Effective 20 September 2026
This Data Processing Agreement (“DPA”) is the standard terms under which MinskyAI Technology Limited (“Processor”, “we”, “us”) processes personal data for a customer (“Customer”, “you”) in connection with production SYVA services. When an order, master services agreement, or statement of work references this DPA, these terms form part of that contract.
This DPA is written for engagements in the United Kingdom and Hong Kong. It addresses the UK GDPR and the Data Protection Act 2018, and contractual duties under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”). Where EU personal data is processed, we apply equivalent safeguards.
The public SYVA website, forms, and Voice concierge are covered by our Privacy Policy, not this DPA.
1. Parties and roles
For personal data that Customer controls in a production SYVA engagement, Customer is the controller under UK law and the data user under the PDPO. MinskyAI Technology Limited is the processor under UK law and processes that personal data under contract for Customer under the PDPO.
Our Hong Kong affiliate, MinskyAI Tech Limited, may process Customer personal data as a subprocessor when local staff support delivery or incident response.
Customer remains responsible for deciding what personal data is processed in its systems and for the lawfulness of its instructions.
2. Scope
This DPA applies when we process Customer personal data in connection with:
- production pilots and deployments of SYVA (including Voice, Data Nexus, MeetInsight, and Knowledge AI where contracted);
- install, configure, support, and incident-response access to Customer’s environment;
- tickets, logs, or copies that contain Customer personal data and that we hold for delivery.
This DPA does not apply to:
- the public website and its forms;
- the Voice concierge (SYVA Product Concierge) on this website, provided for evaluation purposes only;
- personal data we collect as controller for our own marketing or investor enquiries.
Production SYVA is designed to run on the Customer’s premises, in the Customer’s private cloud, or on isolated networks with no external connectivity. Customer production personal data is not used to train foundation models.
3. Definitions
- Customer Data — personal data processed by us on behalf of Customer under this DPA.
- Instructions — Customer’s documented instructions in the contract, order, and this DPA (including Schedule A).
- Subprocessor — a third party engaged by us to process Customer Data on our behalf.
- UK GDPR — the UK General Data Protection Regulation as applied by the Data Protection Act 2018.
- PDPO — the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong.
4. Duration
This DPA lasts for the term of the services agreement that incorporates it, and then until Customer Data in our possession is deleted or returned under Section 14, except where law requires longer retention of specific records.
5. Nature and purpose
We process Customer Data only to deliver the contracted SYVA services: install and configure software, enable Customer-approved capabilities and knowledge on Customer’s instructions, provide support, and respond to incidents. Processing is limited to what is needed for those tasks and to Customer’s documented Instructions.
We do not sell Customer Data. We do not use Customer production personal data to train public foundation models.
6. Categories of data
Categories of data subjects and personal data are determined by Customer and described in the order or in Schedule A. Typical categories for SYVA Voice and related products include:
- callers, website visitors, and app users who interact with Customer’s Voice agent;
- Customer employees and contractors who administer or support the deployment;
- content in knowledge bases or tickets that may include personal data;
- support correspondence and access logs created during delivery.
Special-category or sensitive data is processed only if the order expressly allows it and Customer has a lawful basis.
7. United Kingdom (UK GDPR)
Where UK GDPR applies, we will:
- process Customer Data only on documented Instructions, unless UK law requires otherwise (in which case we inform Customer unless the law forbids notice);
- ensure persons authorised to process Customer Data are bound by confidentiality;
- implement appropriate technical and organisational measures under Article 32;
- not engage a Subprocessor without general or specific authorisation as in Section 10, and flow down equivalent duties;
- taking into account the nature of processing, assist Customer with data-subject requests;
- assist Customer with security, breach notification, and data-protection impact assessments, considering the information available to us;
- at the end of services, delete or return Customer Data as in Section 14;
- make available information needed to demonstrate compliance and allow audits as in Section 13;
- for restricted international transfers, use an approved mechanism such as the UK International Data Transfer Agreement or Addendum, or adequacy regulations.
8. Hong Kong (PDPO)
Where Customer Data relates to Hong Kong or the PDPO applies, Customer remains the data user primarily responsible under the PDPO. We process that data as Customer’s contracted processor and will:
- follow Customer’s Instructions and not use Customer Data for our own direct marketing;
- take practicable steps to protect Customer Data against unauthorised or accidental access, processing, erasure, loss, or use;
- retain Customer Data in our possession only as long as needed for the engagement or as required by law;
- assist Customer with data access and correction requests that relate to data we hold;
- transfer Customer Data outside Hong Kong only with Customer’s authority and with practicable contractual or other safeguards on recipients;
- ensure staff and Subprocessors who handle Customer Data are under appropriate confidentiality and security duties.
9. Customer obligations
Customer will:
- ensure Instructions are lawful and that Customer has a valid basis to process and to instruct us;
- provide the Schedule A details (or equivalent) needed to describe the processing;
- control the production environment, including access policies on Customer infrastructure;
- not instruct us to process Customer Data in a way that would cause unlawful processing.
10. Subprocessors
Customer gives general authorisation for us to use (a) MinskyAI Tech Limited and other MinskyAI affiliates for delivery and support, and (b) infrastructure, hosting, email, and security vendors strictly needed to perform the contract, under written terms that protect Customer Data no less carefully than this DPA.
We will give notice of material Subprocessor changes that affect Customer Data. Customer may object on reasonable data-protection grounds within fifteen (15) days. If we cannot accommodate a reasonable objection, either party may terminate the affected services on written notice without penalty for that objection alone.
11. Security
We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit for remote support paths, least-privilege staff access, and logging of support access where practicable.
Customer’s production environment remains under Customer’s control. Support access is limited to named roles for delivery and incident response — not open standing access. No measure can guarantee absolute security.
12. Personal data breaches
After becoming aware of a personal data breach affecting Customer Data in our possession or under our control, we will notify Customer without undue delay and provide information reasonably available to us so Customer can meet its own notification duties. We will cooperate on investigation and mitigation.
13. Audits
On reasonable written notice, we will provide information and security questionnaires to help Customer verify compliance. Customer may conduct an audit no more than once per twelve (12) months, unless a competent authority requires otherwise or a confirmed breach justifies an extra audit. Remote review is preferred. Audits must not unreasonably disrupt operations or expose other customers’ data.
14. Deletion and return
When the services end, or earlier on Customer’s written request, we will delete or return Customer Data in our possession (including support copies and tickets that contain it), except where UK, Hong Kong, or other applicable law requires retention. On request we will confirm deletion in writing.
15. Liability and precedence
Liability under this DPA follows the limitations and exclusions in the master services agreement or order that incorporates it, unless a mandatory data-protection law says otherwise.
If there is a conflict on data-protection topics, this DPA prevails over the commercial agreement. The executed order controls the commercial scope of services. An executed paper or electronic DPA signed for a specific deal prevails over this website text for that deal.
16. Contact
Privacy and DPA questions: info@minskyaitech.com.hk.
Related: Privacy Policy · Terms of Service.
Schedule A — Description of processing
Defaults for a typical SYVA Voice production engagement on the Customer’s infrastructure. The order may replace or extend these rows.
| Subject matter | Personal data processed to deliver and support contracted SYVA services |
|---|---|
| Duration | Term of the services agreement, then deletion or return under Section 14 |
| Nature | Access, storage, transmission, and deletion in the course of install, support, and incident response |
| Purpose | Perform the contracted SYVA services on Customer’s Instructions |
| Types of personal data | Identity and contact data; call or chat content; knowledge content that includes personal data; support tickets and access logs — as present in Customer’s systems |
| Data subjects | Callers and end users of Customer’s channels; Customer staff and contractors; other individuals whose data Customer places in scope |
| Security measures | Access control, encryption in transit for remote support, least privilege, support logging where practicable; Customer infrastructure controls remain Customer’s responsibility |