Legal
Data processing addendum
For business customers who need a DPA in place. This sets out how we process personal data on your behalf under UK and EU GDPR — in plain language, with the formal terms behind it.
Last updated .
When this applies
This Data Processing Addendum (“DPA”) forms part of the agreement between you (the controller) and vocabotics (the processor) where we process personal data on your behalf in providing the service — for example, when your team and the people you bring into the platform use it. It applies in addition to our terms of service and privacy policy. Where we determine the purposes of processing ourselves (for example, our own marketing), we act as a controller and the privacy policy governs instead.
Roles and scope
- You are the controller of the personal data you and your users put into the service; we are your processor for that data.
- Subject matter & duration — processing lasts for the term of your agreement, plus any retention required by law (see data handling & retention).
- Nature & purpose — providing AI advice, training, content and the DIAGNOSE features you use.
- Types of data — identifiers and contact details, account data, and business information your users choose to submit. Please don’t submit special-category data unless we’ve agreed it in writing.
- Data subjects — your staff, contractors and other authorised users.
Our obligations as processor
- Process only on your instructions — we process personal data only to provide the service and on your documented instructions, unless the law requires otherwise (in which case we’ll tell you, where permitted).
- Confidentiality — people who process your data are bound by confidentiality obligations.
- Security — we apply appropriate technical and organisational measures, as described in our data handling page (encryption, access control, tamper-evident audit logs, backups and network protection).
- Assistance — taking into account the nature of processing, we’ll help you respond to data-subject requests and meet your security, breach-notification and impact-assessment obligations.
- Breach notification — we’ll notify you without undue delay after becoming aware of a personal-data breach affecting your data.
- Deletion or return — at the end of the service we’ll delete or return your personal data, except where we must keep it by law.
- Audits — we’ll make available the information needed to demonstrate compliance and allow for reasonable audits, subject to confidentiality and notice.
Subprocessors
You give us general authorisation to engage the subprocessors listed on our subprocessor page. We impose data-protection terms on each of them no less protective than this DPA, and we remain responsible for their performance. If we intend to add or replace a subprocessor that handles your personal data, we’ll update that page; you may object on reasonable data-protection grounds.
International transfers
Your data is hosted in the EU. Where a subprocessor processes data outside the UK/EEA, the transfer is covered by an appropriate safeguard — the EU Standard Contractual Clauses and/or the UK International Data Transfer Addendum — which are incorporated into this DPA by reference for those transfers.
AI processing
Where the service uses AI to process your data, our AI subprocessors do not train their models on it, and we do not train our own models on your identifiable data without explicit consent. See the AI-use disclosure for detail.
Liability and precedence
This DPA is governed by the same law and subject to the same liability provisions as our terms of service. Where this DPA conflicts with the terms on the subject of data protection, this DPA prevails.
Requesting a signed copy
Need a countersigned DPA for your records, or have specific compliance requirements? Email privacy@vocabotics.com and we’ll arrange it.
Next step
Questions about any of this? We’d rather you ask than wonder.