Data Processing Agreement

Version 1.0 — 31 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the business customer using the Services (the "Client" or "Controller") and My Nebulas (the "Processor"). It applies where My Nebulas processes Personal Data on behalf of the Client in connection with the Services, and is incorporated by reference into our Terms & Conditions.

1. Scope, subject matter, and duration

1.1 This DPA governs the processing of Personal Data by Processor on behalf of Controller for the purpose of providing the Services, including: answering and routing business telephone calls and text messages; taking bookings; issuing and chasing invoices; related support, administration, and service delivery activities.

1.2 The duration of this DPA shall be for the term of the Client's subscription or service agreement, plus any additional period required for deletion, return, or legal retention obligations.

2. Roles of the parties

2.1 For Personal Data relating to the Client's own customers, contacts, and end users, the Client acts as Controller and My Nebulas acts as Processor. The people whose data is processed are the Client's own customers — members of the public who telephoned, texted, or booked with the Client's business. They have no relationship with My Nebulas.

2.2 For Personal Data relating to the Client's account administration, billing, support, platform access, and other data processed for My Nebulas' own business purposes, My Nebulas acts as an independent Controller.

2.3 Each party shall process Personal Data only in the capacity applicable to the relevant processing activity.

3. Categories of Personal Data

3.1 The categories of Personal Data processed under this DPA may include: telephone numbers; text message content, in both directions; names; email addresses; call transcripts; the stated reason for calling; appointment details; invoice amounts and status; opt-out records; audit and authentication records; and other information supplied by the Client or by data subjects in the course of using the Services.

3.2 The Processor does not intentionally solicit special category data. However, the reason a caller gives for contacting a business is free text, and such data may be incidentally included there, or in call transcripts or message content. The Controller remains responsible for ensuring a lawful basis and, where applicable, an Article 9 condition for processing such data.

4. Processing instructions

4.1 Processor shall process Personal Data only on documented instructions from Controller, unless otherwise required by applicable law.

4.2 Controller instructs Processor to process Personal Data for the provision of the Services and related administration, support, billing, and compliance functions.

5. Call recording and transcription

5.1 The missed-call service does not record calls.

5.2 The AI receptionist transcribes calls in order to function. Those transcripts are held by our telephony provider in their conversation store, and are not copied into the My Nebulas database.

5.3 Transcripts are deleted at the provider on an automated schedule, with a sample retained for quality checking. Access to any retained transcript is restricted to authorised personnel through a read-only, key-gated route.

5.4 Where call audio exists, it is stored by our telephony provider rather than by My Nebulas.

5.5 The Processor shall not intentionally record calls unless the Service expressly indicates that recording is active.

6. Retention

6.1 Personal Data shall be retained only for the periods necessary for the purposes of the Services and applicable legal obligations. Retention is enforced automatically rather than manually.

6.2 Retention periods are:

  • Message content and voice leads — 24 months
  • Bookings — 36 months
  • Missed calls and CRM lead events — 12 months
  • Voicemail records, booking reminders, and authentication logs — 90 days
  • In-call working state — 30 days
  • Opt-out records — retained indefinitely; deleting one would re-enable contact with a person who has objected
  • Invoices — retained for statutory and accounting purposes
  • Usage records — retained as the basis for billing

6.3 On termination of the Services, a departed Client's customer data is purged 90 days after the account ends, with notice 14 days beforehand so that an export can be taken first. Opt-out records, invoices, and usage records survive as described above.

7. Deletion and return

7.1 On request, Processor shall provide the Client's bookings, leads, message history, missed calls, and invoices as a single exportable file.

7.2 On a request to erase an individual's data, Processor shall: delete that person's messages, missed calls, and lead records; redact bookings, so that the appointment record survives without the person; flag invoices for human decision rather than deleting them, because of statutory retention; and retain the opt-out record, deliberately, so that erasure does not re-enable contact.

7.3 Every erasure writes a record, so that compliance can be demonstrated rather than merely asserted.

8. Sub-processors

8.1 Controller provides general authorization for Processor to engage sub-processors for the provision of the Services.

8.2 The current sub-processors are:

  • Twilio (United States) — telephony and SMS carriage; receives numbers, message content, call metadata, and any recordings
  • Telnyx (United States) — AI receptionist; receives live call audio and transcripts
  • Stripe (United States / Ireland) — payments and invoicing; receives customer name, email, and amounts
  • Google (United States) — sending email on the Client's behalf, and calendar
  • Anthropic (United States) — AI drafting; receives lead text and drafting inputs
  • Cloudflare (United States) — CDN, DNS, and object storage; handles traffic in transit and media objects
  • Pipedrive (Estonia / United States) — optional CRM path only, where the Client chooses it
  • Hetzner (Germany) — hosting for the My Nebulas CRM
  • Hostinger (United States) — hosting for the primary application and database

8.3 Each sub-processor above operates under a data processing agreement incorporating Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

8.4 Processor shall ensure that sub-processors are bound by written terms imposing data protection obligations no less protective than those in this DPA, and shall notify Controller before adding a new sub-processor where required by applicable law.

9. Where data is processed

9.1 The primary application and database are hosted in the United States. Backups are held in an EU-jurisdiction store, taken nightly and verified by restoration rather than by upload alone. The My Nebulas CRM is hosted in Germany.

9.2 Clients outside the United States should note that their data is currently processed and stored in the United States. Transfers are made under the mechanisms described in clause 8.3.

9.3 Where Personal Data is transferred outside the UK, EEA, or other applicable jurisdiction, Processor shall ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses, the UK IDTA, or other lawful transfer safeguards as applicable.

10. Security measures

10.1 Processor shall implement appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption at rest for all third-party credentials and access tokens, with the key held outside the database
  • TLS in transit for all public endpoints
  • Key-gated administrative access, with attempts logged and automatic lockout after repeated failures
  • Session expiry and authentication controls on the client portal
  • Nightly backups with local rotation and an offsite copy in an EU-jurisdiction store, verified by restoring them rather than by confirming the upload succeeded, and monitored so that a failed or missing backup raises an alert
  • Logging of administrative actions, and monitoring and alerting for security and availability

10.2 Processor shall maintain and review security controls appropriate to the nature of the Services and the risks presented by the processing.

11. Personal data breaches

11.1 Processor shall notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Data.

11.2 Notification shall include available information concerning: the nature of the breach; the likely consequences; measures taken or proposed to address the breach; and any other information reasonably required by Controller.

11.3 The parties shall cooperate in good faith to investigate, mitigate, and respond to any Personal Data breach.

12. Assistance

12.1 Taking into account the nature of the processing, Processor shall assist Controller with: data subject access requests; rectification, erasure, restriction, and objection requests; data portability, where applicable; security and breach response; and data protection impact assessments and prior consultation, where applicable.

13. Audit and compliance

13.1 Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.

13.2 Controller may request reasonable audit information, subject to confidentiality, security, and operational constraints.

14. Liability and governing law

14.1 Liability, indemnity, governing law, venue, and dispute resolution are as set out in our Terms & Conditions, which form part of the agreement between the parties.

14.2 The parties acknowledge that My Nebulas operates as a sole proprietorship.

15. Miscellaneous

15.1 In the event of conflict between this DPA and the main service agreement, this DPA shall prevail to the extent required for data protection compliance.

15.2 This DPA shall be interpreted in accordance with applicable data protection law.

Schedule 1 — Processing details

Subject matter: Business communications, call handling, booking, invoicing, and related support services.

Duration: For the term of the subscription plus retention, deletion, and legal hold periods.

Nature and purpose: To automate and support the Client's customer communications and administration, so that enquiries are not missed.

Categories of data subjects: Client customers, callers, leads, booking contacts, invoice contacts, and Client personnel where relevant.

Categories of Personal Data: Telephone numbers, names, email addresses, message content, call transcripts, booking details, invoice data, opt-out data, and related metadata.

Special category data: Not intentionally sought, but may be incidentally provided in free text or transcripts.

Schedule 2 — Security measures

Encryption at rest for credentials and access tokens; TLS in transit; key-gated administrative actions with logging and lockout; authentication controls and session expiry; nightly backups with an EU-jurisdiction offsite copy, verified by restoration and monitored for failure; access and administrative action logging; availability monitoring and alerting; incident response and escalation procedures.

16. Contact

Questions about this agreement, or a request relating to personal data, can be sent via our contact page.