Data processing addendum
Last updated — July 7, 2026
Our GDPR Article 28 processor terms — automatically part of every customer's agreement. No signature required; countersigned copies available on request.
Scope and how this DPA applies
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and asksdotapp, LLC ("Asks") governing your use of the Asks platform under our Terms of Service(the "Agreement"). It applies whenever Asks processes personal data on your behalf that is subject to Data Protection Laws.
No signature is required. This DPA is automatically incorporated into the Agreement for every customer. If your organization requires an executed copy, email legal@asks.app and we will countersign.
Definitions
- "Data Protection Laws"means all laws applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act as amended ("CCPA").
- "Customer Data"means personal data that Asks processes on Customer's behalf: end-user conversations and messages, contact records, uploaded content and knowledge base material, and related metadata.
- "Account Data"means personal data relating to Customer's own relationship with Asks: workspace member names and emails, billing contacts, and support communications with us.
- "Usage Data" means telemetry about how the platform itself is used (feature usage, performance, and diagnostic data).
- "Subprocessor" means a third party engaged by Asks to process Customer Data.
- "SCCs" means the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.
- Terms such as "controller," "processor," "data subject," "personal data," and "processing" have the meanings given in the GDPR.
Relationship of the parties
Customer Data — Asks as processor
For Customer Data, Customer is the controller (or a processor acting for another controller) and Asks is the processor. Asks will process Customer Data only on Customer's documented instructions — which are: the Agreement, this DPA, and Customer's configuration and use of the platform — unless required otherwise by law, in which case Asks will inform Customer before processing unless the law prohibits it. Asks will promptly inform Customer if, in our opinion, an instruction infringes Data Protection Laws.
Account Data and Usage Data — Asks as controller
For Account Data and Usage Data, Asks is an independent controller, processing such data to manage the customer relationship, provide support, bill, secure and improve the service, and comply with law — as described in our Privacy Policy.
Customer responsibilities
Customer is responsible for the lawfulness of the Customer Data it submits, for providing any required notices to and obtaining any required permissions from its end users, and for configuring the platform (channels, retention, integrations) consistently with its own obligations.
CCPA
Where the CCPA applies, Asks acts as Customer's "service provider." Asks does not sell or share Customer Data, does not retain, use, or disclose it except to provide the services, and certifies that it understands these restrictions.
Confidentiality and personnel
Asks ensures that every person it authorizes to process Customer Data is bound by an appropriate obligation of confidentiality (contractual or statutory), and that access to Customer Data is limited to personnel who need it to perform the services. Asks may disclose Customer Data to its professional advisers or auditors only under confidentiality obligations and only to the extent needed.
Subprocessors
Customer grants Asks general written authorization to engage the subprocessors listed at asks.app/subprocessors, which identifies each subprocessor, its purpose, the data it processes, and its location.
- Advance notice: Asks will update that page and notify workspace owners by email at least 10 days before a new subprocessor processes Customer Data.
- Right to object: Customer may object within the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected services and receive a pro-rata refund of prepaid fees. Continued use after the notice period constitutes approval.
- Flow-down and liability:Asks imposes data protection obligations on each subprocessor materially equivalent to those in this DPA, and remains liable for its subprocessors' performance.
Security
Taking into account the state of the art and the nature of the data, Asks implements and maintains appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are described in Exhibit B (Technical and Organizational Measures) below and summarized on our Security page. Asks may update them from time to time, provided the updates do not materially reduce the overall level of protection.
International transfers
Asks primarily processes Customer Data in the United States, with certain subprocessors in other locations as listed on the subprocessors page.
- EEA transfers: transfers of personal data originating in the EEA are governed by the SCCs, Module Two (controller → processor) or Module Three (processor → processor), which are incorporated into this DPA by reference. For the SCCs: Clause 7 (docking) is included; Clause 9 uses Option 2 with the notice period in the Subprocessors section above; Clause 17 selects Irish law and Clause 18 the courts of Ireland; Annexes I–III are completed by Exhibit A, the subprocessors page, and Exhibit B respectively.
- UK transfers: the UK International Data Transfer Addendum to the SCCs (issued by the ICO) applies, with the tables completed by the same information.
- Swiss transfers: the SCCs apply as adapted for the FADP — references to the GDPR are read as references to the FADP and the competent authority is the Swiss FDPIC.
- Government requests: if Asks receives a legally binding request for Customer Data from a public authority, it will attempt to redirect the authority to Customer, notify Customer before disclosure unless legally prohibited, and disclose only the minimum required.
Data subject rights
Taking into account the nature of the processing, Asks assists Customer in fulfilling its obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection) by providing in-product controls — including conversation and customer-record deletion, workspace deletion, and data export — and, where those are insufficient, direct assistance on request.
If a data subject contacts Asks directly about Customer Data, Asks will not respond substantively but will promptly refer the request to Customer, unless legally required to respond.
Personal data breaches
Asks will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures taken or proposed. Asks will cooperate with Customer and take reasonable steps to mitigate the effects of the breach. Notification is not an acknowledgement of fault or liability.
Audits and assessments
Asks makes available the information reasonably necessary to demonstrate compliance with this DPA — including this document, the subprocessors list, and security documentation — and will assist Customer with data protection impact assessments and consultations with supervisory authorities where required.
Customer may audit Asks' compliance no more than once per calendar year(unless required by a supervisory authority or following a breach), on at least 30 days' notice, during business hours, without disrupting operations, and at Customer's expense. Audits are satisfied first by written responses and documentation before any on-site exercise is considered.
Deletion and return of data
Upon termination or expiry of the Agreement, Asks will, at Customer's choice, delete or return all Customer Data (including deleting the workspace's vector search index), and delete existing copies, unless applicable law requires longer storage. Deletion from live systems occurs promptly; residual copies in encrypted backups are overwritten in the ordinary backup cycle. Customer may also delete data self-serve at any time — individual records, conversations, or the entire workspace.
Precedence, liability, and updates
- Order of precedence: where documents conflict, the SCCs prevail over this DPA, and this DPA prevails over the Agreement with respect to data protection.
- Liability:each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Laws do not permit such limitation.
- Updates: we may update this DPA to reflect changes in law or the services; material changes will be notified in advance, and no update will materially reduce your protections.
Exhibit A — Details of processing
Subject matter and duration
Processing of Customer Data to provide the Asks AI customer support platform, for the term of the Agreement plus the deletion period described above.
Nature and purpose
Hosting and storing support conversations; generating AI-assisted responses grounded in Customer's knowledge base (retrieval-augmented generation); routing messages across connected channels; search, analytics, and reporting for Customer's support operations.
Categories of data subjects
- Customer's end users and customers who contact Customer through connected support channels
- Customer's workspace members, employees, and contractors
Categories of personal data
- Contact details: names, email addresses, phone numbers, channel handles and identifiers
- Conversation content: messages, attachments, voice notes, and ratings
- Context data: source page URLs, referrer, browser language, device type, and country derived from IP address
- Commerce data (Shopify-connected workspaces): order references and store browsing events
- Any personal data contained in content Customer uploads to its knowledge base
Sensitive data
The services are not designed for and Customer agrees not to submit special categories of data (Article 9 GDPR), payment card data, or government identifiers. End users may nonetheless volunteer information in free-text messages; Customer is responsible for policies governing such content.
Frequency and recipients
Continuous, for as long as Customer uses the services. Recipients are the subprocessors listed at asks.app/subprocessors.
Competent supervisory authority
For EEA transfers, the supervisory authority determined in accordance with Clause 13 of the SCCs; for UK transfers, the ICO; for Swiss transfers, the FDPIC.
Exhibit B — Technical and organizational measures
The measures below apply to Asks' processing of Customer Data (SCC Annex II). Our Security page describes them in plain language.
- Encryption in transit: TLS 1.2+ for all connections between clients, our services, and subprocessors.
- Encryption at rest: databases and file storage are encrypted at rest by our infrastructure providers; integration credentials, channel tokens, and webhook secrets are additionally encrypted at the application layer with AES-256-GCM.
- Authentication: passwords hashed with bcrypt; optional two-factor authentication; SAML single sign-on with audit logging for enterprise workspaces; API keys stored only as SHA-256 hashes.
- Access control: role-based access control (owner, admin, member) enforced server-side on every workspace operation; least-privilege access to production systems.
- Tenant isolation: every record is scoped to a workspace at the application layer, and AI search indexes are isolated per workspace in dedicated namespaces.
- Integrity of integrations: all inbound webhooks (payment, channel, and email providers) are verified with cryptographic signatures using constant-time comparison; outbound webhooks are signed with HMAC-SHA256.
- Abuse resistance: rate limiting, request idempotency, widget origin allow-listing, signed widget session tokens, and automated abuse detection on AI conversations.
- Data minimization: raw IP addresses are not stored on conversations (only a derived country code); error reports are scrubbed of emails and IPs; secrets are redacted from logs.
- Deletion: cascading deletion across all stores (database, files, search and vector indexes) when a workspace, customer record, or conversation is deleted; automated purging of time-limited data such as store browsing events (30 days).
- Backups and continuity: managed, encrypted database backups through our database provider with point-in-time recovery.
- Monitoring: centralized error and performance monitoring, security event logging for SSO and administrative actions, and alerting on anomalous failures.
- Organizational measures: confidentiality obligations for all personnel, least-privilege vendor access, data protection agreements with every subprocessor, and documented incident response.
Contact
Questions about this DPA, or need a countersigned copy for your records?