Data Processing Agreement (DPA)

Effective 10 May 2026.

This DPA forms part of the Terms of Service between Silux Telecom Ltd (Processor) and the customer (Controller) when personal data is processed under UK GDPR / EU GDPR.

1. Roles

Customer is the Controller for personal data uploaded into Silux Call (including call recordings, transcripts, contacts, voicemail). Silux Telecom Ltd is the Processor.

2. Subject matter and duration

Processing is for the purpose of delivering the Silux Call service for the term of the Customer's subscription, plus a 30-day post-termination wind-down.

3. Categories of data subjects and data

  • Data subjects: end-users at the Customer, callers and called parties, voicemail leavers.
  • Data categories: identification (name, email), contact (phone), audio (call recording), text (transcripts), traffic (CDR), payment (where the agent-assisted payment feature is enabled and tokenised by Stripe).

4. Sub-processors

Current list, by category. Customer is notified of changes 30 days before they take effect.

ProviderServiceRegion
Hetzner Online GmbHPrimary hostingGermany / Finland
Amazon Web ServicesBackup + KMS for HIPAA tenantsUK / EU
Stripe Payments UK LtdCard processing + Stripe ConnectUK + United States (with SCC)
Sendinblue / BrevoTransactional emailEU
Twilio Inc. (optional)SMS / OTPUK / Ireland (with SCC + IDTA)
Apple Push NotificationiOS VoIP pushUnited States (with SCC)
Google Firebase Cloud MessagingAndroid pushEU + United States (with SCC)
Voiceflex / BT WholesaleUK PSTN terminationUnited Kingdom

5. Technical & organisational measures

  • TLS 1.2/1.3 in transit, AES-256 at rest, KMS for HIPAA tenants.
  • SRTP+TLS for SIP at tenant request (`encryptionPolicy = require_srtp_tls`).
  • Role-based access; Asterisk AMI on loopback only.
  • Recording redaction during PCI DTMF capture.
  • Annual third-party penetration test; quarterly internal review.
  • Audit log retained 6 years; immutable on HIPAA tenants.

6. International transfers

Where transfers occur outside the UK / EEA, we rely on the IDTA and the EU SCCs (Module 2: controller-to-processor) plus encryption.

7. Audit

Customer may audit Silux on 30 days' written notice, no more than once a year, except in the event of a confirmed breach.

8. Breach notification

We notify the Customer's registered admin within 24 hours of confirmed incidents.


Silux Telecom Ltd is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Telecom Ltd. ICO registration: pending.