Office Elves
PrivacyTermsCookiesDPAContact
Sign in

Data Processing Addendum

Last updated: 6 July 2026

This Data Processing Addendum ("DPA") forms part of the Office Elves Terms of Service between the site operator ("Office Elves", the "Processor") and the customer that holds the workspace (the "Customer", the "Controller"). It applies whenever Office Elves processes personal data on the Customer's behalf, and is intended to satisfy Article 28 of the UK GDPR (and, where applicable, the EU GDPR).

1. Roles and scope

For personal data the Customer and its end users put into a workspace (contacts, companies, deals, tickets, chat conversations, campaign lists and related content, "Customer Data"), the Customer is the controller and Office Elves is the processor. For account, billing and site data, Office Elves is an independent controller as described in the Privacy Policy.

2. Details of processing

  • Subject matter and nature: hosting, storage, transmission, display, automated reply generation and email delivery, as needed to provide the Service.
  • Purpose: providing the Office Elves platform under the Terms of Service.
  • Duration: the term of the Customer's subscription plus the deletion window in section 8.
  • Categories of data subjects: the Customer's customers, prospects, website visitors and staff.
  • Categories of personal data: names, contact details, employer and role, conversation and ticket content, deal and purchase information, campaign engagement data, and any other personal data the Customer chooses to submit. The Service is not designed for special category data and the Customer agrees not to submit it.

3. Processor obligations

Office Elves will:

  • process Customer Data only on the Customer's documented instructions (the Terms of Service, this DPA and the Customer's use of the product controls), unless required by law, in which case we will inform the Customer unless prohibited;
  • ensure everyone authorised to process Customer Data is bound by confidentiality;
  • implement appropriate technical and organisational measures (Article 32), including encryption in transit and at rest, per-tenant workspace isolation enforced by server-side security rules, least-privilege access to production systems, and managed secret storage;
  • assist the Customer, taking into account the nature of processing, with data subject requests (Articles 12-23) and with the Customer's obligations under Articles 32 to 36, including notifying the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data;
  • make available information reasonably necessary to demonstrate compliance with Article 28 and allow for audits (see section 7).

4. Sub-processors

The Customer gives general written authorisation to the sub-processors below. We will give at least 30 days' notice (by email or in-product) before adding or replacing a sub-processor; if the Customer reasonably objects on data protection grounds and we cannot offer an alternative, the Customer may terminate the affected subscription.

Sub-processorPurposeLocation
Google Cloud / Firebase (Google Ireland Ltd / Google LLC)Hosting, authentication, database and storageEEA / United States
Anthropic PBCGeneration of automated replies from workspace knowledgeUnited States
Stripe Payments Europe Ltd / Stripe IncSubscription billing (Customer's own billing data)EEA / United States
Amazon Web Services (SES)Email delivery for campaigns and notificationsEEA / United States

Each sub-processor is bound by written terms imposing data protection obligations no less protective than this DPA. Office Elves remains fully liable for its sub-processors' performance.

5. International transfers

Where Customer Data is transferred outside the UK or EEA to a country without an adequacy decision, the transfer is protected by appropriate safeguards: the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses for transfers from the UK, the EU Standard Contractual Clauses for transfers from the EEA, and, where the recipient is certified, the EU-US Data Privacy Framework and its UK Extension.

6. AI processing

Automated replies are generated by sending relevant conversation content and workspace knowledge to Anthropic for processing. This content is used only to generate the response; we do not permit sub-processors to use Customer Data to train their models.

7. Audits

No more than once per year, on at least 30 days' written notice, the Customer may audit our compliance with this DPA by requesting our then-current security documentation and written responses to reasonable questions. Where that is insufficient to meet a regulatory requirement, we will discuss a proportionate further audit at the Customer's cost.

8. Return and deletion

The Customer can export Customer Data at any time during the subscription. On termination, Customer Data remains exportable for 30 days, after which it is deleted from live systems, with backups expiring on their normal cycle within a further 90 days, unless retention is required by law.

9. General

This DPA takes precedence over the Terms of Service to the extent of any conflict concerning the processing of personal data. Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of England and Wales.

Customers who need a countersigned copy of this DPA, or an Enterprise variant, can reach us through our contact page or by email at hello@officeelves.com.

Office Elves
PrivacyTermsCookiesDPAContact
Reach the Office Elves team through our contact page.