Legal
Data processing addendum
Last updated
Scope and roles
This addendum applies wherever the privacy policy describes us as your processor: your end customers' conversations with the assistant you configured, and anything else you or your customers put into the platform on your instructions. For your own account and workspace data (who signs in, what you configure, your usage) we are the controller in our own right, as the privacy policy already explains, and this addendum does not change that. Terms not defined here have the meaning the privacy policy gives them.
Processing instructions
We process end-customer data only on your documented instructions: the assistant answers, acts and reaches only the systems, connectors and knowledge sources you configure for your workspace in the Console. We do not use your customers' conversations to train models that we develop or operate, or for any other purpose of our own. When your workspace enables an external AI provider, that provider processes prompts under its own terms and settings; see the privacy policy for the provider list and location information. If we believe an instruction would break the law, we tell you before carrying it out.
Sub-processors
The sub-processors are the same conditional list the privacy policy publishes and keeps current: Supabase (account authentication and support services), DigitalOcean (hosting and DNS), the AI model providers enabled for a workspace (Anthropic, OpenAI, xAI, or a customer-supplied OpenAI-compatible or self-hosted endpoint), TypeSafe AI, Inc. (routing decisions over a short excerpt of the latest message), Stripe (billing, where a plan is paid), Twilio (voice, where enabled), Telegram (hand-off, where connected), and Apple/Google (app distribution and push). Their roles, confirmed deployment locations and provider-published location information are described in the privacy policy; exact processing and transfer terms depend on the selected service and account. Adding a sub-processor that touches conversation content is a change to that same published list; watch the privacy policy for updates, or ask us to notify you directly.
Security measures
Every conversation, published version and permission belongs to one workspace, enforced by row-level security in the database itself, not only by the application — one workspace cannot read another's rows even if a request asks for them. Credentials you give us for your own systems are write-only: once set, nobody, including us, can read them back. Before the assistant connects to a new address we check that address cannot reach anything internal. Full detail is on our security page (busymate.ai/security).
Data subject requests
If your customer contacts us directly about their data, we forward the request to you as the controller and confirm that we have, rather than acting on it ourselves. We give you the tools to fulfil a request yourself — you control the workspace's connectors and knowledge sources, and its retention setting — and we assist you with anything only we can do (for example, deleting conversation content held in our systems), consistent with the nature of the processing.
International transfers
Our confirmed primary deployments are in London, United Kingdom (DigitalOcean `lon1`) and Ireland (the Supabase project's primary storage region, `eu-west-1`). Supabase Edge Functions are not region-pinned by our integration and execute globally near requesters. Providers enabled for a workspace may process data in additional countries, as described in the privacy policy and each provider's current notices and settings. We have not established every provider-account route, remote-access location or applicable transfer term, so these locations do not guarantee EU- or UK-only processing. Choose providers and workspace settings that meet your requirements, and consult the terms applicable to each provider.
Deletion and return
Conversation data follows the retention period you set for your workspace; where you have not set one, we keep it for as long as the workspace exists so you can keep answering your own customers. Deleting your account or workspace removes its data from our live systems immediately, and backups roll off within 30 days as they naturally expire. You can export what your workspace holds at any time through the Console or the REST/MCP API rather than waiting for an off-boarding request.
Audits
We have not commissioned a third-party audit or certification (SOC 2, ISO 27001, or similar) and do not claim one. What we can show today is what is on the security page — the access controls, the isolation model, and the standards our identity and connector protocols actually implement — and a live authorization-server metadata excerpt that page reads at request time rather than typing out. For a vendor or security review beyond that, use the "Vendor / security review" reason on the contact page.