Put plainly
You are the controller, we are the processor. We act on your instructions, we do not use your clients' data for anything else, and we delete it on the schedule you choose.
What this is
This agreement forms part of the terms between Bonafile LLC and any customer who is a firm, organisation or professional acting for their own clients. Where you are a controller under the UK GDPR, the EU GDPR or comparable law, and we process personal data on your behalf, this sets out how.
We will sign a copy on request — write to legal@bonafiles.com. If your own DPA is required instead, send it and we will review it rather than insist on ours.
Roles
You are the controller. You decide whose conversations are processed and why. We are the processor and act only on your documented instructions, which are these terms and whatever you do in the product.
If we ever believe an instruction breaks data-protection law, we will tell you rather than carry it out quietly.
What we process, and for how long
Subject matter: producing an evidential record, translations and exhibits from correspondence you or your client supplies.
Categories of data subject: your client, and the other participants in the conversations they supply.
Categories of personal data: message content, participant names and identifiers, timestamps, call metadata, and any attachment supplied. This may include special-category data — health, sex life, religious belief — because private correspondence frequently does.
Duration: the retention window selected on the account. Three days by default; seven, twenty-one, or one year in archive by choice. Deletion is described in the privacy policy, including the limits backups place on it.
What we will not do
We do not use your clients' data to train models, ours or anyone else's, and our providers are contractually held to the same.
We do not sell it, share it for advertising, or use it for any purpose other than providing the service to you.
We do not access it except where necessary to provide or support the service, and every access is logged against a named person.
Security
Encrypted in transit and at rest. Access is limited to a small number of named engineers under individual accounts, with every read written to an append-only log. Support staff cannot read case content.
Identifiers we detect are removed or replaced with a one-way token before storage. Detection is strongest on English and Latin-script text.
The security page describes the controls in full and is incorporated into this agreement by reference.
Sub-processors
We use the sub-processors listed on the sub-processor page, which forms part of this agreement. You consent to their use generally.
We will give you thirty days' notice before adding or replacing one. If you object on reasonable data-protection grounds within that period and we cannot resolve it, you may terminate for that reason without penalty and we will refund any unused balance.
Each is bound by written terms no less protective than these.
Helping you meet your own obligations
If a data subject exercises a right against you, we will help you answer within a reasonable time and at no charge for anything proportionate.
We will help with data-protection impact assessments and with prior consultation where you need them, and we will make available the information reasonably required to demonstrate compliance with this agreement.
Breach notification
We will tell you without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting your data, with what we know, what we are doing, and what we recommend you do.
We will not wait for a complete account before telling you. An early notice that is later revised is more useful to you than an accurate one that arrives too late to act on.
International transfers
Data is stored and processed in the United States. Where you are in the UK or the EEA, transfers rely on the Standard Contractual Clauses, which our providers are bound by and which we incorporate here.
Deletion and return
At the end of the retention window, or on termination, we delete the data. Live copies go immediately; encrypted backups expire within thirty days and are never restored except to recover from a failure.
You can export everything at any time before then, and we will not hold your work to make you stay.
Audit
We will answer a security questionnaire and provide the documentation we hold. Where a firm's obligations require more, we will discuss a proportionate arrangement rather than refuse.
We are a small company and we will not pretend to certifications we do not hold. If you need SOC 2, ask, and we will tell you honestly where we are.
Questions about this document? Write to legal@bonafiles.com and a person will answer.
Contact us