JavaScript Required

This website requires JavaScript to be enabled.

Cirel

Legal

Data Processing Addendum.

Last updated: 19 June 2026

This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the agreement for the supply of the Cirel services (the “Agreement”) between Cirel Technologies Ltd, a company incorporated in England and Wales with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ (“Provider,” “Cirel,” “we”), and the customer identified in the Agreement, an Order Form, or otherwise accessing or using the Services (“Customer,” “you”).

By accepting the Agreement, signing an Order Form incorporating this DPA, making payment under such Order Form, or otherwise accessing or using the Services (including Cirel’s websites, dashboards, APIs, and AI voice workers), Customer agrees that Customer Personal Data processed in connection with the Services will be governed by this DPA. If you accept on behalf of an entity, you represent that you have authority to bind that entity.

01Definitions

“Agreement” means the agreement between Customer and Provider for the supply of the Services.

“Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” (and inflections) have the meanings given in the applicable Data Protection Laws.

“Customer Personal Data” means Personal Data contained in the data Customer (or its end users / callers) submits to, or that is generated through, the Services — including voice recordings, call transcripts, call summaries, conversational content, contact details, and metadata.

“Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including as applicable: (i) the UK GDPR and the UK Data Protection Act 2018; (ii) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”, and together with the UK GDPR, the “GDPR”); and (iii) the Swiss Federal Act on Data Protection (“FADP”); in each case as amended or replaced.

“Customer Instructions” means: (i) Processing to provide the Services and perform Provider’s obligations under the Agreement (including this DPA); and (ii) other reasonable, documented instructions consistent with the Agreement.

“Restricted Transfer” means a transfer of Customer Personal Data to a country not subject to an applicable adequacy decision, where such transfer would be prohibited absent a lawful transfer mechanism.

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data Processed by Provider. Security Incidents do not include unsuccessful attempts or activities that do not compromise Customer Personal Data (e.g. failed log-ins, pings, port scans, denial-of-service attempts).

“Specified Notice Period” means 72 hours.

“Subprocessor” means any third party (including Provider’s affiliates) authorised by Provider to Process Customer Personal Data.

“Subprocessor List” means Provider’s then-current list of Subprocessors, made available to Customer on written request to compliance@cirel.ai (or at a URL notified by Provider).

“Schedules” means: Schedule 1 (Details of Processing), Schedule 2 (Technical and Organisational Measures), and Schedule 3 (Cross-Border Transfers).

02Scope and Duration

2.1 Roles. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer as a Controller (or Processor on behalf of a third-party controller) of Customer Personal Data.

2.2 Scope. This DPA applies to Provider’s Processing of Customer Personal Data under the Agreement to the extent subject to Data Protection Laws, and is governed by the governing law of the Agreement unless Data Protection Laws require otherwise. Except in connection with a Security Incident, Provider may charge Customer at its then-current rates (on prior written notice) for any non-standard or excessive assistance under this DPA — including audits, security questionnaires, and Data Subject or information requests — that materially exceeds what is reasonably necessary for routine compliance.

2.3 Duration. This DPA commences on the effective date of the Agreement and continues until Provider has ceased all Processing of Customer Personal Data.

2.4 Order of Precedence. In case of conflict, the order of precedence is: (1) the transfer mechanisms in Schedule 3; (2) this DPA; (3) the Agreement. To the fullest extent permitted by Data Protection Laws, all claims under this DPA are subject to the exclusions and limitations of liability in the Agreement.

03Processing of Personal Data

3.1 Customer Instructions. Provider will Process Customer Personal Data as a Processor only (i) in accordance with Customer Instructions, or (ii) as required by applicable law (subject to any notice requirement under Data Protection Laws). Provider will inform Customer if it considers an instruction to infringe Data Protection Laws, but has no obligation to monitor Customer’s compliance.

3.2 Confidentiality. Provider will protect Customer Personal Data in accordance with its confidentiality obligations in the Agreement and will ensure that personnel authorised to Process Customer Personal Data are bound by confidentiality.

3.3 Customer Responsibilities. Customer is solely responsible for, and warrants that it will:

  • (a) establish and maintain a valid lawful basis under Data Protection Laws for all Processing of Customer Personal Data through the Services, and issue Customer Instructions in compliance with Data Protection Laws;
  • (b) provide all required notices to, and obtain all required consents and authorisations from, Data Subjects — including, where required by law, consent to the recording, transcription, and AI processing of calls and voice, and consent to outbound contact;
  • (c) make all disclosures required by law that a Data Subject is interacting with an artificial intelligence system or automated voice agent (including any transparency obligations under the EU AI Act, the UK regime, telemarketing / robocall rules, and any equivalent or successor laws). Provider has no obligation to make such AI disclosures, identify the agent as AI, or obtain such consents on Customer’s behalf, and Customer will not configure the Services in a manner that relies on Provider to do so;
  • (d) ensure its use of the Services, its scripts, prompts, call lists, and target audiences comply with all applicable laws (including do-not-call, quiet-hours, marketing, and recording laws), and that it has the right to submit all data it submits;
  • (e) not submit special categories of Personal Data (Article 9 GDPR), data relating to criminal convictions, or other sensitive data to the Services unless separately agreed in writing, and Customer accepts the risk of any such data it nonetheless submits; and
  • (f) review the information Provider makes available about the Services’ security and independently determine that the Services meet Customer’s requirements and legal obligations.

3.4 Compliance with Laws. Each party will comply with Data Protection Laws applicable to it in respect of its Processing of Customer Personal Data.

3.5 Aggregated and De-Identified Data. Provider may generate and use aggregated, anonymised, or de-identified data derived from the Processing to operate, secure, analyse, and improve the Services and for Provider’s legitimate business purposes, provided such data does not identify Customer or any Data Subject. For clarity, unless separately agreed in writing, Provider does not use Customer Personal Data from Customer’s workspace to train generalised AI or machine-learning models.

3.6 Changes to Laws. The parties will negotiate in good faith any amendment to this DPA reasonably necessary to address changes in Data Protection Laws.

04Subprocessors

4.1 Authorisation. Customer generally authorises Provider to engage Subprocessors (including Provider’s affiliates) to Process Customer Personal Data. Provider will (i) impose data protection obligations on each Subprocessor that are substantially the same as those in this DPA, and (ii) remain responsible for its Subprocessors’ performance of those obligations.

4.2 List and Notice. Provider maintains the Subprocessor List and may update it from time to time. Provider will make the updated list available before a new Subprocessor begins Processing Customer Personal Data.

4.3 Objection. Customer may object to a new Subprocessor within ten (10) days of notice on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, and Provider will refund any prepaid, unused fees for the terminated Services as of the termination date.

05Security

5.1 Security Measures. Provider will implement and maintain technical and organisational measures appropriate to the nature of the Customer Personal Data, designed to protect its security, confidentiality, integrity, and availability and to protect against Security Incidents, as further described in Schedule 2. Provider may update its measures provided the overall level of security is not materially reduced.

5.2 Incident Notice. Provider will notify Customer without undue delay, and in any event within the Specified Notice Period, after becoming aware of a Security Incident affecting Customer, and will make reasonable efforts to identify the cause, mitigate the effects, and remediate within its reasonable control. On request and taking into account the nature of the Processing, Provider will provide information reasonably necessary for Customer to meet its own notification obligations. Provider’s notification is not an acknowledgement of fault or liability.

5.3 Customer Responsibility. Customer is solely responsible for fulfilling its own Security Incident notification obligations to authorities, Data Subjects, and others.

06Data Protection Impact Assessments

On Customer’s request, and taking into account the nature of the Processing and the information available to Provider, Provider will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Data Protection Laws.

07Data Subject Requests

7.1 Taking into account the nature of the Processing, Provider will provide reasonable assistance (by appropriate technical and organisational measures, insofar as possible) to enable Customer to respond to Data Subject requests under Data Protection Laws, where Customer cannot reasonably do so itself (including through the Services).

7.2 If Provider receives a request directly from a Data Subject regarding Customer Personal Data, Provider will, unless legally required to act otherwise, direct the Data Subject to Customer and notify Customer. Customer is responsible for responding.

08Return or Deletion

8.1 During the term, Customer may access, export, or delete Customer Personal Data through the features of the Services.

8.2 Following termination or expiry of the Agreement, Provider will delete Customer Personal Data from its active systems in accordance with the Agreement. Provider may retain Customer Personal Data (i) as required by applicable law, or (ii) in accordance with its standard backup and record-retention cycles, provided that it keeps such data confidential and does not further Process it except as required by law. Provider will confirm deletion in writing on request.

09Audits

9.1 Provider will keep records of its Processing as required by Data Protection Laws and, on Customer’s reasonable written request (subject to confidentiality), make available information reasonably necessary to demonstrate compliance with this DPA.

9.2 On Customer’s reasonable written request and subject to confidentiality, Provider will make available a summary of its security measures and, where available, the relevant third-party audit reports or certifications held by its key infrastructure Subprocessors (for example, the SOC 2 report of its database and storage provider, Supabase). Customer agrees that this documentation, together with the process in Section 9.3, satisfies any audit rights under Data Protection Laws.

9.3 Only if Provider does not make acceptable documentation available within thirty (30) days of request may Customer, at Customer’s expense, conduct an audit limited to matters reasonably necessary to verify compliance with this DPA, subject to the following parameters: (i) conducted by an independent third party bound by confidentiality; (ii) on reasonable prior notice and during Provider’s normal business hours; (iii) no more than once per year (unless required by a supervisory authority or following a Security Incident); (iv) limited to facilities and systems controlled by Provider that Process Customer Personal Data, and not affecting other customers’ data; and (v) all findings treated as Provider’s confidential information.

10Liability

Notwithstanding anything to the contrary, each party’s (and its affiliates’) total aggregate liability arising out of or relating to this DPA, any Standard Contractual Clauses, and any related data-protection agreements is subject to the aggregate limitations and exclusions of liability in the Agreement. Any regulatory penalty incurred by one party as a result of the other party’s breach of this DPA or Data Protection Laws counts toward and reduces the incurring party’s liability under the Agreement as if it were liability owed to the other party.

11Cross-Border Transfers

11.1 Provider (and its Subprocessors) may Process and transfer Customer Personal Data globally as necessary to provide the Services. Where Provider engages in a Restricted Transfer, it will comply with Schedule 3.


S1Schedule 1 — Details of Processing

Data Exporter / ControllerCustomer, as identified in the Agreement or applicable Order Form. Role: Controller (or Processor on behalf of a third-party controller). Contact for data protection: as provided by Customer.
Data Importer / ProcessorCirel Technologies Ltd. Contact for data protection: Louis Aventine, CEO — compliance@cirel.ai. Address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Role: Processor.
ActivitiesProviding the Services to Customer (AI voice workers: inbound reception, outbound calling, follow-up, and related dashboard / analytics).
Data SubjectsDetermined and controlled by Customer: prospects, customers, callers, business partners, and vendors of Customer who are natural persons; employees or contacts of the foregoing; Customer’s own employees, agents, and authorised users.
Personal DataTo the extent Customer submits or the Services generate them: name; contact details (phone, email, company, business address); job title / role; voice recordings and audio; call transcripts, summaries, and conversational content; call metadata (date, time, duration, numbers, status, disposition); appointment / booking data; and any other data a Data Subject provides during an interaction.
Special categoriesNone intended. Customer must not submit special-category or other sensitive data unless separately agreed in writing (see Section 3.3(e)).
Nature of ProcessingSpeech-to-text and text-to-speech conversational processing, call handling (inbound / outbound), transcription, summarisation, scheduling / booking, follow-up communications, persistent caller memory, storage, and related analytics, as necessary to provide the Services.
PurposeTo provide the Services as described in the Agreement and this DPA, and as otherwise instructed by Customer.
Duration / RetentionFor the term of the Services and any additional period specified in the Agreement or required by law (see Section 8).
Frequency of transferContinuous.
Storage and locationsCore customer application data (including contacts, transcripts, summaries, and metadata) is stored within the EU / EEA. Telephony / PSTN connectivity is provided within the EU. Call recordings are stored in Switzerland (which benefits from determinations of adequacy under the EU GDPR and UK GDPR).
Key SubprocessorsSupabase — database, authentication, and storage infrastructure (EU region; maintains SOC 2 Type II compliance). AI model infrastructure — primarily open-source models hosted within the EU. Telephony / PSTN provider (EU) and call-recording storage (Switzerland), together with billing (Stripe) and transactional email (Resend) providers used to operate the Services. Provider may engage additional model or infrastructure providers where reasonably necessary to provide the Services.

The current Subprocessor List, including functions and locations, is available on written request to compliance@cirel.ai.

S2Schedule 2 — Technical and Organisational Measures

Provider implements and maintains measures appropriate to the nature of the data, including:

  • Information security programme with assigned ownership and personnel security training.
  • Access controls — role-based, least-privilege access; unique credentials; prompt revocation on role change or termination; multi-factor authentication for privileged access where supported.
  • Encryption — Customer Personal Data encrypted in transit (TLS 1.2 or higher) and at rest where supported by the underlying infrastructure.
  • Tenant isolation — logical separation of customer workspaces and enforced data-access boundaries.
  • Data residency — core customer application data is stored within the EU / EEA; telephony / PSTN connectivity is provided within the EU; call recordings are stored in Switzerland (which benefits from adequacy determinations under the EU GDPR and UK GDPR).
  • Logging and monitoring of access and system activity.
  • Vulnerability and patch management, with periodic assessment and remediation per Provider’s risk policies.
  • Network security — firewalls, segregation, and intrusion-limiting controls.
  • Change management for material changes to systems.
  • Incident response procedures to detect, investigate, mitigate, and notify.
  • Backup and recovery procedures, periodically reviewed.
  • Subprocessor due diligence and contractual data-protection obligations.
  • Secure deletion / disposal of media and systems.

Provider’s database and storage infrastructure is operated by Supabase, which maintains SOC 2 Type II compliance. These infrastructure certifications support the security of the platform, but do not, of themselves, mean that Cirel Technologies Ltd is itself certified — Provider does not currently hold its own SOC 2 certification. See also Cirel’s privacy policy at cirel.ai/privacy.

S3Schedule 3 — Cross-Border Transfer Mechanisms

1. UK adequacy. Provider is established in the United Kingdom, which benefits from an EU adequacy decision. Accordingly, transfers of Customer Personal Data from the EEA to Provider in the UK are not, of themselves, Restricted Transfers for so long as that adequacy decision remains in force.

2. EU SCCs. Where Customer Personal Data is protected by the EU GDPR and is subject to a Restricted Transfer (including onward transfers to Subprocessors outside the EEA without an adequacy decision), the EU Standard Contractual Clauses (Commission Decision 2021/914) are incorporated by reference: Module 2 (Controller-to-Processor) where Customer is a Controller, and Module 3 (Processor-to-Processor) where Customer is a Processor; Customer is the data exporter and Provider the data importer; the docking clause (Cl. 7) does not apply; in Clause 9, Option 2 applies with the change-notice period in Section 4.2; in Clause 11 the optional language does not apply; in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; in Clause 18(b), disputes are resolved before the courts of Ireland; Schedule 1 supplies Annex I and Schedule 2 supplies Annex II.

3. UK Addendum. Where Customer Personal Data is protected by the UK GDPR and is subject to a Restricted Transfer, the EU SCCs apply as amended by the UK International Data Transfer Addendum (Version B1.0); the parties are deemed to have signed it; Tables 1–3 are completed by Schedules 1–2 and Section 2 of this Schedule; in Table 4, either party may end the Addendum as permitted.

4. Swiss transfers. Where the FADP applies, the EU SCCs apply with the competent authority being the Swiss FDPIC, governed by Swiss law, with references to the GDPR read as references to the FADP, and Swiss Data Subjects able to enforce their rights in Switzerland.

5. Onward transfers. Provider flows down equivalent transfer mechanisms to any Subprocessor receiving Customer Personal Data via a Restricted Transfer.


Questions about this DPA, or to request the current Subprocessor List, contact compliance@cirel.ai.