Data Processing Agreement (Article 28 GDPR)

Provided by Helios Media Limited (Hong Kong) · Effective date: October 2026

This Data Processing Agreement (“DPA”) forms part of the SetterHero Terms of Service and applies where Helios processes personal data of the Customer’s contacts on the Customer’s behalf. It reflects Article 28 GDPR and equivalent UK/Swiss requirements.

1. Roles

The Customer is the controller (or processor acting for its own controller) and Helios is the processor. Each party complies with applicable data protection law. The Customer is responsible for the lawfulness of the processing it instructs, including the lawful basis and any consent in respect of its contacts.

2. Subject-matter and details of processing

Subject-matter: provision of the Service. Duration: the term of the Terms. Nature and purpose: AI-assisted drafting, orchestration and management of messages exchanged between the Customer and its contacts. Types of personal data: contact identifiers, message content and metadata determined by the Customer. Categories of data subjects: the Customer’s contacts and prospects. Special-category data must not be processed unless agreed under a Tier 2 Order Form (see AUP §2).

3. Processing on instructions

Helios processes personal data only on the Customer’s documented instructions (including these Terms and the configuration the Customer chooses), including as regards international transfers, unless required otherwise by law, in which case Helios informs the Customer where legally permitted.

4. Confidentiality

Helios ensures that persons authorised to process the data are bound by confidentiality.

5. Security

Helios implements appropriate technical and organisational measures under Article 32, taking account of the state of the art, the risks and the nature of the data. The Service runs on cloud infrastructure provided by Helios’s hosting sub-processors (application hosting, managed database and workflow-automation hosting; see Annex 1), configured and controlled by Helios; the application and its database are hosted in the European Union. These measures include encryption of data in transit, encryption at rest of the credentials used to connect the Customer’s accounts (such as CRM access tokens and API keys), logical separation of each customer’s data, and access restricted to authorised personnel.

6. Sub-processors (general authorisation)

The Customer grants Helios general authorisation to engage sub-processors within the categories described in Annex 1 (set out at the end of this DPA). Helios maintains an up-to-date list of named sub-processors, which it makes available to the Customer on request, and imposes on each sub-processor data-protection obligations no less protective than this DPA, remaining liable for their performance. Helios will give the Customer prior notice of any intended addition or replacement of a sub-processor, allowing the Customer to object on reasonable data-protection grounds. The Customer’s own GHL account, WhatsApp Business and Instagram channels and their providers are the Customer’s own processors and are not Helios sub-processors.

7. AI processing safeguards

Personal data contained in the Customer’s messages is processed by AI model providers, accessed through an LLM gateway (see Annex 1), to generate AI-assisted replies and drafts and to provide the analytics features of the Service, such as conversation reports. Helios selects the models used and sends them only the data needed for the requested function. Helios does not use the Customer’s contact personal data to train its own models and does not sell it. Helios configures the LLM gateway so that requests are routed only to model providers whose terms do not permit the use of the data for model training. The workflow orchestration that connects the Customer’s channels to the AI model providers runs on Helios’s hosting sub-processors under Helios’s configuration and control, and is not used to transmit the Customer’s contact personal data to any third party other than the sub-processors described in Annex 1. Transfers to sub-processors located outside the EEA, the UK or Switzerland are made in accordance with Section 12.

8. Assistance to the Customer

Helios assists the Customer, by appropriate measures and taking into account the nature of processing, to respond to data-subject requests (Chapter III GDPR) and to meet its obligations under Articles 32–36 (security, breach notification, data-protection impact assessments and prior consultation).

9. Personal data breach

Helios notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, with the information reasonably available to assist the Customer’s own obligations.

10. Return or deletion

On termination, Helios deletes or returns the personal data at the Customer’s choice and deletes existing copies, save where retention is required by law. Automated back-ups are deleted on their ordinary cycle and remain subject to this DPA until then.

11. Audits

Helios makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, by the Customer or a mandated auditor, on reasonable notice, subject to confidentiality and to not compromising other customers’ security.

12. International transfers

Where the Customer is subject to EEA, UK or Swiss data protection law and transfers personal data to Helios in Hong Kong, the EU Standard Contractual Clauses (controller-to-processor module), together with the UK International Data Transfer Addendum and the Swiss amendments as applicable, are incorporated into this DPA and apply to the transfer, with Helios as data importer and the Customer as data exporter. Onward transfers to sub-processors are made under equivalent clauses.

13. Priority

In case of conflict on data protection matters, this DPA prevails over the other parts of the Terms; the SCCs prevail over this DPA.

Annex 1 – Sub-processor categories

This Annex forms part of this DPA (and is also referenced by the Privacy Policy).

Helios engages sub-processors only within the following categories, and discloses the current named list to the Customer on request, under confidentiality:

  • Cloud infrastructure / hosting – application hosting, managed database and hosting of the workflow-automation environment used to run the Service.
  • LLM gateway / orchestration service – routing of requests to AI model providers.
  • AI model providers – generation of AI-assisted replies and drafts and analysis of conversations for the reporting features of the Service; engaged on terms that do not permit the use of the data for model training.
  • Transactional email – delivery of service emails to the Customer’s users, including operational alerts that may contain contact names and conversation summaries.
  • Payment processing – billing and payment collection; processes account and billing data only.
  • Internal operations tools – project management and internal team notifications used for onboarding and support; process account data (business contact details and onboarding information), not the content of the Customer’s conversations.

The Customer’s own GHL account, WhatsApp Business and Instagram channels and their underlying providers are managed by the Customer and are not Helios sub-processors. Helios notifies the Customer in advance of any change to its named sub-processors, allowing objection on reasonable data-protection grounds.