Skip to content
Strath AICustomer dashboard

LEGAL INFORMATION · 2026-09-08.2

Data processing agreement

This agreement forms part of new Strath AI business subscriptions accepted under the Terms of service. The customer identified in the subscription order is the Controller. Strathern OPEX Consulting Ltd (company 17166345), trading as Strath AI, is the Processor. Version 2026-09-08.2. Existing agreements are not retrospectively changed by publication.

Contents

1. Scope and instructions2. People and information3. Confidentiality and security4. Subprocessors and transfers5. Assistance and incidents6. Return, deletion and retention7. Evidence, audit and precedence

1. Scope and instructions

This agreement applies to personal data entrusted to Strath AI for the customer's receptionist and workspace. Processing consists of receiving and analysing inbound calls, collecting enquiries, managing customer records and appointments, delivering service messages, and providing hosting and support. It continues for the subscription and the agreed return/deletion period. The customer's order, settings and lawful support instructions define the purposes; Strath AI does not acquire ownership of this data.

The customer is responsible for its lawful basis, caller notices, accuracy and authority to provide data. Strath AI processes only on documented instructions, including instructions concerning transfers, unless law requires processing. It will notify the customer of that requirement unless legally prohibited, and inform the customer if it considers an instruction infringes applicable data-protection law. The parties will resolve the issue before the disputed processing continues.

2. People and information

Data subjects are callers, customers, prospective customers, appointment attendees and business contacts. Data includes names, telephone numbers, email and service addresses, enquiry/job details, conversation content where enabled, appointment times and service correspondence. Account administration, fraud prevention and statutory payment records processed for Strath AI's own purposes are governed by the Privacy policy instead.

The service is not designed for deliberate collection of medical information, special-category data, criminal-offence data, children's records or payment-card details spoken to the agent. The customer must not configure those uses without a separately agreed risk assessment and appropriate safeguards. Unexpected sensitive information must be restricted and reviewed for prompt minimisation.

3. Confidentiality and security

Authorised personnel must be subject to confidentiality obligations and access only what their role requires. Strath AI will maintain appropriate technical and organisational measures proportionate to the nature and risk of processing, review their effectiveness and avoid materially reducing protection during the agreement.

The security schedule comprises tenant-scoped database access and RLS, verified authentication, additional administrator MFA, restricted backend credentials, encrypted network connections, audited administrative commands, protected provider requests and backup/recovery procedures. No independent certification, uninterrupted service or error-free AI is implied. The customer must protect its own credentials and review important AI outputs. Current evidence and limitations are available through the workspace security documents.

4. Subprocessors and transfers

The customer grants general written authorisation for the subprocessors identified in the published Subprocessors schedule. Strath AI will give at least 30 days' notice before appointing a new direct subprocessor or replacing one, allowing the customer to object on reasonable data-protection grounds before it processes that customer's data. The parties will seek a practical alternative; if none is available, the customer may end the affected service before the change and receive a refund of unused prepaid fees for that service.

Subprocessors must be bound by obligations providing the protection required by applicable law. Strath AI remains responsible to the customer for its subprocessor obligations. Changes made by a supplier to its own suppliers are assessed and communicated promptly under the applicable contractual notice arrangements; they are not represented as having an independently controllable 30-day delay.

Strath AI will make restricted international transfers only with a valid mechanism and any necessary assessment and supplementary safeguards. An EU hosting region does not guarantee UK/EU-only access. Customers may request the applicable transfer information, subject to protection of confidential and third-party information.

5. Assistance and incidents

Strath AI will assist the customer, taking account of the processing and information available, with individual rights, security duties, data-protection impact assessments and prior regulatory consultation. Requests concerning customer-controlled data will be referred to the customer rather than answered independently unless authorised or required by law.

On becoming aware of a personal-data breach affecting the customer's data, Strath AI will notify the customer without undue delay and provide available information about its nature, affected records and people, likely consequences, response measures and a contact. Information may be supplied in stages; an initial notice will not wait for complete investigation. Strath AI will cooperate with containment, evidence preservation and the customer's notification decisions.

6. Return, deletion and retention

At the end of service, the customer may request return or deletion of service data. Operational data will be removed within 30 days of account closure unless a lawful hold or other applicable requirement prevents this; the customer should request an export before closure. Earlier valid erasure requests will be handled under documented instructions and applicable deadlines. Identity and scope must be verified before disclosure or irreversible action.

The approved schedule is 30 days for stored recordings/full transcripts, 12 months for summaries and notification content, and 12 months after closure for support tickets. Active CRM/job records are reviewed annually for continuing necessity. Temporary provider exports expire after 24 hours. Necessary accounting records may be retained for six years from the relevant financial year end. Retention does not justify keeping unrelated content.

A fulfilment record will distinguish deletion, restricted lawful retention and provider/backup expiry. Backup copies are kept out of ordinary use and expire through the backup cycle; deletion and access-revocation records must be reapplied before restoring service. Provider-assisted steps are tracked until confirmed. Strath AI will not describe an unresolved provider copy as deleted.

7. Evidence, audit and precedence

Strath AI will provide information reasonably necessary to demonstrate its obligations and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Reasonable scheduling, confidentiality and scope arrangements must protect other customers without defeating these rights. Urgent regulatory or incident requirements take priority over routine scheduling.

This agreement takes precedence over conflicting service terms for customer-data processing. It does not limit rights of individuals or regulators, or liabilities that cannot lawfully be limited. Contact support@strath.io for instructions, rights assistance, transfer information or audit arrangements.

Questions? Contact support@strath.io.

Terms of servicePrivacy policyData processing agreementSubprocessors