Data processing terms
Last updated 5 October 2026
These terms apply when the operator of autoai.im (“processor”) processes personal data on behalf of a customer (“controller”) through autoai, as required by Article 28 of the UK GDPR. They form part of our terms of service.
1. Scope
- Subject matter: providing AI chat assistants on the controller’s websites.
- Data subjects: visitors to the controller’s websites who use the chat, and anyone named in the controller’s uploaded content.
- Personal data: chat messages, contact details visitors choose to give (name, email, phone), page addresses and browser information.
- Duration: for as long as the controller uses autoai, plus up to 30 days for deletion.
2. Our commitments
- We process personal data only on the controller’s documented instructions (including these terms and the way the controller configures autoai).
- Everyone who can access the data is bound by confidentiality.
- We apply appropriate technical and organisational security measures, including encryption in transit, hashed passwords, per-workspace isolation and restricted access.
- We help the controller respond to data subject requests and meet its security, breach-notification and impact-assessment obligations.
- We notify the controller without undue delay after becoming aware of a personal data breach affecting its data.
- At the end of the service we delete the controller’s personal data (the controller can delete conversations, leads or its whole workspace at any time).
- We make available the information needed to show compliance with these terms.
3. Sub-processors
The controller authorises us to use these sub-processors, each bound by equivalent data protection obligations: Anthropic (AI answer generation), Stripe (payments, account data only), and our hosting and email delivery providers. We’ll give at least 14 days’ notice of new sub-processors by email, during which the controller may object.
4. International transfers
Where a sub-processor processes data outside the UK, we ensure an appropriate safeguard is in place, such as UK adequacy regulations or the International Data Transfer Addendum.
5. The controller’s responsibilities
The controller is responsible for having a lawful basis for processing, giving visitors appropriate privacy information (including that they are chatting with an AI), and not instructing visitors to share special category data through the chat.
Need a signed copy? Email [email protected].