Data Processing Agreement (DPA).
1. 1. Parties and roles
This data processing agreement forms a standard part of every agreement between you as the customer and Fenna Ltd, Bond House, 216 Sheriff Street Upper, Coopers Cross, Dublin 1, D01 K1W5, Ierland ("Fenna") and applies from the moment you use the service; no separate signature is required, although we are happy to sign a copy on request. You determine why and by which means personal data is processed and are therefore the controller within the meaning of the GDPR. Fenna processes that data solely on your behalf and is therefore the processor within the meaning of Article 28 GDPR. Questions about this agreement can be sent to privacy@heyfenna.com.
2. 2. Subject matter, duration, nature and purpose of processing
Fenna answers phone calls and messages for your business, responds to questions, records bookings and appointments and displays all of this in your dashboard. To do so, we process personal data of your callers and guests, solely to deliver this service as described in the agreement. The nature of the processing consists of receiving, storing, transcribing, organising, displaying, forwarding and deleting this data. Processing continues for as long as the agreement runs, plus the short period afterwards needed to return or delete data as described in section 13.
3. 3. Categories of data subjects and data
The data subjects are the people who call or message your number, your guests and customers with a booking or appointment, and your own staff insofar as they hold an account in the dashboard. The data consists of phone numbers, names, booking and appointment details such as date, time, party size and notes, messages via SMS or WhatsApp, and call recordings and transcripts insofar as you have actively enabled that feature. The service is not intended for special categories of personal data; if a caller volunteers such information, for example an allergy in a booking note, we process it only within the scope of this agreement.
4. 4. Documented instructions and purpose limitation
Fenna processes personal data only on your documented instructions: this agreement, the settings you choose in the dashboard and any additional written instructions. We do not use your callers' and guests' data for our own purposes, do not sell it and do not use it for advertising. We may only deviate where Union or Member State law requires us to process; in that case we inform you beforehand, unless that law prohibits this on important grounds of public interest. If we believe an instruction infringes the GDPR or other data protection law, we will tell you immediately.
5. 5. Confidentiality
Only people who need access for their work are given access to personal data we process for you. Everyone who works with this data on Fenna's behalf is bound by a contractual duty of confidentiality or by an appropriate statutory obligation of confidentiality. That duty continues to apply after their employment or engagement ends.
6. 6. Security
We implement appropriate technical and organisational measures within the meaning of Article 32 GDPR, proportionate to the risk of the processing. In concrete terms this includes: encryption of data in transit (TLS), access control on a least-privilege basis, row-level data isolation in the database so that your data remains strictly separated from that of other customers, hosting of the core database within the EU/EEA, logging of relevant operations and automated deletion in line with fixed retention periods. We continuously evaluate and improve these measures and will not lower the level of protection during the term of the agreement.
7. 7. Sub-processors
You grant Fenna a general authorisation to engage sub-processors to deliver the service. We impose on every sub-processor, by contract, the same data protection obligations as set out in this agreement, and we remain fully liable to you for the performance of our sub-processors. We engage the following categories of sub-processor: a database and account platform (EU-Ireland), providers for speech technology, language models and speech recognition (US), telephony and messaging providers (US/EU), a hosting provider (US/EU), an email provider (US) and a payment provider (EU). The list naming the sub-processors we currently engage, and where they are established, is available on request via privacy@heyfenna.com. We announce changes to that list by email to the contact address we hold for you, before the new sub-processor starts processing personal data. If you have reasonable, data protection based objections, let us know within 30 days of the announcement via privacy@heyfenna.com; we will then work with you to find a solution, and if none can be found you may terminate the affected part of the service.
8. 8. International transfers
The core database is hosted within the EU/EEA. Some sub-processors process data wholly or partly outside the EEA, notably in the United States; the list we provide on request under section 7 shows which ones. Transfers to countries outside the EEA take place only under a valid transfer mechanism from Chapter V of the GDPR: an adequacy decision such as the EU-US Data Privacy Framework where the sub-processor is certified under it, and otherwise the European Commission's Standard Contractual Clauses (SCCs), supplemented with additional measures where needed.
9. 9. Assistance with data subject rights
If a caller or guest exercises their rights under the GDPR with you, such as access, rectification, erasure, restriction, objection or data portability, we assist you with appropriate technical and organisational measures to fulfil that request, for example by locating, correcting, deleting or exporting the data. If such a request reaches us directly, we forward it to you without undue delay and do not respond to the data subject on the merits, unless you instruct us to or the law requires us to.
10. 10. Assistance with security, DPIAs and the supervisory authority
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36 GDPR. This means that on request we provide information about our security measures, cooperate with a data protection impact assessment (DPIA) insofar as it concerns our service, and support you in any prior consultation of the supervisory authority. Requests can be sent to privacy@heyfenna.com.
11. 11. Personal data breaches
If we establish a personal data breach affecting your data, we notify you without undue delay by email to the contact address we hold for you. That notification contains, to the extent known at that time, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences and the measures we have taken or propose; in short, the information you need to make your own notification to the supervisory authority within 72 hours where required. If not all information is available yet, we notify in phases and supplement as we learn more. We do not notify the supervisory authority or data subjects on your behalf unless the law requires it or you ask us to, and we reasonably cooperate in investigating and containing the breach.
12. 12. Audits
On request, we make available all information reasonably necessary to demonstrate compliance with the obligations of Article 28 GDPR. In addition, you have the right to an audit, at most once per year, unless a data breach or an instruction from the supervisory authority justifies an additional audit. An audit starts in writing, through our documentation and answers to your questions; only if that is demonstrably insufficient will an inspection of our systems follow by arrangement, announced in advance, during business hours and without unnecessary disruption to our services. The reasonable costs of an audit are borne by you, unless the audit reveals a material failure on Fenna's part.
13. 13. Return and deletion
When the agreement ends, you can export your data via the dashboard or request it via privacy@heyfenna.com; at your choice, we return the personal data or delete it. After that, we delete or anonymise the personal data we process for you in line with the fixed retention periods; call recordings and transcripts are in any event automatically deleted no later than 90 days after recording. We only retain data longer where a legal obligation requires us to, and on request we confirm deletion in writing.
14. 14. Liability
Liability under this data processing agreement is governed by the arrangements, limitations and exclusions in the general terms and conditions that apply to the agreement. Nothing in this section limits the rights that data subjects derive directly from Article 82 GDPR, or any liability that cannot be limited or excluded under mandatory law.
15. 15. Order of precedence, changes and term
In the event of a conflict between this data processing agreement and the agreement or the general terms and conditions, this data processing agreement prevails insofar as the processing of personal data is concerned; mandatory law, including the GDPR, always prevails. We may update this data processing agreement, for example in response to new legislation or changes to the service; we announce material changes in advance on this page and by email, and will not lower the level of protection. This data processing agreement applies for as long as we process personal data for you, and it is governed by the same law as the main agreement.
Also legal:Privacy PolicyTerms and ConditionsEthical AI Framework