Data Processing Agreement

Last updated: October 6, 2026

This Data Processing Agreement (“DPA”) applies when CallBooker processes personal data on your behalf while you use CallBooker, mainly the data of the leads your AI agents call. It is part of our Terms of Service: by accepting the Terms you also accept this DPA, with no separate signature needed. It is written to meet Article 28 of the EU GDPR and the UK GDPR.

Questions, or need a countersigned copy for your records? Email support@callbooker.com.

1. Roles

You are the controller of your leads’ personal data: you decide who is called, why, and with what message. CallBooker is your processor: we process that data only to provide the service to you.

For your own account data (your name, email, billing), CallBooker is a separate controller, as described in our Privacy Policy; this DPA does not cover it.

Your Twilio account is your own: Twilio processes calls under your contract with Twilio, not as our sub-processor. The same goes for the calendar you connect (Google Calendar or Calendly).

2. What we process

  • Subject matter and purpose: placing AI phone calls to your leads, holding the conversation, qualifying them, booking meetings on your calendar, and showing you the results, as you instruct through the product, the API and integrations.
  • Data subjects: your leads and contacts, and people who join the calls or meetings.
  • Categories of data: names, phone numbers, email addresses, company and job details, notes and custom fields you add, call audio, transcripts, call summaries, answers to your qualifying questions, and meeting details.
  • Special categories: none are needed for the service. Don’t upload sensitive data (such as health data) about your leads, and don’t configure agents to collect it.
  • Duration: for as long as you use CallBooker, then until deletion as described in section 9.

3. Processing only on your instructions

We process your leads’ data only on your documented instructions: the Terms, this DPA, and what you set up in CallBooker (agents, campaigns, API calls, integrations). We don’t use it for our own purposes, sell it, or use it to train AI models.

If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process data in another way, we will tell you first unless the law forbids it.

You confirm you have a lawful basis to give us your leads’ data and to have them called, including any consent required for calls made with an AI or artificial voice, as set out in our Terms and the calling agreement you accept in the app.

4. Confidentiality

Anyone at CallBooker who can access your leads’ data is bound by confidentiality and only accesses it when needed to run, support or secure the service.

5. Security measures

We protect your data with technical and organisational measures suited to the risk, including:

  • Encryption in transit (HTTPS/TLS) for all traffic, and encryption at rest on Google Cloud.
  • Your Twilio Auth Token stored encrypted (AES-256-GCM); API keys stored only as hashes; outgoing webhooks signed.
  • Database rules so each account can only read its own data, and server-only access to anything sensitive.
  • Rate limits, bot protection on public forms, and monitoring that alerts us to errors and unusual activity.
  • Access to production systems limited to the people who need it.

We review these measures as the service grows and may improve them, but never lower the overall level of protection.

6. Sub-processors

You authorise us to use the sub-processors below. Each is bound by written terms that protect the data at least as well as this DPA, and we remain responsible to you for them.

ElevenLabs

United States

Voice AI: runs the conversation, speech-to-text, text-to-speech, transcripts and call recordings

Google Cloud / Firebase

United States

Hosting, database, sign-in, background jobs and translation of agent greetings

Vercel

United States

Hosting of the website and dashboard; API requests pass through it

Resend

United States

Sending emails (notifications, meeting reminders to leads when you turn them on)

Stripe

United States

Payments (your billing details only, never your leads’ data)

We will update this list at least 30 days before adding or replacing a sub-processor. If you have a reasonable data protection objection, tell us within that time; if we can’t address it, you may stop using the affected part of the service or close your account.

7. International transfers

Our sub-processors process data in the United States. Where data from the EU/EEA, the UK or Switzerland is transferred, the transfer is covered by the EU Standard Contractual Clauses (Module 2 from you to us, and Module 3 from us to our sub-processors), the UK International Data Transfer Addendum and the Swiss amendments, or by another valid mechanism such as the EU-US Data Privacy Framework where the recipient is certified.

For the Standard Contractual Clauses, this DPA provides the required details: the parties and roles are in section 1, the processing in section 2, and the security measures in section 5.

8. Helping you meet your obligations

We help you answer requests from your leads to access, correct, delete or export their data. Most of it you can do yourself in CallBooker: edit or delete contacts, and export leads, calls and meetings as CSV. If a lead contacts us directly, we will send them to you and won’t answer for you unless you ask.

Where reasonably needed, we also help with data protection impact assessments and consultations with authorities, using the information we have.

9. Retention and deletion

Leads, calls, transcripts and meetings are kept while your account is active, until you delete them. Call recordings stay playable for 30, 90 or 365 days depending on your plan and are held by ElevenLabs. API request and webhook logs are kept for 30 days and in-app notifications for 90 days.

When you delete your account (Settings → Profile), we delete your data and ask our sub-processors to delete it, within 30 days, except what the law requires us to keep. Export anything you want to keep before deleting.

10. Personal data breaches

If we become aware of a breach affecting your leads’ data, we will notify you without undue delay, with what we know about what happened, the data and people affected, its likely consequences and what we are doing about it, and keep you updated as we learn more, so you can meet your own notification duties.

11. Information and audits

On request, we will give you the information reasonably needed to show we comply with this DPA, such as answers to security questionnaires and our sub-processors’ certifications. If that isn’t enough and the law or an authority requires it, you may audit our compliance, with reasonable notice, at most once a year, at your cost, and under confidentiality.

12. General

This DPA lasts as long as we process personal data for you. If it conflicts with the Terms on data protection, this DPA wins; if it conflicts with the Standard Contractual Clauses, the Clauses win. Liability under this DPA is subject to the limits in the Terms, except where the law doesn’t allow them.

We may update this DPA to reflect changes in the law or the service. We will tell you about important changes by email or in the app before they apply.