This Data Processing Addendum ("DPA") forms part of the CallbackPilot Terms of Service between the customer, normally acting as data controller, and P&EWEALTH LTD trading as CallbackPilot, normally acting as data processor. It applies where CallbackPilot processes personal information on the customer's behalf in providing the service.
1. Scope and relationship to the Terms
This DPA supplements and forms part of the Terms of Service and applies to customer personal data processed by CallbackPilot in connection with the service. Terms such as controller, processor, personal data, processing, data subject and personal-data breach have the meanings given in applicable UK data-protection law.
Except as varied by this DPA, the Terms continue in full effect.
2. Controller and processor roles
The customer is normally the controller of personal data relating to its staff, users, callers, prospective customers and SMS participants. P&EWEALTH LTD trading as CallbackPilot normally acts as processor when providing missed-call, messaging, notification and lead-management functions on the customer's behalf.
Each party must comply with the obligations applicable to its role under UK GDPR, the Data Protection Act 2018 and other applicable data-protection law.
3. Documented customer instructions
CallbackPilot will process customer personal data only on documented customer instructions, including the instructions contained in the Terms, this DPA, the customer's configured service settings and lawful support requests, unless processing is required by applicable law.
If law requires other processing, CallbackPilot will inform the customer before processing unless the law prohibits that notice. CallbackPilot will promptly inform the customer if, in its reasonable opinion, an instruction infringes applicable data-protection law and may suspend the affected processing while the issue is resolved.
4. Subject matter, nature, purpose and duration
The subject matter is the processing of customer personal data needed to provide and secure CallbackPilot. The nature and purpose include receiving call events, identifying missed calls, initiating automatic text-backs, routing two-way SMS conversations, producing notifications, maintaining lead-pipeline activity, supporting users and protecting the service.
Processing continues for the subscription term and then for configured deletion, backup and legally required retention periods, as further described in Schedule 1.
5. Data subjects and personal information
The categories of data subjects and personal information are set out in Schedule 1. The service is not designed to require special-category data. Customers must not instruct CallbackPilot to process special-category data unless this has been separately agreed in writing, is legally permitted and appropriate safeguards are in place.
6. Customer responsibilities and lawful instructions
The customer is responsible for the lawfulness, fairness and transparency of its processing and instructions. This includes establishing an appropriate lawful basis, providing required privacy information, respecting marketing and telecommunications rules, configuring retention appropriately, responding to data subjects and ensuring that its users are authorised.
The customer warrants that it has all permissions and authority required to provide customer personal data to CallbackPilot and instruct the processing described in this DPA.
7. Confidentiality
CallbackPilot will ensure that people authorised to process customer personal data are subject to an appropriate duty of confidentiality, receive relevant privacy and security guidance, and access the data only as necessary for their responsibilities.
8. Security measures
CallbackPilot will implement and maintain appropriate technical and organisational measures proportionate to the risks of the processing. Measures may include access controls, authentication, least-privilege permissions, secure transmission, logging and monitoring, vulnerability and incident management, resilient infrastructure, backup controls, supplier assessment and staff confidentiality arrangements.
Security measures may develop over time, provided that the overall protection of customer personal data is not materially reduced.
9. Subprocessors
The customer gives CallbackPilot general written authorisation to appoint subprocessors needed to provide the service. Current categories and key subprocessors are described in Schedule 2.
CallbackPilot will impose written data-protection obligations on subprocessors that provide protections equivalent in all material respects to the obligations relevant to their processing under this DPA. CallbackPilot remains responsible for the performance of those obligations to the extent required by applicable law.
10. Changes to subprocessors and objections
CallbackPilot will give reasonable advance notice of a material addition or replacement of a subprocessor, where practicable through account notice, email, website notice or an updated subprocessor schedule.
The customer may raise a reasonable, evidence-based data-protection objection by contacting [email protected] within the notice period. The parties will work in good faith to address the concern, which may include providing further information, applying reasonable safeguards or identifying a commercially reasonable alternative. If no reasonable solution is available, either party may terminate the materially affected service in accordance with the Terms.
11. Data-subject requests
Taking into account the nature of the processing, CallbackPilot will provide reasonable assistance through appropriate technical and organisational measures to help the customer respond to requests to exercise data-subject rights.
If CallbackPilot receives a request relating to customer personal data, it will normally direct the requester to the customer and will not respond on the customer's behalf unless instructed or legally required.
12. Personal-data breaches
CallbackPilot will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data. The notice will include information reasonably available to CallbackPilot about the nature of the breach, affected data and people, likely consequences, and containment or remediation measures.
CallbackPilot will provide reasonable assistance with the customer's investigation, risk assessment, documentation and any legally required notifications. A notification is not an admission of fault or liability.
13. DPIAs and regulatory enquiries
Taking into account the nature of the processing and information available, CallbackPilot will provide reasonable assistance with data-protection impact assessments, prior consultation and relevant regulatory enquiries relating to the service. The customer remains responsible for determining whether a DPIA or consultation is required and for communicating with its regulator unless otherwise agreed.
14. Deletion or return after termination
At the end of the relevant service, CallbackPilot will delete or return customer personal data in accordance with the customer's available choices and documented instructions, unless applicable law requires retention. Data may remain in protected backups until those backups are overwritten under normal retention cycles and will not be restored except for resilience or recovery purposes.
This obligation does not require deletion of records that CallbackPilot must retain by law or holds independently as controller, provided those records remain protected and are used only for the applicable lawful purpose.
15. Compliance information and audit assistance
CallbackPilot will make available information reasonably necessary to demonstrate compliance with the processor obligations addressed by this DPA. Where information is not reasonably sufficient, CallbackPilot will provide reasonable cooperation with an audit or inspection conducted by the customer or an independent auditor bound by confidentiality.
Audits must be proportionate, normally occur no more than once per year unless a breach or regulator requires otherwise, avoid disruption and protect other customers' confidential information and security. The customer bears its audit costs unless material non-compliance by CallbackPilot is identified.
16. International transfers
Where customer personal data is transferred outside the United Kingdom and a safeguard is required, CallbackPilot will use an appropriate lawful transfer mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to approved standard contractual clauses, together with supplementary measures where appropriate.
17. Priority
If this DPA conflicts with ordinary data-processing provisions in the Terms, this DPA takes priority to the extent of that conflict. The Terms continue to govern all other matters.
18. Governing law and contact
This DPA is governed by the law of Scotland, and the jurisdiction provisions in the Terms apply.
Data-protection questions and subprocessor objections may be sent to [email protected].
P&EWEALTH LTD trading as CallbackPilot
Company number SC770238
Squirrel Barn, Coultra Steadings
Newport On Tay, DD6 8SE
United Kingdom
Schedule 1: Processing details
| Data subjects | Client staff and users, callers, prospective customers and people participating in SMS conversations. |
|---|---|
| Personal data | Names, telephone numbers, email addresses where supplied, call metadata, missed-call events, SMS content, pipeline activity, account identifiers and technical or security logs. |
| Purpose | Missed-call identification, automatic text-back, two-way conversations, notifications, lead tracking, service security and customer support. |
| Duration | The subscription term plus configured deletion, backup and legally required retention periods. |
| Special-category data | Special-category data is not intentionally required. Customers should not instruct CallbackPilot to process it unless separately agreed in writing, legally permitted and protected by appropriate safeguards. |
Schedule 2: Current subprocessors
| HighLevel and LeadConnector group entities | CRM, workflow, email and communications infrastructure. |
|---|---|
| Telecommunications carriers, including Twilio where applicable | Telephone-number provision, voice routing and SMS routing. |
| Hosting, monitoring and security suppliers | Infrastructure, service operation, reliability monitoring, threat detection and security support. |