All MicHelper legal documents

Data Processing Agreement

Last updated: June 2026 · Version 3.0

Planned legal operator: TOV "MikHelper" (MicHelper LLC), Lviv, Ukraine. State registration is currently being completed. Official registration details will be published immediately after registration.

Legal contact: legal@michelper.com

Current market: MicHelper is preparing for launch in Ukraine.

About This Agreement

These Data Processing Terms form part of the agreed customer relationship between MicHelper ("Processor") and the Customer ("Controller") and govern processing of personal data by MicHelper on the Customer's behalf in accordance with applicable Ukrainian law.

On This Page

  • 1. Definitions
  • 2. Scope & Application
  • 3. Processing Instructions
  • 4. Confidentiality
  • 5. Security Measures
  • 6. Subprocessors
  • 7. Provider and processing safeguards
  • 8. Data Subject Rights
  • 9. Data Breach Notification
  • 10. Data Deletion & Return
  • 11. Audit Rights
  • 12. Liability
  • Annexes

1. Definitions

In this DPA, the following terms have the meanings set out below:

  • "Controller" means the Customer who determines the purposes and means of processing Personal Data.
  • "Processor" means MicHelper, which processes Personal Data on behalf of the Controller.
  • "Personal Data" means information relating to an identified or identifiable natural person under applicable law.
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, and deletion.
  • "Data Subject" means the individual to whom the Personal Data relates.
  • "Subprocessor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
  • "Applicable law" means the Ukrainian personal-data and related legislation applicable to the agreed service.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for international data transfers.

2. Scope & Application

2.1 Subject Matter

This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the MicHelper service as described in the Terms of Service.

2.2 Duration

This DPA shall remain in effect for the duration of the Terms of Service and shall automatically terminate upon termination or expiration of the Terms of Service, subject to the data deletion obligations set out herein.

2.3 Nature and Purpose of Processing

The Processor processes Personal Data for the purpose of providing the MicHelper sales quality control service, including:

  • Receiving, storing, and processing audio recordings
  • Transcribing audio to text using AI/ML technologies
  • Analyzing transcripts against sales scripts and rules
  • Generating performance scores, reports, and analytics
  • Enabling data export and reporting functions

2.4 Types of Personal Data

The Personal Data processed may include:

  • Employee identifiers (names, employee IDs, login credentials)
  • Contact information (email addresses, phone numbers)
  • Audio recordings of sales conversations
  • Transcripts of conversations
  • Performance data and scores
  • Usage data and access logs

2.5 Categories of Data Subjects

The Data Subjects whose Personal Data may be processed include:

  • Controller's employees (sellers, managers, administrators)
  • Controller's customers (voices captured in recordings)

3. Processing Instructions

3.1 Controller's Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.

3.2 Documented Instructions

The Controller's instructions are documented in:

  • This DPA and its Annexes
  • The Terms of Service
  • Configuration settings in the MicHelper platform
  • Written communications between the parties

3.3 Additional Instructions

If the Controller provides additional instructions that require changes beyond the scope of the Service, the Processor may charge additional fees for implementing such instructions.

3.4 Notification of Unlawful Instructions

If the Processor believes that an instruction from the Controller infringes applicable data protection law, the Processor shall promptly inform the Controller and shall not be required to follow such instruction until the matter is resolved.

4. Confidentiality

4.1 Confidentiality Obligations

The Processor shall ensure that persons authorized to process Personal Data:

  • Have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
  • Process Personal Data only as instructed
  • Are informed of the confidential nature of the Personal Data

4.2 Access Limitation

The Processor shall ensure that access to Personal Data is limited to those personnel who need access to perform the Service and that such personnel are trained in data protection requirements.

5. Security Measures

5.1 Technical and Organizational Measures

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B, including:

  • Encryption of Personal Data in transit and at rest
  • Measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Measures to restore availability and access to Personal Data in a timely manner in the event of an incident
  • Process for regularly testing, assessing, and evaluating effectiveness of security measures

5.2 Security Assessment

In assessing the appropriate level of security, the Processor takes into account:

  • The risks presented by Processing, particularly from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data
  • The state of the art and costs of implementation
  • The nature, scope, context, and purposes of Processing

6. Subprocessors

6.1 Authorization

The Controller provides general authorization for the Processor to engage Subprocessors. The current list of Subprocessors is available at /legal/subprocessors.html, upon request, or in the Controller's account settings.

6.2 Obligations

When engaging a Subprocessor, the Processor shall:

  • Enter into a written agreement with the Subprocessor imposing data protection obligations equivalent to those set out in this DPA
  • Remain fully liable to the Controller for the performance of the Subprocessor's obligations
  • Conduct appropriate due diligence on the Subprocessor's security practices

6.3 Notification of Changes

The Processor shall provide the Controller with at least 30 days' notice before adding or replacing any Subprocessor, giving the Controller an opportunity to object. If the Controller objects on reasonable grounds, the parties shall discuss in good faith to resolve the matter.

7. International Data Transfers

7.1 Transfer Mechanisms

Cross-border transfers are governed by applicable Ukrainian law and the safeguards in Annex D, not by the EEA as the sole legal framework. Before production data is sent to a recipient in a jurisdiction that does not provide an adequate level of protection, the Controller and Processor must document the applicable legal mechanism and written safeguards.

  • Purpose limitation and confidentiality
  • Security controls appropriate to the data and risk
  • No onward transfer outside the agreed provider chain without authorisation
  • Deletion or return at the end of processing
  • Assistance with incidents and data-subject requests

7.2 Current destinations

The current list of subprocessors and their known jurisdictions is published at /legal/subprocessors.html. Unknown jurisdictions remain marked [TODO] and must be verified before production customer data is transferred.

7.3 Additional Safeguards

The technical measures in Annex B supplement, but do not replace, the written transfer safeguards required by Annex D.

7.4 Uncompleted safeguards

[TODO: execute and archive contractual transfer safeguards with every non-adequate-jurisdiction subprocessor before production customer data is sent.]

8. Assistance with Data Subject Rights

8.1 Data Subject Requests

Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law.

8.2 Notification

If the Processor receives a verified conversation-data request directly, it shall forward the request to the relevant Controller within 5 days, notify the requester of the recipient, and assist the Controller. The Controller remains responsible for the substantive response unless applicable law requires the Processor to act directly.

8.3 Tools and Features

The Processor provides only the self-service tools that are actually available in the current product. As of this version these include:

  • Access and export Personal Data
  • Submit privacy and account-deletion requests through the interface

[TODO: add and verify controller self-service correction, network-wide deletion, configurable speaker-specific retention and restriction controls before claiming them here.]

9. Data Breach Notification

9.1 Notification to Controller

The Processor shall notify the Controller without undue delay after becoming aware of a Data Breach affecting Personal Data processed under this DPA. Notification shall be made within 72 hours where feasible.

9.2 Content of Notification

The notification shall include, to the extent known:

  • A description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9.3 Assistance

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach and in meeting the Controller's obligations under applicable data protection law.

10. Data Deletion & Return

10.1 Upon Termination

Upon termination of the Terms of Service, the Processor shall, at the Controller's choice:

  • Return all Personal Data to the Controller in a commonly used format; and/or
  • Delete all Personal Data, unless retention is required by applicable law

10.2 Data Export Period

The Controller has 30 days following termination to export Personal Data. After this period, the Processor shall delete all Personal Data within 90 days, except as required by law.

10.3 Certification

Upon request, the Processor shall provide written certification that Personal Data has been deleted in accordance with this section.

11. Audit Rights

11.1 Audit Access

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor.

11.2 Conditions

Audits shall be conducted:

  • Upon reasonable notice (at least 30 days unless a Data Breach has occurred)
  • During normal business hours
  • In a manner that does not unreasonably disrupt the Processor's operations
  • Subject to confidentiality obligations
  • At the Controller's expense (unless the audit reveals material non-compliance)

11.3 Third-Party Certifications

The Processor may satisfy audit requests by providing relevant third-party certifications, audit reports, or summaries thereof, where available.

12. Liability

12.1 Allocation

Each party's liability under this DPA shall be subject to the limitations of liability set out in the Terms of Service.

12.2 Regulatory Fines

Nothing in this DPA shall limit either party's liability for regulatory fines or penalties imposed directly on that party by a supervisory authority.

Annexes

Annex A: Details of Data Processing

Subject MatterProcessing of audio recordings and derived data for sales quality monitoring and analytics
DurationFor the term of the Customer's subscription plus 30 days
Nature and PurposeAudio transcription, AI-powered analysis, performance scoring, compliance checking, reporting
Categories of Data SubjectsCustomer's employees (sellers, managers), incidental recording of customers/visitors in retail environments
Categories of Personal DataVoice recordings (transient), text transcripts, performance scores, names, login credentials, IP addresses, device identifiers, Telegram chat IDs (if applicable), payment transaction references
Potentially sensitive dataVoice data (MicHelper does not use voice for identification purposes)

Data Processing Lifecycle

Data CategoryProcessingRetentionDeletion Method
Audio recordingsTranscription through the disclosed speech-recognition subprocessorDeleted after successful transcription; a failed-transcription retry copy may remain for no more than 6 hoursPermanent file deletion from server storage after success or expiry of the retry window
Customer/visitor transcript textAnalysis and authorised reviewUp to 30 days; up to 12 months only for a session validly placed in legal holdAutomated redaction of the customer-role portion of the transcript, excluding any session under legal hold. [TODO: this automated pass exists in code but is disabled by default pending verification against a non-production database before go-live; confirm it has been enabled in production before relying on this row.]
Employee transcript textQuality analysis for the Controller[TODO: implement verified speaker-specific retention for the subscription term — the current server-side cleanup deletes sessions/transcripts on a fixed schedule regardless of active-subscription status][TODO: verify speaker-specific hard deletion]
Sensitive vertical customer textNot persisted for accounts flagged as a sensitive vertical (pharmacy, optical, medical/clinic retail)Blocked at write time before storage, not merely deleted afterward[TODO: this write-time block exists in code but has not yet been verified against production traffic; confirm before enabling any sensitive-vertical account]
Analytics & scoresComputed from transcripts, aggregatedPersist during subscription + 30 days after terminationAccount deletion request or subscription termination
Account dataAuthentication, configurationDuration of subscription + 30 daysAccount deletion process with confirmation
AI provider routing auditProvider, region, model and request metadata without prompt/response content12 monthsAutomated hard deletion

Annex B: Technical and Organizational Security Measures

The Processor implements the following security measures:

1. Encryption:

  • Data in transit: TLS 1.2 or higher
  • Data at rest: AES-256 encryption
  • Database encryption enabled

2. Access Controls:

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Two-factor authentication planned for a future release
  • Password policies enforced
  • Session management and timeout

3. Audit & Monitoring:

  • Comprehensive audit logging
  • Security monitoring and alerting
  • Regular log review

4. Data Protection:

  • Regular backups with encryption
  • Data segregation between customers
  • Secure deletion procedures
  • Configurable retention policies

5. Organizational Measures:

  • Security awareness training
  • Incident response procedures
  • Vendor security assessments
  • Regular security reviews

Annex C: Authorized Subprocessors

The authoritative list is rendered from the same facts file used by the notice and sticker:

The Processor shall notify the Controller at least 30 days in advance of a material change to this list, giving the Controller an opportunity to object. Information required for a specific customer agreement is available from legal@michelper.com.

Annex D: Cross-border Transfer Safeguards

For every recipient in a jurisdiction that does not provide an adequate level of protection, the parties shall document the lawful transfer mechanism and obtain written guarantees covering confidentiality, purpose limitation, security, prohibition of unauthorised onward transfer, deletion or return, incident assistance, and enforceable audit/cooperation duties.

[TODO: attach signed provider-specific safeguards and verified jurisdictions before production processing.]

Last updated: June 2026 · Version 3.0

Planned legal operator: TOV "MikHelper" (MicHelper LLC), Lviv, Ukraine

Questions about this agreement? legal@michelper.com

© 2026 MicHelper. All rights reserved.