Legal

Data Processing Agreement

Article 28 GDPR / UK GDPR terms for Dottie voice platform customers.

Last updated 2026-08-04

Parties

Customer ("Controller") engages Digital by Default AI Ltd ("Processor") to process personal data on the Controller's behalf when using the Dottie voice agent platform.

Subject matter, nature, and duration

Subject matter: hosting and operating AI voice agents (browser and phone), call transcripts, optional call recordings, lead capture, CRM/webhook delivery, and related support tooling.

Nature: collection, storage, organisation, retrieval, transmission to authorised integrations, and deletion on instruction or retention expiry.

Duration: for the term of the Customer's subscription and any post-termination retention required by law or the Controller's configured retention settings.

Types of personal data and data subjects

Data subjects: callers and browser-voice users interacting with Customer agents; Customer staff using the dashboard.

Categories may include: voice audio and transcripts; name, email, phone and other details volunteered on a call; call metadata (time, duration, channel); booking/lead fields; and quality-evaluation scores derived from transcripts.

Special categories: Dottie is not designed to process special-category data. Customers must not instruct the system to collect health, biometric identification beyond voice as a communication medium, or other special-category data without a documented lawful basis and written agreement.

Documented instructions

Processor processes personal data only on documented instructions from Controller, including configuration in the Dottie dashboard, API/webhooks, and this DPA — unless required by UK/EU law, in which case Processor informs Controller where legally permitted.

Processor obligations (Art. 28)

Confidentiality: persons authorised to process data are bound by confidentiality.

Security: implement appropriate technical and organisational measures (encryption in transit, access control, org isolation, rate limiting, private recording storage). See SECURITY.md / security programme for current controls.

Subprocessors: only engage subprocessors under written terms offering equivalent protection; maintain the list at /subprocessors; give Controller notice of material additions where required.

Assistance: assist Controller with data subject requests, DPIAs, and consultations with supervisory authorities, taking into account the nature of processing.

Breach: notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data.

Deletion/return: on termination or Controller request, delete or return personal data (subject to legal retention of billing/audit records) and delete existing copies where feasible.

Audit: make available information necessary to demonstrate compliance and allow audits as mutually agreed (reasonable notice, confidential, no more than annually unless for cause).

International transfers

Where subprocessors process data outside the UK/EEA, Processor uses appropriate safeguards such as the EU Standard Contractual Clauses and/or UK IDTA / Addendum, or an applicable adequacy decision.

Controller authorises such transfers subject to those safeguards. Details of locations are summarised on /subprocessors.

Controller responsibilities

Controller warrants it has a lawful basis to process caller data and will provide required privacy notices (including AI interaction and call recording notices where applicable).

Controller is responsible for configuring retention, integrations, and agent prompts lawfully, and for responding to data subjects as controller of end-user data.

Execution

This DPA is incorporated into the Terms of Service when you use Dottie for business purposes. Contact legal@dottie.cloud for a countersigned copy. Legal entity details may be updated when company registration is finalised.

Dottie — Voice AI agent builder for service businesses