Data Processing Agreement (DPA)
Effective 10 May 2026.
This DPA forms part of the Terms of Service between Silux Telecom Ltd (Processor) and the customer (Controller) when personal data is processed under UK GDPR / EU GDPR.
1. Roles
Customer is the Controller for personal data uploaded into Silux Call (including call recordings, transcripts, contacts, voicemail). Silux Telecom Ltd is the Processor.
2. Subject matter and duration
Processing is for the purpose of delivering the Silux Call service for the term of the Customer's subscription, plus a 30-day post-termination wind-down.
3. Categories of data subjects and data
- Data subjects: end-users at the Customer, callers and called parties, voicemail leavers.
- Data categories: identification (name, email), contact (phone), audio (call recording), text (transcripts), traffic (CDR), payment (where the agent-assisted payment feature is enabled and tokenised by Stripe).
4. Sub-processors
Current list, by category. Customer is notified of changes 30 days before they take effect.
| Provider | Service | Region |
|---|---|---|
| Hetzner Online GmbH | Primary hosting | Germany / Finland |
| Amazon Web Services | Backup + KMS for HIPAA tenants | UK / EU |
| Stripe Payments UK Ltd | Card processing + Stripe Connect | UK + United States (with SCC) |
| Sendinblue / Brevo | Transactional email | EU |
| Twilio Inc. (optional) | SMS / OTP | UK / Ireland (with SCC + IDTA) |
| Apple Push Notification | iOS VoIP push | United States (with SCC) |
| Google Firebase Cloud Messaging | Android push | EU + United States (with SCC) |
| Voiceflex / BT Wholesale | UK PSTN termination | United Kingdom |
5. Technical & organisational measures
- TLS 1.2/1.3 in transit, AES-256 at rest, KMS for HIPAA tenants.
- SRTP+TLS for SIP at tenant request (`encryptionPolicy = require_srtp_tls`).
- Role-based access; Asterisk AMI on loopback only.
- Recording redaction during PCI DTMF capture.
- Annual third-party penetration test; quarterly internal review.
- Audit log retained 6 years; immutable on HIPAA tenants.
6. International transfers
Where transfers occur outside the UK / EEA, we rely on the IDTA and the EU SCCs (Module 2: controller-to-processor) plus encryption.
7. Audit
Customer may audit Silux on 30 days' written notice, no more than once a year, except in the event of a confirmed breach.
8. Breach notification
We notify the Customer's registered admin within 24 hours of confirmed incidents.
Silux Telecom Ltd is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Telecom Ltd. ICO registration: pending.