Legal

Data Processing Agreement

The Article 28 terms that apply when Holp processes personal data on your behalf.

Start here

The short version.

  • When your assistant talks to your website visitors, you are the controller and we are your processor.
  • UK GDPR Article 28 requires that relationship to be in writing. This is that document.
  • It lists every sub-processor and what each one does, sets out how we secure data, and says what happens when you leave.
  • It forms part of the subscriber terms, and on data protection it takes precedence over them.

You do not need to sign anything separately: this agreement applies automatically from the moment you start using Holp to process personal data. If your procurement process needs a countersigned copy, email [email protected] and we will send one.

In this document, “you” means the Holp customer, “we” and “Holp” mean Holp Ltd, and the terms “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” carry the meanings given to them in UK GDPR.

1. Roles, scope and duration

Who is what

For conversations between your assistant and your website visitors, and for the knowledge content you upload, you are the controller and Holp is your processor. You decide what the assistant knows, how long conversations are kept and who on your team reads them. We process that data only on your instructions.

Separately, we are a controller in our own right for your account, billing and support records. That processing is not covered by this agreement; it is covered by the privacy policy.

Your instructions

Your documented instructions are: this agreement, the subscriber terms, and the settings and configuration you choose inside the product, including the retention window you set on each assistant. We will not process personal data for any other purpose. If we think an instruction breaches data protection law, we will tell you promptly and may pause that processing until it is resolved.

How long it lasts

This agreement starts when you first use Holp to process personal data and runs for as long as we hold personal data on your behalf, which is a little longer than your subscription because of the deletion windows in section 8.

2. What we process for you

Article 28(3) requires this to be set out specifically rather than described in general terms, so here it is.

Detail
Subject matter Providing the Holp AI assistant service to you.
Nature and purpose Collecting, storing, indexing, retrieving and analysing content and conversations so that an assistant can answer questions on your website, and so you can review what it said.
Duration For as long as your account is open, plus the deletion windows in section 8.
Types of personal data Chat messages and the assistant’s replies, including anything a visitor chooses to type. Contact details a visitor submits through lead capture: name, email address, phone number and company. Technical data: a shortened IP address (we remove the last part, keeping the /24 network for IPv4 or the /48 prefix for IPv6, so it points at a network rather than a device), browser user agent, and the town and country derived from that shortened address. A hashed browser token used to group a returning visitor’s conversations. Conversation summaries and the analytics shown on your dashboard. Plus any personal data contained in the knowledge content you upload.
Categories of data subject Your website visitors and prospective customers, and anyone your visitors mention in a conversation.
Special category data Not requested and not required. We tell visitors not to type sensitive information into a chat box, but we cannot stop them, so you should not rely on the chat as a channel for it.
Children Holp is not directed at children and we do not knowingly process their data. If your own audience includes children, that is a controller decision for you to assess.

3. Our obligations

We will:

  • Process personal data only on your documented instructions, including for transfers out of the UK, unless the law requires otherwise, in which case we will tell you first unless the law prohibits it.
  • Make sure everyone we authorise to process your data is under a duty of confidentiality, and that access is limited to those who need it to do their job.
  • Put in place the security measures in section 5, as required by Article 32.
  • Respect the sub-processor conditions in section 4.
  • Help you respond to data subjects who exercise their rights, taking into account the nature of the processing. In practice you can find, export and delete conversations yourself from the Conversations screen, and where you cannot, we will do it for you.
  • Help you meet your own obligations under Articles 32 to 36: security, breach notification, data protection impact assessments and prior consultation with the ICO.
  • Delete or return personal data at the end of the agreement, as set out in section 8.
  • Make available the information you need to demonstrate compliance, and submit to audits, as set out in section 9.

We will not sell your data, share it for advertising, or use it to train AI models. Neither will the AI providers: we hold zero data retention terms with them.

4. Sub-processors

You give us general authorisation to use the sub-processors listed below. Each is bound by written terms that are no less protective than this agreement, and we remain fully liable to you for what they do.

Sub-processor What they do Where
Amazon Web Services Cloud hosting and databases, in the London region (eu-west-2) United Kingdom
OpenAI Generates the assistant’s answers United States
Anthropic Generates the assistant’s answers, as the alternative model provider United States
Pinecone The search index that finds the right passage of your knowledge to answer from United States
Jina AI Reads the pages and PDFs you add to an assistant’s knowledge Germany
Exa Web search, when an assistant needs to look something up United States
Tavily Backup web search, used when Exa is unavailable United States
Stripe Payments and subscriptions Ireland and United States
Mailgun Sends transactional email United States
ip-api.com Turns the shortened IP address into a town and country Germany
Cloudflare Bot protection on public forms United States
Sentry Error monitoring United States

Changing the list

We will give you at least 30 days’ notice by email before adding or replacing a sub-processor that handles personal data on your behalf. Within those 30 days you may object on reasonable data protection grounds. We will work with you to find a way round it, and if we cannot, you may terminate the affected part of the service without penalty and we will refund the unused portion of what you have paid.

5. Security

Taking into account the state of the art, the cost of implementation, and the risk to the people whose data this is, we maintain the following technical and organisational measures.

Area Measure
Encryption Personal data is encrypted in transit using TLS, and encrypted at rest in our databases.
Authentication Account passwords are stored hashed and are never readable by us. Optional sign-in through Google is available.
Access control Access to production data is limited to the people who need it for their role, and is logged.
Separation Each customer workspace is logically separated. One customer cannot reach another’s conversations or knowledge.
Data minimisation Visitor IP addresses are shortened before they are stored or sent anywhere, keeping the /24 network for IPv4 or the /48 prefix for IPv6. Returning visitors are grouped by a hashed browser token rather than anything identifying. Card details never reach our systems.
Abuse prevention Bot protection on public forms, and rate limiting on the API.
Resilience Regular backups, with restoration tested.
People Everyone with access is under a written confidentiality obligation.

We review these measures periodically and may improve them, but we will not reduce the overall level of security during the term of this agreement.

6. Personal data breaches

If a personal data breach affects data we process for you, we will tell you without undue delay, and in any event within 48 hours of becoming aware of it.

We will tell you what we know at the time: what happened, which categories of data and roughly how many people are affected, what the likely consequences are, and what we are doing about it. Where we cannot give you everything at once, we will send it in stages rather than wait until the picture is complete.

Deciding whether to notify the ICO or the affected individuals is your call as controller, and the clock on your own 72-hour obligation is yours to manage. We will give you the information you need to make that decision and to make the notification.

We will not make a public statement identifying you in connection with a breach without discussing it with you first, unless the law requires it.

7. International transfers

Everything we store in the platform is hosted in the United Kingdom. The transfers out of the UK are the ones you can see in the sub-processor table in section 4, and they happen because the AI models, the search index and some supporting services are operated abroad.

For those transfers we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment covering the safeguards each provider has in place. If a transfer mechanism we rely on is invalidated, we will work with you on a replacement without undue delay, and if there is not one, you may terminate the affected part of the service.

If you have seen a UK supplier cite “Standard Contractual Clauses” on their own, that is the EU mechanism. UK transfers need the IDTA or the Addendum, which is why this document names them.

8. Deletion and return

While your account is open

You control retention. Conversations can be deleted at any time from the dashboard, and each assistant can be given a retention window: keep conversations forever, or for 30, 60 or 90 days, six months, one year or two years. Conversations left idle for longer than the window you choose are permanently deleted overnight, transcripts, notes and analytics links included. Leads a visitor has given you stay in your Leads list, since deleting those is a separate decision and we will not make it for you.

When you leave

You can export your conversations and leads from the Conversations screen at any time, and we would encourage you to do that before you close an account.

When this agreement ends, we will delete the personal data we hold on your behalf: from live systems within 30 days, and from backups within 90 days. If you would rather have it returned than deleted, tell us within 30 days of closing the account and we will provide it in a machine-readable format.

The exception is anything we are required by law to keep, such as billing records, which we retain for six years for tax purposes. Those records are held under the privacy policy, as controller, not under this agreement.

Once deleted it is gone, and we cannot recover it for you.

9. Audits and information

We will make available to you the information reasonably needed to demonstrate that we are meeting our obligations under Article 28. In most cases that means answering a security questionnaire, which we are happy to do.

Beyond that, you may audit us once in any twelve-month period, on at least 30 days’ written notice, during business hours, in a way that does not disrupt the service or expose another customer’s data. You may use an independent auditor provided they are not a competitor of ours and they sign a confidentiality undertaking. You bear the cost of the audit, unless it finds a material breach of this agreement, in which case we bear it.

Where we hold a relevant third-party certification or report, we may offer that first, and you will accept it if it reasonably answers the question.

An additional audit may be carried out if the ICO requires it, or following a personal data breach affecting your data.

10. What you are responsible for

As controller, it is on you to:

  • Have a lawful basis for the conversations your assistant holds and for any leads you capture.
  • Mention the chat in your own privacy notice, and say that a processor handles it.
  • Tell your visitors what the chat stores on their device, so they can find it in your cookie notice.
  • Answer requests from your visitors about their data. If one comes to us, we will refer them to you and tell you it happened.
  • Not upload personal data into the assistant’s knowledge that has no business being there, and not use the chat to collect special category data.
  • Keep your own account access under control, since anyone you invite can read the conversations.

You confirm that your instructions to us comply with data protection law, and that you have the authority to give them.

11. The legal bits

Precedence

This agreement forms part of the subscriber terms. Where our documents disagree, this is the order of precedence, highest first:

  1. any order form or enterprise agreement we have both signed;
  2. this data processing agreement, on anything to do with data protection;
  3. the subscriber terms;
  4. the terms of use.

So this agreement wins on data protection, and the commercial documents win on everything else.

Liability

Liability under this agreement is subject to the limits and exclusions in the subscriber terms, and the cap there applies across those terms, the terms of use and this agreement taken together rather than separately to each. Nothing here limits either side’s liability to a data subject, or the ICO’s ability to act against either of us.

Changes

We may update this agreement to reflect a change in the law, in the service, or in our sub-processors. For anything that materially affects your rights we will give you at least 30 days’ notice by email.

Governing law

This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Contact

Company Holp Ltd, registered in England and Wales, company number 16582223
Registered office Unit 20b Yarrow Mill, Yarrow Road, Chorley, England, PR6 0LP
Data protection enquiries [email protected]

Last updated: 24 August 2026.

Related

Book a demo