This agreement applies automatically to every customer and forms part of our terms of service. If your procurement process needs it signed as a separate document, email [email protected] and we will arrange it.
1. Roles: who controls what
Getting this right is the whole point of the document, because two different relationships exist at once:
- You are the controller of the personal data your use of the service involves: the contacts you upload, the people your agents call and message, and everything those people say on a call. You decide who is contacted, why, and what is collected.
- We are your processor for that data. We process it only to provide the service and only on your documented instructions, which, in ordinary use, are the settings and prompts you configure in the product.
- We are a controller in our own right only for your account itself: the names and email addresses of your team, billing records, and support correspondence. That is covered by our privacy policy, not by this agreement.
2. Scope of processing
Subject matter: supplying and running B3 Voice bots on the customer’s campaigns.
Duration: for as long as your account is active, plus the deletion period in section 8.
Nature and purpose: placing calls on your campaigns through your dialer, transcribing them so the bot can respond, qualifying callers against your script, transferring qualified callers to your closers, and returning the outcome to your dialer.
Categories of data subject: the people you call or message, and the people who call your numbers.
Categories of personal data: names, telephone numbers, email addresses, call audio, transcripts, and whatever else a caller volunteers during a conversation or you include in a contact list.
Special-category data: the service is not designed for it. If your use case means callers are likely to disclose health or other special-category data, you must have a lawful basis and appropriate safeguards, and you should tell us before you go live.
3. Our obligations
- Process personal data only on your instructions, unless required otherwise by law , in which case we will tell you first unless the law forbids it.
- Ensure everyone with access is under a duty of confidentiality, and limit access to those who need it.
- Apply the security measures in section 5.
- Assist you, so far as we reasonably can, with data-subject requests, data protection impact assessments and consultations with the ICO.
- Tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- Make available the information you need to demonstrate compliance.
4. Your obligations
- Have a lawful basis for contacting everyone on your lists, and be able to evidence it. See the acceptable use policy.
- Tell people their call is being recorded, at the start of the call, and explain why.
- Provide your own privacy information to the people you contact, we are not in a position to do it for you.
- Configure retention to something you can justify, rather than keeping recordings indefinitely by default.
- Handle data-subject requests that reach you, using the tools in the product.
5. Security measures
The measures in place are described in full on our security page, including what we are not certified for. In summary: encryption in transit and at rest, organisation-scoped isolation enforced on every query, role-based access control, session revocation checked on every request, and telephony credentials encrypted per number with AES-256-GCM.
6. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with what each one does and where it processes data, is maintained at /sub-processors.
We will give at least 30 days’ notice before adding or replacing one. If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you to resolve it; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund of fees paid in advance.
Each sub-processor is bound by written terms no less protective than these, and we remain liable to you for their performance.
7. International transfers
Some sub-processors process data outside the UK, principally in the United States. Where they do, transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with a transfer risk assessment. The region for each provider is shown on the sub-processors page.
8. Return and deletion
You can export or delete your data from the product at any time. On termination we retain it for a short period so you can export it, then delete it from live systems, with backups ageing out on their normal cycle. Ask us in writing if you need deletion sooner, or written confirmation once it is done.
9. Audit
On reasonable written notice, and no more than once a year unless required by a regulator or following a breach, we will provide the information reasonably necessary to demonstrate compliance with this agreement. We are not currently able to offer a SOC 2 or ISO 27001 report, see our security page, so this takes the form of a written response and, where appropriate, a call with the people who run the systems.
