LetsBot Menu
Get Started العربية

Meta Business Partner UK Registered Company

Legal terms

Data Processing Agreement

Our commitments as processor of the personal data you manage in LetsBot: instructions, security, sub-processors, breaches, deletion and international transfers.

Last updated
1 October 2026
Breach notice
Within 24 hours
Governing version
English
Questions and requests
support@letsbot.net
On this page (26)

About this agreement

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between the customer (the business that subscribes to LetsBot, "you") and BOT FOR DIGITAL SOLUTIONS LIMITED, a company registered in England and Wales under number 15477940, of 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ("LetsBot", "we", "us").

By accepting the Terms & Conditions you also enter into this DPA, including the transfer clauses incorporated by reference in Annexes IV to VI. They apply automatically to every customer from acceptance, before any Customer Personal Data is transferred, and no signature is needed.

Signed copies and bespoke documents. On request at support@letsbot.net, we will provide a copy of this DPA countersigned by us, or a bespoke agreement or document your organisation needs, such as a filled-in set of transfer clauses.

Order of precedence. If there is a conflict, the transfer clauses in Annexes IV to VI prevail, then this DPA, then the Terms & Conditions.

Language. The English version of this DPA governs; the Arabic version is provided for convenience. For the Brazilian ANPD standard clauses, the official Portuguese text governs.

Definitions

  • Customer Personal Data: personal data we process on your behalf in providing the service, including your contacts' details, messages, media and orders. Annex I has the details.
  • Sub-processor: any third party we engage to process Customer Personal Data.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • Data Protection Laws: the laws that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Saudi Personal Data Protection Law and its regulations, Brazil's LGPD, and Egypt's Law No. 151 of 2020 and its Executive Regulations.
  • "Controller", "processor", "data subject" and "processing" have the meanings in the Data Protection Laws. "Processor" includes an "operador" under the LGPD.

Roles and instructions

  1. You are the controller of Customer Personal Data (or a processor acting for another controller), and we are the processor.
  2. We process Customer Personal Data only on your documented instructions, including with regard to transfers to other countries. Your instructions are the Terms & Conditions, this DPA, the settings you choose in the panel (such as channels, integrations, AI features and retention periods), and any other written instructions we agree.
  3. If a law requires us to process Customer Personal Data other than on your instructions, we will tell you before we do so, unless that law prohibits it.
  4. We will tell you immediately if we believe an instruction infringes the Data Protection Laws.
  5. You are responsible for collecting the data lawfully and for having a lawful basis to message your contacts, including any consent that Meta or the law requires.
  6. We do not use Customer Personal Data for our own purposes, we do not sell it, and we do not use it to train AI models.

Our personnel

Only employees and contractors who need access to provide, support or secure the service can access Customer Personal Data, and all of them are bound to keep it confidential.

The people who have access to Customer Personal Data work mainly in Egypt, through our affiliate Bot for Digital Solutions LLC («بوت للحلول الرقمية» ش.ذ.م.م), under our instructions and on terms no less protective than this DPA.

Security

We apply the technical and organisational measures in Annex II, review them regularly, and will not reduce the overall level of protection during your subscription.

In addition, we commit to:

  • encrypted backups of workspace databases: every night for paying, trial and complimentary workspaces, and on a 10-day rotation for other workspaces, plus a daily backup of the central account database. Backups are kept in private storage, separate from the production server, on Google Cloud in the United States (us-east1), for 30 days and then deleted;
  • media files exchanged in conversations are kept in storage that cannot be browsed or listed, and are served through long, random links that are hard to guess (except contact profile pictures). Anyone who has the exact link can open the file. We are moving media to time-limited signed links;
  • recording every support entry into a workspace, and every sign-in, in that workspace's security log.

Sub-processors

  1. General authorisation. You authorise us to engage the sub-processors listed on our subprocessors page (Annex III).
  2. Advance notice. We will give at least 30 days' notice before we add or replace a sub-processor, by e-mail to everyone who has subscribed and by updating the page. To subscribe, write to support@letsbot.net with the subject "Subprocessor updates".
  3. Objection. You may object in writing during the notice period on reasonable data protection grounds. We will try to resolve your objection, for example by not using that sub-processor for your data. If we cannot, you may terminate the affected part of the service and receive a refund of any prepaid fees for the remaining period.
  4. Emergency replacement. If we must replace a sub-processor immediately to protect the security or continuity of the service, we will tell you as soon as possible, and you keep the same right to object.
  5. Equivalent obligations. We bind every third-party sub-processor by a written contract with data protection obligations no less protective than this DPA, and we remain liable to you for its performance.
  6. Integrations you choose, such as Meta (WhatsApp, Messenger, Instagram), e-commerce platforms and CRMs, are not our sub-processors. You connect them, and they process data under their own terms with you.

Personal data breaches

  1. We will notify you of any Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware of it. This is our standard in every country.
  2. We send the notice to the account owner's e-mail address, and in the panel where possible. As far as the information is available, it describes: the nature and cause of the breach; the categories and approximate number of data subjects and records; the likely consequences; the measures taken or proposed to contain it; and our contact point.
  3. If we do not have all the information at once, we will provide it in phases without undue delay, and update you regularly until the incident is closed.
  4. We will help you meet your own duties to notify authorities and data subjects, including the 72-hour deadlines in the EU, the UK and Saudi Arabia, and the three-business-day deadline in Brazil.
  5. A notice is not an admission of fault or liability.

Requests from data subjects

  1. If we receive a request from a data subject about Customer Personal Data, we will forward it to you within 48 hours and will not answer it without your authorisation, other than to say we have passed it on.
  2. The panel lets you export, correct and delete contacts, conversations and messages. Where these tools are not enough, we will give you reasonable help.
  3. Our help takes into account your legal deadlines, including six working days in Egypt.

Assessments and consultations

We will give you the information you reasonably need to carry out a data protection impact assessment, a transfer risk assessment, or a prior consultation with an authority. Where the law requires you to share the relevant impact assessment with us, we will receive it.

Deletion and return of data

  1. During your subscription you can, at any time, export your data, delete any single conversation (which erases its messages and media), or delete your whole workspace from the panel. Giving a reason is optional.
  2. When the service ends, your data remains available for export for 30 days. When a workspace is deleted, we delete Customer Personal Data from our live systems within 30 days, including media, the archived copy, files and stored responses held at our AI provider, and messages held by our QR-code connection service. Copies in backups expire within a further 30 days.
  3. We keep only what the law requires us to keep, and continue to protect it under this DPA until it is deleted.
  4. On request, we will confirm the deletion in writing.

Information and audits

  1. We will make available the information needed to demonstrate our compliance with this DPA, and answer reasonable security questionnaires.
  2. If that information is not enough, you or an independent auditor bound by confidentiality may audit us once every 12 months, with 30 days' notice, during business hours, and without putting other customers' data at risk. This limit does not apply after a Personal Data Breach or when an authority requires the audit.
  3. Each party bears its own costs, unless the audit reveals a material breach by us.
  4. We will cooperate with competent supervisory authorities, including the Saudi Data and AI Authority (SDAIA), when they ask.

International transfers and foreign laws

  1. Where data is processed. Customer Personal Data is hosted on Google Cloud in the United States (region us-east1), accessed remotely by our staff, who work mainly in Egypt through our affiliate, and processed by sub-processors in the locations shown on their page. All our servers and backups are in the United States; we do not offer hosting in any other region.
  2. Transfer mechanisms. The clauses in Annex IV (EU and UK), Annex V (Brazil) and Annex VI (Saudi Arabia) form part of this DPA for every customer, and govern each transfer to which the corresponding law applies.
  3. Foreign laws we are subject to. We are a UK company subject to UK law. The data is hosted with a US provider, and US authorities can require US providers to disclose data under US law, including the CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act. Our affiliate in Egypt is subject to Egyptian law. We are not aware of any of these laws preventing us from meeting this DPA, and will tell you promptly if that changes.
  4. Requests from public authorities. If we receive a binding request from a public authority to disclose Customer Personal Data, we will tell you unless the law prohibits it, ask the authority to come to you, challenge requests that are unlawful or excessive, and disclose only the minimum required.

AI features

  1. When you turn on AI replies, AI agents, voice-note transcription or AI tools, we send to OpenAI (a sub-processor in the United States) the data the feature needs: messages, conversation history, voice notes, knowledge files and product catalogue, and the contact's name and number where the feature uses them.
  2. OpenAI keeps the responses it generates under its API data policy. Under OpenAI's API terms, data sent through the API is not used to train its models by default (see OpenAI's business terms), and we have not opted in to any training use.
  3. We do not use Customer Personal Data to train any model. What the "learn from history" feature learns stays inside your workspace.
  4. These features are optional and you can switch them off at any time. When you delete your workspace, we delete the files stored for it at OpenAI.
  5. You are responsible for telling your customers that replies may be generated by AI where the law requires it.

Support access to your workspace

  1. Our support staff enter your workspace only to provide support.
  2. Every entry is recorded in your workspace's security log, which you can review.
  3. If you turn on two-factor authentication for your workspace, our staff can enter it only with your explicit approval.

Liability

Each party's liability under this DPA is subject to the limitations in the Terms & Conditions, except for liability that cannot be limited by law, and without affecting data subjects' rights under the transfer clauses in Annexes IV to VI, which nothing in this DPA or the Terms & Conditions limits.

Term, changes and governing law

  1. This DPA applies for as long as we process Customer Personal Data.
  2. We may update this DPA to keep up with the law or the service. We will give 30 days' notice of any material change, and no change will reduce the level of protection during your paid subscription term.
  3. This DPA is governed by the laws of England and Wales, and its courts have jurisdiction, except that each set of transfer clauses in Annexes IV to VI is governed by the law and courts it specifies.

Country terms: Saudi Arabia

For the Personal Data Protection Law and its Implementing Regulation (Article 17):

  • The purpose, categories of data and duration of the processing are in Annex I.
  • We notify you of a breach without undue delay and within 24 hours (section 7).
  • The foreign laws we are subject to, and their impact, are described in section 12.
  • If Saudi law requires us to make a disclosure, we will notify you of it.
  • Sub-processors and other recipients are identified in Annex III, and we notify you before any change, with a right to object (section 6).
  • We forward data subject requests within 48 hours (section 8), and accept assessments and audits (section 11).
  • Transfer clauses: Annex VI.

Country terms: Brazil

For the LGPD we act as "operador":

  • We process data on your instructions (Article 39) and keep a record of processing operations (Article 37).
  • We apply the security measures in Annex II, and our security duty continues after processing ends (Articles 46 and 47).
  • We notify you of a breach within 24 hours so that you can notify the ANPD and data subjects within three business days (Article 48).
  • We delete data when processing ends, under section 10 (Article 16).
  • Nothing in this DPA limits our liability to data subjects where the LGPD imposes it.
  • Transfer clauses: Annex V. On request we provide a Portuguese summary of the international transfer that you can publish for your customers.

Country terms: Egypt

For Law No. 151 of 2020 and its Executive Regulations:

  • Our affiliate in Egypt is Bot for Digital Solutions LLC («بوت للحلول الرقمية» ش.ذ.م.م), commercial register no. 223572 (Cairo Investment registry office), Tower 22, 3rd floor, Masaken Sidi Abdel Rahim, Seger, Tanta 1st, Gharbia, Egypt.
  • We obtain any licence or permit the law requires for our processing and cross-border transfers before relying on it, and appoint a data protection officer registered with the Personal Data Protection Center.
  • In addition to notifying you within 24 hours, we notify the Personal Data Protection Center of a breach within 72 hours where the law requires us to do so as processor, in coordination with you.
  • We work with you to answer data subject requests within six working days.
  • You are responsible for obtaining data subjects' consent where the law requires it, including consent to transfers outside Egypt.

Country terms: EU and UK

This DPA contains the terms required by Article 28(3) of the EU GDPR and the UK GDPR: instructions (section 3), confidentiality (section 4), security (section 5 and Annex II), sub-processors (section 6), assistance with data subject requests (section 8) and with security, breaches and assessments (sections 5, 7 and 9), deletion and return (section 10), and information and audits (section 11).

The United Kingdom, where we are established, is covered by an adequacy decision of the European Commission. Annex IV (the EU Standard Contractual Clauses and the UK Addendum) is nevertheless incorporated for every customer and governs any transfer of Customer Personal Data that the EU GDPR or UK GDPR does not otherwise permit, including our onward transfers to the United States.

Annex I: Details of the processing

Subject matterProviding the LetsBot service: a shared multichannel messaging inbox, contact management, campaigns, automation, integrations and AI features.
DurationThe subscription term, then the deletion period in section 10.
NatureReceiving and sending through channels, storage, organisation, search, display, export, AI processing and voice transcription where you enable them, and deletion.
PurposeProviding, supporting and securing the service according to your settings and instructions.
Data subjectsYour customers and prospects whom you message, visitors to the web chat on your site, your team members who use the service, and people who appear in the messages and files you process.
Categories of dataName, phone number, channel identifiers and e-mail address; message content (text, images, video, documents, voice notes, contact cards and locations); call recordings where enabled; order and cart data from connected stores (name, phone, address, items and amounts); labels, custom fields and notes; consent and opt-out records; survey answers; technical data of web-chat visitors; AI outputs and voice-note transcripts.
Sensitive dataNot required by the service. It may appear in message content depending on your use, which you control.
FrequencyContinuous.
RetentionFor the subscription term according to your settings, then as set out in section 10.
Sub-processorsAnnex III.

Annex II: Technical and organisational measures

These measures are in place today:

  • Encryption in transit: TLS 1.3 at the Cloudflare edge with HSTS, and TLS certificates on the origin server.
  • Encryption at rest: Google Cloud default encryption with Google-managed keys for disks and storage buckets, plus application-level encryption of channel access tokens, integration and webhook secrets, two-factor secrets, survey answers and consent records.
  • Passwords and tokens: passwords hashed with bcrypt; API tokens stored as hashes.
  • Isolation: a separate database for each workspace.
  • Network: databases and caches are not reachable from the internet; Cloudflare DDoS protection and web application firewall; Turnstile bot protection on public forms.
  • Server hardening: CageFS account isolation, Imunify360 firewall and malware scanning, and live kernel security patching (KernelCare).
  • Access control: per-user roles and permissions, a separate sign-in guard for internal administration tools, two-factor authentication available to every workspace, and sign-in IP restrictions.
  • Logging: a security log for each workspace covering sign-ins and failed attempts, two-factor and role changes, support access and API key rotation.
  • Integrations: signature verification on incoming data from Meta, Salla and Zid, and a separate signing secret for each new outgoing webhook.
  • Private storage: documents, e-mail attachments, call recordings, backups and archived workspaces are kept in private storage buckets with public access prevented.
  • Conversation media: kept in storage that cannot be browsed or listed, and served through long, random links that are hard to guess (except contact profile pictures); the move to time-limited signed links is in progress.
  • Backups: nightly backups of the databases of paying, trial and complimentary workspaces, a 10-day rotation for other workspaces, and a daily backup of the central account database; kept for 30 days in private storage in the United States (us-east1).
  • Deletion: every customer can delete the whole workspace from the panel, including its media, archived copy and AI files at OpenAI; deleting a conversation erases its messages and media.
  • Data minimisation: incoming platform payloads deleted after 14 days, server logs after 14 days, and call recordings after 90 days by default.
  • Monitoring: external uptime monitoring, and internal monitoring of memory, databases, sessions and queues with real-time alerts, in which phone numbers and e-mail addresses are masked.

Annex III: Sub-processors

The current list of sub-processors, with the data they process, their locations and transfer safeguards, is published on our subprocessors page and forms part of this DPA.

Annex IV: EU Standard Contractual Clauses and UK Addendum

The Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference:

  • Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you act as a processor for someone else.
  • Clause 7 (docking clause): included.
  • Clause 9(a): Option 2 (general written authorisation), with 30 days' advance notice.
  • Clause 11(a): the optional language does not apply.
  • Clause 13: the competent supervisory authority is determined under Clause 13(a) according to your situation.
  • Clause 17: Option 1, governed by the law of Ireland. Clause 18: the courts of Ireland.
  • Annex I.A: the parties in section 1 (you as data exporter, us as data importer). Annex I.B: Annex I of this DPA. Annex I.C: as determined under Clause 13. Annex II: Annex II of this DPA. Annex III: Annex III of this DPA.

For transfers governed by UK law, the ICO's International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated by reference: Table 1, the parties above; Table 2, the clauses selected above; Table 3, Annexes I to III; Table 4, either party may end the Addendum as set out in its Section 19.

Annex V: Brazilian standard contractual clauses (ANPD)

For international transfers of data governed by the LGPD, by accepting the Terms & Conditions the parties adopt the standard contractual clauses in Annex II of Resolution CD/ANPD No. 19/2024 in full and without any change. The official Portuguese text governs.

  • Section I: you are the exporter (controller) and we are the importer (operator); the transfer is described in Annex I.
  • Section III (security measures): Annex II.
  • Section IV: no additional clauses.

No other term of this DPA or the Terms & Conditions may exclude, modify or contradict these clauses.

Annex VI: Saudi standard contractual clauses (SDAIA)

For transfers of personal data outside the Kingdom, by accepting the Terms & Conditions the parties adopt the Standard Contractual Clauses for Personal Data Transfer issued by the Saudi Data and AI Authority (SDAIA), Template 2 (controller to processor), without modification.

  • Parties: you are the exporter and we are the importer.
  • Appendices 1 to 3 of the template: section 1, Annex I and Annex II of this DPA.
  • These clauses are governed by the laws of the Kingdom of Saudi Arabia and its courts have jurisdiction, as the clauses provide.
  • We notify you of a breach within 24 hours, forward data subject requests within 48 hours, and cooperate with SDAIA in any audit.
  • We tell you which sub-processors outside the Kingdom have acceded to these clauses, and which have not before we rely on them for your data.

Signed copy

Need a countersigned copy or a bespoke document?

Send us your company name, workspace ID and what you need, and we will send you a countersigned copy or the document you need.