Data Processing Addendum
Last updated 17 August 2026
This Data Processing Addendum (DPA) explains how we handle the personal data that flows through your PlainAnswer agent, which belongs to you and your customers. It applies to every business customer, forms part of our Terms of Service, and is written so you can rely on it for your own compliance.
1. Who is who
When your customers use the PlainAnswer agent on your website, you decide why and how their personal data is handled, so you are the controller. We handle that data only to run the service for you, so we are your processor. In this DPA, "you" means the business customer (controller) and "we", "us" and "our" mean Culture & Clarity Ltd (processor).
2. What we process, and why
| Subject matter | Providing the PlainAnswer service to you. |
|---|---|
| Duration | For as long as you use the service, plus the short wind-down period in section 8. |
| Nature and purpose | Answering your customers' questions from your content, capturing the visitor's contact details when the agent hands a question to you, and storing the related conversation in your dashboard. |
| Types of personal data | Mainly the content of questions your customers type, and any name, phone number or email address they choose to leave. Occasionally personal data that appears on the public pages of your website that the agent has read. |
| Categories of data subject | Your website visitors and customers. |
3. Our obligations
As your processor, we agree that we will:
- process the personal data only on your documented instructions, which include your use of the service and its settings, unless the law requires otherwise, in which case we will tell you unless we are legally barred from doing so;
- make sure the people who handle the data are bound by confidentiality;
- apply appropriate technical and organisational security measures (see section 5);
- help you, as far as we reasonably can, to respond to requests from individuals exercising their data rights;
- help you, taking into account the nature of the processing and the information available to us, to meet your own duties around security, breach notification and data protection impact assessments;
- only use another processor (a subprocessor) as set out in section 4;
- delete or return the personal data at the end of the service, as set out in section 8;
- make available the information you reasonably need to show that these obligations are being met.
4. Subprocessors
You give us general authorisation to use the subprocessors below to provide the service. Each is used only for its stated purpose.
| Subprocessor | Purpose |
|---|---|
| Our AI model providers | Generating the agent's answers from the question and your relevant content. We use more than one for reliability. |
| Our hosting provider | Running the service and storing its data. |
| Stripe | Processing your subscription payments (this involves your billing data, not your customers' question data). |
| Our email provider | Delivering the notifications that tell you a customer needs a reply. |
If we plan to add or change a subprocessor that handles your customers' personal data, we will give you reasonable notice so you can object on reasonable data protection grounds. We remain responsible to you for the work of our subprocessors.
5. Security
We protect the personal data with measures appropriate to the risk, including encryption of data in transit, strict separation of each business customer's data from every other's, access limited to what is needed to run the service, and monitoring for abuse. We keep these measures under review as the service develops.
6. International transfers
Some subprocessors are outside the United Kingdom, including in the United States. Where personal data is transferred outside the UK, we rely on a transfer mechanism recognised under UK data protection law, such as the UK International Data Transfer Agreement or an adequacy decision.
7. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and give you the information you reasonably need to meet your own notification duties.
8. Return and deletion
You can delete FAQs, notes and conversations from your dashboard at any time. When the service ends, we will, at your choice, delete or return the personal data we hold for you, and delete existing copies, unless the law requires us to keep it, within a reasonable period.
9. Liability and governing law
This DPA is subject to the liability provisions in our Terms of Service, and is governed by the law of England and Wales.