RepCall

Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement between Bordosa Ltd (“we”, “us”, “the processor”), a company registered in England and Wales (company number 11604533), and the customer identified on the RepCall order or account (“the customer”, “the controller”).

It applies whenever we process personal data on the customer’s behalf as part of the RepCall service, and takes precedence over the main Terms of Service on data protection matters in the event of a conflict.

Subject matter and duration

The subject matter of this DPA is our processing of personal data uploaded to, or connected with, the customer’s RepCall account, and the call outcomes and notes generated through use of the service.

Processing continues for the duration of the customer’s subscription, and for the retention periods set out in “Deletion or return on termination” below.

Categories of data and data subjects

Categories of personal data processed: contact name, company name, phone number, account/tier code, and the free-text content of the last CRM note on file; call outcomes and timestamps; spoken call summaries converted to text, and the CRM-ready notes generated from them.

Categories of data subjects: the customer’s business contacts — typically employees or representatives of the businesses on the customer’s call list.

Processor obligations

We will:

  • process personal data only on the customer’s documented instructions, including regarding international transfers, unless required to do otherwise by law;
  • ensure that people authorised to process the data are subject to a duty of confidentiality;
  • implement appropriate technical and organisational security measures;
  • engage sub-processors only as set out below, and only under a written contract imposing equivalent data protection obligations;
  • assist the customer in responding to data subject requests and in meeting its security, breach notification and data protection impact assessment obligations;
  • make available the information necessary to demonstrate compliance with this DPA, and allow for audits as set out below; and
  • delete or return personal data at the end of the provision of services, as set out below.

Confidentiality

We keep all customer personal data confidential and accessible only to staff and contractors who need it to provide the service, all of whom are bound by confidentiality obligations.

Security measures

We use encryption in transit, access controls limiting data access to authorised personnel, and routine review of our security practices. We do not currently hold a formal security certification such as ISO 27001, SOC 2 or Cyber Essentials.

Sub-processors

The customer authorises the use of the sub-processors listed below. We will give the customer at least 30 days’ notice before appointing a new sub-processor or replacing an existing one, during which the customer may object on reasonable data protection grounds.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageAWS eu-west-2 (London), UK
VercelWebsite and portal hostingEU/US
OpenAITurning call-note transcripts into clean CRM notesUSA
StripePayment processingEU/US
ResendTransactional emailEU/US

International transfers

Personal data is held in the UK by default, on Supabase’s UK region (AWS eu-west-2, London). Where a sub-processor transfers personal data outside the UK — Vercel, Stripe and Resend (EU/US) and OpenAI (USA) — we rely on the UK International Data Transfer Addendum or an equivalent safeguard recognised under UK GDPR.

Assistance with data subject requests

Where we receive a request from a data subject relating to data we process on the customer’s behalf, we will forward it to the customer promptly and provide reasonable assistance in responding to it.

Personal data breach notification

We will notify the customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting data processed on the customer’s behalf, together with the information reasonably available to us to help the customer meet its own notification obligations.

Audit rights

The customer may request evidence of our compliance with this DPA, including relevant security documentation. Where reasonably necessary, and on reasonable notice, we will support an audit, which may be satisfied by a report from an independent third party where available.

Deletion or return on termination

On termination of the customer’s subscription, we will delete the customer’s contact and call data within 30 days, or return it in an exportable format if requested before deletion — except where we are required to retain it by law (for example, billing records, which we retain for 7 years).

Liability

This DPA does not expand the liability limits set out in the Terms of Service. It is subject to the same limitations described there.

Contact us

Questions about this DPA: email privacy@repcall.co.uk.

Bordosa Ltd, registered in England and Wales (company number 11604533). To write to us by post, use our registered office address.