Last updated: 1 March 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Remtel ("Processor", "Remtel", "we") and governs the processing of personal data in connection with the Service.
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Sub-processor" have the meanings given in the UK GDPR and EU GDPR (General Data Protection Regulation).
"Service Data" refers to the personal data processed by REM on behalf of the Controller in the course of providing the Service, limited to account information and usage metadata.
REM processes personal data solely for the purpose of providing the Service as described in the Terms of Service. The categories of personal data processed include:
The data subjects are users of the Service (account holders and API consumers).
REM shall:
REM currently uses the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | United States |
| Cloud Infrastructure Provider | Hosting, database, compute | EU / UK |
| Anthropic, PBC | AI extraction pipeline (no personal data) | United States |
We will notify the Controller of any intended changes to Sub-processors at least 30 days in advance, providing an opportunity to object.
REM implements the following technical and organisational measures:
REM will assist the Controller in fulfilling data subject requests including access, rectification, erasure, data portability, and restriction of processing. Requests will be actioned within 30 days.
Where personal data is transferred outside the UK or EEA, REM ensures that appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as approved by the European Commission, or the UK International Data Transfer Agreement (IDTA) as applicable.
In the event of a personal data breach, REM shall notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
This DPA remains in effect for the duration of the Service agreement. Upon termination, REM will delete all personal data within 30 days, unless retention is required by applicable law. The Controller may request a copy of their data in a portable format prior to deletion.
For DPA-related enquiries:
dpo@remtel.io