Data processing agreement

Last updated 4 September 2026

This agreement sets out how Redialler processes personal data on your behalf. It applies to every customer and forms part of the Terms of Service. It is written in plain English so you can read it without a lawyer, though you are welcome to bring one.

1. Parties and roles

This agreement is between the customer who holds a Redialler account (the customer) and Redialler (Redialler). It forms part of the Terms of Service.

For the personal data of the people you call and the people in your CRM, the customer is the controller and Redialler is the processor. Redialler processes that data only on the customer's instructions.

2. Subject matter and duration

The subject matter is the personal data Redialler handles to place calls, record and transcribe them where enabled, and save results to the customer's CRM.

Processing lasts for as long as the customer has an active account, plus the deletion period in section 10.

3. Nature and purpose of processing

Redialler reads contact details from the customer's CRM, places calls through Twilio, logs call events, records and transcribes calls where the customer has enabled it, produces notes from transcripts, and writes outcomes, notes, recordings, and tasks back to the CRM.

The purpose is to let the customer's team make and log outbound calls. Redialler does not process the data for any other purpose.

4. Categories of data subjects and data

Data subjects: the customer's staff who use Redialler, and the contacts, leads, and customers the customer calls.

Data: names, phone numbers, email addresses, company names, job titles, CRM notes, call times and outcomes, call audio where recording is enabled, transcripts, and generated notes.

5. Processor obligations

Instructions: Redialler processes personal data only on the customer's documented instructions, which include the Terms, this agreement, and the settings the customer chooses in the product. Redialler will tell the customer if it believes an instruction breaks data protection law.

Confidentiality: everyone at Redialler who can access personal data is bound by a duty of confidentiality.

Security: Redialler applies the measures in section 8.

Sub-processors: Redialler uses only the sub-processors in section 7. Redialler will give notice before adding or replacing one, and the customer may object.

Assistance: Redialler will help the customer respond to data subject requests, carry out impact assessments, and deal with regulators, to the extent Redialler can.

Deletion: Redialler deletes or returns personal data as set out in section 10.

Audit: Redialler will provide the information a customer reasonably needs to show compliance, and will allow audits by the customer or an auditor the customer appoints, on reasonable notice and no more than once a year unless a regulator requires it.

6. Sub-processors

Twilio: carries voice calls, provides phone numbers, and holds recordings while they are being processed.

Attio: the customer's CRM. Holds contacts, notes, outcomes, and saved recordings and transcripts.

Clerk: sign-in and user accounts for the customer's staff.

OpenRouter: transcribes call audio and produces cleaned-up notes from transcripts.

Convex: stores runtime state such as queues, sessions, call logs, and number pool state.

Vercel: hosts the application.

7. International transfers

Some sub-processors operate in the United States. Where personal data protected by UK or EU law is transferred outside the UK or EEA, Redialler relies on standard contractual clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, as required.

8. Security measures

All data in transit is encrypted with TLS. CRM and carrier credentials are encrypted at rest. Access to production systems is limited to named staff and protected by multi-factor sign-in.

Recordings are held only during processing and are removed from Redialler once saved to the customer's CRM. Reps see only their own queues and calls unless the customer gives them wider access.

Redialler reviews these measures as the product changes and will not reduce the overall level of protection during the term.

9. Breach notification

If Redialler becomes aware of a personal data breach affecting the customer's data, Redialler will tell the customer without undue delay, and in any case within 72 hours of becoming aware.

The notice will describe what happened, the data and people likely affected, the likely consequences, and the steps taken or proposed. Redialler will give further details as they become known.

10. Deletion and return

When the customer closes its account, or asks in writing, Redialler deletes all personal data it holds for the customer within 30 days, unless law requires Redialler to keep it.

Before deletion, the customer can export call logs from the product. Recordings, transcripts, and notes already saved to the customer's CRM are not affected, because they live in the CRM, not in Redialler.

11. Liability and precedence

Each party's liability under this agreement is subject to the limits in the Terms of Service.

If this agreement and the Terms conflict on a data protection matter, this agreement prevails. On every other matter, the Terms prevail.

This agreement is governed by the law of England and Wales.

12. Contact

For anything about this agreement, data subject requests, or to ask for a signed copy, email hello@redialler.com with the subject Data processing.

Questions about this page? Email hello@redialler.com.