Skip to content
All legal documents

PBot Data Processing Agreement

How we handle the personal data of a customer's people when we run PBot for them, as UK GDPR Article 28 requires.


Version 1.0. Effective 28 July 2026.

PBot is the AI assistant Pulsar AI Ltd builds and runs for a business, trained on that business's own material and answering questions from the people it authorises. Running it means processing personal data belonging to those people, on that business's behalf. This document sets out the terms on which we do that, as UK GDPR Article 28 requires.

This DPA forms part of the agreement between Pulsar AI Ltd, registered in England and Wales under company number 17310016 and registered with the Information Commissioner's Office under reference ZC206261 ("Processor", "we"), and the customer named on the Order Form ("Controller", "you"). It applies where we process personal data on your behalf in providing the Service.

Terms defined in the Terms of Service have the same meaning here. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where applicable, EU Regulation 2016/679, in each case as amended or replaced.


1. Roles

1.1 You are the controller and we are the processor in respect of the personal data described in Annex 1.

1.2 You are responsible for determining that your instructions, and the processing described in Annex 1, comply with Data Protection Law. You warrant that you have a valid lawful basis for the processing, and that you have given the data subjects the privacy information required by Articles 13 and 14 UK GDPR (Annex 4 gives wording you may adapt).

1.3 Customer Services. Where the Service uses a Customer Service (as defined in clause 5.1 of the Terms), meaning any technology you nominate, supply, license, host or operate, including AI models and any other platform or tool, accessed under your own account, licence or infrastructure, then in respect of that service:

  1. its provider processes personal data as your processor under your contract with them, or, where you host it yourself, you process that data directly;
  2. it is not our sub-processor, and it does not appear in Annex 2;
  3. you are responsible for having appropriate data protection terms and, where the processing leaves the UK, an appropriate transfer mechanism in place with that provider;
  4. we are not responsible for that processing, for the security of that service, or for what that provider does with the data.

We will tell you what data the Service sends to a Customer Service, so that you can carry out your own assessment.

2. Our obligations

We will:

2.1 Process only on your documented instructions, which are the Order Form, this DPA, the Terms, and any further written instruction you give. If we believe an instruction breaches Data Protection Law we will tell you without undue delay, and may pause that processing until it is resolved.

2.2 Not transfer personal data outside the UK except as permitted by clause 6.

2.3 Ensure confidentiality. Everyone we authorise to process the personal data is bound by an appropriate duty of confidentiality.

2.4 Apply appropriate security. We will implement and maintain the technical and organisational measures in Annex 3, appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing.

2.5 Use sub-processors only as set out in clause 5.

2.6 Help you respond to data subjects. Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection. Where a data subject contacts us directly, we will not respond to the substance, and will refer them to you promptly. We will action a verified erasure or export instruction from you within 30 days, subject to the security incident records provision in clause 2.9.

2.7 Help you with compliance. We will provide reasonable assistance with your obligations under Articles 32 to 36 UK GDPR (security, personal data breaches, data protection impact assessments and prior consultation), taking account of the nature of processing and the information available to us.

2.8 Notify you of a personal data breach affecting personal data processed under this DPA without undue delay and in any event within 48 hours of becoming aware of it, with the information reasonably available to us at that time, and further information as it becomes available. We will not make any public statement identifying you without your consent unless required by law. Notification is not an admission of fault.

2.9 Delete or return data on termination. On termination, and after the 30 day export window in clause 12.7 of the Terms, we will delete the personal data. Backups are retained for up to 90 days and are overwritten on our normal cycle. Where personal data is erased before a backup is expired, we maintain an erasure log and replay it against any restored backup, so a restore cannot resurrect erased data. We may retain personal data where required by law, and this DPA continues to apply to it. This includes records of security incidents, such as a record that a message was blocked before it could reach the wrong customer's community, which we retain for as long as necessary to investigate the incident, meet our legal obligations (including Article 33(5) UK GDPR breach documentation), and establish, exercise or defend legal claims, as Article 17(3)(e) UK GDPR permits. Such records hold the minimum personal data needed to evidence the incident and are excluded from erasure and deletion under this DPA only to that extent.

2.10 Records and audit. We will keep records of the processing we carry out for you and make available the information reasonably necessary to demonstrate compliance with this DPA. You may audit compliance once in any 12 month period, on at least 30 days' written notice, during business hours, at your cost, without accessing other customers' data, our source code, or anything that would breach our confidentiality obligations. We may satisfy an audit request by providing a written description of our measures, our security review documentation, or a third party report. Additional audits may be carried out where required by a regulator or following a confirmed personal data breach affecting your data.

3. Your obligations

3.1 You will comply with Data Protection Law, including in the collection and supply of Customer Content.

3.2 You will maintain the member allowlist, so that only people you have authorised, and told, can use the assistant.

3.3 You will not instruct us to process special category data (health, race, ethnicity, political opinions, religion, trade union membership, genetic or biometric data, sex life or sexual orientation) or criminal offence data, and you will take reasonable steps to keep such data out of the content you supply and out of your members' use of the assistant. If such data is processed anyway, you remain the controller of it, this DPA applies to it, and you are responsible for the additional conditions Data Protection Law requires.

3.4 You will not use the Service to process the personal data of anyone under 18.

3.5 You are responsible for handling data subject requests, complaints and regulator contact in the first instance, as controller.

4. Instructions

Your documented instruction to us is: process the personal data in Annex 1, for the purposes in Annex 1, for as long as the agreement lasts, in order to provide, secure, monitor, support, debug, evaluate and improve the Service for you. This includes collecting content from the third party sources named on your Order Form, which you instruct and authorise us to collect.

5. Sub-processors

5.1 You give general written authorisation for us to appoint sub-processors. The current list is in Annex 2.

5.2 We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

5.3 We will give you at least 30 days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds within 14 days. If we cannot resolve your objection, you may terminate the affected part of the Service on written notice, with a pro rata refund of prepaid fees for the unused period, and that is your sole remedy.

6. International transfers

6.1 Personal data is stored at rest in a London, United Kingdom region.

6.2 Some sub-processors in Annex 2 process personal data outside the UK, principally in the United States. Where we transfer personal data outside the UK we will ensure a lawful transfer mechanism is in place, being one of: an adequacy decision or adequacy regulations; the UK International Data Transfer Agreement; or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, in each case with any supplementary measures required following a transfer risk assessment.

6.3 We will provide details of the mechanism relied on for any sub-processor on request.

7. Liability

7.1 Each party's liability under this DPA is subject to the limits in clause 15 of the Terms, except to the extent Data Protection Law does not permit that.

7.2 Nothing in this DPA restricts a data subject's rights or a regulator's powers.

8. General

8.1 This DPA takes precedence over the Terms on any data protection matter.

8.2 If a change in Data Protection Law requires a change to this DPA, the parties will negotiate in good faith to make it.

8.3 This DPA is governed by the law of England and Wales, and clause 17 of the Terms applies.


Subject matter. Provision of PBot, Pulsar's AI assistant service.

Duration. For the term of the agreement, plus the retention periods in clause 2.9.

Nature and purpose. Collection, storage, structuring, transcription, indexing, retrieval, transmission, analysis, evaluation and deletion of personal data, in order to operate an AI assistant that answers members' questions, to route unanswered questions to the Controller's administrators, to meter usage, to monitor and secure the platform, and to evaluate answer quality.

Categories of data subject.

  • The Controller's members and community participants
  • The Controller's staff and administrators
  • Individuals mentioned in content the Controller supplies or authorises us to collect

Categories of personal data.

  • Identifiers: name or display name, email address, messaging platform user ID and chat ID
  • Profile information: business niche, revenue range, and other profile fields the Controller configures
  • Content: the full text of messages members send and the assistant's replies; voice notes and images sent by members, and transcriptions of them; conversation history; automatically generated rolling summaries of a member's history
  • Questions escalated to the Controller's administrators
  • Usage and technical data: timestamps, message identifiers, token counts, latency, error events
  • Any personal data contained within the content the Controller supplies or authorises us to collect (for example call transcripts, recordings, documents, social posts)

Special category or criminal offence data. Not requested and not permitted (clause 3.3).

Frequency. Continuous, for the duration of the agreement.

Retention. For the term, then per clause 2.9 of this DPA and clause 12.7 of the Terms. Backups: up to 90 days.


This annex lists the providers we engage to deliver the platform. It does not list Customer Services, which are covered by clause 1.3 and are not our sub-processors.

Part A: Platform sub-processors

These providers underpin the Service for every customer. This is our current platform stack and may change on notice under clause 5.3.

Sub-processorWhat it doesLocation of processing
SupabaseHosted Postgres database, the system of record for customer dataLondon, United Kingdom
ModalServerless compute running the applicationUnited States
VercelHosts the optional web chat interfaceUnited States and global edge
GitHubSource control and release automationUnited States
AnthropicGenerates the assistant's answers, where Pulsar supplies the modelUnited States
OpenAIConverts content into the searchable index (embeddings), where Pulsar supplies itUnited States
GoogleYouTube Data API, where Pulsar collects content from a nominated channelUnited States and global
TelegramCarries messages between members and the assistant, where the messaging channel runs on Pulsar's accountGlobal
ApifyCollects published video content from nominated public channels and profiles, where Pulsar runs the collectionUnited States and global

Part B: Customer-nominated services (not our sub-processors)

Where you nominate, supply, license, host or operate a service yourself, it is recorded in Part B of the copy of this DPA attached to your Order Form, together with what it does and whose account it runs on. Those services are not our sub-processors.

Clause 1.3 applies to everything in Part B.

Where a sub-processor in Part A processes personal data outside the UK, clause 6 applies.


Tenant separation. Each customer is a separate tenant. Row level security is enabled and forced on every tenant-scoped database table, so isolation is enforced by the database itself and not by application code. The tenant identity is set per transaction, so a pooled connection cannot carry one tenant's context into another's request.

Credential separation. The request-serving application runs under a database role that is subject to row level security and cannot bypass it. The privileged role used for migrations and operations is held in a separate secret store and is never mounted into the request path.

Secrets management. Credentials and API keys are held in a managed secret store, scoped per tenant where applicable. They are not stored in the database, in source control, or in correspondence.

Channel authentication. Inbound messages are authenticated against a per-tenant shared secret before any processing, and are rejected if it does not match.

Access control. Only authorised members on the customer's allowlist can use the assistant, bound to a verified messaging identity. Administrative access to production is limited to personnel who need it.

Encryption. Data is encrypted in transit using TLS, and encrypted at rest by the database and storage providers.

Backups and recovery. Backups are taken daily, retained for up to 90 days, and are restore tested. A documented restore runbook exists.

Erasure integrity. Erasure is a hard delete, not a flag. Erasures are recorded in an erasure log which is replayed against any restored backup, so a restore cannot resurrect erased personal data.

Change control. Every change runs an automated lint, test and evaluation suite, and release is gated on that suite passing. Deployment is performed by an authorised operator, whose credential is held in a managed secret store. Rollback to the previous release is a single operation.

Monitoring. Application errors, dependency health and synthetic checks are monitored, with alerting on failure.

Rate limiting. Per member and per tenant limits are enforced in the database, to limit abuse and runaway usage.

Personnel. Personnel with access are bound by confidentiality obligations.


Provided for the Controller's convenience. The Controller is responsible for its own privacy

notice. Adapt as needed. This is not legal advice.

Suggested wording for the Controller to give its members:

This community uses an automated AI assistant to answer your questions. You are talking to

software, not a person.

When you message the assistant we collect your name, your email address, your messaging

platform ID, anything you tell it about your business, and the messages you send. We keep a

history of your conversations so the assistant can remember context and give you better

answers. Questions the assistant cannot answer may be passed to our team so we can answer them.

We use [Controller name] and our technology provider Pulsar AI Ltd to run the assistant. Data is

stored in the United Kingdom. Some processing takes place outside the United Kingdom, under

appropriate safeguards. [Adjust this sentence to match the services actually used, and delete it

if all processing stays in the UK.]

The assistant is automated and can be wrong. Do not rely on it for legal, financial, medical or

other professional advice, and check anything important with us.

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by

contacting [Controller contact]. You can also complain to the Information Commissioner's Office

at ico.org.uk.


Pulsar AI Ltd, registered in England and Wales, company number 17310016.