Vlok Data Processing Agreement

Last updated: 1 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Vlok Ltd and the Client governing the Client’s use of the Vlok Service.

This DPA applies where Vlok processes Personal Data on behalf of the Client in connection with the Service.

1. Parties and incorporation

1.1 Parties

This DPA is entered into between:

Vlok Ltd, a company registered in England and Wales with its registered office at The Oval, 57 New Walk, Leicester, England, LE1 7EA (“Vlok” or “Processor”); and

the restaurant, hospitality business or other organisation that has entered into an Agreement with Vlok (“Client” or “Controller”).

Each is a “Party” and together they are the “Parties”.

1.2 Incorporation

This DPA forms part of and is incorporated into:

1.3 Priority

If there is a conflict between this DPA and another part of the Agreement concerning the processing of Client Personal Data, this DPA will take priority.

If there is a conflict between this DPA and a binding international data-transfer agreement entered into by the Parties, the international data-transfer agreement will take priority in relation to the relevant Restricted Transfer.

1.4 Relationship with Privacy Policy

Vlok’s Privacy Policy explains how Vlok processes Personal Data, including activities for which Vlok acts as an independent Controller.

The Privacy Policy does not replace this DPA.

2. Definitions

In this DPA:

Agreement means the Vlok Terms of Service, the applicable Order Form, this DPA, the Fees and Billing Policy, any Telecom and Number Authorisation and any other document expressly incorporated into the contractual relationship.

Applicable Data Protection Law means all data-protection and privacy laws applicable to processing under this DPA, including:

Client Personal Data means Personal Data processed by Vlok on behalf of the Client in connection with the Service.

Controller, Data Subject, Personal Data, Personal Data Breach, processing, Processor and Special Category Personal Data have the meanings given under Applicable Data Protection Law.

Data Subject Request means a request by a Data Subject to exercise a right under Applicable Data Protection Law.

Restricted Transfer means a transfer of Personal Data that requires an adequacy decision, appropriate safeguard, exception or other lawful transfer mechanism under Applicable Data Protection Law.

Service means Vlok’s AI-powered call-handling, restaurant booking, messaging, reporting, support and related services.

Subprocessor means another Processor appointed by Vlok to process Client Personal Data on behalf of the Client.

UK Addendum means the international data-transfer addendum to the European Commission’s standard contractual clauses approved for use under UK data-protection law.

UK GDPR means the retained UK version of the General Data Protection Regulation, as amended or replaced.

UK IDTA means the International Data Transfer Agreement approved for use under UK data-protection law.

3. Roles of the Parties

3.1 Client as Controller

The Client acts as Controller where it determines the purposes and essential means of processing caller, guest, reservation and related information through the Service.

3.2 Vlok as Processor

Vlok acts as Processor where it processes Client Personal Data on behalf of the Client to provide the Service under the Client’s documented instructions.

3.3 Vlok’s independent-controller activities

Vlok may separately act as an independent Controller for processing undertaken for Vlok’s own purposes, including:

Processing carried out by Vlok as an independent Controller is not carried out on behalf of the Client and is not governed by the Client’s instructions under this DPA.

Vlok must comply with Applicable Data Protection Law for such processing.

3.4 Legal classification

Nothing in the Agreement overrides a Party’s legal classification where its actual processing activities determine that it acts as a Controller, joint Controller or Processor.

4. Details of processing

The details of processing are set out in Annex 1.

The Parties agree that Annex 1 describes:

The Client may provide additional documented instructions through:

5. Documented instructions

5.1 Processing on instructions

Vlok will process Client Personal Data only:

5.2 Instructions contained in the Agreement

The Client instructs Vlok to process Client Personal Data as necessary to:

5.3 Instructions required by law

Where Vlok is required by law to process Client Personal Data other than on the Client’s instructions, Vlok will inform the Client before processing unless the law prohibits that notification.

5.4 Unlawful instructions

Vlok will inform the Client if Vlok reasonably believes that an instruction infringes Applicable Data Protection Law.

Vlok may suspend performance of the affected instruction until the Parties clarify, amend or withdraw it.

Vlok is not required to undertake an instruction that:

Where an instruction is outside the agreed Service, Vlok may agree to perform it subject to additional Fees and terms.

6. Client obligations

The Client must:

The Client is responsible for determining whether it is legally permitted to enable:

7. Allergy and Special Category Personal Data

7.1 Client responsibility

The Client acknowledges that allergy, medical dietary and certain accessibility information may constitute Special Category Personal Data.

The Client is responsible for:

7.2 Vlok’s processing

Vlok may process Special Category Personal Data on the Client’s behalf to:

7.3 No independent verification

Vlok does not independently inspect, verify or certify the Client’s:

The Client remains responsible for the accuracy of that information and its compliance with food-safety and allergen law.

7.4 Exclusion from general AI training

Vlok will not intentionally use known allergy, health or other Special Category Personal Data to train general Vlok AI models.

Where reasonably practicable, Vlok will use filtering, removal, masking, access restrictions and dataset review to exclude such information from general model-training datasets.

This does not prevent Vlok from processing the information where necessary to:

8. Confidentiality

Vlok will ensure that persons authorised to process Client Personal Data:

Vlok will maintain appropriate procedures for:

Confidentiality obligations will continue after a person’s employment or engagement ends.

9. Security

9.1 Security obligation

Taking into account:

Vlok will implement appropriate technical and organisational measures designed to protect Client Personal Data.

9.2 Security objectives

The measures will be designed to protect against:

9.3 Security measures

The measures maintained by Vlok are described in Annex 2 and may include:

9.4 Changes to security measures

Vlok may update its technical and organisational measures as:

Vlok will not materially reduce the overall level of protection during the term of the Agreement.

9.5 Client security

The Client is responsible for:

10. Subprocessors

10.1 General authorisation

The Client gives Vlok general written authorisation to appoint and replace Subprocessors for the purpose of providing, supporting, securing and developing the Service.

10.2 Subprocessor obligations

Before a Subprocessor processes Client Personal Data, Vlok will enter into a written agreement requiring the Subprocessor to provide protections that are no less protective in material respects than those required by this DPA, to the extent applicable to the Subprocessor’s services.

10.3 Responsibility

Vlok remains responsible for the performance of its Subprocessors’ data-processing obligations to the extent required by Applicable Data Protection Law.

10.4 Existing Subprocessors

The Client authorises the Subprocessors identified in Annex 3.

The Client also authorises other infrastructure and service providers used by Vlok where:

10.5 Notice of material changes

Vlok will provide reasonable notice before appointing a new material Subprocessor that will process Client Personal Data.

Notice may be provided through:

10.6 Objections

The Client may object to a new material Subprocessor on reasonable and documented data-protection grounds.

An objection must:

The Parties will work in good faith to address a valid objection.

Vlok may:

If no reasonable alternative is available, either Party may terminate only the affected Service by written notice. The Client must pay Fees incurred up to the termination date.

An objection may not be used solely to avoid contractual payment obligations or for reasons unrelated to data protection.

11. Data Subject Requests

11.1 Requests received by Vlok

If Vlok receives a Data Subject Request relating primarily to Client Personal Data, Vlok will:

Vlok will not independently determine the Client’s response unless required by law.

11.2 Assistance

Taking into account the nature of processing, Vlok will provide reasonable technical and organisational assistance to help the Client respond to requests concerning:

11.3 Client responsibility

The Client remains responsible for:

11.4 Charges

Vlok may charge reasonable Fees for assistance that is unusually complex, repetitive, technically burdensome or outside the standard functionality of the Service.

Vlok will not charge additional Fees where the assistance is required because of Vlok’s material breach of this DPA.

12. Personal Data Breaches

12.1 Notification

Vlok will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.

Notification does not constitute an admission of fault or liability.

12.2 Contents of notification

To the extent known and available, Vlok’s notification will include:

12.3 Phased information

Where complete information is not immediately available, Vlok may provide information in stages without undue further delay.

12.4 Investigation and remediation

Vlok will take reasonable steps to:

12.5 Client notification decisions

The Client is responsible for determining whether it must notify:

Vlok will provide reasonable assistance based on the nature of processing and information available to it.

12.6 Communications

Neither Party will publicly identify the other Party in connection with a Personal Data Breach without prior consultation, unless legally required.

13. Compliance assistance

Taking into account the nature of processing and information available to Vlok, Vlok will provide reasonable assistance to the Client concerning:

The Client must provide Vlok with sufficient information about:

Vlok may charge reasonable Fees for substantial assistance that:

Vlok will not charge additional Fees where the assistance is required because of Vlok’s material breach of this DPA.

14. International transfers

14.1 Authorisation

The Client authorises Vlok and its Subprocessors to process Client Personal Data in the United Kingdom and other countries where Vlok or its approved providers operate, subject to this section.

14.2 Lawful transfer mechanisms

Vlok will ensure that a Restricted Transfer is supported by a lawful transfer mechanism where required, which may include:

14.3 Transfer assessments

Where required, Vlok or the relevant data exporter will undertake an appropriate transfer risk assessment or equivalent assessment.

14.4 Supplementary safeguards

Vlok may implement supplementary safeguards where reasonably necessary, including:

14.5 Provider and location changes

Vlok may change:

provided that Vlok maintains a lawful transfer mechanism where required and does not materially reduce the overall level of protection.

14.6 Transfer documentation

Where the Parties must enter into an IDTA, UK Addendum or similar document, they will cooperate reasonably to complete it.

The information in the Agreement and Annexes may be used to complete relevant tables, appendices and annexes.

15. Return and deletion

15.1 Client choice

At the end of the provision of processing services, the Client may instruct Vlok to:

The Client must submit its instruction before termination or within the export period made available by Vlok.

15.2 Export period

Unless otherwise stated in the Order Form, Vlok may make an export of relevant active Client Personal Data available for up to 30 days after termination.

The Client is responsible for downloading any required export during that period.

15.3 Deletion

Following expiry of the export period, Vlok may delete or place beyond ordinary use the remaining Client Personal Data processed solely on the Client’s behalf.

15.4 Permitted retention

Vlok may retain information where:

Where Personal Data is retained under this section, Vlok will:

15.5 Backups

Client Personal Data may remain in secure backups until overwritten or deleted in accordance with Vlok’s backup cycle.

Backup data will not ordinarily be restored except for:

If backup data is restored, applicable deletion instructions will be reapplied where reasonably practicable.

15.6 Anonymised information

This DPA does not require deletion of information that has been genuinely anonymised so that no individual is identified or reasonably identifiable.

16. Audits and compliance information

16.1 Information

Vlok will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Vlok may satisfy this obligation by providing:

16.2 Documentation first

Before requesting an audit, the Client must first review the information and documentation reasonably made available by Vlok.

An audit may proceed where that information does not reasonably address a material compliance concern.

16.3 Audit rights

The Client may audit Vlok’s compliance with this DPA:

16.4 Audit conditions

Unless urgent circumstances or a regulator require otherwise:

16.5 Costs

The Client will bear its audit costs.

Vlok may charge reasonable costs incurred in supporting an audit where:

Vlok will not charge those additional costs where the audit establishes a material breach of this DPA by Vlok.

16.6 Audit findings

The Client must:

Vlok will address confirmed material deficiencies within a reasonable period, taking into account their severity and technical complexity.

17. Records and regulatory cooperation

Each Party will maintain records required of it under Applicable Data Protection Law.

Vlok will cooperate reasonably with a competent data-protection authority in relation to processing governed by this DPA.

Where legally permitted, a Party receiving a regulatory request materially affecting the other Party will inform the other Party.

Nothing in this DPA requires a Party to:

18. Vlok’s independent AI-development processing

18.1 Separate purpose

The Client acknowledges that Vlok may undertake separately disclosed processing as an independent Controller for eligible AI development, evaluation, safety and improvement purposes.

This separate processing is governed by:

It is not undertaken solely on the Client’s instructions under this DPA.

18.2 Eligible information

Subject to applicable law and Vlok’s Privacy Policy, eligible information may include:

18.3 Safeguards

Vlok will use safeguards appropriate to the risks, which may include:

18.4 Special Category Personal Data

Known Special Category Personal Data will be excluded from general model-training datasets in accordance with section 7.

18.5 Provider use

Where a third-party AI provider processes eligible information for Vlok:

18.6 No identifiable-data sale

Vlok will not sell identifiable Client Personal Data as a standalone personal-data product.

This does not prevent:

19. Liability

19.1 General allocation

Each Party is responsible for its own compliance with Applicable Data Protection Law and for losses caused by its breach of this DPA, subject to the limitations below.

19.2 Client responsibility

The Client is responsible for claims, losses and regulatory consequences arising from:

19.3 Vlok responsibility

Vlok is responsible for its breach of obligations imposed directly on it as Processor under Applicable Data Protection Law or under this DPA, subject to the Agreement’s limitations and exclusions.

19.4 Non-excludable liability

Nothing in this DPA limits or excludes liability for:

19.5 Excluded losses

Subject to section 19.4, neither Party will be liable under this DPA for:

19.6 Liability cap

Subject to section 19.4, Vlok’s total aggregate liability arising out of or in connection with this DPA, whether in contract, tort including negligence, breach of statutory duty, misrepresentation or otherwise, will not exceed the total Fees paid or payable by the Client to Vlok during the 12 months immediately preceding the event giving rise to the first claim.

If the relevant event occurs during the first 12 months of the Agreement, the cap will be the total Fees paid or payable from the beginning of the Agreement to the date of that event.

19.7 Aggregate cap

Unless the Terms expressly state otherwise, liability under this DPA counts toward, and does not create a separate cap in addition to, the total liability cap under the Terms of Service.

19.8 Data Subject and regulatory rights

Nothing in this section affects:

20. Term and termination

20.1 Term

This DPA begins when the Agreement begins and continues for as long as Vlok processes Client Personal Data on behalf of the Client.

20.2 Termination

Termination or expiry of the Agreement will terminate this DPA, except to the extent that:

20.3 Survival

The following will survive termination:

21. Changes to this DPA

Vlok may update this DPA where reasonably necessary to:

Vlok will provide reasonable notice of a material change.

Where a material change substantially disadvantages the Client, the Client may terminate the affected Service in accordance with the Terms of Service.

No change will retrospectively authorise unlawful processing.

22. General provisions

22.1 Entire agreement concerning processing

This DPA and the data-protection provisions of the Agreement constitute the Parties’ agreement concerning Vlok’s processing of Client Personal Data.

22.2 No third-party rights

Except where Applicable Data Protection Law or an applicable transfer mechanism provides otherwise, a person who is not a Party has no right to enforce this DPA.

22.3 Severability

If a provision of this DPA is invalid, unlawful or unenforceable, it will be modified to the minimum extent necessary to make it enforceable.

If modification is not possible, it will be removed without affecting the remaining provisions.

22.4 Waiver

A delay or failure to exercise a right does not waive that right.

22.5 Assignment

This DPA may be assigned or transferred together with the Agreement in accordance with the Terms of Service.

22.6 Electronic acceptance

This DPA may be accepted:

23. Governing law and jurisdiction

This DPA and any non-contractual obligations arising out of or in connection with it are governed by the law of England and Wales.

The courts of England and Wales have exclusive jurisdiction to settle disputes arising out of or in connection with this DPA.

Annex 1: Details of Processing

1. Subject matter

Provision of Vlok’s AI-powered telephone receptionist, call-handling, restaurant booking, SMS, escalation, reporting, integration, support and associated services.

2. Duration

Processing will continue:

3. Nature of processing

Processing may include:

4. Purposes of processing

Vlok may process Client Personal Data on behalf of the Client to:

5. Categories of Data Subjects

Data Subjects may include:

6. Categories of Personal Data

Personal Data may include:

7. Special Category Personal Data

Special Category Personal Data may include:

The Client must not instruct Vlok to collect Special Category Personal Data unless reasonably necessary and lawfully permitted.

8. Frequency

Processing may occur continuously or whenever:

9. Client rights

The Client may, subject to the Agreement:

10. Client obligations

The Client’s obligations include those described in sections 6 and 7 of this DPA.

Annex 2: Technical and Organisational Measures

Vlok will maintain technical and organisational measures appropriate to the risks of processing.

The specific implementation of these measures may evolve as the Service and available technology develop.

1. Governance and accountability

Measures may include:

2. Access control

Measures may include:

3. Encryption and transmission security

Measures may include:

4. Infrastructure and hosting security

Measures may include:

5. Application and development security

Measures may include:

6. Logging and monitoring

Measures may include:

7. Vulnerability and patch management

Measures may include:

8. Availability and resilience

Measures may include:

9. Incident management

Measures may include:

10. Data minimisation

Measures may include:

11. Personnel security

Measures may include:

12. Supplier security

Measures may include:

13. Physical security

Vlok relies substantially on cloud and telecommunications providers for physical infrastructure.

Measures may include:

14. Data return and deletion

Measures may include:

15. Review and improvement

Vlok may periodically review and update security measures based on:

Annex 3: Approved Subprocessors

The Client authorises Vlok to use the following material provider categories and named providers.

The exact contracting entity, data location and transfer mechanism may depend on Vlok’s account, product configuration and provider terms. Vlok should verify and maintain those details internally and in any published Subprocessor register.

1. OpenAI

Provider: OpenAI
Purpose:

Potential data:

Potential locations:

Transfer safeguards:

Important configuration: Where reasonably available and appropriate, Vlok will use business or API configurations under which submitted content is not used by the provider to train its general models.

2. Twilio

Provider: Twilio
Purpose:

Potential data:

Potential locations:

Transfer safeguards:

3. ElevenLabs

Provider: ElevenLabs
Purpose:

Potential data:

Potential locations:

Transfer safeguards:

4. Cloud hosting and database providers

Purpose:

Potential data:

All Client Personal Data required to host or operate the Service.

Provider details: To be maintained by Vlok based on the infrastructure in use.

5. Monitoring, logging and security providers

Purpose:

Potential data:

6. Customer-support and communications providers

Purpose:

Potential data:

7. Payment providers

Purpose:

Potential data:

Payment providers may act as independent Controllers for some regulated payment activities.

8. Professional advisers

Purpose:

Professional advisers may act as independent Controllers and are generally subject to legal, professional or contractual confidentiality duties.