Dialem

Legal

Data Processing Agreement

When you put your leads into Dialem, you stay responsible for them and we act on your instructions. This is the contract that says so, and what we owe you as a result.

Version 1.0 · Effective 13 August 2026

What this is, in plain terms

  • You are the controller of your leads. We are your processor. You decide what the data is for; we do what you tell us with it.
  • It applies automatically. You do not need to sign anything or ask us for a copy - it forms part of your Terms of Service the moment you open an account.
  • Annex II lists the security measures we actually perform, not the ones we aspire to. Annex III names every sub-processor.
  • We will tell you 30 days before a new sub-processor starts handling your data, so you have time to object.

This summary is not part of the agreement. Sections 1 to 13 and the Annexes are.

1. Definitions and how this fits together

This agreement (the “DPA”) is between Studio 404 Development Ltd, registered in England and Wales under number 17241297, registered office 344 Oldfield Road, Altrincham, England, WA14 4QS (“we”, the Processor), and the customer identified on the Dialem account (“you”, the Controller).

It forms part of, and is governed by, the Terms of Service. Where this DPA and those terms conflict on the processing of personal data, this DPA wins. Where this DPA and the Privacy Policy conflict as between you and us, this DPA wins - the Privacy Policy is a notice to the world, this is a contract between two parties.

“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and the EU GDPR where it applies to your use of the Services. “Controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” carry the meanings in that law.

“Customer Personal Data” means personal data we process on your behalf through the Services - principally your leads and the record of your contact with them, as described in Annex I.

2. Roles, and the one part where we are not your processor

For Customer Personal Data, you are the controller and we are your processor. You are responsible for having a lawful basis to hold and contact those people, for the accuracy of what you upload, and for the notices you give them.

We are a controller of your account data - the names and email addresses of the people on your team, billing details, and our logs of how the Services are used. That is not processed on your instructions and is not covered by this DPA; it is covered by the Privacy Policy. Nobody can be another company’s processor for their own billing records, and a DPA claiming otherwise is one that has not been read.

Neither of us is a joint controller with the other, and nothing here makes us one.

3. Our instructions come from you

We process Customer Personal Data only on your documented instructions, including on transfers, unless we are required to do otherwise by law - in which case we will tell you before processing, unless that law forbids us from telling you.

Your documented instructions are: the Terms of Service, this DPA, and what you do in the product. Configuring a flow, importing a list, pressing dial and switching on the assistant are all instructions, and we treat them as such.

If we believe an instruction infringes Data Protection Law, we will tell you. We may decline to carry it out until it is resolved, and doing so is not a breach of the Terms of Service by us.

We will not sell Customer Personal Data, use it for our own marketing, use it to train artificial intelligence models, or combine it with another customer’s data.

4. Confidentiality

Everyone we allow near Customer Personal Data - employees, contractors, anyone acting under our authority - is bound by a written duty of confidence that survives the end of their engagement, and is given access only to what their work actually requires.

Our people do not read customer data as a matter of routine. Access happens where it is needed to investigate a fault you have reported, to keep the Services running, or where the law requires it.

5. Security

We implement and maintain the technical and organisational measures set out in Annex II, which are designed to meet Article 32 of the UK GDPR having regard to the state of the art, the cost of implementation, and the risk to the people whose data it is.

We may change those measures as the Services develop, but not in a way that materially reduces their overall protection.

6. Sub-processors

You give us general authorisation to appoint sub-processors. Those engaged today are listed in Annex III, and your acceptance of this DPA is your authorisation of them.

Before a new sub-processor starts processing Customer Personal Data we will update Annex III and notify you at least 30 days beforehand, by email to the account owner.

You may object on reasonable data protection grounds within those 30 days. We will work with you to find an alternative; if we cannot, you may terminate the affected Services and we will refund any fees you have paid for a period after termination. That is the remedy - a right to object without a right to leave would be a right in name only.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

7. Helping you answer data subjects

Where a data subject contacts you exercising a right - access, rectification, erasure, restriction, portability, objection - the Services are built so you can answer without us: you can export everything held about a person and erase them, including deleting their call recordings from our telephony provider.

Where you cannot do it yourself, we will assist by appropriate technical and organisational measures, taking into account the nature of the processing.

If a data subject contacts us directly about your data, we will not respond substantively. We will tell them to approach you and tell you that they made contact, promptly, so your one-month clock is not spent on our desk. We will act ourselves only where the law requires it.

8. Breaches, assessments, and telling you things

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours of becoming aware of it. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved so far as known, the likely consequences, and what we are doing about it.

Where we cannot provide all of that at once we will provide it in phases as it becomes available, rather than waiting until the picture is complete. Your own 72-hour duty to the ICO starts when you become aware, so a tidy report that arrives late is worse than a partial one that arrives quickly.

We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, so far as it relates to our processing and taking into account the information available to us.

9. What happens at the end

On termination or expiry, you may export your data from the Services. Thirty days after your account closes, we delete Customer Personal Data from our production systems and instruct our sub-processors to do the same, including deleting call recordings from our telephony provider.

We keep data beyond that only where the law requires it, in which case it stays subject to this DPA and we process it for no purpose other than that legal requirement.

We do not keep a copy. Once the 30 days are up there is nothing to restore, which is the point of deleting your data. If you might want it, export it before the window closes.

10. Information and audits

We will make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice: ask us and we will answer in writing, provide our security documentation, and complete a reasonable security questionnaire. Where that genuinely does not satisfy a specific, identified concern, we will permit an on-site audit - no more than once in any twelve months unless a supervisory authority requires otherwise or there has been a breach, on 30 days’ notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Services or the data of our other customers. You bear your own costs and ours if the audit goes beyond what Article 28 requires.

11. International transfers

Customer Personal Data is held in the United Kingdom or the European Economic Area. Some sub-processors in Annex III operate from the United States, so limited categories of data are transferred there - the Annex says which for each.

Where a transfer is to a country without UK adequacy, it is made under the European Commission Standard Contractual Clauses as amended by the UK International Data Transfer Addendum, together with the supplementary measures in Annex II. Ask and we will provide the safeguards for any particular sub-processor.

You appoint us to enter into those clauses with sub-processors on your behalf where that is the appropriate mechanism.

12. Liability, and changes to this DPA

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing here limits either party’s liability to a data subject under Article 82 of the UK GDPR, or any liability that cannot lawfully be limited.

We may update this DPA where required by law, by a supervisory authority, or to reflect a change in how the Services work. For any change that materially affects your rights we will give at least 30 days’ notice by email to the account owner. Continuing to use the Services after that is acceptance; if you do not accept, you may terminate before it takes effect.

Previous versions are available on request.

13. Governing law

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction - the same as the Terms of Service, so a single dispute cannot end up in two places.

Questions about this agreement: tombrookes06@gmail.com.

Annex I - Details of the processing

I.1. Subject matter, nature, purpose and duration

Subject matterProviding the Dialem outbound calling, messaging and lead management service.
Nature of the processingStoring, organising, retrieving, displaying, transmitting, recording and erasing personal data; placing calls and sending SMS and email at your direction; generating suggested message text.
PurposeSo that you can contact and manage your own leads and customers.
DurationFor as long as your account is open, plus the retention periods in section 9 and the Privacy Policy.
FrequencyContinuous, for the duration of the agreement.

I.2. Categories of data subject

  • Your leads, prospects and customers - the members of the public you contact through the Services.
  • Anyone who calls, texts or emails one of your Dialem numbers or connected mailboxes, whether or not you already held a record for them.
  • People whose details appear inside a lead’s record because somebody typed them there or said them on a recorded call.

I.3. Categories of personal data

CategoryWhat that means here
Identity and contactName, phone number, email address, and any custom fields on the form or file the lead came from
Acquisition dataThe advert, ad set, campaign or lead form that produced them; the file they were imported in
Communications contentThe full text of SMS and email in both directions; conversations with the automated assistant
Call recordsTime, duration, direction, the agent involved, the outcome and any notes written
Call recordings and voicemailsAudio of calls, where you have switched recording on - see the note below
Commercial dataPipeline stage, deal value, callbacks booked, and the timeline of everything done to the record
Contact preferencesDo-not-contact records, which are retained after erasure so that contact cannot restart
Special category data. The Services are not designed for it and we do not ask for it. We cannot prevent one of your agents typing it into a notes field or a caller mentioning their health on a recorded call, so you must not use the Services to deliberately process special category or criminal offence data without telling us first - the measures in Annex II are not scoped for it.

Annex II - Technical and organisational measures

Every measure below is one the Services actually implement. This is a list of what we do, not what we intend to do.

II.1. Measures in force

AreaMeasure
Encryption in transitTLS on all connections between you, the Services, and every sub-processor.
Encryption at restProvided by our database and telephony providers across all stored data.
Credential protectionThird-party credentials you connect - Twilio secrets, mail passwords, advertising tokens - are separately encrypted with AES-256-GCM before storage, under a key held outside the database. A copy of the database alone does not yield them. Automated checks fail the build if code reads or writes one unencrypted.
AuthenticationPasswords stored only as one-way hashes; we cannot recover one. Mobile access tokens stored only as SHA-256 hashes.
Access controlEvery query is scoped to the account that owns the data, so one customer's data is unreachable from another's session. Within an account, per-member permissions restrict which flows a team member may open.
Recording protectionCall audio is streamed through an authenticated endpoint that verifies the request belongs to the owning account. The underlying provider URL is never exposed to a browser, so a recording cannot be shared by copying a link.
Webhook integrityRequests claiming to originate from our telephony provider are signature-verified before they are acted on.
Rate limiting and abuse controlApplied to authentication, messaging, AI features and number purchasing, to limit both abuse and accidental runaway cost.
Contact suppressionDo-not-contact is enforced server-side at the moment of sending, across every channel, keyed to the person rather than the record - so duplicates of the same person are also silenced.
Calling hoursCalls are refused outside the configured window, calculated from the recipient's own time zone where their number allows it.
DeletionErasure removes a person's records and deletes their audio from the telephony provider. Call recordings are deleted automatically 12 months after the call. Account data is deleted 30 days after closure.
Segregation of environmentsDevelopment and production use separate databases and separate credentials.
PersonnelAccess limited to those who need it, protected by multi-factor authentication, and subject to written confidentiality obligations.
Breach detection and responseApplication and provider logging, with the notification process in section 8.

II.2. Measures for transfers

For transfers to sub-processors outside the UK and EEA, in addition to the clauses in section 11: the categories of data transferred are minimised to what the sub-processor needs to perform its function (Annex III sets out what each one receives); no call recordings are transferred to any artificial intelligence provider; and credentials are never transferred to any sub-processor other than the one they authenticate to.

Annex III - Sub-processors

Authorised as at 13 August 2026. Changes are notified 30 days in advance under section 6.

III.1. Current sub-processors

Sub-processorFunctionData it receivesLocation
Twilio Inc.Telephony: calls, SMS, phone numbers, call recording storagePhone numbers, message content, call audio, call metadataUS / EU
Neon Inc.Database hostingAll Customer Personal Data stored in the ServicesEU - London (eu-west-2)
Vercel Inc.Application hosting and deliveryData in transit; request logsEU / global edge
OpenAI, L.L.C.Automated assistant and suggested repliesMessage text of the conversation, the lead's first name, and the business description you wrote. No call audio, no credentials, no other customer's data.US
Meta Platforms Inc.Lead advertisement forms, where you connect themLead records Meta already holds, which we retrieve on your behalfUS / EU
Expo (650 Industries, Inc.) and Apple Inc.Push notifications to the mobile appA device token and the text of the notificationUS
Your own mail server is not our sub-processor. When you connect a mailbox for sending and reading email, you have chosen that provider and your relationship is with them. We pass mail through it on your instruction; what they do with it is governed by their terms, not ours.

OpenAI does not use data submitted through its API to train its models. It retains submitted data for a limited period for abuse monitoring and then deletes it.

III.2. How you will hear about changes

By email to the account owner, at least 30 days before the new sub-processor begins processing, with this Annex updated at the same time. Your right to object and the consequences of objecting are in section 6.