Skip to content

Data processing agreement

Last updated 10 October 2026

This data processing agreement ("DPA") forms part of the terms of service between [company name], a company registered in England and Wales with company number [number], whose registered office is at [address], trading as Tilly ("we", "us") and the business that uses Tilly ("you"). You accept it when you accept the terms. It sets out how we handle personal data on your behalf, as Article 28 of the UK GDPR requires.

1. Meaning of words

1.1 "Data protection law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any other UK law about personal data that applies, as amended from time to time.

1.2 "Customer personal data" means personal data that we process on your behalf when providing Tilly. It is mainly the personal data of people who call your number, and of anyone they or you mention, as set out in Annex 1.

1.3 "Controller", "processor", "personal data", "personal data breach", "processing" and "data subject" have the meanings given in the UK GDPR. "Sub-processor" means another processor we engage to process customer personal data.

2. Roles

2.1 For customer personal data, you are the controller and we are your processor.

2.2 You are responsible for having a lawful basis for the processing, for telling callers and others how their data is used (for example with the recording notice in your greeting and a privacy notice on your website), and for the instructions you give us. Where callers may share special category data, such as health information, you are responsible for having a condition for processing it.

2.3 We are a controller, not a processor, for the personal data we need to run your account, bill you and keep the service secure. Our privacy policy covers that.

3. Your instructions

3.1 We process customer personal data only on your documented instructions. Your instructions are: the terms of service, this DPA, the way you set up and use the service (for example your greeting, call handling rules, alerts and connections to other systems), and any other reasonable written instructions you send us that are consistent with them. This includes transfers outside the UK as described in section 7.

3.2 If UK law requires us to process customer personal data in another way, we will tell you before we do, unless the law forbids us from telling you.

3.3 We will tell you straight away if we think an instruction breaks data protection law.

4. Our people

Everyone we authorise to process customer personal data is bound by a duty of confidentiality, whether by contract or by law, and has access only as far as their work needs.

5. Security

5.1 We take appropriate technical and organisational measures to protect customer personal data, as Article 32 of the UK GDPR requires. Annex 2 describes them.

5.2 We may update these measures as long as the overall level of protection does not go down.

6. Sub-processors

6.1 You give us general written authorisation to use the sub-processors listed in Annex 3.

6.2 We will tell you by email at least 30 days before we add or replace a sub-processor. You may object on reasonable data protection grounds within that time. If we cannot address your objection, you may end the agreement before the change takes effect and we will refund any fees you have paid in advance for the period after it ends.

6.3 We put a written contract in place with each sub-processor that gives customer personal data at least the protection this DPA requires. We remain responsible to you for our sub-processors' performance of those obligations.

7. Transfers outside the UK

7.1 Our database is hosted in the United Kingdom. Some sub-processors process customer personal data in the United States or the European Economic Area, as Annex 3 shows.

7.2 We only make those transfers with a safeguard that UK data protection law recognises: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, known as the UK-US data bridge, for recipients certified to it), or the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses issued under section 119A of the Data Protection Act 2018. You can ask us for a copy of the relevant safeguard.

8. Helping you with people's rights

8.1 If someone asks us to exercise their data protection rights about customer personal data, we will pass the request to you without undue delay and will not answer it ourselves unless you ask us to.

8.2 Your dashboard lets you find, read and correct the information held about a caller. Where you need more, for example a copy of a caller's data or deleting it from our systems, we will help you within a reasonable time, taking into account the nature of the processing.

9. Helping you with your other obligations

Taking into account the nature of the processing and the information available to us, we will give you reasonable help with your obligations on security, personal data breaches, data protection impact assessments and consulting the Information Commission (the UK regulator, known as the ICO).

10. Personal data breaches

10.1 We will tell you without undue delay, and in any case within 48 hours, after we become aware of a personal data breach affecting customer personal data.

10.2 We will give you the information you need to meet your own obligations, as far as it is available to us: what happened, the categories and rough numbers of people and records affected, the likely consequences and what we have done or plan to do. We will add to it as we learn more, take reasonable steps to contain the breach and work with you on next steps.

11. When the service ends

11.1 When your subscription ends, we stop processing customer personal data except to store it until it is deleted. If you want a copy first, ask us before your subscription ends and we will provide one in a common format.

11.2 We delete customer personal data from our systems 90 days after your subscription ends, unless UK law requires us to keep it. Copies in our backups are deleted within a further 14 days, as the backups roll over.

11.3 Call audio, and our voice provider's copy of each transcript, are deleted by that provider 90 days after each call in any case, while your subscription is running.

12. Showing that we comply

12.1 We will make available to you the information reasonably needed to show that we meet our obligations under Article 28 of the UK GDPR.

12.2 We will allow for and contribute to audits, including inspections, by you or an auditor you appoint who is bound by confidentiality. You must give us at least 30 days' notice, keep audits to normal working hours and to once a year (unless a regulator requires more, or after a personal data breach), and pay your own costs. We may first answer with written information, and only arrange an inspection if that is not enough to show compliance.

13. Liability and length

13.1 Each of us is liable for our own breaches of data protection law. The limits of liability in the terms of service apply to this DPA, except where the law does not allow them to.

13.2 This DPA lasts for as long as we process customer personal data.

Annex 1: Details of the processing

Subject matterAnswering and handling phone calls to your business, and the messages, bookings, alerts and records that come from them.
DurationFor as long as your subscription lasts, then until the data is deleted under section 11.
Nature of the processingReceiving and carrying calls; recording them; turning speech into text; generating the receptionist's replies and call summaries with AI; storing calls, transcripts, messages, bookings and contacts; recognising returning callers; sending alerts by email, text message and WhatsApp; sending data to systems you connect; deleting data.
PurposeTo provide Tilly to you under the terms of service.
People whose data is processedPeople who call your number; people they mention; your customers and contacts held in your account; your staff named in transfer rules or alerts; anyone whose voice you copy with their permission.
Types of personal dataPhone numbers; names; email and postal addresses and other contact details given on calls; call recordings (voice); transcripts and the content of what callers say, which can include any information they choose to share; call details such as time, length and outcome; appointment details; notes.
Special category dataNot intended. It may be processed if callers volunteer it, or if your business means callers are likely to share it (for example a clinic and health information). You are responsible for having a lawful condition and telling callers.
How oftenContinuously, whenever your number receives calls.

Annex 2: Security measures

  • Encryption in transit: all connections to Tilly, and between Tilly and our sub-processors, use TLS (HTTPS). Webhooks we receive are checked with signatures.
  • Access to accounts: customers sign in with single-use email links that expire quickly; two-step sign-in is available to every customer. Sessions use secure, HTTP-only cookies.
  • Access by our staff: only staff who need it can reach the back office, and they must use two-step sign-in. Administrative actions are recorded in an audit log, kept for two years.
  • Separation between customers: every request is checked against the account it belongs to, so one customer cannot see another's data.
  • Secrets: sign-in secrets and keys are encrypted or kept out of the database, and never sent to the browser.
  • Abuse protection: public endpoints are rate limited, and suspicious use can be blocked.
  • Retention: data is deleted automatically on a fixed schedule, as set out in our privacy policy and in section 11.
  • Backups: the database is backed up daily on our UK server and backups are kept for 14 days, with access limited to administrators.
  • Monitoring: the service is monitored around the clock for availability and security problems.
  • Suppliers: we use established sub-processors with their own data processing terms and security programmes, listed in Annex 3.

Annex 3: Sub-processors

Sub-processorWhat it doesWhereSafeguard
Eleven Labs Inc. (ElevenLabs)Answers calls: speech recognition, the AI conversation, the voices, and call recordings and transcripts (deleted after 90 days)United StatesUK-US data bridge; UK Addendum to the EU standard contractual clauses
Google (Gemini), through ElevenLabsThe AI language model that writes the receptionist's replies. If you choose a different model in Advanced settings, that model's provider insteadUnited States and other locationsUnder ElevenLabs' contract and safeguards
Twilio Ireland Limited (Twilio)Phone numbers, carrying calls, and sending text message and WhatsApp alertsUnited States and IrelandUK-US data bridge; Twilio's binding corporate rules; International Data Transfer Agreement
WhatsApp (Meta), through TwilioDelivers WhatsApp alerts, only if you turn them onWorldwideUnder Meta's WhatsApp Business terms
Plus Five Five, Inc. (Resend)Sends emails: alerts, summaries and sign-in linksUnited StatesUK-US data bridge; UK Addendum to the EU standard contractual clauses
Anthropic Ireland, Limited (Anthropic)Reads your website and documents when you ask it to fill in your receptionist's answers (Pro and Business). Deletes what it receives within 30 daysUnited StatesUK Addendum to the EU standard contractual clauses
Fasthosts Internet LimitedHosts our servers, database and backupsUnited Kingdom (its suppliers IONOS in Germany and Arsys in Spain help run the platform)Hosted in the UK; UK adequacy regulations cover the EU suppliers