This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service or other written agreement between CallGuard AI Ltd, a company registered in England and Wales (company number 17279006, registered office at 106 Haytor Avenue, Paignton, England, TQ4 7TB) ("Processor"), and the customer ("Controller") governing use of the CallGuard AI services (the "Services"). It reflects the parties' agreement on the processing of Personal Data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and where applicable the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR").

Customers requiring a counter-signed copy may request one by emailing privacy@callguardai.co.uk. The terms below apply by default to all paid customers from the date of order acceptance, even where a separately signed DPA has not yet been countersigned.

Contents

  1. Definitions
  2. Roles of the parties
  3. Scope and processing details
  4. Processor obligations
  5. Confidentiality of staff
  6. Security measures
  7. Sub-processors
  8. Data subject rights
  9. Personal data breaches
  10. DPIA assistance
  11. Deletion or return of data
  12. Audits
  13. International transfers
  14. Liability
  15. Term and termination
  16. General

1. Definitions

Capitalised terms used but not defined in this DPA have the meaning given to them in UK GDPR. The following definitions apply:

Customer Personal Data
Personal Data uploaded to, streamed into, or generated through the Services on behalf of the Controller. Includes call audio, transcripts, agent and end-customer identifiers, scoring outputs, breach records, coaching briefs and metadata.
Sub-processor
Any third party engaged by the Processor to assist in providing the Services and which processes Customer Personal Data on the Processor's behalf.
Standard Contractual Clauses (SCCs)
The European Commission's Standard Contractual Clauses for the transfer of personal data to third countries, as updated and supplemented (where required) by the UK International Data Transfer Addendum or the UK International Data Transfer Agreement (IDTA).
Supervisory Authority
The UK Information Commissioner's Office (ICO) for UK transfers; the relevant lead supervisory authority for EU transfers.

2. Roles of the parties

For Customer Personal Data, the Controller is the data controller and the Processor acts as a data processor. The Controller determines the purposes and means of the Processing; the Processor processes only on the Controller's documented instructions.

Where the Controller is itself acting as a processor for an underlying customer (a "controller-of-controller-of-processor" chain), the Processor acts as a sub-processor. The terms of this DPA apply equally in that scenario.

3. Scope and processing details

3.1 Subject matter and duration

The subject matter of the Processing is the provision of the Services. The Processing will continue for the duration of the Agreement, plus any post-termination period required for deletion or return of data.

3.2 Nature and purpose

The nature and purpose of the Processing is automated transcription of call audio, AI-driven scoring against scorecards, breach detection, generation of coaching outputs and insight digests, secure storage and retrieval, and provision of audit and reporting features.

3.3 Categories of data subjects

3.4 Categories of personal data

3.5 Special category data

Customer Personal Data may contain special category data (UK GDPR Art 9), in particular health information discussed during regulated advice or insurance calls. Where this is foreseeable, the Controller is responsible for ensuring that an appropriate condition under Art 9 applies. The Processor implements heightened technical measures (encryption, access controls, deletion controls) by default for all Customer Personal Data and does not differentiate between special-category and standard data in its handling.

4. Processor obligations

4.1 General obligations

The Processor shall:

4.2 Service improvement (opt-in only)

By default, the Processor does not use Customer Personal Data to train, fine-tune or develop any machine-learning model, nor to develop or improve its products and services, beyond what is necessary to provide the Services to the Controller. This default applies unless and until the Controller expressly opts in under this Section.

The Controller may opt in by written notice to privacy@callguardai.co.uk (and, where the Processor makes such a control available, by enabling the corresponding setting within the Services), authorising the Processor to create Anonymised Data from Customer Personal Data and to use that Anonymised Data to develop, test, benchmark and improve the Services, including the Processor's scoring and calibration models. Where the Controller does so:

Nothing in this Section permits the Processor to sell Customer Personal Data, to use it for advertising, or to disclose identifiable Customer Personal Data to any third party for that third party's own purposes.

5. Confidentiality of staff

The Processor shall ensure that any person it authorises to Process Customer Personal Data:

6. Security measures

Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing, the Processor implements the technical and organisational measures set out in Annex 2: Technical and Organisational Measures. The Processor will not materially weaken these measures without notifying the Controller and obtaining consent where required.

7. Sub-processors

7.1 General authorisation

The Controller authorises the Processor to engage Sub-processors to assist in providing the Services, subject to the conditions in this clause. The current list of Sub-processors is published at callguardai.co.uk/sub-processors.

7.2 Conditions on sub-processing

Before engaging any Sub-processor, the Processor shall:

7.3 Notification of changes

The Processor will give the Controller at least 30 days' written notice (which may be by email or update to the published Sub-processor list) before adding or replacing a Sub-processor. The Controller may object on reasonable data-protection grounds within 14 days of notification. If the parties cannot resolve the objection, the Controller may terminate the affected Services on written notice without further liability.

8. Data subject rights

Taking into account the nature of the Processing, the Processor shall provide the Controller with reasonable assistance, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to data subject requests under UK GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).

Where a data subject contacts the Processor directly with a request relating to a Controller's Customer Personal Data, the Processor will refer the request to the Controller and assist as reasonably required.

9. Personal data breaches

The Processor shall:

10. DPIA assistance

The Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments (DPIA) and any prior consultation with the Supervisory Authority required under UK GDPR Articles 35 and 36, taking into account the nature of the Processing and the information available to the Processor.

11. Deletion or return of data

On termination or expiry of the Agreement, the Processor shall, at the Controller's choice and within 30 days:

Deleted Customer Personal Data may persist in routine backups for up to 7 days, after which it is permanently overwritten.

12. Audits

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including by responding to written audit questionnaires.

The Controller may, no more than once per calendar year (or more frequently in response to a confirmed Personal Data Breach), conduct an audit of the Processor's relevant systems and procedures, on at least 30 days' written notice and during normal business hours. Such audits will be performed at the Controller's cost, will be subject to confidentiality and minimum-disruption commitments, and may be conducted by an independent auditor mutually agreed.

Where available, third-party assurance reports (e.g., SOC 2, ISO 27001) will be accepted in lieu of an on-site audit.

13. International transfers

Where the Processor or any Sub-processor transfers Customer Personal Data outside the UK or the European Economic Area, the parties shall ensure that an appropriate safeguard under UK GDPR Article 46 is in place, including:

The Processor will, at the Controller's request, provide a copy of the relevant transfer mechanism applicable to each Sub-processor.

14. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA varies, increases or decreases the parties' liability under the Agreement.

15. Term and termination

This DPA takes effect on the day the Controller first uses the Services and remains in force for as long as the Processor processes Customer Personal Data. Sections that by their nature should survive termination (in particular Sections 4, 5, 11, 12 and 13) will survive.

16. General

This DPA is governed by the laws of England and Wales, with exclusive jurisdiction of the courts of England and Wales. In the event of a conflict between the Agreement and this DPA, this DPA prevails on matters of data protection.

Annex 1: Description of processing

This Annex summarises the key Processing characteristics required under UK GDPR Article 28(3).

Subject matterAI compliance scoring of customer conversations
DurationFor the term of the Agreement plus any post-termination period required for return or deletion
Nature and purposeTranscription, AI-driven scoring against scorecards, breach detection, coaching, insight generation, secure storage, retrieval and audit
Categories of data subjectsAuthorised Users; the Controller's customers; third parties whose voice is incidentally captured
Categories of dataIdentification, contact, communication content, financial, health (where discussed), voice biometrics (incidental), behavioural/performance, technical metadata
FrequencyContinuous for the duration of Service use
RetentionRetained while held in the Controller's account; deleted within 30 days of a deletion request or contract termination, subject to Section 11

Annex 2: Technical and organisational measures (TOMs)

The Processor implements the following technical and organisational measures, which it may improve over time:

Access control

Encryption

Network and infrastructure

Logging and monitoring

Backups and resilience

Personnel

Incident response

Annex 3: Sub-processors

The current list of authorised Sub-processors is maintained at callguardai.co.uk/sub-processors and is updated when new Sub-processors are added or replaced. Notification of changes is given in accordance with Section 7.3.