This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service or other written agreement between CallGuard AI Ltd, a company registered in England and Wales (company number 17279006, registered office at 106 Haytor Avenue, Paignton, England, TQ4 7TB) ("Processor"), and the customer ("Controller") governing use of the CallGuard AI services (the "Services"). It reflects the parties' agreement on the processing of Personal Data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and where applicable the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR").
Customers requiring a counter-signed copy may request one by emailing privacy@callguardai.co.uk. The terms below apply by default to all paid customers from the date of order acceptance, even where a separately signed DPA has not yet been countersigned.
Contents
1. Definitions
Capitalised terms used but not defined in this DPA have the meaning given to them in UK GDPR. The following definitions apply:
- Customer Personal Data
- Personal Data uploaded to, streamed into, or generated through the Services on behalf of the Controller. Includes call audio, transcripts, agent and end-customer identifiers, scoring outputs, breach records, coaching briefs and metadata.
- Sub-processor
- Any third party engaged by the Processor to assist in providing the Services and which processes Customer Personal Data on the Processor's behalf.
- Standard Contractual Clauses (SCCs)
- The European Commission's Standard Contractual Clauses for the transfer of personal data to third countries, as updated and supplemented (where required) by the UK International Data Transfer Addendum or the UK International Data Transfer Agreement (IDTA).
- Supervisory Authority
- The UK Information Commissioner's Office (ICO) for UK transfers; the relevant lead supervisory authority for EU transfers.
2. Roles of the parties
For Customer Personal Data, the Controller is the data controller and the Processor acts as a data processor. The Controller determines the purposes and means of the Processing; the Processor processes only on the Controller's documented instructions.
Where the Controller is itself acting as a processor for an underlying customer (a "controller-of-controller-of-processor" chain), the Processor acts as a sub-processor. The terms of this DPA apply equally in that scenario.
3. Scope and processing details
3.1 Subject matter and duration
The subject matter of the Processing is the provision of the Services. The Processing will continue for the duration of the Agreement, plus any post-termination period required for deletion or return of data.
3.2 Nature and purpose
The nature and purpose of the Processing is automated transcription of call audio, AI-driven scoring against scorecards, breach detection, generation of coaching outputs and insight digests, secure storage and retrieval, and provision of audit and reporting features.
3.3 Categories of data subjects
- The Controller's employees, contractors and authorised agents (Authorised Users);
- The Controller's customers, prospects and end-users whose conversations are recorded or transcribed (e.g., financial-planning clients, contact-centre callers, doorstep customers);
- Any third parties whose voice or personal information is captured incidentally during a recorded call.
3.4 Categories of personal data
- Identification data (name, employer, role);
- Contact data (email, phone number);
- Communication content (audio recordings, transcripts);
- Financial data discussed during calls (e.g., investment values, account references);
- Health-related data discussed during calls (only where lawful basis exists);
- Voice biometrics (incidental to audio recordings);
- Behavioural and performance data (scores, breach flags, coaching notes);
- Technical metadata (call duration, timestamps, device identifiers, GPS coordinates for field visits where supplied).
3.5 Special category data
Customer Personal Data may contain special category data (UK GDPR Art 9), in particular health information discussed during regulated advice or insurance calls. Where this is foreseeable, the Controller is responsible for ensuring that an appropriate condition under Art 9 applies. The Processor implements heightened technical measures (encryption, access controls, deletion controls) by default for all Customer Personal Data and does not differentiate between special-category and standard data in its handling.
4. Processor obligations
4.1 General obligations
The Processor shall:
- Process Customer Personal Data only on documented instructions from the Controller, including the instructions set out in the Agreement and this DPA;
- Not Process Customer Personal Data for any other purpose, including its own marketing, profiling, model training or product development, except to the limited extent the Controller has opted in under Section 4.2;
- Inform the Controller without undue delay if, in the Processor's opinion, an instruction infringes UK GDPR or other applicable data-protection law;
- Comply with applicable data-protection law in its capacity as a processor, including making available to the Controller all information necessary to demonstrate compliance.
4.2 Service improvement (opt-in only)
By default, the Processor does not use Customer Personal Data to train, fine-tune or develop any machine-learning model, nor to develop or improve its products and services, beyond what is necessary to provide the Services to the Controller. This default applies unless and until the Controller expressly opts in under this Section.
The Controller may opt in by written notice to privacy@callguardai.co.uk (and, where the Processor makes such a control available, by enabling the corresponding setting within the Services), authorising the Processor to create Anonymised Data from Customer Personal Data and to use that Anonymised Data to develop, test, benchmark and improve the Services, including the Processor's scoring and calibration models. Where the Controller does so:
- "Anonymised Data" means data that has been irreversibly stripped of all direct and indirect identifiers such that, applying the standards of the ICO's guidance on anonymisation, it can no longer be attributed to an identified or identifiable natural person — whether the Controller, an Authorised User, or any data subject — without disproportionate effort. Once anonymised in this way, the data no longer constitutes Personal Data and falls outside the scope of UK GDPR.
- Anonymisation is carried out by the Processor before any use under this Section. The Processor does not retain a means of re-identification linking Anonymised Data back to Customer Personal Data, and does not attempt to re-identify any data subject.
- Special category data (Section 3.5) is excluded from this Section and is never used for Service improvement.
- The Controller may withdraw its opt-in at any time, by written notice or by disabling the setting. Withdrawal takes effect prospectively and stops further use of Customer Personal Data under this Section; it does not require the Processor to unwind Anonymised Data already derived, which, being non-personal, cannot be attributed back to the Controller or any data subject.
Nothing in this Section permits the Processor to sell Customer Personal Data, to use it for advertising, or to disclose identifiable Customer Personal Data to any third party for that third party's own purposes.
5. Confidentiality of staff
The Processor shall ensure that any person it authorises to Process Customer Personal Data:
- Is bound by a written or statutory duty of confidentiality;
- Has received appropriate training in data protection and information security;
- Accesses Customer Personal Data only on a need-to-know basis to perform their role.
6. Security measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing, the Processor implements the technical and organisational measures set out in Annex 2: Technical and Organisational Measures. The Processor will not materially weaken these measures without notifying the Controller and obtaining consent where required.
7. Sub-processors
7.1 General authorisation
The Controller authorises the Processor to engage Sub-processors to assist in providing the Services, subject to the conditions in this clause. The current list of Sub-processors is published at callguardai.co.uk/sub-processors.
7.2 Conditions on sub-processing
Before engaging any Sub-processor, the Processor shall:
- Conduct due diligence on the Sub-processor's data-protection practices;
- Enter into a written contract with the Sub-processor imposing data-protection obligations no less protective than those in this DPA;
- Remain fully liable to the Controller for the performance of the Sub-processor's obligations.
7.3 Notification of changes
The Processor will give the Controller at least 30 days' written notice (which may be by email or update to the published Sub-processor list) before adding or replacing a Sub-processor. The Controller may object on reasonable data-protection grounds within 14 days of notification. If the parties cannot resolve the objection, the Controller may terminate the affected Services on written notice without further liability.
8. Data subject rights
Taking into account the nature of the Processing, the Processor shall provide the Controller with reasonable assistance, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to data subject requests under UK GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).
Where a data subject contacts the Processor directly with a request relating to a Controller's Customer Personal Data, the Processor will refer the request to the Controller and assist as reasonably required.
9. Personal data breaches
The Processor shall:
- Notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data;
- Provide the Controller with sufficient information to comply with its own breach-notification obligations to the Supervisory Authority and to affected data subjects;
- Take reasonable steps to contain, investigate and mitigate the breach;
- Cooperate with the Controller and the Supervisory Authority in any investigation.
10. DPIA assistance
The Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments (DPIA) and any prior consultation with the Supervisory Authority required under UK GDPR Articles 35 and 36, taking into account the nature of the Processing and the information available to the Processor.
11. Deletion or return of data
On termination or expiry of the Agreement, the Processor shall, at the Controller's choice and within 30 days:
- Return all Customer Personal Data to the Controller in a structured, commonly used and machine-readable format; or
- Delete all Customer Personal Data and existing copies, save where retention is required by applicable law (e.g., financial records, audit logs).
Deleted Customer Personal Data may persist in routine backups for up to 7 days, after which it is permanently overwritten.
12. Audits
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including by responding to written audit questionnaires.
The Controller may, no more than once per calendar year (or more frequently in response to a confirmed Personal Data Breach), conduct an audit of the Processor's relevant systems and procedures, on at least 30 days' written notice and during normal business hours. Such audits will be performed at the Controller's cost, will be subject to confidentiality and minimum-disruption commitments, and may be conducted by an independent auditor mutually agreed.
Where available, third-party assurance reports (e.g., SOC 2, ISO 27001) will be accepted in lieu of an on-site audit.
13. International transfers
Where the Processor or any Sub-processor transfers Customer Personal Data outside the UK or the European Economic Area, the parties shall ensure that an appropriate safeguard under UK GDPR Article 46 is in place, including:
- The UK International Data Transfer Agreement (IDTA);
- The EU Standard Contractual Clauses (SCCs) supplemented by the UK Addendum;
- An adequacy decision recognised under UK GDPR;
- Binding Corporate Rules where applicable.
The Processor will, at the Controller's request, provide a copy of the relevant transfer mechanism applicable to each Sub-processor.
14. Liability
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA varies, increases or decreases the parties' liability under the Agreement.
15. Term and termination
This DPA takes effect on the day the Controller first uses the Services and remains in force for as long as the Processor processes Customer Personal Data. Sections that by their nature should survive termination (in particular Sections 4, 5, 11, 12 and 13) will survive.
16. General
This DPA is governed by the laws of England and Wales, with exclusive jurisdiction of the courts of England and Wales. In the event of a conflict between the Agreement and this DPA, this DPA prevails on matters of data protection.
Annex 1: Description of processing
This Annex summarises the key Processing characteristics required under UK GDPR Article 28(3).
| Subject matter | AI compliance scoring of customer conversations |
|---|---|
| Duration | For the term of the Agreement plus any post-termination period required for return or deletion |
| Nature and purpose | Transcription, AI-driven scoring against scorecards, breach detection, coaching, insight generation, secure storage, retrieval and audit |
| Categories of data subjects | Authorised Users; the Controller's customers; third parties whose voice is incidentally captured |
| Categories of data | Identification, contact, communication content, financial, health (where discussed), voice biometrics (incidental), behavioural/performance, technical metadata |
| Frequency | Continuous for the duration of Service use |
| Retention | Retained while held in the Controller's account; deleted within 30 days of a deletion request or contract termination, subject to Section 11 |
Annex 2: Technical and organisational measures (TOMs)
The Processor implements the following technical and organisational measures, which it may improve over time:
Access control
- JWT-based authentication for all platform access; bcrypt-hashed passwords with secure salt; password complexity rules enforced.
- Role-based access control for organisations, with separate admin and member roles and least-privilege defaults.
- Session tokens that expire after a set period.
- API access authenticated via per-organisation API keys, stored only as hashes.
Encryption
- TLS 1.2+ enforced for all client and inter-service traffic.
- Audio files encrypted at rest with AES-256-GCM.
- Database storage encrypted at rest at the cloud-provider layer.
- Signed share-links for any external customer access, with token expiry and revocation.
Network and infrastructure
- Hosting with a reputable cloud provider in the UK (London region).
- DDoS mitigation and a Web Application Firewall at the edge (via Cloudflare).
- The database is not exposed directly to the public internet.
- Security patching of OS-level dependencies.
Logging and monitoring
- An audit log recording user, timestamp, action and source IP for key data-modifying events (such as deletions, score corrections and breach updates).
- Periodic review of access logs.
Backups and resilience
- Automated daily backups of the database and audio storage, retained for 7 days.
- Point-in-time recovery available on the managed database.
- Audio is stored as AES-256-GCM ciphertext on encrypted disk in the London region.
Personnel
- All individuals with access to production data are bound by confidentiality obligations.
- Access to production data is limited to those who need it to operate the Services.
Incident response
- We notify affected Controllers of a Personal Data Breach without undue delay and within 72 hours of becoming aware of it.
- Post-incident review and remediation.
Annex 3: Sub-processors
The current list of authorised Sub-processors is maintained at callguardai.co.uk/sub-processors and is updated when new Sub-processors are added or replaced. Notification of changes is given in accordance with Section 7.3.