Data Processing Agreement
Last updated: 16 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Alayic Ltd ("Alayic", "we", "us") and the customer or partner using our AI voice services ("you", "the Customer"). It sets out how we process personal data on your behalf, and applies wherever our services process personal data subject to the UK GDPR, the EU GDPR, or the Data Protection Act 2018.
1. Roles of the parties
You are the controller of the personal data processed through our services: you decide why calls are answered and what happens with the resulting information. Alayic is your processor, acting on your instructions. The providers listed in section 6 act as our sub-processors.
Where you are a partner or reseller providing our services to your own customers, your customers are the controllers in respect of their own callers' data, and you and Alayic each act as processors in the chain.
2. Subject matter and duration
Subject matter: the provision of AI voice answering, ordering and booking services.
Duration: for the term of your agreement with us, plus the retention periods set out in section 7.
Nature and purpose: receiving and answering telephone calls on your behalf, converting speech to text, generating spoken responses, capturing orders and bookings, and making the resulting records available to you.
3. Categories of data subjects and personal data
Data subjects: the people who call you (your customers and enquirers), and the staff users you authorise to access our platform.
Personal data processed:
Caller details: the calling telephone number.
Call content: the audio recording of the call, and a written transcript of what was said by the caller and by the AI agent.
Call summaries: an AI-generated summary of the call.
Order and booking details: where captured during a call — name, telephone number, email address, delivery address and postcode, and any instructions given.
Technical data: IP address and device information relating to platform users.
Account data: the names and email addresses of your staff users.
We do not ask for special category data, and our services are not designed to capture it. Because calls are open conversations, a caller may volunteer such information unprompted; it would then form part of the transcript and recording.
4. Our obligations
We will:
Process personal data only on your documented instructions, including the configuration choices you make in our platform, unless required otherwise by law.
Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
Implement appropriate technical and organisational measures, as described in section 5.
Not sell personal data, and not use it for our own purposes.
Assist you in meeting your obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of processing and the information available to us.
Make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are subject to reasonable notice, confidentiality, and no more than once in any twelve month period unless required by a supervisory authority or following a personal data breach.
5. Security
Personal data is held in access-controlled systems. Data in transit is encrypted using TLS, and connections to our databases require TLS. Access to customer data through our platform is restricted to the users you authorise, and each workspace is logically separated so that one customer's data is not exposed to another. Administrative access to production systems is limited to named Alayic personnel. Call recordings are stored in private object storage and are never publicly accessible; where a recording is played back in our platform it is served through a time-limited link that expires after one hour.
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed below. We remain responsible for their performance. We will give you reasonable notice before adding a new sub-processor that processes call content, and you may object on reasonable data protection grounds.
Microsoft Azure — application hosting, database and logging. United Kingdom (UK South).
Amazon Web Services — call recording storage. Ireland (eu-west-1).
LiveKit — real-time call media transport and recording capture.
Twilio — telephone numbers and call connectivity.
Groq — speech recognition and language model processing of call content.
OpenAI — speech recognition and language model processing of call content, including speech-to-speech models where selected.
Deepgram — speech recognition.
Cartesia — speech synthesis (the agent's voice).
Google — language model processing; address lookup where delivery is used; sign-in where you use Google accounts.
Anthropic — processing of your published website and menu content during setup.
Stripe and Paystack — payment processing.
SendGrid — transactional and notification email.
Voodoo SMS — SMS notifications.
Cloudflare — content delivery and bot protection for our website.
Additional sub-processors may be engaged only where you enable a specific integration — for example a point of sale or calendar provider that you connect to your workspace.
Which speech and language providers are engaged for a given call depends on the configuration of that workspace.
7. Retention and deletion
Call recordings and transcripts are retained for 365 days and are then permanently deleted automatically. Partners may set a shorter period for their customers; where a shorter period is set, the shorter period applies.
Call summaries are deleted on the same basis as transcripts.
Call records — the fact of a call, its time, duration and cost — are retained after the content is deleted, because they form part of our billing and accounting records.
On termination, we will delete the personal data we hold for you on request, and in any event the retention periods above continue to apply. Certain financial records are retained where we are required to keep them for statutory accounting purposes.
Backups are retained for 7 days and are overwritten on a rolling basis. Data deleted from our live systems may persist in backups until they expire.
8. Assisting with data subject rights
We provide tooling that allows a caller's personal data to be located across your workspace, exported in a structured format, and erased. Where you receive a request from a data subject, we will assist you in responding to it. Requests should be sent to the address in section 11 and we will act on them without undue delay.
Because callers are identified by the number they call from, and numbers may be recorded in different formats, location of a caller's data is thorough but cannot be guaranteed to be exhaustive where a caller has provided details in free-form conversation.
Erasure removes the call transcript, summary, any order and booking details, and the call recording. The underlying call record is retained for billing, with the calling number and technical identifiers removed. We record each erasure — what was erased, when, and by whom — so that it can be evidenced, without retaining a register of the individuals who asked.
9. Artificial intelligence and model training
Alayic does not use your data, or your callers' data, to train our own models.
Call content is processed by the third-party providers named in section 6 in order to deliver the service. Whether any of those providers may use data submitted to them for their own model improvement depends on that provider and the plan under which we access it. We cannot therefore give an unqualified undertaking that no sub-processor uses call content for model improvement. We name our providers above so that you can review their terms, and we will work with customers who require processing to be restricted to particular providers.
10. International transfers
Our application, database and call recordings are held in the United Kingdom and Ireland. Some sub-processors, in particular speech and language model providers, process data outside the UK and the European Economic Area, including in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum or Standard Contractual Clauses.
11. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and will provide the information you reasonably need in order to meet your own notification obligations.
12. Changes to this DPA
We may update this DPA from time to time. The current version will always be available on this page. Where a change materially reduces your rights or our obligations, we will notify you.
13. Contact
Questions about this DPA, requests relating to data subject rights, and sub-processor objections should be sent to:
Alayic Ltd
9 West Street, Congleton, England, CW12 1JN
Registered in England & Wales, company number 16581244
Email: [email protected]
Create your free demo agent ans start making test calls
Get Started Free