Data Processing Addendum
Last updated: 12 August 2026
Parties and scope
This Data Processing Addendum (“DPA”) forms part of the agreement between Bordosa Ltd (“we”, “us”, “the processor”), a company registered in England and Wales (company number 11604533), and the customer identified on the RepCall order or account (“the customer”, “the controller”).
It applies whenever we process personal data on the customer’s behalf as part of the RepCall service, and takes precedence over the main Terms of Service on data protection matters in the event of a conflict.
Subject matter and duration
The subject matter of this DPA is our processing of personal data uploaded to, or connected with, the customer’s RepCall account, and the call outcomes and notes generated through use of the service.
Processing continues for the duration of the customer’s subscription, and for the retention periods set out in “Deletion or return on termination” below.
Categories of data and data subjects
Categories of personal data processed: contact name, company name, phone number, account/tier code, and the free-text content of the last CRM note on file; call outcomes and timestamps; spoken call summaries converted to text, and the CRM-ready notes generated from them.
Categories of data subjects: the customer’s business contacts — typically employees or representatives of the businesses on the customer’s call list.
Processor obligations
We will:
- process personal data only on the customer’s documented instructions, including regarding international transfers, unless required to do otherwise by law;
- ensure that people authorised to process the data are subject to a duty of confidentiality;
- implement appropriate technical and organisational security measures;
- engage sub-processors only as set out below, and only under a written contract imposing equivalent data protection obligations;
- assist the customer in responding to data subject requests and in meeting its security, breach notification and data protection impact assessment obligations;
- make available the information necessary to demonstrate compliance with this DPA, and allow for audits as set out below; and
- delete or return personal data at the end of the provision of services, as set out below.
Confidentiality
We keep all customer personal data confidential and accessible only to staff and contractors who need it to provide the service, all of whom are bound by confidentiality obligations.
Security measures
We use encryption in transit, access controls limiting data access to authorised personnel, and routine review of our security practices. We do not currently hold a formal security certification such as ISO 27001, SOC 2 or Cyber Essentials.
Sub-processors
The customer authorises the use of the sub-processors listed below. We will give the customer at least 30 days’ notice before appointing a new sub-processor or replacing an existing one, during which the customer may object on reasonable data protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | AWS eu-west-2 (London), UK |
| Vercel | Website and portal hosting | EU/US |
| OpenAI | Turning call-note transcripts into clean CRM notes | USA |
| Stripe | Payment processing | EU/US |
| Resend | Transactional email | EU/US |
International transfers
Personal data is held in the UK by default, on Supabase’s UK region (AWS eu-west-2, London). Where a sub-processor transfers personal data outside the UK — Vercel, Stripe and Resend (EU/US) and OpenAI (USA) — we rely on the UK International Data Transfer Addendum or an equivalent safeguard recognised under UK GDPR.
Assistance with data subject requests
Where we receive a request from a data subject relating to data we process on the customer’s behalf, we will forward it to the customer promptly and provide reasonable assistance in responding to it.
Personal data breach notification
We will notify the customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting data processed on the customer’s behalf, together with the information reasonably available to us to help the customer meet its own notification obligations.
Audit rights
The customer may request evidence of our compliance with this DPA, including relevant security documentation. Where reasonably necessary, and on reasonable notice, we will support an audit, which may be satisfied by a report from an independent third party where available.
Deletion or return on termination
On termination of the customer’s subscription, we will delete the customer’s contact and call data within 30 days, or return it in an exportable format if requested before deletion — except where we are required to retain it by law (for example, billing records, which we retain for 7 years).
Liability
This DPA does not expand the liability limits set out in the Terms of Service. It is subject to the same limitations described there.
Contact us
Questions about this DPA: email privacy@repcall.co.uk.
Bordosa Ltd, registered in England and Wales (company number 11604533). To write to us by post, use our registered office address.