Data Processing Agreement

Draft updated 8 August 2026 · qualified UK legal review required before paid launch

This is the launch contract draft, not legal advice. It records the intended UK GDPR controller/processor terms and must be approved with the company’s exact legal identity, registration details and transfer schedules before checkout is enabled.

1. Parties, roles and duration

TRADEMASON LTD (company number 17253179), registered at 7 Park Way, Wolverhampton, England, WV11 2NA, provides TradeMason Response. The business subscribing to TradeMason Response is the controller for personal data supplied by callers and other people contacting that business. TradeMason acts as processor for that data. TradeMason remains controller for its own account administration, billing, security, fraud-prevention and support records.

Processing begins when the business configures or uses Response and continues until the service ends and controller data is returned or deleted in accordance with section 9, subject to lawful retention.

2. Subject matter, nature and purpose

TradeMason processes data to receive conditionally forwarded unanswered calls, provide a clearly disclosed AI voice interaction, exchange supported SMS messages, transcribe and structure information supplied by the caller, prepare a callback brief, notify authorised business recipients, provide account history and usage information, secure the service and support the controller.

Response is decision-support. It does not independently accept work, set a final price, promise attendance, confirm availability or make a legally or similarly significant decision about a caller. The controller retains meaningful human review and final decision-making.

3. Categories of people and data

Data subjects may include callers, prospective customers, existing customers, suppliers, workers and other people whose details a caller includes in an enquiry.

Personal data may include telephone number, name, postcode, job description, urgency stated by the caller, access information, callback preference, message and transcript content, structured qualification answers, notification destination, delivery metadata, call/session timing and service audit records. Raw audio is not intentionally retained in the launch configuration.

The controller must not instruct Response to collect special-category data, criminal-offence data, payment-card data or information that is unnecessary for the enquiry unless a documented lawful basis, risk assessment and suitable safeguards are in place.

4. Documented instructions

TradeMason will process controller data only on documented instructions contained in the service configuration, these terms and written support instructions, unless UK law requires otherwise. If legally permitted, TradeMason will tell the controller before carrying out a processing requirement imposed by law.

If TradeMason reasonably believes an instruction infringes data protection law, it may pause the affected processing and notify the controller while the issue is reviewed.

5. Confidentiality and security

TradeMason will ensure that people authorised to process controller data are bound by confidentiality duties. Technical and organisational measures include tenant separation through row-level security, least-privilege service identities, provider-webhook validation, secret isolation, encryption in transit, provider-supported encryption at rest, bounded rate and concurrency controls, restricted administrative access, retention jobs, audit evidence, backup arrangements and tested fail-closed service switches.

No internet service can promise absolute security. Security measures may evolve where the replacement provides an equivalent or stronger level of protection.

6. Sub-processors

The planned launch sub-processors are Twilio for telephone and messaging; OpenAI for real-time AI voice and structured extraction; Supabase for database, authentication and storage; Microsoft Azure for hosting, gateway and background processing; Stripe for subscription billing; and Resend for transactional email. Limited privacy-preserving website analytics may also be used where documented in the Privacy Policy.

TradeMason will maintain the production sub-processor register, impose equivalent data-protection obligations, remain responsible for sub-processor performance under this agreement and give appropriate notice before adding or replacing a material sub-processor. The controller may raise a reasonable data-protection objection during the notice period.

7. International transfers

Where controller data is transferred outside the UK, TradeMason will use an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary measures where required. The final launch schedule must identify relevant provider locations and transfer safeguards.

8. Assistance, rights and incidents

Taking account of the nature of processing, TradeMason will provide reasonable assistance with data-subject access, correction, deletion, restriction, objection and portability requests; security obligations; data-protection impact assessments; prior consultation; and regulator enquiries.

TradeMason will notify the controller without undue delay after becoming aware of a personal-data breach affecting that controller’s Response data and provide available information needed for the controller’s assessment and notification duties. The controller remains responsible for deciding whether it must notify individuals or the regulator.

9. Retention, return and deletion

Ordinary enquiry history uses a six-month launch retention period. Voice transcript segments are scheduled for deletion after 30 days. Duplicated notification subject/body content is redacted after 7 days while limited delivery evidence may remain. Other controller data is retained for the configured service period and legitimate support, security or contractual needs.

The controller can download an organisation-scoped machine-readable export from Settings. An owner can also record an account-deletion request. TradeMason will verify identity, scope, subscription state and lawful retention before deletion, then return or delete controller data at the controller’s choice where technically and legally applicable. Limited billing, suppression, fraud-prevention, security or legal evidence may be retained for the period required.

10. Audit and compliance information

TradeMason will make available reasonable information needed to demonstrate compliance and support proportionate audits or inspections. Audits must protect other customers, provider security and confidential information, avoid unreasonable disruption, and use existing independent assurance before requiring duplicative testing where appropriate.

11. Order of precedence and contact

If this agreement conflicts with general service terms about processing controller data, this agreement takes priority for that processing. Questions and data-protection requests can be sent to support@trademason.co.uk.