1. Definitions
- “Controller” — the client business deploying Calltura to handle inbound calls.
- “Processor” — Calltura, processing personal data on behalf of the Controller.
- “Personal Data” — call audio, transcripts, caller phone numbers, names, and any other personal data processed via the Service.
- “UK GDPR” — the UK General Data Protection Regulation (retained from EU GDPR under the European Union (Withdrawal) Act 2018).
- “Sub-processor” — any third party engaged by the Processor to process Personal Data (see Schedule A).
2. Scope and purpose
The Processor processes Personal Data solely to provide the AI voice receptionist service to the Controller — specifically: handling inbound calls, generating transcripts, booking appointments, and surfacing call data in the admin portal.
The Processor does not process Personal Data for its own independent purposes.
3. Processor obligations (UK GDPR Art. 28)
The Processor agrees to:
- Process Personal Data only on documented instructions from the Controller (including via the platform configuration and these Terms).
- Ensure persons authorised to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see section 5).
- Respect conditions for engaging Sub-processors (see section 4).
- Assist the Controller in responding to data subject rights requests within 30 days.
- Delete or return Personal Data on termination, at the Controller’s election (within 30 days of termination).
- Provide all information necessary to demonstrate compliance and allow audits (with reasonable notice).
4. Sub-processors
The Controller grants general authorisation for the Processor to engage the Sub-processors listed in Schedule A. The Processor will give 14 days’ written notice before adding material new Sub-processors. The Controller may object on reasonable data protection grounds within that window.
The Processor ensures each Sub-processor is bound by obligations equivalent to those in this DPA.
5. Security
Technical and organisational measures in place:
- All data in transit encrypted via TLS 1.2 or higher.
- Data at rest encrypted (AES-256) by Supabase and Google Cloud Storage.
- Admin portal access restricted by password authentication and session cookies.
- API keys and service account credentials stored as environment secrets (never hardcoded).
- Sentry error tracking configured to minimise PII in error payloads.
- Access to production infrastructure limited to authorised engineers.
6. International transfers
Some Sub-processors are based outside the UK (see Schedule A). These transfers are conducted under one of:
- UK adequacy regulations (for countries with adequacy decisions).
- UK International Data Transfer Agreements (IDTAs) or UK Addendum to EU SCCs.
The Controller can request copies of applicable transfer mechanisms by contacting hello@calltura.com.
7. Data subject rights
The Processor will forward data subject rights requests received directly to the Controller within 3 business days and will assist the Controller in fulfilling the request (e.g. by deleting or providing a transcript on instruction).
8. Data breach notification
The Processor will notify the Controller of any personal data breach without undue delay, and in any event within 72 hours of becoming aware. Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
9. Retention and deletion
Default retention periods: call transcripts and recordings are retained for 12 months. The Controller may delete individual records at any time via the portal. On termination of the service agreement, all Personal Data is deleted within 30 days unless the Controller requests an export first.
10. Liability
Each party’s liability under this DPA is subject to the limitation of liability in the main Terms of Service. Notwithstanding, neither party excludes liability for breaches of UK GDPR that result in regulatory fines or data subject compensation claims.
Schedule A — Sub-processors
| Sub-processor | Processing activity | Location | Transfer basis |
|---|---|---|---|
| Supabase Inc. | Database storage (transcripts, call logs, bookings) | EU (Frankfurt) | EU adequacy |
| LiveKit Inc. | Real-time audio infrastructure | US | UK IDTA / SCCs |
| Google LLC (Vertex AI) | Speech-to-text, language model, embeddings | US (us-central1) | UK IDTA / SCCs |
| Google LLC (GCS) | Call recording storage | Configured per-client | UK IDTA / SCCs |
| Cal.com Inc. | Appointment booking data | EU | EU adequacy |
| Telnyx LLC | UK telephony / SIP number | UK / EU | EU adequacy / UK domestic |
| Functional Software (Sentry) | Error monitoring | EU (Frankfurt) | EU adequacy |