Duty Agent020 3000 0000

Legal · Effective 4 September 2026 · v1.1

Data Processing Addendum

Version 1.1. Effective 4 September 2026. The Article 28 UK GDPR processor terms an agency accepts by signing up. Duty Agent processes caller data only on the agency's instructions, with named sub-processors, security measures, 72-hour breach notice and deletion on exit.

Draft note. Placeholders to fill before publishing
[LEGAL ENTITY NAME], [COMPANY NUMBER], [REGISTERED ADDRESS], [RETENTION MONTHS] (default 12), [POST-CANCELLATION DAYS] (default 30), [HOSTING PROVIDER], [EMAIL PROVIDER], [TELEPHONY PROVIDER], [PAYMENT PROVIDER], [LOCATION] (per provider), [TRANSFER MECHANISM FOR RETELL], [TRANSFER MECHANISM] (per other provider: "none needed, UK" or the safeguard relied on).
This is a draft. Bracketed placeholders are filled and a solicitor reviews the text before the first agency signs.

In plain English

You (the agency) decide that your out-of-hours calls are answered and recorded, so you are the controller. We record them for you, so we are your processor. This document is the contract UK GDPR says we must have. It says we only do what you tell us, who else touches the data, how we protect it, that we tell you within 72 hours of learning that something has gone wrong, and that we delete the data when you leave unless the law makes us keep something.

1.Definitions

Agreement
the Terms of Service between the Agency and Duty Agent, of which this Addendum forms part.
Data Protection Law
the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and any replacement of them.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing
as defined in the UK GDPR.
Agency Personal Data
Personal Data that we Process on the Agency's behalf under the Agreement, principally Call Data as defined in the Terms of Service.
Sub-processor
any third party engaged by us to Process Agency Personal Data.
Restricted Transfer
a transfer of Agency Personal Data to a country outside the UK that is not covered by UK adequacy regulations.

1.7 Other capitalised words have the meaning given in the Terms of Service.

2.Roles and scope

2.1 The Agency is the Controller of Agency Personal Data. Duty Agent is the Processor.

2.2 This Addendum applies to all Processing of Agency Personal Data by us under the Agreement. It is accepted by the Agency when it opens an Account and takes effect from that date.

2.3 Duty Agent is a separate Controller of Personal Data about Agency Users (staff names, work contact details, login and billing records). That Processing is governed by our Privacy Notice, not this Addendum.

3.Details of the Processing

ItemDetail
Subject matterAnswering, recording, transcribing and summarising telephone calls to the Agency's diverted Branch line(s), and delivering the results to the Agency
DurationFrom Branch activation until [POST-CANCELLATION DAYS] days after cancellation or termination of the Agreement, when deletion under clause 11 completes
Nature and purposeAutomated answering of inbound calls by an AI receptionist; audio recording; speech-to-text transcription; automated summarisation and lead qualification notes; storage; delivery to the Agency by email Digest and call log page; warm transfer of emergency calls to the Agency's on-call number
Types of Personal DataVoice recording; transcript; caller telephone number; date, time and duration; name and contact details stated by the caller; enquiry details (renting or buying, budget, areas, timing, property of interest); nature of any emergency described. Special category data is not requested and is Processed only if volunteered by the caller, and then only as part of the recording and transcript
Categories of Data SubjectCallers to the Agency's line: applicants, tenants, landlords, vendors, buyers, contractors and members of the public
Controller's instructionsSet out in this Addendum, the Terms of Service and the Agency's configuration in the Account (on-call number, hours, listings, tone notes, retention period). Any further instruction must be in writing to hello@dutyagent.co.uk

4.Processor obligations

We will:

4.1 Process Agency Personal Data only on the Agency's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by law, in which case we tell the Agency before Processing unless the law forbids it.

4.2 Tell the Agency immediately if, in our opinion, an instruction breaches Data Protection Law.

4.3 Ensure that every person we authorise to Process Agency Personal Data is bound by a duty of confidentiality.

4.4 Implement the security measures in clause 7.

4.5 Engage Sub-processors only under clause 6.

4.6 Assist the Agency, taking into account the nature of the Processing, in responding to Data Subject requests (clause 8).

4.7 Assist the Agency with its obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with the ICO, taking into account the information available to us.

4.8 Delete or return Agency Personal Data at the end of the Processing (clause 11).

4.9 Make available all information necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits (clause 10).

4.10 Keep a record of Processing activities carried out on the Agency's behalf.

4.11 Not use Agency Personal Data for any purpose of our own, including training general AI models, product analytics that identify a Data Subject, or marketing.

5.Controller obligations

The Agency will:

5.1 Ensure it has a lawful basis for the Processing and has documented it (we recommend legitimate interests with a written assessment for the recording, and pre-contract steps for capturing enquiry details).

5.2 Ensure its own privacy information tells Callers that out-of-hours calls are answered by an AI service on its behalf, are recorded, and are transferred to a processor in the United States.

5.3 Not instruct us to remove the AI disclosure or the recording notice from calls.

5.4 Not instruct us to Process special category data or to ask questions designed to elicit it.

5.5 Give instructions that comply with Data Protection Law.

5.6 Keep the Digest email addresses and Account access restricted to staff who need them, and tell us promptly when a staff member leaves.

6.Sub-processors

6.1 The Agency gives general written authorisation to the Sub-processors listed in clause 6.2 and to any replacement or addition notified under clause 6.3.

6.2 Current Sub-processors:

Sub-processorPurposeLocationTransfer mechanism
Retell AI, Inc.Voice AI platform: call handling, speech recognition, language model responses, text-to-speech, recording, transcriptionUnited States (AWS)[TRANSFER MECHANISM FOR RETELL]
Retell AI's own sub-processors (speech, language model, voice and telephony providers)As engaged by Retell AI to deliver its platformAs listed by Retell AIFlowed down under Retell AI's DPA
[TELEPHONY PROVIDER]UK number and call carriage[LOCATION][TRANSFER MECHANISM]
[HOSTING PROVIDER]Application, database and file storage[LOCATION][TRANSFER MECHANISM]
[EMAIL PROVIDER]Sending the Digest and account email[LOCATION][TRANSFER MECHANISM]
[PAYMENT PROVIDER]Billing (no Agency Personal Data about Callers)[LOCATION]not applicable

6.3 We will email the Agency's Account contacts at least 14 days before adding or replacing a Sub-processor that Processes Agency Personal Data. The Agency may object in writing within that period on reasonable data protection grounds. If we cannot resolve the objection, the Agency may cancel the affected Branch under the Terms of Service without charge for the following month.

6.4 We impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this Addendum, and we remain liable to the Agency for the Sub-processor's performance.

7.Security measures

We maintain at least the following technical and organisational measures:

7.1 Encryption of Agency Personal Data in transit (TLS 1.2 or above) and at rest.

7.2 Access to the call log page only by magic link sent to a verified Agency email address; access to our infrastructure only by the founder using multi-factor authentication and unique credentials; no shared accounts.

7.3 Logical separation of each Agency's data so that a recording can be viewed only by the Agency it belongs to.

7.4 Retention limits configured at Retell AI matching clause 11.1, with automatic deletion.

7.5 Access logging on the call log page and on infrastructure; review on suspicion of misuse.

7.6 Backups encrypted and held for no longer than the retention period plus 30 days.

7.7 A written incident procedure that meets clause 9.

7.8 Use of Sub-processors that hold independent security attestations where available (Retell AI reports SOC 2 Type 2).

7.9 Review of these measures at least annually and after any Personal Data Breach.

8.Data Subject requests

8.1 If we receive a request from a Data Subject relating to Agency Personal Data (for example to hear or delete a recording), we will pass it to the Agency within one Working Day and will not respond on the substance unless the Agency instructs us to.

8.2 On the Agency's instruction we will locate, provide a copy of, correct, restrict or delete the relevant Agency Personal Data within 5 Working Days, so that the Agency can meet its one-month deadline.

8.3 There is no charge for reasonable assistance under this clause.

9.Personal Data Breach

9.1 We will notify the Agency without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Agency Personal Data.

9.2 The notification will describe, as far as we know at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We will send further information as it becomes available.

9.3 We will co-operate with the Agency and take reasonable steps the Agency directs to contain and remedy the breach.

9.4 We will not notify the ICO or Data Subjects on the Agency's behalf unless the Agency asks us to in writing.

10.Audit

10.1 On written request, no more than once in any 12-month period (or more often after a Personal Data Breach or where required by a regulator), we will provide the information reasonably necessary to demonstrate compliance with this Addendum, including our record of Processing, security measures, Sub-processor contracts (or the relevant extracts) and any third-party attestations we hold.

10.2 If that information is not sufficient, the Agency or an independent auditor bound by confidentiality may audit our Processing on 30 days' written notice, during Working Days, at the Agency's cost, and in a way that does not disrupt the Service or expose other Agencies' data.

10.3 For Sub-processors we will make available the audit reports and certifications they provide to us.

11.Retention and deletion

11.1 Unless the Agency instructs a shorter period in the Account, we retain Agency Personal Data for [RETENTION MONTHS] months from the date of each call and then delete it.

11.2 Within [POST-CANCELLATION DAYS] days after cancellation or termination of the Agreement the Agency may download its recordings and transcripts. At the end of that period, or sooner on written request, we delete all Agency Personal Data from our systems and instruct Sub-processors to delete their copies, unless UK law requires us to keep it.

11.3 We will confirm deletion in writing on request.

11.4 Deletion from backups follows the backup cycle in clause 7.6.

12.Restricted Transfers

12.1 The Agency authorises the Restricted Transfer to Retell AI in the United States on the terms in clause 6.2.

12.2 We will not make any other Restricted Transfer without the Agency's prior authorisation under clause 6.3, and only with an appropriate safeguard under Chapter V UK GDPR (UK adequacy regulations, the ICO International Data Transfer Agreement, or the ICO Addendum to the EU Standard Contractual Clauses) and a transfer risk assessment where required.

12.3 On request we will provide a copy of the safeguard relied on.

13.Liability

13.1 Each party's liability under this Addendum is subject to the limits and exclusions in the Terms of Service, except that nothing limits either party's liability to a Data Subject under Article 82 UK GDPR.

13.2 The Agency is responsible for any fine or claim arising from its own instructions or from its failure to meet clause 5.

14.General

14.1 If this Addendum conflicts with the Terms of Service on a data protection matter, this Addendum prevails.

14.2 We may update this Addendum to reflect changes in Data Protection Law or ICO guidance by giving 30 days' notice by email. Changes that reduce the Agency's protection require the Agency's agreement.

14.3 This Addendum is governed by the law of England and Wales.

Contact

We would rather hear about a problem than lose you quietly. Every message to the address below is read by a person.

Post
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Post is checked weekly; email is faster.
Complaints
Email hello@dutyagent.co.uk with "Complaint" in the subject line. Complaints are acknowledged within 5 working days and answered in full within 20.
Company
Duty Agent is a trading name of [LEGAL ENTITY NAME], a company registered in England and Wales, company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]. ICO registration [ICO REGISTRATION NUMBER].

Version history

DateVersionChange
4 September 20261.0First version
4 September 20261.1Wording review: claims aligned with the site, asides no stronger than their clauses