Navigation
Article 28 UK GDPR Compliance

Data Processing Addendum (DPA)

Version 1.0 · Effective Date: August 29, 2026 · Andrii Moskalets trading as amoskalets.com

1. Purpose, Roles & Binding Incorporation

This Data Processing Addendum ("DPA", Version 1.0) supplements and forms an integral, legally binding part of the Terms of Service between Andrii Moskalets trading as amoskalets.com ("Sole Trader", "Processor", "we", "us"), located in Belfast, Northern Ireland, United Kingdom, and the client business entity ("Controller", "Client", or "you").

Binding Execution: By subscribing to our services, entering into an order, or completing client onboarding, Controller formally executes this DPA pursuant to Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

Role Separation: Where Controller utilizes amoskalets.com autonomous AI agents to process personal data of third-party callers, leads, or end-users ("Client Personal Data"), amoskalets.com acts exclusively as a Data Processor on behalf of the Controller. amoskalets.com acts as an independent Data Controller solely for direct account registration, authentication, direct billing, and business relationship records, governed separately by our Privacy Policy.

2. Scope, Nature and Details of Processing

Subject Matter & Purpose: Provision of autonomous AI business agents, real-time voice reception (+44 UK line), conversational lead intake, calendar and booking scheduling, workflow automation, and CRM integrations.

Duration: For the duration of Controller's active subscription agreement, plus the transition period required for data return or cryptographic purge.

Categories of Data Subjects: Controller's callers, prospective clients, customers, and individuals interacting with Controller's deployed AI agents.

Categories of Personal Data: Contact identifiers (names, telephone numbers, email addresses), call audio streams, transcripts, inquiry contents, booking timestamps, and operational metadata.

Special Category Data Restriction: Controller shall not instruct, submit, or transmit special category personal data (as defined in Article 9 UK GDPR) or criminal offence data to the services unless separately agreed in writing with explicit lawful safeguards in place.

3. Documented Instructions (Article 28(3)(a))

Processor shall process Client Personal Data solely on documented instructions from Controller (including prompt definitions, agent instructions, trigger parameters, and integration settings configured within the Client Portal), unless required to do so by applicable UK law.

If Processor is required by applicable law to process data outside Controller's instructions, Processor shall inform Controller of that legal requirement prior to processing, unless prohibited on important public interest grounds.

4. Confidentiality (Article 28(3)(b))

Processor ensures that all personnel and contractors authorized to process Client Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Technical and Organisational Measures (TOMs) (Article 28(3)(c) & Article 32)

Processor implements appropriate technical and organisational measures, documented on request, designed to ensure a level of security appropriate to the risk of processing, including:

• Database tenant isolation via PostgreSQL Row-Level Security (RLS) policies;

• Encrypted transmission of data across public networks via modern TLS standards;

• Principle of least privilege enforced across application runtime roles (app_runtime);

• Guarded administrative data deletion and retention procedures without unattended cron jobs.

6. Subprocessors (Article 28(3)(d) & Article 28(2))

General Authorization: Controller grants general written authorization to Processor to engage the third-party infrastructure and service providers listed on our official versioned Subprocessors List at amoskalets.com/subprocessors (including Oracle Cloud Infrastructure UK, self-hosted PostgreSQL/n8n on OCI, Google Cloud AI EMEA, Vapi, Zadarma, Square, and Resend).

Flow-Down Obligations: Processor shall impose data protection terms on each subprocessor providing substantially the same level of protection for Client Personal Data as set out in this DPA.

Notification of Changes: Processor maintains a changelog on the Subprocessors List and shall notify Controller's designated administrative contact email at least fourteen (14) days prior to authorizing any new subprocessor.

Objection Mechanism: Controller may submit a written objection on reasonable data protection grounds to andriimoskaletsgb@gmail.com within fourteen (14) days of receiving notice. If the parties cannot resolve the objection, Controller may terminate the affected service without financial penalty.

7. International Data Transfers (Chapter V UK GDPR)

Where processing involves transfers of Client Personal Data outside the United Kingdom, Processor ensures such transfers comply with Chapter V of the UK GDPR through valid transfer mechanisms, such as UK Adequacy Regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to European Commission Standard Contractual Clauses (SCCs).

8. Assistance with Data Subject Rights (Article 28(3)(e))

Taking into account the nature of the processing, Processor assists Controller by appropriate technical and organisational measures, insofar as possible, to fulfil Controller's obligation to respond to requests exercising data subject rights under Chapter III of the UK GDPR (access, rectification, erasure, restriction, objection, and data portability).

9. Incident Notification & DPIA Assistance (Article 28(3)(f))

Breach Notification: Processor shall notify Controller without undue delay after becoming aware of a confirmed personal data breach affecting Client Personal Data, providing sufficient information to assist Controller in meeting statutory ICO reporting deadlines.

DPIA Assistance: Processor shall provide reasonable assistance to Controller with data protection impact assessments (DPIAs) and prior consultations with the Information Commissioner's Office (ICO) where required.

10. Return and Deletion of Data (Article 28(3)(g))

Upon termination of the service agreement, Processor shall, at Controller's choice, delete or return all Client Personal Data via guarded administrative data lifecycle procedures, and delete existing copies, unless statutory UK law (including mandatory 6-year HMRC financial accounting retention rules) requires continued retention of transaction ledgers.

11. Audit and Information Rights (Article 28(3)(h))

Processor shall make available to Controller all information necessary to demonstrate compliance with Article 28 UK GDPR obligations, and allow for and contribute to reasonable audits or inspections conducted by Controller or its designated auditor, subject to reasonable advance notice, operational non-disruption, and confidentiality.

12. Governing Law and Jurisdiction

This DPA is governed by the laws of Northern Ireland and the United Kingdom. Both parties submit to the exclusive jurisdiction of the courts of Belfast, Northern Ireland.

Contractual Inquiries & Privacy Contact
For subprocessor notices, audit requests, or DPA inquiries: andriimoskaletsgb@gmail.com