories of sub-processors to assist in providing the service. The notice and objection process for new sub-processors is set out below.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider (name and current hosting regions available on request at support@astroxtech.com) | Infrastructure hosting and data storage | Vetted cloud regions; where located outside the UK/EEA, UK IDTA / SCC safeguards apply (s.8) |
| OpenAI, Inc. | AI model processing to generate agent responses and two-way conversation translation in the agent inbox | USA |
| Meta Platforms (WhatsApp Business Cloud API) | WhatsApp message delivery (under your own Meta Business account — BYOA) | EU / USA |
| Shopify Inc. | eCommerce store data integration (at your direction) | USA / Canada |
| Stripe, Inc. | Payment processing; holds billing contact information for your account | USA (PCI-DSS compliant; UK IDTA / Standard Contractual Clauses) |
| Transactional email provider (name available on request) | Sending account notifications, billing receipts, and system emails | EU / USA (details available on request) |
| Cloudflare, Inc. | Website delivery (CDN), DDoS protection, and DNS | USA / Global (Standard Contractual Clauses) |
We require all sub-processors to enter into data processing agreements with us that provide equivalent protections to those in this DPA. A full and current list of sub-processors is available on request at support@astroxtech.com.
New sub-processors: We will notify you by email to your account address before engaging a new sub-processor that will process your end-customers' personal data — ordinarily at least 30 days in advance, or as soon as practicable where the change is required urgently for security, legal, or service-continuity reasons. If you reasonably object on data-protection grounds within 14 days of our notice, we will discuss the objection in good faith. If we cannot provide the Services without the new sub-processor and the objection cannot be resolved, you may terminate the affected subscription before the change takes effect, and we will refund pro rata any subscription fees prepaid for the period after termination (excluding top-up credits and add-ons already consumed). This is your sole remedy in respect of a sub-processor change.
AI model training: We use OpenAI's API under its business terms to power AI agent responses and inbox translation. OpenAI's published API data-usage policy states that API inputs and outputs are not used to train OpenAI's models and are retained only for a limited period for abuse monitoring and legal compliance (currently up to 30 days). We rely on OpenAI's published policy and our agreement with OpenAI; we do not control OpenAI's practices and will update this DPA if they change materially. For the current OpenAI API data usage policy, see openai.com/policies/api-data-usage-policies.
7. Security measures
We implement and maintain technical and organisational measures appropriate to the risk of the processing, which currently include:
- Encryption: Data encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption (such as AES-256) provided by our cloud providers.
- Access control: Role-based access control; staff access limited to what is necessary for their role.
- Authentication: Multi-factor authentication for our internal administrative access where supported by the relevant system.
- Vulnerability management: Regular security reviews and dependency updates.
- Incident response: Documented procedures for detecting, containing, and reporting data breaches.
- Backups: Regular encrypted backups with tested recovery procedures.
- Vendor security: Due diligence on sub-processors' security practices before engagement.
We may update these measures over time provided the overall level of security is not materially reduced.
8. International transfers
Where personal data is transferred to sub-processors outside the UK or EEA (e.g., OpenAI in the USA), we rely on appropriate transfer mechanisms, including the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses, or adequacy decisions as applicable.
9. Data subject rights
If a data subject (your end-customer) contacts you to exercise their rights under UK GDPR (access, rectification, erasure, portability, etc.), we will provide reasonable assistance to help you fulfil those requests. Contact us at support@astroxtech.com.
10. Data breaches
If we become aware of a personal data breach affecting data we process on your behalf, we will:
- Notify you without undue delay after becoming aware and, where feasible, within 72 hours of becoming aware, with the information reasonably available to us at that time; further details will follow in phases as our investigation progresses. Our notification is not an admission of fault or liability.
- Provide details of the nature of the breach, the data and data subjects involved (where known), and the likely consequences.
- Describe the measures taken or proposed to address the breach.
You remain responsible for notifying the ICO and affected data subjects where required.
11. Audit rights
You may request information to verify our compliance with this DPA, subject to the following conditions:
- Frequency: Audit rights may be exercised no more than once per 12-month period, except where a material data breach or confirmed compliance failure has occurred.
- Questionnaire first: We will first respond to written compliance questionnaires, provide relevant certifications, security documentation, or third-party audit summaries. An on-site or system audit is only required if our documentary response is materially insufficient to address a specific confirmed compliance concern.
- Notice: You must give at least 30 days' written notice before commencing any audit.
- Scope restrictions: Any audit must not: (a) access, inspect, or expose data belonging to other customers; (b) involve direct access to production systems or databases; (c) involve penetration testing or vulnerability scanning without separate written agreement.
- Confidentiality: All audit findings and information obtained must be treated as confidential and used only to verify compliance with this DPA.
- Costs: Costs of audits are borne by you unless the audit reveals a material breach on our part.
12. Term and termination
This DPA remains in effect for as long as we process personal data on your behalf under the Terms of Service. On termination of the Terms, we will delete or return your data as described in Section 3 (Retention) and our standard data deletion procedures.
13. Governing law
This DPA is governed by the laws of England and Wales. Any disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.
14. Contact
For data protection enquiries under this DPA: support@astroxtech.com
ASTROX TECHNOLOGIES LTD (Company No. 16584933), registered in England and Wales; registered office address as recorded at Companies House.
Language: This DPA is drafted in English, and the English text is the sole binding version; any translation or summary is for convenience only.
Document History
| Version | Effective Date | Summary of changes |
|---|---|---|
| 1.5 | 2 September 2026 | Retention wording aligned with the storage-limitation principle (s.3); breach notification clarified as from awareness, phased, and not an admission (s.4, s.10); sub-processor notice and objection process stated once, with termination and pro-rata refund as sole remedy (s.6); OpenAI training and retention described by reference to OpenAI's published policy (s.6); security measures described as appropriate-to-risk current measures (s.7); language statement and registered company details (s.14). |
| 1.4 | 9 August 2026 | Retention schedule aligned with the published post-cancellation periods — logs kept for the life of the subscription, deleted within 30/30/90/365 days of cancellation by plan (s.3); CookieYes removed from sub-processor table — consent notice is provided natively (s.6); cloud hosting location wording aligned with transfer safeguards (s.6); OpenAI purpose extended to cover inbox conversation translation (s.6); EU GDPR applicability noted in definitions (s.1). |
| 1.3 | 14 March 2026 | Added Cloudflare, Inc. and CookieYes to sub-processor table (s.6). |
| 1.2 | 14 March 2026 | Restricted audit rights: max once/year, questionnaire-first, no production access, no cross-tenant data (s.11); added sub-processor objection process and termination right (s.6); added OpenAI no-training disclosure (s.6). |
| 1.1 | 14 March 2026 | Added Stripe, Inc. and transactional email provider to sub-processor table; noted full sub-processor list available on request; updated cloud host row. |
| 1.0 | January 2026 | Initial release. |