Skip to content
Bletchley
ProductIntegrationApplications
Login
Terms of ServicePrivacy PolicyData Processing AgreementCookie Policy

BLETCHLEY

Bletchley platform

Data Processing Agreement

On this page

  1. 1. Acceptance and scope
  2. 2. Definitions
  3. 3. Roles of the parties
  4. 4. What is processed, and why
  5. 5. Customer's obligations
  6. 6. Bletchley's obligations
  7. 7. Security
  8. 8. Subprocessors
  9. 9. Data subject requests and cooperation
  10. 10. International transfers
  11. 11. Security Incidents
  12. 12. Return and deletion
  13. 13. Audit and information
  14. 14. Liability
  15. 15. Changes to this DPA
  16. 16. General
On this page+
  1. 1. Acceptance and scope
  2. 2. Definitions
  3. 3. Roles of the parties
  4. 4. What is processed, and why
  5. 5. Customer's obligations
  6. 6. Bletchley's obligations
  7. 7. Security
  8. 8. Subprocessors
  9. 9. Data subject requests and cooperation
  10. 10. International transfers
  11. 11. Security Incidents
  12. 12. Return and deletion
  13. 13. Audit and information
  14. 14. Liability
  15. 15. Changes to this DPA
  16. 16. General

1. Acceptance and scope

1.1 This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between Bletchley Consulting Services Limited ("Bletchley", "we", "us") and the customer that uses the Bletchley platform ("Customer", "you") (the "Agreement"). It governs Bletchley's processing of personal data on Customer's behalf.

1.2 Customer accepts this DPA electronically within the Bletchley platform Console, at the point of account activation or before personal data is first supplied to the platform. No signature is required and no counter-signed copy is issued. Bletchley records the identity of the person who accepted, the account concerned, the version accepted and the date and time of acceptance, and makes that record available to Customer on request. Where Customer requires a signed instrument instead, it may request one in writing, and this DPA will be executed in the same terms.

1.3 This DPA applies from the date of acceptance and for as long as Bletchley processes personal data on Customer's behalf, regardless of whether the Agreement has ended.

1.4 Where this DPA conflicts with the Agreement in respect of personal data, this DPA prevails, and the provision giving the higher level of data protection prevails over any other. Where this DPA conflicts with the Standard Contractual Clauses or the UK Addendum incorporated under clause 10, those clauses prevail in respect of the transfers they govern.

1.5 This DPA is entered into by Bletchley on its own behalf and, where relevant, on behalf of its affiliates that process personal data in delivering the platform.

1.6 This DPA is Bletchley's standing data processing terms and applies to every customer without variation. Bletchley does not enter into a customer's own data processing agreement or equivalent document, and no term proposed by a customer, whether in a purchase order, vendor questionnaire, procurement portal, supplier code or other instrument, varies this DPA or forms part of it, whether or not Bletchley completes or returns that instrument.

1.7 Where a customer requires a variation, it takes effect only by an addendum to this DPA agreed in writing and signed by both parties, which identifies the provisions it varies. Such an addendum applies to that customer alone, prevails over this DPA only to the extent it expressly says so, and does not vary this DPA in respect of any other customer, establish any practice or precedent, or affect Bletchley's position in any other engagement. Save as expressly varied, this DPA continues in full force for that customer.

2. Definitions

Applicable Data Protection Law every law relating to the protection of personal data that applies to a party's processing under the Agreement, including the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486), the EU General Data Protection Regulation, the UK General Data Protection Regulation and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Singapore Personal Data Protection Act 2012, and the privacy laws of the states of the United States, in each case as amended.

Customer Personal Data personal data contained in Customer Records, in Input or in Output, which Bletchley processes on Customer's behalf in delivering the platform.

Data Subject Request a request from an individual to exercise a right under Applicable Data Protection Law, including a right of access, correction, erasure, restriction, portability, objection or opt-out.

Security Incident a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data processed by Bletchley or a Subprocessor.

Standard Contractual Clauses the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries.

Subprocessor any third party engaged by Bletchley to process Customer Personal Data in delivering the platform.

UK Addendum the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018.

"Controller", "processor", "data subject", "personal data", "processing", "supervisory authority", "service provider" and "sale" each have the meaning given in the Applicable Data Protection Law concerned. Terms defined in the Agreement and not defined here carry their meaning from the Agreement.

3. Roles of the parties

3.1 In respect of Customer Personal Data, Customer is the controller, and Bletchley is the processor acting on Customer's behalf. Where Customer is itself a processor for another controller, Bletchley acts as that other controller's subprocessor, and Customer warrants that it has the authority of that controller to enter into this DPA and to issue the instructions it gives.

3.2 Under Hong Kong law, Customer is the data user and Bletchley is a data processor acting on Customer's behalf. Customer discharges its obligations under Data Protection Principles 2(3) and 4(2) by contractual means, and this DPA is that contractual means.

3.3 Where the privacy law of a state of the United States applies, Bletchley acts as a service provider or processor, as that law defines it, and not as a third party. Bletchley does not sell or share Customer Personal Data, does not retain, use or disclose it other than to perform the services and for the purposes permitted by that law, does not combine it with personal information obtained from any other source except as that law permits, and will notify Customer if it determines that it can no longer meet these obligations.

3.4 Bletchley acts in its own right, as a controller or data user, in respect of its own account, billing, support, security and website data. That processing is governed by Bletchley's Privacy Policy and not by this DPA.

4. What is processed, and why

4.1 Subject matter and duration. The subject matter of the processing is the operation of the conversational service Customer configures on the platform. The duration is for as long as Customer's account remains open, together with the periods set out in clause 12 and any continuing processing covered by clause 1.3.

4.2 Nature and purpose. Bletchley processes Customer Personal Data in order to receive and store the data Customer supplies or connects, to operate Customer's service so that it can answer enquiries and take the actions Customer configures, to record what the service was asked and answered, to deliver messages on the surfaces Customer selects, to provide support and investigate faults, and to secure the platform. Bletchley does not process Customer Personal Data for any other purpose.

4.3 Categories of data subject. Customer determines these. They will ordinarily include Customer's own customers, enquirers and prospective customers, and Customer's staff and contractors who administer the service.

4.4 Types of personal data. Customer determines these. They will ordinarily include identifiers and contact details such as name, telephone number, email address and messaging handle; transaction and service records such as bookings, orders, enquiries, references, shipments and account status; the content of conversations between an individual and Customer's service, including any voice message and its transcription; and technical data generated in the course of a conversation.

4.5 Data excluded from the platform. Customer must not supply government identity numbers, passport numbers, full payment card numbers, bank account credentials, biometric templates or free-text clinical remarks. Automated checks cover full payment card numbers and government identity numbers. Where those numbers are detected in an uploaded file or data source, the upload or ingestion is rejected. Where detected in a message to Customer's service, the numbers are masked before the message is stored or sent to a provider of model inference. These checks do not provide automatic detection or masking of every prohibited category, and Customer remains responsible for not supplying prohibited data.

4.6 Data requiring prior agreement. Customer must not supply special category or sensitive personal data, information concerning health, data about individuals below the age of majority, cardholder data, or personal data subject to sector-specific regulation, unless the Agreement expressly permits it and any further terms required by Applicable Data Protection Law have been agreed in writing. Absent that agreement, Customer warrants that it will not supply such data, and Customer is solely responsible for any such data it nonetheless supplies.

5. Customer's obligations

5.1 Customer determines the purposes and means of the processing, within the functionality the platform provides, and is responsible for the lawfulness of the instructions it gives.

5.2 Customer warrants that it has a lawful basis for the processing; that it has given every notice and obtained every consent, authorisation or permission that Applicable Data Protection Law requires, including any consent required to record or transcribe a conversation, to send a marketing or proactive message, or to transfer personal data to Bletchley; and that it is entitled to disclose Customer Personal Data to Bletchley and to have Bletchley process it as this DPA describes.

5.3 Customer is responsible for the accuracy, quality and currency of Customer Personal Data. The platform's automated suitability and security checks do not verify factual accuracy. Bletchley does not undertake a general review, correction or monitoring of Customer Personal Data and is under no obligation to do so.

5.4 Customer is responsible for issuing its own privacy notice to data subjects, for informing them that they are interacting with an artificial intelligence system, and for the retention settings it chooses within the platform.

5.5 Customer must not use the platform in a way that requires Bletchley to process personal data in breach of Applicable Data Protection Law, and must not instruct Bletchley to do so.

6. Bletchley's obligations

6.1 Bletchley processes Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA, the configuration Customer applies within the platform and Customer's use of the platform are Customer's instructions. Bletchley will process on any other instruction only where Customer and Bletchley agree it in writing, and Bletchley may charge for work outside the scope of the platform.

6.2 Where Bletchley is required by law to process Customer Personal Data otherwise than on Customer's instructions, it will inform Customer of that requirement before processing, unless the law prohibits it from doing so.

6.3 Where Bletchley considers that an instruction infringes Applicable Data Protection Law, it will inform Customer without undue delay and may suspend performance of that instruction until it is withdrawn, amended or confirmed.

6.4 Customer Personal Data is never used to train, fine-tune or otherwise improve any general-purpose or foundation model, in raw or derived form. Bletchley contractually prohibits every provider of model inference it engages from doing so, and where such a provider offers processing without retention of submitted data, Bletchley uses that option.

6.5 Bletchley does not sell Customer Personal Data, does not disclose it for any third party's own purposes, and does not use it for its own marketing, product development or any purpose other than those in clause 4.2. Bletchley may produce and use statistics about activity volumes, response times and resolution rates, provided that they are aggregated and do not identify Customer, any individual or the content of Customer Personal Data.

6.6 Bletchley ensures that each person it authorises to process Customer Personal Data is subject to a duty of confidentiality that survives the end of their engagement, receives training appropriate to their role, and has access only to the data that role requires.

6.7 Bletchley keeps records of its processing of Customer Personal Data sufficient to demonstrate compliance with this DPA and makes them available to Customer on reasonable request.

7. Security

7.1 Bletchley implements and maintains technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. Those measures include encryption of personal data in transit and at rest; access control on least-privilege principles with individual authentication and multi-factor authentication for Bletchley personnel with administrative access; logical separation of each customer's data from every other customer's; logging of access and of administrative action, with retention of those logs; change management and testing before release; vulnerability management and patching; screening, training and confidentiality obligations for personnel; resilience and backup of data, with periodic testing of restoration; secure disposal of media and data; assessment of Subprocessors before engagement; and an incident response plan that addresses incidents specific to artificial intelligence systems, including the unauthorised entry of personal data into a model and abnormal model output.

7.2 Bletchley reviews those measures periodically and may change them, provided that it does not materially reduce the level of protection afforded to Customer Personal Data.

7.3 Customer is responsible for its own systems and credentials, for the access it grants to its personnel, for the retention and disclosure settings it chooses within the platform, and for the authentication and identity verification controls applied to any system it connects. Multi-factor authentication is available to Customer's users and is optional. Customer is responsible for assessing whether the measures in clause 7.1 meet its own obligations under Applicable Data Protection Law.

8. Subprocessors

8.1 Customer gives Bletchley general written authorisation to engage Subprocessors for the purposes in clause 4.2. Bletchley engages Subprocessors in the following categories: providers of infrastructure, hosting, database and backup services; providers of machine learning and language model inference; operators of the messaging, voice and application surfaces on which Customer's service runs; providers of the support, communication and monitoring tools Bletchley operates on; and, where the Agreement provides for it, implementation partners.

8.2 Bletchley makes available to Customer, on request and within the Bletchley platform Console, the identity of each Subprocessor engaged, the processing it performs and the country in which it does so. That information is Bletchley's confidential information, and Customer must not disclose it other than to its own professional advisers and regulators, and to any controller on whose behalf Customer acts.

8.3 Bletchley will give Customer at least 30 days' notice before engaging a new Subprocessor or replacing an existing one. Customer may object on reasonable data protection grounds within that period by writing to info@bletchley.cc. Where Customer objects, the parties will discuss the objection in good faith; if Bletchley cannot accommodate it without materially impairing the platform, Customer may close its account on written notice. For closure on that ground, notwithstanding the ordinary Customer-closure rule in Terms clause 6.8, Bletchley will refund unused purchased Credits pro rata, calculated under Terms clause 6.8.3. Free Trial Credits and Referral Credits have no refund value except where law requires otherwise. Any fees paid under an order form are dealt with under that order form and applicable law. Where notice must be shortened in order to replace a Subprocessor for reasons of security, legality or continuity of service, Bletchley will give as much notice as the circumstances permit.

8.4 Bletchley imposes on each Subprocessor data protection obligations no less protective than those in this DPA, and remains responsible to Customer for each Subprocessor's performance of them.

9. Data subject requests and cooperation

9.1 Where Bletchley receives a Data Subject Request concerning Customer Personal Data, it will not respond to it substantively, except to tell the individual that the request must be directed to Customer, and will pass the request to Customer without undue delay.

9.2 Bletchley will assist Customer in responding to a Data Subject Request, taking account of the nature of the processing, by making available the functionality and the information within Bletchley's control that Customer reasonably requires in order to locate, provide, correct, restrict, delete or export the personal data concerned.

9.3 Bletchley will provide Customer, on reasonable request, with the information Customer needs in order to carry out a data protection impact assessment or a transfer risk assessment, and will assist Customer in any prior consultation with a supervisory authority arising from the processing under this DPA.

9.4 Where Bletchley receives a binding demand from a public authority for Customer Personal Data, it will inform Customer without undue delay unless it is prohibited from doing so, will challenge the demand where there are reasonable grounds to consider it unlawful, and will disclose no more than the minimum the demand requires.

9.5 Bletchley may charge Customer for assistance under this clause 9 that is not attributable to a failure on Bletchley's part and that goes materially beyond the functionality the platform already provides.

10. International transfers

10.1 Bletchley and its Subprocessors process Customer Personal Data in the countries in which they operate. Where the Agreement provides for processing in a specified region, Bletchley processes that Customer's data accordingly.

10.2 Where Customer Personal Data is transferred from the European Economic Area, or from a country whose law applies the EU General Data Protection Regulation, to a country that is not the subject of an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA and apply to that transfer. Module Two applies where Customer is a controller and Bletchley a processor; Module Three applies where Customer is a processor and Bletchley a subprocessor. Customer is the data exporter and Bletchley is the data importer. The optional docking clause in Clause 7 applies. In Clause 9, Option 2 applies, and the notice period for changes to Subprocessors is the period in clause 8.3 of this DPA. The optional language in Clause 11(a) concerning an independent dispute resolution body does not apply. The governing law under Clause 17 is the law of Ireland. The courts for the purposes of Clause 18(b) are the courts of Ireland. Annex I is completed by clauses 1, 4 and 8.1 of this DPA and by the contact address in clause 16; Annex II is completed by clause 7.1; and Annex III is completed by clause 8 and the information made available under clause 8.2.

10.3 Where Customer Personal Data is transferred from the United Kingdom, the UK Addendum is incorporated into this DPA and applies to that transfer. Tables 1 to 3 of the UK Addendum are completed by the corresponding provisions of clause 10.2 and of this DPA. For the purposes of Table 4, the party that may end the UK Addendum when the Approved Addendum changes is the data importer.

10.4 Where Customer Personal Data is transferred from Switzerland, the Standard Contractual Clauses apply as modified so that references to the Regulation are to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and the term "member state" does not prevent a data subject resident in Switzerland from bringing proceedings in Switzerland.

10.5 Where Customer Personal Data is transferred out of Hong Kong, Bletchley applies contractual protections consistent with the model contractual clauses recommended by the Privacy Commissioner for Personal Data, and the obligations in this DPA operate as those protections.

10.6 Where Customer Personal Data is transferred out of Singapore or out of another market whose law requires a comparable standard of protection, Bletchley takes steps to ensure that the data continues to receive protection at least comparable to that required by that law, and the obligations in this DPA operate as those steps.

10.7 Where a transfer mechanism relied upon in this clause is invalidated, replaced or supplemented, the parties will apply the successor mechanism, and will execute any further document reasonably required to give effect to it, without interruption to the service.

11. Security Incidents

11.1 Bletchley will notify Customer of a Security Incident without undue delay, and in any event within 72 hours of becoming aware of it, by writing to the administrator contact on the account.

11.2 The notification will describe the nature of the incident, the categories and approximate volume of personal data and data subjects affected so far as known, the likely consequences, the measures taken or proposed to address it and to mitigate its effects, and a contact point for further information. Where the full picture is not available at the time, Bletchley will provide information in stages as it is established.

11.3 Bletchley will take reasonable steps to contain and remedy the incident and will cooperate with Customer in Customer's own investigation and in any notification Customer must make to a supervisory authority or to affected individuals.

11.4 Notification of an incident is not an acknowledgement of fault or liability by Bletchley.

11.5 Customer is responsible for determining whether the incident must be notified under Applicable Data Protection Law and for making that notification. Bletchley will not notify a supervisory authority or an affected individual on Customer's behalf unless Customer instructs it to do so in writing or the law requires Bletchley to do so directly.

12. Return and deletion

12.1 On closure of Customer's account or termination or expiry of the Agreement, Customer may export Customer Personal Data, its records and its configuration from the platform for 30 days.

12.2 Bletchley will delete or return Customer Personal Data within 30 days after the end of that export window, and will procure that each Subprocessor does the same, except for copies held in routine backups, which are deleted on expiry of their ordinary cycle, and for data Bletchley is required by law to retain, which remains subject to this DPA for as long as it is held.

12.3 Records that exist in order to give effect to an individual's objection to further contact are retained for as long as is necessary to honour that objection. Deleting them would defeat their purpose.

12.4 Bletchley will confirm deletion in writing on request.

12.5 While Customer's account remains open, Customer may delete Customer Personal Data, or shorten the period for which conversation records are retained, using the controls the platform provides.

13. Audit and information

13.1 Bletchley will make available to Customer, on reasonable request, the information necessary to demonstrate compliance with this DPA, including a description of its technical and organisational measures, the results of its own testing in summary form, and responses to Customer's security assessment questionnaire once in any 12-month period.

13.2 Where Applicable Data Protection Law entitles Customer to audit or inspect, and the information provided under clause 13.1 does not reasonably satisfy that entitlement, Customer may audit Bletchley's compliance, subject to at least 30 days' written notice, no more than once in any 12-month period except following a Security Incident affecting Customer, conduct during business hours in a manner that does not disrupt the platform or the confidentiality of other customers' data, the audit being carried out by Customer or by an independent auditor who is not a competitor of Bletchley and who is bound by confidentiality, and Customer bearing its own and Bletchley's reasonable costs.

13.3 Information disclosed under this clause 13 is Bletchley's confidential information and is subject to the confidentiality provisions of the Agreement.

14. Liability

14.1 Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement, including the limitation that applies to breach of this DPA.

14.2 Where the Standard Contractual Clauses or the UK Addendum confer rights on a data subject that cannot be limited, nothing in clause 14.1 limits those rights.

14.3 Neither party excludes liability that Applicable Data Protection Law does not permit it to exclude.

15. Changes to this DPA

15.1 Bletchley may amend this DPA where an amendment is required by a change in Applicable Data Protection Law, by a decision of a supervisory authority or court, by the adoption of a new or replacement transfer mechanism, or in order to reflect a change in the platform, provided that no amendment materially reduces the level of protection afforded to Customer Personal Data.

15.2 Bletchley will give Customer 30 days' notice of an amendment, except where a shorter period is required by law. Where an amendment is materially adverse to Customer, Customer may close its account without a closure charge before it takes effect. Where Customer does so, notwithstanding the ordinary Customer-closure rule in Terms clause 6.8, Bletchley will refund unused purchased Credits pro rata, calculated under Terms clause 6.8.3. Free Trial Credits and Referral Credits have no refund value except where law requires otherwise. Any fees paid under an order form are dealt with under that order form and applicable law. Continued use after the effective date constitutes acceptance of the amended DPA.

16. General

16.1 Notices and requests under this DPA are sent to Bletchley by email to info@bletchley.cc, which is also the contact point for the purposes of the Standard Contractual Clauses and the UK Addendum, and to Customer at the administrator contact on the account.

16.2 This DPA is governed by, and construed in accordance with, the law and the dispute resolution provisions of the Agreement, except in respect of transfers governed by the Standard Contractual Clauses or the UK Addendum, where the law and forum stated in clause 10 apply.

16.3 If any provision of this DPA is held to be invalid or unenforceable, it is severed or modified to the minimum extent necessary and the remainder continues in force.

16.4 This DPA is in English. Any translation is provided for convenience and the English version prevails.

Back to top
Bletchley
Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAffiliation and Partnership

© 2026 Bletchley Consulting Services Limited. All Rights Reserved.