Data Processing Agreement (DPA)
Effective 10 May 2026.
This DPA forms part of the Terms of Service between Silux Control UK Ltd T/A Silux Call (Processor) and the customer (Controller) when personal data is processed under UK GDPR / EU GDPR.
1. Roles
Customer is the Controller for personal data uploaded into Silux Call (including call recordings, transcripts, contacts, voicemail). Silux Control UK Ltd T/A Silux Call is the Processor.
2. Subject matter and duration
Processing is for the purpose of delivering the Silux Call service for the term of the Customer's subscription, plus a 30-day post-termination wind-down.
3. Categories of data subjects and data
- Data subjects: end-users at the Customer, callers and called parties, voicemail leavers.
- Data categories: identification (name, email), contact (phone), audio (call recording), text (transcripts), traffic (CDR), payment (where the agent-assisted payment feature is enabled and tokenised by Stripe).
4. Sub-processors
Current list, by category. Customer is notified of changes 30 days before they take effect.
| Provider | Service | Region |
|---|---|---|
| Hetzner Online GmbH | Primary hosting | Germany / Finland |
| Amazon Web Services | Backup + KMS for HIPAA tenants | UK / EU |
| Stripe Payments UK Ltd | Card processing + Stripe Connect | UK + United States (with SCC) |
| Sendinblue / Brevo | Transactional email | EU |
| Twilio Inc. (optional) | SMS / OTP | UK / Ireland (with SCC + IDTA) |
| Apple Push Notification | iOS VoIP push | United States (with SCC) |
| Google Firebase Cloud Messaging | Android push | EU + United States (with SCC) |
| Voiceflex / BT Wholesale | UK PSTN termination | United Kingdom |
5. Technical & organisational measures
- TLS 1.2/1.3 in transit, AES-256 at rest, KMS for HIPAA tenants.
- SRTP+TLS for SIP at tenant request (`encryptionPolicy = require_srtp_tls`).
- Role-based access; the telephony management interface is reachable on loopback only.
- Recording redaction during PCI DTMF capture.
- Annual third-party penetration test; quarterly internal review.
- Audit log retained 6 years; immutable on HIPAA tenants.
6. International transfers
Where transfers occur outside the UK / EEA, we rely on the IDTA and the EU SCCs (Module 2: controller-to-processor) plus encryption.
7. Audit
Customer may audit Silux on 30 days' written notice, no more than once a year, except in the event of a confirmed breach.
8. Breach notification
We notify the Customer's registered admin within 24 hours of confirmed incidents.
Silux Control UK Ltd T/A Silux Call is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Control UK Ltd T/A Silux Call. ICO registration: pending.