Ringby
LEGAL

Data Processing Agreement

Last updated: 27 July 2026

1. Parties

This DPA forms part of the Terms of Service between Ringby UK ("Processor") and the Customer ("Controller"). Both parties agree to comply with their respective obligations under UK GDPR, the Data Protection Act 2018, and other applicable data protection laws.

2. Scope & Duration

This DPA applies to the processing of personal data by Ringby on behalf of the Customer when providing the Service. It remains in effect for the duration of the Customer's subscription and for a reasonable period afterward to allow for data retrieval or deletion.

3. Categories of Data Processed

  • End User Personal Data. Names, phone numbers, email addresses, and any other personal information disclosed during AI phone calls.
  • Call Recordings and Transcripts. Audio recordings and AI-generated transcripts of phone calls handled by the AI agent.
  • Appointment Data. Scheduled appointments, service requests, and related communications.

4. Data Subjects

The personal data processed concerns the Customer's end users, customers, and prospective customers. Typically individuals contacting the Customer for home service enquiries, appointments, or support.

5. Processor Obligations

Ringby will:

  • Process personal data only on documented instructions from the Customer, unless required to do otherwise by applicable law.
  • Ensure that persons authorised to process the data are subject to a duty of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 8).
  • Not engage any sub-processor without prior notice and the option for the Customer to object.
  • Assist the Customer in fulfilling their obligations regarding data subject rights, data breach notifications, and data protection impact assessments.
  • Delete or return all personal data at the end of the Service, at the Customer's choice.
  • Make available all information necessary to demonstrate compliance with this DPA.

6. Controller Obligations

The Customer will:

  • Ensure that the processing of personal data, and the instructions given to Ringby, comply with applicable data protection laws.
  • Obtain all necessary consents from End Users for the recording of calls and processing of their personal data through the Service.
  • Provide clear privacy notices to End Users explaining how their data is collected and processed through Ringby.
  • Maintain a record of processing activities under its own responsibility.

7. Sub-processors

The Customer authorises Ringby to engage the following sub-processors:

UK-Based

These providers process data within the UK. No international transfer safeguards are required.

  • Neon. Postgres database hosting (London, UK). Account data, call logs, and service data are stored in Neon's London region.
  • Resend. Transactional email delivery (UK data residency). Email notifications and service communications are processed in the UK.

EU-Based

Transfers to the EU benefit from the UK's adequacy decision under UK GDPR.

  • Cal.com. Scheduling and appointment booking platform (EU).

US-Based

Transfers to these providers are safeguarded by the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses.

  • Clerk. Authentication and user identity management (USA).
  • Stripe Inc.. Payment processing and subscription management (USA).
  • Twilio Inc.. Telephony and call routing services for the AI phone agent (USA). Call data is routed through Twilio's US infrastructure.
  • ElevenLabs. Voice AI platform for the AI phone agent (USA). Processes call audio, speech-to-text, text-to-speech, and conversation data in real time.
  • Vercel Inc.. Hosting and infrastructure (USA/EU).
  • Cloudflare Inc.. CDN, DDoS protection, and Turnstile bot verification (global edge network).
  • Google Workspace. Email hosting and internal collaboration tools (USA/EU).

No Personal Data Processed

These services are listed for transparency but do not process personal data on our behalf.

  • Plausible Analytics. Privacy-friendly website analytics (EU). No cookies, no personal data collected. All data is anonymised and processed in the EU.

Ringby will notify the Customer at least 14 days before adding or replacing any sub-processor, giving the Customer an opportunity to object.

8. Technical & Organisational Security Measures

  • Encryption at rest. All data stored in our database is encrypted using AES-256.
  • Encryption in transit. All API traffic is TLS 1.3 encrypted.
  • Access controls. Strict role-based access to production systems. Multi-factor authentication required for all infrastructure access.
  • Incident response. 24/7 security monitoring with documented incident response procedures.
  • Regular audits. Annual security assessments and penetration testing.
  • Data minimisation. We collect and retain only the data necessary to provide the Service.
  • Staff training. All employees receive data protection and security awareness training.

9. Data Breach Notification

Ringby will notify the Customer without undue delay upon becoming aware of a personal data breach affecting the Customer's data. We will provide reasonable information to assist the Customer in meeting their own breach notification obligations under Article 33 of UK GDPR.

10. Data Subject Rights

Ringby will assist the Customer in responding to data subject requests (access, rectification, erasure, portability, restriction, objection). Where an End User contacts Ringby directly with a request, we will forward it to the Customer promptly.

11. International Transfers

Where personal data is transferred outside the UK or EEA to sub-processors, we have implemented the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as approved by the Information Commissioner's Office. Where necessary, we also carry out Transfer Impact Assessments and implement supplementary measures to ensure an equivalent level of protection.

A copy of the relevant safeguards is available on request.

12. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

Data Protection enquiries: dpo@ringby.co.uk