Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of, and is incorporated into, the Terms of Service between:
Skye Line Trades Ltd, a company incorporated in England and Wales with company number 17358493, whose registered office is at Suite 3b, Kings House, 1 King Street, Leeds LS1 2HH ("Processor", "we", "us", "our"); and
the business customer who subscribes to the Service ("Controller", "you", "your").
By accepting the Terms of Service or using the Service, you agree to this DPA. This DPA records the terms on which we process Personal Data relating to your callers and end-clients on your behalf, and reflects the requirements of Article 28 of the UK GDPR.
1. Definitions and interpretation
1.1 In this DPA:
"Account" means your customer account for the Service.
"Caller Data" means the Personal Data relating to callers, end-clients and other third parties which we process on your behalf through the Service, as further described in Schedule 2.
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and all other applicable laws and regulations relating to the processing of personal data and privacy, as amended or replaced from time to time.
"Service" means the AI receptionist service described in the Terms of Service.
"Sub-processor" means any third party engaged by us to process Caller Data.
"Transcripts" means the text records generated from calls handled by the Service.
"UK GDPR" has the meaning given in section 3(10) of the Data Protection Act 2018, as supplemented by section 205(4) of that Act.
1.2 "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing" and "Special Category Data" have the meanings given to them in the Data Protection Legislation.
1.3 Clause and Schedule headings do not affect interpretation. References to a Clause or Schedule are to a Clause of, or Schedule to, this DPA. "Including" and "in particular" are not words of limitation.
2. Roles of the parties
2.1 In respect of Caller Data, you are the Controller and we are the Processor.
2.2 The subject-matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Schedule 2.
2.3 This DPA does not apply to Personal Data for which we are the controller in our own right — for example, the contact and billing details of your own staff and account users, which we process as described in our Privacy Policy.
3. Your obligations as Controller
3.1 You are responsible for ensuring that you have a lawful basis for the processing of Caller Data and that all necessary notices have been given and, where required, consents obtained.
3.2 In particular, you shall ensure that callers to your business are informed, in a clear and timely way and before or at the start of the call, that:
(a) calls are answered and handled by an automated or artificial-intelligence system;
(b) calls are recorded and transcribed; and
(c) how they may exercise their data protection rights, including where to direct a request.
The Service includes a default call-opening announcement covering (a) and (b). Providing this information remains your obligation as Controller under Article 13 of the UK GDPR. You are responsible for ensuring that the information given to your callers is adequate for your business, including the information at (c), and for not disabling or modifying the announcement in a way that removes it.
3.3 You warrant that your instructions to us in respect of Caller Data, and the configuration of your Account, comply with the Data Protection Legislation.
3.4 You shall not direct to the Service any calls or data that fall outside the scope of the Service as described in Schedule 2.
4. Processing on documented instructions
4.1 We shall process Caller Data only on your documented instructions, including with regard to transfers of Caller Data outside the United Kingdom, unless we are required to process it by law to which we are subject. In that case we shall inform you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.
4.2 Your documented instructions are set out in this DPA, the Terms of Service and the configuration of your Account. The permitted purposes are:
(a) operating the Service, including passing messages and bookings to you;
(b) keeping records for quality, dispute-resolution and support purposes;
(c) sharing call summaries and Transcripts back with you; and
(d) producing call and usage records for billing and account management.
4.3 We shall immediately inform you if, in our opinion, an instruction from you infringes the Data Protection Legislation.
4.4 No AI or model training. We shall not use Caller Data, call audio or Transcripts to train, develop or improve any artificial-intelligence or machine-learning model, whether ours or a third party's. This exclusion applies notwithstanding any other provision of this DPA or the Terms of Service.
5. Confidentiality
5.1 We shall ensure that all persons authorised by us to process Caller Data are subject to a binding duty of confidentiality, whether by contract or by statutory obligation.
5.2 We shall ensure that access to Caller Data is limited to those persons who need it in order to provide the Service, and that they process Caller Data only as necessary for that purpose.
6. Security
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, we shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Schedule 3, including as appropriate:
(a) encryption of Personal Data in transit and at rest;
(b) measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
(c) access controls and authentication; and
(d) processes for regularly testing, assessing and evaluating the effectiveness of those measures.
6.2 We may update the measures in Schedule 3 from time to time, provided that any update does not materially reduce the overall level of security.
7. Sub-processors
7.1 You give us general written authorisation to engage the Sub-processors listed in Schedule 1.
7.2 We shall enter into a written contract with each Sub-processor imposing data-protection obligations equivalent in substance to those set out in this DPA, and we remain fully liable to you for the performance of each Sub-processor's obligations.
7.3 We shall give you at least 14 days' notice of any intended addition or replacement of a Sub-processor, by email to the address on your Account or by notice in your Account. You may object on reasonable data-protection grounds within that period.
7.4 If you object and we cannot reasonably accommodate the objection, you may terminate the affected part of the Service by cancelling in accordance with the Terms of Service, without penalty.
7.5 Where an urgent change of Sub-processor is required to maintain the security or continuity of the Service, we may make the change immediately and notify you as soon as reasonably practicable, and Clauses 7.3 and 7.4 apply from the date of that notice.
8. Assistance with Data Subject rights
8.1 Taking into account the nature of the processing, we shall assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights under the Data Protection Legislation.
8.2 If we receive a request directly from a Data Subject relating to Caller Data, we shall not respond to it ourselves, other than to acknowledge receipt and, where appropriate, direct the Data Subject to you. We shall forward the request to you without undue delay and in any event within 2 working days.
9. Assistance with compliance, breaches and DPIAs
9.1 Taking into account the nature of the processing and the information available to us, we shall assist you in ensuring compliance with your obligations relating to:
(a) the security of processing;
(b) notification of Personal Data Breaches to the Information Commissioner's Office ("ICO");
(c) communication of Personal Data Breaches to Data Subjects;
(d) data protection impact assessments ("DPIAs"); and
(e) prior consultation with the ICO.
9.2 We shall notify you without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data Breach affecting Caller Data.
9.3 That notification shall include, to the extent known to us at the time and updated as further information becomes available: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; and the measures taken or proposed to address it and mitigate its effects. We shall provide you with sufficient information to allow you to meet your own breach-notification obligations.
9.4 We shall not notify the ICO or any Data Subject of a Personal Data Breach affecting Caller Data on your behalf unless you instruct us to do so or we are required to by law.
9.5 Assistance under Clause 8 and this Clause 9 is included in your Subscription to the extent it is reasonably required of a processor under Articles 28 and 32 to 36 of the UK GDPR. Assistance that goes materially beyond that, or that arises from repeated, manifestly unfounded or excessive requests, may be chargeable at our then-current standard rates. We shall tell you in advance if we consider a request chargeable, and give you the opportunity to withdraw or narrow it.
10. Audit
10.1 We shall make available to you all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this DPA.
10.2 We shall allow for and contribute to audits, including inspections, conducted by you or by an auditor mandated by you, subject to Clauses 10.3 and 10.4.
10.3 In the first instance, you agree that we may satisfy a request under Clause 10.2 by providing our then-current security documentation, policies and any relevant third-party certifications or reports, together with written responses to reasonable questions. Where that documentation does not reasonably answer your request, you may conduct an inspection.
10.4 Any inspection shall be: on at least 30 days' prior written notice; during our normal business hours; conducted so as not to disrupt our business or compromise the confidentiality or security of other customers' data; subject to written confidentiality undertakings by you and your auditor; at your cost; and no more than once in any 12-month period, unless required more frequently by a regulator or following a Personal Data Breach affecting Caller Data.
10.5 Clause 10.4 applies except where the inspection is necessitated by a Personal Data Breach caused by us or one of our Sub-processors, or by our material non-compliance with this DPA, in which case we shall bear the reasonable costs of the inspection.
11. Special Category Data and criminal-offence data
11.1 The Service is not intended or designed to process Special Category Data or Personal Data relating to criminal convictions and offences.
11.2 You shall not knowingly or deliberately direct to the Service any calls whose purpose is to collect or process Special Category Data (such as data concerning health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation) or criminal-offence data.
11.3 You acknowledge that, because callers speak freely, a caller may incidentally and unpredictably disclose Special Category Data during a call. Where this occurs incidentally, we shall process that data only as part of the ordinary Caller Data, for the permitted purposes set out in Clause 4.2 and subject to the retention limits in Clause 12. We do not separately identify, flag, index or search for Special Category Data within Caller Data, and the Service has no capability to do so. You remain responsible for ensuring an appropriate lawful basis and, where applicable, a condition for processing under Articles 6 and 9 of the UK GDPR.
11.4 You shall put in place reasonable measures to discourage the collection of Special Category Data through the Service and to configure your call handling accordingly. Compliance with this Clause 11 is a condition of your use of the Service.
12. Retention, return and deletion
12.1 We shall retain Caller Data only for as long as is necessary to provide the Service and for the permitted purposes. In particular:
(a) call audio recordings are retained for 1 month from the end of the call and are then deleted; and
(b) Transcripts are retained for 6 months from the end of the call and are then deleted.
These periods mirror those stated in our Privacy Policy.
12.2 On termination or expiry of the Service, we shall, at your choice, delete or return all Caller Data then held, and delete existing copies, unless we are required by law to retain a copy.
12.3 You must notify us of your choice under Clause 12.2 within 30 days of termination or expiry. If you do not, we shall delete the Caller Data.
12.4 Given the retention periods in Clause 12.1, Caller Data is in any event deleted within those periods after the relevant call.
12.5 Where deletion from backup media is not immediately possible, we shall isolate the Caller Data, protect it from further processing and delete it in accordance with our backup cycle.
13. International transfers
13.1 We shall not transfer Caller Data outside the United Kingdom unless an appropriate transfer mechanism required by the Data Protection Legislation is in place.
13.2 Where a Sub-processor is located outside the United Kingdom (see Schedule 1), the transfer is made under one or more of:
(a) the UK International Data Transfer Agreement (IDTA); or
(b) the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum,
in each case supported by a transfer risk assessment and, where appropriate, additional safeguards; or under UK adequacy regulations where these apply to the destination country.
13.3 You authorise us to enter into the mechanisms in Clause 13.2 with each relevant Sub-processor on your behalf, as your agent, for the purposes of these transfers.
13.4 Where we add a Sub-processor located outside the United Kingdom, we shall confirm and implement the applicable transfer mechanism, and record it in the transfer mechanism column of Schedule 1 Part A, before any Caller Data is transferred to that Sub-processor.
14. Liability
14.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service.
14.2 Nothing in this DPA limits or excludes either party's liability where it cannot lawfully be limited or excluded, including a Data Subject's rights to compensation under the Data Protection Legislation.
15. Term and changes to this DPA
15.1 This DPA takes effect on the date you accept the Terms of Service and continues until the Service terminates or expires and all Caller Data has been deleted or returned in accordance with Clause 12.
15.2 Clauses which by their nature are intended to survive termination — including Clauses 5, 12, 13, 14 and 16 — shall continue in force.
15.3 We may update this DPA where necessary to reflect a change in the Data Protection Legislation, regulatory guidance, or our Sub-processors or security measures. We shall give you reasonable notice of any material change, and no update shall reduce the protections given to Caller Data under this DPA.
16. General
16.1 Governing law and jurisdiction. This DPA is governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
16.2 Order of precedence. In the event of any conflict between this DPA and the Terms of Service in relation to the processing of Personal Data, this DPA prevails. Except as amended by this DPA, the Terms of Service remain in full force and effect.
16.3 Contact. Data protection queries, Data Subject requests and audit requests under this DPA should be sent to support@skyelinetrades.com.
16.4 Notices. Notices under this DPA may be given by email to the address on your Account (for notices to you) and to the address in Clause 16.3 (for notices to us).
16.5 Severance. If any provision of this DPA is or becomes invalid or unenforceable, it shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall be unaffected.
16.6 Acceptance. This DPA is accepted electronically when you accept the Terms of Service or use the Service, and no physical signature is required.
Schedule 1 — Sub-processors
Part A — Sub-processors of Caller Data
The following Sub-processors are authorised to process Caller Data. The general authorisation in Clause 7.1 and the objection right in Clause 7.3 apply to this Part A only.
| Sub-processor | Service provided | Country of processing | Transfer mechanism |
|---|---|---|---|
| Vapi | Voice orchestration, call handling, recordings and Transcripts | United States | [TO CONFIRM] |
| Deepgram (Nova-3) | Speech-to-text transcription | United States | [TO CONFIRM] |
| OpenAI | Conversational AI model | United States | [TO CONFIRM] |
| Cartesia (Sonic 3.5) | Text-to-speech | United States | [TO CONFIRM] |
| ElevenLabs | Fallback text-to-speech / voice | United States | [TO CONFIRM] |
| Zoho Mail | Support and data-request inbox hosting, where caller correspondence is received | European Union | UK adequacy regulations (EEA) |
Part B — Our own service providers (not Sub-processors of Caller Data)
The following providers support our business but do not process Caller Data. They are listed for transparency only. They process Personal Data for which we are the controller in our own right, as described in Clause 2.3 and in our Privacy Policy, and the authorisation and objection provisions in Clause 7 do not apply to them.
| Provider | Service provided | Country of processing |
|---|---|---|
| Stripe | Billing and payment processing | United States / Ireland |
| Squarespace | Website hosting and contact form | United States |
The current list of Sub-processors is available on request from support@skyelinetrades.com. This list was last updated on 8 September 2026.
Schedule 2 — Details of processing
Subject-matter of the processing. The provision of the AI receptionist Service, under which we answer inbound telephone calls made to the Controller's business, capture messages and bookings, and pass them on to the Controller.
Duration of the processing. For the duration of the Controller's subscription, subject to the retention periods set out in Clause 12 (call audio deleted after 1 month; Transcripts deleted after 6 months).
Nature of the processing. Receiving and answering calls using automated speech recognition, conversational AI and text-to-speech; recording call audio; generating Transcripts; extracting messages and booking details; and making summaries, Transcripts, messages and bookings available to the Controller. Processing operations include collection, recording, storage, transcription, structuring, retrieval, disclosure to the Controller and erasure.
Purpose of the processing. Limited to: operating the Service; keeping records for quality, dispute-resolution and support purposes; sharing summaries and Transcripts back with the Controller; and producing call and usage records for billing and account management. We do not use Caller Data to train or improve artificial-intelligence or machine-learning models.
Types of Personal Data. Caller name; caller telephone number; caller address (where given); the content of the call (audio recording and Transcript); message and booking details, including details of the job, property or enquiry; and any other information the caller chooses to provide during the call. The Service is not intended to process Special Category Data, though a caller may incidentally disclose such data (see Clause 11).
Categories of Data Subjects. Callers and end-clients of the Controller — that is, members of the public and other third parties who telephone the Controller's business and whose calls are handled by the Service.
Controller. The business customer (tradesperson) who subscribes to the Service.
Processor. Skye Line Trades Ltd.
Schedule 3 — Technical and organisational measures
The measures below are those referred to in Clause 6.
Encryption. Caller Data is encrypted in transit using industry-standard TLS. Caller Data at rest is held on encrypted storage operated by the Sub-processors listed in Schedule 1.
Access control. Access to systems holding Caller Data is restricted to authorised personnel on a need-to-know basis, protected by unique credentials and multi-factor authentication where the platform supports it. Access is reviewed periodically and revoked promptly when no longer required.
Customer separation. Each Controller's Caller Data is separated by account, and dashboard access is limited to that Controller's own Account.
Retention and deletion. Automated retention settings are applied so that call audio and Transcripts are deleted in line with Clause 12.
Resilience and availability. Caller Data is hosted on cloud infrastructure operated by the Sub-processors listed in Schedule 1, which provide resilience and backup as part of their platforms.
Sub-processor management. Sub-processors are engaged under written contracts containing data-protection terms, and their locations and transfer safeguards are recorded in Schedule 1.
Breach handling. A documented process is in place for identifying, assessing and reporting Personal Data Breaches, including notification to affected Controllers within the period set out in Clause 9.2.
Review. These measures are reviewed at least annually and following any material change to the Service or its Sub-processors.