This page summarises the standard Data Processing Addendum ("DPA") between KROK GROUP LTD (operating Fourmina, the "Processor") and each business customer (the "Controller"), as required by Article 28 UK GDPR / EU GDPR. The full signed DPA is available on request at hello@fourmina.com.
Subject matter: operation of AI assistants (voice agent, WhatsApp/web chat assistant, restaurant voice ordering) on the Controller's behalf. Duration: the term of the subscription. Nature and purpose: receiving, transcribing, answering and logging calls and chats from the Controller's end customers. Data subjects: the Controller's end customers and staff. Data categories: call audio and recordings, conversation transcripts, call metadata (caller number, time, duration, outcome), chat logs, names, contact details, and booking or order details shared in conversation.
We process personal data only on the Controller's documented instructions, including the assistant configuration and retention settings the Controller chooses in the product, unless UK or EU law requires otherwise. If we believe an instruction breaches data protection law, we inform the Controller before proceeding. We do not use the data for our own purposes and do not use it to train public AI models.
Everyone we authorise to process personal data is bound by a contractual or statutory duty of confidentiality. Access is limited to what each role requires.
We implement appropriate technical and organisational measures under Article 32 GDPR, including:
The full description of our technical and organisational measures is set out in the TOMs annex, which forms part of the DPA.
The Controller gives general authorisation for the subprocessors we use to run the Service (cloud hosting, LLM APIs, telephony, payments, email - described generically in our Privacy Policy; the named list is available on request). We notify Controllers of intended additions or replacements in advance. A Controller may object on reasonable data protection grounds; if no workable alternative exists, the Controller may terminate the affected service. Every subprocessor is bound by data protection obligations equivalent to this DPA, and we remain fully liable to the Controller for their performance.
Taking into account the nature of the processing, we assist the Controller with data subject requests (access, erasure, portability and the rest of Articles 12-23), with security, breach notification, and with data protection impact assessments where relevant. We notify the Controller of a personal data breach without undue delay after becoming aware of it.
Transfers outside the UK/EEA occur only with recognised safeguards: an adequacy decision or Standard Contractual Clauses, plus the UK International Data Transfer Addendum where UK GDPR applies.
At the end of the subscription, we delete or return all personal data processed on the Controller's behalf, at the Controller's choice, and delete existing copies unless UK or EU law requires storage. Export is available for 30 days after termination; deletion follows.
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable notice and no more than once per year unless a supervisory authority requires otherwise or a breach has occurred.
This page is a summary for transparency. It does not replace the signed agreement. Request the full signed DPA at hello@fourmina.com.