This Data Processing Addendum (“Addendum”) forms part of the Terms of Service (“Terms”) between Sayora Ltd, a company registered in Scotland with company number SC888928 (“we”, “us”), and the business that holds the Sayora account (“you”). It sets out the terms required by Article 28 of the UK GDPR for the personal data we process on your behalf. If this Addendum and the Terms conflict on the processing of personal data, this Addendum wins.
You accept this Addendum by using Sayora. If you need a signed copy, email hi@sayora.ai with your business’s legal name and we will return a countersigned PDF of this version.
1. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended from time to time.
- Caller Data means the personal data described in Annex 1 that we process on your behalf.
- Sub-processor means a provider we engage that processes Caller Data for us.
- Regulator means the Information Commission (formerly the Information Commissioner’s Office) or any successor.
- Controller, processor, data subject, personal data breach and processing have the meanings given in the UK GDPR.
2. Roles
You are the controller of Caller Data and we are your processor. We are a controller in our own right for the data we hold about you as our customer (your account, billing and support conversations) and for the analytics of your own use of Sayora described in our Privacy Policy. That processing is outside this Addendum. The per-call outcome and duration our product analytics also receives is Caller Data, and is covered by Annex 1 and Annex 3.
3. Your instructions
We process Caller Data only on your documented instructions. Your instructions are:
- the Terms and this Addendum;
- how you set Sayora up in the portal, including your knowledge base, the details you ask Sayora to collect, any rules you give it, your notification settings, whether Sayora texts your callers, and any calendar, CRM or stock system you connect;
- the transfers described in §8 and the Sub-processors described in Annex 3;
- using Caller Data to support, test and improve the service we provide to you, as described below; and
- any further written instruction you send to hi@sayora.ai. We will carry it out where the service can, and otherwise tell you what we can do.
Supporting, testing and improving the service. You instruct us to use Caller Data to resolve support requests and faults, to check call quality, to test changes to how Sayora answers calls before and after they go live, and to produce anonymised, aggregated statistics (for example average call length) that cannot identify you or any caller. When we test with Caller Data we use only what the test needs, keep working copies only for as long as the test needs them, never use the data to contact anyone, never share it outside Sayora and its Sub-processors, and never use it to train a model to recognise or imitate a caller.
If we think an instruction infringes Data Protection Law, we will tell you straight away. We may decline to carry it out, or switch off the setting or rule concerned, until it is resolved.
If the law requires us to process Caller Data in a way you have not instructed, we will tell you before we do, unless the law prohibits that.
4. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subjects, and your obligations and rights as controller are set out in Annex 1.
5. Confidentiality
Only people who need Caller Data to provide, support or secure the service can access it, and each of them is under a contractual or statutory duty of confidentiality. A person may listen to a recording or read a transcript only for the purposes in §3.
6. Security
We take the technical and organisational measures required by Article 32 of the UK GDPR to protect Caller Data, including those in Annex 2. We review them as the service and the risks change, and will not reduce the overall level of protection during the Terms.
7. Sub-processors
You give us general written authorisation to engage Sub-processors for the functions listed in Annex 3. We will give you their names, functions and what we know about where each processes on request, and before you sign if you ask, on the confidentiality terms in our Privacy Policy.
- We will tell you by email at least 14 days before we add or replace a Sub-processor that processes Caller Data, naming the provider, its function and, so far as we know it, where it processes, and you can object on reasonable data-protection grounds within that time. If we can’t resolve your objection, you can end the Terms and we will refund any fees you have prepaid for the period after the change takes effect.
- Each Sub-processor is bound by written processor terms that impose data protection obligations no less protective in substance than this Addendum, including a lawful route for any transfer it makes outside the UK. A telephony carrier or network provider may also act as a controller of its own network and usage records under its own terms; that processing is theirs, not ours.
- We remain fully liable to you for how our Sub-processors handle Caller Data.
A calendar, CRM or stock system that you connect to Sayora is your own provider, not our Sub-processor. We send Caller Data to it on your instruction, and its provider handles that data under your own agreement with them.
8. International transfers
Your account data and all call recordings are held in Europe, and our speech-to-text providers are configured to European endpoints. Some Sub-processors, in particular the language models, process Caller Data outside the UK, and you should assume they do.
We transfer Caller Data outside the UK only where the transfer is to a country or organisation approved by regulations under Article 45A of the UK GDPR (including a recipient certified under the EU-US Data Privacy Framework and its UK Extension), or under the International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses, or where another lawful route under Data Protection Law applies. Before relying on the Agreement or the Addendum we assess that the data protection test in Article 46 of the UK GDPR is met and keep a record of that assessment, which we will summarise for you on request. If a route we rely on stops being valid, we will put another lawful route in place without undue delay.
9. Requests from callers
We will help you respond to callers exercising their rights under Data Protection Law, taking into account the nature of the processing. The portal shows you each call’s transcript, summary and caller details, and its recording until the recording is deleted. On your instruction we will give you a copy of what we hold about a caller, correct or delete it, restrict its processing, or stop texting their number, without undue delay.
If a caller contacts us directly about their data, we will pass the request to you without undue delay and will not respond to it ourselves, other than to tell the caller we have done so.
10. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Caller Data. We will tell you what we know about its nature, the data and callers likely to be affected, its likely consequences and the steps we are taking, and add to that as we learn more. We will take reasonable steps to contain the breach and to help you meet your own notification duties.
11. Other assistance
Taking into account the nature of the processing and the information available to us, we will give you reasonable help with your obligations under Articles 32 to 36 of the UK GDPR, including data protection impact assessments and any prior consultation with the Regulator.
12. When the service ends
When your service ends, you choose whether we delete Caller Data or return it to you. Unless you tell us otherwise, we delete it on the schedule in §10 of the Terms: 90 days after the service ends, or 30 days for a trial that never paid and was not closed by email. You can ask us to delete it sooner. If you ask for a copy before deletion, we will send you all the Caller Data we still hold, including any recordings still within their 90-day life, in commonly used formats (CSV for records, audio files for recordings), and we will confirm deletion in writing when you ask. Recordings are deleted 90 days after each call, whether or not the account is still open.
Encrypted backups can hold a copy for up to 30 days (the database) or 90 days (recordings) after the backup was taken, plus a short recovery window. Nothing in the service reads them, they are restored only to recover from a disaster, and if a restore ever brings deleted Caller Data back we delete it again. We keep Caller Data beyond these periods only where the law requires it.
13. Information and audits
We will make available the information you reasonably need to show that we comply with this Addendum, including answers to reasonable security questionnaires. If you reasonably consider that is not enough, you, or an independent auditor you appoint who is bound by confidentiality, may audit our compliance with this Addendum:
- on at least 30 days’ written notice, during business hours and without unreasonable disruption to the service;
- no more than once in any 12 months, except where the Regulator requires an audit or after a personal data breach affecting Caller Data, when neither the notice period nor the limit applies; and
- at your own cost, and without access to other customers’ data or to information whose disclosure would compromise the security of the service.
We will fix any material failure an audit finds within a reasonable time.
14. Liability
The limitations and exclusions of liability in the Terms apply to this Addendum, to the extent Data Protection Law allows, except that the exclusion in §14 of the Terms for loss caused by third-party providers does not apply to a Sub-processor’s breach of this Addendum. Nothing in this Addendum limits either party’s liability to data subjects or to the Regulator under Data Protection Law.
15. Duration, changes and governing law
This Addendum applies for as long as we process Caller Data for you. We may update it in the same way as the Terms (see §17 of the Terms), but no change will reduce the protection it gives Caller Data except to reflect a change in Data Protection Law. It is governed by the laws of Scotland, and the Scottish courts have exclusive jurisdiction.
Annex 1: Details of the processing
| Subject matter | Answering inbound calls to the phone numbers Sayora answers for you, and handling the personal data those calls produce. |
|---|---|
| Duration | For as long as the Terms last, and then for the retention periods below and in §12. |
| Nature of the processing | Receiving and routing calls, and declining calls from withheld numbers if you ask us to; recognising a returning caller by their number; recording calls; speech recognition and AI-generated speech and replies during the call; transcription; automatic removal of detected sensitive details from transcripts and recordings; post-call analysis that produces a summary, an urgency flag, a quality rating and the details you asked Sayora to collect; storage; notifying your team by text and email; texting callers a recap (if you turn it on) and confirming appointments Sayora books, moves or cancels; booking into a calendar you connect; sending leads, and the property or item they asked about, to a CRM or stock system you connect; recording per-call outcome and duration in our product analytics; and the support, testing and improvement described in §3. |
| Purpose | Providing the service described in the Terms, in line with your instructions. |
| Data subjects | People who call the numbers Sayora answers for you; people a caller mentions on a call; and your staff and anyone else named in content you give Sayora, such as your knowledge base. |
| Personal data | Phone number and caller ID; name; email address and postal address where given; the reason for the call and the details you ask Sayora to collect; the property or item a caller asked about; appointment details; call audio; transcripts and summaries; the texts we send a caller; notes and tags your team or ours add to a caller; and call metadata (start and end times, duration, outcome, urgency, whether the lead has been handled, and spam classification). |
| Special category and criminal offence data | Not intended. A caller may volunteer it, for example a health detail. If your calls routinely involve special category data, you must have a condition under Article 9 of the UK GDPR, and for criminal offence data a condition under Article 10 (see §6 of the Terms). Detected card numbers, bank details, passwords and similar are removed automatically after the call, but removal is not guaranteed. |
| Frequency | Continuous, whenever a call is answered. |
| Retention | Recordings: deleted 90 days after the call. Transcripts, summaries, caller details and call metadata: kept while the account is open or archived, then deleted as set out in §12. |
| Your obligations | To have a lawful basis for processing Caller Data, and an Article 9 or 10 condition where one is needed; to tell callers that Sayora answers and records your calls, including in your own privacy notice, and not to disable the recording notice; to give us your instructions through the portal or in writing; to respond to callers’ requests about their data; to tell us promptly of any breach you become aware of that involves Caller Data; and to keep the content you give Sayora accurate (see §§4 and 6 of the Terms). |
| Your rights | To instruct us (§3); to be told before a Sub-processor changes, and to object (§7); to be helped with callers’ requests, breaches and impact assessments (§§9 to 11); to choose deletion or return when the service ends, and to ask for deletion sooner (§12); and to information and audits (§13). |
Annex 2: Security measures
- Separation: each customer’s data is kept apart by row-level security in the database, so one customer’s session cannot read another’s records.
- Access: your users see only your own account. Sayora staff access runs through a separate administrative role, limited to the people who need it and bound by §5.
- Encryption in transit: data sent over the internet between your browser or app, our systems and our providers is encrypted with TLS. Calls and texts over the public phone network are carried by the telephony providers.
- Secrets: the keys, tokens and webhook secrets for connected calendars and CRMs are encrypted at rest with AES-256-GCM, under a key held in our hosting provider’s secret store, separate from the database.
- Recordings: held in private storage and played back only through an authenticated route to authorised users, using a short-lived link.
- Redaction: after each call, detected sensitive details, including card numbers, bank details and passwords, are removed from the transcript and bleeped out of the recording. Where that step cannot complete, for example during a provider outage, only phone numbers and email addresses are removed from that call, and occasionally the recording is left unedited or replaced entirely by a tone. The caller’s name and the address they gave you are deliberately kept.
- Retention: recordings and closed accounts are deleted automatically on the schedule in this Addendum.
- Backups: encrypted offsite backups of the database and recordings, which expire automatically.
- Providers: our speech-recognition and voice providers are opted out of using what they process for us to train or improve their models, and our language-model providers’ terms do not allow them to train on it.
- Review: we review the code and configuration of the service for security issues, and fix, mitigate or formally accept what we find.
Annex 3: Sub-processors
We use Sub-processors for the following. We will give you their names, functions and what we know about where each processes on request at hi@sayora.ai, and before you sign if you ask.
- Telephony and call routing, including the UK phone number assigned to you.
- The real-time voice platform that carries the call audio and runs the receptionist.
- Speech-to-text transcription, and the word timings used to bleep sensitive details out of a recording.
- Large language models, for what Sayora says on the call, the post-call analysis, the texts Sayora writes and the index of your knowledge base.
- Text-to-speech, the voice callers hear.
- Cloud hosting, the database and file storage for call recordings.
- Encrypted offsite backup.
- Email and SMS delivery.
- Product analytics, which receives each call’s outcome and duration against your account, and never a caller’s identity or call content.
- Error monitoring for the Sayora app and voice runtime.