Skip to main content

Data Processing Agreement

Last updated: September 16, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between PuglieseWeb LTD ("we", "us", "our") and the business that uses our services ("you"). It is incorporated by reference into our Terms of Service.

You accept this DPA when you accept the Terms — when you create an account, which says that you agree to them, or when you use our services. It does not need to be signed separately. It applies from the date at the top of this page, including to accounts created before that date, and changes as section 14 describes.

1. Scope and roles

This DPA applies to the personal data we process on your behalf when we provide our software services to you, including the Ema products — for example the messages your website visitors send your assistant, the contact details they choose to leave with you, and the appointments they book ("Customer Personal Data").

For Customer Personal Data you are the controller and we are your processor. Where we process personal data for our own purposes — your account and sign-in details, billing, and keeping our services secure and working — we are the controller, this DPA does not apply, and that processing is described in our Privacy Policy.

If you accept the Terms on behalf of a business, you confirm that you are authorised to bind it. If you set up or manage an organisation for another business — as an agency or reseller, for example — you confirm that you hold that business's authority to give the instructions in this DPA on its behalf.

2. Definitions

In this DPA:

  • "Data Protection Law" means the UK GDPR and the Data Protection Act 2018 and, where they apply to the processing, Regulation (EU) 2016/679 (the "EU GDPR") and the laws that implement or supplement it.
  • "Controller", "processor", "data subject", "personal data", "personal data breach" and "processing" have the meanings given to them in Data Protection Law.
  • "Services" means the services we provide to you under the Terms.
  • "Sub-processor" means a third party we engage to process Customer Personal Data.
  • "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914.

3. Your instructions

We process Customer Personal Data only on your documented instructions, unless the law we are subject to requires otherwise — in which case we tell you before processing, unless that law forbids it. Your instructions are the Terms, this DPA, and the choices you make when you set up and use the Services: for example which website your assistant answers on, what it may read, where enquiries are sent and whether it takes bookings.

We tell you promptly if, in our opinion, an instruction infringes Data Protection Law.

You are responsible for the lawfulness of the processing you instruct: for having a lawful basis for it, for telling the people whose data it is — your website's privacy notice should mention the assistant and what happens to what people write in it — and for not setting the Services up to ask for special categories of personal data or for children's data.

4. Details of the processing

Subject matter and duration: the provision of the Services to you, for as long as we provide them and until Customer Personal Data is deleted or returned under section 12.

Nature and purpose: receiving, storing and answering messages; generating answers with AI models from the content you approve; capturing the enquiries and bookings people make, summarising them and passing them to you; and protecting the Services against abuse — in each case only to provide the Services to you. We do not use Customer Personal Data to train or fine-tune AI models, and we do not sell it.

Data subjects

  • Visitors to your website who use your assistant.
  • People who contact your business through a channel you connect to the Services, such as WhatsApp or email.
  • People who leave their contact details with you or book an appointment with you.
  • Anyone whose personal data appears in the website content or documents you ask us to read.

Categories of personal data

  • The content of messages and conversations, including anything a person chooses to write or send, such as an image.
  • Contact details and answers a person gives: for example their name, email address, phone number, their message and their answers to the questions you set.
  • Appointment details: the date, time, service booked and any notes.
  • Technical data used to deliver and protect the Services: a pseudonymous visitor identifier, IP address, browser and device information, and the address of the page a message was sent from.
  • Personal data contained in the website content and documents you ask us to read.
  • Records of how an enquiry or booking was handled, such as when it was received and whether it was answered, and the summary of an enquiry that an AI model writes for you.

Special categories of personal data: none are required, and you must not set the Services up to ask for them. A person may still volunteer them in what they write; we process such data only as part of the messages that carry it.

5. Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality. Our staff access it only as far as they need to in order to provide, support and secure the Services, including in the support sessions described in section 4 of the Terms.

6. Security

We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as Article 32 of the UK GDPR and the EU GDPR requires. The measures in place — where data is hosted, encryption, retention and deletion, access control and vulnerability handling — are described on our Trust and Security page, whose sections on those subjects form part of this DPA: Trust and Security.

We may change those measures as technology and threats change, but we will not reduce the overall level of protection they give Customer Personal Data.

7. Sub-processors

You give us general authorisation to engage Sub-processors. The list of our current Sub-processors, the service each provides and where it processes data forms part of this DPA and is published here: Trust and Security.

We give at least 30 days' notice before a new or replacement Sub-processor starts processing Customer Personal Data, by updating that list and by email to everyone who has asked to be told. To be told, write to privacy@puglieseweb.com.

You may object to a new Sub-processor on reasonable data protection grounds within that notice period by writing to the same address. We will discuss your objection in good faith. If we cannot reasonably avoid using that Sub-processor for you, you may stop using the Service concerned, and we will refund any fees you have paid in advance for the period after it stops.

We impose on each Sub-processor, by contract, data protection obligations that give Customer Personal Data the same protection as this DPA, and we remain responsible to you for how each Sub-processor performs them.

8. International transfers

We host the Services mainly in the United Kingdom. Some Sub-processors process data in other countries, as the list in section 7 shows.

Where Customer Personal Data is transferred outside the United Kingdom — or, for data subject to the EU GDPR, outside the European Economic Area — to a country that is not covered by adequacy regulations or an adequacy decision, the transfer is made under a safeguard that Data Protection Law recognises, such as the Standard Contractual Clauses together with the UK International Data Transfer Addendum.

Where you are established in the European Economic Area, transfers of Customer Personal Data from you to us in the United Kingdom rely on the European Commission's adequacy decision for the United Kingdom while one is in force.

If no such decision is in force, the Standard Contractual Clauses, module two (controller to processor), are incorporated into this DPA for those transfers, with you as data exporter and us as data importer. Clause 7 does not apply; option 2 of clause 9 applies, with the notice period in section 7; the optional wording in clause 11 does not apply; the competent supervisory authority under clause 13 is the one for your establishment; clauses 17 and 18 choose the law and the courts of Ireland; and Annexes I to III are completed by sections 1 and 4 of this DPA, the security sections of our Trust and Security page, and the list of Sub-processors. If the clauses conflict with this DPA, the clauses prevail.

9. Requests from data subjects

Taking into account the nature of the processing, we help you by appropriate technical and organisational measures, as far as possible, to respond to people exercising their rights under Data Protection Law. If a person contacts us directly about Customer Personal Data, we do not answer the request ourselves, other than to tell them to contact you, and we pass it on to you without undue delay.

10. Personal data breaches

We notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We send the notice to your organisation's owner. It carries what we know at the time — the nature of the breach, the categories and approximate number of people and records concerned, its likely consequences, and the measures taken or proposed — and we follow it with further information as it becomes available.

We take reasonable steps to contain and investigate the breach and to reduce its effects. Notifying you of a breach is not an admission of fault or liability.

11. Assistance, records and audits

Taking into account the nature of the processing and the information available to us, we give you reasonable assistance with data protection impact assessments, and with prior consultation of a supervisory authority, that relate to the Services.

We keep a record of the processing we carry out on your behalf, and we make available to you the information necessary to demonstrate compliance with this DPA — including our Trust and Security page and answers to reasonable security questionnaires.

If that information is not enough to demonstrate compliance, or a supervisory authority requires it, you or an independent auditor you appoint may audit our compliance with this DPA: once in any 12 months unless a personal data breach has occurred, on at least 30 days' written notice, during business hours, without disrupting the Services, under a duty of confidentiality, and at your own cost. An auditor must not be our competitor.

12. Deletion and return

When you close your account, or we stop providing the Services to you, we wait 30 days before deleting Customer Personal Data, so that a closure made by mistake can be undone, and then delete it within a further 30 days, unless the law requires us to keep it. We confirm the deletion in writing if you ask. Until it is deleted, you may ask us in writing for a copy of it in a commonly used, machine-readable format.

While you use the Services, Customer Personal Data is kept and deleted as described in the retention section of our Trust and Security page. A deleted record can remain in backups for up to 35 days afterwards; those copies expire on their own and the Services cannot read them. The retention section is here: Trust and Security.

To ask for deletion or a copy, write to privacy@puglieseweb.com.

13. Liability and precedence

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent Data Protection Law allows.

If this DPA conflicts with the rest of the Terms, this DPA prevails as regards the processing of Customer Personal Data.

14. Changes and governing law

We may update this DPA in the same way as the Terms (section 13 of the Terms). We will not make a change that reduces the protection this DPA gives Customer Personal Data unless Data Protection Law or a supervisory authority requires it. We give at least 30 days' notice of a material change by email to your organisation's owner, and each version carries its date at the top of this page. If you continue to use the Services after a change takes effect, you accept it.

This DPA is governed by the law of England and Wales, like the Terms, except where Data Protection Law or the Standard Contractual Clauses require otherwise.

15. Contact

To ask about this DPA, to object to a Sub-processor, to be told when the list of Sub-processors changes, or to ask for Customer Personal Data to be deleted or returned, write to:

PUGLIESEWEB LTD

Registered office: 10 Upper Wheatfield, Hook, England, RG27 9YR

privacy@puglieseweb.com

Company No. 17078772, registered in England and Wales

Basket is empty