Data Processing Addendum
Last updated 2 September 2026. Draft prepared for professional legal review; not yet reviewed by a solicitor.
This Addendum forms part of the Terms of Service between Callkept ("Processor") and the account holder ("Controller") and reflects Article 28 UK GDPR.
1. Subject matter and duration
Processing of personal data of the Controller's prospective and existing customers (callers, web enquirers) for the purpose of responding to, qualifying and booking enquiries, for the duration of the account.
2. Nature and purpose
Receiving call metadata and messages; sending automated SMS/web replies; extracting job details, postcode and urgency; creating bookings and notifications; producing reports.
3. Categories of data and data subjects
Names, telephone numbers, email addresses, postcodes/addresses, the content of enquiries (which may incidentally include health or vulnerability information volunteered by the customer). Data subjects: the Controller's customers and prospective customers.
4. Processor obligations
- Process only on documented instructions (the Service configuration and these terms).
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organisational measures (encryption in transit, encrypted secrets, tenant isolation, access control, audit logs, backups).
- Engage sub-processors only under written terms offering equivalent protection; maintain the sub-processor list and give 30 days' notice of changes with a right to object.
- Assist the Controller with data subject requests, security, breach notification (without undue delay and within 48 hours of becoming aware), DPIAs and consultations.
- Delete or return personal data at the end of the Service (export available for 30 days), unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow audits on reasonable notice.
5. Controller obligations
The Controller warrants it has a lawful basis for the processing, provides required privacy information to its customers, and configures the Service lawfully (including not using it for unsolicited marketing to individuals).
6. International transfers
Transfers outside the UK are made under the ICO's International Data Transfer Addendum or an adequacy regulation.
7. No model training
The Processor will not use Controller data to train machine-learning models shared across customers.