Data Processing Agreement

Last updated: 1 January 2025

1. Parties

This Data Processing Agreement ("DPA") is entered into between CallWrk ("Processor") and the business customer ("Controller") who subscribes to the CallWrk platform. This DPA forms part of the Terms and supplements the UAE Personal Data Protection Law (PDPL).

2. Roles and scope

The Controller is the business that determines the purposes and means of processing personal data. The Processor (CallWrk) processes personal data on behalf of the Controller as described in this DPA. The scope of processing is limited to providing the CallWrk services: AI call handling, messaging, booking management, analytics, and integrations as configured by the Controller.

3. Data processed

The Processor processes the following categories of personal data on behalf of the Controller:

  • Customer contact details (name, phone number, email, address)
  • Call recordings, transcripts, and metadata
  • Chat and SMS message content
  • Booking and appointment data
  • Lead information from web forms and Google LSA
  • Inbound WhatsApp, Telegram, and web chat messages

4. Processor obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorised to process data are bound by confidentiality obligations
  • Implement appropriate technical and organisational measures under UAE PDPL
  • Notify the Controller without undue delay of any personal data breach
  • Delete or return all personal data after the end of the services
  • Maintain records of processing activities as required by Article 30

5. Technical and organisational measures

The Processor implements the following security measures:

  • Encryption of personal data in transit (TLS 1.2+) and at rest
  • Phone numbers stored as SHA-256 hashes, not in plaintext
  • Multi-tenant database isolation with per-business access controls
  • Session-based authentication with iron-session (encrypted cookies)
  • Rate limiting on all API endpoints
  • Automated data retention and deletion policies
  • Per-business Twilio subaccounts for billing and data isolation
  • Regular security reviews and dependency updates

6. Sub-processors

The Processor uses the following sub-processors to provide the services:

  • Neon — PostgreSQL database hosting (AWS me-central-1, UAE region)
  • Twilio — Telephony and SMS infrastructure
  • xAI — AI voice agent, chat, and call scoring
  • Pusher — Real-time messaging infrastructure
  • Resend — Email delivery
  • Vercel — Web application hosting
  • Nango — OAuth integration management

The Controller is notified of any new sub-processors at least 30 days in advance. The Controller may object to a new sub-processor by terminating the subscription.

7. Data subject rights

The Processor assists the Controller in responding to data subject requests by providing:

  • Data export functionality (Subject Access Request) via the PDPL dashboard
  • Right to erasure — complete deletion of a contact's data across all tables
  • Consent management — recording and withdrawing consent for outbound communications
  • Data retention controls — configurable per-business retention periods

8. International transfers

All data relating to UAE customers is stored within the UAE (AWS me-central-1) where possible. Where any sub-processor processes data outside the UAE, appropriate safeguards and Standard Contractual Clauses are in place in accordance with UAE PDPL requirements.

9. Breach notification

The Processor shall notify the Controller of any personal data breach within 48 hours of becoming aware of it. The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken to address it.

10. Deletion on termination

Upon termination of the Controller's subscription, the Processor shall:

  • Release all Twilio phone numbers and close subaccounts
  • Delete all xAI agent configurations
  • Delete all personal data within 30 days, subject to legal retention requirements
  • Provide written confirmation of deletion upon request

11. Contact

For any queries regarding this DPA, contact our Data Protection Officer at: privacy@callwrk.uk or write to CallWrk Ltd, Level 12, Burj Daman, JLT, Dubai, UAE.