Legal
Data Processing Agreement
What we owe your business for the personal data in its conversations: on whose instruction we hold it, who else touches it, where it goes, and what happens when something goes wrong.
What this agreement is
This applies whenever your business uses Oleon Workspace to hold personal data about other people: the customers you message, the contacts behind them, and whatever your team writes down about them. It forms part of the terms. You do not have to sign anything separate for it to apply, and it applies from the moment you connect a channel.
If your business has signed a data processing agreement with us as part of a negotiated contract, that document governs where it says something different, in the same way a signed proposal governs over the terms.
Who decides and who acts
- You decide
- For your end users' personal data. Your business chose to message them, chose what to ask them and chose what to keep. You are responsible for having a lawful basis to do it and for telling them what you do with what they send.
- We act
- We hold that data and do things to it because you told us to. We do not decide what it is for, and we do not use it for anything of our own.
- Where we decide
- For your own account: the people who sign in, the billing details, and the record of what those people did. That is ours to answer for, and the privacy policy rather than this agreement covers it.
What we process, and for how long
- What we do with it
- Run Oleon Workspace for you: carry messages on the channels you connect, store them, show them to your team, and where you have turned the agent on, generate replies.
- Whose data
- The people your business exchanges messages with, and anyone your team records in a contact or a note.
- What data
- Names, phone numbers and profile handles as the channel supplies them. Message content in both directions. Attachments: images, audio, video, documents and locations. The labels, notes and conversation state your team adds.
- How long
- While your project is open, and then on the timetable in the deletion section below.
- Sensitive data
- The product does not ask for it and does not need it. If your business uses it for conversations that carry health, financial or similarly sensitive data, that is your decision to make and worth telling us about, so we can agree what it needs before it matters.
Your instructions
We process that data only on your instructions. Your instructions are the terms, this agreement, and what you actually do in the product: connecting a channel, turning the agent on, exporting a conversation, deleting one.
The privacy policy describes what the product does. It is not your instruction to us, and we cannot widen what we are allowed to do by editing a page we control. If we ever think an instruction of yours would break a law that applies to us, we will tell you rather than quietly not do it.
Our own people
Inside Olee AI, access is limited to the people who need it to run the product or to answer a support request you raised. It is decided by role and checked on the server on every request rather than hidden in an interface, and everyone who has it is under a duty of confidentiality that outlasts their employment here.
Administrative actions are logged, and those logs are visible to you rather than only to us. If you want to know whether one of our people opened a conversation of yours, that is a question with an answer.
Who else we use
Parts of the product run on other people's services, and the privacy policy sets out what each of them does. You authorise us to use them for those purposes.
You can have the current list in full, by name, by writing to the address at the foot of this page. We will send it and we will keep it current. This is a right rather than a favour, and a security review or a procurement questionnaire is reason enough to ask.
Before we add a provider that will process your conversations, or swap one for another, we will email account holders at least 30 days beforehand. If you object on reasonable data protection grounds, tell us inside those 30 days and we will work to find a way round it. If there is none, you may cancel the affected service without penalty, and anything you have paid for a period you will now not get comes back.
Each of them is under a written contract holding it to the obligations this agreement puts on us, and we stay answerable to you for what it does with your data.
Where it is processed
Outside Sri Lanka, for most of it. The platform the application runs on, the database and the storage behind attachments, the cache and the queue, the email delivery provider and the AI model providers are all abroad. Realtime delivery is the exception and runs on our own servers here.
Sri Lanka's Personal Data Protection Act allows data to leave the country where the receiving country has been found to protect it adequately, or where the transfer is governed by a binding instrument. No adequacy decision has been issued yet, so each provider holds the data under a written contract binding it to process only on our instruction, to protect it, and to return or delete it when we are done. Where your own obligations turn on the mechanism behind a particular transfer, ask and we will tell you what is in place.
The agent and the model providers
This is the part of the processing most worth reading twice, because it is where your conversations leave our servers.
- Where you turn the agent on for a project, the content of an incoming message and enough of the recent conversation to make sense of it are sent to a model provider so a reply can be generated. Material you train it on is sent once, to be turned into a search index.
- It happens only for projects with the agent enabled. A project running a human inbox alone sends nothing to a model provider.
- The providers are under contract not to train on your data, not to keep it beyond what answering requires, and not to use it for anything of their own.
- We do not train our own models on your conversations and we do not permit anyone else to train theirs.
- Turning the agent off stops the sending. It is your decision to make and it is reversible.
How it is protected
We keep technical and organisational measures appropriate to the risk. These are the ones that carry the weight:
- Everything travels over TLS, between you and us and between us and every provider above.
- Sensitive fields, including conversation history and stored credentials, are encrypted with keys held separately from the data.
- What a person can see is decided by their role in that organisation and checked on the server on every request.
- Two-factor authentication is available on every account, and we recommend it for anyone who can read conversations.
- Administrative actions are logged, and you can read those logs.
The first two of those are also terms rather than only commitments here: the terms say that your data is never used to train a model and that it is encrypted in transit and at rest, and that weakening either is a change that needs a month's notice and never reaches back over data already handled under the old wording.
Security is not a fixed list and we may replace a measure with a better one. What we will not do is lower the overall level of protection while you are a customer.
When something goes wrong
If there is a breach affecting personal data you are responsible for, we will tell you within 72 hours of becoming aware of it. Not when the investigation is finished and not when we have worked out how to say it: within 72 hours, with what we know at the time.
- What happened as far as we can tell, and when.
- Which categories of data are involved and roughly how many people.
- What we are doing about it, and what we suggest you do.
- A named person to talk to, and more as we learn it.
We will notify Sri Lanka's Data Protection Authority inside the same 72 hours where the rules made under the Act require it. Telling the people affected is yours to do, because they are your customers and it is your relationship with them, and we will give you what you need to do it properly.
When one of your customers asks
Someone your business has messaged may ask to see, correct or delete what is held about them. That request is yours to answer, and the product is built so that you can: you can find the conversation, ask us to export it, and delete it.
If one of them writes to us instead we will not act on it. We will tell them to ask you, pass the request on, and press for an answer. What we will not do is delete a business's records because a third party asked us to, and you would not want us to for your own.
Where a request needs more than the product gives you, write to us and we will help. There is no charge for that unless it becomes genuinely repetitive.
Getting it back, and getting rid of it
You can ask us for an export of your conversations at any time while the project is open, and we will give it to you in a form you can read and keep.
When a project or an organisation closes, the data stays available for 30 days so you can ask for that export. We delete it within 90 days of the closure. What remains after that is only what a law requires us to keep, which in practice means billing records, kept for as long as Sri Lankan tax and company law requires and used for nothing else.
Backups age out on their own cycle rather than being edited, so a deleted conversation can survive in a backup for a short period after it has gone from the product. It is not restored into the product and nothing reads it.
Checking us
You can ask us to show that we are doing what this agreement says. In practice that is a security questionnaire, the current subprocessor list, or a written answer about one specific control, and we will answer within 30 days.
Where your own regulator or auditor needs more than that, write to us and we will agree what is reasonable, including an audit at your cost, on reasonable notice, and no more than once a year unless a breach or a regulator makes another one necessary.
How this fits the rest
This agreement is part of the terms. The limits on liability there apply to it as they apply to everything else, and nothing here creates a second cap or a separate one.
Where a signed agreement between us says something different about data processing, the signed document governs. Where this agreement and the privacy policy disagree about your end users' data, this one governs, because this is the one your business has with us.
Changes to this agreement
We may update this as the product changes, and the date at the top says when it last happened. Where a change materially affects your rights or ours we will email account holders at least 30 days before it takes effect. A new provider gets the same 30 days and the same right to object, as the section on who else we use sets out.
Contact
The subprocessor list, security questionnaires and anything else a procurement or compliance review needs go here.
Oleon