Agency legal centre

HyperChat Agency Data Processing Addendum

Controller–processor framework for personal data handled through agency workspaces.

Draft for professional review. This operational draft is not a substitute for advice from a UK-qualified solicitor or data-protection professional. It must be approved before being incorporated into a binding agency order.

1. Roles and scope

For client chatbot and lead data, the agency or its client is normally controller and Clone Centre Ltd is processor. Each party remains responsible for any processing where it acts as an independent controller, including billing, fraud prevention and legal compliance.

2. Processing instructions

HyperChat processes website content, chat messages, consented lead details, configuration, integration events, usage and support data only to provide, secure and support the service, follow documented customer instructions and meet legal obligations.

3. Confidentiality and security

Authorised personnel are bound by confidentiality. Measures include tenant-scoped access, hashed credentials, encrypted integration secrets, TLS, audit logs, rate limits, signed webhooks, restricted crawler behaviour and incident response.

4. Subprocessors

The agency gives general authorisation for the subprocessors listed on the public subprocessor page. HyperChat will provide reasonable notice of material additions and a process for a documented data-protection objection.

5. Assistance

Taking account of the processing, HyperChat will reasonably assist with data-subject requests, security enquiries, breach response, DPIAs and regulator consultation. The agency remains responsible for validating the requester and deciding the response.

6. Incidents

HyperChat will notify the agency without undue delay after confirming a personal-data breach affecting agency data and will provide available information needed for the agency's legal assessment.

7. International transfers

Where protected data is transferred internationally, the parties will use a lawful transfer mechanism appropriate to the relevant law, such as the UK International Data Transfer Addendum or another valid safeguard, together with supplementary measures where required.

8. Return, deletion and audit

At the end of service, data is returned or deleted in accordance with the order and retention schedule unless law requires retention. HyperChat will make appropriate compliance information available and support proportionate audits subject to confidentiality and security safeguards.

Version: 18 July 2026 · Operator: Clone Centre Ltd, England and Wales company 16536248.