Data Protection Addendum
Governing the processing of personal data by Tactful Ltd as data processor
Last updated: August 9, 2026
Version effective: 9 August 2026 (see Section 14 — Version and Applicability)
1. Key Parties and Roles
Data Processor: Tactful Ltd, The Venture Centre, Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, United Kingdom, CB25 9PB (Company No: 10279888).
Data Controller: The Customer, as identified in the relevant Order Form.
This Data Protection Addendum ("DPA") forms part of the agreement between the parties and governs the processing of personal data by Tactful Ltd on behalf of the Customer in connection with the Product(s) specified in the Order Form.
2. Scope of Data Processing
The following categories of personal data may be processed under this DPA, depending on the Product(s) in use:
| Service | Personal Data Processed |
|---|---|
| Unified Inbox & Ticketing | Name, contact identifiers (email address, phone number, social/messaging handles), message and conversation content, ticket content and attachments, and customer-provided identifiers (e.g. account, order or trip references) |
| AI Agents & Automation | Conversation content and the personal data contained within it, as submitted by or on behalf of the Customer's end users |
The Customer determines the categories of data subjects (e.g. its customers, end users, drivers, riders, agents and staff) and the personal data submitted to the Product(s).
3. Customer Obligations
The Customer, as Data Controller, must:
- Comply with all applicable Data Protection Legislation in respect of the personal data processed under this DPA;
- Ensure that all instructions given to Tactful Ltd regarding the processing of personal data are lawful; and
- Ensure that the personal data is accurate and that its transfer to Tactful Ltd for processing is permitted under applicable law.
4. Data Security Measures
Tactful Ltd implements appropriate technical and organisational measures to protect personal data, including:
- Role-based access controls limiting access to authorised personnel only;
- Background checks on employees with access to personal data;
- Encryption of personal data in transit and at rest;
- Annual security training for all relevant staff;
- Regular vulnerability assessments and penetration testing; and
- Multi-layered security controls across infrastructure and applications.
5. Data Breach Notification
In the event of a personal data breach, Tactful Ltd will:
- Notify the Customer within 48 hours of becoming aware of the breach;
- Provide information in accordance with Article 33(3) of the UK GDPR, including the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
6. Sub-processors
A current list of sub-processors is maintained at tactful.ai/sub-processors.
Tactful Ltd will provide 30 business days' notice prior to engaging any new sub-processor or making material changes to existing sub-processors. Customers have the right to object to new sub-processors during this notice period.
Tactful Ltd remains responsible for ensuring that all sub-processors provide equivalent data protection guarantees and comply with obligations equivalent to those set out in this DPA.
7. International Data Transfers
Where personal data is transferred outside the UK or the European Economic Area, Tactful Ltd will ensure appropriate safeguards are in place, including:
- UK International Data Transfer Agreements (IDTA);
- EU Commission Standard Contractual Clauses; and/or
- Such other supplementary measures as are required to ensure an equivalent level of protection.
8. Data Subject Rights
Tactful Ltd will assist the Customer in fulfilling its obligations to respond to data subject rights requests under applicable Data Protection Legislation, including requests to access, correct, erase, restrict, or transfer personal data.
9. Return and Deletion of Data
Upon termination or expiry of the agreement, or upon request from the Customer, Tactful Ltd will, at the Customer's election:
- Return all personal data to the Customer in a structured, commonly used, and machine-readable format; or
- Securely delete or destroy all personal data processed on behalf of the Customer,
and certify in writing that it has done so, unless applicable law requires continued storage of the personal data.
10. Liability Limits
10.1 Liability arising under or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in clause 15 of the EULA. Nothing in this DPA creates a separate or additional pool of liability.
10.2 Without prejudice to clause 10.1, Tactful Ltd's total aggregate liability arising out of or in connection with this DPA in respect of direct damages shall in no event exceed EUR 500,000 (the "DPA Ceiling"). For clarity: where the cap under clause 15.4 of the EULA (total Fees paid in the relevant Contract Year) is lower than the DPA Ceiling, that lower amount applies; the DPA Ceiling operates solely as the maximum amount recoverable in any event.
10.3 Indirect and consequential damages are excluded to the fullest extent permitted by applicable law.
10.4 Nothing in this DPA excludes or limits either party's liability which cannot be excluded or limited under applicable law, including liability for fraud or fraudulent misrepresentation, or for death or personal injury caused by negligence.
11. Audit Rights
11.1 Information and documentation. Tactful Ltd shall, on the Customer's written request and subject to the frequency cap in clause 11.8, make available such information as is reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the UK GDPR and the EU GDPR, including: (a) its then-current security documentation and security whitepaper; (b) such third-party audit report(s), certification(s) or attestation(s) as Tactful Ltd then holds in respect of the Product(s) or of the infrastructure on which they run; and (c) a completed response to a standard industry security questionnaire.
11.2 Live audit. Where the Customer, acting reasonably, demonstrates that the materials provided under clause 11.1 are insufficient to demonstrate compliance with this DPA, or where a competent supervisory authority requires it, the Customer (or an auditor appointed under clause 11.3) may audit Tactful Ltd's compliance with this DPA, subject to clauses 11.4 to 11.8.
11.3 Appointed auditor. Any auditor appointed by the Customer must be: (a) independent of both the Customer and Tactful Ltd; (b) professionally qualified to conduct the audit; (c) bound by written obligations of confidentiality no less protective than those in the Agreement; and (d) not engaged in the supply of customer-experience, contact-centre or conversational-AI software in competition with Tactful Ltd. The Customer shall procure the auditor's compliance with this clause 11 and remains responsible for its acts and omissions.
11.4 Notice. The Customer shall give Tactful Ltd not less than thirty (30) days' prior written notice of an audit under clause 11.2, save where a competent supervisory authority requires a shorter period or where the audit is conducted under the exception in clause 11.8, in which case the Customer shall give as much notice as is reasonably practicable.
11.5 Scope. An audit under clause 11.2 or clause 11.8 shall not extend to: (a) data, systems or information relating to any other customer of Tactful Ltd; (b) Tactful Ltd's commercially sensitive information, including its pricing, costs and the commercial terms agreed with other customers; (c) penetration testing, intrusion testing, vulnerability scanning or other active or intrusive testing of shared or multi-tenant infrastructure; or (d) information which Tactful Ltd is prohibited from disclosing by law or by obligations of confidentiality owed to a third party.
11.6 Conduct. Audits shall be conducted during Tactful Ltd's normal business hours, at such premises or by such means of systems access as the parties agree, and in a manner that does not cause unreasonable disruption to Tactful Ltd's business or to the provision of its services to its other customers.
11.7 Costs. Each party bears its own costs in connection with an audit. Tactful Ltd shall make available up to eight (8) hours of personnel time per audit at no charge to the Customer; time reasonably incurred by Tactful Ltd beyond that allowance shall be reimbursed by the Customer at Tactful Ltd's then-current professional services rates.
11.8 Frequency. The rights in clauses 11.1 and 11.2 are capped separately, and each may be exercised once in any rolling twelve (12) month period. For the avoidance of doubt, requesting or receiving the materials described in clause 11.1 does not exhaust or limit the Customer's right to conduct an audit under clause 11.2 in the same period. In addition, and without the Customer being required to satisfy the condition in clause 11.2, the Customer may conduct one further audit following a personal data breach affecting that Customer's personal data which has been notified to the Customer under clause 5; such an audit remains subject to clauses 11.3 to 11.6, and clause 11.7 does not apply to it. Each party bears its own costs of an audit conducted under this post-breach exception, and the allowance in clause 11.7 does not limit the personnel time Tactful Ltd makes available for it.
11.9 Supervisory authorities. Nothing in this clause 11 limits or conditions any inspection, audit or investigation carried out by or at the direction of a competent supervisory authority, or the exercise by a supervisory authority of its powers under applicable Data Protection Legislation, and the restrictions in clauses 11.2 to 11.8 do not apply to any such inspection, audit or investigation.
12. Use of Customer Data for Model Training
12.1 Tactful Ltd processes Customer Personal Data and the content of Customer conversations solely to provide, maintain and support the Product(s) in accordance with the Customer's documented instructions and this DPA. Tactful Ltd does not use Customer Personal Data or the content of Customer conversations to train, fine-tune, re-train or evaluate any machine-learning, artificial-intelligence or generative model, and does not disclose, make available or transfer such data to any third party for that purpose.
12.2 Tactful Ltd shall procure that each sub-processor engaged in the provision of the Product(s), including each provider of model inference services, is bound by contractual obligations prohibiting the use of Customer Personal Data and the content of Customer conversations to train, fine-tune, re-train or evaluate any model, and prohibiting the retention of such data other than for the period strictly necessary to return the relevant output and to comply with applicable legal obligations. Tactful Ltd shall not engage any sub-processor for model inference which is not bound by obligations equivalent to this clause 12.
12.3 This clause 12 prevails over any inconsistent provision of the EULA, including clause 9 (Use of Metrics and Aggregated Data). For the avoidance of doubt, nothing in clause 9 of the EULA permits Tactful Ltd to use Customer Personal Data or the content of Customer conversations to train, fine-tune, re-train or evaluate any model, whether in identifiable, pseudonymised, anonymised or aggregated form.
12.4 This clause 12 applies to all Customers and to all Product tiers and is not varied by any Order Form.
13. Governing Law
This DPA, and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims), is governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this DPA.
14. Version and Applicability
This version of the DPA is effective from 9 August 2026 and applies to:
- (a) Order Forms executed on or after 9 August 2026; and
- (b) Renewal Periods commencing on or after 9 August 2026.
Order Forms executed on or after 3 July 2026 and before 9 August 2026 remain governed, for the remainder of their then-current Term or Renewal Period, by the version of this DPA dated 3 July 2026, which remains available at tactful.ai/dpa/2026-07-03.
Order Forms executed before 3 July 2026 remain governed, for the remainder of their then-current Term or Renewal Period, by the version of this DPA dated 5 January 2024, which remains available at tactful.ai/dpa/2024-01-05.
Exception — Section 12. Section 12 (Use of Customer Data for Model Training) applies to all Customers from 9 August 2026, irrespective of which version of this DPA otherwise governs their Order Form, and supersedes any inconsistent provision of an earlier version.
Version History
| Version | Effective | Changes |
|---|---|---|
| 9 August 2026 (this version) | 9 August 2026 | Section 11 (Audit Rights) replaced: documentation-first mechanism (11.1), conditioned live-audit right (11.2), auditor qualification including independence and non-competitor requirements (11.3), 30-day notice period (11.4), scope carve-outs (11.5), conduct limits (11.6), 8-hour cost allowance (11.7), rolling twelve-month frequency cap with a post-breach exception that is exempt from both the insufficiency gateway and the cost allowance (11.8), and a saving clause preserving supervisory-authority powers (11.9). New Section 12 (Use of Customer Data for Model Training), which applies to all Customers irrespective of DPA version. Governing Law renumbered 12 to 13; Version and Applicability renumbered 13 to 14 and extended to cover both archived versions and the Section 12 exception. |
| 3 July 2026 | 3 July 2026 | Clause 10 (Liability Limits) restated to clarify the interaction with clause 15 of the EULA — the EUR 500,000 figure operates as an overall ceiling, with liability otherwise subject to the EULA cap — and to state the statutory non-excludable liabilities. Clause 12 (Governing Law) restated as the laws of England and Wales with the exclusive jurisdiction of the courts of England and Wales. Section 2 (Scope of Data Processing) updated to describe the current Product(s). New Section 13 (Version and Applicability). |
| 5 January 2024 | 5 January 2024 | Prior version — applies to Order Forms executed before 3 July 2026 (see Section 14). |
Tactful Ltd trading as Tactful AI. Registered in England — Company No: 10279888. The Venture Centre, Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, United Kingdom, CB25 9PB.