Legal
Data processing agreement
Version 1.0 - effective 5 August 2026
This agreement applies automatically to every organisation using Handbook under our standard terms, and forms part of them - there is nothing to sign. Organisations with a signed agreement have their own data processing terms, which govern instead. It is written in plain English on purpose; it is still binding.
1. Roles
Your organisation is the controller of the personal data inside its documents and its staff's questions. Jigsaw Software Development Ltd is the processor: we handle that data only to provide Handbook, on your organisation's behalf and its documented instructions - using the service is the instruction.
2. What we process, and why
- Document content your admins upload - stored, indexed and retrieved to answer staff questions.
- Staff questions and the answers given - stored pseudonymously; the chatbot collects no names, logins or identifying details, and keeps no lasting record of IP addresses.
- Admin account data (name, email, organisation) - to run the account.
- Usage counts - to meter the plan.
Processing lasts for the life of the agreement plus at most 90 days for deletion. Nothing is processed for any other purpose: no advertising, no profiling, and no training of AI models on your data - by us or by our providers.
3. Our commitments
- Everyone who can touch personal data is bound by confidentiality.
- Security by design: encryption in transit and at rest, strict tenant isolation checked on every query, UK and EU storage, and access limited to the few people who need it to run the service.
- We help with data subject requests - if a member of your staff writes to us, we pass it to you and assist.
- If a personal data breach affects your data, we tell you without undue delay after becoming aware of it, with what we know and what we are doing.
- When you leave, we delete your organisation's data on request, and in any case within 90 days - see the standard terms.
4. Sub-processors
We use a short list of carefully chosen services, published at /subprocessors with what each one does and where. You authorise that list. If we plan to add or change one, we email your admins at least 30 days first; if you object and we can't resolve it, you can end the agreement and we refund any unused part of a paid period. Every sub-processor is bound by terms at least as protective as these.
5. International transfers
Stored data stays in the UK and EU. The transient AI processing described in our privacy notice involves transfers to providers in the United States, covered by the UK International Data Transfer Agreement or EU standard contractual clauses, together with each provider's data processing terms - including their commitments not to retain or train on the data.
6. Showing our workings
We will answer reasonable written questions about how we protect your data and share summaries of relevant security measures and certifications. Where the law gives you an audit right, we will cooperate with an audit on reasonable notice, run so it doesn't put other organisations' data at risk.