Data-processing agreement
LEVER CONSULTANCY LTD, trading as Hi Boss · Version 2026-09-07.2 · 7 September 2026
Parties and scope
This agreement forms part of the terms between LEVER CONSULTANCY LTD, trading as Hi Boss (processor), and the business customer identified by the account or organisation accepting the terms (controller). It governs UK GDPR personal data processed on customer instructions. It does not govern our independent controller activities described in the privacy notice. Processing continues for the service term and the applicable deletion period.
Processing particulars
Subject matter: AI meeting participation and authorised knowledge retrieval. Operations: receiving, transmitting, transcribing, indexing, retrieving, generating answers and summaries, storing permitted records, exporting and deleting. Purposes: supporting customer-selected meetings and post-meeting review. Data subjects: users, meeting participants, customer staff, customers, suppliers and people mentioned in authorised content. Data: names, contact details, professional context, meeting metadata, speech, transcripts, documents, images, outputs and diagnostics. Highly sensitive, special-category, criminal-offence and children’s data are not permitted in this beta.
Documented instructions
We will process customer personal data only on documented instructions, including the service configuration, selected sources, meeting dispatch, sharing and deletion requests, unless UK law requires otherwise. We will inform the customer of that legal requirement before processing unless prohibited. We will promptly inform the customer if we consider an instruction infringes applicable data-protection law. The customer determines lawful purposes and bases, provides required notices, has authority over supplied data and responds to individuals’ requests.
Confidentiality and security
We will restrict access to authorised persons under confidentiality obligations and implement appropriate technical and organisational measures having regard to risk, state of the art and processing circumstances. These include account and workspace access controls, protected credentials, transport protection, scoped meeting access, deletion controls, security testing and incident handling. We will maintain and review these measures and not materially reduce protection during the service term. The security notice describes current measures and limitations; no certification or zero-risk guarantee is given.
Subprocessors and transfers
The customer generally authorises the providers described in the subprocessor notice for the stated purposes. We will impose equivalent data-protection obligations by written contract and remain responsible for their performance of delegated obligations. We will notify the customer in writing at least 30 days before adding or replacing a subprocessor, allowing a reasonable data-protection objection. We will seek a workable alternative; if none exists, the customer may terminate affected processing before the change. International transfers will only take place on instructions and using lawful safeguards where required.
Assistance and incidents
Taking account of processing and available information, we will assist the customer with individual rights requests, security obligations, impact assessments and consultation with regulators. We will notify the customer without undue delay after becoming aware of a personal-data breach affecting its data and provide available details of nature, affected data and people, likely consequences, contact and mitigation. Details may be supplied in stages. We will cooperate with investigation and remediation and preserve appropriate evidence. The customer remains responsible for its own notification decisions.
Return, deletion and audit
At the customer’s choice we will return or delete personal data at the end of services and delete copies unless UK law requires retention. Exports and deletion controls are available; contact us for additional assistance. Backup data awaiting deletion will be put beyond ordinary use, protected and deleted under the applicable cycle. We will provide information necessary to demonstrate these obligations and allow and contribute to reasonable audits and inspections by the customer or its mandated auditor, subject to proportionate security and confidentiality arrangements that do not defeat statutory rights. Contractual business liability provisions do not restrict data subjects’ statutory remedies.