Data processing agreement
This applies where we answer calls on your behalf. You are the controller of your customers' information; we are your processor.
Version 1.0. Effective 30 July 2026.
This Data Processing Agreement forms part of the agreement governing the provision of the BuilderVoice AI service between BuilderVoice AI, referred to as the Processor, and the person or organisation identified as the customer in the applicable order form, subscription agreement or online account, referred to as the Customer or the Controller.
1. Purpose and status
1.1 This DPA applies where BuilderVoice AI processes personal data on behalf of the Customer in connection with the BuilderVoice AI service.
1.2 For personal data relating to callers, customers, prospective customers and other persons contacting the Customer, the Customer is the controller and BuilderVoice AI is the processor.
1.3 This DPA is intended to satisfy the requirements applicable to contracts between controllers and processors under Article 28 of the UK GDPR.
1.4 This DPA must take effect before BuilderVoice AI handles the Customer's first live call containing personal data.
1.5 BuilderVoice AI may process certain information as an independent controller where it determines the purposes and means of processing, including account administration, billing, fraud prevention, information security, legal compliance and BuilderVoice AI's own marketing activities. Such processing is governed by the BuilderVoice AI Privacy Policy and not by this DPA.
3. Processing instructions
3.1 BuilderVoice AI shall process Customer Data only on the Customer's documented instructions, as necessary to provide, maintain, secure and support the Services, as configured by the Customer through its account, or where required by applicable law.
3.4 BuilderVoice AI shall notify the Customer if, in BuilderVoice AI's reasonable opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing until the instruction is amended, withdrawn or confirmed as lawful.
3.5 BuilderVoice AI shall not sell Customer Data, use it for unrelated advertising, permit a Sub-processor to use it to train a general-purpose artificial-intelligence model unless the Customer has expressly authorised that use in writing, or use it for an incompatible purpose.
5. Customer responsibilities
5.1 The Customer is responsible for complying with its obligations as controller, including establishing a lawful basis, providing privacy information to callers, and assessing whether a Data Protection Impact Assessment is required.
5.4 The Customer shall inform callers that calls may be answered by an AI-assisted receptionist and may be transcribed. The Customer acknowledges that the Services do not automatically announce at the start of each call that the receptionist is an AI system. If a caller asks whether the receptionist is an AI system, the receptionist is configured to confirm this accurately and clearly.
5.5 The Customer is responsible for ensuring that its call greeting, website privacy notice and other customer-facing communications provide sufficient information about the use of the AI-assisted receptionist and call transcription.
5.6 The Customer shall not configure the Services to make final decisions that produce legal or similarly significant effects without first informing BuilderVoice AI and implementing all legally required safeguards.
9. Special Category Data and vulnerable callers
9.1 The Services are not designed to solicit Special Category Data. However, callers may disclose health, disability or vulnerability-related information without being asked.
9.2 The Services may flag operational circumstances indicating possible vulnerability or urgency, including a person being without heating, hot water or essential facilities.
9.3 BuilderVoice AI shall limit the processing of such information to handling and escalating the enquiry, restrict access according to role and need, avoid making medical diagnoses, and not use vulnerability information for marketing.
9.4 The Customer is responsible for determining and documenting any applicable Article 6 lawful basis, Article 9 condition and additional Data Protection Act 2018 requirements.
10. Live audio and transcripts
10.1 BuilderVoice AI processes live call audio transiently for the purpose of speech recognition, transcription and generating conversational responses.
10.2 Audio recording is not currently available. The Services do not retain call audio, and the Customer cannot enable audio recording through the Services.
10.3 Live audio may be transmitted to authorised telephony, speech-processing and artificial-intelligence providers as necessary to operate the conversation.
10.4 The Services create and retain a written transcript of the call. The transcript may be used to:
- understand and document the caller's enquiry;
- generate a call summary;
- extract structured lead information;
- identify apparent urgency or vulnerability;
- notify the Customer;
- support follow-up by the Customer; and
- investigate operational, security or service issues.
10.5 BuilderVoice AI uses separate providers for different stages of call processing. OpenAI currently supports live speech processing and transcription. DeepSeek currently processes completed call transcripts for post-call summarisation and structured information extraction.
10.6 If BuilderVoice AI introduces audio recording in the future, BuilderVoice AI shall, before making that functionality available, update this DPA and the applicable Sub-processor information, describe the storage location and retention arrangements, implement appropriate security and deletion controls, and provide Customers with sufficient information to update their caller disclosures and privacy notices.
11. Artificial intelligence and automated processing
11.2 Unless the Customer has purchased and specifically configured additional functionality, the Services do not confirm appointments, enter contracts on behalf of the Customer, determine final prices, decide whether a caller is eligible to receive a service, reject a customer, or make a solely automated decision producing a legal or similarly significant effect.
11.3 Appointment information captured by BuilderVoice AI is a request only. The Customer must confirm availability directly with the caller.
11.4 The Customer shall maintain meaningful human oversight of emergency flags, vulnerability flags, appointments, pricing, service eligibility and material customer decisions.
12. Sub-processors
12.1 The Customer gives BuilderVoice AI general written authorisation to appoint the Sub-processors listed below and to appoint replacement or additional Sub-processors in accordance with this clause.
12.3 BuilderVoice AI shall provide reasonable advance notice of a new Sub-processor that will materially process Customer Data.
12.4 The Customer may object on reasonable data protection grounds by contacting [PRIVACY EMAIL] within 14 days of notice.
| Provider | What they do | What they receive | Where |
|---|---|---|---|
| OpenAIIn use | Live speech recognition and conversational response during a call (Realtime API) | Live call audio, the resulting transcript, and the business brief supplied as context | United States, under the applicable transfer mechanism |
| DeepSeekNot currently enabled | Post-call summarisation and structured extraction; analysis of publicly available business websites | Full call transcripts, including caller name, telephone number, postcode, enquiry details and any special category data a caller volunteered; public website content | Mainland China. No UK adequacy regulationA restricted transfer. Requires an IDTA or UK Addendum and a documented transfer risk assessment before live call data is processed. |
| TwilioIn use | Telephony, phone numbers, call routing and SMS delivery | Telephone numbers, call metadata, call audio in transit, and the content of text messages | International, under the applicable transfer mechanism |
| RenderIn use | Application and database hosting | Account information, call records, transcripts and structured leads | Frankfurt, Germany |
| ResendNot currently enabled | Transactional email notifications | Recipient email address and notification content | United States, under the applicable transfer mechanism |
Status reflects the live configuration of this deployment at the time this page was loaded.
13. International transfers
13.1 BuilderVoice AI shall not make a restricted transfer of Customer Data unless the transfer complies with Applicable Data Protection Law.
13.3 BuilderVoice AI shall conduct and document a transfer risk assessment or equivalent data protection test where required.
13.5 BuilderVoice AI uses DeepSeek for post-call summarisation and structured extraction from completed call transcripts. This processing may include caller names, telephone numbers, postcodes, descriptions of problems at a property and information relating to apparent urgency or vulnerability.
13.6 Where DeepSeek processes Customer Data in mainland China, BuilderVoice AI shall not activate or continue such processing for live Customer calls unless:
- an appropriate international-transfer mechanism is in place, which may include the UK International Data Transfer Agreement or the UK Addendum to the European Commission Standard Contractual Clauses;
- BuilderVoice AI has completed and documented a transfer risk assessment or other legally required data protection test;
- the assessment concludes that the transfer provides protection that is not materially lower than that required under UK data protection law, taking account of any supplementary measures;
- appropriate contractual, technical and organisational safeguards have been implemented;
- the processing has been disclosed in the current Sub-processor list; and
- the Customer has been notified in accordance with clause 12.
13.7 If the requirements in clause 13.6 have not been satisfied, BuilderVoice AI shall disable DeepSeek processing of Customer call transcripts and use an alternative provider or provide the Services without DeepSeek-generated summaries.
13.8 Website analysis involving publicly available business information may be assessed separately from processing private caller information. BuilderVoice AI shall nevertheless consider whether personal data is contained in the relevant website content and whether an international-transfer safeguard is required.
14. Data Subject requests
14.1 Taking account of the nature of the processing, BuilderVoice AI shall provide reasonable assistance to enable the Customer to respond to requests concerning access, rectification, erasure, restriction, objection, portability where applicable, and safeguards relating to automated decision-making. Such assistance may be provided through manual technical or database operations where self-service or per-Data-Subject functionality is not available.
14.4 BuilderVoice AI may charge the Customer reasonable costs for assistance that requires manual database investigation or modification, is unusually complex or repetitive, requires information to be retrieved from multiple systems or Sub-processors, or falls outside standard account administration. BuilderVoice AI shall inform the Customer of any proposed charge before carrying out chargeable work, except where urgent action is reasonably required to prevent harm or comply with law.
16. Personal Data Breaches
16.1 BuilderVoice AI shall notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Data.
16.6 The Customer is responsible for deciding whether to notify the ICO, affected individuals or another authority.
17. Deletion, return and retention
17.1 Unless otherwise configured or agreed, BuilderVoice AI's standard operational retention settings are:
| Information | Standard retention |
|---|---|
| Call transcripts | 365 days |
| Call audio | Not retained |
| Structured leads and appointment requests | Subscription period and configured retention period |
| Account information | Account period plus a reasonable legal, tax and dispute period |
| Billing and transaction records | Normally up to 6 years after the relevant accounting period |
| Prospect records | While relevant for business development, subject to periodic review |
| Consent and permission records | For as long as needed to demonstrate the permission relied upon |
| Suppression records | As long as reasonably necessary to ensure the person is not contacted again |
| Security logs | According to security need and risk |
| Support records | For the account period and a reasonable period afterwards |
Transcript and recording periods are read from this deployment's configuration, not typed in by hand. Recording retention would be 30 days if recording were available.
17.2 The Customer may select shorter transcript or record-retention periods where supported by the Services.
17.3 On termination, BuilderVoice AI shall, at the Customer's request made within 30 days, provide the Customer's call records, transcripts and lead data in a structured, commonly used and machine-readable format, and delete Customer Data after the applicable account-closure period.
17.4 The Customer acknowledges that the export described in clause 17.3 may be prepared and provided through a manual process where an automated export function is not available.
17.5 BuilderVoice AI may retain information where required by law, to establish, exercise or defend legal claims, in secure backups until overwritten through the normal backup cycle, in security or audit records where continued retention is necessary and proportionate, or where the information has been irreversibly anonymised.
17.7 Unless otherwise agreed, the Customer must submit a request for data return within 30 days following termination. After that period, BuilderVoice AI may delete the Customer Data in accordance with its account-closure procedures.
Schedule 1: Details of processing
Subject matter. Provision of an AI-assisted telephone receptionist and enquiry-management service for the Customer.
Duration. For the subscription or trial period, plus applicable export, closure, backup and legal-retention periods.
Nature of processing. Collection; real-time audio transmission; speech recognition; transcription; conversational response generation; organisation; classification; structuring; storage; retrieval; consultation; post-call summarisation; structured information extraction; urgency and vulnerability flagging; lead creation; appointment-request capture; notification; manual or automated export; restriction; and deletion. BuilderVoice AI does not currently retain call audio.
Categories of Data Subject. Customers and prospective customers of the Customer; homeowners, tenants, landlords and property occupiers; family members, neighbours or carers calling for another person; suppliers and contractors; Customer personnel; and any other person calling the connected or diverted number.
Types of Personal Data. Name; telephone number; email address where supplied; address or postcode; property and occupancy information; details of plumbing, heating or property problems; appointment preferences and availability; call date, time and duration; telephone metadata; full or partial call transcript; AI-generated call summary; structured information extracted from the transcript; lead status and outcome; urgency or emergency flag; potential vulnerability flag; Customer notes; notification and communication records; technical logs and identifiers. Call audio is processed transiently but is not retained by BuilderVoice AI.
Special Category Data. Not intentionally requested. Callers may voluntarily disclose health, disability or other Special Category Data. The Services may record this within a transcript or operational vulnerability note.
Schedule 2: Technical and organisational measures
BuilderVoice AI maintains measures appropriate to its size, risk and processing activities, including: encryption of data in transit; encryption of stored production data where supported by the hosting provider; role-based access controls; authentication and secure credential management; separation of Customer accounts and tenant records; restricted production access; audit and security logging; monitoring of critical services and errors; secure software-development and code-review practices; dependency and vulnerability management; secure management of API keys and secrets; backup and recovery arrangements; incident detection and response procedures; data-retention and deletion processes; confidentiality obligations for personnel; Sub-processor due diligence; change management; business continuity arrangements proportionate to the Services; data minimisation within AI prompts and provider requests; and testing of access controls and deletion functionality.
Specific certifications are not claimed unless obtained and current.