CORE CALL LTD DATA PROCESSING AGREEMENT (DPA) Last Updated: 19 June 2026 PARTIES This Data Processing Agreement (“DPA”) forms part of the agreement between Core Call Ltd (“Processor”) and the Customer (“Controller”). This DPA applies where Core Call processes Personal Data on behalf of the Customer in connection with the services provided. DEFINITIONS For the purposes of this DPA: “Controller” means the party determining the purposes and means of processing Personal Data. “Processor” means the party processing Personal Data on behalf of the Controller. “Personal Data” has the meaning given under applicable UK data protection legislation. “Data Protection Laws” means all applicable data protection and privacy legislation including the UK GDPR and Data Protection Act 2018. “Personal Data Breach” shall have the meaning given under applicable Data Protection Laws. SCOPE OF PROCESSING Core Call may process Personal Data including: • Caller names • Telephone numbers • Email addresses • Site contact information • Engineer information • Customer account information • Call recordings • Call transcripts • Incident information • Job information • Client portal user information Processing activities may include: • Collection • Recording • Storage • Retrieval • Analysis • Transmission • Deletion PURPOSE OF PROCESSING Core Call processes Personal Data solely for the purpose of: • Delivering services • Managing incidents • Dispatching engineers • Providing customer communications • Operating the client portal • Maintaining service security • Providing reporting and analytics • Supporting customer requests PROCESSOR OBLIGATIONS Core Call shall: • Process Personal Data only on documented instructions from the Customer • Comply with applicable Data Protection Laws • Implement appropriate technical and organisational security measures • Ensure authorised personnel are subject to confidentiality obligations • Take reasonable steps to protect Personal Data SECURITY MEASURES Core Call shall maintain appropriate safeguards including: • Access controls • Password protection • Encryption where appropriate • Secure cloud infrastructure • Monitoring and logging systems • Security procedures and policies • Role-based access controls • Reasonable measures to restrict access to authorised personnel only CONFIDENTIALITY Core Call shall ensure that any personnel authorised to process Personal Data are subject to confidentiality obligations. CALL RECORDING DATA Call recordings and transcripts may contain Personal Data and operational information. Core Call shall process such information solely for: • Service delivery • Quality assurance • Incident management • Compliance purposes • Customer support AI PROCESSING Core Call may use artificial intelligence providers to assist with: • Call transcription • Fault classification • Incident processing • Service improvements The Customer acknowledges that information submitted through the services may be processed by such providers in accordance with applicable Data Protection Laws. While Core Call takes reasonable steps to ensure appropriate safeguards are in place, AI-generated outputs may contain errors or inaccuracies and should not be relied upon as the sole basis for operational, commercial or safety-critical decisions. SUBPROCESSORS The Customer authorises Core Call to use subprocessors where reasonably required to deliver services. Subprocessors may include: • Twilio • OpenAI • Supabase • Email service providers • Hosting providers • Messaging providers Core Call shall take reasonable steps to ensure subprocessors provide appropriate protection for Personal Data. Core Call may add, replace or remove subprocessors from time to time. An up-to-date list of approved subprocessors shall be made available upon reasonable request. INTERNATIONAL DATA TRANSFERS Customer data may be stored and processed within: • The United Kingdom • The European Economic Area • Other jurisdictions used by approved subprocessors Where Personal Data is transferred outside the United Kingdom, Core Call shall implement appropriate safeguards in accordance with applicable Data Protection Laws. CUSTOMER RESPONSIBILITIES The Customer shall: • Ensure it has a lawful basis for processing Personal Data • Provide required notices to data subjects • Obtain any required consents • Ensure submitted data is accurate and lawful DATA SUBJECT RIGHTS Core Call shall provide reasonable assistance to the Customer in responding to requests relating to: • Access requests • Correction requests • Deletion requests • Restriction requests • Data portability requests • Objection requests PERSONAL DATA BREACHES In the event of a Personal Data Breach affecting Customer Personal Data, Core Call shall: • Take reasonable steps to contain and investigate the breach • Notify the Customer without undue delay after becoming aware of the breach where required by law • Provide available information regarding the breach • Cooperate with reasonable requests relating to breach management GOVERNMENT REQUESTS Where legally permitted, Core Call shall notify the Customer of any legally binding request from a public authority requiring disclosure of Customer Personal Data. AUDITS AND INFORMATION Upon reasonable request, Core Call shall provide information reasonably necessary to demonstrate compliance with this DPA. Audit requests must be: • Reasonable • Proportionate • Subject to confidentiality obligations • Conducted in a manner that does not unreasonably interfere with Core Call’s business operations or security requirements BACKUPS AND DISASTER RECOVERY Core Call maintains reasonable backup and disaster recovery procedures designed to support: • Service continuity • Data protection • Operational resilience DATA RETENTION Core Call shall retain Personal Data only for as long as reasonably necessary to: • Deliver services • Comply with legal obligations • Resolve disputes • Maintain security Retention periods may vary depending on the nature of the information. RETURN OR DELETION OF DATA Upon termination of services and subject to legal obligations, Core Call may: • Return Customer data where reasonably practicable • Delete Customer data in accordance with retention policies • Retain information where required by law Where Customer data is returned, it may be supplied in a commonly used electronic format determined by Core Call. LIABILITY Liability arising under this DPA shall be subject to the liability limitations contained within the applicable Customer Service Agreement unless otherwise required by law. TERM This DPA shall remain in effect for as long as Core Call processes Personal Data on behalf of the Customer. GOVERNING LAW This DPA shall be governed by the laws of England and Wales. Any dispute arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales. CONTACT Core Call Ltd Company Registration Number: 17285444 ICO Reference: ZC178387 Website: www.corecall.co.uk Support: support@corecall.co.uk England & Wales
← Back to Home