1. Parties & definitions
Controller:the business with a Kaidence account, who determines the purposes and means of processing its customers' personal data. Processor:Kaidence, who processes that data on the Controller's behalf. "Personal data", "processing", and "data subject" have the meanings given in UK GDPR.
2. Subject matter & duration
This agreement covers the Processor's handling of personal data submitted by the Controller's customers via the Kaidence chat assistant and customer portal, for the duration of the Controller's Kaidence subscription, plus any retention period agreed in the Privacy Policy.
3. Processing details
| Nature & purpose | Operating an AI chat assistant to capture enquiries, draft quotes, book appointments, and send follow-ups on the Controller's behalf. |
| Categories of data | Name, contact details, property/job address, job description, urgency, budget, uploaded photos, chat transcripts. |
| Categories of data subjects | The Controller's customers and prospective customers. |
4. Processor obligations
The Processor agrees to:
- Process personal data only on the Controller's documented instructions
- Keep it confidential, and ensure anyone processing it is under a duty of confidentiality
- Implement appropriate technical and organisational security measures
- Assist the Controller in responding to data subject rights requests
- Assist the Controller with data protection impact assessments where relevant
- Notify the Controller without undue delay after becoming aware of a personal data breach
- Delete or return all personal data at the end of the agreement, at the Controller's choice
- Make available information necessary to demonstrate compliance with this agreement
5. Sub-processors
The Controller authorises the Processor to use the following sub-processors:
| Sub-processor | Role |
|---|---|
| Supabase | Database, authentication, file storage |
| Anthropic | AI processing of chat messages (Claude API) |
| Stripe | Payment processing |
| Vercel | Application hosting |
The Processor will give reasonable notice of any change to this list, and the Controller may object on reasonable data-protection grounds.
6. International transfers
Where a sub-processor is located outside the UK, the Processor ensures an appropriate transfer mechanism is in place (such as the UK International Data Transfer Addendum) before any personal data is transferred.
7. Assistance & breach notice
If the Processor becomes aware of a personal data breach affecting the Controller's data, it will notify the Controller without undue delay, and no later than 72 hours after becoming aware, with enough detail for the Controller to meet its own reporting obligations.
8. Ending & data return
On termination of the Controller's Kaidence subscription, the Processor will, at the Controller's choice, delete or return all personal data processed under this agreement, except where retention is required by law.