CopytoneSign inScore a page

Legal

Data processing agreement

How Copytone handles the personal data in what your organisation uploads, in plain English. It covers what Article 28 of UK GDPR asks of a processor.

Last updated 16 September 2026

Who does what

Your organisation is the controller. It decides why and how the personal data in its uploads is used.

Copytone, run by [Owen to confirm: the legal name of the business that runs Copytone, any trading name, and its postal address], is the processor. We handle that data only to run Copytone for you, and only as this agreement and your instructions say.

For our own records about you, such as account and billing details, we are the controller. Our privacy policy covers those.

Questions about this agreement go to hello@copytone.co. [Owen to confirm: that hello@copytone.co is the address for privacy and data requests]

The processing

What it is for
Running Copytone for your organisation: reading your guides, preparing what your customers said, scoring your copy, writing suggestions and starting points, and keeping your team's work.
What we do with the data
Store it. Take identifying details out of customer exports. Count words. Sort what customers said by what they used, the point in their journey and how they felt. Send guides, lines of copy, and customer words with identifying details taken out, to our AI model provider. Show the results to your team in the studio. Delete it.
Whose data
Your customers and patients, in the reviews and comments you export. People named in your guides, emails and documents. The people on your team who use Copytone.
What kinds of data
Whatever your uploads hold. In customer exports that is usually names, contact details, order and reference numbers, and what people said about their experience. For your team, names, work email addresses, and a record of who made which change and when.
Special category data
Information about health, in reviews and comments. See Health data, below.
How long
For as long as your subscription runs, and until deletion at the end. Raw uploads are deleted [Owen to confirm: how many days after they arrive]. [Owen to confirm: how long the copy of each export with identifying details taken out is kept, now that the raw file is deleted as soon as it is read] [Owen to confirm: what is kept from uploaded emails and documents once the raw file is deleted]

Your instructions

We act only on your documented instructions. Our terms of service, this agreement, the settings you choose and what you ask Copytone to do are those instructions.

If we think an instruction breaks data protection law, we tell you. If a law requires us to process your data in some other way, we tell you before we do, unless that law forbids telling you.

Confidentiality

Only people who need access to run Copytone for you can reach your data. Each of them is bound to keep it confidential.

Security

We protect your data with measures that fit the risk, and health data carries more risk. The measures include:

  • Identifying details come out of customer exports on arrival, before anything else is done with them.
  • Raw uploads are deleted [Owen to confirm: how many days after they arrive].
  • Every connection to Copytone is encrypted.
  • Your studio is shown only to people signed in to your organisation's account.
  • Your data is kept apart from other customers' data.
  • Only people who need access can reach the server.
  • [Owen to confirm: whether there are backups, whether stored data and backups are encrypted, and how long deleted data can stay in a backup]

If we find a personal data breach that affects your data, we tell you without undue delay, with what we know, so you can meet your own duties.

Health data

Reviews of health services often mention health, which is special category data. Before your organisation uploads it, it must have a lawful basis and a condition under Article 9 of UK GDPR. [Owen to confirm with a lawyer: which condition under Article 9 of UK GDPR customers are expected to rely on when they upload health data]

Named health conditions from a set list come out on arrival, with the other identifying details. What we keep is counts of words, and some sentences, each kept apart from the review it came from, and only where nothing had to be taken out of it.

Automatic removal can miss things. So we protect everything we keep from your uploads as personal data until it is deleted, and we never try to find out who wrote a review.

If your organisation carries out a data protection impact assessment, we give you the information you need for it.

Sub-processors

You give us general permission to use the sub-processors listed on our sub-processors page.

Before we add or replace one, we give you [Owen to confirm: how many days of notice, and how customers are told], and you can object in that time. If we cannot resolve a reasonable objection, you can end your subscription.

Each sub-processor is bound by a written contract that puts the same data protection duties on it as this agreement puts on us. We remain responsible to you for its work.

Transfers outside the UK

Some sub-processors are based outside the UK, or handle data outside it. Before your data leaves the UK, a safeguard UK law allows is in place: a country the UK recognises as adequate, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

Anthropic's data processing addendum includes the UK Addendum. [Owen to confirm with a lawyer: the safeguard for each transfer out of the UK, including any transfer to the business that runs Copytone, which depends on where it is based]

People's requests about their data

If someone asks us to see, correct or delete their data in your uploads, we pass the request to you without undue delay. We do not answer it ourselves unless you tell us to.

We help you answer the requests people send you. Identifying details come out on arrival, so we often cannot link what we keep to one person. When that is the case, we tell you, so you can say so in your reply.

Helping with your other duties

When you need it, we give you the information we have to help you keep data secure, deal with a breach, carry out an impact assessment, or consult the Information Commissioner's Office.

At the end

When your subscription ends, you choose whether we return your data to you or delete it. Either way, we delete it [Owen to confirm: how many days after the subscription ends], unless the law requires us to keep it.

Audits

We give you the information you need to show that we keep to this agreement. We answer written questions first. If that is not enough, you, or an auditor you choose who is bound to confidentiality, may audit how we handle your data, with reasonable notice.

[Owen to confirm with a lawyer: how much notice an audit needs, how often one can happen, and who pays for it]

The full agreement

This page is a summary. [Owen to confirm with a lawyer: where the full data processing agreement is kept, how a customer accepts it, and whether this summary forms part of the terms]