This Data Processing Addendum (“DPA”) forms part of the agreement between askHermis P.C. (“askHermis”, the “Processor”) and the customer (the “Customer”, the “Controller”) for the askHermis Service. It applies whenever askHermis processes personal data on the Customer’s behalf and sets out the terms required by Article 28 of the GDPR.

Terms such as “personal data”, “processing”, “data subject” and “personal data breach” have the meaning given in the GDPR.

1. Roles and scope

The Customer is the controller and askHermis is the processor of the personal data described below. Where the Customer is itself a processor on behalf of another controller, askHermis acts as its sub-processor, and the Customer is responsible for obtaining the necessary instructions and authorisations.

This DPA does not cover personal data askHermis processes as a controller, such as data about the Customer’s account users for billing and account management. That is covered by our Privacy policy.

2. Details of the processing

Subject matterProviding the askHermis Service: AI-assisted guest communication, shared inbox, web check-in, upsells and integrations.
DurationThe term of the agreement, plus the period until deletion under this DPA.
Nature and purposeReceiving, storing, organising, analysing and transmitting data to answer Guests, draft and send replies, run check-in and upsell flows, sync with the Customer’s systems, and support the Customer.
Data subjectsThe Customer’s guests and prospective guests, people who contact the Customer through connected channels, and the Customer’s staff who use the Service.
Categories of dataContact details; booking and stay details; conversation content across channels, including call recordings and transcripts where voice is enabled; preferences and requests; check-in data such as identity document details and signatures where the Customer enables them; payment status of upsells; staff names and activity in the Service.
Special categoriesNot intended. Guests may volunteer such data in their messages; the Customer should configure its flows so that it is not requested.

3. Processing on documented instructions

askHermis processes personal data only on the Customer’s documented instructions, which are the agreement, this DPA and the Customer’s configuration and use of the Service, including transfers to third countries, unless EU or Member State law requires otherwise; in that case askHermis will inform the Customer before processing, unless the law prohibits it.

askHermis will inform the Customer immediately if, in its opinion, an instruction infringes data protection law.

The Customer is responsible for the lawfulness of the processing, for having a legal basis, and for providing the information data subjects are entitled to, including that they are interacting with an AI system.

4. Confidentiality

askHermis ensures that everyone authorised to process the personal data is bound by confidentiality obligations and has access only to what they need for their role.

5. Security

askHermis implements appropriate technical and organisational measures under Article 32 of the GDPR, including:

  • hosting of the platform and Customer data in the European Union;
  • encryption of data at rest (AES-256) and in transit (TLS 1.3);
  • role-based access control and the principle of least privilege for staff and systems;
  • separation of each Customer’s data within the platform;
  • a record of the actions agents take, available to the Customer;
  • use of infrastructure providers with SOC 2 reports, and an information security and privacy programme aligned with ISO/IEC 27001 and ISO/IEC 27701.

askHermis may update these measures as technology evolves, provided the overall level of protection is not reduced.

6. Sub-processors

The Customer gives askHermis general authorisation to engage sub-processors. The current list is published on our Sub-processors page.

askHermis will inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance. The Customer may object on reasonable data protection grounds within that period; the parties will then discuss a solution in good faith, and if none is found, the Customer may terminate the affected part of the Service.

askHermis imposes on each sub-processor, by contract, data protection obligations that offer at least the same level of protection as this DPA, and remains responsible to the Customer for their performance.

AI sub-processors process personal data only to generate a response to the Customer’s instructions. They do not use it to train or improve their models: they are engaged under zero-retention, no-training terms.

7. International transfers

Where personal data is transferred to a country outside the European Economic Area that does not benefit from an adequacy decision, askHermis ensures an appropriate safeguard under Chapter V of the GDPR, such as the European Commission’s Standard Contractual Clauses, or relies on the EU–US Data Privacy Framework where the recipient is certified.

8. Assistance to the Customer

Taking into account the nature of the processing, askHermis will assist the Customer:

  • to respond to requests from data subjects exercising their rights. If askHermis receives such a request directly, it will forward it to the Customer without undue delay and will not respond itself unless instructed;
  • with security, data protection impact assessments and prior consultations with supervisory authorities, under Articles 32 to 36 of the GDPR, with the information available to askHermis.

9. Personal data breaches

askHermis will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and will provide the information the Customer reasonably needs to meet its own notification obligations, as it becomes available. askHermis will take reasonable steps to contain the breach and limit its effects.

10. Deletion or return of data

When the Service ends, the Customer may request an export of its data within 30 days. After that period, askHermis deletes the Customer’s personal data from its systems, unless EU or Member State law requires it to be kept.

11. Information and audits

askHermis makes available to the Customer the information necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and allows for audits, including inspections, by the Customer or an auditor it mandates. Audits take place on at least 30 days’ written notice, during business hours, no more than once a year unless required by a supervisory authority or following a personal data breach, and under confidentiality. Each party bears its own costs.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the agreement, to the extent the law allows. On data protection matters, this DPA prevails over the rest of the agreement. This DPA is governed by the same law as the agreement.

For questions about this DPA or to request a signed copy, email team@askhermis.com.