LEGAL · DPA

Data Processing Agreement.


Last updated: 3 June 2026.

This Data Processing Agreement (“DPA”) forms part of the agreement between Every Call Handled (“we”, “us”, the “Processor”) and the customer (“you”, the “Controller”) for use of our AI receptionist service (the “Service”). It sets out the terms required by Article 28 of the UK GDPR and EU GDPR. A counter-signable copy is available on request - email hello@everycallhandled.com.

1. Roles of the parties

For personal data relating to your callers that we process to deliver the Service (caller ID, names, call recordings, transcripts, and enquiry details), you are the Controller and we are the Processor. We process that data only to provide the Service and only on your documented instructions, including those set out in this DPA and in your use of the Service.

2. Subject matter, duration, nature and purpose

  • Subject matter: processing of caller personal data to operate an AI receptionist on your behalf.
  • Duration: for the term of your subscription and any retention period set out below.
  • Nature and purpose: answering calls, conversing with callers, capturing enquiry details, generating transcripts and summaries, and delivering those to you.

3. Personal data and data subjects

  • Categories of data subjects: your callers and contacts.
  • Types of personal data: phone number (caller ID), name where provided, call audio, transcripts, and any details the caller chooses to share during the call.
  • You must not use the Service to capture special category data unless you have a lawful basis and have configured the Service appropriately.

4. Our obligations as Processor

  • process personal data only on your documented instructions, unless required by law (in which case we will inform you unless legally prohibited);
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (see clause 6);
  • assist you, taking account of the nature of processing, in responding to data subject requests and in meeting your obligations under Articles 32 to 36 (security, breach notification, and data protection impact assessments);
  • make available the information reasonably necessary to demonstrate compliance with Article 28.

5. Sub-processors

You provide general authorisation for us to engage the sub-processors needed to run the Service:

  • Amazon Web Services - cloud hosting and storage
  • Twilio - telephony and call handling
  • OpenAI, Anthropic, and Google - AI conversation processing
  • Cartesia - speech (text-to-speech) synthesis
  • Stripe - payment processing
  • Email and messaging providers - to deliver summaries and notifications

Each sub-processor is bound by data protection terms no less protective than this DPA. We will give you reasonable notice of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable data protection grounds.

6. Security and data subject requests

We apply encryption in transit and at rest, access controls and authentication, and regular review, consistent with Article 32. Where we receive a request directly from one of your callers to exercise their rights, we will promptly inform you and will not respond ourselves except on your instruction, unless legally required to do so.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information you reasonably need to meet your own notification obligations to regulators and data subjects.

8. Return and deletion

On termination of the Service, and subject to the retention periods below, we will delete or return your caller personal data at your choice, and delete existing copies unless retention is required by law. By default, call recordings are deleted after a maximum of 30 days; this can be configured down, including to no retention.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency.

10. International transfers

Where personal data is transferred outside the UK/EEA, we ensure an appropriate safeguard is in place - typically the UK International Data Transfer Addendum or the EU Standard Contractual Clauses - together with additional measures such as encryption.

11. Putting this DPA in place

These terms apply automatically when you use the Service to process caller personal data. If your organisation requires a signed copy or a bespoke addendum, contact hello@everycallhandled.com and we will provide one.