Data Processing Agreement

Last updated July 21, 2026

1.Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Humaner ("Processor", "we", "us") and the customer organization using Humaner ("Controller", "you") for the Humaner service described in our Terms of Service.

This DPA applies when Humaner processes personal data on your behalf in connection with AI customer support agents, widgets, shareable links, React components, APIs, knowledge retrieval, memory features, analytics, and desk handoff.

If there is a conflict between this DPA and other documents regarding personal data processing, this DPA controls for that subject matter.

2.Roles of the parties

You are the Controller of Customer Personal Data (as defined below). Humaner is the Processor. Each party will comply with applicable data protection laws, including the GDPR and UK GDPR where applicable.

Humaner is an independent controller for account registration data, billing contacts, website analytics on humaner.io, and other data we collect for our own business operations, as described in the Privacy Policy.

3.Definitions

Capitalized terms not defined here have the meaning in the Terms of Service or applicable data protection law.

  • Customer Personal Data — personal data contained in end-user conversations, session metadata, knowledge content that includes personal data, desk/handoff records, and other personal data you or your end-users submit to the Service for processing on your behalf.
  • Subprocessor — a third party engaged by Humaner to process Customer Personal Data in connection with the Service.
  • Applicable Data Protection Law — GDPR, UK GDPR, and other privacy laws that apply to the processing under this DPA.

4.Subject matter and duration

Subject matter: provision of Humaner agents that answer from your knowledge sources, maintain conversation context where enabled, connect configured integrations, and escalate to your team with preserved context.

Duration: for the term of your subscription and any period required to delete or return Customer Personal Data after termination, plus any longer period required by law.

Nature and purpose: hosting, transmission, storage, retrieval, analysis for support delivery, generation of AI responses, embeddings/search, memory, analytics within your workspace, and desk handoff workflows.

5.Types of personal data and data subjects

Data subjects typically include your website or product visitors, customers, and other individuals who interact with your Humaner agents, as well as individuals whose personal data appears in knowledge sources you upload.

Categories of personal data may include identifiers, contact details, message content, technical metadata (IP address, device/browser information), support history, and any other personal data you choose to include in knowledge or conversations. You determine the categories by how you configure and use the Service.

Humaner is not intended for processing special categories of personal data unless you have a lawful basis and configure appropriate safeguards. Industry guardrails may block certain sensitive topics, but you remain responsible for preventing prohibited or high-risk processing.

6.Processing instructions

Humaner will process Customer Personal Data only on documented instructions from you, including configuration in the dashboard (agents, knowledge, retention, integrations, and optional product-improvement settings), unless required by law. If legal requirements conflict with your instructions, we will inform you unless prohibited.

You instruct Humaner to process Customer Personal Data to provide the Service, including model inference, retrieval, caching, memory (where enabled), analytics, and handoff features you activate.

7.Confidentiality

Humaner ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security training.

8.Security measures

Humaner implements appropriate technical and organizational measures to protect Customer Personal Data against unauthorized access, loss, or alteration, taking into account the nature of AI support processing. Measures include access controls, encryption in transit, least-privilege access, monitoring, and secure development practices, as further described on our Security page.

You are responsible for securing your accounts, API keys, domain allowlists, and the systems where you embed Humaner.

9.Subprocessors

You authorize Humaner to engage Subprocessors to deliver the Service. Current categories and examples include:

  • Anthropic — large language model inference for agent responses.
  • Redis (Redis Cloud / Redis Iris) — vector search, semantic cache, agent memory, and context retrieval.
  • Supabase — database and authentication infrastructure.
  • Polar — subscription billing (account/billing data; may process limited customer identifiers).
  • Resend — transactional email.
  • OpenAI — text embeddings for knowledge search.
  • Hosting and CDN providers — application hosting and delivery.

10.Subprocessor changes

Humaner will impose data-protection obligations on Subprocessors that are no less protective than those in this DPA. We will provide notice of material Subprocessor changes (for example via email, dashboard notice, or an updated list). You may object on reasonable data-protection grounds within thirty (30) days. If we cannot reasonably accommodate the objection, you may terminate the affected Service as your sole remedy.

11.Assistance with data subject rights

Taking into account the nature of processing, Humaner will assist you with appropriate technical and organizational measures to respond to requests from data subjects exercising rights under Applicable Data Protection Law, insofar as possible through the Service (for example deletion tools and export capabilities) or via privacy@humaner.io.

If Humaner receives a request directly from an end-user of your agent, we will direct the individual to you where appropriate, unless we are legally required to respond ourselves.

12.Personal data breach

Humaner will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations.

13.DPIAs and consultations

Upon reasonable request, Humaner will provide information reasonably necessary for you to carry out data protection impact assessments and prior consultations with supervisory authorities, to the extent relating to Humaner's processing of Customer Personal Data.

14.International transfers

Where Humaner transfers Customer Personal Data from the EEA, UK, or Switzerland to a country not recognized as providing adequate protection, Humaner will ensure appropriate safeguards, such as Standard Contractual Clauses (and UK/Swiss addenda where required), or another lawful transfer mechanism.

Details of transfer safeguards are available on request at privacy@humaner.io.

15.Return and deletion

Upon termination of the Service, or upon your written request, Humaner will delete Customer Personal Data or return it to you, and delete existing copies, unless retention is required by law or necessary for security, dispute resolution, or backup cycles for a limited period.

Default conversation retention is 90 days unless you configure otherwise. Knowledge sources remain until you delete them or your account is closed.

16.Audits and information

Humaner will make available information reasonably necessary to demonstrate compliance with this DPA. Where an on-site or detailed audit is required by Applicable Data Protection Law and cannot be satisfied by documentation, the parties will agree in advance on scope, timing, confidentiality, and frequency. Audits must avoid unreasonable disruption and protect other customers' data.

17.Your obligations as controller

You represent that you have a lawful basis to process Customer Personal Data and to instruct Humaner to process it. You will not instruct Humaner to process data in violation of Applicable Data Protection Law.

You are responsible for providing required notices to end-users, obtaining consents where required, configuring retention and access appropriately, and ensuring knowledge uploads do not include data you are not permitted to process.

18.Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent Applicable Data Protection Law prohibits such limitation.

19.Order of precedence

Regarding the processing of Customer Personal Data: (1) this DPA, (2) the Terms of Service, (3) the Privacy Policy (for transparency about Humaner's independent controller activities). For all other matters, the Terms of Service control.

20.Contact

For DPA or processor questions, email privacy@humaner.io. For security incidents, email security@humaner.io.