legal
Data Processing Agreement
The Article 28 terms that apply whenever CallHQ processes personal data on your behalf. This forms part of your contract with us and does not need to be signed separately.
Version 1.0 · last updated 2026-08-09
Draft — not yet in force
These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.
Status of this document
This DPA is incorporated into the Terms of Service and applies automatically to every customer, without a separate signature. If your procurement process requires a countersigned copy, we will provide one on request — the terms will be these terms.
It gives effect to Article 28 of the UK GDPR and EU GDPR. Where it conflicts with the Terms of Service on a data protection matter, this document wins.
Definitions
Controller, processor, data subject, personal data, processing and personal data breach have the meanings given in the UK GDPR.
Customer Personal Data means personal data that you put into CallHQ or that CallHQ collects on your instruction — principally records about your prospects and their staff.
Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR, and PECR or the ePrivacy Directive as applicable.
Roles and scope
For Customer Personal Data, you are the controller and we are the processor. You determine who is contacted, on what basis, and with what content.
Separately, we are a controller of data about your own users — account and billing records. That processing is governed by our Privacy Policy, not by this DPA.
You warrant that you have a lawful basis for the Customer Personal Data you process through CallHQ, that you have given any notices and obtained any consents your basis requires, and that your instructions will not put us in breach of Data Protection Law.
We will process Customer Personal Data only on your documented instructions. Your use of the product's features is itself an instruction. If we are required by law to process it otherwise, we will tell you first unless the law forbids it.
We will not sell Customer Personal Data, use it for our own purposes, use it to train machine-learning models, or combine it into any cross-customer dataset.
Our obligations as processor
- Process only on your instructions, and only for the purposes in Annex 1.
- Ensure everyone we authorise to process it is under a duty of confidentiality.
- Implement the measures in Annex 2 and keep them under review.
- Engage sub-processors only on the terms below.
- Assist you with data-subject rights, impact assessments and regulator consultations, as set out below.
- Delete or return the data at the end of the relationship, as set out below.
- Make available the information you need to demonstrate our compliance.
Security measures
We maintain appropriate technical and organisational measures against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. They are described in Annex 2.
We may change specific measures as technology moves, but not in a way that materially reduces overall security.
Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published at the sub-processor register and is kept up to date.
Before adding or replacing a sub-processor that handles Customer Personal Data we will give at least 30 days' notice. If you reasonably object on data protection grounds within that period, tell us and we will work to offer an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of anything prepaid — you will not be locked into a change you object to.
We impose data protection terms on each sub-processor no less protective than these, and we remain fully liable to you for their performance.
A practical note: several sub-processors are only engaged if you connect your own account. If you never connect an enrichment vendor, no Customer Personal Data reaches one.
International transfers
Where we transfer Customer Personal Data outside the UK or EEA, we do so under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated here by reference. For EU transfers, Module Two (controller to processor) applies, with you as data exporter and us as data importer; Module Three applies onward to sub-processors.
Primary storage is in [hosting region — not yet supplied]. The register marks each sub-processor's location.
Assisting you
Data-subject requests. The product lets you find, export, correct and delete any record yourself, which is normally faster than asking us. If a data subject contacts us directly we will not respond substantively — we will tell them to contact you and pass on what we have, except that we will action a suppression request immediately, because stopping unwanted contact should never wait on a ticket.
Assessments and consultations. Taking into account what we know, we will give you reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority.
Personal data breach
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data.
The notice will describe what happened, the categories and approximate number of records affected, the likely consequences, and what we are doing about it — or, where the picture is still forming, what we know so far and when we will update you. We would rather tell you something incomplete quickly than something complete late.
Notification is not an admission of fault by either side.
Deletion and return
You can export your data at any time without asking. On termination you retain export access for 30 days, after which we delete Customer Personal Data from live systems within a further 30 days, and from backups within 90 days as backups age out.
One deliberate exception: suppression records — the minimal data needed to remember that someone asked not to be contacted. Deleting those would risk contacting that person again. We keep the minimum necessary and nothing else, and we consider retaining it a protection for the data subject rather than a benefit to us.
Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you mandate.
In practice: ask, and we will answer questionnaires and share what we have. On-site audits are limited to once in any 12 months unless a regulator requires otherwise or there has been a breach, must be on reasonable notice and during business hours, and must not compromise other customers' confidentiality.
Annex 1 — details of processing
- Subject matter — provision of the CallHQ platform.
- Duration — the term of your subscription, plus the deletion periods above.
- Nature and purpose — sourcing business records from public registers; enrichment; multi-channel outreach by email, SMS, LinkedIn and telephone; call recording and transcription where enabled; meeting booking; pipeline and revenue tracking; compliance suppression.
- Categories of data subject — your prospects and their staff; your own users; attendees at meetings booked through the platform.
- Categories of personal data — business contact details (name, role, business email, business phone, business address); publicly filed company information; communications content you send and replies received; call metadata and, where enabled, call audio and transcripts; meeting details; and the notes your users write.
- Special category data — none is requested, required or expected. CallHQ is not designed to process special category or criminal-offence data, and you should not put it in. If free-text notes contain it, that is your processing decision and your risk.
Annex 2 — technical and organisational measures
- Encryption — TLS in transit; encryption at rest on the underlying storage.
- Tenant isolation — enforced at the database client so a query for one workspace physically cannot return another's rows. Isolation is structural, not a filter someone must remember to apply.
- Access control — role-based permissions, per-workspace scoping, two-factor authentication available, least privilege for operators.
- Credential separation — the application holds no third-party API keys; vendor credentials live in a separate self-hosted automation layer, so compromising the web app does not expose your vendor accounts.
- Authentication — passwords hashed with a modern algorithm, never logged in the clear.
- Integrity of inbound data — every webhook is signature-verified and fails closed on mismatch.
- Auditability — administrative and compliance-relevant actions are recorded in an append-only trail, exportable by you.
- Fail-closed compliance controls — suppression, calling-hours windows and consent gates refuse the action when they cannot confirm it is permitted.
- Resilience — automated backups with periodic restore verification.
- Confidentiality — personnel with access are bound by confidentiality obligations.
Contact for data protection matters: [privacy contact address — not yet supplied] · [registered legal entity — not yet supplied].