The Data Processing Addendum.
The Article 28-compliant terms for when NPC Protocol processes your customers’ data as a processor — subprocessors, security, breach, rights, and deletion. Built to sit under the MSA.
Version 1.0 · August 2026
MSA →When the front-desk or lead engine handles your customers’ data, you are the controller and NPC Protocol is your processor. This DPA is the contract that makes that relationship legally sound under UK GDPR (and US state law where it applies). Square brackets are the few specifics to confirm per client. Have your own counsel review it before signature.
1. Scope and roles
This Data Processing Addendum (“DPA”) applies whenever NPC Protocol (“Provider”) processes personal data on a client’s (“Client”) behalf in connection with the services. For this purpose Client is the controller (or, where Client is itself a processor, the party upstream) and Provider is the processor. This DPA supplements the Master Services Agreement and its Order Forms; where a conflict arises, the order of precedence is: this DPA, then the Order Form, then the MSA, then the website privacy and terms pages.
2. Subject matter, duration, and purpose
The subject matter is the personal data needed to deliver the services: websites, lead capture and qualification, the AI voice front-desk, and AI-visibility work. The duration of processing is the term of the relevant Order Form plus any lawful retention period. The nature and purpose of processing is to provide and operate those services on Client’s behalf. Provider does not process personal data for its own purposes.
3. Categories of data subjects and data
Data subjects include Client’s customers, callers, leads, and website visitors. Categories of personal data include contact details (name, email, phone), communication content (form text, emails, chat), voice call data (transcripts; raw audio only transiently, deleted after transcription), and interaction data (how a visitor or caller engages with the service). Where a form, email, call, or transcript contains special-category data (health, finances, or details about another person), Provider treats it as confidential, uses it only for the service, and deletes it on request.
4. Provider’s obligations (UK GDPR Article 28(3))
Provider will: process personal data only on documented instructions from Client, including with regard to transfers (this DPA and the MSA are those instructions); ensure persons authorised to process the data are bound by confidentiality; implement the technical and organisational measures in Annex B; and comply with the subprocessor, security, rights, audit, and deletion conditions in this DPA. Provider will not process the data in a way that is incompatible with the purpose of the service.
5. Subprocessors
Client gives Provider a general written authorisation to engage the subprocessors listed in Annex A, and to replace or add subprocessors, provided Provider remains fully responsible for each subprocessor’s performance of its obligations. Provider will give Client reasonable notice (at least thirty (30) days) before adding or replacing a subprocessor, and Client may object on reasonable data-protection grounds. Provider will flow down the same data-protection obligations to each subprocessor by contract.
6. Data subject rights
Provider will assist Client with requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection) and with Client’s obligations under the applicable law. If Provider receives a data subject request directly, it will forward it to Client without undue delay and will not respond to the data subject except as instructed by Client or required by law.
7. Security of processing (Article 28(3)(c))
Provider will implement and maintain the technical and organisational measures in Annex B, including encryption in transit and at rest, access controls and least privilege, multi-factor authentication for administrative access, logging and monitoring, and a process to detect and respond to security events. Provider will review and update these measures as technology and the risk change.
8. Personal data breach
Provider will notify Client of a confirmed or reasonably suspected personal data breach without undue delay, and in any event within forty-eight (48) hours of becoming aware of it, with the information needed for Client to meet its own notification duties. Provider will cooperate with Client’s investigation and any regulator or affected-person notifications, and will take steps to mitigate the effects.
9. International transfers
Where personal data is transferred to a country the relevant authority does not recognise as adequate — including transfers to or from the United Arab Emirates — the parties will put in place the appropriate transfer safeguard: for UK data, a UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; for EU/EEA data, the applicable SCCs. Provider will execute and provide the transfer document on request, and will complete a transfer risk assessment where required.
10. Audit and compliance
Client may audit Provider’s compliance with this DPA. Provider will make available reasonable evidence of compliance — such as relevant attestations, certifications, or a security summary — in place of on-site access where that is proportionate and sufficient, and will provide on-site or detailed inspection where reasonable and requested. Audits happen during business hours, with reasonable notice, and without unduly disrupting Provider’s operations.
11. Deletion and return
At the end of the service, Provider will, at Client’s choice, delete or return the personal data, and will delete existing copies, except where Provider is required to retain some data under applicable law — in which case Provider will isolate and protect that data and delete it when the retention reason ends.
12. Liability
Each party is liable to the other for breach of this DPA, subject to the limitation of liability in the MSA. A party is not liable for a breach caused by the other party’s failure to meet its own obligations here.
Annex A — Subprocessors (general authorisation)
The following categories of subprocessors are authorised for the service. Provider does not publish vendor names on public pages; the exact subprocessors, and the countries in which they process personal data, are identified to Client in the Order Form or on written request. (1) A third-party AI voice platform — call handling and speech-to-text. (2) A telephony service — phone numbers and call routing. (3) A messaging service — sending and receiving SMS, including the missed-call callback, and the caller numbers and message content that involves. (4) A language-model provider — text generation and lead scoring. (5) A hosting provider — site and service hosting. Each is bound to equivalent data-protection obligations by contract. This list matches the categories Provider is permitted to engage under clause 15 of the MSA.
Annex B — Technical and organisational measures
Encryption of data in transit (TLS) and at rest; role-based access control and least privilege; multi-factor authentication for administrative and remote access; segregation of environments; logging and monitoring with alerting; a documented process to detect, contain, and report security events; secure disposal of hardware and media; and personnel bound by confidentiality. These measures are reviewed as the risk and the technology change.