Skip to content

Data processing terms

Last updated

Draft: pending UK legal review. This document is a working draft and will be reviewed by a UK solicitor before JobsAnswered launches.

These data processing terms ("DPA") form part of the JobsAnswered terms of service and apply where JobsAnswered processes personal data on behalf of a customer under UK data protection law (UK GDPR and the Data Protection Act 2018).

1. Roles

The customer is the controller and JobsAnswered is the processor of personal data relating to the customer's callers ("Caller Data").

2. Details of processing

Subject matter Answering calls, recording enquiry details, sending service texts, transfers and bookings
Duration The term of the subscription plus the retention period after cancellation
Data subjects People who call the customer's business, and the customer's staff where named for transfers
Personal data Phone numbers, names, postcodes/addresses, contact details, enquiry details, transcripts, recordings (if enabled), photos uploaded by callers
Special category data Not intended. Callers may volunteer health information (for example a vulnerable household member). It is used only to prioritise the enquiry.

3. Instructions

JobsAnswered processes Caller Data only on the customer's documented instructions, including the configuration the customer approves, unless required by law.

4. Confidentiality and security

Personnel with access are bound by confidentiality. Measures include encryption in transit and at rest, role-based access, tenant isolation, signed and expiring links, audit logging, backups with restore testing, and monitoring.

5. Subprocessors

The customer gives general authorisation for the subprocessors listed on our subprocessors page. We will give at least 30 days' notice of new subprocessors; the customer may object on reasonable grounds and, if unresolved, terminate.

6. International transfers

Where Caller Data is transferred outside the UK, we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.

7. Assistance

We assist the customer with data subject requests (including export and deletion tools), data protection impact assessments and consultations where reasonably required.

8. Breaches

We notify the customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Caller Data, with the information reasonably available.

9. Deletion and return

On termination, the customer may export Caller Data for 90 days, after which we delete it, except where retention is required by law.

10. Audits

We make available information reasonably necessary to demonstrate compliance and allow for reasonable audits on notice, no more than once a year unless required by a regulator or following a breach.