Polycarp Data Processing Agreement
In force from 21 September 2026. Last updated: 21 September 2026.
This agreement forms part of the Polycarp Terms of Service between GestureLoop Limited (company number 792165), 44 Cluain Droichead, Sixmilebridge, Co. Clare, V95 HD62, Ireland ("the Processor", "we") and the Customer ("the Controller", "you"). It applies whenever we process personal data on your behalf in providing Polycarp, and it is intended to satisfy Article 28 of the GDPR. Where a term is defined in the GDPR it has that meaning here.
1. The processing
| Subject matter | Operating a website assistant on your site and recording its conversations. |
|---|---|
| Duration | The life of your Polycarp account, plus the deletion period in section 9. |
| Nature and purpose | Reading your website content; producing answers to visitor questions with an AI model; storing conversations for your review; forwarding handoff requests to you; measuring usage. |
| Data subjects | Visitors to your website; your visitors who sign in to your site, where you attach their account; your staff who sign in to Polycarp. |
| Personal data | Conversation messages and replies; a browser visitor identifier; handoff details (name, email, organisation, message); account identifier and any profile fields you send when attaching an account; network addresses, briefly, for abuse limits; feedback verdicts; your staff's email addresses and sign-in records. |
| Special categories | None are expected, and the Terms forbid using the agent to seek them out or to collect children's data. Visitors may volunteer such data in free text; you are responsible for your visitors' notices and for routing such questions to a person if your context makes them likely. |
2. Your instructions
We process personal data only on your documented instructions. The Terms, this agreement, and the settings you choose in your account are your instructions. If we believe an instruction breaks the law we will tell you. If the law requires us to process data in some other way we will tell you before we do, unless the law forbids it.
3. Our obligations
We will:
- ensure that everyone we allow to process your data is bound by confidentiality;
- apply the security measures in section 6;
- engage sub-processors only as set out in section 5;
- help you respond to data subjects who exercise their rights, and forward to you without undue delay any request we receive that concerns your data;
- help you meet your obligations on security, breach notification, impact assessments and consultation with supervisory authorities, taking into account the nature of the processing and the information available to us;
- delete or return your data at the end of the service as set out in section 9;
- make available the information needed to show that we are meeting these obligations, and allow and contribute to audits as set out in section 7.
4. Your obligations
You will ensure that you have a lawful basis for the processing, that your visitors receive a privacy notice covering the chat window, and that your instructions to us comply with the law. You will not configure the agent to solicit personal data beyond what the handoff form asks for.
5. Sub-processors
You give general authorisation for the sub-processors below. We will tell you by email at least thirty days before adding or replacing one, and you may object on reasonable grounds within that period; if we cannot resolve the objection you may close your account without penalty. The current list is always the one in this section, at polycarp.yohanun.com/dpa.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of Polycarp and the Yohanun platform, including the databases that hold conversations and content | Helsinki, Finland (EU) | None needed |
| Anthropic, PBC | Producing the agent's replies (chat model) | United States | EU–U.S. Data Privacy Framework where certified; otherwise Standard Contractual Clauses. API terms exclude training on your data. |
| OpenAI, L.L.C. | Text embeddings for retrieval; extraction and summarisation of content | United States | EU–U.S. Data Privacy Framework; API terms exclude training on your data. |
| Resend, Inc. | Sending handoff, welcome and service emails | United States | Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Payment collection and invoicing for customers who subscribe: your billing contact, card details (held by Stripe, never by us), invoices | Ireland (EU), with Stripe, Inc. (United States) as its sub-processor under Stripe's own DPA | None needed for the EU entity; Stripe's Standard Contractual Clauses for transfers within its group |
Stripe processes the customer's own billing data, not visitors' data. The Yohanun platform is operated by us and is not a sub-processor.
6. Security
Taking into account the state of the art, the costs of implementation and the nature of the processing, we apply these measures:
- Isolation. Each customer's content and conversations live in their own tenant on the Yohanun platform. Retrieval is filtered by tenant and by conversation ownership inside the database query, before any model is called, so one customer's data cannot reach another's agent, and one visitor's conversation cannot reach another visitor.
- Encryption. All traffic is encrypted in transit (TLS). Platform credentials held by Polycarp are encrypted at rest with a key kept outside the database.
- Access. Production access is limited to the people who operate the service, over key-based SSH. Customer sign-in is rate-limited and logged. Passwords are stored as salted scrypt hashes.
- Availability. The service is monitored every five minutes. Databases are backed up daily.
- Records. Every retrieval and every change to an agent's knowledge is recorded in append-only logs. Removing content retires it from retrieval and keeps the record.
- Erasure. Where you or a data subject require data to be erased rather than retired, we erase the data itself from every store the platform keeps it in, through a governed process that needs an authorised person's approval. The log then keeps only a record that the erasure happened, with none of the erased content.
We will review these measures as the service develops and will not reduce them without notice.
7. Audit
On request, no more than once a year unless a supervisory authority requires it or a breach has occurred, we will provide the information reasonably needed to demonstrate compliance with this agreement, and will allow an audit by you or an independent auditor you appoint, at your cost, on thirty days' notice, during business hours, and under confidentiality.
8. Breach notification
We will tell you without undue delay, and in any case within seventy-two hours of becoming aware, of a personal data breach affecting your data, with what we know about its nature, the data and people affected, the likely consequences, and what we are doing about it. We will not tell your visitors or a supervisory authority on your behalf unless you ask us to or the law requires it.
9. Return and deletion
You may export your content and your conversations at any time, and remove individual pages from your account. You decide how long conversations are kept: in your account you can set a period after which the conversations of visitors who have not signed in are erased automatically once they have been quiet for that long; if you set none, they are kept for the life of your account. A newly chosen period takes effect after twenty-four hours. You can erase an individual conversation, or all of one visitor's conversations with an agent, yourself from the conversation's page in your account; it takes effect at once. You may ask us to erase an earlier version of a page, and we will do so without undue delay and in any case within thirty days. When your account closes we will, at your choice made within thirty days, return your data to you or delete it. Absent a choice, we will delete it thirty days after closure. Deletion covers the live systems and the platform's records; backups are overwritten on their normal cycle within a further thirty days. We may keep what the law requires us to keep, and only for that purpose.
10. Liability
Liability under this agreement is subject to the limits in the Terms of Service. Each party is liable for its own breaches of the GDPR as the law provides.
11. General
This agreement takes precedence over the Terms where they conflict on the processing of personal data. It is governed by the law of Ireland. If the law changes so that this agreement no longer meets it, we will update the agreement and tell you.
Contact
GestureLoop Limited (company number 792165, VAT IE4457373FH), 44 Cluain Droichead, Sixmilebridge, Co. Clare, V95 HD62, Ireland. privacy@yohanun.com.