Data Processing Agreement (DPA)

The Data Processing Agreement describes how Intavia processes personal data on behalf of customers in compliance with GDPR and other data protection laws.


Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) forms part of the Agreement between Truetide AI Limited (“Processor”, “Provider”, “we”) and any Customer entering into an Order Form or using the Services (“Controller”, “Customer”, “you”).

This DPA reflects the parties’ obligations under the UK GDPR, EU GDPR, and applicable data protection laws governing the processing of Personal Data in connection with the Services.


1. Definitions

Capitalised terms have the meanings set out in the Agreement unless defined here.

“Agreement” means the Statement of Work, this DPA, all Order Forms, and any applicable addenda.

“Data Protection Laws” means all applicable data protection and privacy legislation in force from time to time in the United Kingdom and, where applicable, the European Union, including without limitation the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), the EU GDPR, and any successor or implementing legislation.

“Personal Data” means any information relating to an identified or identifiable natural person.

“Personal Data Breach” has the meaning given in Data Protection Laws and includes any loss, accidental or unlawful destruction, damage, corruption, alteration, disclosure of, or access to Personal Data.

“Processing”, “Controller”, “Processor”, “Data Subject”, and “Supervisory Authority” have the meanings given in Data Protection Laws.

“Customer Data” means all data (including Personal Data) submitted or generated by Customer via the Services.

“Customer Systems” means systems, CRMs, telephony providers, infrastructure, and tools Customer owns or controls.

“Sub-Processor” means any third party engaged by Provider to process Customer Data.

“Services” means the functionality described in the Order Form and Documentation. Any functionality not expressly described in the Order Form or Documentation is excluded.

“Term” has the meaning given in clause 3.3 of this DPA.

Any functionality not expressly described in the Order Form or Documentation is excluded.


2. Roles of the Parties

2.1 Controller–Processor

For Customer Data processed through the Services, Customer is the Controller and Provider is the Processor.

2.2 Independent Controller Activities

For Provider’s own processing (billing, account management, fraud prevention, product analytics using aggregated/anonymised data), Provider acts as an independent Controller.

2.3 Instructions

Provider will only process Personal Data on documented instructions from Customer:

If Provider believes an instruction violates Data Protection Laws, it shall notify Customer.


3. Subject Matter, Nature, Purpose, Duration

3.1 Subject Matter

Processing of Customer Data in connection with the provision of the Services.

3.2 Nature & Purpose

Provider processes Personal Data to:

3.3 Duration

Processing continues for the term of the Agreement, plus applicable retention periods.

Detailed processing information appears in Annex 1.


4. Types of Personal Data & Data Subjects

4.1 Categories of Personal Data

Categories include (without limitation):

Category Examples
Identification & Contact Names, phone numbers, email addresses, business identifiers
Communication Content Call audio, transcripts, text interactions, free-text content spoken or entered
Metadata Phone numbers dialled, timestamps, duration, routing, menu selections, call outcomes, tags, labels
Booking / Appointment Information   Service types, dates, times, staff members, notes entered by Customer
Customer Users User account details, login identifiers, usage logs
Technical Information IP addresses, device/browser type, operational logs
Free-Text Notes Any text entered by Customer via dashboards or configuration panels

4.2 Special Categories

Not intended to process special category data.

If callers voluntarily share such data, Controller is responsible for:

4.3 Data Subjects

Data Subjects may include:


5. Processor Obligations

Provider shall:

5.1 Records of Processing

Maintain records of processing activities to the extent required by Data Protection Laws.

5.2 Confidentiality

Ensure all authorised persons are under confidentiality obligations.

5.3 Security

Implement appropriate technical and organisational safeguards (see Annex 2).

5.4 Assistance with Data Subject Rights

Assist Customer (at Customer’s cost where applicable) with Data Subject rights requests.

5.5 Assistance with Compliance

Assist Customer with:

5.6 Breach Notification

Provider shall notify Customer without undue delay (and where feasible within 72 hours) of any Personal Data Breach affecting Customer Data, including any loss, unintended destruction, corruption, alteration, unauthorised access to, or disclosure of Personal Data. Provider will supply sufficient information to enable Customer to meet its legal obligations.

5.7 Deletion or Return at Termination

Upon termination:


6. AI Output Behaviour

6.1 Nature of AI Outputs

The Services use machine-learning models that may:

6.2 AI Output Is Not a Data Breach

AI hallucination, synthetic generation, or inaccurate inference does not constitute a Personal Data Breach unless caused by an underlying security incident.

6.3 Controller Responsibility

Customer remains responsible for:

6.4 Sensitive Data

Customer must not require AI to generate, infer, or process special category data unless they have a lawful basis and configure retention/controls accordingly.


7. Sub-Processors

7.1 Authorisation

Customer authorises the Sub-Processors listed in Annex 3.

7.2 Additions & Changes

Provider may add or replace Sub-Processors.

Customer will be notified of material changes.

7.3 Objection Right

If Customer objects on reasonable data protection grounds, parties will seek a solution.

If none is found, Customer may terminate only the affected Services.

7.4 Sub-Processor Obligations

Provider ensures Sub-Processors are bound by obligations no less protective than this DPA.

Provider remains liable for Sub-Processor actions.


8. International Transfers

Provider and Sub-Processors may process Personal Data in the UK, EEA, US, or other jurisdictions.

Where required, Provider relies on:


9. Security Measures

Provider implements:

Detailed overview: Annex 2.


10. Data Storage, Recordings, and Retention

10.1 Call Recordings & Transcripts

Where enabled:

10.2 Customer Responsibility

Customer is responsible for:

10.3 Deletion at Request

Provider will act on Customer deletion instructions where technically feasible.


11. Use of Data for Service Improvement

Provider may use anonymised or aggregated data to:

Customer may opt out by written notice, acknowledging performance may degrade.

Provider does not sell Personal Data or use it for third-party marketing.


12. Audits & Information

12.1 Documentation

Provider will make available information demonstrating compliance, including:

12.2 Audits

Where required by law, Customer may conduct audits:

Limited to one audit per year, unless required by a Supervisory Authority or following a confirmed breach.

Costs: Customer bears its own costs and Provider’s reasonable costs unless Provider is in material breach.


13. Data Subject Requests

If a Data Subject submits a request or complaint directly to Provider, Provider will, where feasible, redirect the individual to Customer or notify Customer without undue delay.

Customer is responsible for responding to Data Subject rights requests and complaints. Provider will assist Customer to the extent required by Data Protection Laws and technically feasible, and may charge for such assistance where permitted by law.


14. Priority & Conflict

If this DPA conflicts with other parts of the Agreement, this DPA prevails solely for Personal Data Processing.

All other terms remain in full force.


15. Governing Law

This DPA is governed by the laws of England and Wales.

Courts of England and Wales have exclusive jurisdiction.


16. Liability

Liability arising under or in connection with this DPA is governed exclusively by the liability provisions set out in the Agreement (MSA). No additional liabilities are created by this DPA.


Annex 1 — Data Processing Details

This Annex provides the detail required by Article 28(3) GDPR regarding the nature, scope, purpose, and duration of processing carried out by Provider on behalf of Customer.

1. Subject Matter of Processing

Processing of Customer Data (including Personal Data contained in inbound and outbound calls, transcripts, metadata, booking information, logs, and any data surfaced into the Platform) for the purpose of providing the Services.


2. Duration of Processing

Processing occurs for:

Customer may request earlier deletion where technically feasible.


3. Nature and Purpose of Processing

Processing activities include:

Inbound Call Handling

Outbound Calling (if enabled)

AI-Generated Outputs

Data Surfacing and Storage

Integrations with Customer Systems

Support & Quality Assurance

Service Improvement (aggregated/anonymised)

Customer may opt out of improvement processing (beyond operational necessity) by written notice.


4. Categories of Personal Data

The following categories may be processed (non-exhaustive, depending on Customer configuration):

Category Examples
Identification & Contact Information Name, phone number, email address; business or practice name; role/title where provided
Call Audio & Transcripts Voice recordings of callers; text transcripts generated by speech models; metadata associated with recordings; summaries or structured derivatives (tags, actions, labels)
Operational Metadata Call timestamps, duration, routing choices; telephone numbers involved (inbound/outbound); flow paths, menu selections; call outcomes (answered, missed, transferred, completed)
Appointment & Booking Data Appointment type, service category; date, time, location; staff/resource allocation; notes provided by caller or Customer
Customer User Data Authorised user names, emails; role and permission levels; platform activity logs
Technical Data IP address; device/browser information; performance logs and error traces (e.g., via Sentry or Datadog)
Free-Text Content Any unstructured data provided by Customer or callers, manually or verbally

5. Categories of Data Subjects


6. Special Categories of Data

Provider does not intend to process special category data.

However, callers may voluntarily disclose such data during conversations (e.g., minor health information such as “I have back pain”). If Customer configures flows that lead to such disclosures, Customer is responsible for:

Provider will process such data only as necessary to fulfil Customer instructions.


Annex 2 — Security Measures

Provider implements technical and organisational measures appropriate to the risk, in accordance with Articles 28, 32 and 5(1)(f) GDPR.

A high-level summary of measures is outlined below.

1. Organisational Measures

1.1 Information Security Policies

1.2 Access Control & Authentication

1.3 Confidentiality Obligations

1.4 Secure Development Practices


2. Technical Measures

2.1 Encryption

2.2 Infrastructure Security

2.3 Monitoring & Logging

2.4 Incident Response

2.5 Data Minimisation & Retention Controls


3. Telephony & AI Model Security

3.1 Telephony Security (Twilio)

3.2 AI Model Security


4. Third-Party Sub-Processor Controls

Provider ensures Sub-Processors:


5. Business Continuity & Resilience


These measures are reviewed periodically and updated to reflect evolving risks, best practices, and operational needs.


Annex 3 — Sub-Processors

Provider uses certain Sub-Processors to support the delivery of the Services.

The current list of Sub-Processors is available upon request.

Provider may update the list in accordance with Section 7 of this DPA (Sub-Processors).

Customer will be notified of any material changes in accordance with the Agreement.


Contact us

Email: team@truetide.ai
Controller: Truetide AI Limited
Registered address: Wembley Park, London