Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Cold Calling Group Ltd ("Processor", "we", "us"), trading as Will This Person Answer. It applies whenever you send us contact data to analyze. We are a private limited company registered in England and Wales under company number 13490535, with our registered office at 5 Ducketts Wharf, South Street, Bishops Stortford, Hertfordshire, CM23 3AR, United Kingdom.
Where this DPA and the Terms of Service disagree about the processing of personal data, this DPA applies.
Roles
You are the controller of the contact data you send us. You decide whose numbers to submit and why. We are your processor and handle that data only to provide the service to you.
We are a separate controller of your own account data, such as your name, work email address and billing records. That processing is described in our Privacy Policy and is not covered by this DPA.
What we process
- Categories of personal data: the first name, last name and phone number of each contact you submit, and the grade, action, reason and signals we return for them.
- Categories of data subjects: the people whose contact details you submit, who are typically prospects or candidates of your business.
- Nature and purpose: checking a phone number against our data provider and returning a calling priority, so that your team knows who to call.
- Duration: for as long as your account is open, and for the period described under Deletion below.
We do not ask for and do not want special category data. Do not send us health, biometric, political, religious or similar data about anyone.
Your instructions
We process contact data only on your documented instructions. Submitting a contact through the API, the MCP server, the web app or a CSV upload is that instruction. We will tell you if we believe an instruction breaks UK or EU data protection law.
You confirm that you have a lawful basis for sending us each contact, that you have given any notice your own privacy information requires, and that you are entitled to have us process that data on your behalf.
Confidentiality
Everyone we allow to access contact data is bound by a duty of confidentiality and only has the access their role requires.
Security
We take appropriate technical and organisational measures, including:
- Encryption of personal data in transit and at rest.
- Row level security on customer-owned tables, so an account can only ever reach its own records.
- Private file storage. Uploaded files are not public, and result downloads are served through signed, server-issued links checked against the account that owns the job.
- Server-only credentials. Keys that can bypass access control are never exposed to the browser.
- Access control and authentication for our own staff, and separation of production from development.
Sub-processors
You give us general authorisation to engage sub-processors. We impose data protection terms on each of them that are no less protective than this DPA, and we remain liable to you for their performance.
Our current sub-processors are:
- A specialist phone-data provider, used to analyze the contacts you submit.
- Supabase, for our database and authentication.
- Vercel, for hosting the website and application.
- Stripe, for payments and subscriptions.
- An email delivery provider, for account and service emails.
We will give you reasonable notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot resolve the objection, you may stop using the service and close your account.
International transfers
Some of our sub-processors are based in, or store data in, the United States. When personal data leaves the UK we rely on appropriate safeguards, such as the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Addendum or the UK International Data Transfer Agreement.
Helping you meet your obligations
- Data subject requests: if a data subject contacts us directly about data we hold for you, we will not respond on your behalf. We will tell you without undue delay and help you respond, taking account of what the service makes available to you.
- Personal data breaches: we will notify you without undue delay after becoming aware of a breach affecting your contact data, with the information we have at the time.
- Assessments: we will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.
Audit
We will make available the information reasonably needed to show that we meet this DPA. Where that is not enough, you may audit us, or appoint an independent auditor, no more than once a year, on at least 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality.
Deletion
You may delete uploaded files and results from your account at any time.
To close your account, email us. We will delete or anonymise the personal data associated with it within 30 days, except where we must keep records to meet a legal obligation, such as billing records kept for tax purposes.
We do not regenerate historical result files. A file you have already downloaded is yours.
Liability and governing law
Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Contact
Questions about this DPA, or a request to sign a counterpart, should go to support@willthispersonanswer.com.