Privacy protection starts with clear roles, limited instructions, and accurate data flows.
Ask Bennett is an AI-powered website and voice assistant. Depending on the features a Customer enables, the service may receive website visitor questions, caller audio, chat messages, transcripts, contact details, appointment information, technical logs, and information retrieved from the Customer’s approved website and connected systems. This Addendum governs that processing when Ask Bennett acts for the Customer.
Purpose, Incorporation, and Order of Priority
This Data Processing Addendum (“DPA”) is between Ask Bennett (“Ask Bennett,” “we,” “us,” or “our”), and the business or organization that accepts an order, checkout record, Service Agreement, or Terms of Service for Ask Bennett (“Customer,” “you,” or “your”).
This DPA is incorporated into the Agreement whenever Ask Bennett processes Customer Personal Data as a processor, service provider, contractor, or comparable role under applicable Data Protection Law. It applies automatically without a separate signature when the Customer accepts the Agreement or uses the service.
If this DPA conflicts with the Agreement concerning Customer Personal Data, this DPA controls. The EU Standard Contractual Clauses or a mandatory local transfer instrument controls over this DPA to the extent of a direct conflict. An order controls only if it expressly identifies the provision of this DPA that it replaces and is signed by authorized representatives of both parties.
Definitions
“Customer Personal Data” means Personal Data processed by Ask Bennett on behalf of Customer through the service. “Personal Data” includes personal information, personal data, and any equivalent term under applicable Data Protection Law. “Processing,” “Controller,” “Processor,” “Business,” “Service Provider,” “Contractor,” “Consumer,” and “Data Subject” have the meanings assigned by applicable law.
“Data Protection Law” means every privacy, data protection, breach-notification, and cross-border-transfer law applicable to the Processing, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, California Consumer Privacy Act as amended, other comprehensive U.S. state privacy laws, Canada’s PIPEDA and substantially similar provincial laws, Australia’s Privacy Act 1988 and Australian Privacy Principles, and New Zealand’s Privacy Act 2020.
“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Ask Bennett. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data, such as blocked attacks, pings, scans, or failed login attempts.
“Subprocessor” means a third party engaged by Ask Bennett to process Customer Personal Data for the service. “Restricted Transfer” means a transfer requiring an approved transfer mechanism under applicable Data Protection Law.
Roles and Scope of Processing
Customer determines the purposes and essential means of Processing Customer Personal Data and acts as the Controller, Business, or equivalent principal. Ask Bennett acts as the Processor, Service Provider, Contractor, or equivalent agent for that Processing.
If Customer processes Personal Data for another organization, Customer may be a Processor and Ask Bennett a Subprocessor. Customer represents that it is authorized to appoint Ask Bennett and that its instructions are consistent with the instructions of the relevant Controller.
Ask Bennett does not determine the Customer’s legal basis, privacy notices, recording notices, consent design, data categories, source content, retention choices, audience, or lawful use of Output. Those decisions remain with Customer. Ask Bennett will not assume a Controller role merely because it makes routine technical, security, operational, or product decisions needed to provide the service.
Documented Instructions and Purpose Limitation
Ask Bennett will process Customer Personal Data only on documented instructions from Customer, including the Agreement, order, account settings, enabled integrations, support requests, source materials, and other written directions accepted by Ask Bennett.
Ask Bennett may process Customer Personal Data to configure and provide Bennett; answer or route end-user questions; transcribe or process voice interactions when enabled; schedule appointments; transfer calls; operate integrations; secure, troubleshoot, support, and maintain the service; prevent fraud and abuse; and comply with law.
If Ask Bennett believes an instruction violates Data Protection Law, it may suspend the affected Processing and inform Customer unless prohibited by law. Customer remains responsible for revising unlawful instructions. Ask Bennett is not required to provide legal advice or independently investigate the Customer’s compliance basis.
Customer Responsibilities and Lawful Basis
Customer is responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of Customer Personal Data and the instructions it gives. Customer must have every required legal basis, notice, consent, authorization, and permission before collecting or directing Ask Bennett to process Personal Data.
Customer must provide legally sufficient privacy, AI, recording, transcription, telephone, cookie, and indirect-collection notices; honor opt-outs and consent withdrawals; avoid collecting unnecessary data; maintain accurate website and source content; and configure retention and access consistent with its obligations.
Customer must not direct Ask Bennett to process Personal Data in a manner that violates law, third-party rights, platform rules, or the Acceptable Use Policy. Customer is responsible for responding to regulators and individuals concerning the Customer’s decisions and for determining whether a privacy impact assessment, consent, representative, local registration, or data-protection officer is required.
Personnel Confidentiality and Access
Ask Bennett will limit access to Customer Personal Data to personnel and contractors who need access to provide, secure, support, or maintain the service. Those persons will be subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
Ask Bennett will use role-appropriate access controls and will revoke or adjust access when it is no longer reasonably required. Customer is responsible for its own administrators, users, credentials, connected accounts, and internal access decisions.
Security Measures
Taking into account the nature, scope, context, and purposes of Processing, the state of the art, implementation costs, and risks to individuals, Ask Bennett will maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against Security Incidents.
The measures may include access controls, credential protection, encryption or equivalent protections where appropriate and supported, logging, monitoring, backups, recovery procedures, vulnerability and patch management, secure configuration, vendor review, personnel confidentiality, incident response, and data-retention controls. Annex II describes the categories of measures applicable to the service.
No system is completely secure. The measures are risk-based and may evolve without materially reducing the overall protection of Customer Personal Data. Customer is responsible for secure endpoints, browsers, networks, credentials, permissions, source systems, integrations, and the security of data after it is exported from the service.
Personal Data Breach Notification and Cooperation
Ask Bennett will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notification may be delivered to the account owner, security contact, privacy contact, or other contact designated by Customer.
To the extent reasonably available, the notice will describe the nature of the incident, affected data and individuals, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be provided in phases as the investigation develops.
Ask Bennett will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will reasonably assist Customer with legally required notifications. Customer is responsible for deciding whether notice to individuals, regulators, customers, insurers, or others is required and for the timing and content of those notices. Ask Bennett’s notification is not an admission of fault or liability.
Individual Rights and Customer Requests
Taking into account the nature of the Processing, Ask Bennett will provide reasonable assistance through available product features, exports, deletion tools, or support so Customer can respond to valid requests for access, correction, deletion, portability, restriction, objection, opt-out, or appeal.
If Ask Bennett receives a request directly from an individual concerning Customer Personal Data, Ask Bennett may direct the individual to Customer and will not substantively respond unless Customer instructs it, the law requires a response, or doing so is necessary to verify and route the request.
Customer is responsible for verifying requesters, interpreting exceptions, meeting statutory deadlines, maintaining request records, and communicating the final response. Ask Bennett may charge reasonable fees for unusually burdensome, repetitive, or custom assistance not included in the service, where permitted by law.
Privacy Assessments, Consultations, and Regulatory Assistance
Ask Bennett will provide information reasonably available to it that Customer needs to conduct a data protection impact assessment, risk assessment, transfer assessment, or prior consultation relating specifically to Customer’s use of the service.
Customer remains responsible for determining whether an assessment or consultation is required, documenting its decisions, and evaluating the Customer’s broader systems, data sources, notices, legal bases, and uses. Assistance beyond standard documentation or reasonable support may be subject to a separate written scope and fee.
Government, Law-Enforcement, and Compelled Requests
Ask Bennett may disclose Customer Personal Data when required by valid law, legal process, or binding governmental demand. Unless prohibited, Ask Bennett will notify Customer before disclosure so Customer may seek protection or object.
Where reasonably appropriate, Ask Bennett will review the legal validity of a demand, seek clarification or narrowing, disclose only data legally required, and document the request. Ask Bennett is not required to pursue litigation, violate law, or risk penalties on Customer’s behalf.
Subprocessors and General Authorization
Customer gives Ask Bennett general written authorization to engage Subprocessors needed to provide, host, secure, support, communicate, transcribe, integrate, analyze, or maintain the service. Subprocessors may include platform, cloud, hosting, AI-model, communications, telephony, transcription, email, analytics, storage, security, and support providers.
Ask Bennett will impose written data-protection obligations on each Subprocessor that are materially consistent with the obligations applicable to Ask Bennett for the relevant Processing. Ask Bennett remains responsible for the Subprocessor’s performance of those obligations to the extent required by applicable law and the Agreement.
Ask Bennett will maintain an up-to-date Subprocessor list or other reasonable disclosure mechanism identifying material Subprocessors and their processing functions. Customer is responsible for subscribing to or monitoring the designated notice channel and keeping its contact information current.
Notice of Changes and Subprocessor Objections
Ask Bennett will provide reasonable advance notice of a new material Subprocessor where required by law, ordinarily through email, account notice, service documentation, or the published Subprocessor list.
Customer may object within fifteen days after notice by sending a detailed written explanation of the specific data-protection concern. The parties will work in good faith to address the concern through available configuration, a commercially reasonable alternative, or additional safeguards.
If no reasonable solution is available and the objection is based on a genuine data-protection risk, Customer may stop the affected Processing or terminate the affected service before the new Subprocessor begins Processing. That termination is Customer’s sole remedy for the objection and does not relieve Customer of fees already incurred or other amounts due, except where mandatory law provides otherwise.
International Processing and Restricted Transfers
Customer Personal Data may be processed in the United States and in other countries where Ask Bennett or its Subprocessors operate. Customer authorizes those transfers, subject to this DPA and any legally required transfer mechanism.
Ask Bennett will not rely solely on this authorization where Data Protection Law requires additional safeguards. For a Restricted Transfer, the parties will use the applicable adequacy decision, Standard Contractual Clauses, UK Addendum, approved contractual clauses, consent, certification, or other lawful mechanism.
Customer is responsible for identifying the origin of Customer Personal Data, providing required transfer notices, and completing any Customer-specific transfer risk or impact assessment. Ask Bennett will provide reasonably available information about the service and relevant safeguards.
European Union and EEA Standard Contractual Clauses
For a Restricted Transfer of Customer Personal Data governed by the EU GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 (“EU SCCs”) as follows:
- Module Two applies when Customer is a Controller and Ask Bennett is a Processor.
- Module Three applies when Customer is a Processor and Ask Bennett is a Subprocessor.
- Clause 7, the docking clause, applies.
- For Clause 9, Option 2 general written authorization applies, with notice under Sections 12 and 13 of this DPA.
- The optional language in Clause 11 does not apply.
- For Clause 17, the governing law is the law of Ireland, and for Clause 18 the courts of Ireland have jurisdiction, unless another EU Member State is required or expressly selected in a signed order.
- Annexes I through III are completed by the Agreement, the applicable order, and Annexes I through III of this DPA.
If the EU SCCs require additional supplementary measures after a transfer assessment, the parties will reasonably cooperate to implement proportionate measures. If no lawful transfer mechanism is available, Ask Bennett may suspend the affected Processing or Customer may discontinue the affected service.
United Kingdom Restricted Transfers
For a Restricted Transfer governed by the UK GDPR, the parties incorporate the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (“UK Addendum”).
The tables and appendices of the UK Addendum are completed by reference to the parties, Modules, selections, Processing details, security measures, and Subprocessor information in the Agreement and this DPA. If the UK Addendum cannot lawfully be used, the parties will use the UK International Data Transfer Agreement or another valid safeguard.
Nothing in this DPA limits the powers of the Information Commissioner or the rights of UK Data Subjects. Customer remains responsible for determining whether its transfer is restricted and for completing any required transfer risk assessment.
Comprehensive U.S. State Privacy Laws
To the extent a comprehensive U.S. state privacy law applies and Customer is a Controller, Ask Bennett is a Processor for Customer Personal Data. Ask Bennett will:
- process data only under Customer’s instructions and for the limited purposes described in the Agreement;
- ensure persons processing data are subject to confidentiality;
- use reasonable security measures appropriate to the data and risk;
- assist Customer with consumer rights, security obligations, breach response, and legally required assessments;
- delete or return data at the end of the service as provided in this DPA;
- engage Subprocessors under written obligations that provide an appropriate level of protection; and
- make information reasonably necessary to demonstrate compliance available to Customer.
If Ask Bennett determines the purposes and means of a Processing activity outside Customer’s instructions, Ask Bennett will be treated as a Controller for that activity to the extent required by law.
California Service Provider and Contractor Terms
For Customer Personal Data subject to the California Consumer Privacy Act, Ask Bennett acts as a Service Provider or Contractor and receives the data only for the specific business purposes described in the Agreement.
Ask Bennett will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship with Customer or for purposes other than the specified business purposes; or combine it with Personal Data received from another person or collected from Ask Bennett’s own interaction with a consumer, except as permitted by the CCPA and its regulations.
Ask Bennett will provide the same level of privacy protection required by the CCPA, cooperate with consumer requests and compliance duties, notify Customer if Ask Bennett determines it can no longer meet its obligations, and allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized Processing.
Customer may monitor Ask Bennett’s compliance through the audit and documentation process in this DPA. Ask Bennett certifies that it understands and will comply with these restrictions. Customer discloses Customer Personal Data to Ask Bennett for a business purpose and not for monetary or other valuable consideration.
Canadian Processing and Outsourcing
Where Canadian privacy law applies, Customer remains accountable for Customer Personal Data transferred to Ask Bennett for processing. Ask Bennett will use contractual and organizational safeguards intended to provide a level of protection comparable to that required of Customer for the relevant Processing.
Ask Bennett will process Customer Personal Data only for the identified service purposes, limit access, protect the data with safeguards appropriate to sensitivity, assist with access and correction requests, and notify Customer of Security Incidents without undue delay.
Customer is responsible for meaningful notice and consent, identifying foreign processing where required, responding to individuals and regulators, evaluating provincial requirements, and determining whether data may be processed outside Canada.
Australian Privacy Act and Cross-Border Disclosures
Where the Australian Privacy Act 1988 applies, Ask Bennett will handle Customer Personal Data consistently with the Processing instructions and safeguards in this DPA. Customer is responsible for determining whether its disclosure to Ask Bennett is an overseas disclosure under Australian Privacy Principle 8 and for taking reasonable steps required by law.
Ask Bennett will reasonably assist Customer with information about processing locations, safeguards, access, correction, deletion, and Security Incidents. Customer is responsible for APP notices, collection necessity, consent for sensitive information, overseas-recipient disclosures, and notifications under the Notifiable Data Breaches scheme.
Nothing in this DPA transfers to Ask Bennett the Customer’s statutory accountability for an overseas recipient where Australian law places that accountability on Customer.
New Zealand Privacy Act 2020
Where New Zealand privacy law applies, Ask Bennett will process Customer Personal Data only for the authorized service purposes and under safeguards intended to support Customer’s obligations, including obligations concerning access, correction, security, retention, and notifiable privacy breaches.
Customer is responsible for determining whether Information Privacy Principle 12 applies to an overseas disclosure and for ensuring a lawful basis and comparable safeguards. Customer is also responsible for direct and indirect collection notices, including any notice required when Ask Bennett receives Personal Data from Customer rather than directly from the individual.
Ask Bennett will provide reasonable assistance so Customer can locate, retrieve, correct, export, or delete Customer Personal Data within applicable statutory timeframes.
Retention, Return, Export, and Deletion
Ask Bennett will retain Customer Personal Data only for the service term and a limited period afterward as reasonably necessary to provide exports, complete deletion, maintain backups, resolve disputes, prevent fraud, enforce the Agreement, or comply with law.
During the service term, Customer may use available features to access, export, correct, or delete data. Following termination or a valid written instruction, Ask Bennett will delete or return Customer Personal Data within a commercially reasonable period, unless retention is required by law or technically necessary in secure backups.
Backup copies may remain until overwritten under standard cycles and will remain protected and unavailable for ordinary business use. Ask Bennett may retain minimal records necessary to demonstrate compliance, document instructions, maintain suppression or deletion records, protect legal rights, and satisfy financial or security obligations.
Compliance Information, Audits, and Inspections
Ask Bennett will make available information reasonably necessary to demonstrate compliance with this DPA, which may include policies, security summaries, questionnaires, certifications, independent reports, or other appropriate evidence.
Customer may request an audit no more than once in any twelve-month period, unless a regulator requires more frequent review or a confirmed Security Incident creates a reasonable need. Customer must provide at least thirty days’ notice, keep information confidential, avoid unreasonable disruption, and use a qualified independent auditor that is not a competitor.
On-site inspection is available only when documentation is insufficient to satisfy a specific legal requirement and must be narrowly scoped. Customer bears its audit costs and Ask Bennett’s reasonable assistance costs unless the audit identifies a material breach by Ask Bennett. No audit may expose another customer’s data, security secrets, privileged material, or information restricted by law or provider obligations.
Ask Bennett’s Independent-Controller Processing
This DPA does not apply when Ask Bennett independently determines the purposes and means of Processing. Ask Bennett may act as an independent Controller for business contact information, account ownership records, billing and transaction metadata, service communications, fraud prevention, security logs, abuse investigations, legal compliance, dispute records, and website analytics.
Independent-controller Processing is governed by the Privacy Policy and applicable law. Ask Bennett will not use this section to convert Customer interaction content into independent data for unrelated advertising, sale, sharing, or generalized AI-model training.
Sensitive, Regulated, and Restricted Data
Unless Ask Bennett expressly approves the Processing in a signed written addendum, Customer must not submit or direct Ask Bennett to collect protected health information, full payment-card data, bank-account credentials, government identification numbers, authentication secrets, biometric templates, precise geolocation, criminal-history records, children’s data, or other highly sensitive or specially regulated information.
Voice audio and transcripts may be Personal Data. Ask Bennett does not create or use a biometric voiceprint to identify an individual unless separately agreed, technically enabled, lawfully authorized, and specifically disclosed.
If Customer submits restricted data without authorization, Customer does so contrary to the Agreement and remains responsible for all legal duties and resulting risk. Ask Bennett may suspend Processing, delete the data, require additional terms, or terminate the affected feature.
Deidentified Data, Service Metrics, and AI Training
Ask Bennett may create and use aggregated or deidentified service metrics that cannot reasonably identify Customer or an individual for security, capacity planning, billing verification, reliability, fraud prevention, and service analytics. Ask Bennett will not attempt to reidentify data that is maintained as deidentified, except to test whether deidentification remains effective where permitted by law.
Ask Bennett will not use Customer Personal Data to train a generalized AI model for Ask Bennett’s independent purposes unless Customer expressly authorizes that use in writing after receiving a clear description of the purpose, data, retention, and available controls.
Customer acknowledges that underlying providers may process limited technical or interaction data under their agreements with Ask Bennett. Ask Bennett will contractually restrict Subprocessors consistent with this DPA and will disclose material provider categories through its Subprocessor process.
Liability, Indemnity, and Agreement Terms
Each party remains responsible for its own compliance duties and for damages caused by its breach to the extent provided by applicable law. The disclaimers, exclusions, liability cap, indemnification, dispute, governing-law, and remedy provisions in the Agreement apply to this DPA and all claims relating to Processing.
Nothing in this DPA limits a regulator’s authority, an individual’s nonwaivable rights, or liability that cannot lawfully be limited. The parties do not create an unlimited contractual liability merely because privacy law may impose separate statutory liability.
Term, Suspension, and Survival
This DPA begins when Ask Bennett first processes Customer Personal Data and continues until that Processing ends. Ask Bennett may suspend Processing that creates an immediate security risk, violates law, exceeds Customer’s instructions, or breaches the Agreement.
Confidentiality, restricted-use, security, deletion, transfer, audit, liability, and other provisions that by their nature should continue will survive termination for as long as Ask Bennett retains Customer Personal Data.
Details of Processing
Subject matter
Provision of Ask Bennett’s AI-powered website, chat, and voice-assistant services, including configuration, retrieval from Customer-approved source content, end-user interactions, call or chat routing, appointment functions, integrations, support, security, and related operations.
Duration
The term of the service plus the limited retention and deletion period described in Section 22, subject to legal holds, backup cycles, and required records.
Nature and operations
Collection, receipt, recording when enabled, transmission, organization, storage, retrieval, consultation, analysis, transcription, generation of responses, routing, appointment processing, support access, security monitoring, export, restriction, erasure, and destruction.
Purposes
To provide and support Bennett; respond to website visitors and callers; use Customer-approved website and business information; route questions, calls, or appointments; operate integrations; secure and troubleshoot the service; prevent abuse; and comply with documented lawful instructions.
Categories of Data Subjects
Customer administrators, employees, contractors, representatives, website visitors, callers, prospects, customers, appointment participants, contacts in connected systems, and other persons whose Personal Data Customer makes available.
Categories of Personal Data
Names; business and personal contact details; voice audio when enabled; chat messages; transcripts; questions and responses; appointment details; call routing data; business communications; website interaction data; device, browser, network, and log data; account identifiers; integration data; and Personal Data contained in Customer-approved source content.
Sensitive Data
Not intentionally required for the standard service. Customer must not provide sensitive or specially regulated data except under a separately signed addendum and lawful configuration.
Frequency
Continuous or event-driven, depending on end-user interactions, Customer settings, and enabled features.
Categories of Technical and Organizational Measures
Governance and confidentiality
Documented responsibilities, confidentiality obligations, access approval, workforce awareness, provider review, and incident-response procedures proportionate to the service.
Identity and access
Role-based or need-to-know access, unique credentials where supported, password controls, administrative permission management, account termination procedures, and multi-factor authentication where available and appropriate.
Data transmission and storage
Encryption in transit using industry-standard protocols and encryption, tokenization, access controls, or equivalent protection for stored data where appropriate and supported by the relevant platform.
Logging, monitoring, and security response
Operational or security logging, monitoring for suspicious activity where available, escalation procedures, incident investigation, containment, remediation, and lessons-learned review.
Availability and recovery
Resilience measures, backups or provider redundancy where appropriate, restoration procedures, and continuity planning designed for the service’s risk and dependency profile.
Vulnerability and change management
Reasonable patching, configuration management, provider updates, vulnerability remediation, testing, and change review appropriate to the components controlled by Ask Bennett.
Data minimization and retention
Purpose limitation, configurable collection where available, restricted administrative access, retention controls, deletion workflows, and secure disposal or overwrite processes.
Subprocessor management
Risk-based review, written data-protection obligations, security and confidentiality requirements, transfer safeguards, and change-notice procedures.
Customer controls
Account permissions, source-content selection, enabled features, integration choices, recording settings where available, exports, deletions, and other product controls. Customer is responsible for configuring and using those controls lawfully.
Transfer and Party Details
Data exporter
The Customer identified in the applicable order, checkout record, invoice, account, or signature block. Customer’s activities are described in its business records and its use of Ask Bennett. Customer contact details are those maintained in the account.
Data importer
Ask Bennett, United States. Privacy contact: [email protected]. Telephone: (888) 515-8088. The complete legal notice address must be stated in the applicable order or legal notice before the parties rely on the EU SCCs or UK Addendum.
Roles and transfer
Customer is the Controller or Processor. Ask Bennett is the Processor or Subprocessor. Transfers may occur continuously or as end users interact with the service. The Processing categories and security measures are described in Annexes I and II.
Competent supervisory authority
The authority determined under Clause 13 of the EU SCCs based on the Customer’s establishment, representative, or affected Data Subjects. For UK transfers, the Information Commissioner is the competent authority where the UK GDPR applies.
Subprocessors
Material Subprocessors are identified through Ask Bennett’s current Subprocessor list or designated disclosure mechanism. Customer grants general authorization subject to Sections 12 and 13.
Privacy, Security, and DPA Contact
Questions about this DPA, security documentation, Subprocessors, transfer mechanisms, deletion, or privacy assistance may be sent to:
Ask Bennett
United States
Email: [email protected]
Phone: (888) 515-8088
Use the subject “Data Processing Addendum,” “Security Request,” “Subprocessor Question,” or “Privacy Assistance.” Include the business name, account email, website, and enough information to identify the relevant service. Do not email passwords, full payment credentials, private keys, or unnecessary sensitive information.