1. Parties and scope
This Data Processing Agreement ("DPA") is between Zak Goichman, trading as esek.io, a sole proprietor registered in Israel ("esek.io", the processor), and the business that uses the esek.io service (the "Customer", the controller).
It applies whenever esek.io processes personal data on the Customer's behalf through the service ("Customer Data"). It forms part of our Terms of Service. On data protection matters, this DPA prevails over the Terms of Service. Terms used here, such as "personal data", "processing", "controller" and "processor", have the meaning given in the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Details of processing
- Subject matter and duration: providing the esek.io service, for the term of the Customer's subscription or trial, plus the deletion period in section 10.
- Nature and purpose: sending, receiving and storing messages; handling phone calls; AI replies and assistance; scheduling and bookings; orders; and analytics for the Customer.
- Data subjects: the Customer's end customers and other contacts, and the Customer's staff.
- Types of personal data: names, phone numbers, message content, call audio and transcripts, order and booking details, and any other information the Customer's end customers choose to send.
3. Instructions
esek.io processes Customer Data only on the Customer's documented instructions, including with regard to transfers to other countries. Those instructions are the Terms of Service, this DPA, and the Customer's use and configuration of the service. If the law requires esek.io to process Customer Data otherwise, esek.io will tell the Customer first, unless that law forbids it.
esek.io will tell the Customer promptly if, in its opinion, an instruction breaks the GDPR or other data protection law.
4. Confidentiality
esek.io ensures that everyone it authorises to process Customer Data is bound by a duty of confidentiality, by contract or by law.
5. Security
esek.io takes appropriate technical and organisational measures to protect Customer Data (GDPR Art. 32). They currently include:
- Encryption in transit with TLS.
- Encryption at rest by our cloud provider (AES-256).
- Meta access tokens additionally encrypted at the application layer (AES-256-GCM).
- Passwords hashed with bcrypt.
- Database access restricted to authenticated services inside a private network.
- Least-privilege access to production systems.
- Regular database backups.
esek.io may update these measures as long as the overall level of protection does not decrease.
6. Sub-processors
The Customer gives esek.io general written authorisation to engage sub-processors. The current list is on our Sub-processors page.
esek.io will email the owner of each workspace at least 30 days before a new sub-processor starts processing Customer Data. The Customer may object by writing to privacy@esek.io. If esek.io cannot reasonably resolve the objection, the Customer may terminate the affected service.
esek.io imposes data protection obligations on each sub-processor that are equivalent to those in this DPA, by written contract. esek.io remains liable to the Customer for its sub-processors' performance of those obligations.
7. Data subject requests
Taking into account the nature of the processing, esek.io assists the Customer by appropriate technical and organisational measures, as far as possible, to respond to requests from data subjects exercising their rights. If esek.io receives such a request directly, it forwards the request to the Customer and does not answer it on its own, unless the Customer asks it to.
8. Assistance with the Customer's obligations
Taking into account the nature of the processing and the information available to it, esek.io assists the Customer in meeting its obligations under GDPR Articles 32 to 36: security of processing, notifying personal data breaches, data protection impact assessments, and prior consultation with a supervisory authority.
9. Personal data breaches
If esek.io becomes aware of a personal data breach affecting Customer Data, it will notify the Customer without undue delay and within any timeline that applicable law requires. The notice will include the information reasonably available to esek.io that the Customer needs to meet its own notification duties, and esek.io will provide further information as it becomes available.
10. Deletion or return at the end of the service
At the end of the service, esek.io deletes or returns Customer Data, at the Customer's choice. To receive a copy, the Customer asks privacy@esek.io before deleting its workspace.
When a workspace is deleted, its data is removed from the live service and permanently removed from the workspace recovery backup within 30 days, as described in our Privacy Policy and on our Data Deletion page. esek.io may keep only the minimal records that the law requires it to keep.
11. Audits and information
esek.io makes available to the Customer the information needed to demonstrate compliance with this DPA and GDPR Article 28. esek.io allows audits, including inspections, by the Customer or an auditor it appoints, on reasonable notice. Audits take place no more than once a year, unless a supervisory authority requires one or a personal data breach has occurred. The Customer bears the cost of the audit, and the auditor must keep confidential what it learns.
12. International transfers
Customer Data is hosted in the United States. esek.io is established in Israel, which the European Commission recognises as providing an adequate level of protection.
Where the Customer transfers Customer Data from the EU or the EEA to esek.io and no adequacy decision covers the transfer, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) ("SCCs"), Module 2 (controller to processor), are incorporated into this DPA by reference. For onward transfers to sub-processors, esek.io relies on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the SCCs, Module 3 (processor to processor).
Where the SCCs apply: the Customer is the data exporter and esek.io the data importer (Module 2); Clause 9(a) Option 2 applies with the 30 days' notice in section 6; Clause 17 Option 1 applies with the law of Ireland; the courts of Ireland are chosen under Clause 18; and the details of processing in section 2 and the measures in section 5 complete the Annexes.
For personal data from the United Kingdom, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies, and the UK Extension to the EU-US Data Privacy Framework applies to certified recipients.
13. Term, liability, law and precedence
- Term: this DPA lasts for as long as esek.io processes Customer Data for the Customer.
- Liability: each party's liability under this DPA is subject to the limitations in the Terms of Service, to the extent the law allows. Nothing in this DPA limits the rights of data subjects under the SCCs.
- Governing law and venue: this DPA is governed by the laws of the State of Israel, and the competent courts of Israel have exclusive jurisdiction, except where the Standard Contractual Clauses require otherwise.
- Order of precedence: if documents conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms of Service.
14. Contact
Questions about this DPA? Contact us at privacy@esek.io.