Home / Data Processing Agreement
Data Processing Agreement
How we process personal data on your behalf. It forms part of our Terms of Service.
Version 2026-10-02.
This Data Processing Agreement ("DPA") forms part of the agreement ("Agreement") between:
- Ringmere, a service operated by Peoplely Ltd, company number 16386277, registered office 71-75 Shelton Street, London, England, WC2H 9JQ, ICO registration ZC192829 ("Processor", "we", "us"); and
- the business customer identified in the Agreement ("Controller", "you"),
each a "party" and together the "parties". It governs our processing of personal data on your behalf when you use the Ringmere AI phone receptionist service (the "Service").
Where you and we have already agreed conflicting terms, this DPA prevails on the subject of data protection.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law"). "Sub-processor" means any third party we engage to process personal data under this DPA.
2. Roles of the parties
You are the Controller and we are the Processor of the personal data processed through the Service on your behalf (the "Controller Personal Data"). You are responsible for establishing a lawful basis for that processing, for the accuracy of the data you and your callers provide, and for providing any notices and, where required, obtaining any consents from data subjects.
3. Scope and instructions
3.1 We will process Controller Personal Data only on your documented instructions, including as set out in this DPA and the Agreement and as configured by you in the Service, unless required to do otherwise by law (in which case we will, where lawful, inform you first).
3.2 The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex A.
3.3 We will inform you if, in our opinion, an instruction infringes Data Protection Law.
4. Confidentiality
We ensure that personnel authorised to process Controller Personal Data are bound by appropriate confidentiality obligations and access the data only as needed to provide and support the Service.
5. Security
Taking into account the state of the art and the nature of the data, we implement appropriate technical and organisational measures to protect Controller Personal Data, as described in Annex C, in line with UK GDPR Article 32.
6. Sub-processors
6.1 You give us general authorisation to engage the sub-processors listed in Annex B (and in our published sub-processor list) to process Controller Personal Data.
6.2 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for each sub-processor's performance.
6.3 We will give you at least 30 days' notice (by email or via the Service) before adding or replacing a sub-processor. If you reasonably object on data-protection grounds within that period, we will work with you in good faith to resolve it; if we cannot, you may terminate the affected part of the Service.
7. Assistance with data-subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). The Service provides self-service tools to look up, export and erase all data held about an individual caller by phone number or email address.
8. Assistance with security, breaches and DPIAs
We will assist you, taking into account the nature of processing and the information available to us, with your obligations under UK GDPR Articles 32–36 (security, breach notification, and data protection impact assessments).
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, and provide the information reasonably available to us to help you meet your own notification obligations.
10. Return or deletion
On termination of the Service, and at your choice, we will delete or return Controller Personal Data and delete existing copies, unless retention is required by law. In normal operation, caller personal data (number, name, call summary, transcript, and any call recording) is automatically purged after the retention period you configure in the Service.
11. Audits
We will make available to you information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, no more than once per year (unless required by a supervisory authority), subject to confidentiality and to not compromising other customers' data.
12. International transfers
Controller Personal Data is hosted in the UK/EU. Where a sub-processor processes data outside the UK, we ensure an appropriate transfer mechanism is in place (e.g. UK adequacy regulations, the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or equivalent safeguards). See Annex B for the location of each sub-processor.
13. Liability, term and governing law
This DPA is subject to the liability, term and termination provisions of the Agreement. It takes effect on the Agreement's start date and lasts as long as we process Controller Personal Data. It is governed by the laws of England and Wales and subject to the exclusive jurisdiction of its courts.
Annex A: Details of processing
| Subject matter | Provision of an AI telephone receptionist that answers inbound calls, books/reschedules/cancels appointments, takes orders, captures enquiries, and escalates to a human on the Controller's behalf. |
| Duration | For the term of the Agreement, plus the Controller's configured retention window. |
| Nature & purpose | Answering calls, converting speech to text, generating spoken responses, creating/updating calendar events and bookings, sending SMS/WhatsApp/email confirmations and reminders, and producing call transcripts, summaries and (if enabled) recordings. |
| Types of personal data | Caller phone number; caller name; booking/appointment details; order details and delivery address/postcode (food businesses); free-text notes the caller provides; call transcript; call summary; and, where the Controller enables call recording, call audio. Business-user account data (name, email) is processed by us as controller under our Privacy Policy, not under this DPA. |
| Special category data | Not intentionally processed. The Controller must not configure the Service to solicit special-category data. Callers may volunteer such data in free text; the AI is instructed not to request or assess it and to escalate clinical/medical matters to a human. |
| Categories of data subjects | The Controller's callers and customers; the Controller's own staff named in bookings/handoff settings. |
Annex B: Authorised sub-processors
The current list is also published at ringmere.com/privacy. As of 2026-10-02:
| Sub-processor | Purpose | Personal data processed | Location / transfer basis |
|---|---|---|---|
| Twilio | Telephony, SMS, WhatsApp and call recording | Phone numbers, message content, call audio (where recording is enabled) | United States (Twilio's default US1 region; no other region is configured); UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| OpenAI | Real-time voice AI, chat, transcription and summaries | Call audio and transcript content, chat messages | United States; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Two-way Google Calendar sync and Meet links, for businesses that connect it; Sign in with Google | Booking and event details, the caller details Ringmere writes on an event, calendar tokens; for sign-in, the account holder's name and email address | Global; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA | |
| Microsoft | Outlook and Microsoft 365 calendar sync, for businesses that connect it; Sign in with Microsoft | Booking and event details, the caller details Ringmere writes on an event, calendar tokens; for sign-in, the account holder's name and email address | Global; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Resend | Transactional email: confirmations, reminders and alerts | Recipient email address, name and booking details | United States; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Stripe | Subscription billing and payments | Business-customer billing data (not caller data) | United States; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Fly.io | Application hosting and the database | All Controller Personal Data at rest | United Kingdom (London region) |
| Cloudflare R2 | Encrypted offsite database backups | All Controller Personal Data, as an encrypted full database backup | EU jurisdiction bucket; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Sentry | Application error monitoring | Diagnostic events, with phone numbers and email addresses removed before sending | United States; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Meta | Two-way WhatsApp messages, for businesses that connect WhatsApp (Embedded Signup in the dashboard) | WhatsApp numbers and message content | Global; UK International Data Transfer Addendum / Standard Contractual Clauses under its DPA |
| Beds24 | Hotel room availability and booking, for hotels that connect it | Guest name, phone, email and stay dates | Not yet confirmed |
| Cloudbeds | Hotel room availability and booking, for hotels that connect it | Guest name, phone, email and stay dates | Not yet confirmed |
| postcodes.io | Delivery-radius lookup, for food businesses only | A postcode (no name or number is sent) | United Kingdom |
Annex C: Technical & organisational measures
- Encryption: data encrypted in transit (TLS) and at rest; third-party credentials (e.g. calendar tokens) encrypted with a separate key.
- Tenant isolation: every record is scoped to a single business; access is enforced per authenticated owner on every request.
- Access control: authentication with hashed credentials; least-privilege access; recordings served only through an authenticated, ownership-checked proxy (never public URLs).
- Data minimisation & retention: configurable retention window after which caller number, name, summary, transcript and any recording are automatically and permanently purged.
- Data-subject tooling: built-in subject-access lookup, data export, and right-to-erasure by phone number or email address, with an erasure audit log. Erasure also deletes any stored recordings, has the telephony provider delete its records of that caller's calls and texts still inside the retention window, and removes their details from calendar events the Service created.
- Disclosure: by default, every call opens by telling the caller they are speaking to an automated assistant (and that the call may be recorded, where recording is enabled). The Controller can switch the automated-assistant disclosure off in its settings, except while call recording is on, and is then responsible for its callers being told.
- Spam/abuse controls: blocklist, anonymous-caller policy, and frequency-based auto-blocking.
- Resilience: hosted on always-on infrastructure with graceful deploys that drain live calls; signed webhooks; deep health checks.
- Sub-processor governance: written data-processing terms with each sub-processor; 30-day change notice to controllers.
Questions about this agreement: info@ringmere.com.