Data Processing Agreement
Last updated: 24 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between ReplyRig and each business customer, and is incorporated into our Terms of Service by reference. It applies where ReplyRig processes personal data on a customer's behalf as part of the missed-call service.
In this DPA: the Controller is the ReplyRig customer - the trade business using the service - who determines why and how caller information is used. The Processor is 7 Red Stags, trading as ReplyRig, of 3 Mayburn Vale, Loanhead, EH20 9HQ, Scotland, which processes that information on the Controller's documented instructions.
1. Subject matter and duration
This DPA covers ReplyRig's processing of caller/customer personal data on the Controller's behalf for the duration of the Controller's ReplyRig subscription, and for any period afterwards reasonably necessary to wind down the service in line with this DPA.
2. Nature and purpose of processing
ReplyRig processes personal data to operate the missed-call text-back service: receiving forwarded unanswered calls, sending an automated SMS to the caller, conducting an automated/AI-assisted SMS conversation to gather basic enquiry details, and passing the resulting lead information to the Controller.
3. Categories of data subjects
- Callers to the Controller's business number;
- potential customers of the Controller; and
- existing customers of the Controller.
4. Categories of personal data
- Name (where supplied);
- telephone number;
- call details (date, time, status);
- SMS conversation content;
- postcode or location;
- description of the requested work; and
- timing or urgency details voluntarily supplied by the caller.
ReplyRig does not ask for or expect to receive special-category data (such as health, racial or ethnic origin, or similar sensitive information) as part of the missed-call service, and Controllers should not seek to collect this data through the service.
5. Processing only on documented instructions
ReplyRig will process personal data only on the Controller's documented instructions, including as set out in the Controller's use of the service's normal features, unless required to do otherwise by law - in which case ReplyRig will inform the Controller of that legal requirement first, unless the law prohibits this.
6. Confidentiality
ReplyRig ensures that anyone authorised to process personal data under this DPA is subject to an appropriate duty of confidentiality.
7. Security measures
ReplyRig implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, and against accidental loss, destruction or damage, taking into account the nature of the data and the risks involved.
8. Sub-processors
The Controller authorises ReplyRig to engage sub-processors reasonably necessary to operate the service (for example, providers of CRM/workflow technology, telephony and SMS delivery, cloud hosting, AI processing, and payment processing). ReplyRig will ensure that any sub-processor is bound by data-protection obligations no less protective than those in this DPA, and remains responsible for each sub-processor's performance of those obligations.
9. International transfers
Where a sub-processor processes personal data outside the UK, ReplyRig will ensure that appropriate safeguards and transfer mechanisms recognised under UK data-protection law are in place.
10. Assistance with data-subject rights
ReplyRig will provide reasonable assistance to the Controller in responding to requests from data subjects seeking to exercise their rights under UK data-protection law, to the extent this relates to personal data processed under this DPA.
11. Assistance with security and breach obligations
ReplyRig will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonable assistance to help the Controller meet its own notification obligations under UK data-protection law.
12. Deletion or return of data
Where reasonably practicable and subject to ReplyRig's own legal, accounting and record-keeping obligations, ReplyRig will delete or return personal data processed under this DPA at the end of the provision of services relating to that processing, upon the Controller's request.
13. Audit and information
ReplyRig will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits or inspections conducted by the Controller or an auditor mandated by the Controller, on reasonable notice and subject to reasonable confidentiality and cost arrangements.
14. Controller responsibilities
The Controller is responsible for ensuring it has a lawful basis to collect and share personal data with ReplyRig for processing under this DPA, for the accuracy of any instructions it gives, and for its own compliance with UK data-protection law in its capacity as controller.
This DPA should be read alongside our Privacy Policy and Terms of Service. Questions? Contact hello@replyrig.co.uk.