Data Processing Agreement
Last updated: 13 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Bit Robotics Ltd (company number 11680576, registered office 13 Freeland Park Wareham Road, Lytchett House, Poole, Dorset, England, BH16 6FA, United Kingdom), trading as Recalld ("Recalld", "we", "us"), and the customer that accepted those terms ("you"). It applies automatically whenever the content you send to the service contains personal data. No signature is needed. If you need a countersigned copy for your records, email support@recalld.ai.
1. Roles and scope
- For personal data contained in the content you send to Recalld ("Customer Data"), you are the controller and Recalld is your processor. Where you are yourself a processor for another organisation, Recalld is your sub-processor and you warrant that your own controller has authorised this DPA.
- "Data protection law" means the UK GDPR, the Data Protection Act 2018 and, where it applies to you, the EU GDPR. Terms such as controller, processor, personal data, processing and personal data breach have the meanings given there.
- If this DPA conflicts with the Terms of Service, this DPA prevails for the processing of Customer Data. Personal data about you as an account holder (email, billing, usage) is handled by Recalld as a controller under the Privacy Policy, not under this DPA.
2. Details of processing
| Subject matter | Storage, fact extraction, embedding and retrieval of content you send to the Recalld API, dashboard, MCP server or chat application. |
|---|---|
| Duration | For as long as you hold an account, plus the backup roll-off period in section 8. |
| Nature and purpose | Providing the memory service to you as described in the Terms of Service. Recalld does not process Customer Data for any other purpose, and never to train machine-learning models. |
| Categories of data subjects | Determined by you. Typically your end users, employees, customers and other people mentioned in the content your agents store. |
| Types of personal data | Determined by you. Typically names, contact details, preferences, conversation history and other personal data contained in unstructured text. |
| Prohibited data | You must not send biometric data, genetic data, health data or payment card data. Other special category data (for example data revealing racial or ethnic origin, political opinions, religious beliefs or sexual orientation) may be sent only if you have a lawful basis and appropriate safeguards; Recalld applies the same technical measures to all Customer Data. |
3. Your instructions
Recalld processes Customer Data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, your use of the service (including the API calls you make and the settings you choose), and any further written instructions we agree to. We will tell you if we believe an instruction breaches data protection law, and we may then pause the affected processing until the point is resolved.
4. Our obligations as processor
- Confidentiality. Everyone we authorise to access Customer Data is bound by a duty of confidentiality and is given access only where needed to operate or support the service.
- Security. We maintain the technical and organisational measures described on our Security page, including encryption in transit, encrypted off-site backups, per-account isolation at the database layer, multi-factor authentication on all administrative access, hashed API keys, logging and prompt patching. We may update these measures, but not in a way that reduces the overall level of protection.
- Data subject requests. The dashboard and API let you export, correct and delete data directly. If a data subject contacts us about data you control, we will forward the request to you within 5 working days and will not respond to it ourselves unless you ask us to or the law requires it.
- Assistance. Taking into account the nature of the processing, we will give you reasonable help with your obligations on security, personal data breaches, data protection impact assessments and consultation with supervisory authorities.
- Personal data breach. If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 48 hours, giving the information we have at the time and updating it as the investigation continues.
- Records and audits. We will make available the information reasonably needed to show compliance with Article 28 of the GDPR. If that information is not sufficient, you may audit us once in any 12-month period, on at least 30 days' written notice, during business hours, at your cost, and in a way that does not compromise the security of other customers. Where a recognised third-party audit report or certification covers the point, we may provide that instead.
5. Sub-processors
- You give general authorisation for Recalld to use the sub-processors listed on our sub-processor page, which forms part of this DPA. Each sub-processor is bound by written terms that impose data protection obligations no less protective than this DPA.
- We will email account holders at least 14 days before a new sub-processor starts processing Customer Data. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate your account and we will refund any prepaid fees for the unused period.
- Recalld remains fully liable to you for the performance of its sub-processors.
- If you connect your own model provider key (BYOK), that provider acts for you directly under your own agreement and is not a Recalld sub-processor.
6. International transfers
- Customer Data in the EU region is stored and backed up within the European Union. Customer Data in the US region is stored and backed up within the United States. Data is never moved between regions.
- Recalld administers the service from the United Kingdom. Access to EU region data from the UK relies on the European Commission's adequacy decision for the United Kingdom; transfers from the UK to the EEA rely on the UK adequacy regulations for the EEA.
- Where a sub-processor processes Customer Data outside the UK and EEA (for example a model provider in the United States), the transfer is protected by the EU Standard Contractual Clauses with the UK Addendum, or, where the provider is certified, the EU-US Data Privacy Framework and its UK Extension.
7. Your obligations
- You are responsible for the lawfulness of the Customer Data you send, including having a lawful basis, giving any required notices to data subjects, and not sending prohibited data.
- You must keep your API keys and account credentials secure and configure the service, including model choices and what you store and delete, in line with your own obligations.
8. Deletion and return
- You can export all Customer Data at any time from the dashboard or API, and delete individual threads, agents or your whole account.
- Deleting your account permanently erases Customer Data from live systems immediately. Encrypted backups roll off within 14 days and are used only for disaster recovery.
- We may retain Customer Data only where and for as long as the law requires, and will keep it confidential and stop all other processing.
9. Liability
Each party's liability under or in connection with this DPA is subject to the exclusions and the cap in section 13 of the Terms of Service, which apply to the Terms of Service and this DPA together as a single aggregate limit.
10. Term, governing law and jurisdiction
This DPA starts when you accept the Terms of Service and lasts for as long as Recalld processes Customer Data for you. It is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute or claim arising out of or in connection with it, wherever you are located. Nothing in this DPA removes rights that data protection law grants to controllers or data subjects and does not allow to be waived.
11. Contact
Questions about this DPA, or a request for a countersigned copy: support@recalld.ai. Our representative in the European Union under Article 27 EU GDPR is SKILL SOFTWARE SRL, Str. Sold. Er. Arhip Nicolae 12, Bl. 66, Sc. A, Et. 9, Ap. 39, Ploiești, Prahova, Romania, eu-representative@bitrobotics.co.uk.