Legal

Data Processing Agreement

Standard contractual terms for customers who upload personal data to CallForge as a processor.

Last updated: 1 March 2026

1. Scope and roles

This Data Processing Agreement ("DPA") applies when you ("Controller") use CallForge to process personal data relating to your leads, prospects, customers, or employees ("Personal Data"). CallForge acts as Processor on your documented instructions.

This DPA supplements our Terms of Service and Privacy Policy. If there is a conflict regarding data protection, this DPA prevails.

2. Subject matter and duration

Processing is limited to providing AI outbound calling, storage of lead and call data, integrations, analytics, and support for the subscription term and any post-termination export window.

3. Processor obligations

CallForge will process Personal Data only on documented instructions, ensure confidentiality of personnel, implement appropriate security measures, and assist with data subject requests and DPIAs where reasonably required.

  • Maintain records of processing activities as required by law.
  • Notify you without undue delay after becoming aware of a Personal Data breach.
  • Delete or return Personal Data at end of service unless retention is required by law.
  • Make available information necessary to demonstrate compliance and allow audits on reasonable notice.

4. Subprocessors

You authorise CallForge to engage subprocessors for hosting, telephony, AI inference, email, and payment processing (including Stripe). We impose data protection terms consistent with this DPA. We will notify you of material subprocessor changes and provide an opportunity to object on reasonable grounds.

5. International transfers

Where Personal Data is transferred outside the UK, we implement UK GDPR-approved transfer mechanisms including the UK Addendum to EU Standard Contractual Clauses or the UK International Data Transfer Agreement as applicable.

6. Controller obligations

You warrant that you have a lawful basis to upload Personal Data, that instructions comply with applicable law, and that you will not instruct processing of special category data unless explicitly agreed and technically supported with additional safeguards.

7. Security measures

We maintain administrative, technical, and physical safeguards including encryption in transit, role-based access, logging, vulnerability management, and staff training. Details are available on our Security page and in our security pack on request.

8. Executing this DPA

For most customers, accepting the Terms of Service constitutes acceptance of this DPA. Enterprise customers may request a signed copy by contacting legal@callforge.ai with your company name, registered address, and signatory details.

9. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service unless otherwise required by UK data protection law.

Related legal documents

Questions? Contact us or email contact@callforge.uk.

Get started

Need a custom agreement?

Enterprise customers can request bespoke terms and a signed DPA.