Data Processing Agreement
Steady Bow ARROW Limited (trading as AI Phone Calls) and the Customer
UK GDPR Article 28 · Version 1.0 · Effective 13.08.26
How this Agreement applies
This Agreement forms part of the AI Phone Calls Terms of Service (the "Terms"). It applies automatically to every customer whose service involves ARROW processing personal data on the customer's behalf. By accepting the Terms, or by using the Service, the Customer also enters into this Agreement. No signature is needed.
If your organisation needs a countersigned copy for its records, email support@aiphonecalls.co.uk and we will execute one. A countersigned copy has the same content as this page as at the date of signature.
"ARROW", "we" and "us" mean Steady Bow ARROW Limited, a company registered in England and Wales under company number 16372439, whose registered office is at Office 3605xda, 60 Tottenham Court Road, London, England, W1T 2EW, trading as AI Phone Calls. "Customer" means the business that holds the account under the Terms.
Background
(A) ARROW provides a managed AI telephone answering service (the "Service") to the Customer under the Terms and the Customer's order or subscription (together the "Principal Agreement").
(B) In delivering the Service, ARROW processes personal data relating to people who telephone the Customer, and to people the Customer instructs ARROW to telephone.
(C) This Agreement records the terms required by Article 28(3) of the UK GDPR, and how personal data is transferred outside the United Kingdom in providing the Service.
(D) This Agreement forms part of, and is subject to, the Principal Agreement. On the subject of data protection, this Agreement prevails, as set out in clause 12.
1. Definitions
1.1 "UK GDPR" means the UK General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018, read with that Act and the Data (Use and Access) Act 2025, as amended or replaced from time to time.
1.2 "Call Data" means the personal data ARROW processes on the Customer's behalf in delivering the Service, as described in Annex 1.
1.3 "Restricted Transfer" means a transfer of personal data outside the United Kingdom that is subject to Chapter V of the UK GDPR.
1.4 "Addendum" means the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
1.5 "Sub-processor List" means the list ARROW maintains under clause 6.1 of the sub-processors authorised to process Call Data.
1.6 controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in the UK GDPR.
2. Roles of the parties
2.1 In respect of Call Data, the Customer is the controller and ARROW is the processor.
2.2 ARROW is a separate and independent controller of the Customer's account administration data, meaning the business contact details of the Customer's staff, billing records, support correspondence and aggregated statistics that identify no one. That processing is described in ARROW's privacy policy at aiphonecalls.co.uk/privacy-policy and is outside this Agreement.
2.3 Where the Customer is itself a processor acting for a third party controller, ARROW acts as a sub-processor, this Agreement applies with the necessary changes, and the Customer confirms it has that controller's authority to appoint ARROW.
3. Scope and duration
3.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex 1.
3.2 This Agreement takes effect on the date of the Principal Agreement or, if earlier, the date ARROW first processed Call Data for the Customer, and continues for as long as ARROW processes Call Data.
4. ARROW's obligations
4.1 Instructions. ARROW processes Call Data only on the Customer's documented instructions, including as to Restricted Transfers, unless required to do otherwise by law, in which case ARROW informs the Customer before processing unless the law prohibits it. The Principal Agreement, the Customer's approved call flow and configuration, and this Agreement are the Customer's complete documented instructions at the date of this Agreement.
4.2 Unlawful instructions. ARROW will tell the Customer immediately if, in its opinion, an instruction infringes data protection law, and may suspend the affected instruction until it is withdrawn, amended or confirmed.
4.3 Personnel. ARROW limits access to Call Data to those who need it to deliver the Service, ensures that every person it authorises to process Call Data has committed to a binding duty of confidentiality that continues after the end of their engagement, and briefs them on their data protection obligations.
4.4 Security. ARROW implements and maintains the technical and organisational measures in Annex 2, which are appropriate to the risk under Article 32 of the UK GDPR. ARROW may update them provided the level of protection is not reduced.
4.5 Data subject rights. ARROW assists the Customer by appropriate technical and organisational measures, taking into account the nature of the processing and insofar as this is possible, to respond to requests from data subjects exercising their rights under Chapter III of the UK GDPR. If ARROW receives such a request directly it notifies the Customer without undue delay, and does not respond itself except to direct the individual to the Customer.
4.6 Wider assistance. ARROW assists the Customer with its obligations under Articles 32 to 36 of the UK GDPR, including security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to ARROW.
4.7 Deletion and return. At the Customer's choice, ARROW deletes or returns Call Data in accordance with clause 8.
4.8 Information and audit. ARROW makes available all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and allows for and contributes to audits, including inspections, in accordance with clause 10.
4.9 No secondary use. ARROW does not sell Call Data and does not use it to train, fine-tune or improve any general purpose artificial intelligence model. ARROW may use Call Data to configure, test and improve the Customer's own agent, and may use aggregated data identifying neither any individual nor the Customer for service statistics.
5. The Customer's obligations
5.1 The Customer warrants that it has a valid lawful basis under Article 6 of the UK GDPR for the processing it instructs, and a condition under Article 9 for any special category data.
5.2 The Customer is responsible for giving callers, and people it asks ARROW to call, the information required by Articles 13 and 14 of the UK GDPR, including that calls are handled by an AI assistant, are recorded, and involve a transfer outside the United Kingdom. ARROW supplies suggested privacy notice wording as a convenience. It is not legal advice, and the Customer remains responsible for its own notices.
5.3 Where the Customer instructs outbound calls for direct marketing, it is responsible for compliance with the Privacy and Electronic Communications (EC Directive) Regulations 2003. The Customer acknowledges that the AI agent transmits synthesised rather than live speech, so such a call is capable of amounting to a call made by means of an automated calling system under regulation 19, requiring the subscriber's prior consent, and that screening against the Telephone Preference Service and Corporate Telephone Preference Service registers under regulation 21 is not on its own sufficient. The Customer will maintain consent records and suppression lists, and any direct marketing use of the Service must be agreed with ARROW in writing before it goes live.
5.4 The Customer will not instruct ARROW to process special category data or criminal offence data as a routine or designed feature of a call flow without first agreeing that processing with ARROW in writing.
6. Sub-processors
6.1 The Customer gives ARROW general written authorisation to appoint sub-processors. For privacy and security reasons ARROW does not publish the names of its sub-processors. ARROW maintains the Sub-processor List, recording for each sub-processor the legal entity name, the function performed, the country in which Call Data is processed and the transfer safeguard relied on, and provides the current version to the Customer on request to support@aiphonecalls.co.uk. The Sub-processor List is confidential information under the Principal Agreement, is for the Customer's own compliance purposes, and is not to be disclosed further except to the Customer's professional advisers or as data protection law requires. Annex 3 describes the functions the current sub-processors perform and the countries in which they process Call Data. Where the Sub-processor List and Annex 3 differ, the Sub-processor List governs, but only in respect of a change ARROW has notified under clause 6.2 or clause 6.3 and for which the applicable notice period has expired. No change to the Sub-processor List operates to reduce ARROW's obligations under this Agreement.
6.2 Before adding or replacing a sub-processor, before changing the country in which an existing sub-processor processes Call Data, and before changing the transfer safeguard relied on for an existing sub-processor, ARROW updates the Sub-processor List and gives the Customer at least 30 days' notice by email to the address in clause 14.2. The Customer may object on reasonable data protection grounds within that period. The sub-processor or change concerned will not be applied to the Customer's Call Data before the notice period has expired or, where the Customer objects, while that objection remains unresolved. If the objection cannot be resolved, the Customer may terminate the affected part of the Service on written notice, with a pro-rata refund of prepaid fees for the unused period. No notice is required to remove a sub-processor, or for a change of name or corporate details that does not change where or how Call Data is processed.
6.3 Where a change originates with a sub-processor that has given ARROW less than 30 days' notice of it, ARROW will notify the Customer within two working days of becoming aware and will pass on as much of the notice period as ARROW has itself received. The Customer's objection and termination rights under clause 6.2 apply over that shorter period. ARROW will not agree a shorter notice period with a sub-processor than that sub-processor's standard terms require. Where the change takes effect at the sub-processor regardless of ARROW's objection, ARROW will say so in its notice. In that case the Customer's remedy is to suspend or to terminate the affected part of the Service under clause 6.2, and ARROW's obligation is to notify, to object on the Customer's behalf, and to suspend processing of the Customer's Call Data through the affected sub-processor if the Customer requires it.
6.4 ARROW imposes on each sub-processor it appoints, by written contract, data protection obligations no less protective than those in this Agreement, including a requirement to impose equivalent obligations on any further sub-processor that party engages. ARROW remains fully liable to the Customer for each sub-processor's performance.
6.5 ARROW keeps a dated and sequentially numbered record of every version of the Sub-processor List, and retains that record for the term of this Agreement and six years afterwards. On the Customer's written request ARROW provides, within 10 working days, the version in force on any date the Customer specifies.
7. International transfers
7.1 The Customer instructs and authorises ARROW to make the Restricted Transfers described in Annex 4 for the purpose of delivering the Service.
7.2 Each Restricted Transfer ARROW makes is covered by an appropriate safeguard under Article 46 of the UK GDPR, being the Addendum or the safeguard identified for that sub-processor on the Sub-processor List, incorporated into ARROW's written contract with the sub-processor concerned. Where a sub-processor is engaged by another sub-processor rather than directly by ARROW, ARROW's contract requires equivalent safeguards to be imposed and evidence of them made available. ARROW will provide a copy of the transfer terms it has executed, and details of the safeguards notified to it for onward sub-processors, on request.
7.3 ARROW has carried out a transfer risk assessment for the transfer of Call Data to the United States, dated 19 March 2026, applying the data protection test in Chapter V of the UK GDPR as amended by the Data (Use and Access) Act 2025, namely whether the standard of protection in the destination country is materially lower than under UK data protection law. It is reviewed at least annually and on any material change in law or in the sub-processor's processing. A copy is available on request.
7.4 If ARROW becomes aware that a safeguard relied on is no longer effective, it will notify the Customer without undue delay and work with the Customer to find an alternative or, failing that, suspend the affected transfer.
7.5 If a transfer from the Customer to ARROW is itself a Restricted Transfer, the Addendum is incorporated into this Agreement with the Customer as exporter and ARROW as importer, the parties' details and Annexes 1 to 4 completing its Tables.
8. Retention, deletion and return
8.1 Call audio recordings, transcripts and platform call logs are retained for 30 days from the date of the call and then deleted automatically by the voice platform. This period is configured on every AI agent operated for the Customer.
8.2 Call metadata, meaning date, time, duration, direction, the caller's telephone number, the outcome, the sentiment score ARROW generates for service quality purposes, the cost, the AI agent used, ARROW's own record identifier, and a link to the call recording held on the voice platform, is retained in ARROW's operations records for the term of the Principal Agreement, for billing, dispute resolution and service management. ARROW holds no copy of the call audio and no transcript content in those records. The link is an address for the recording as stored by the voice sub-processor, not a copy of it, and ARROW removes the link when the recording it refers to is deleted under clause 8.1, so that no route to call audio is retained beyond that period. Within 30 days of termination or expiry of the Principal Agreement ARROW removes the caller's telephone number from those records, and retains the remaining fields, which identify no individual, for a further 12 months for billing and dispute resolution only.
8.3 Post-call summaries, notifications and lead records delivered to the Customer, or into the Customer's own systems, pass into the Customer's control on delivery, and the Customer is responsible for their retention and deletion.
8.4 Subject to the 30 day removal period in clause 8.2, on termination or expiry of the Principal Agreement, ARROW will, at the Customer's choice, delete or return all Call Data then held and delete all existing copies, including in backups, within 30 days. The Customer notifies its choice in writing before termination or within 10 working days afterwards; absent a choice, ARROW deletes. Where retention is required by law, ARROW retains the data only as long as required, processes it only for that purpose, and continues to protect it under this Agreement. Written confirmation of deletion or return is available on request.
8.5 The Customer may request earlier deletion of a specific call or of all calls at any time. ARROW will action the request within 10 working days and confirm in writing.
8.6 Where the Customer requires a different retention period for its own regulatory obligations, the parties may agree it in writing and ARROW will reconfigure the setting accordingly.
8.7 Call detail records generated at the telephony layer, comprising the calling and called numbers, the time and the duration of the call and containing no audio or transcript content, are retained by the telephony sub-processor under its own standard billing and regulatory retention period. Clause 8.4 applies to those records only to the extent that sub-processor permits deletion, and ARROW will request deletion on the Customer's behalf.
9. Personal data breach
9.1 ARROW will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Call Data.
9.2 The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences and the measures taken or proposed, with further information as it becomes available. ARROW will cooperate with the Customer in investigating and remedying the breach.
9.3 ARROW will not notify the Information Commissioner or affected data subjects on the Customer's behalf unless instructed in writing to do so.
10. Information and audit
10.1 ARROW will respond to reasonable written information requests about its processing, including its sub-processors' current security certifications and attestations and such sub-processor audit reports as ARROW is permitted to share.
10.2 The Customer, or an auditor mandated by the Customer and reasonably acceptable to ARROW, may audit and inspect ARROW's compliance once in any 12 month period, on 30 days' notice, during business hours, and without disrupting the Service or compromising other customers' data. A further audit may follow a personal data breach affecting Call Data or where a supervisory authority requires it. Each party bears its own costs.
10.3 Clause 10.2 gives the Customer rights in respect of ARROW's own processing operations. In respect of sub-processors, ARROW's obligation is limited to providing the information and reports described in clause 10.1, which reflects the audit rights available to ARROW under its own contracts with those sub-processors.
10.4 Where the Principal Agreement gives the Customer rights of information and audit at least equivalent to those in this clause 10 and meeting the requirements of data protection law, the Customer may exercise either set of rights, but is not entitled to require the same audit twice.
11. Liability and indemnity
11.1 The limitations and exclusions of liability in the Principal Agreement apply to this Agreement, except that nothing limits either party's liability to a data subject under Article 82 of the UK GDPR, or any liability that cannot lawfully be limited.
11.2 The Customer will indemnify ARROW against losses, claims, regulatory fines and reasonable costs ARROW incurs to the extent they arise from: (a) an instruction of the Customer that infringes data protection law, where the infringement lies in the instruction rather than in ARROW's performance of it; (b) the Customer's failure to establish a lawful basis under clause 5.1 or to give the notices required by clause 5.2; (c) outbound calling instructed by the Customer in breach of clause 5.3; or (d) special category or criminal offence data submitted in breach of clause 5.4. This clause does not apply to the extent a loss results from ARROW's own breach of this Agreement.
12. Order of precedence and third party rights
12.1 If there is a conflict between these documents, they apply in this order: first the Addendum or other transfer safeguard in force under clause 7, then this Agreement, then the Principal Agreement, in each case only to the extent of the conflict.
12.2 A person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms. This does not affect any right a data subject has under the Addendum or under data protection law.
13. Changes to this Agreement
13.1 ARROW may update this Agreement from time to time. A change that reduces ARROW's obligations or the Customer's rights takes effect only after ARROW has given the Customer at least 30 days' notice by email to the address in clause 14.2, and does not apply retrospectively. Corrections, clarifications and changes required by law may take effect on publication.
13.2 Each version of this Agreement carries a version number and effective date. ARROW keeps every published version and provides, on written request, the version in force on any date the Customer specifies.
14. Term, notices and governing law
14.1 This Agreement terminates when ARROW has completed the deletion or return required by clause 8.4 and completed the removal required by clause 8.2, whichever is later. Clauses 4.1 to 4.9, 6.4, 7, 8, 9, 10, 11 and 12 continue to apply for as long as ARROW holds any Call Data, and clause 6.5 continues to apply for the period stated in it.
14.2 Notices are given in writing to support@aiphonecalls.co.uk for ARROW, and to the email address held on the Customer's account for the Customer. The Customer keeps that address current.
14.3 This Agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1 · Details of the processing
| Subject matter | Provision of a managed AI telephone answering service, including answering inbound calls and, where instructed, placing outbound calls on the Customer's behalf. |
| Duration | The term of the Principal Agreement, plus the retention and deletion periods in clause 8. |
| Nature and purpose | Real-time speech to text transcription, natural language understanding and response generation, text to speech, call recording and storage, call summarisation, appointment booking, message taking, call transfer, and delivery of summaries and lead records to the Customer. Recording and storage support service delivery, quality assurance and dispute resolution. |
| Categories of data subject | Members of the public and business contacts who telephone the Customer. Where outbound calling is enabled, people who have given the Customer their telephone number and whom the Customer instructs ARROW to call. Employees or representatives of the Customer whose details appear in call routing configuration. |
| Types of personal data | Voice recordings of the call. Call transcripts. Caller telephone number. Name, and any contact or other details volunteered by the caller during the call, which may include email address, postal address, vehicle or property details, appointment details and the reason for the call. Call metadata, meaning date, time, duration, direction, outcome, sentiment score, cost, the AI agent used, ARROW's own record identifier, and a link to the call recording held on the voice platform. |
| Special category data | Not intentionally collected and not solicited by the call flow. A caller may volunteer special category data, for example health information when calling a healthcare or care provider. Where the Customer's sector makes this likely, the parties will agree the position in writing under clause 5.4. |
| Frequency of transfer | Continuous, for the duration of each call and for the retention period afterwards. |
| Automated decision making | None producing legal effects or similarly significant effects on the data subject. The AI agent conducts the conversation and may route, book or take a message. It does not make decisions about entitlement, credit, employment or similar matters. |
Annex 2 · Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | Personal data is encrypted in transit using TLS, and encrypted at rest on the voice platform. |
| Access control | Role based access control. Access to Call Data is limited to the two directors of ARROW and to named personnel with a service need. Multi-factor authentication is enforced on the voice platform and the telephony platform. Access is withdrawn promptly when a person no longer needs it. |
| Segregation | Each customer's AI agents, telephone numbers and call records are logically separated. Separate API keys are used per environment, and production keys are never used in development or preview environments. |
| Telephony abuse controls | Inbound and outbound country permissions are locked to the United Kingdom on production agents unless the Customer requires otherwise in writing. Maximum call duration limits are enforced. Public web call widgets are protected by bot detection. |
| Retention limits | Automatic deletion of recordings, transcripts and call logs after 30 days, configured per agent, which limits the volume of personal data held at any time. |
| Logging and monitoring | Audit logging on the voice platform. Call monitoring and review by ARROW for quality assurance and fault diagnosis. |
| Supplier assurance | Sub-processors are assessed before appointment. The principal voice sub-processor reports a current SOC 2 Type II examination. Written data processing terms, incorporating the Addendum where the sub-processor processes Call Data outside the United Kingdom and outside a country covered by UK adequacy regulations, are in place with each sub-processor ARROW appoints directly, and equivalent terms are required to be flowed down to sub-processors those parties engage. |
| Personnel | Confidentiality obligations in contracts of engagement. Data protection and security briefing on engagement and on material change. Access revoked promptly on the end of an engagement. |
| Business continuity | Voice and telephony platforms are operated on resilient cloud infrastructure with provider level redundancy. Call routing failover to a Customer nominated number is available on request. |
| Incident response | Defined incident response process, with notification to the Customer within 48 hours of becoming aware of a personal data breach. |
Annex 3 · Sub-processors
For privacy and security reasons ARROW does not publish the names of its sub-processors. The Sub-processor List, recording each sub-processor's legal entity name, function, country of processing and transfer safeguard, is available to customers and their professional advisers on request to support@aiphonecalls.co.uk, on the confidential basis set out in clause 6.1.
The table below describes the functions the current sub-processors perform and the countries in which Call Data is processed, as at the effective date of this Agreement.
| Function | Country of processing |
|---|---|
| Voice agent platform. Real-time call handling, orchestration, call recording, transcript and log storage. | United States |
| Telephony. Number provisioning, call routing and call detail records. | Ireland, with onward transfer to the United States |
| Language model for conversational understanding, response generation and call summarisation. | United States |
| Text to speech voice generation. | United States |
| Speech to text transcription, engaged by the voice agent platform rather than directly by ARROW. | United States |
| Calendar availability and appointment creation. | Ireland |
| ARROW's internal operations records. Call metadata and a link to the recording held on the voice platform, removed when the recording is deleted. No copy of the audio, and no transcript content is written to these records. | Cyprus, hosted in Germany |
| Appointment scheduling during and after the call. | United States |
| Workflow automation. Delivery of summaries, notifications and lead records to the Customer's nominated systems. | Ireland |
Customer specific integrations, for example a calendar, CRM or messaging platform nominated by the Customer, are added by agreement before they are connected. Where the Customer nominates its own existing system, the Customer is the controller of the data once it is delivered into that system.
Annex 4 · Restricted Transfers
| Data exporter | Steady Bow ARROW Limited, acting as processor on the Customer's behalf and on the Customer's instructions. |
| Data importers | The sub-processors on the Sub-processor List that process Call Data outside the United Kingdom and outside a country covered by UK adequacy regulations. Sub-processors established in the European Economic Area are covered by UK adequacy regulations and no Article 46 safeguard is required for those transfers. |
| Transfer mechanism | The International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018. Where ARROW's written terms with a sub-processor are made on a processor to processor basis, Module Three of the EU SCCs applies, ARROW exporting as the Customer's processor and the sub-processor importing as a processor. Where a sub-processor's standard terms operate on a controller to processor basis only, ARROW records that position in its transfer risk assessment, satisfies itself that the terms give equivalent protection to Module Three, and notifies the Customer under clause 6.2 if it cannot. |
| Categories of data and data subjects | As set out in Annex 1. |
| Transfer risk assessment | Completed 19 March 2026 in respect of the transfer to the United States, and reviewed at least annually. Outcome: the residual risk to data subjects is assessed as low to moderate and is judged acceptable, on the basis that the data comprises routine commercial telephone calls, the safeguards in Annex 2 apply, and retention is limited to 30 days. A copy is available on request. |
| Supplementary measures | Encryption in transit using TLS. Encryption at rest on the voice platform. Contractual obligation on the importer to challenge and to notify government access requests where legally permitted, under Clause 15 of the SCCs. 30 day retention limit reducing the volume of data exposed at any time. Flow down of equivalent obligations to onward sub-processors. |
| Ending the Addendum | Table 4 of the Addendum: neither party may end the Addendum as set out in Section 19 of the Addendum. The Addendum is deemed revised by any revised Approved Addendum issued by the Information Commissioner, from the date it comes into force. |
Note on the position under UK law. The United States does not benefit from a general UK adequacy decision. The UK Extension to the EU-US Data Privacy Framework permits transfers only to US organisations that have self-certified to the Framework and opted into the UK Extension. ARROW does not rely on that route as its primary safeguard, and instead relies on the Addendum to the EU Standard Contractual Clauses supported by the transfer risk assessment described above. Where a sub-processor also holds a current UK Extension certification, the Sub-processor List says so, and ARROW may rely on it in addition to, not in place of, the Addendum.
Version history
| Version | Effective date | Change |
|---|---|---|
| [1.0] | 11.04.25 | First publication. |
Steady Bow ARROW Limited, company number 16372439, registered in England and Wales. ICO data protection register reference ZC011942. Trading as AI Phone Calls, aiphonecalls.co.uk. Questions about this Agreement go to support@aiphonecalls.co.uk. This Agreement is a contractual document and does not constitute legal advice to the Customer.