Data Processing Agreement
Last updated September 11, 2026
1. Purpose and scope
This Data Processing Agreement (“DPA”) supplements our Terms of Service and applies wherever CYBIBOT processes personal data on a Customer’s behalf as part of the Service — most notably, the conversation data exchanged between a Customer’s end customers and their AI receptionist.
2. Roles of the parties
For personal data processed through the Service, the Customer is the data controller (or, where applicable, a processor acting for its own customer) and CYBIBOT is the data processor, processing personal data only on the Customer’s documented instructions as set out in the Terms of Service and this DPA.
3. Processing instructions
CYBIBOT will process personal data only to provide, secure and support the Service, and won’t use it for its own purposes (including training AI models) unless the Customer instructs otherwise in writing.
4. Subprocessors
CYBIBOT may engage subprocessors (such as hosting and AI model providers) to deliver the Service, under written terms that impose data protection obligations equivalent to those in this DPA. A current subprocessor list is available on request through our contact page, and we’ll give reasonable notice before adding a new one where required.
5. Security measures
CYBIBOT maintains technical and organizational measures appropriate to the risk, including encryption in transit, hashed credential storage, encrypted storage of the tokens for any calendar, messaging or CRM service a Customer connects, access controls scoped per workspace, and rate limiting on authentication endpoints. See our Privacy Policy for further detail.
6. Assistance with data subject requests
Where CYBIBOT receives a request from a data subject relating to data it processes on a Customer’s behalf, it will forward the request to the Customer promptly and provide reasonable assistance in responding to it, without responding directly unless instructed or legally required to.
7. Personal data breach notification
CYBIBOT will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, with the information reasonably available at the time and updates as the investigation progresses.
8. Deletion or return of data
On termination of the Service, CYBIBOT will return or delete Customer Data on the Customer’s written request, except where retention is required by law. Export and deletion are currently handled by our team on request rather than through a self-serve control in the product; automated retention and erasure are on our roadmap, and this clause will be updated when they ship.
9. Audit rights
On reasonable request, CYBIBOT will provide information reasonably necessary to demonstrate compliance with this DPA, such as summary documentation of its security measures.
10. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.
11. Requesting a signed copy
If your organization requires a countersigned DPA for its own compliance program, reach us through our contact page and we’ll get one arranged.