Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Lion’s Point Ltd ("Relai", "Processor") and the Customer ("Controller") and governs Relai's processing of personal data on the Customer's behalf. It is intended to satisfy Article 28 of the UK GDPR and the EU GDPR.
1. Roles and scope
In respect of Customer Data, the Customer is the controller (or a processor acting for a third-party controller) and Relai is the processor (or sub-processor). Relai processes Customer Data only to provide the Service and only as described in this DPA and Annex 1. Where terms are not defined here, they have the meaning given in the Terms or the UK/EU GDPR.
2. Definitions
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR and other applicable data-protection laws. "Customer Data", "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the Terms and Data Protection Law. "Subprocessor" means a processor engaged by Relai to process Customer Data.
3. Processing on documented instructions
Relai will process Customer Data only on the Customer's documented instructions, including as set out in this DPA, the Terms, and the Customer's configuration and use of the Service, unless required to do otherwise by law (in which case Relai will inform the Customer unless legally prohibited). Relai will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
4. Confidentiality
Relai ensures that personnel authorised to process Customer Data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities, and that access is limited to those who need it to provide the Service.
5. Security
Relai implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32, as described in Annex 2 and our Security Overview. Relai will not materially reduce the overall level of protection during the term.
6. Subprocessors
The Customer provides general written authorisation for Relai to engage the subprocessors listed in Annex 3 and, going forward, others of the same kind. Relai imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for their performance. Relai will maintain an up-to-date list of subprocessors and will give the Customer prior notice of the addition or replacement of a subprocessor with a reasonable opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Customer may terminate the affected part of the Service.
7. International transfers
Where Relai (or a subprocessor) transfers Customer Data outside the UK/EEA, it will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or reliance on an adequacy decision or the EU–US Data Privacy Framework where applicable, together with any additional measures required.
8. Assisting with data-subject rights
Taking into account the nature of the processing, Relai will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights, and will promptly forward to the Customer any such request it receives directly.
9. Personal data breach notification
Relai will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its own notification obligations. Relai will assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification and, where relevant, data-protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Relai.
10. Deletion and return
On termination of the Service, and at the Customer's choice, Relai will delete or return Customer Data and delete existing copies, unless retention is required by law. Because the Customer's CRM remains the system of record, much Customer Data continues to reside in the Customer's own systems, which are outside Relai's control.
11. Audits and information
Relai will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, frequency and security conditions. Relai may satisfy audit requests by providing relevant documentation and responding to reasonable questionnaires.
Annex 1 — Details of processing
- Subject matter: Relai's processing of Customer Data to provide the AI SDR Service.
- Duration: the term of the subscription, plus any deletion/return period.
- Nature and purpose: answering, qualifying, nurturing and booking leads across WhatsApp, email and phone; generating messages, insights and summaries; recording and transcribing calls; and logging back to the Customer's CRM.
- Categories of personal data: identifiers and contact details (name, email, phone); lead, deal and CRM records and notes; communication content (messages, call audio and transcripts); calendar and meeting data; and any personal data the Customer or its contacts include in communications.
- Categories of data subjects: the Customer's leads, prospects, customers and other contacts, and the Customer's own users and staff.
- Special categories: not intended; the Customer should not submit special-category data without an appropriate basis.
Annex 2 — Technical and organisational measures
Relai maintains measures including: encryption of data in transit; role-based access controls and least-privilege access; hashed credentials; segregation of duties and an operator role that has no access to tenant conversation content; audit logging; secure development and secrets management; and vetting of subprocessors. A fuller description is in the Security Overview, which is incorporated here by reference.
Annex 3 — Approved subprocessors
The current subprocessors are those listed in Section 7 of the Privacy Policy (including Anthropic, HubSpot, 360dialog, Meta, Twilio, Aurinko, Google, Microsoft, Stripe and our hosting provider). The up-to-date list is available on request at privacy@relaioffice.com.