Document Change Log
Version 1.0 - Effective 2026-07-08 - Change log
Template document: review by a qualified data-protection lawyer or DPO before commercial reliance. Not legal advice.
This page is the canonical record of changes to Amaigo's legal and compliance documents, including changes to our sub-processor list. See the Subprocessor Change Notification Policy for how we notify clients of sub-processor changes.
How versioning works
- Every document carries a version number and effective date in its header.
- Major versions (1.0 to 2.0) mark substantive legal changes: new obligations, changed commitments, new data flows.
- Minor versions (2.0 to 2.1) mark clarifications and corrections that do not change the legal substance.
- Prior versions are retained in our records and are available on request at hello@amaigo.com.
- The
consentPolicyVersionrecorded against each lead references the version of the Consent Notice in force when consent was given.
Sub-processor changes
| Date | Change | Notice given |
|---|---|---|
| 2026-07-11 | SMS provider named: Bird (MessageBird B.V., Netherlands) for appointment confirmation and reminder texts; still conditional on the client enabling SMS, disabled by default. | n/a (no active clients at the change date) |
| 2026-07-11 | Cal.com removed (booking now writes directly into the client's own Microsoft 365 / Google Workspace calendar, where Microsoft/Google act as the client's own processors). Resend/Postmark replaced by Google Workspace for lead alert emails. | n/a (no active clients at the change date) |
| 2026-07-07 | Baseline list published (see Sub-processors) | n/a (initial publication) |
Document history
| Document | Version | Effective | Summary of changes |
|---|---|---|---|
| AI Transparency Notice | 1.5 | 2026-08-27 | Voice (Aura, early access) added: spoken AI disclosure at the start of every answered call with an automatic append when a custom greeting omits it; no call recording, live transcription only with the text conversation under the existing transcript and retention rules; European telephony and speech providers to be named on the sub-processor list before launch. |
| Consent Notice | 2.4 | 2026-07-19 | AI-disclosure description corrected: the persistent "AI assistant" label lives in the conversation header (shown before any message can be typed); the home panel is navigation only and carries no label. Consent statement wording unchanged; the widget consent line now also shows the documented "Stored securely in the EU." sentence. |
| AI Transparency Notice | 1.4 | 2026-07-19 | Same correction: label described as conversation-header only, with the Article 50 before-first-interaction reasoning stated explicitly. |
| Privacy Policy | 2.2 | 2026-07-18 | Corrected the description of the self-serve data rights portal: requests are email-verified and executed immediately by Amaigo on the controller's documented instructions (Art. 28(3)(e)), with audit trail and third-party-name withholding, rather than "routed to the controller". |
| DSAR Procedure | 2.1 | 2026-07-18 | Documented the self-serve portal as an agreed standing-instruction exception to the assist-the-controller flow. |
| Cookie Notice | 2.2 | 2026-07-18 | Storage-key inventory corrected: removed the never-shipped teaser-dismissed key; added the two sessionStorage flags (auto-open once per session, one anonymous "opened" count per session); noted the in-widget "Delete my data from this device" control. |
| AI Transparency Notice | 1.3 | 2026-07-18 | Audit-record retention corrected to "at least 13 months (configurable, never below 6 months)" to match the enforced purge; audit metadata described as pseudonymised rather than "no personal data". |
| Security Overview | 2.2 | 2026-07-18 | Audit-log description corrected to pseudonymised technical metadata (salted IP/operator-email hashes); bot-mitigation line updated for the widget-rendered Turnstile challenge. |
| Security Questionnaire | 1.2 | 2026-07-18 | Q29 audit-trail answer corrected to the pseudonymised-metadata description with the 13-month purge bound. |
| Data Retention Policy | 2.1 | 2026-07-18 | Audit-log row corrected: pseudonymised metadata, purged after at least 13 months (previously described as containing no personal data and retained indefinitely). |
| Data Processing Agreement | 2.1 | 2026-07-18 | Annex B item 8 (audit logging) corrected to the pseudonymised-metadata description with bounded retention. Minor correction only; no change to obligations. |
| Privacy Policy | 2.1 | 2026-07-13 | Your rights section now points to the self-service data rights portal for export and erasure, in addition to the email route. No change to lawful bases or data flows. |
| Cookie Notice | 2.1 | 2026-07-13 | Documented the 72-hour hard ceiling on conversation storage regardless of a site's persistHours setting, and linked the data rights portal. |
| AI Transparency Notice | 1.2 | 2026-07-12 | New human oversight and decision logging section: every AI-proposed outcome audit-logged (ai_outcome_recorded), dashboard outcome override with audited before/after values (outcome_overridden), all leads visible including disqualified. |
| Consent Notice | 2.3 | 2026-07-12 | Follow-up section updated for multi-touch: up to three configurable service emails (default one) within 7 days, spaced 48 hours apart by default, final message always marked as the last. |
| Consent Notice | 2.2 | 2026-07-11 | New section: one-off service follow-up email for leads who left contact details but did not book (at most once, within 7 days, no marketing content, recorded against the lead and audit log). |
| Sub-processors | 3.1 | 2026-07-11 | SMS provider named as Bird (MessageBird B.V.); SMS row extended to confirmations as well as reminders. Clarified that follow-up and report emails ride the existing Google Workspace row. |
| Sub-processors | 3.0 | 2026-07-11 | Cal.com removed: booking is now a direct integration into the client's own calendar (Microsoft/Google act as the client's own processors, not Amaigo sub-processors). Lead alert email moved from Resend/Postmark to Amaigo's own Google Workspace. |
| Security Overview | 2.1 | 2026-07-11 | Hosting map updated: booking via direct client-calendar integration, lead alerts via Google Workspace. |
| Security Questionnaire | 1.1 | 2026-07-11 | Q8 hosting answer updated for the direct calendar integration and Google Workspace email. |
| Consent Notice | 2.1 | 2026-07-11 | Updated to the conversational capture flow: submission-as-consent statement beneath the input, marketing opt-in at the email step, and the shipped persistent AI label and pinned disclosure line. |
| AI Transparency Notice | 1.1 | 2026-07-11 | AI disclosure section updated to present tense: the persistent "AI assistant" label and pinned pre-input disclosure line are now shipped in the widget. |
| Privacy Policy | 2.0 | 2026-07-08 | Dual EU GDPR and UK GDPR coverage, per-purpose lawful-bases table, AI processing section, DPF plus SCC-fallback transfers, ICO and EU complaint routes, honest DPO statement. |
| Cookie Notice | 2.0 | 2026-07-08 | UK PECR and EU ePrivacy dual references, strictly-necessary exemption reasoning, every widget localStorage key listed with purpose and lifetime. |
| Data Processing Agreement | 2.0 | 2026-07-08 | Full Article 28(3)(a)-(h) rewrite: auto-incorporation, chapeau table, 30-day sub-processor notice with objection and pro-rata refund, 48-hour breach notice, audit clause, Annexes A-D including quantified TOMs and the UK Addendum. |
| Sub-processors | 2.0 | 2026-07-08 | Five-column register with data categories and transfer mechanisms, AI providers flagged with a no-training line, on-page notice and subscription regime. |
| Terms of Service | 2.0 | 2026-07-08 | Incorporation-by-reference framework with precedence clause, AI service terms including Article 50 disclosure duties, no-automated-rejection design commitment, change-notice process. Commercial terms unchanged. |
| Security Overview | 2.0 | 2026-07-08 | Named hosting map, key and secret management, honest certification roadmap, pointer to the pre-answered security questionnaire. |
| Data Retention Policy | 2.0 | 2026-07-08 | Per-record-type retention table including backups and browser storage, 90-180 day recommendation for non-engaged sensitive intake. |
| Data Subject Requests | 2.0 | 2026-07-08 | Dual timelines, controller-versus-processor routing table, real export and erasure endpoints, 5-business-day processor assistance commitment. |
| Breach Response | 2.0 | 2026-07-08 | Operational runbook with severity classes, forensics phase, 48-hour controller notification commitment, controller reminder table. |
| DPIA Template | 2.0 | 2026-07-08 | ICO screening block and a pre-filled AI-specific risk table with Whistle mitigations and the automated-decision-making design position. |
| Records of Processing (ROPA) | 2.0 | 2026-07-08 | Two pre-filled Article 30 records (processor and controller capacities) with a dual-jurisdiction note. |
| Consent Notice | 2.0 | 2026-07-08 | Rewritten to match the shipped widget exactly: tier 1 submission-as-consent card, tier 2 required checkbox with separate marketing opt-in, honest AI-disclosure description. |
| AI Transparency Notice | 1.0 | 2026-07-08 | New: AI disclosure under EU AI Act Article 50, redaction-first data flow, provider no-training terms, confidentiality and privilege positioning for law firms, ethics vetting map. |
| Acceptable Use Policy | 1.0 | 2026-07-08 | New: general and AI-specific prohibitions keeping deployments outside high-risk EU AI Act territory. |
| Service Level Agreement | 1.0 | 2026-07-08 | New: 99.5% monthly availability target, exclusions, single-tier 10% credit, chronic-failure termination right. |
| Subprocessor Change Notification Policy | 1.0 | 2026-07-08 | New: 30-day advance email notice, notice contents, objection procedure, emergency replacement rules. |
| Transfer Risk Assessment | 1.0 | 2026-07-08 | New: six-step EDPB template pre-filled for the AI sub-processor transfer with completion fields. |
| Security Questionnaire | 1.0 | 2026-07-08 | New: about 43 pre-answered due-diligence questions mapped to legal-ethics vendor vetting. |
| Client Onboarding SOP | 1.0 | 2026-07-08 | New: the eight-step compliance onboarding procedure mirroring the generated client pack. |
| All documents | 1.0 | 2026-07-01 | Initial GDPR-aligned template set published. |
This document is a GDPR-aligned template and must be reviewed by a qualified data-protection lawyer or DPO before commercial reliance. It is not legal advice.