Vlok Data Processing Agreement
Last updated: 1 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Vlok Ltd and the Client governing the Client’s use of the Vlok Service.
This DPA applies where Vlok processes Personal Data on behalf of the Client in connection with the Service.
1. Parties and incorporation
1.1 Parties
This DPA is entered into between:
Vlok Ltd, a company registered in England and Wales with its registered office at The Oval, 57 New Walk, Leicester, England, LE1 7EA (“Vlok” or “Processor”); and
the restaurant, hospitality business or other organisation that has entered into an Agreement with Vlok (“Client” or “Controller”).
Each is a “Party” and together they are the “Parties”.
1.2 Incorporation
This DPA forms part of and is incorporated into:
- the Vlok Terms of Service;
- the applicable Order Form; and
- any other agreement expressly incorporating this DPA.
1.3 Priority
If there is a conflict between this DPA and another part of the Agreement concerning the processing of Client Personal Data, this DPA will take priority.
If there is a conflict between this DPA and a binding international data-transfer agreement entered into by the Parties, the international data-transfer agreement will take priority in relation to the relevant Restricted Transfer.
1.4 Relationship with Privacy Policy
Vlok’s Privacy Policy explains how Vlok processes Personal Data, including activities for which Vlok acts as an independent Controller.
The Privacy Policy does not replace this DPA.
2. Definitions
In this DPA:
Agreement means the Vlok Terms of Service, the applicable Order Form, this DPA, the Fees and Billing Policy, any Telecom and Number Authorisation and any other document expressly incorporated into the contractual relationship.
Applicable Data Protection Law means all data-protection and privacy laws applicable to processing under this DPA, including:
- the UK GDPR;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003, where applicable; and
- any legislation replacing, amending or supplementing them.
Client Personal Data means Personal Data processed by Vlok on behalf of the Client in connection with the Service.
Controller, Data Subject, Personal Data, Personal Data Breach, processing, Processor and Special Category Personal Data have the meanings given under Applicable Data Protection Law.
Data Subject Request means a request by a Data Subject to exercise a right under Applicable Data Protection Law.
Restricted Transfer means a transfer of Personal Data that requires an adequacy decision, appropriate safeguard, exception or other lawful transfer mechanism under Applicable Data Protection Law.
Service means Vlok’s AI-powered call-handling, restaurant booking, messaging, reporting, support and related services.
Subprocessor means another Processor appointed by Vlok to process Client Personal Data on behalf of the Client.
UK Addendum means the international data-transfer addendum to the European Commission’s standard contractual clauses approved for use under UK data-protection law.
UK GDPR means the retained UK version of the General Data Protection Regulation, as amended or replaced.
UK IDTA means the International Data Transfer Agreement approved for use under UK data-protection law.
3. Roles of the Parties
3.1 Client as Controller
The Client acts as Controller where it determines the purposes and essential means of processing caller, guest, reservation and related information through the Service.
3.2 Vlok as Processor
Vlok acts as Processor where it processes Client Personal Data on behalf of the Client to provide the Service under the Client’s documented instructions.
3.3 Vlok’s independent-controller activities
Vlok may separately act as an independent Controller for processing undertaken for Vlok’s own purposes, including:
- management of Vlok’s client accounts;
- billing and financial administration;
- service and information security;
- fraud and abuse prevention;
- regulatory and legal compliance;
- establishing, exercising or defending legal claims;
- managing complaints and support records;
- maintaining Vlok’s corporate records;
- selected manual quality and safety reviews; and
- eligible AI development, testing, evaluation and improvement activities described in Vlok’s Privacy Policy.
Processing carried out by Vlok as an independent Controller is not carried out on behalf of the Client and is not governed by the Client’s instructions under this DPA.
Vlok must comply with Applicable Data Protection Law for such processing.
3.4 Legal classification
Nothing in the Agreement overrides a Party’s legal classification where its actual processing activities determine that it acts as a Controller, joint Controller or Processor.
4. Details of processing
The details of processing are set out in Annex 1.
The Parties agree that Annex 1 describes:
- the subject matter of processing;
- the duration of processing;
- the nature and purpose of processing;
- the categories of Data Subjects;
- the categories of Personal Data;
- relevant Special Category Personal Data; and
- the Client’s rights and obligations.
The Client may provide additional documented instructions through:
- the Order Form;
- Service configuration;
- onboarding records;
- account settings;
- authorised support requests; or
- other written communications accepted by Vlok.
5. Documented instructions
5.1 Processing on instructions
Vlok will process Client Personal Data only:
- on the Client’s documented instructions;
- as reasonably necessary to provide the Service;
- as described in the Agreement; or
- where processing is required by applicable law.
5.2 Instructions contained in the Agreement
The Client instructs Vlok to process Client Personal Data as necessary to:
- receive and route telephone calls;
- convert speech to text;
- generate automated responses;
- provide restaurant information;
- create, confirm, amend and cancel bookings;
- apply the Client’s opening hours, capacity and booking rules;
- send SMS messages and confirmations;
- send menus and allergen information approved by the Client;
- collect and communicate guest requests;
- transfer or escalate interactions to Client staff;
- provide transcripts, booking records and call information;
- provide support and troubleshooting;
- detect and prevent fraud, misuse and security incidents;
- operate integrations;
- use approved Subprocessors;
- perform the processing described in Annex 1; and
- delete or return Client Personal Data in accordance with this DPA.
5.3 Instructions required by law
Where Vlok is required by law to process Client Personal Data other than on the Client’s instructions, Vlok will inform the Client before processing unless the law prohibits that notification.
5.4 Unlawful instructions
Vlok will inform the Client if Vlok reasonably believes that an instruction infringes Applicable Data Protection Law.
Vlok may suspend performance of the affected instruction until the Parties clarify, amend or withdraw it.
Vlok is not required to undertake an instruction that:
- is unlawful;
- is technically impossible;
- would materially compromise the security of the Service;
- would breach another person’s rights;
- is outside the agreed scope of the Service; or
- would require disproportionate changes to the Service.
Where an instruction is outside the agreed Service, Vlok may agree to perform it subject to additional Fees and terms.
6. Client obligations
The Client must:
- comply with Applicable Data Protection Law;
- ensure that its processing instructions are lawful;
- identify and document an appropriate lawful basis for processing;
- identify an appropriate condition for processing Special Category Personal Data;
- provide Data Subjects with required privacy information;
- ensure that Client Personal Data is collected fairly and lawfully;
- only instruct Vlok to process Personal Data that is adequate, relevant and reasonably necessary;
- ensure that Client Personal Data and Client-supplied information are accurate and kept up to date;
- maintain appropriate account and user-access controls;
- ensure that Authorised Users protect their credentials;
- respond to Data Subject Requests as Controller;
- notify Vlok promptly of any relevant restriction, objection or withdrawal of consent;
- maintain appropriate human escalation and food-safety procedures;
- keep menus, allergen menus and ingredient information complete and accurate;
- not instruct Vlok to make unsupported allergen or food-safety guarantees;
- not provide unnecessary health, financial or other sensitive information;
- not use the Service for unlawful monitoring, discrimination or profiling; and
- cooperate reasonably with Vlok regarding security and compliance matters.
The Client is responsible for determining whether it is legally permitted to enable:
- call recording;
- transcription;
- storage of interaction histories;
- SMS communications;
- collection of allergy or accessibility information; and
- integrations with other systems.
7. Allergy and Special Category Personal Data
7.1 Client responsibility
The Client acknowledges that allergy, medical dietary and certain accessibility information may constitute Special Category Personal Data.
The Client is responsible for:
- establishing an Article 6 lawful basis;
- establishing an applicable Article 9 condition;
- providing required privacy information;
- ensuring that only necessary information is collected;
- ensuring allergen and ingredient information is correct;
- keeping allergen materials up to date;
- determining whether a dietary request can safely be accommodated; and
- ensuring trained Client staff handle escalated enquiries.
7.2 Vlok’s processing
Vlok may process Special Category Personal Data on the Client’s behalf to:
- record a caller’s request;
- communicate the request to the Client;
- manage the relevant booking;
- send Client-approved information;
- escalate an interaction to Client staff;
- investigate a particular complaint or safety incident; or
- comply with a lawful instruction.
7.3 No independent verification
Vlok does not independently inspect, verify or certify the Client’s:
- allergen menus;
- ingredient information;
- food-preparation procedures;
- kitchen controls; or
- dietary representations.
The Client remains responsible for the accuracy of that information and its compliance with food-safety and allergen law.
7.4 Exclusion from general AI training
Vlok will not intentionally use known allergy, health or other Special Category Personal Data to train general Vlok AI models.
Where reasonably practicable, Vlok will use filtering, removal, masking, access restrictions and dataset review to exclude such information from general model-training datasets.
This does not prevent Vlok from processing the information where necessary to:
- complete the relevant Service interaction;
- investigate a specific safety or security issue;
- comply with law; or
- establish, exercise or defend a legal claim.
8. Confidentiality
Vlok will ensure that persons authorised to process Client Personal Data:
- are subject to contractual, statutory or professional confidentiality obligations;
- receive access only where reasonably necessary for their work;
- are informed of their privacy and security responsibilities; and
- process Client Personal Data only in accordance with Vlok’s instructions.
Vlok will maintain appropriate procedures for:
- granting access;
- modifying access;
- reviewing access; and
- removing access when it is no longer required.
Confidentiality obligations will continue after a person’s employment or engagement ends.
9. Security
9.1 Security obligation
Taking into account:
- the state of the art;
- implementation costs;
- the nature, scope, context and purposes of processing; and
- the likelihood and severity of risks to individuals,
Vlok will implement appropriate technical and organisational measures designed to protect Client Personal Data.
9.2 Security objectives
The measures will be designed to protect against:
- accidental or unlawful destruction;
- accidental loss;
- unauthorised alteration;
- unauthorised disclosure;
- unauthorised access;
- misuse; and
- material loss of availability.
9.3 Security measures
The measures maintained by Vlok are described in Annex 2 and may include:
- encryption in transit;
- encryption at rest where appropriate;
- access controls;
- authentication controls;
- least-privilege access;
- logging and monitoring;
- secure development and change-management practices;
- vulnerability and patch management;
- backup and recovery controls;
- incident-response procedures;
- staff confidentiality controls;
- supplier assessment;
- data minimisation;
- pseudonymisation and masking where appropriate; and
- periodic access and security reviews.
9.4 Changes to security measures
Vlok may update its technical and organisational measures as:
- technology develops;
- threats change;
- providers change;
- the Service develops; or
- laws and industry practices evolve.
Vlok will not materially reduce the overall level of protection during the term of the Agreement.
9.5 Client security
The Client is responsible for:
- securing its own systems, devices and networks;
- managing Authorised Users;
- protecting credentials;
- configuring appropriate permissions;
- promptly disabling former users;
- reviewing information exported from the Service; and
- notifying Vlok promptly of suspected compromise.
10. Subprocessors
10.1 General authorisation
The Client gives Vlok general written authorisation to appoint and replace Subprocessors for the purpose of providing, supporting, securing and developing the Service.
10.2 Subprocessor obligations
Before a Subprocessor processes Client Personal Data, Vlok will enter into a written agreement requiring the Subprocessor to provide protections that are no less protective in material respects than those required by this DPA, to the extent applicable to the Subprocessor’s services.
10.3 Responsibility
Vlok remains responsible for the performance of its Subprocessors’ data-processing obligations to the extent required by Applicable Data Protection Law.
10.4 Existing Subprocessors
The Client authorises the Subprocessors identified in Annex 3.
The Client also authorises other infrastructure and service providers used by Vlok where:
- their use is reasonably necessary to provide or support the Service;
- appropriate contractual protection is in place; and
- any applicable international-transfer requirements are satisfied.
10.5 Notice of material changes
Vlok will provide reasonable notice before appointing a new material Subprocessor that will process Client Personal Data.
Notice may be provided through:
- email;
- the Client account;
- Vlok’s website;
- a Subprocessor page;
- release notes; or
- another reasonable electronic method.
10.6 Objections
The Client may object to a new material Subprocessor on reasonable and documented data-protection grounds.
An objection must:
- be submitted within 14 days after notice;
- identify the specific data-protection concern;
- explain why the concern cannot reasonably be addressed by existing safeguards; and
- provide supporting information where available.
The Parties will work in good faith to address a valid objection.
Vlok may:
- provide additional information;
- implement reasonable safeguards;
- change the relevant processing;
- offer an alternative configuration;
- decide not to use the Subprocessor for that Client; or
- permit the Client to terminate the affected Service.
If no reasonable alternative is available, either Party may terminate only the affected Service by written notice. The Client must pay Fees incurred up to the termination date.
An objection may not be used solely to avoid contractual payment obligations or for reasons unrelated to data protection.
11. Data Subject Requests
11.1 Requests received by Vlok
If Vlok receives a Data Subject Request relating primarily to Client Personal Data, Vlok will:
- notify the Client where reasonably practicable;
- refer the Data Subject to the Client; or
- follow the Client’s documented instructions.
Vlok will not independently determine the Client’s response unless required by law.
11.2 Assistance
Taking into account the nature of processing, Vlok will provide reasonable technical and organisational assistance to help the Client respond to requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- portability;
- consent withdrawal; and
- automated decision-making.
11.3 Client responsibility
The Client remains responsible for:
- verifying the requester’s identity;
- determining whether a right applies;
- identifying any exception;
- communicating with the Data Subject;
- meeting applicable deadlines; and
- maintaining records of its response.
11.4 Charges
Vlok may charge reasonable Fees for assistance that is unusually complex, repetitive, technically burdensome or outside the standard functionality of the Service.
Vlok will not charge additional Fees where the assistance is required because of Vlok’s material breach of this DPA.
12. Personal Data Breaches
12.1 Notification
Vlok will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.
Notification does not constitute an admission of fault or liability.
12.2 Contents of notification
To the extent known and available, Vlok’s notification will include:
- the nature of the Personal Data Breach;
- the date or estimated period of the incident;
- the categories of affected Personal Data;
- the categories and approximate number of affected Data Subjects;
- the approximate number of affected records;
- the likely consequences;
- measures taken or proposed to contain and remediate the incident; and
- a contact point for further information.
12.3 Phased information
Where complete information is not immediately available, Vlok may provide information in stages without undue further delay.
12.4 Investigation and remediation
Vlok will take reasonable steps to:
- investigate the incident;
- contain it;
- mitigate foreseeable harm;
- preserve appropriate evidence;
- remediate relevant weaknesses; and
- reduce the likelihood of recurrence.
12.5 Client notification decisions
The Client is responsible for determining whether it must notify:
- the Information Commissioner;
- another regulator;
- affected Data Subjects;
- insurers;
- business partners; or
- other persons.
Vlok will provide reasonable assistance based on the nature of processing and information available to it.
12.6 Communications
Neither Party will publicly identify the other Party in connection with a Personal Data Breach without prior consultation, unless legally required.
13. Compliance assistance
Taking into account the nature of processing and information available to Vlok, Vlok will provide reasonable assistance to the Client concerning:
- security obligations;
- Data Subject Requests;
- Personal Data Breaches;
- data-protection impact assessments;
- prior consultation with regulators;
- regulatory enquiries;
- processing records; and
- assessments of technical and organisational measures.
The Client must provide Vlok with sufficient information about:
- the proposed processing;
- relevant risks;
- Client systems;
- legal requirements specific to the Client; and
- the assistance requested.
Vlok may charge reasonable Fees for substantial assistance that:
- is outside the ordinary Service;
- requires custom technical work;
- requires extensive professional time; or
- results from the Client’s own breach or unusual processing.
Vlok will not charge additional Fees where the assistance is required because of Vlok’s material breach of this DPA.
14. International transfers
14.1 Authorisation
The Client authorises Vlok and its Subprocessors to process Client Personal Data in the United Kingdom and other countries where Vlok or its approved providers operate, subject to this section.
14.2 Lawful transfer mechanisms
Vlok will ensure that a Restricted Transfer is supported by a lawful transfer mechanism where required, which may include:
- an applicable UK adequacy regulation;
- the UK Extension to the EU–US Data Privacy Framework, where applicable;
- the UK IDTA;
- the UK Addendum;
- binding corporate rules;
- an applicable statutory exception; or
- another mechanism permitted under Applicable Data Protection Law.
14.3 Transfer assessments
Where required, Vlok or the relevant data exporter will undertake an appropriate transfer risk assessment or equivalent assessment.
14.4 Supplementary safeguards
Vlok may implement supplementary safeguards where reasonably necessary, including:
- encryption;
- pseudonymisation;
- access restrictions;
- contractual commitments;
- transparency reporting;
- data minimisation; and
- restrictions on onward transfers.
14.5 Provider and location changes
Vlok may change:
- hosting locations;
- telecommunications providers;
- AI providers;
- cloud providers; and
- other Subprocessors,
provided that Vlok maintains a lawful transfer mechanism where required and does not materially reduce the overall level of protection.
14.6 Transfer documentation
Where the Parties must enter into an IDTA, UK Addendum or similar document, they will cooperate reasonably to complete it.
The information in the Agreement and Annexes may be used to complete relevant tables, appendices and annexes.
15. Return and deletion
15.1 Client choice
At the end of the provision of processing services, the Client may instruct Vlok to:
- return or make available relevant active Client Personal Data; or
- delete relevant Client Personal Data.
The Client must submit its instruction before termination or within the export period made available by Vlok.
15.2 Export period
Unless otherwise stated in the Order Form, Vlok may make an export of relevant active Client Personal Data available for up to 30 days after termination.
The Client is responsible for downloading any required export during that period.
15.3 Deletion
Following expiry of the export period, Vlok may delete or place beyond ordinary use the remaining Client Personal Data processed solely on the Client’s behalf.
15.4 Permitted retention
Vlok may retain information where:
- retention is required by law;
- it is required for tax, accounting or regulatory purposes;
- it is necessary for an active dispute, investigation or legal claim;
- it is contained in access-restricted backups;
- immediate deletion is technically impracticable;
- it is required as evidence of fraud or a security incident;
- Vlok processes it separately as an independent Controller; or
- it has been genuinely anonymised.
Where Personal Data is retained under this section, Vlok will:
- continue to protect it;
- restrict processing to the permitted purpose;
- prevent ordinary operational use where appropriate; and
- delete it when the reason for retention ends.
15.5 Backups
Client Personal Data may remain in secure backups until overwritten or deleted in accordance with Vlok’s backup cycle.
Backup data will not ordinarily be restored except for:
- disaster recovery;
- security investigation;
- system integrity;
- testing of recovery processes; or
- legal requirements.
If backup data is restored, applicable deletion instructions will be reapplied where reasonably practicable.
15.6 Anonymised information
This DPA does not require deletion of information that has been genuinely anonymised so that no individual is identified or reasonably identifiable.
16. Audits and compliance information
16.1 Information
Vlok will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.
Vlok may satisfy this obligation by providing:
- relevant policy summaries;
- security documentation;
- completed questionnaires;
- independent reports;
- certifications;
- penetration-test summaries;
- Subprocessor information;
- data-flow information; or
- other reasonable evidence.
16.2 Documentation first
Before requesting an audit, the Client must first review the information and documentation reasonably made available by Vlok.
An audit may proceed where that information does not reasonably address a material compliance concern.
16.3 Audit rights
The Client may audit Vlok’s compliance with this DPA:
- where required by Applicable Data Protection Law;
- where required by a competent regulator;
- following a material Personal Data Breach affecting Client Personal Data;
- where there is credible evidence of material non-compliance; or
- otherwise no more than once in any 12-month period.
16.4 Audit conditions
Unless urgent circumstances or a regulator require otherwise:
- the Client must provide at least 30 days’ written notice;
- the audit must occur during normal business hours;
- the scope must be limited to processing relevant to the Client;
- the audit must not unreasonably disrupt Vlok’s operations;
- the audit must not expose another client’s data or confidential information;
- the auditor must be independent, suitably qualified and bound by confidentiality;
- the auditor must not be a direct competitor of Vlok;
- remote review and documentation must be used before on-site inspection;
- no vulnerability testing, penetration testing or access to production systems may occur without Vlok’s written approval; and
- the Parties must agree reasonable security and access arrangements.
16.5 Costs
The Client will bear its audit costs.
Vlok may charge reasonable costs incurred in supporting an audit where:
- the audit is unusually burdensome;
- the audit exceeds one request in a 12-month period;
- the audit requires custom work; or
- the audit identifies no material breach.
Vlok will not charge those additional costs where the audit establishes a material breach of this DPA by Vlok.
16.6 Audit findings
The Client must:
- treat audit findings as Vlok Confidential Information;
- use findings only for compliance purposes;
- provide Vlok with a copy of the final report;
- allow Vlok a reasonable opportunity to respond; and
- avoid disclosing findings publicly unless legally required.
Vlok will address confirmed material deficiencies within a reasonable period, taking into account their severity and technical complexity.
17. Records and regulatory cooperation
Each Party will maintain records required of it under Applicable Data Protection Law.
Vlok will cooperate reasonably with a competent data-protection authority in relation to processing governed by this DPA.
Where legally permitted, a Party receiving a regulatory request materially affecting the other Party will inform the other Party.
Nothing in this DPA requires a Party to:
- waive legal privilege;
- disclose another client’s confidential information;
- disclose information prohibited by law;
- compromise system security; or
- disclose trade secrets beyond what is legally required.
18. Vlok’s independent AI-development processing
18.1 Separate purpose
The Client acknowledges that Vlok may undertake separately disclosed processing as an independent Controller for eligible AI development, evaluation, safety and improvement purposes.
This separate processing is governed by:
- Vlok’s Privacy Policy;
- Applicable Data Protection Law; and
- Vlok’s own Controller obligations.
It is not undertaken solely on the Client’s instructions under this DPA.
18.2 Eligible information
Subject to applicable law and Vlok’s Privacy Policy, eligible information may include:
- call transcripts;
- interaction records;
- corrections;
- booking-flow information;
- user feedback;
- failure and error examples;
- intent classifications; and
- system-performance information.
18.3 Safeguards
Vlok will use safeguards appropriate to the risks, which may include:
- removing or masking telephone numbers;
- removing names and email addresses;
- removing booking references;
- reducing client-account identifiers;
- filtering sensitive information;
- limiting dataset access;
- separating identifiers from interaction content;
- sampling selected interactions;
- pseudonymising records; and
- anonymising information where reasonably practicable.
18.4 Special Category Personal Data
Known Special Category Personal Data will be excluded from general model-training datasets in accordance with section 7.
18.5 Provider use
Where a third-party AI provider processes eligible information for Vlok:
- Vlok will assess the provider’s role;
- appropriate contracts will be used;
- applicable international-transfer safeguards will be implemented; and
- where reasonably possible and appropriate, provider settings will be configured to prevent the provider from using submitted content to train its general models.
18.6 No identifiable-data sale
Vlok will not sell identifiable Client Personal Data as a standalone personal-data product.
This does not prevent:
- use of approved Subprocessors;
- a corporate transaction;
- lawful Controller processing;
- use of aggregated information; or
- use of genuinely anonymised information.
19. Liability
19.1 General allocation
Each Party is responsible for its own compliance with Applicable Data Protection Law and for losses caused by its breach of this DPA, subject to the limitations below.
19.2 Client responsibility
The Client is responsible for claims, losses and regulatory consequences arising from:
- unlawful Client instructions;
- absence of a lawful basis;
- absence of an applicable Special Category condition;
- inadequate privacy information;
- inaccurate Client Personal Data;
- inaccurate menus, allergen information or ingredient information;
- Client account compromise not caused by Vlok;
- unauthorised Client users;
- the Client’s own systems;
- failure to respond lawfully to a Data Subject Request; or
- processing carried out by the Client outside the Service.
19.3 Vlok responsibility
Vlok is responsible for its breach of obligations imposed directly on it as Processor under Applicable Data Protection Law or under this DPA, subject to the Agreement’s limitations and exclusions.
19.4 Non-excludable liability
Nothing in this DPA limits or excludes liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation; or
- liability that cannot lawfully be limited or excluded.
19.5 Excluded losses
Subject to section 19.4, neither Party will be liable under this DPA for:
- loss of profit;
- loss of revenue;
- loss of anticipated savings;
- loss of business;
- loss of goodwill;
- loss of business opportunity; or
- indirect or consequential loss.
19.6 Liability cap
Subject to section 19.4, Vlok’s total aggregate liability arising out of or in connection with this DPA, whether in contract, tort including negligence, breach of statutory duty, misrepresentation or otherwise, will not exceed the total Fees paid or payable by the Client to Vlok during the 12 months immediately preceding the event giving rise to the first claim.
If the relevant event occurs during the first 12 months of the Agreement, the cap will be the total Fees paid or payable from the beginning of the Agreement to the date of that event.
19.7 Aggregate cap
Unless the Terms expressly state otherwise, liability under this DPA counts toward, and does not create a separate cap in addition to, the total liability cap under the Terms of Service.
19.8 Data Subject and regulatory rights
Nothing in this section affects:
- the rights of Data Subjects under Applicable Data Protection Law;
- the powers of the Information Commissioner or another competent authority; or
- any statutory allocation of liability that cannot be altered by contract.
20. Term and termination
20.1 Term
This DPA begins when the Agreement begins and continues for as long as Vlok processes Client Personal Data on behalf of the Client.
20.2 Termination
Termination or expiry of the Agreement will terminate this DPA, except to the extent that:
- Vlok continues to hold Client Personal Data;
- deletion or return remains outstanding;
- retention is legally permitted or required; or
- a provision is intended to survive.
20.3 Survival
The following will survive termination:
- confidentiality;
- security obligations applicable to retained data;
- return and deletion;
- audit and compliance obligations concerning processing during the term;
- international-transfer protections;
- liability;
- governing law; and
- any provision intended by its nature to survive.
21. Changes to this DPA
Vlok may update this DPA where reasonably necessary to:
- comply with changes in law;
- reflect regulatory guidance;
- address new security requirements;
- reflect changes to the Service;
- update Subprocessor or transfer arrangements; or
- clarify existing obligations.
Vlok will provide reasonable notice of a material change.
Where a material change substantially disadvantages the Client, the Client may terminate the affected Service in accordance with the Terms of Service.
No change will retrospectively authorise unlawful processing.
22. General provisions
22.1 Entire agreement concerning processing
This DPA and the data-protection provisions of the Agreement constitute the Parties’ agreement concerning Vlok’s processing of Client Personal Data.
22.2 No third-party rights
Except where Applicable Data Protection Law or an applicable transfer mechanism provides otherwise, a person who is not a Party has no right to enforce this DPA.
22.3 Severability
If a provision of this DPA is invalid, unlawful or unenforceable, it will be modified to the minimum extent necessary to make it enforceable.
If modification is not possible, it will be removed without affecting the remaining provisions.
22.4 Waiver
A delay or failure to exercise a right does not waive that right.
22.5 Assignment
This DPA may be assigned or transferred together with the Agreement in accordance with the Terms of Service.
22.6 Electronic acceptance
This DPA may be accepted:
- by signature;
- electronically;
- by accepting the Terms of Service;
- by entering into an Order Form that incorporates it; or
- by continuing to use the Service after receiving it, where legally effective.
23. Governing law and jurisdiction
This DPA and any non-contractual obligations arising out of or in connection with it are governed by the law of England and Wales.
The courts of England and Wales have exclusive jurisdiction to settle disputes arising out of or in connection with this DPA.
Annex 1: Details of Processing
1. Subject matter
Provision of Vlok’s AI-powered telephone receptionist, call-handling, restaurant booking, SMS, escalation, reporting, integration, support and associated services.
2. Duration
Processing will continue:
- for the duration of the Agreement;
- during any agreed post-termination export period;
- during deletion from active systems and backups; and
- for any longer period permitted or required under the Agreement or applicable law.
3. Nature of processing
Processing may include:
- collection;
- receipt;
- recording;
- organisation;
- structuring;
- transcription;
- speech recognition;
- classification;
- consultation;
- retrieval;
- use;
- automated response generation;
- amendment;
- booking creation;
- booking cancellation;
- communication;
- transmission;
- disclosure to authorised recipients;
- storage;
- analysis;
- support access;
- restriction;
- anonymisation; and
- deletion.
4. Purposes of processing
Vlok may process Client Personal Data on behalf of the Client to:
- answer restaurant telephone calls;
- understand caller requests;
- provide restaurant information;
- create, confirm, amend and cancel bookings;
- apply Client-supplied availability and booking rules;
- send booking confirmations;
- send Client-approved menus and allergen information;
- record dietary, accessibility and other guest requests;
- communicate information to Client staff;
- transfer or escalate calls;
- provide call records and transcripts;
- provide reporting;
- operate integrations;
- provide technical and customer support;
- investigate errors;
- protect the Service;
- prevent fraud and abuse;
- maintain continuity and recovery;
- comply with lawful Client instructions; and
- delete or return information.
5. Categories of Data Subjects
Data Subjects may include:
- callers;
- prospective restaurant guests;
- confirmed restaurant guests;
- guests included in a booking;
- persons making a booking for others;
- Client owners;
- Client directors;
- Client employees;
- Client contractors;
- Client authorised users;
- suppliers contacting the Client;
- delivery personnel;
- business contacts;
- complainants; and
- other persons contacting the Client through the Service.
6. Categories of Personal Data
Personal Data may include:
- names;
- telephone numbers;
- email addresses;
- restaurant location;
- booking date and time;
- party size;
- booking references;
- booking history;
- cancellation information;
- attendance and no-show information;
- seating preferences;
- occasion details;
- special requests;
- complaint information;
- enquiry content;
- SMS content;
- call transcripts;
- call audio where enabled;
- communication metadata;
- call timestamps;
- call duration;
- call-routing information;
- escalation information;
- staff contact details;
- support records;
- account identifiers;
- user permissions;
- device and browser information;
- IP addresses;
- access logs;
- integration identifiers; and
- other information voluntarily provided during an interaction.
7. Special Category Personal Data
Special Category Personal Data may include:
- allergy information;
- health-related dietary requirements;
- medical accessibility information; and
- other health information voluntarily disclosed during an interaction.
The Client must not instruct Vlok to collect Special Category Personal Data unless reasonably necessary and lawfully permitted.
8. Frequency
Processing may occur continuously or whenever:
- a caller contacts the Client;
- a message is sent;
- a booking is managed;
- an Authorised User accesses the Service;
- an integration transfers information;
- support is requested; or
- system monitoring and maintenance occur.
9. Client rights
The Client may, subject to the Agreement:
- configure the Service;
- provide processing instructions;
- access available Client Personal Data;
- request correction;
- request export;
- request deletion;
- manage Authorised Users;
- object to a new material Subprocessor on reasonable grounds;
- request compliance information; and
- exercise audit rights.
10. Client obligations
The Client’s obligations include those described in sections 6 and 7 of this DPA.
Annex 2: Technical and Organisational Measures
Vlok will maintain technical and organisational measures appropriate to the risks of processing.
The specific implementation of these measures may evolve as the Service and available technology develop.
1. Governance and accountability
Measures may include:
- assigned responsibility for privacy and security;
- documented internal policies;
- risk assessment;
- supplier review;
- incident-response planning;
- access-management procedures;
- processing records where required;
- staff confidentiality obligations; and
- review of material processing changes.
2. Access control
Measures may include:
- unique user accounts;
- role-based permissions;
- least-privilege access;
- authentication controls;
- multi-factor authentication where appropriate;
- approval processes for privileged access;
- periodic review of access;
- prompt revocation of access;
- restrictions on production access; and
- logging of material administrative actions.
3. Encryption and transmission security
Measures may include:
- encryption of data in transit;
- encrypted connections between material systems;
- encryption at rest where appropriate;
- secure key-management practices;
- restrictions on unencrypted exports; and
- secure transfer methods.
4. Infrastructure and hosting security
Measures may include:
- reputable hosting providers;
- logical separation between clients;
- network controls;
- environment separation;
- firewall and traffic controls;
- infrastructure monitoring;
- controlled administrative access; and
- provider security certifications or assessments where available.
5. Application and development security
Measures may include:
- source-code access controls;
- code review;
- change-management controls;
- separation of development and production environments;
- dependency management;
- secret-management procedures;
- testing before material releases;
- remediation of identified vulnerabilities; and
- logging of material deployment events.
6. Logging and monitoring
Measures may include:
- authentication logs;
- administrative-action logs;
- application logs;
- call-processing logs;
- security monitoring;
- automated alerts;
- investigation procedures;
- access restrictions for logs; and
- defined log-retention practices.
7. Vulnerability and patch management
Measures may include:
- monitoring for relevant vulnerabilities;
- operating-system and software patching;
- dependency updates;
- prioritisation based on risk;
- remediation tracking;
- penetration testing or security review where appropriate; and
- coordinated response to material provider vulnerabilities.
8. Availability and resilience
Measures may include:
- backups;
- recovery procedures;
- redundancy where appropriate;
- monitoring of availability;
- incident escalation;
- recovery testing;
- capacity monitoring; and
- continuity arrangements for material providers.
9. Incident management
Measures may include:
- incident-reporting channels;
- escalation procedures;
- incident classification;
- containment procedures;
- evidence preservation;
- investigation;
- breach assessment;
- notification procedures;
- remediation tracking; and
- post-incident review.
10. Data minimisation
Measures may include:
- limiting configured data fields;
- instructing clients not to collect unnecessary data;
- limiting access to interaction content;
- reducing identifiers in development datasets;
- masking information where appropriate;
- excluding known Special Category Personal Data from general training;
- retention controls; and
- deletion or anonymisation processes.
11. Personnel security
Measures may include:
- confidentiality agreements;
- security and privacy guidance;
- role-appropriate training;
- background screening where lawful and appropriate;
- restricted access according to role;
- disciplinary processes for misuse; and
- termination and offboarding procedures.
12. Supplier security
Measures may include:
- assessment of material suppliers;
- data-processing contracts;
- security obligations;
- confidentiality obligations;
- international-transfer controls;
- review of provider documentation;
- access limitations; and
- incident-notification requirements.
13. Physical security
Vlok relies substantially on cloud and telecommunications providers for physical infrastructure.
Measures may include:
- use of providers with appropriate physical controls;
- controlled access to Vlok work locations;
- device security;
- screen-lock requirements;
- secure disposal; and
- restrictions on local storage.
14. Data return and deletion
Measures may include:
- account closure procedures;
- export tools or managed exports;
- deletion from active systems;
- retention restrictions;
- backup expiry;
- deletion tracking; and
- anonymisation where appropriate.
15. Review and improvement
Vlok may periodically review and update security measures based on:
- identified risks;
- incidents;
- vulnerability findings;
- technical developments;
- provider changes;
- regulatory guidance; and
- changes to the Service.
Annex 3: Approved Subprocessors
The Client authorises Vlok to use the following material provider categories and named providers.
The exact contracting entity, data location and transfer mechanism may depend on Vlok’s account, product configuration and provider terms. Vlok should verify and maintain those details internally and in any published Subprocessor register.
1. OpenAI
Provider: OpenAI
Purpose:
- AI language processing;
- understanding caller requests;
- response generation;
- request classification;
- workflow support;
- service evaluation; and
- eligible AI-development functions.
Potential data:
- selected interaction content;
- call transcripts;
- booking context;
- restaurant information;
- technical prompts; and
- related metadata.
Potential locations:
- United Kingdom;
- European Economic Area;
- United States; or
- other provider locations permitted under applicable arrangements.
Transfer safeguards:
- adequacy where applicable;
- UK–US data bridge where applicable;
- UK IDTA;
- UK Addendum; or
- another lawful mechanism.
Important configuration: Where reasonably available and appropriate, Vlok will use business or API configurations under which submitted content is not used by the provider to train its general models.
2. Twilio
Provider: Twilio
Purpose:
- telephone-number services;
- call connectivity;
- call routing;
- call metadata;
- SMS transmission;
- delivery status; and
- associated telecommunications functions.
Potential data:
- telephone numbers;
- call metadata;
- call-routing details;
- SMS content;
- delivery information;
- interaction data; and
- technical identifiers.
Potential locations:
- United Kingdom;
- European Economic Area;
- United States; or
- other provider network locations.
Transfer safeguards:
- adequacy where applicable;
- UK–US data bridge where applicable;
- UK IDTA;
- UK Addendum; or
- another lawful mechanism.
3. ElevenLabs
Provider: ElevenLabs
Purpose:
- text-to-speech;
- voice generation;
- speech processing;
- audio-stream generation; and
- associated voice functions.
Potential data:
- response text;
- interaction content;
- voice or audio data where required;
- language information; and
- technical metadata.
Potential locations:
- United Kingdom;
- European Economic Area;
- United States; or
- other provider locations permitted under applicable arrangements.
Transfer safeguards:
- adequacy where applicable;
- UK–US data bridge where applicable;
- UK IDTA;
- UK Addendum; or
- another lawful mechanism.
4. Cloud hosting and database providers
Purpose:
- application hosting;
- databases;
- object storage;
- backups;
- authentication;
- networking; and
- system infrastructure.
Potential data:
All Client Personal Data required to host or operate the Service.
Provider details: To be maintained by Vlok based on the infrastructure in use.
5. Monitoring, logging and security providers
Purpose:
- performance monitoring;
- error tracking;
- system logs;
- security alerts;
- fraud prevention; and
- incident investigation.
Potential data:
- technical logs;
- IP addresses;
- user identifiers;
- interaction identifiers;
- error details; and
- limited interaction content where included in an error.
6. Customer-support and communications providers
Purpose:
- support tickets;
- service email;
- client communications;
- notifications; and
- complaint management.
Potential data:
- client contact details;
- support content;
- account information;
- relevant interaction information; and
- attachments supplied for support.
7. Payment providers
Purpose:
- payment mandates;
- Direct Debit administration;
- payment collection;
- invoicing support;
- fraud prevention; and
- payment reconciliation.
Potential data:
- client business details;
- billing contacts;
- mandate status;
- payment references;
- transaction amounts; and
- payment status.
Payment providers may act as independent Controllers for some regulated payment activities.
8. Professional advisers
Purpose:
- legal advice;
- accounting;
- audit;
- insurance;
- regulatory compliance; and
- dispute management.
Professional advisers may act as independent Controllers and are generally subject to legal, professional or contractual confidentiality duties.