Data Processing Agreement
This Data Processing Agreement forms part of the Terms of Service between My Revue Ltd and its clients. It governs the processing of personal data by My Revue on behalf of its clients in accordance with Article 28 of UK GDPR and the Data Protection Act 2018.
1. Parties
Data Processor: My Revue Ltd, London, United Kingdom ("My Revue")
Data Controller: The client engaging My Revue to provide AI marketing services ("Client")
2. Background
My Revue provides AI marketing infrastructure services including lead nurturing, AI outbound calling, Google Review Automation, AI chatbot deployment, and CRM management. In delivering these services, My Revue processes personal data belonging to the Client's customers and leads on the Client's behalf. The Client, as data controller, determines the purposes and means of processing. My Revue, as data processor, processes personal data only on the Client's documented instructions.
3. Details of Processing
Subject matter | AI marketing services delivered by My Revue on behalf of the Client |
Duration | For the duration of the engagement |
Nature | Collection, storage, use, and deletion of personal data in lead nurturing, AI outbound calling, review automation, chatbot interactions, and CRM management |
Purpose | Converting digital leads into booked appointments, collecting client reviews, providing AI chatbot responses, managing CRM pipelines |
Data types | Names, email addresses, telephone numbers, call transcripts, booking data, business contact details |
Data subjects | The Client's customers, leads, and business contacts |
4. Processor's Obligations
4.1 Instructions
My Revue shall process personal data only on the documented instructions of the Client and only for the purposes described in clause 3.
4.2 Confidentiality
All personnel authorised to process personal data are subject to binding confidentiality obligations. Access is restricted to those who need it to deliver the services.
4.3 Security
My Revue implements and maintains appropriate technical and organisational security measures including:
AES-256 encryption for data at rest
TLS 1.2+ encryption for data in transit
Role-based access controls with audit logging
Multi-factor authentication for all systems containing personal data
Regular security reviews and staff data protection training
Daily automated backups with 30-day retention
4.4 Sub-processors
The Client provides general written authorisation for My Revue to engage sub-processors as listed in clause 5. My Revue will notify the Client of any intended changes before a new sub-processor is engaged. Equivalent data protection obligations are imposed on all sub-processors.
4.5 Data subject rights
My Revue shall assist the Client in responding to data subject requests under UK GDPR. Requests made directly to My Revue will be forwarded to the Client without undue delay.
4.6 Audit rights
My Revue shall make available all information necessary to demonstrate compliance and shall allow for audits by the Client or its authorised auditor, subject to reasonable notice and confidentiality obligations. No more than one audit per year unless reasonable cause for concern is established.
5. Sub-processors
Sub-processor | Location | Processing Activity |
|---|---|---|
GoHighLevel (HighLevel Inc.) | USA | CRM, pipeline, SMS and email automation, call tracking, dashboards |
Vapi.ai | USA | AI voice technology for inbound and outbound calling |
Retell AI | USA | AI voice technology (alternative to Vapi) |
Twilio Inc. | USA | SMS delivery, phone numbers, and call routing |
Vonage (Ericsson) | UK / USA | Telephony infrastructure |
OpenAI | USA | Language model (GPT-4o) for AI voice and chatbots |
FastBots.ai / Chatbase | USA | AI chatbot deployment |
Cal.com | USA | Appointment scheduling |
Zapier / Make.com | USA | Workflow automation between platforms |
Google LLC | USA | Google Business Profile API for reviews; Google Workspace for internal communications |
6. Controller's Obligations
The Client warrants that it holds a valid lawful basis under UK GDPR Article 6 for all personal data provided to My Revue, has provided all necessary notices to and obtained all necessary consents from data subjects (including where applicable informing them they may be contacted by an AI-powered system), and will promptly notify My Revue of any changes in processing instructions.
7. Personal Data Breaches
My Revue shall notify the Client within 72 hours of becoming aware of a personal data breach affecting the Client's data, describing the nature of the breach, categories and approximate number of affected data subjects, likely consequences, and measures taken to address it. The Client is responsible for notifying the ICO and data subjects where required.
8. International Data Transfers
All international transfers comply with UK GDPR Chapter 5 using UK adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to EU Standard Contractual Clauses. Details of the transfer mechanism for each sub-processor are available on request.
9. Term and Data Deletion
This Agreement remains in force for the duration of the engagement. Upon termination or written request, My Revue shall at the Client's election return all personal data in a structured machine-readable format and then securely delete all copies, or securely delete all personal data and confirm deletion in writing within 30 days. Data may be retained longer where required by law.
10. Governing Law
This Agreement is governed by the laws of England and Wales. Any dispute shall be subject to the exclusive jurisdiction of the courts of England and Wales.
11. Contact
My Revue Ltd, London, United Kingdom | info@my-revue.co.uk | +44 7824 926072
Clients requiring a signed copy of this DPA may request one by emailing info@my-revue.co.uk.




