sonadesk

Data Processing Agreement

Last updated 14 June 2026 · forms part of the Sonadesk Terms of Service between Sonadesk Ltd ("Processor", "we") and the customer business ("Controller", "you").

This Data Processing Agreement ("DPA") applies where, in providing the Sonadesk service, we process personal data on your behalf — for example your customers' names, phone numbers, email addresses, messages, call recordings and transcripts, bookings and job records. It is incorporated into and governed by our Terms of Service. Where this DPA conflicts with the Terms on data-protection matters, this DPA prevails. Capitalised terms (controller, processor, personal data, processing, data subject, personal data breach) have the meanings given in the UK GDPR and the Data Protection Act 2018 ("Data Protection Law").

1. Roles & scope

You are the controller of the personal data of your own customers and contacts that is processed through Sonadesk. We act as your processor for that data, and only to provide the service. For your own account data (your name, business details, login and billing), we are the controller — that is covered by our Privacy Policy, not this DPA. The subject matter, duration, nature and purpose of processing, and the types of personal data and categories of data subjects are set out in Annex A.

2. Our obligations as processor

We will:

(a) Process only on your instructions

Process the personal data only on your documented instructions — including transfers — unless required to do otherwise by law, in which case we will inform you first unless the law prohibits it. Using the service as configured (and any settings/requests you make) constitutes your documented instructions.

(b) Confidentiality

Ensure that anyone authorised to process the personal data is under an appropriate duty of confidentiality.

(c) Security

Implement appropriate technical and organisational measures to protect the personal data, taking into account the state of the art and the risks of processing. Our current measures are summarised in Annex C.

(d) Sub-processors

Only engage sub-processors in line with section 3.

(e) Assist with data-subject rights

Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). Self-service tools are provided in your dashboard (export and erase customer records); we will help with anything those tools don't cover.

(f) Assist with security, breaches & DPIAs

Assist you in ensuring compliance with your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to us.

(g) Personal data breach

Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification obligations.

(h) Deletion or return

At the end of the service, at your choice, delete or return the personal data and delete existing copies, unless the law requires storage. You can export your data at any time from your dashboard; after closure you have 30 days to export, after which data may be deleted (records we are legally required to retain excepted).

(i) Audits

Make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (unless required by a regulator or after a breach), during business hours, subject to confidentiality and without compromising other customers' data. We may satisfy audit requests by providing relevant certifications or reports of our sub-processors.

3. Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex B to help deliver the service. We impose data-protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible to you for their performance. We will keep Annex B current and give you reasonable prior notice of any new or replacement sub-processor (by updating this page and/or emailing you). You may object on reasonable data-protection grounds within 14 days; if we can't resolve your objection, you may terminate the affected part of the service.

4. International transfers

Personal data is processed primarily in the UK and the EEA. Where a sub-processor processes data outside the UK/EEA (for example certain US-based providers), the transfer is covered by an appropriate safeguard under Data Protection Law — the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK Addendum, and/or an adequacy decision where one applies.

5. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.

6. Term

This DPA takes effect when you accept the Terms and continues for as long as we process personal data on your behalf.

Annex A — Details of processing

Subject matterProvision of the Sonadesk platform (AI front desk, booking, messaging, payments tooling, CRM, certificates) to the Controller.
DurationFor the term of the Controller's subscription, plus the deletion/return window in section 2(h).
Nature & purposeCollecting, storing, organising, transmitting and displaying personal data to answer enquiries, take and manage bookings, send communications (with consent where required), produce quotes/invoices/certificates, and maintain customer records — on the Controller's behalf.
Types of personal dataNames, phone numbers, email addresses, postal/site addresses, message and chat content, call recordings and transcripts, booking and job details, quotes/invoices, and any personal data the Controller or its customers provide through the service.
Categories of data subjectsThe Controller's customers, prospective customers, contacts and (where applicable) staff.
Special category dataNot intended. The Controller should not input special-category data; the AI is designed to flag sensitive matters to a human rather than process them.

Annex B — Sub-processors

Current as of the date above. We will give notice of changes per section 3.

Sub-processorPurposeLocation
VercelApplication hostingUS / global edge
SupabaseDatabase & authenticationEU (eu-central-1)
StripePayments & billingUS / UK / EEA
TwilioTelephony & SMSUS / global
VapiAI voice orchestrationUS
DeepgramSpeech-to-text (voice transcription)US
ElevenLabsText-to-speech (AI voice)US
AnthropicAI language model (Claude)US
ResendOutbound emailUS / EEA
Twilio SendGridInbound email processingUS
GoogleCalendar integration (only where the Controller connects it)US / global
Meta Platforms (Facebook/Instagram)Messenger & Instagram messaging and posting (only where the Controller connects it)US / global
Intuit (QuickBooks)Accounting sync — customer name & email on invoices (only where the Controller connects it)US
X (Twitter)Social posting on the Controller's behalf (only where the Controller connects it)US / global

Annex C — Technical & organisational measures

Our current measures include: encryption of data in transit (TLS) and at rest; access to production data restricted to authorised personnel and service credentials, with database row-level security enabled; tenant isolation so each business's data is segregated and access is scoped per account; secrets held in a managed secrets store, not in code; signed/verified webhooks for telephony and payments; audit logging of sensitive administrative actions; least-privilege access; and regular review of these measures. Measures may evolve; we will not materially reduce overall security during the term.

Questions about this DPA: hayden@sonadesk.co.uk · Sonadesk Ltd · company no. 17275185 · registered in England & Wales.