Data Processing Agreement (DPA)
Last updated: 5 March 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer") and Daysi, operated by Rdentify Ltd ("Daysi", "we", "us").
This DPA applies where Daysi processes personal data on behalf of the Customer in connection with the Daysi platform (the "Service").
This agreement is intended to comply with the requirements of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) where applicable.
1. Roles of the Parties
For the purposes of data protection law:
- the Customer acts as the Data Controller
- Daysi acts as the Data Processor
The Customer determines the purposes and means of processing personal data.
Daysi processes personal data only on behalf of the Customer in order to provide the Service.
2. Scope of Processing
Daysi processes personal data as necessary to operate the Service. This may include:
- conversation messages submitted by end users
- chatbot responses
- conversation transcripts
- customer feedback
- metadata relating to conversations.
Processing activities may include:
- storing conversation data
- analysing conversation data to generate insights
- processing chatbot responses
- providing dashboards and analytics.
3. Duration of Processing
Daysi will process personal data for the duration of the Customer's use of the Service.
Upon termination of the Service, data will be handled according to the data retention provisions in the Terms of Service and Privacy Policy.
4. Types of Personal Data
Depending on how the Service is used, personal data may include:
- names
- contact details
- conversation messages
- customer support inquiries
- technical identifiers such as IP addresses.
Daysi does not intentionally collect sensitive categories of personal data unless such data is submitted by end users through conversations.
5. Categories of Data Subjects
Personal data processed through the Service may relate to:
- customers of the Customer
- website visitors interacting with chatbots
- employees or representatives of the Customer
- other individuals who interact with a Daysi chatbot.
6. Processor Obligations
Daysi agrees to:
- process personal data only on documented instructions from the Customer
- ensure that personnel authorised to process personal data are subject to confidentiality obligations
- implement appropriate technical and organisational measures to protect personal data
- assist the Customer with fulfilling data protection obligations where reasonably possible
- notify the Customer without undue delay if a personal data breach occurs.
7. Security Measures
Daysi implements reasonable technical and organisational measures designed to protect personal data.
8. Subprocessors
Daysi may use trusted third-party service providers ("subprocessors") to operate the platform. These may include providers of:
- cloud infrastructure
- payment processing
- analytics
- messaging services.
Daysi ensures that subprocessors are subject to appropriate data protection obligations.
A list of subprocessors may be made available on request or published on the Daysi website.
9. International Transfers
Where personal data is transferred outside the United Kingdom or European Economic Area, Daysi will ensure that appropriate safeguards are in place. These may include:
- Standard Contractual Clauses
- other legally recognised transfer mechanisms.
10. Data Subject Rights
Daysi will assist the Customer, where reasonably possible, in responding to requests from individuals exercising their rights under data protection laws. These rights may include:
- access to personal data
- correction of inaccurate data
- deletion of personal data
- restriction of processing.
11. Data Breach Notification
Daysi will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.
12. Deletion or Return of Data
Upon termination of the Service, Daysi may delete or anonymise personal data unless retention is required for legal or operational purposes.
Customers are responsible for exporting data they wish to retain before cancelling their account.
13. Audits
Where required under applicable law, Daysi may provide reasonable information necessary to demonstrate compliance with this DPA.
14. Governing Law
This DPA is governed by the same law and jurisdiction specified in the Daysi Terms of Service.
15. Contact
If you have questions regarding this Data Processing Agreement, please contact: