1. Subject matter and duration
Thosjod processes personal data only to provide the Service described in the agreement, for as long as the agreement is in force and any agreed export period afterwards.
2. Nature and purpose of processing
Processing covers engaging, identifying and qualifying the Controller's website visitors; enriching identified records; running AI conversations grounded in the Controller's knowledge sources; routing leads, booking meetings and syncing records to the Controller's connected systems; automated follow-up the Controller configures; and analytics. See our Privacy Policy (Privacy Policy).
3. Categories of data subjects and personal data
- Data subjects: visitors to the Controller's websites, the Controller's leads and prospects, and the Controller's users.
- Personal data: identifiers and contact details, company and role information, device, browser and approximate location data, pages viewed and session activity, conversation content, and voice recordings and transcripts where the voice agent is enabled.
The Controller should not configure the Service to collect special-category data.
4. Processor obligations
Thosjod will process personal data only on the Controller's documented instructions, ensure that people authorised to process it are bound by confidentiality, and apply the security measures in section 8.
5. Sub-processors
The Controller authorises Thosjod to use the sub-processors listed on the Sub-processors page (Sub-processors). Thosjod will give notice of new sub-processors so the Controller can object, and remains responsible for its sub-processors' obligations.
6. Data subject rights
Taking into account the nature of the processing, Thosjod will help the Controller respond to requests from data subjects to exercise their rights, including by letting the Controller delete visitor and conversation data from its workspace.
7. Security measures
Thosjod maintains technical and organisational measures appropriate to the risk, including encryption in transit, role-based access control, single sign-on for Scale and Enterprise workspaces, and a full configuration audit trail.
8. International transfers
Where personal data is transferred across borders, Thosjod will use a lawful transfer mechanism, such as Standard Contractual Clauses where applicable.
9. Audits
Thosjod will make available the information reasonably needed to demonstrate compliance with this DPA and allow audits on reasonable notice.
10. Personal data breach
Thosjod will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provide the information the Controller needs to meet its own obligations.
11. Return and deletion
At the end of the agreement, Thosjod will let the Controller export its data and then delete it, unless the law requires it to be kept.
12. Request a signed DPA
Enterprise customers can request the executable DPA through the contact page (Contact Us) or their account team.