TradieDialTradieDial← Home

Legal · Data processing

Data Processing Addendum

Effective and last updated: 30 August 2026

This Data Processing Addendum (DPA) forms part of the agreement between the Customer and the individual operator of the TradieDial trading name in Iceland for the TradieDial service. Defined terms not explained here have the meaning in the Business Terms.

Publication details still required

Before live outreach or customer onboarding, TradieDial must publish the proprietor’s full legal name, a public business correspondence address, the appointed UK representative’s name, the appointed UK representative’s UK address, the appointed UK representative’s email. The policy deliberately does not invent these facts.

1. Roles and scope

For Customer Data submitted to or generated by TradieDial on the Customer's behalf, the Customer is the controller and TradieDial is the processor. If the Customer itself acts as a processor, TradieDial acts as its sub-processor. Each party must comply with data-protection law applicable to its role, including EU GDPR, UK GDPR and the Icelandic Data Protection Act where applicable.

This DPA applies for as long as TradieDial processes Customer Personal Data, including during deletion from ordinary backups.

2. Processing details

  • Subject matter: AI call answering, recording/transcription where enabled, job capture, urgency flagging, alerts, messaging, secure updates/photos, appointment booking, dashboard reporting, customer support and service security.
  • Duration: the service term plus the deletion and backup period described below.
  • Nature: collection, transmission, recording, organisation, extraction, analysis, storage, retrieval, disclosure to authorised users, restriction, correction and deletion.
  • Purpose: providing, securing and supporting the features selected and instructed by the Customer.
  • People: callers, prospective or existing customers of the Customer, property occupants, Customer staff/contractors and other people included in a communication.
  • Data: names, contact details, address/postcode, voice/audio, transcript, problem description, access notes, appointment details, messages, uploaded job photos, outcome/value, technical identifiers and audit/security records.
  • Sensitive data: not intentionally requested. A caller may volunteer health or other sensitive information. The Customer must identify a lawful Article 9/10 condition where required and instruct TradieDial appropriately.

3. Documented instructions

TradieDial will process Customer Personal Data only on documented instructions in the agreement, configured settings, support requests or other written directions, including for international transfers, unless law requires otherwise. If legally permitted, we will tell the Customer before required processing. We will promptly inform the Customer if an instruction appears to infringe applicable data-protection law and may pause that instruction while it is clarified.

4. Confidentiality and personnel

People authorised to process Customer Personal Data are bound by confidentiality and receive access only where needed for their role. TradieDial maintains access-management and offboarding procedures and remains responsible for its personnel.

5. Security

Taking account of the state of the art, implementation cost, processing context and risk, TradieDial maintains appropriate technical and organisational measures, including:

  • TLS encryption in transit and provider encryption at rest;
  • encrypted mailbox and integration credentials, with secrets kept outside client bundles;
  • authenticated, role- and tenant-scoped access with least-privilege service credentials;
  • private object storage and short-lived signed access for caller photos;
  • signed, expiring continuation and unsubscribe tokens;
  • input validation, rate limits, suppression/frequency controls and fail-closed automation gates;
  • append-only audit/security events, provider-status reconciliation and emergency stops;
  • dependency patching, backups, restoration procedures and incident response; and
  • retention schedules and automated deletion for configured short-lived content.

Security is a shared responsibility. The Customer must protect credentials, limit its users, configure forwarding and integrations correctly, and notify TradieDial promptly of suspected compromise.

6. Sub-processors

The Customer gives general written authorisation for the providers in our Sub-processor Notice. TradieDial remains responsible for each sub-processor's processing under this DPA and imposes data-protection obligations appropriate to the service.

We will give at least 15 days' notice of a new sub-processor that materially affects Customer Personal Data, normally by updating the notice and emailing the Customer contact. The Customer may object on reasonable data-protection grounds during that period. The parties will try to resolve the objection; if no reasonable alternative exists, either party may terminate only the affected feature or service before the change takes effect.

7. International transfers

TradieDial is operated from Iceland in the EEA. Where Customer Personal Data is transferred to a country without applicable adequacy, TradieDial will use a lawful transfer mechanism appropriate to the transfer, such as EU Standard Contractual Clauses, the UK Addendum or IDTA, or a qualifying Data Privacy Framework recipient, and will complete supplementary risk assessment where required. On request we will provide relevant transfer information, subject to confidentiality.

8. Data-subject requests

If TradieDial receives a request relating to Customer Personal Data, it will notify the Customer and not respond substantively unless authorised or legally required. Taking account of the nature of processing, we will provide reasonable assistance through available product controls and support. The Customer remains responsible for deciding the response and verifying the requester.

9. Personal-data breaches

TradieDial will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, affected categories/approximate volume, contact point and mitigation taken or proposed. TradieDial will investigate, contain, remediate and reasonably assist the Customer. Notification is not an admission of fault.

10. Assessments, consultation and records

TradieDial will provide reasonable information needed for the Customer's data-protection impact assessment or regulator consultation relating specifically to the service. Each party keeps records required for its role. Assistance beyond standard documentation may be chargeable at an agreed rate unless caused by TradieDial's breach.

11. Audit information

On written request, TradieDial will first provide available security documentation, relevant test summaries, sub-processor information and responses reasonably needed to demonstrate compliance. If that is insufficient, the Customer may conduct one proportionate audit per year on at least 30 days' notice, during business hours, without accessing another customer's data or disrupting the service. Additional audits are allowed after a material breach or regulator request. The Customer pays its audit costs unless the audit identifies a material TradieDial breach.

12. Return and deletion

During the term, the Customer may request an export reasonably available through the service or support. After termination, TradieDial will delete or return Customer Personal Data at the Customer's choice unless law requires retention. Data in protected backups is deleted through the ordinary backup cycle and remains isolated from routine use. Minimal billing, security, dispute and suppression records may be retained where TradieDial has an independent lawful obligation or purpose.

13. Controller obligations

The Customer warrants that its instructions and collection/use of Customer Personal Data are lawful; that it has provided required notices; that it will not ask TradieDial to collect unnecessary sensitive data; and that its authorised users and integrations have a legitimate need for access. The Customer remains responsible for the accuracy of its instructions, the lawfulness of recording and messaging, and responding to callers.

14. Liability, conflict and governing law

The liability limits in the Business Terms apply to this DPA. If this DPA conflicts with the Business Terms on personal-data processing, this DPA controls. The governing-law and dispute provisions in the Business Terms apply.

15. Contact

Data-protection notices under this DPA should be sent to support@tradiedial.com. Provider identity and address are stated in the Privacy Policy.

PrivacyTermsOutreachDPASub-processorsCookiesHome