This Data Processing Agreement (“DPA”) is incorporated into the Terms of Service between [Legal entity name] (“Processor”, “ParlioTec”) and the Customer (“Controller”), and reflects Article 28 of the UK GDPR and the Data Protection Act 2018.
1. Subject matter and duration
Processing of personal data about the Controller’s callers, contacts, customers and staff for the purpose of providing the ParlioTec Service, for the term of the Terms plus the deletion period in section 9.
2. Nature and purpose of processing
Answering and placing telephone calls; recording and transcribing calls where enabled; handling SMS, WhatsApp and web chat; extracting details the Controller asks for (e.g. name, number, address, problem); creating bookings, tickets and contact records; sending notifications and reminders; analytics and quality scoring; synchronising data to systems the Controller connects.
3. Categories of data subjects and data
- Data subjects: callers, message senders and website visitors of the Controller; the Controller’s customers, prospects, staff and team members.
- Data: voice recordings and transcripts; phone numbers and caller ID; names, addresses, email; appointment details; free-text descriptions of the caller’s request; message content; dashboard user details. Special-category data may be incidentally captured in speech (e.g. health details given by a caller); the Controller must set redaction and retention accordingly.
4. Controller instructions
The Processor processes personal data only on the Controller’s documented instructions, which are the Terms, this DPA, and the configuration the Controller sets in the dashboard (recording, consent wording, retention, redaction, integrations, outbound policies). The Processor will inform the Controller if an instruction appears to infringe data protection law.
5. Confidentiality and personnel
Staff with access to personal data are bound by confidentiality, trained, and access is role-based, two-factor protected and logged. Support access to a tenant’s data occurs only with the Controller’s permission and is recorded in the audit log the Controller can view.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest; per-tenant isolation enforced at the database layer (row-level security).
- UK-region hosting for compute, storage and recordings; optional UK-sovereign single-tenant deployment.
- Configurable PII redaction in transcripts and summaries; hosted payment links so card data is never processed by the assistant.
- Retention policies enforced automatically; export and erasure endpoints per data subject.
- Audit logging, vulnerability management, tested backups, incident response process.
7. Sub-processors
The Controller gives general authorisation to the sub-processors listed below. We will give at least 30 days’ notice of additions or replacements by email or dashboard announcement; the Controller may object on reasonable grounds and, if unresolved, terminate the affected service.
| Provider | Role | Location |
|---|---|---|
| [Cloud host, e.g. DigitalOcean / AWS] | Compute, database, backups | London, UK |
| Cloudflare | Content delivery, website hosting, object storage (recordings) | UK / EU with UK jurisdiction setting |
| Telnyx | Telephony carrier, SMS, numbers | UK / EU |
| LiveKit (self-hosted) | Real-time media | UK |
| Deepgram | Speech-to-text | [region] |
| OpenAI / Anthropic / [as configured] | Language model (no training on Customer Data) | [region] |
| Cartesia / ElevenLabs | Text-to-speech | [region] |
| Resend | Transactional email | [region] |
| Meta (WhatsApp Business) | WhatsApp channel, where enabled by Controller | Global |
| Stripe | Payments and billing | UK / EU / US |
Integrations the Controller connects itself (Google, Microsoft, ServiceM8, CRMs) are independent controllers/processors under the Controller’s own agreements with them.
8. International transfers
Personal data is hosted in the UK. Where a sub-processor processes data outside the UK, transfers rely on UK adequacy regulations or the UK IDTA / Addendum with supplementary measures. Controllers requiring no international transfers may select UK-only providers on Enterprise.
9. Deletion and return
The Controller can export data at any time. On termination the Controller has [30 days] to export, after which personal data is deleted from live systems within 30 days and from backups within [90 days], save where retention is required by law.
10. Assistance
The Processor will assist the Controller with data subject requests (through built-in export/erasure tools), DPIAs, and consultations with the ICO, and will make available information needed to demonstrate compliance, including permitting audits on reasonable notice no more than once a year, or on a regulator’s request.
11. Personal data breaches
The Processor will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, with the information the Controller needs to meet its own 72-hour obligation.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Terms. In case of conflict, this DPA prevails over the Terms with respect to data protection.
Signature
This DPA is accepted electronically when the Controller accepts the Terms. A countersigned copy is available on request from [[email protected]].
