Data processing agreement
Your visitors’ conversations are yours. Here is what we do with them on your behalf.
Roles
You, the copadre account holder, are the controller of the personal data in your conversations. This Company (Digital) Limited, trading as copadre, is your processor. This agreement forms part of the terms of service and applies for as long as your account is open. By creating an account or using copadre, you accept it.
Subject matter and duration
Running the agents you configure, on the websites you allow, for as long as your account is open.
Nature and purpose of the processing
Receiving messages from visitors to your website, sending them to Anthropic’s API on your own key to generate a reply, storing the exchange so you and your team can read it in the portal, and sending you the notifications you have configured.
Types of personal data
- the contents of messages between your visitors and your agents. copadre does not ask visitors for personal details — what a visitor types is up to them and to how you have instructed your agents. Message contents are encrypted at rest.
- a browser session identifier, so a visitor’s conversation survives a page change
- the visitor’s time zone, where their browser reports it
- the visitor’s IP address, recorded when a conversation is blocked (turn limit or abuse), and held in the IP whitelist you set
We do not store visitors’ names, email addresses or payment details as fields — only whatever appears in the message text itself.
Categories of data subject
Visitors to your website who talk to your agents.
Our obligations
- we process this data only on your documented instructions. Configuring an agent in the portal is an instruction; so is a written request for us to configure one for you. The baseline guidance copadre applies to every agent, which protects against abuse and enables features of the service, is part of the service itself — running your agents with it is within your instructions, not a departure from them.
- we will tell you if we believe an instruction you give us breaks data protection law
- our staff who can access it are bound by confidentiality
- we apply the security measures set out below
- we tell you before we add or replace a sub-processor, and you may object (see Sub-processors)
- we will help you respond to a request from a data subject, and to a breach, an impact assessment or a consultation with the regulator
- we will tell you without undue delay if we become aware of a personal data breach
- we delete the data at the end of your account (see Retention and deletion)
- we will answer your questions about how we meet these obligations, as set out in Demonstrating compliance below
Security measures
- copadre is operated by This Company (Digital) Limited, which holds Cyber Essentials certification, the UK government-backed scheme owned by the National Cyber Security Centre
- message contents, your agents’ instructions, personal details and your Anthropic API key are encrypted at rest (AES-256-GCM)
- HTTPS only; the runtime API is token-authenticated, with constant-time checks
- copadre runs in its own isolated account, with its own files and database, on a UK virtual server dedicated to This Company (Digital) Limited and administered solely by us
- your conversations, agents, routing and blocks are isolated from every other customer’s
- every embed key is bound to a single agent and enforced server-side, so a leaked key exposes one agent rather than your whole roster
- agents only run on the domains you allow; requests from other origins are rejected
- turn limits and blocking protect against abuse. Turn limits are scoped to a single conversation, so one visitor’s behaviour does not block a shared office IP.
- visitor input has control tokens neutralised and its length capped, as a defence against prompt injection
- sign-in to the portal is passwordless and rate-limited, with single-use, short-lived tokens
Anthropic is not our sub-processor
Your agents run on your own Anthropic API key. Your relationship with Anthropic is direct: you hold the account, you agree Anthropic’s terms, and Anthropic bills you. copadre is not a party to it.
When a visitor sends a message, copadre transmits it to Anthropic’s API on your key and on your instruction, so that your agent can reply. Anthropic’s handling of that message is governed by your agreement with Anthropic, not by this one. You are responsible for that agreement, including where Anthropic processes the data and any transfer outside the UK it involves.
External tools
If you connect an external tool — including, for example, an AI tool via MCP — to your copadre account, you are instructing us to disclose the data that tool can reach (your conversations, messages and agents’ instructions) to it and its provider. That disclosure happens under your own agreement with the tool’s provider, on terms, retention and jurisdiction we do not control and are not a party to — in the same way as your agreement with Anthropic, above. You are responsible for satisfying yourself about that provider’s data handling before you connect it, and, where you hold your account on behalf of your own clients, for having their authority to disclose their data this way.
Every connection is made by a named user of your account, who must explicitly approve it — including which parts of your data it can reach — before it is granted. We keep a record of who approved each connection and when, and of each individual request made through it afterwards, including which client’s data it touched if it crossed between clients you manage. You can revoke a connection at any time from your account, which cuts off access immediately.
This also covers work we do for you: if you ask us to configure or maintain your agents and we use an external tool to do it, that is within the instructions you’ve already given us under “Our obligations” above, not a separate disclosure you need to authorise again.
Sub-processors
Hosting. copadre is hosted by Unlimited Web Hosting UK Limited, acting as our sub-processor. They are Cyber Essentials certified too, and are registered in England and Wales at The Copper Room, Deva Centre, Trinity Way, Manchester, M3 7BG (Company No. 06786340, VAT No. GB 989668423).
Email — sign-in links and the notifications you configure — is sent from that same server. We do not use a third-party email service.
Unlimited Web Hosting is our only sub-processor, and is bound by written terms that protect your data to a standard equivalent to this agreement. We will tell you before we add or replace a sub-processor. If you object on reasonable data protection grounds and we cannot resolve your objection, you may close your account.
Where the data is held
The data copadre holds — conversations, messages, account details and settings — is stored on UK infrastructure, under UK jurisdiction, on a UK virtual server dedicated to This Company (Digital) Limited: the hosting company provides the infrastructure, but day-to-day administration is ours alone, and no other business has administrative access. Backups are held in the UK. copadre makes no transfer of this data outside the UK.
The exception is the message sent to Anthropic to generate a reply, described above, which travels under your own agreement with Anthropic rather than ours.
Retention and deletion
A conversation counts as finished after the period of inactivity you set (5–60 minutes), and then appears in your portal inbox. You archive conversations yourself in the portal; any conversation left inactive for 30 days is archived automatically. Archiving is a state in the portal, not deletion.
We keep your conversations and the messages in them for as long as your account is open. You can ask us for a copy of them at any time, and we will supply it in a machine-readable format.
When your account is closed, your conversations and messages are deleted within 30 days. If you want a final copy, ask us before you close the account.
Some supporting records are cleared on a shorter cycle:
- sign-in sessions and login links — as soon as they expire
- records of a blocked visitor — once the block has expired
- records of notifications we have sent you — after 180 days
- diagnostic token logs — after 2 years
Your obligations
You are responsible for having a lawful basis for the conversations your agents hold, for telling your visitors what happens to those conversations, and for what you instruct your agents to ask for.
Demonstrating compliance
If you need to satisfy yourself that we are meeting our obligations under this agreement, ask us in writing and we will answer in writing, including completing a reasonable security questionnaire. We will do this once in any twelve-month period, on 30 days’ notice, unless a regulator requires otherwise or there has been a personal data breach affecting your data.
If a written answer is demonstrably not enough — because your regulator requires an audit, or there has been a personal data breach affecting your data — you may have an audit carried out, by you or by an independent auditor we both accept, remotely or at a location we agree. An audit is at your expense, including our time at our then-current rates, on 30 days’ notice, no more than once in any twelve-month period, and under confidentiality.
Our answers, and anything an audit reveals, are confidential to you. Neither extends to anything that would compromise the security or confidentiality of another customer.
Governing law and changes
This agreement forms part of the terms of service and is governed by them, including their governing law and the way we tell you about changes.
Contact
For questions about this agreement, write to hello@copadre.com.
Last updated 13 August 2026.