frontdesq← Back to site

Legal

Data Processing Addendum

FRONTDESQ LTD
Last updated: July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between FRONTDESQ LTD ("FrontDesq", "Processor") and the Customer ("Controller") and applies wherever FrontDesq processes personal data on the Customer's behalf in the course of providing the FrontDesq AI receptionist service.

This DPA reflects the requirements of Article 28 of UK GDPR, applicable Australian privacy obligations, and related data protection legislation. Capitalised terms not defined here have the meanings given to them in the Terms of Service.

1. Definitions

"Applicable Data Protection Law" means all data protection and privacy legislation applicable to the processing of Personal Data under this DPA, including UK GDPR, the UK Data Protection Act 2018, the Australian Privacy Act 1988 (Cth) where applicable, and any other applicable national or state-level privacy legislation.

"Caller Data" means personal data relating to Callers that FrontDesq processes on the Customer's behalf as part of providing the Service, including names, phone numbers, call recordings, transcripts, lead summaries, and scheduling information.

"Controller" means the Customer, who determines the purposes and means of processing Caller Data.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates. In the context of this DPA, this is primarily Callers.

"Personal Data" has the meaning given to it under Applicable Data Protection Law.

"Processing" has the meaning given to it under Applicable Data Protection Law and includes any operation performed on Personal Data, whether automated or manual.

"Processor" means FrontDesq, acting on the Controller's instructions.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries as applicable under UK law, including the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs.

"Sub-processor" means any third party engaged by FrontDesq to process Personal Data on the Controller's behalf.

2. Scope and relationship

2.1 This DPA applies to FrontDesq's processing of Caller Data on behalf of the Customer in the course of providing the Service, including AI call handling, call recording, transcription, lead capture, and related features.

2.2 The Customer is the Controller of Caller Data. FrontDesq is the Processor. FrontDesq processes Caller Data only on the Customer's documented instructions, as set out in this DPA, the Terms of Service, and the Customer's service configuration.

2.3 FrontDesq's processing of Customer account data (name, billing records, contact details, support interactions) is conducted by FrontDesq as a Controller in its own right. That processing is described in the Privacy Policy and is not governed by this DPA.

2.4 Where FrontDesq engages Sub-processors to carry out processing activities on the Customer's behalf, FrontDesq remains liable to the Customer for those Sub-processors' compliance with this DPA.

3. Details of processing (Schedule 1)

ItemDetails
Subject matterProvision of AI receptionist services, including inbound call handling, recording, transcription, lead capture, and scheduling assistance
DurationFor the term of the Customer's active Subscription, plus any retention period required by Applicable Data Protection Law or as configured by the Customer
Nature of processingCollection, recording, transcription, storage, structuring, retrieval, use, disclosure to Sub-processors, and deletion of Caller Data
PurposeEnabling the Customer to receive, manage, and act on inbound calls through FrontDesq's AI receptionist
Types of personal dataNames, phone numbers, postal addresses (where volunteered), enquiry details, appointment preferences, job descriptions, call recordings, call transcripts, AI-generated summaries, and call metadata (timestamp, duration, outcome)
Categories of data subjectsCallers who contact the Customer's business through the AI Receptionist, typically customers, leads, or enquirers of the Customer's business
Special category / sensitive dataThe Service is not designed to collect special category data or other sensitive or high-risk personal information, including health information, biometric data, financial account details, payment card details, passwords, government identification numbers, or information about domestic safety or emergencies. The Customer must not configure the Service to solicit or record such information unless they have a clearly identified lawful basis, appropriate safeguards, and have notified FrontDesq in writing

4. Controller's obligations

4.1 The Customer, as Controller, is responsible for:

  • ensuring a valid lawful basis exists for each processing activity involving Caller Data, including recording, transcription, and any follow-up messaging;
  • providing Callers with appropriate privacy and recording notices before or at the start of each call;
  • ensuring that any instructions given to FrontDesq are lawful and comply with Applicable Data Protection Law;
  • configuring the Service (including call-opening disclosures, recording settings, and retention periods) in a way that is lawful in the jurisdictions where the Customer's Callers are located;
  • managing and responding to Data Subject requests received directly from Callers; and
  • ensuring that use of the Service for follow-up messaging (SMS, email, or other channels) complies with applicable spam, telemarketing, and consent laws.

4.2 The Customer must not instruct FrontDesq to process Personal Data in a way that would violate Applicable Data Protection Law. FrontDesq will inform the Customer promptly if it believes an instruction infringes Applicable Data Protection Law.

5. FrontDesq's obligations as Processor

FrontDesq agrees to:

5.1 Process only on instructions. Process Caller Data solely on the Customer's documented instructions, except where required to do so by applicable law. Where FrontDesq is legally required to process Caller Data beyond the Customer's instructions, it will inform the Customer before doing so, unless prohibited by law.

5.2 Confidentiality. Ensure that all personnel authorised to process Caller Data are subject to binding confidentiality obligations.

5.3 Security. Implement and maintain appropriate technical and organisational measures to protect Caller Data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access, taking into account the nature of the data and the risks involved. See Schedule 3 for a description of FrontDesq's security measures.

5.4 Sub-processors. Engage Sub-processors only in accordance with clause 6 of this DPA, and remain liable to the Customer for Sub-processors' compliance with the obligations of this DPA.

5.5 Data Subject rights. Assist the Customer, by appropriate technical and organisational measures, in responding to Data Subject requests to exercise their rights under Applicable Data Protection Law, to the extent that FrontDesq holds or controls the relevant data.

5.6 Security assistance. Assist the Customer in ensuring compliance with security obligations, breach notification requirements, data protection impact assessments (DPIAs), and prior consultation obligations under Applicable Data Protection Law, taking into account the nature of the processing and the information available to FrontDesq.

5.7 Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a confirmed or reasonably suspected Security Incident affecting Caller Data. The notification will include: the nature of the Security Incident; the categories and approximate number of Data Subjects affected; the categories and approximate volume of Personal Data affected; the likely consequences; and the measures taken or proposed to address the incident. FrontDesq will cooperate with the Customer to investigate and remediate any Security Incident.

5.8 Deletion or return. Upon termination of the Subscription, or on the Customer's written request, delete or return all Caller Data processed under this DPA, and delete existing copies, unless retention is required by applicable law. FrontDesq will confirm in writing that deletion has been completed upon request.

5.9 Audit. Make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. FrontDesq will accommodate reasonable audit or inspection requests from the Customer, subject to reasonable advance notice (at least 30 days), agreement on scope and timing, and the Customer bearing any reasonable costs of the audit. FrontDesq may satisfy this obligation by providing relevant third-party certifications, audit reports, or equivalent documentation where available.

5.10 No use for own purposes. Not use Caller Data for FrontDesq's own commercial purposes, including marketing or product development, without the Customer's prior written consent and a separately identified lawful basis.

6. Sub-processors

6.1 Authorised Sub-processors. The Customer authorises FrontDesq to engage the Sub-processors listed in Schedule 2 to process Caller Data. FrontDesq will enter into written agreements with each Sub-processor that impose data protection obligations no less protective than those in this DPA.

6.2 New Sub-processors. FrontDesq will maintain an up-to-date Sub-processor list. Where FrontDesq intends to add or replace a Sub-processor that will process Caller Data, FrontDesq will provide notice of the change by email, in-account notice, or update to the Sub-processor list. The Customer may object on reasonable data protection grounds within 14 days of that notice, in accordance with clause 6.3.

6.3 Objections. If you have a reasonable objection to a new Sub-processor on data protection grounds, please contact hello@frontdesq.co within 14 days of a notified change. FrontDesq will work with you in good faith to address the concern. If FrontDesq is unable to accommodate the objection, the Customer may terminate the Subscription on written notice, with a pro-rated refund of any prepaid Fees for the unused period.

7. International data transfers

7.1 The Customer acknowledges that FrontDesq uses Sub-processors located outside the UK and Australia, including providers in the United States. A description of Sub-processor locations is set out in Schedule 2.

7.2 UK transfers. Where Personal Data is transferred from the UK to a country not covered by a UK adequacy decision, FrontDesq relies on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses as the transfer mechanism, combined with a data protection test where required.

7.3 Australian transfers. Where personal information is disclosed overseas on the Customer's behalf, FrontDesq takes reasonable steps to ensure that overseas Sub-processors handle it in a manner consistent with the Australian Privacy Principles, including through contractual arrangements where appropriate.

7.4 Where the Customer requires copies of transfer agreements or Standard Contractual Clauses, they may request these by contacting privacy@frontdesq.co.

8. Data Subject rights

8.1 The Customer is primarily responsible for managing and responding to Data Subject rights requests from Callers. This includes requests to access, correct, restrict, delete, or port their Personal Data.

8.2 Where a Data Subject contacts FrontDesq directly in respect of Caller Data held on the Customer's behalf, FrontDesq will redirect that request to the Customer and provide reasonable assistance to help the Customer respond.

8.3 FrontDesq will respond to the Customer's requests for assistance with Data Subject rights within a reasonable timeframe and in any event in time to allow the Customer to meet its statutory response deadlines.

9. Australian privacy obligations

9.1 Where the Customer uses FrontDesq to process personal information relating to individuals in Australia, both parties acknowledge their respective obligations under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles where applicable.

9.2 The Customer, as the party with a direct relationship with Australian Callers, is responsible for:

  • providing collection notices to Callers as required by APP 5, where the Australian Privacy Act applies to the Customer;
  • ensuring that cross-border disclosure of Caller Data (to FrontDesq and its Sub-processors) is disclosed in the Customer's own privacy policy or collection notices; and
  • where APP 8 applies to the Customer, taking reasonable steps to ensure that overseas recipients of Caller Data do not breach the Australian Privacy Principles.

9.3 FrontDesq will assist the Customer in meeting these obligations by maintaining accurate Sub-processor information and responding to reasonable requests for information about processing locations and safeguards.

10. Duration and termination

10.1 This DPA takes effect on the date the Customer first uses the Service and continues for the duration of the Subscription.

10.2 Termination of the Terms of Service automatically terminates this DPA, subject to any obligations that by their nature survive termination, including the obligation to delete Caller Data and the confidentiality obligations.

10.3 Obligations relating to processing that took place during the term of this DPA survive its termination to the extent required by Applicable Data Protection Law.

11. Governing law

This DPA is governed by the laws of England and Wales. Any disputes arising under or in connection with this DPA are subject to the jurisdiction provisions in the Terms of Service.

12. Contact

For data protection matters relating to this DPA, contact:

FRONTDESQ LTD Company No. 17302785 Registered office: 128 City Road, London, United Kingdom, EC1V 2NX Email: privacy@frontdesq.co

Schedule 1: Processing details

See clause 3 above.

Schedule 2: Approved Sub-processors

The following Sub-processors are authorised to process Caller Data on behalf of the Customer as part of delivering the Service. FrontDesq will maintain this list and notify Customers of material additions or replacements in accordance with clause 6.2.

Sub-processorFunctionMain processing location
TelnyxTelephony and voice media (inbound call delivery, speech processing)United States
Anthropic (Claude)AI language model that powers the call conversationUnited States
SupabaseDatabase and data storageAustralia or other configured project region
Fly.io / RailwayApplication hosting and infrastructureUnited States / EU

Vercel (website hosting) and Resend (transactional email to business customers) do not process Caller Data and are therefore not listed here. They appear in the Privacy Policy subprocessor list. Payment processing (Stripe) relates to Customer billing data only and does not involve Caller Data.

Schedule 3: Technical and organisational security measures

FrontDesq implements and maintains the following measures to protect Caller Data against unauthorised access, loss, destruction, alteration, or disclosure:

Access controls

  • Access to systems holding Caller Data is restricted to authorised personnel on a least-privilege basis.
  • Administrative access requires strong authentication.
  • Access rights are reviewed periodically and revoked promptly on role change or departure.

Encryption

  • Data in transit between FrontDesq systems and Sub-processors is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted where supported by the underlying infrastructure provider.

Logging and monitoring

  • System access and data operations are logged.
  • Logs are retained for security review and incident investigation purposes.

Subprocessor security

  • FrontDesq selects Sub-processors with appropriate security certifications or demonstrated security practices.
  • Contractual security obligations are imposed on Sub-processors.

Incident response

  • FrontDesq maintains an incident response procedure for Security Incidents.
  • Confirmed Security Incidents affecting Caller Data are escalated and notified to affected Customers in accordance with clause 5.7.

Data minimisation

  • FrontDesq processes only the Caller Data necessary to provide the Service.
  • Retention periods are applied to call recordings and transcripts as described in the Privacy Policy and as configured by the Customer.

Vulnerability management

  • FrontDesq applies security updates to its infrastructure on a timely basis.
  • Application code is reviewed for security issues as part of the development process.

This DPA was last updated in July 2026. If you have questions about this DPA or wish to request a separately signed version, contact privacy@frontdesq.co.

frontdesq

Your phone, taken care of

frontdesq is an AI receptionist and phone answering service for small businesses across Australia.

10 Eagle Street
Brisbane QLD 4000, Australia
hello@frontdesq.co 0485 078 913

Explore

How it worksHear the demoPricingFAQBlog

Learn

AI receptionist for tradiesVirtual receptionist for law firmsVirtual medical receptionistAI receptionist AustraliaVirtual receptionistAI phone answeringAI answering serviceAfter hours answeringOverflow call answering

Policies

Privacy policyTerms of serviceData processingRefunds & cancellation
© 2026 FRONTDESQ LTD. All rights reserved.