Data Processing Agreement

Version 1.0, 10 July 2026

This Data Processing Agreement (DPA) is entered into between Answrd (the data processor) and the client business (the data controller) as required under UK GDPR Article 28. It forms part of the Answrd Terms of Service and applies to all clients from the date of subscription.

1. Definitions

Controller: The client business signing up for Answrd, who determines the purposes and means of processing their customers' personal data.

Processor: Calem Taylor, trading as Answrd, who processes personal data on behalf of the Controller.

Personal Data: Any information relating to an identified or identifiable natural person, including phone numbers, names, addresses, and conversation content.

Processing: Any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.

UK GDPR: The UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018.

2. Subject matter and duration

This DPA governs the processing of personal data by Answrd on behalf of the Controller in connection with providing the Answrd service. It remains in effect for the duration of the subscription and for 12 months following termination, after which all personal data will be deleted or anonymised.

3. Nature and purpose of processing

Answrd processes personal data for the following purposes on behalf of the Controller:

4. Categories of personal data processed

5. Categories of data subjects

The personal data relates to customers and prospective customers of the Controller's business who contact the Controller by phone or SMS.

6. Processor obligations

Answrd, as data processor, agrees to:

7. Controller obligations

The Controller agrees to:

8. Sub-processors

Answrd uses the following sub-processors to deliver the service. The Controller consents to their use by accepting these terms:

All sub-processors are bound by data processing agreements with Answrd. International transfers are protected by Standard Contractual Clauses where applicable.

Answrd will notify the Controller of any intended changes to sub-processors, giving the Controller reasonable opportunity to object.

9. Security measures

Answrd implements the following technical and organisational security measures:

10. Data breaches

In the event of a personal data breach affecting the Controller's data, Answrd will notify the Controller within 72 hours of becoming aware of the breach, providing sufficient information to allow the Controller to meet their own notification obligations under UK GDPR.

11. Data subject rights

Answrd will assist the Controller in fulfilling data subject rights requests, including requests for access, rectification, erasure, restriction, and portability, within timeframes that allow the Controller to meet their legal obligations.

12. Audit rights

The Controller may request reasonable information from Answrd to demonstrate compliance with this DPA. Answrd will respond to such requests within 30 days.

13. Termination and deletion

Upon termination of the service, Answrd will, at the Controller's written request, either delete or return all personal data processed under this DPA within 30 days. Answrd may retain anonymised or aggregated data that does not identify individuals.

14. Governing law

This DPA is governed by the laws of England and Wales and is subject to the jurisdiction of the courts of England and Wales.

15. Acceptance

This DPA is incorporated into and forms part of the Answrd Terms of Service. By subscribing to Answrd, the Controller accepts this DPA. No separate signature is required for standard subscriptions.

Where a signed copy is required, contact calem.taylor@answrd.co.uk to arrange a countersigned version.

For signed agreements, complete and return to hello@answrd.co.uk

Data Processor (Answrd)

Signature
Name: Calem Taylor
Date

Data Controller (Client)

Signature
Name and business name
Date