Data processing addendum
Last updated: 28 August 2026
This addendum applies whenever we process personal data on behalf of a customer under Article 28 GDPR. It forms part of the terms of service. A signed copy is available on request.
1. Roles
The customer is the controller of call data and end-user personal data processed through its workspace. Receply (Receply) is the processor and processes that data only on the customer's documented instructions, which include the configuration made in the dashboard.
2. Subject matter and duration
Subject matter: operating AI phone agents and the associated dashboard. Duration: for the term of the subscription plus the deletion window described below.
3. Categories of data and data subjects
- Data subjects: the customer's callers, customers, staff and workspace members.
- Personal data: phone numbers, names, call audio, transcripts, summaries, stated reasons for calling, contact details for callbacks and any information a caller volunteers.
- Special-category data is not requested. Customers must not configure agents to solicit health, biometric or other special-category data.
4. Processor obligations
- Process personal data only on the controller's instructions and for the service.
- Impose confidentiality on all personnel with access.
- Implement the technical and organisational measures described in section 6.
- Assist the controller with data subject requests, DPIAs and regulator enquiries.
- Notify the controller without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach.
- Make available the information needed to demonstrate compliance.
5. Sub-processors
The customer authorises the use of sub-processors for cloud hosting and database (EU region), voice AI processing, telephony connectivity, email delivery and payment processing. Each sub-processor is bound by equivalent data protection obligations. We give notice before adding or replacing a sub-processor, and the customer may object on reasonable data protection grounds.
6. Security measures
- Encryption in transit (TLS) and at rest.
- Per-tenant isolation enforced by row-level security in the database.
- Private storage for recordings, accessed only through short-lived signed links.
- Role-based access control; secrets stored server-side and never exposed to browsers.
- Audit logging of administrative and configuration changes, plus integration logs.
- Signed and idempotent webhooks with replay protection.
- Backups with restore testing, and least-privilege staff access.
7. International transfers
Primary processing takes place in the European Union. Any transfer outside the EEA is covered by the European Commission's Standard Contractual Clauses and supplementary technical measures.
8. Audits
On reasonable written notice and no more than once per year, we provide the documentation needed to verify compliance and answer a reasonable security questionnaire. On-site audits are available where legally required.
9. Return and deletion
Customers can export call data and delete records at any time in the dashboard. After termination we delete or irreversibly anonymise the customer's personal data within 30 days, except where retention is required by law.
To request a countersigned addendum, write to privacy@receply.io.