This Data Processing Agreement applies automatically when you use CustomerEagle to process personal data on behalf of your own customers, and forms part of your agreement with us. If your organisation requires bespoke data-processing terms, contact us at [email protected].
This Data Processing Agreement ("DPA") forms part of the agreement between the customer that uses CustomerEagle ("Customer") and CustomerEagle for the provision of the CustomerEagle service ("Service"). It governs the processing of personal data that CustomerEagle carries out on behalf of the Customer under Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
If there is any conflict between this DPA and the rest of the agreement on the subject of personal-data processing, this DPA prevails.
Parties and Roles
For personal data that CustomerEagle processes to deliver the Service, the Customer acts as the controller and CustomerEagle acts as the processor. Where the Customer is itself a processor for another controller (for example, its own client), CustomerEagle acts as a sub-processor and this DPA applies accordingly.
CustomerEagle is operated by RSG Digital (KvK 42085647). Questions about this DPA can be sent through our contact page or to [email protected].
Subject Matter and Duration
The subject matter of the processing is the provision of the Service: AI-assisted customer support across a chat widget, help center, email and messaging channels, an agent inbox with an AI copilot, and connected integrations. Processing lasts for the duration of the agreement and continues only for as long as needed to provide the Service, plus any limited period required to return or delete personal data as described under Return and Deletion below, or where retention is required by law.
Nature and Purpose of Processing
CustomerEagle processes personal data solely to provide and support the Service on the Customer's documented instructions. This includes:
- Receiving and storing conversations between the Customer's visitors or end-customers and the Customer, across the widget, help center, email and messaging channels.
- Generating AI-assisted answers and draft replies grounded in the Customer's knowledge base, and classifying and routing messages.
- Performing order and account lookups where the Customer connects a commerce integration (for example Shopify or WooCommerce). Before order data is revealed, the visitor must supply the email address and order number matching the order (an email-match check); the Customer may additionally enable a one-time code sent to that email address, and on Shopify storefronts a signed-in customer's verified session may be used.
- Hosting the Customer's knowledge base and help-center content used to answer questions.
- Sending transactional communications (such as email replies) on the Customer's behalf.
- Providing analytics, reporting, security, and support relating to the Service.
Categories of Data Subjects
- Visitors and end-customers of the Customer who contact it through CustomerEagle.
- Authorised users of the Customer's workspace (owners, administrators and agents).
- Any other individuals whose personal data appears in conversations, knowledge-base content or connected records that the Customer chooses to process through the Service.
Categories of Personal Data
- Contact and identity data of visitors and customers — name, email address, phone number, and similar identifiers they provide.
- Conversation content — chat, email and messaging content, support tickets, attachments and their metadata.
- Order and account metadata retrieved from connected integrations — order numbers, status, fulfilment and shipping details, and Shopify (or other commerce) customer identifiers.
- Workspace-user data — account names, email addresses and authentication data of the Customer's agents and administrators.
- Technical data — IP address, device and browser information, and session identifiers processed to operate and secure the Service.
The Customer must not use the Service to process special categories of personal data (Article 9 GDPR) unless expressly agreed in writing, and remains responsible for the content it or its end-customers submit.
Processing on Documented Instructions
CustomerEagle processes personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law to which it is subject; in that case CustomerEagle informs the Customer of that legal requirement before processing, unless the law prohibits it. The agreement, the Service configuration options the Customer selects, and this DPA constitute the Customer's complete and final documented instructions. CustomerEagle informs the Customer if, in its opinion, an instruction infringes data-protection law.
Confidentiality
CustomerEagle ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to personal data is limited to personnel who need it to provide the Service.
Security Measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, CustomerEagle implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit — TLS for data transmitted between clients, the Service and integrations.
- Encryption at rest — AES-256-GCM encryption for stored credentials and sensitive personal data.
- Tenant isolation — a multi-tenant architecture with per-tenant scoping and PostgreSQL row-level security as a defence-in-depth layer to keep each Customer's data separate.
- Access control — role-based access control (RBAC) for staff and mandatory multi-factor authentication (MFA) for platform staff accounts.
- Audit logging — logging of security-relevant and administrative events to support monitoring and investigation.
- Resilience and recovery — encrypted backups and measures to restore availability and access to personal data after an incident.
- Testing — processes to review and improve the effectiveness of these measures.
CustomerEagle may update its security measures over time provided the level of protection is not materially reduced.
Sub-processors
The Customer provides a general authorisation for CustomerEagle to engage sub-processors to provide the Service. CustomerEagle imposes data-protection obligations on each sub-processor that are, in substance, no less protective than those in this DPA, and remains liable for its sub-processors' performance of those obligations.
Service sub-processors — vendors CustomerEagle engages to process Customer personal data on the Customer's behalf.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Railway | Application and database hosting | EU / US |
| Cloudflare | Content delivery, object storage and custom domains | Global edge (EU / US) |
| Resend | Transactional email delivery | EU / US |
| OpenAI | AI-generated answers and drafting (enabled features) | US |
| DeepSeek | Alternative AI provider (enabled features) | US |
| GlitchTip / Sentry-compatible monitoring | Error and performance monitoring where configured | EU / US |
Customer-directed integrations — services the Customer independently connects and controls. These are not sub-processors engaged by CustomerEagle; the Customer's own agreement with each provider governs that processing.
| Service | Purpose | Processing location |
|---|---|---|
| Shopify | Commerce data lookups where the Customer connects Shopify | EU / US |
Other integrations the Customer connects — for example WooCommerce stores or Meta channels such as WhatsApp, Messenger and Instagram — are likewise customer-directed and governed by the Customer's own agreement with each provider.
CustomerEagle controller-side vendors — vendors CustomerEagle uses for its own account administration, billing and consent-based analytics, where CustomerEagle acts as an independent controller (as described in the Privacy Policy) rather than as the Customer's processor.
| Vendor | Purpose | Processing location |
|---|---|---|
| Stripe | Billing and payment processing for the customer relationship | EU / US |
| PostHog EU Cloud | Consent-based product and website analytics | EU |
| Google Analytics 4 (Google Ireland Limited) | Consent-based public-site measurement | EU / US |
CustomerEagle notifies the Customer of any intended addition or replacement of a sub-processor with at least 30 days' advance notice, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer reasonably objects and the parties cannot resolve the concern, the Customer may terminate the affected part of the Service.
International Transfers
Where processing involves a transfer of personal data outside the European Economic Area or the United Kingdom to a country without an adequacy decision, CustomerEagle relies on an appropriate transfer mechanism — primarily the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum — together with any supplementary measures needed to protect the data.
Assistance to the Customer
Taking into account the nature of the processing and the information available to it, CustomerEagle assists the Customer by appropriate technical and organisational measures, insofar as possible, in:
- Responding to data-subject requests — the Service provides self-service export and deletion tools, and CustomerEagle assists with requests to access, rectify, erase, restrict, port or object to the processing of personal data (Articles 12–23 GDPR).
- Security, breach notification and impact assessments — assisting the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation.
Personal Data Breach Notification
CustomerEagle notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, providing an initial notification where practicable within 24 hours of becoming aware. Information that is not available at the time of the initial notification may be provided in phases without undue further delay. The notification describes, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, and names a contact point for further information ([email protected]). CustomerEagle provides reasonable cooperation to help the Customer meet its own notification obligations, including ongoing updates as the investigation progresses.
Audit Rights
CustomerEagle makes available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. To protect the security and confidentiality of other customers, audits are conducted on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. CustomerEagle may satisfy audit requests by providing relevant certifications, reports or documentation where available.
Return and Deletion
On termination of the Service, and at the Customer's choice, CustomerEagle deletes or returns the personal data it processes on the Customer's behalf and deletes existing copies, unless EU or Member State law requires continued storage. Personal data is removed from active systems promptly after termination; residual copies in encrypted backups are deleted in the ordinary backup cycle, ordinarily within 90 days. The Customer can also export data before termination using the Service's export tools.
Liability and Changes
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement. CustomerEagle may update this DPA where needed to reflect changes in law, sub-processors or the Service, and will provide notice of material changes as described in the agreement.
Contact
Data protection / privacy team Email: [email protected] CustomerEagle · RSG Digital · KvK 42085647