Embermont Concierge

Data Processing Agreement

Last updated 11 September 2026

In short. When you put Embermont Concierge on your website, you decide why your visitors' personal data is collected, so you are the controller. We handle that data only to run the service for you, so we are your processor. UK data protection law requires a written agreement between us setting out how we do that. This is it.

1. Who this agreement is between, and when it applies

This agreement is between Embermont Ltd, registered in England and Wales, company number 17400705, registered office 124 City Road, London, EC1V 2NX (“we”, “us”), and the business that holds an Embermont Concierge account (“you”).

It forms part of our Terms of Service and applies automatically whenever we process personal data on your behalf. If this agreement and the Terms conflict on a data protection matter, this agreement takes priority.

It covers only data we process for you. Information about you as our customer, such as your account login, is covered by our Privacy Policy, where we are the controller.

“UK GDPR”, “personal data”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018.

2. What we process, and why

The subject matter, nature, purpose and duration of the processing, and the types of personal data and people involved, are set out in Schedule 1.

3. We act only on your instructions

We process personal data only on your documented instructions. Your instructions are these Terms and this agreement, plus the choices you make when you set up and use the service, for example which pages to train on, which enquiry fields to collect, your retention setting, and any integrations you switch on.

The exception is where the law requires us to process data in another way. If that happens, we will tell you before we do it, unless the law forbids us from telling you.

If we believe an instruction from you breaks data protection law, we will tell you.

4. Confidentiality

Only people at Embermont who need access to run or support the service can access your personal data, and they are bound by confidentiality. We open your conversation records only when you ask us for help, or where we need to in order to keep the service running or to comply with the law.

5. Security

We maintain the technical and organisational measures described in Schedule 2, which are designed to protect personal data to a level appropriate to the risk, as Article 32 of the UK GDPR requires. We may change these measures over time, but not in a way that reduces the overall level of protection.

No set of measures removes all risk. The optional tools described in our Terms, such as personal-data filters, are configuration choices for you and are not part of the measures we commit to here.

6. Sub-processors

You give us general authorisation to use the sub-processors listed in Schedule 3.

Before we add or replace a sub-processor, we will update Schedule 3 and email the address on your account at least 14 days in advance. If you object on reasonable data protection grounds, tell us within that period. We will try to address the concern. If we cannot, you may close your account before the change takes effect.

We impose data protection obligations on each sub-processor that are equivalent in substance to this agreement. We remain responsible to you for how they perform those obligations.

Services you choose to connect are not our sub-processors. If you configure your own AI provider, an online shop or other system, a webhook, or any other third-party service, that service receives data because you instructed it, and your relationship with it is your own.

7. Transfers outside the UK

Some sub-processors process data outside the UK, as shown in Schedule 3. We make such transfers only where they are permitted by UK data protection law. That means a UK adequacy decision, or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

8. Helping you respond to your visitors

Your visitors have rights under data protection law, including to access or erase their personal data. The service gives you tools to respond, including finding and deleting conversations and enquiries, and a way for visitors to erase their own conversation from the chat.

If a visitor contacts us directly about data we process for you, we will pass the request to you without undue delay and will not respond to it ourselves unless you ask us to. Where the tools are not enough, we will give you reasonable help.

9. Personal data breaches

If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay. We will give you the information we have that you need to meet your own obligations, including to notify the Information Commissioner's Office and affected people where required. As a minimum, that means what happened, the kinds of data and roughly how many people are affected, the likely consequences, and what we are doing about it. Where we do not have all of this at once, we will provide it as we learn it.

10. Other help we give you

We will give you reasonable help, taking into account the information available to us, with your data protection impact assessments and any prior consultation with the Information Commissioner's Office that relates to the service.

11. When the processing ends

When you delete a site or close your account, we delete the personal data we process for you for that site or account from our live systems. Before you do, you can export your enquiries from your dashboard, and ask us for a copy of your conversations.

Copies held in backups, if any, are deleted as those backups expire under our providers' normal retention cycles. We may also keep data where the law requires us to. Until they are deleted, those copies remain protected by this agreement and are not used for anything else.

12. Information and audits

We will make available the information reasonably needed to show that we meet our obligations under this agreement. We will answer reasonable written questions about our processing.

Where that information is not enough, you, or an independent auditor you appoint who is bound by confidentiality, may carry out an audit. You must give at least 30 days' written notice, audit no more than once in any 12 months (unless there has been a personal data breach or a regulator requires it), and cover your own costs. The audit must be conducted so as not to disrupt the service or expose other customers' data.

13. Your responsibilities

As the controller, you are responsible for:

14. Liability and duration

This agreement lasts as long as we process personal data for you, including during deletion under section 11. Each party's liability under it is subject to the limits in section 10 of our Terms, except where the law does not allow liability to be limited.

15. Changes and governing law

We may update this agreement, for example to reflect a change in the law or to Schedule 3 under section 6. If a change materially affects you, we will tell you before it takes effect. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Schedule 1 — Details of the processing

Subject matterProviding Embermont Concierge, a chat assistant you add to your website.
Nature of the processingCollecting, storing, retrieving, organising and deleting data; sending messages to an AI model to generate replies; presenting conversations and enquiries to you; sending you notifications.
PurposeTo answer your visitors' questions from your content, pass enquiries to you, let you read and take over conversations, and show you usage insights.
DurationFor as long as you use the service, and then until deletion under section 11.
People whose data is processedVisitors to your website who use the chat assistant. People named on the public pages of your website that you choose to train the assistant on.
Types of personal data
  • Whatever visitors type into the chat. This may include their name and contact details, and anything else they choose to share.
  • Enquiry details submitted through the chat. By default these are name, email address and phone number, plus any other fields you add.
  • A conversation identifier stored in the visitor's browser so their conversation survives a page refresh.
  • A visitor count based on a one-way hash that changes daily. No raw IP address or user agent is stored for this.
  • Personal data that appears on the public pages of your website that you choose to train on, such as staff names.
Special-category dataNone is intended. The service is not designed for it, and our Terms say you must not configure it to collect such data. A visitor may still volunteer it in a message.
RetentionConversations are kept according to the retention setting on your account, and deleted with the site. Enquiries are kept until you delete them or the site.

Schedule 2 — Security measures

Schedule 3 — Sub-processors

Sub-processorWhat it doesWhere
Google CloudApplication hosting and file storageEuropean Union (Belgium, europe-west1)
MongoDB Atlas, hosted on Amazon Web ServicesDatabase hostingEuropean Union (Ireland, AWS eu-west-1)
OpenAIGenerating chat replies, and processing your site content so the assistant can search it. Receives visitor messages and relevant extracts of your content.United States
IONOSSending enquiry notification emails that contain the enquiry details, where you have turned them on and chosen to include the details. By default these emails contain only a link to the enquiry in your dashboard.UK and EEA, and other locations where IONOS's data-processing terms and international-transfer safeguards allow

Notifications to your devices. If you turn on browser notifications, a short preview of a new message is sent to your own browser through that browser's push service. The notification is encrypted in transit, and the push service cannot read it.