Data processing agreement
Effective 15 August 2026
When someone rings your business, your AI receptionist handles their personal information — their number, their voice, their message. Under UK data protection law, youare the controller of that information (they’re your callers, calling your business) and GoReceptionist Ltdis your processor, handling it only to run your receptionist. The law — UK GDPR Article 28 — requires a written agreement between us saying exactly what that means. This is that agreement, in plain English, with the formal wording alongside where it’s needed. It forms part of our terms of service and sits alongside our privacy policy. Questions: email info@goreceptionist.co.uk.
The processing, at a glance
- What we process:your callers’ phone numbers (calling and callback), call recordings and their transcripts, AI-written call summaries, and the details callers give the receptionist — typically a name, a callback number, and a description of the job. When a caller books an appointment, the booking (name, number, job, time) too.
- Whose data it is: people who call your business — and anyone whose details a caller mentions on the call.
- Why we process it:to answer your calls, take messages, book appointments, and show you all of it in your dashboard and your summary emails. Nothing else — never advertising, never selling, and we never use it to train AI models. What the AI providers themselves may do under their own published policies is stated plainly in our privacy policy’s “How AI is involved” section.
- For how long:for as long as your account is open. What happens when it closes is in “When the service ends” below.
- Your side of the deal: you make sure you have the right to have your business calls answered and recorded this way, your own privacy notice reflects it, and the instructions you give us are lawful ones.
We act on your instructions
We only process your callers’ data to do what you’ve asked us to do: run the receptionist the way you’ve configured it in your dashboard. Your documented instructions are this agreement, your dashboard settings, and anything you ask us in writing. And if you ever instruct us to do something we believe breaks data protection law, we’ll tell you instead of doing it — the standing example is the recording announcement, which the terms already say we will not remove for anyone.
In formal terms: We process personal data only on your documented instructions, including with regard to transfers to third countries, unless required to do otherwise by law — in which case we inform you of that requirement before processing unless the law prohibits it. We will immediately inform you if, in our opinion, an instruction infringes UK data protection law.
Who can access it, and confidentiality
GoReceptionist is a small company: the people authorised to access caller data are its staff — today, its director — and they are bound to confidentiality. Access happens for three reasons only: running the service, fixing problems, and checking quality. Each business’s data is separated at the database level, so one customer can never see another’s calls.
How we keep it secure
- Everything travels over encrypted connections (HTTPS) — the website, the dashboard, and every call to every provider.
- Separation is enforced by the database itself, not just by application code: row-level security policies mean each business's session can only ever read its own calls and bookings, and internal records (billing, registrations, acceptance records) have no customer access at all.
- Call recordings are never exposed publicly: playback goes through an authenticated route that checks the recording belongs to the logged-in business before serving a byte.
- Every webhook and callback into our systems is authenticated — payment events, telephony callbacks and call reports all carry verified signatures or secrets, compared in constant time.
- Access keys and secrets live in environment configuration, never in code, and are rotated if ever exposed.
- Data minimisation is structural, not aspirational: when a repeat caller rings, the receptionist's memory is handed only a booked day and time — the code never fetches the previous caller's name or job, so the AI cannot reveal what it was never given. Summary emails never contain recording links.
The companies that help us (sub-processors)
Running an AI receptionist takes specialist companies, and each one below handles some part of your callers’ data under contract — with us directly, or with the provider we engage it through: the three AI engines (Deepgram, OpenAI and ElevenLabs) work under contract with Vapi, not with us. By agreeing to this DPA you authorise the list below. If we add or change a company we work with directly, we’ll email you at least 30 days before it starts handling your callers’ data — and if you’re not happy with the change, you can cancel before it takes effect. For the AI engines engaged through Vapi, we pass on any change Vapi announces as soon as we learn of it — we can’t promise more warning than we’re given ourselves.
In formal terms: You grant general written authorisation for the sub-processors listed in this agreement. We will inform you of any intended addition or replacement of a sub-processor we engage directly at least 30 days in advance, giving you the opportunity to object by terminating the service before the change takes effect. For sub-processors engaged by Vapi, we will pass on any notice we receive without undue delay. We impose data protection obligations consistent with those in this agreement on each sub-processor we engage directly. Where a sub-processor is engaged by another processor rather than by us — as Vapi engages the AI engines — UK GDPR Article 28(4) requires the engaging processor to impose the same obligations. Either way, we remain fully liable to you for the performance of the whole chain.
Vapi — USA
Runs the AI receptionist during the call; stores call recordings and transcripts. Engages Deepgram, OpenAI and ElevenLabs (below) on its own accounts to do it.
Twilio — USA
Provides your receptionist's UK phone number and carries the call.
Deepgram — USA
Converts the caller's speech to text during the call. Engaged through Vapi, which holds its contract.
OpenAI — USA
The AI language model that decides what the receptionist says. Engaged through Vapi, which holds its contract.
ElevenLabs — USA
Provides the receptionist's voice. Engaged through Vapi, which holds its contract.
n8n — Germany
Moves finished call details from the call system into our database.
Supabase — United Kingdom (London)
Our database — where call records and bookings live.
Vercel — USA (global infrastructure)
Hosts the website, the dashboard, and the code that processes calls and bookings.
Resend — USA
Sends your call summary and booking alert emails, which contain caller details and transcripts.
Google — USA
Only if you connect Google Calendar: booked appointments (caller name and job in the event) are written into your calendar.
One deliberate absence: Stripe handles your subscription payments, which is yourdata, not your callers’ — for that we’re the controller, and it’s covered by the privacy policy rather than this agreement.
Helping with your callers’ rights
Your callers can ask you — or us directly — for a copy of their data, or for it to be corrected or deleted. When a request reaches us, we help; when it reaches you, tell us and we’ll do our part. Here’s what deletion actually involves, because a caller’s details can live in three places:
- The call record — recording, transcript and summary. We delete our records, and we instruct Vapi (which stores the recording itself) to delete theirs.
- The booking record— if they booked an appointment, their name, number and job description are on the booking. We erase those details, and if you’d like, the calendar event too (or you can delete it from your own calendar).
- The receptionist’s memory — when a repeat caller is recognised, that comes from the booking record, not a separate store. Erasing the booking details silences it automatically; there is nothing extra to wipe.
Our timings: we action a documented erasure request in our own systems within 7 days, issue instructions to the relevant sub-processors at the same time, and confirm the outcome to you within 30 days — comfortably inside the one calendar month the law gives you to answer the caller.
In formal terms: Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests for exercising data subjects’ rights under Chapter III of the UK GDPR.
If something goes wrong
If we become aware of a personal data breach affecting your callers’ data, we’ll tell you within 72 hours— with what we know at that point: what happened, whose data and roughly how much, what we’re doing about it, and what we suggest you do. We keep you updated as we learn more, and we help with anything you need to tell the ICO or your callers. If you’re doing a data protection impact assessment that touches the receptionist, we’ll answer what you need for it.
In formal terms: We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting personal data processed under this agreement, and assist you in ensuring compliance with your obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the processing and the information available to us.
When the service ends
When your account closes, we delete your callers’ data — recordings, transcripts, summaries and booking details — from our systems and instruct our sub-processors to do the same, exactly as our terms and privacy policy promise. If you want a copy of anything first, ask before the account closes and we’ll provide it in a commonly used format — once deleted, it can’t be brought back. The only records that survive are the ones the law requires us to keep, such as invoicing records — and those are about you, not your callers.
Showing our work
If you need to check we’re holding up our end — for your own compliance records, or because your own customers ask — start with paper: we’ll answer written questions and share the relevant documentation (this agreement, our security overview, our sub-processor arrangements) within 30 days, free of charge. If that genuinely isn’t enough, you can audit us: once in any 12 months, on 30 days’ notice, remotely, during business hours, at your cost, and never touching other customers’ data. Worth knowing: we don’t run our own data centres — the infrastructure is Supabase’s and Vercel’s, and their own security certifications cover that layer.
In formal terms: We make available to you all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable conditions of notice, frequency, scope, confidentiality and cost as described here.
International transfers
Our database is in London, so your callers’ records rest in the UK — a region we have verified, not assumed. The live call, though, is processed by providers in the United States, and recordings are stored there — the privacy policy says this openly, and it’s true. Where your callers’ data leaves the UK, the safeguard depends on the provider, and we have checked provider by provider rather than generalised: Twilio and Vercel hold active certifications under the UK Extension to the EU–US Data Privacy Framework (checked against the official register), and the agreements that bind our direct providers — Twilio, Supabase, Vercel and Resend — incorporate standard contractual clauses with the UK Addendum, as does Vapi’s according to its published transfer statement; n8n processes only within the EU, which UK law treats as adequate without more. For the three AI engines engaged through Vapi, the safeguards sit in Vapi’s contracts with them, not in agreements of ours — that is how UK law arranges responsibility down a processor chain, and we would rather say so plainly than claim agreements we don’t hold. You authorise these transfers as part of this agreement.
How this fits with the terms
This agreement is part of our terms of service and is agreed the same way — when you create your account. If the terms and this agreement ever say different things about personal data, this agreement wins on that subject. Everything else — payment, liability, cancellation, governing law (England and Wales) — lives in the terms and applies here too. If we change this agreement, the same rules as the terms apply: we update this page and the date at the top, and significant changes are emailed to you at least 30 days ahead.
Who we are: GoReceptionist Ltd, a company registered in England and Wales (company number 17228440), registered office: 94 Harbour Way, Folkestone, England, CT20 1NB. We operate www.goreceptionist.co.uk. Contact: info@goreceptionist.co.uk.