Back to Pembico AI

Legal

Data Processing Agreement

Last updated: 28 July 2026

These processor terms apply where Pembico AI processes personal data on behalf of a client as part of AI front desk, AI website, AI marketing, voice agent, lead capture, CRM or reporting services.

Roles and purpose

The client is normally controller for its customer, visitor, lead, enquiry, voice transcript, booking, quote and CRM data. Pembico AI acts as processor when processing that data to provide the agreed services.

The subject matter is website, enquiry, AI agent, SEO/reporting and support services. The duration is the service term plus any agreed retention period.

Data and data subjects

Data may include names, contact details, business details, job requirements, website/chat/form messages, voice transcripts, call/message metadata, booking details, quote status, invoice status, reviews, service areas and technical logs. Data subjects may include client staff, customers, prospects, website visitors and suppliers.

Processing instructions and security

Pembico AI will process personal data only on documented client instructions unless legally required otherwise, and will use reasonable technical and organisational security measures appropriate to the service.

Sub-processors and transfers

The client gives general written authorisation for Pembico AI to use the sub-processors identified in the current subprocessor list. Pembico AI will give reasonable advance notice of material additions or replacements so the client can object on reasonable data-protection grounds. Equivalent data-protection obligations will be imposed on each sub-processor. Providers may include Vercel, Clerk, Convex, Twilio, a managed PostgreSQL host, Resend, Formspree, approved AI model providers, booking tools and support providers.

Restricted international transfers will use an applicable adequacy regulation or appropriate safeguards, such as the UK IDTA or UK Addendum, and a transfer risk assessment where required.

Requests, breaches and cooperation

Pembico AI will provide reasonable help with data subject requests, security incidents, DPIAs and regulator enquiries relating to the services. Pembico AI will notify the client without undue delay after becoming aware of a personal data breach affecting client personal data.

Return, deletion and audit

At the end of services, Pembico AI will delete or return personal data where reasonably possible, subject to legal, accounting, security and backup retention. Pembico AI will provide reasonable audit/cooperation information, normally by documentation or written responses rather than unrestricted system access.