Data Processing Agreement (DPA)

Effective 10 May 2026.

This DPA forms part of the Terms of Service between Silux Control UK Ltd T/A Silux Call (Processor) and the customer (Controller) when personal data is processed under UK GDPR / EU GDPR.

1. Roles

Customer is the Controller for personal data uploaded into Silux Call (including call recordings, transcripts, contacts, voicemail). Silux Control UK Ltd T/A Silux Call is the Processor.

2. Subject matter and duration

Processing is for the purpose of delivering the Silux Call service for the term of the Customer's subscription, plus a 30-day post-termination wind-down.

3. Categories of data subjects and data

  • Data subjects: end-users at the Customer, callers and called parties, voicemail leavers.
  • Data categories: identification (name, email), contact (phone), audio (call recording), text (transcripts), traffic (CDR), payment (where the agent-assisted payment feature is enabled and tokenised by Stripe).

4. Sub-processors

Current list, by category. Customer is notified of changes 30 days before they take effect.

ProviderServiceRegion
Hetzner Online GmbHPrimary hostingGermany / Finland
Amazon Web ServicesBackup + KMS for HIPAA tenantsUK / EU
Stripe Payments UK LtdCard processing + Stripe ConnectUK + United States (with SCC)
Sendinblue / BrevoTransactional emailEU
Twilio Inc. (optional)SMS / OTPUK / Ireland (with SCC + IDTA)
Apple Push NotificationiOS VoIP pushUnited States (with SCC)
Google Firebase Cloud MessagingAndroid pushEU + United States (with SCC)
Voiceflex / BT WholesaleUK PSTN terminationUnited Kingdom

5. Technical & organisational measures

  • TLS 1.2/1.3 in transit, AES-256 at rest, KMS for HIPAA tenants.
  • SRTP+TLS for SIP at tenant request (`encryptionPolicy = require_srtp_tls`).
  • Role-based access; the telephony management interface is reachable on loopback only.
  • Recording redaction during PCI DTMF capture.
  • Annual third-party penetration test; quarterly internal review.
  • Audit log retained 6 years; immutable on HIPAA tenants.

6. International transfers

Where transfers occur outside the UK / EEA, we rely on the IDTA and the EU SCCs (Module 2: controller-to-processor) plus encryption.

7. Audit

Customer may audit Silux on 30 days' written notice, no more than once a year, except in the event of a confirmed breach.

8. Breach notification

We notify the Customer's registered admin within 24 hours of confirmed incidents.


Silux Control UK Ltd T/A Silux Call is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Control UK Ltd T/A Silux Call. ICO registration: pending.