Legal
Data Processing Addendum
Effective 1 September 2026
1. Roles and scope
This addendum forms part of the Agent Telco Terms of Service between Clyde Works Limited, trading as Agent Telco, and the customer. For Customer Data, the customer is the controller and we are its processor under UK data protection law.
"Customer Data" means personal data submitted to Agent Telco for customer-directed telecom work: senders and recipients, telephone numbers, message content and delivery metadata, and personal data in customer webhook payloads. We are a separate controller for account, workspace membership, authentication, billing, security, pilot, support, and complaint records described in our Privacy Notice.
2. Instructions
We will process Customer Data only on the customer's documented instructions, including for international transfers, unless UK law requires otherwise. If law requires processing, we will tell the customer before it happens unless the law prohibits notice for an important public-interest reason. Instructions include the Terms, API and MCP requests, console settings, OAuth approvals, webhook configuration, and later written instructions consistent with the service. We will tell the customer immediately if we believe an instruction infringes UK data protection law.
3. Confidentiality
We ensure that every person we authorise to process Customer Data is bound by a contractual or statutory duty of confidentiality.
4. Security
We maintain measures appropriate to the risk, including encryption in transit, credential hashing or encryption where appropriate, tenant isolation, scoped API and OAuth permissions, signed customer webhooks, access controls, rate and spend limits, idempotency, and security-event logging. The customer must protect its accounts, credentials, agents, clients, receiving endpoints, and local copies.
5. Sub-processors
The customer gives general written authorisation for sub-processors that provide cloud hosting and storage, email and queue delivery, and telecom number provisioning and SMS carriage. We maintain a current list and provide it on request. We will give at least 14 days' notice before adding or replacing a sub-processor that processes Customer Data, so the customer can object on reasonable data protection grounds. If we cannot resolve a reasonable objection, the customer may end the affected service and receive a pro-rata refund of prepaid fees for it.
We impose equivalent data protection obligations on each sub-processor and remain liable to the customer for that sub-processor's performance of those obligations.
6. Assistance
Taking account of the processing and information available to us, we help the customer respond to data-subject requests and meet duties concerning security, breach notification, data protection impact assessments, and prior consultation with the Information Commissioner. We pass a request concerning Customer Data to the customer without undue delay.
7. Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data. As information becomes available, we provide the nature of the breach, affected categories and approximate numbers, likely consequences, and measures taken or proposed.
8. Return and deletion
At the end of the service, we will return or delete Customer Data at the customer's choice, and delete existing copies, unless UK law requires retention. The customer must make its choice before account closure and allow time to settle number, message, and webhook operations. Copies in encrypted backups are deleted or put beyond use through the applicable backup cycle. We may keep limited operational evidence where needed to resolve a live telecom delivery, security incident, dispute, or legal obligation.
9. Information and audit
We provide information needed to show compliance with this addendum and allow audits, including inspections, by the customer or its appointed auditor. Audits are at the customer's cost, on at least 14 days' notice, during business hours, and normally no more than once in 12 months. Those limits do not apply where a regulator, personal data breach, or material non-compliance requires an audit. An audit must protect other customers, security information, and our suppliers.
10. International transfers
We do not transfer Customer Data outside the UK without a valid UK transfer mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any required transfer assessment. We identify the applicable mechanism on request.
11. Customer obligations
The customer is responsible for the lawfulness of Customer Data and messaging instructions. This includes choosing a lawful basis, giving privacy information, obtaining required consent, honouring opt-outs and rights, controlling its agents, and making sure its instructions comply with UK data protection law.
12. Details of the processing
- Subject matter. UK mobile number provisioning, SMS transmission and receipt, message status, API and MCP access, and customer webhook delivery.
- Duration. The term of the customer's use, plus the return, deletion, and operational resolution period in section 8.
- Nature and purpose. Collection, storage, organisation, transmission, retrieval, display, and delivery of telecom data under the customer's instructions.
- Personal data. Names where included in content, phone numbers, message content, timestamps, delivery metadata, and webhook payloads and responses.
- Data subjects. Message senders and recipients, and people identified in customer-directed messages or webhook data.
- Sensitive data. The service is not designed for special-category or criminal-offence data. The customer must not submit it unless it has assessed the risk, has a lawful condition, and has agreed appropriate safeguards with us in writing.
Clyde Works Limited (SC897847), registered in Scotland. Registered office: 48 West George Street, Glasgow, Scotland, G2 1BP. Trading as Agent Telco. support@sharedmobile.co.uk