Version 1.0 — 31 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the business customer using the Services (the "Client" or "Controller") and My Nebulas (the "Processor"). It applies where My Nebulas processes Personal Data on behalf of the Client in connection with the Services, and is incorporated by reference into our Terms & Conditions.
1.1 This DPA governs the processing of Personal Data by Processor on behalf of Controller for the purpose of providing the Services, including: answering and routing business telephone calls and text messages; taking bookings; issuing and chasing invoices; related support, administration, and service delivery activities.
1.2 The duration of this DPA shall be for the term of the Client's subscription or service agreement, plus any additional period required for deletion, return, or legal retention obligations.
2.1 For Personal Data relating to the Client's own customers, contacts, and end users, the Client acts as Controller and My Nebulas acts as Processor. The people whose data is processed are the Client's own customers — members of the public who telephoned, texted, or booked with the Client's business. They have no relationship with My Nebulas.
2.2 For Personal Data relating to the Client's account administration, billing, support, platform access, and other data processed for My Nebulas' own business purposes, My Nebulas acts as an independent Controller.
2.3 Each party shall process Personal Data only in the capacity applicable to the relevant processing activity.
3.1 The categories of Personal Data processed under this DPA may include: telephone numbers; text message content, in both directions; names; email addresses; call transcripts; the stated reason for calling; appointment details; invoice amounts and status; opt-out records; audit and authentication records; and other information supplied by the Client or by data subjects in the course of using the Services.
3.2 The Processor does not intentionally solicit special category data. However, the reason a caller gives for contacting a business is free text, and such data may be incidentally included there, or in call transcripts or message content. The Controller remains responsible for ensuring a lawful basis and, where applicable, an Article 9 condition for processing such data.
4.1 Processor shall process Personal Data only on documented instructions from Controller, unless otherwise required by applicable law.
4.2 Controller instructs Processor to process Personal Data for the provision of the Services and related administration, support, billing, and compliance functions.
5.1 The missed-call service does not record calls.
5.2 The AI receptionist transcribes calls in order to function. Those transcripts are held by our telephony provider in their conversation store, and are not copied into the My Nebulas database.
5.3 Transcripts are deleted at the provider on an automated schedule, with a sample retained for quality checking. Access to any retained transcript is restricted to authorised personnel through a read-only, key-gated route.
5.4 Where call audio exists, it is stored by our telephony provider rather than by My Nebulas.
5.5 The Processor shall not intentionally record calls unless the Service expressly indicates that recording is active.
6.1 Personal Data shall be retained only for the periods necessary for the purposes of the Services and applicable legal obligations. Retention is enforced automatically rather than manually.
6.2 Retention periods are:
6.3 On termination of the Services, a departed Client's customer data is purged 90 days after the account ends, with notice 14 days beforehand so that an export can be taken first. Opt-out records, invoices, and usage records survive as described above.
7.1 On request, Processor shall provide the Client's bookings, leads, message history, missed calls, and invoices as a single exportable file.
7.2 On a request to erase an individual's data, Processor shall: delete that person's messages, missed calls, and lead records; redact bookings, so that the appointment record survives without the person; flag invoices for human decision rather than deleting them, because of statutory retention; and retain the opt-out record, deliberately, so that erasure does not re-enable contact.
7.3 Every erasure writes a record, so that compliance can be demonstrated rather than merely asserted.
8.1 Controller provides general authorization for Processor to engage sub-processors for the provision of the Services.
8.2 The current sub-processors are:
8.3 Each sub-processor above operates under a data processing agreement incorporating Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
8.4 Processor shall ensure that sub-processors are bound by written terms imposing data protection obligations no less protective than those in this DPA, and shall notify Controller before adding a new sub-processor where required by applicable law.
9.1 The primary application and database are hosted in the United States. Backups are held in an EU-jurisdiction store, taken nightly and verified by restoration rather than by upload alone. The My Nebulas CRM is hosted in Germany.
9.2 Clients outside the United States should note that their data is currently processed and stored in the United States. Transfers are made under the mechanisms described in clause 8.3.
9.3 Where Personal Data is transferred outside the UK, EEA, or other applicable jurisdiction, Processor shall ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses, the UK IDTA, or other lawful transfer safeguards as applicable.
10.1 Processor shall implement appropriate technical and organizational measures to protect Personal Data, including:
10.2 Processor shall maintain and review security controls appropriate to the nature of the Services and the risks presented by the processing.
11.1 Processor shall notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Data.
11.2 Notification shall include available information concerning: the nature of the breach; the likely consequences; measures taken or proposed to address the breach; and any other information reasonably required by Controller.
11.3 The parties shall cooperate in good faith to investigate, mitigate, and respond to any Personal Data breach.
12.1 Taking into account the nature of the processing, Processor shall assist Controller with: data subject access requests; rectification, erasure, restriction, and objection requests; data portability, where applicable; security and breach response; and data protection impact assessments and prior consultation, where applicable.
13.1 Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.
13.2 Controller may request reasonable audit information, subject to confidentiality, security, and operational constraints.
14.1 Liability, indemnity, governing law, venue, and dispute resolution are as set out in our Terms & Conditions, which form part of the agreement between the parties.
14.2 The parties acknowledge that My Nebulas operates as a sole proprietorship.
15.1 In the event of conflict between this DPA and the main service agreement, this DPA shall prevail to the extent required for data protection compliance.
15.2 This DPA shall be interpreted in accordance with applicable data protection law.
Subject matter: Business communications, call handling, booking, invoicing, and related support services.
Duration: For the term of the subscription plus retention, deletion, and legal hold periods.
Nature and purpose: To automate and support the Client's customer communications and administration, so that enquiries are not missed.
Categories of data subjects: Client customers, callers, leads, booking contacts, invoice contacts, and Client personnel where relevant.
Categories of Personal Data: Telephone numbers, names, email addresses, message content, call transcripts, booking details, invoice data, opt-out data, and related metadata.
Special category data: Not intentionally sought, but may be incidentally provided in free text or transcripts.
Encryption at rest for credentials and access tokens; TLS in transit; key-gated administrative actions with logging and lockout; authentication controls and session expiry; nightly backups with an EU-jurisdiction offsite copy, verified by restoration and monitored for failure; access and administrative action logging; availability monitoring and alerting; incident response and escalation procedures.
Questions about this agreement, or a request relating to personal data, can be sent via our contact page.