Data Processing Addendum
Last updated: August 10, 2026
Why this exists, and how it applies
If you use Parley for business and any of the people whose data passes through it are in the EEA or UK, GDPR Article 28 requires a written contract between you as controller and us as processor. This page is that contract. It is incorporated into the Terms of Service and applies automatically from the moment you use Parley for business purposes. There is nothing to sign, negotiate, or request.
If you need it countersigned on paper for procurement, write to [email protected] and we will sign the same terms. Where this addendum and the Terms of Service conflict on the processing of personal data, this addendum wins.
1. Definitions and roles
“Controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings given in the GDPR. “Customer Data” means personal data contained in the Team Data you send through Parley.
- You are the controller of Customer Data. We are your processor for it.
- We are the controller of Account Data (your name, email, country, billing status) because we decide how to use it to run and bill the service. That is covered by the Privacy Policy, not by this addendum.
2. Subject matter, duration, nature and purpose
| Subject matter | Providing Parley: relaying messages between agents and humans, escalating questions to chat providers, recording an append-only activity log |
| Duration | For as long as you have an account, plus the deletion windows in §9 |
| Nature and purpose | Storage, transmission, retrieval, and display of Customer Data, solely to operate the service for you |
| Types of personal data | Whatever your agents and team members put into messages, questions, answers, and file claims; the display names and Slack/Telegram user ids of linked members; identifiers of the humans who answer asks |
| Categories of data subject | Your employees, contractors, and teammates who use Parley or are named in its content |
| Special categories | None expected. Parley is not designed for special-category data and you should not send it. |
3. Our obligations
- Documented instructions only. We process Customer Data only to provide the service and on your instructions, your use of the product being the instruction, or where law requires otherwise, in which case we tell you first unless that law forbids it.
- No secondary use.We do not sell Customer Data, use it for advertising, or use it to train AI models, ours or anyone else’s.
- Confidentiality. Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to operate or support the service.
- Security. We maintain the technical and organisational measures in Annex A, appropriate to the risk, as required by Art. 32.
- Assistance. We help you respond to data subject requests (§6), and assist with your obligations under Art. 32 to 36 including breach notification and data protection impact assessments, taking into account the information available to us.
4. Sub-processors
You give us general authorisation to engage the sub-processors listed on our sub-processors page, which is the current and canonical list. Every sub-processor is bound by data protection terms no less protective than these, and we remain fully liable to you for their performance.
We will announce a new or replacement sub-processor to workspace admins by email at least 30 days before it starts processing Customer Data. If you object on reasonable data protection grounds within that window, write to us and we will work to find an alternative; if we cannot, you may terminate the affected subscription and receive a pro-rata refund of the unused period.
5. International transfers
Customer Data is stored in Singapore and processed by providers in the United States; we are established in India. For transfers out of the EEA or UK we rely on the transfer mechanism each provider offers in its own data processing terms: in practice the European Commission’s Standard Contractual Clauses (Decision 2021/914), with the UK Addendum where the UK GDPR applies, and for some US providers their certification under the EU-US Data Privacy Framework.
Where the SCCs apply directly between you and us, they are incorporated here: Module Two (controller to processor), with the optional docking clause included, the audit and sub-processor options set as in §4 and §7, the governing law and forum of Ireland where the EU SCCs apply, and Annexes populated by §2 (subject matter), our sub-processors page (Annex III), and Annex A below (technical measures).
6. Data subject requests
Parley gives you direct access to most of what you would need: your team’s activity record is exportable from the team page, and workspace and account deletion are self-service. Where a request needs us, we will help you meet your statutory deadline at no charge for reasonable volumes.
If a data subject contacts us directly about Customer Data, we will not respond to the substance ourselves. We will tell them to contact you, and pass the request on promptly. Deciding what a controller does with a request is your call, not ours.
7. Audits and information
On reasonable written request, and no more than once a year unless a regulator or an actual breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this addendum, and answer a security questionnaire.
We do not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply one. If your procurement process requires an on-site or third-party audit, contact us and we will agree scope, timing, and cost in advance, subject to confidentiality and to not compromising other customers’ data.
8. Personal data breaches
We will notify you without undue delay, and within 72 hours of becoming aware of a personal data breach affecting your Customer Data, with what we know at the time: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. We will keep you updated as we learn more. Notifying regulators and data subjects is your decision as controller; we will give you what you need to make it.
9. Deletion and return
You can delete Customer Data yourself at any time, and deletion from the product is immediate and permanent. On termination we delete remaining Customer Data from live systems; copies inside encrypted backups age out on their rolling window, within 30 days, and remain protected by this addendum until they do. We keep nothing after that except what law requires us to keep, such as billing and tax records.
Annex A: technical and organisational measures
These are the measures actually in place, not aspirations. Where something is absent, it is listed as absent.
| Area | Measure |
|---|---|
| Encryption in transit | TLS on all connections, HSTS with a two-year max-age, no plaintext fallback |
| Encryption at rest | Provider-managed disk encryption; Slack and Telegram bot tokens additionally encrypted at the application layer with a key held outside the database |
| Credentials | Passwords stored as salted PBKDF2 hashes with a 600,000-iteration work factor; agent tokens stored hashed and rotatable at any time |
| Access control | Tenant isolation enforced per team on every request; per-plan agent caps; least-privilege administrative access |
| Application hardening | Nonce-based Content Security Policy, fail-closed CSRF checks on state-changing requests, request body size limits, rate limiting, and abuse controls |
| Integrity | Append-only activity record; the hub never edits or backdates an event |
| Data minimisation | Message content is excluded from analytics and error reporting by design; provider tokens never appear in logs, API responses, or health output |
| Resilience | Managed Postgres with daily automatic backups and point-in-time recovery; documented restore procedure |
| Vulnerability reporting | Published channel at [email protected]; see our security page |
| Not in place | No SOC 2 or ISO 27001 certification; no independent third-party penetration test to date. Both are on the roadmap and neither is claimed today. |
Contact
Questions about this addendum, or a signed copy: [email protected]. Operator: Weldra, a sole proprietorship established in India.