Data processing agreement
A plain summary of how we handle personal data when we process it on a customer's behalf. A full signed agreement is available on request.
Introduction
This page applies where Levrg processes personal data on a business customer's behalf through our AI products — for example the callers, visitors or customers of that business. In that arrangement the customer is the controller and Levrg is the processor. It summarises our processor commitments; a signed data processing agreement is available to customers on request and governs the relationship in full. For our own website and enquiries, see our privacy policy instead.
Scope and roles
The customer determines the purposes and means of processing (controller); Levrg processes the data only to deliver the agreed services (processor). Each party is responsible for its own compliance with UK data protection law.
Nature of the processing
We process personal data to operate the customer's AI voice and chat services — answering calls and messages, taking bookings, orders and enquiries, and producing recordings, transcripts and analytics.
- Categories of personal data — names, phone numbers, email addresses, and the contents of calls and messages (including any details a caller or visitor chooses to share).
- Data subjects — the customer's own callers, website visitors, enquirers and customers.
Processing on documented instructions
We process personal data only on the controller's documented instructions, including the configuration of the service, unless we're required to do otherwise by law — in which case we'll tell the controller first, where the law allows.
Confidentiality
Anyone we authorise to process the data is bound by an appropriate duty of confidentiality and only has access on a need-to-know basis.
Security measures
We apply appropriate technical and organisational measures, including encryption at rest for personal data, role-based access controls, and EU-region hosting for our database and call-recording storage. Security is reviewed and improved over time.
Sub-processors
We use a small set of vetted sub-processors, each for a specific purpose, and we give the controller notice of any intended changes so it can object:
- OpenAI — language model that generates responses.
- Cartesia — text-to-speech.
- Deepgram — speech-to-text.
- Twilio — telephony.
- Supabase — database hosting (Frankfurt, EU).
- Amazon Web Services — call-recording storage (eu-central-1, EU).
- Microsoft Clarity — website analytics.
- IONOS — email.
- Cloudflare — content delivery and security.
- Hetzner — application hosting (Germany, EU).
- n8n — workflow automation.
Assisting with data-subject requests
We help the controller respond to requests from individuals exercising their rights — access, rectification, erasure, restriction, objection and portability — taking into account the nature of the processing and the information available to us.
Personal-data breaches
If we become aware of a personal-data breach affecting the controller's data, we will notify the controller without undue delay and provide the information it needs to meet its own obligations.
Retention and deletion
We keep the call recording and chat record for 12 months; after that the recording is deleted and the transcript is anonymised (phone numbers and names removed). On termination we delete or return the personal data at the controller's choice, and we honour in-conversation erasure where an individual asks for their details to be removed.
International transfers
Where a sub-processor processes data outside the UK/EEA, the transfer is protected by appropriate safeguards — Standard Contractual Clauses or the UK International Data Transfer Addendum.
Audit and compliance
We make available the information reasonably needed to demonstrate compliance with these commitments and will cooperate with reasonable audits, on reasonable notice and subject to confidentiality, as set out in the signed agreement.
Governing law
This arrangement is governed by the laws of England and Wales.
Contact
To request the signed DPA or ask a data-processing question, email [email protected].
Levrg Automations Ltd · Company No. 16982533 · South Wales · Last updated July 2026.
