Embermont Concierge
Data Processing Agreement
Last updated 11 September 2026
1. Who this agreement is between, and when it applies
This agreement is between Embermont Ltd, registered in England and Wales, company number 17400705, registered office 124 City Road, London, EC1V 2NX (“we”, “us”), and the business that holds an Embermont Concierge account (“you”).
It forms part of our Terms of Service and applies automatically whenever we process personal data on your behalf. If this agreement and the Terms conflict on a data protection matter, this agreement takes priority.
It covers only data we process for you. Information about you as our customer, such as your account login, is covered by our Privacy Policy, where we are the controller.
“UK GDPR”, “personal data”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018.
2. What we process, and why
The subject matter, nature, purpose and duration of the processing, and the types of personal data and people involved, are set out in Schedule 1.
3. We act only on your instructions
We process personal data only on your documented instructions. Your instructions are these Terms and this agreement, plus the choices you make when you set up and use the service, for example which pages to train on, which enquiry fields to collect, your retention setting, and any integrations you switch on.
The exception is where the law requires us to process data in another way. If that happens, we will tell you before we do it, unless the law forbids us from telling you.
If we believe an instruction from you breaks data protection law, we will tell you.
4. Confidentiality
Only people at Embermont who need access to run or support the service can access your personal data, and they are bound by confidentiality. We open your conversation records only when you ask us for help, or where we need to in order to keep the service running or to comply with the law.
5. Security
We maintain the technical and organisational measures described in Schedule 2, which are designed to protect personal data to a level appropriate to the risk, as Article 32 of the UK GDPR requires. We may change these measures over time, but not in a way that reduces the overall level of protection.
No set of measures removes all risk. The optional tools described in our Terms, such as personal-data filters, are configuration choices for you and are not part of the measures we commit to here.
6. Sub-processors
You give us general authorisation to use the sub-processors listed in Schedule 3.
Before we add or replace a sub-processor, we will update Schedule 3 and email the address on your account at least 14 days in advance. If you object on reasonable data protection grounds, tell us within that period. We will try to address the concern. If we cannot, you may close your account before the change takes effect.
We impose data protection obligations on each sub-processor that are equivalent in substance to this agreement. We remain responsible to you for how they perform those obligations.
Services you choose to connect are not our sub-processors. If you configure your own AI provider, an online shop or other system, a webhook, or any other third-party service, that service receives data because you instructed it, and your relationship with it is your own.
7. Transfers outside the UK
Some sub-processors process data outside the UK, as shown in Schedule 3. We make such transfers only where they are permitted by UK data protection law. That means a UK adequacy decision, or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
8. Helping you respond to your visitors
Your visitors have rights under data protection law, including to access or erase their personal data. The service gives you tools to respond, including finding and deleting conversations and enquiries, and a way for visitors to erase their own conversation from the chat.
If a visitor contacts us directly about data we process for you, we will pass the request to you without undue delay and will not respond to it ourselves unless you ask us to. Where the tools are not enough, we will give you reasonable help.
9. Personal data breaches
If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay. We will give you the information we have that you need to meet your own obligations, including to notify the Information Commissioner's Office and affected people where required. As a minimum, that means what happened, the kinds of data and roughly how many people are affected, the likely consequences, and what we are doing about it. Where we do not have all of this at once, we will provide it as we learn it.
10. Other help we give you
We will give you reasonable help, taking into account the information available to us, with your data protection impact assessments and any prior consultation with the Information Commissioner's Office that relates to the service.
11. When the processing ends
When you delete a site or close your account, we delete the personal data we process for you for that site or account from our live systems. Before you do, you can export your enquiries from your dashboard, and ask us for a copy of your conversations.
Copies held in backups, if any, are deleted as those backups expire under our providers' normal retention cycles. We may also keep data where the law requires us to. Until they are deleted, those copies remain protected by this agreement and are not used for anything else.
12. Information and audits
We will make available the information reasonably needed to show that we meet our obligations under this agreement. We will answer reasonable written questions about our processing.
Where that information is not enough, you, or an independent auditor you appoint who is bound by confidentiality, may carry out an audit. You must give at least 30 days' written notice, audit no more than once in any 12 months (unless there has been a personal data breach or a regulator requires it), and cover your own costs. The audit must be conducted so as not to disrupt the service or expose other customers' data.
13. Your responsibilities
As the controller, you are responsible for:
- having a lawful basis for the personal data you collect through the service;
- telling your visitors, in your own privacy notice, that you use an automated chat assistant and that we process their data on your behalf;
- not configuring the service to ask visitors for payment card details or special-category data, such as health information, as our Terms set out;
- making sure your instructions to us are lawful.
14. Liability and duration
This agreement lasts as long as we process personal data for you, including during deletion under section 11. Each party's liability under it is subject to the limits in section 10 of our Terms, except where the law does not allow liability to be limited.
15. Changes and governing law
We may update this agreement, for example to reflect a change in the law or to Schedule 3 under section 6. If a change materially affects you, we will tell you before it takes effect. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Schedule 1 — Details of the processing
| Subject matter | Providing Embermont Concierge, a chat assistant you add to your website. |
|---|---|
| Nature of the processing | Collecting, storing, retrieving, organising and deleting data; sending messages to an AI model to generate replies; presenting conversations and enquiries to you; sending you notifications. |
| Purpose | To answer your visitors' questions from your content, pass enquiries to you, let you read and take over conversations, and show you usage insights. |
| Duration | For as long as you use the service, and then until deletion under section 11. |
| People whose data is processed | Visitors to your website who use the chat assistant. People named on the public pages of your website that you choose to train the assistant on. |
| Types of personal data |
|
| Special-category data | None is intended. The service is not designed for it, and our Terms say you must not configure it to collect such data. A visitor may still volunteer it in a message. |
| Retention | Conversations are kept according to the retention setting on your account, and deleted with the site. Enquiries are kept until you delete them or the site. |
Schedule 2 — Security measures
- Hosting. The application runs on Google Cloud in the europe-west1 region (Belgium).
- Encryption. Data is encrypted in transit using HTTPS/TLS. Data at rest is encrypted by our hosting and database providers.
- Database access. The database accepts connections only from network addresses we have approved, including the application's fixed address, and requires an authenticated account. The application's database account can read and write data but has no administrative rights over the database service.
- Accounts. Passwords are stored as one-way hashes (bcrypt), never in readable form. Administrative functions require a separate operator role.
- Separation between customers. Each site has its own key. The chat widget works only on the domains you list for your site.
- Staff access. Access is limited to people who need it to run the service. Viewing enquiries and conversation analytics through the service is recorded in an audit log.
- Retention. Stored conversation and log records carry expiry dates and are removed automatically when those dates pass.
- Deletion. Deleting a site or an account removes its conversations, enquiries and trained content from our live systems.
Schedule 3 — Sub-processors
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud | Application hosting and file storage | European Union (Belgium, europe-west1) |
| MongoDB Atlas, hosted on Amazon Web Services | Database hosting | European Union (Ireland, AWS eu-west-1) |
| OpenAI | Generating chat replies, and processing your site content so the assistant can search it. Receives visitor messages and relevant extracts of your content. | United States |
| IONOS | Sending enquiry notification emails that contain the enquiry details, where you have turned them on and chosen to include the details. By default these emails contain only a link to the enquiry in your dashboard. | UK and EEA, and other locations where IONOS's data-processing terms and international-transfer safeguards allow |
Notifications to your devices. If you turn on browser notifications, a short preview of a new message is sent to your own browser through that browser's push service. The notification is encrypted in transit, and the push service cannot read it.