Legal

Data processing agreement

The Article 28 terms on which we handle personal data for you. Written to be read by the person who actually runs the calling team, not only by a lawyer.

Last updated 21 August 2026

Draft, pending professional review. This document describes how Dialspire actually works today, but it has not been reviewed by a solicitor and some details are still to be filled in. Please don’t rely on it as a final statement of our obligations.

1. Who this is between

This agreement is between you (the controller, referred to as “you”) and [REGISTERED COMPANY NAME] trading as Dialspire (the processor, “we”).

It forms part of our terms of service and takes effect automatically when you open a workspace — there is nothing to sign. It sets out the terms UK GDPR Article 28(3) requires whenever one organisation processes personal data on another’s behalf.

This covers the data your team puts into Dialspire — leads, calls, notes, transcripts, emails. It does not cover the data we hold about you as our own customer (your account, your billing). We are the controller for that, and it is dealt with in the privacy notice.

2. What we process, and why

Article 28(3) requires the subject matter, duration, nature and purpose of the processing, the type of personal data and the categories of data subject to be set out. They are:

Details of the processing
Subject matterProviding the Dialspire calling-sheet service to you.
DurationFor as long as your subscription is live, plus the deletion window in clause 9.
Nature of the processingStorage, organisation, retrieval, transmission and erasure — carried out by computer, on our infrastructure and that of the suppliers listed on the sub-processors page.
PurposeHolding your calling lists; presenting them as a working queue; placing and recording calls; transcribing and summarising them; sending email; synchronising with your CRM; and reporting on the activity back to you.
Types of personal dataNames, company names, telephone numbers, email addresses, postal and other details in whatever additional columns you import; call records and their outcomes; call recordings, transcripts and AI summaries; notes; the content of emails sent through the service; do-not-contact entries; and your own users’ names, work email addresses and roles.
Categories of data subjectThe people on your calling lists (your prospects and customers); your own staff who use the workspace; and anyone else whose details happen to appear in a note, an email or a call recording.
Special category dataNot requested and not expected. Dialspire is not designed or assessed for health, biometric, or other Article 9 data, and you should not put it in.

3. We act on your instructions

We process personal data only on your documented instructions, including in relation to any transfer outside the UK, unless we are required to do otherwise by law — in which case we will tell you before we do it, unless the law forbids us from telling you.

Your instructions are: this agreement, our terms, the configuration choices your admins make in the product, and anything else you tell us in writing (email counts). Using a feature is an instruction to carry it out — turning on call recording instructs us to record.

If we think an instruction breaches data protection law, we will say so. We will not decide the purpose or means of the processing ourselves; if we ever did, we would be a controller for that processing and would carry a controller’s liability for it.

4. Duty of confidence

Everyone we allow to touch your data — employees, contractors and temporary staff alike — is under a binding duty of confidence, and has access only where they need it to do their job. That duty survives the end of their engagement with us.

5. Security

We implement appropriate technical and organisational measures under Article 32. In concrete terms, today:

  • data is encrypted in transit over TLS, and at rest by our database provider;
  • every credential you enter — carrier keys, mailbox app passwords, CRM tokens — is encrypted with AES-256-GCM before it is stored, under a key that is not in the database;
  • passwords and PINs are stored as salted scrypt hashes, never in a reversible form;
  • repeated failed sign-ins lock an account, and the shared-workstation PIN screen carries a second per-device limit so an attacker cannot cycle through your team’s names for a fresh budget of guesses each time;
  • every workspace’s data is scoped to its own organisation on every query, and access is checked on the server rather than hidden in the interface;
  • changing a password revokes every other session for that user, and admins can see and revoke individual devices.

The current detail is on our security page. We keep these measures under review and may change them, but not in a way that materially reduces protection.

6. Sub-processors

You give us general written authorisation to engage the sub-processors listed on our sub-processors page, which is kept current.

  • We will tell workspace admins at least 30 days before a new or replacement sub-processor starts processing, so you have a real chance to object.
  • If you object on reasonable data protection grounds and we cannot offer you an alternative, you may terminate the affected service without penalty.
  • Every sub-processor is under a contract imposing data protection obligations equivalent to these, and we remain fully liable to you for what they do.

7. Helping you answer people’s requests

People have rights over their data — access, correction, erasure, restriction, objection, portability. Those requests are yours to answer, because you are the controller. Our job is to make that possible.

  • The product lets you find, edit, export and delete a lead and everything attached to it, so most requests need nothing from us at all.
  • A single call’s recording, transcript and AI summary can be purged on request, which is the usual answer to an erasure request about a recorded call.
  • If a request reaches us directly, we will not answer it ourselves. We will pass it to you without undue delay and help you respond.

One honest limit: deleting a recording removes our copy and everything derived from it. Your carrier holds the master under its own retention policy, and only you can remove that. We will tell you so rather than let you report a deletion that has not fully happened.

8. Breaches, DPIAs and other assistance

Personal data breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, with what we know about what happened, who is affected, the likely consequences and what we are doing about it. You decide whether it needs reporting to the ICO or to the people affected; we will give you what you need to make that call and to meet the 72-hour deadline.

Other assistance

Taking into account the nature of the processing and the information available to us, we will help you with keeping data secure, notifying breaches, carrying out data protection impact assessments, and consulting the ICO where an assessment shows a high risk that cannot be mitigated.

9. What happens when you leave

Ending your subscription does not by itself delete your data. Cancelling stops the billing; the workspace and everything in it stay where they are until somebody asks us to remove them. We would rather tell you that plainly than let you assume a deletion that has not happened.

Getting your data out

An admin or manager can export the whole workspace at any time — leads, calls, notes, emails and their history — including during the closure window described below. You do not need to ask us, and there is no window in which the door is shut.

Deleting part of it

Individual leads can be found and erased from the product, along with the calls, notes and emails attached to them, which is how a single person’s erasure request is normally answered. A single call’s recording, transcript and AI summary can be purged on its own.

Deleting all of it

Closing the workspace is what deletes everything, and only an admin can do it — they confirm by typing the workspace name, not by ticking a box. What then happens:

  • Your Stripe subscription is set to stop at the end of the period you have already paid for.
  • The workspace enters a 30-day grace window. Nothing changes during it: your team keeps working, your data stays put, and an admin can call the closure off and carry on as though it had never been clicked.
  • Once the window expires, a nightly job deletes the workspace and everything belonging to it — users, lists, leads, calls, recordings, transcripts, AI summaries, notes, emails, suppression entries, sessions, connected accounts and CRM connections — together with the failed-sign-in counters that hold your team’s email addresses. We keep a count of what was removed, and no record of what it was.
  • After the window has passed the closure can no longer be cancelled, because there may be nothing left to restore.

If you would rather we did it, or you want your data returned to you instead of deleted, ask at [PRIVACY CONTACT EMAIL] and we will act on your instruction. Either way the choice is yours, which is what Article 28(3)(g) requires of us. We keep only what the law requires us to keep — invoices and payment records.

Backups are the practical exception: they roll off on their own cycle rather than being surgically edited. Deleted data in a backup is put beyond use and is not restored into the live service.

10. Audits and inspections

We will make available all the information you reasonably need to show that our Article 28 obligations have been met, and will allow for and contribute to audits and inspections you carry out or commission.

In practice we would rather answer a security questionnaire, walk you through our security page, or give you our documentation than have you send in auditors — but if that is not enough, an on-site audit can go ahead on reasonable notice, no more than once a year unless there has been a breach or the ICO requires it, during business hours, without disturbing other customers, and under confidentiality.

11. Transfers outside the UK

Some of our sub-processors process data outside the UK, principally in the United States. You instruct us to make those transfers, and we make them only under the safeguards described on the sub-processors page — the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the importer is certified.

Where the Addendum is used, a transfer risk assessment must be in place. [CONFIRM WHICH MECHANISM APPLIES TO EACH SUPPLIER, AND HOLD THE TRAs]

12. What you are responsible for

Some things are yours by law and cannot be handed to a supplier. Dialspire enforces what software can enforce, but the obligations below stay with you.

  • Having a lawful basis to hold and call your list. You decide who is on it and why. We do not source, buy or supply leads.
  • Telling people you hold their data. Where a list came from somewhere other than the person themselves, UK GDPR Article 14 requires a privacy notice within a month — and at the latest when you first contact them.
  • Screening against TPS and CTPS. Dialspire blocks a dial to any number on the suppression list you maintain, but it does not subscribe to the registers for you. Under PECR regulation 21 the screening obligation is yours.
  • Call recording consent. Recording is off until you switch it on. Whether you may record, and what you must tell the other person, depends on where your team and the person you called are — that assessment is yours.
  • Your own users. Keeping your team’s access accurate, and removing people when they leave.

There is more detail on what may and may not be done with the service in our acceptable use policy.

13. Liability, precedence and changes

If this agreement and our terms of service conflict on anything to do with the processing of personal data, this agreement wins.

We may update this agreement to reflect a change in law, in the service, or in our suppliers. Where a change materially affects your rights we will give workspace admins at least 30 days’ notice by email before it takes effect.

Questions about this agreement, or a request for a signed copy, go to [PRIVACY CONTACT EMAIL].