Data Processing Agreement

Version 1.0  ·  Last updated: May 2026  ·  Elevyn Systems Ltd

What this document is: When you use SalesJet to process personal data from your own customers (leads), Elevyn Systems Ltd acts as your data processor. This agreement sets out the terms of that processing relationship as required by Article 28 of the UK GDPR. By accepting this agreement at signup, you confirm your acceptance of these terms.

1. Definitions

2. Subject Matter and Duration

This agreement governs the processing of personal data by Elevyn Systems Ltd on behalf of the Controller in connection with the provision of SalesJet Services.

This agreement is effective from the date of account creation and remains in force for the duration of the Controller's use of SalesJet. Upon termination, data is deleted in accordance with Section 9 below.

3. Nature and Purpose of Processing

The Processor will process personal data on behalf of the Controller for the following purposes:

The Processor will process personal data only on documented instructions from the Controller. Use of the SalesJet platform constitutes documented instructions.

4. Categories of Personal Data and Data Subjects

CategoryExamples
Contact dataName, phone number, email address
Communication dataMessage content, conversation history, channel used
Booking dataAppointment date, time, Calendly event ID
Payment dataPayment status, amount (full card data handled by Stripe, not SalesJet)
Technical dataTimestamps, message identifiers
Voice dataCall recordings and transcriptions (where applicable)

Data subjects are the Controller's leads, prospects, and customers who contact the Controller through channels connected to SalesJet.

5. Processor Obligations

Elevyn Systems Ltd undertakes to:

  1. Process personal data only on the Controller's documented instructions, and not for any other purpose
  2. Ensure all personnel who access personal data are bound by appropriate confidentiality obligations
  3. Implement and maintain appropriate technical and organisational security measures as described in Section 6
  4. Assist the Controller in responding to data subject requests (access, erasure, portability, rectification) at no additional charge
  5. Notify the Controller within 48 hours of becoming aware of a personal data breach affecting the Controller's data subjects
  6. Delete or return all personal data upon termination of services (see Section 9)
  7. Make available all information necessary to demonstrate compliance with this agreement
  8. Not transfer personal data to any country outside the UK or EEA unless appropriate safeguards are in place (see Section 7)

6. Security Measures

The Processor implements the following technical and organisational measures:

7. Sub-processors

The Controller authorises the use of the following sub-processors. All sub-processors are bound by data processing terms at least as protective as this agreement:

Sub-processorPurposeLocationTransfer Mechanism
AirtableDatabase — stores leads and conversationsUSAUK IDTA
Anthropic (Claude)AI message processingUSAUK IDTA
TwilioWhatsApp, SMS and voice deliveryUSAUK IDTA
ManychatInstagram and Facebook message deliveryUSAUK IDTA
SendGrid (Twilio)Email deliveryUSAUK IDTA
StripePayment processingUSA/EUUK IDTA / Adequacy
CalendlyAppointment bookingUSAUK IDTA
RailwayServer hostingUSAUK IDTA

UK IDTA = UK International Data Transfer Agreement (the post-Brexit equivalent of EU Standard Contractual Clauses). The Processor will notify the Controller of any changes to this sub-processor list with 14 days' notice, giving the Controller opportunity to object.

8. Controller Obligations

The Controller undertakes to:

  1. Ensure it has a valid lawful basis under UK GDPR for processing each data subject's personal data through SalesJet
  2. Provide appropriate privacy notices to data subjects at or before the point of data collection (e.g. on web forms, in messaging profiles, or via a privacy policy on the Controller's website)
  3. Honour data subject requests received directly (the Processor will assist, but the Controller is responsible for the overall response)
  4. Only connect channels and services for which it has the necessary rights and permissions
  5. Not instruct the Processor to process personal data in a way that would violate applicable law

9. Data Retention and Deletion

10. Data Subject Requests

When a data subject (one of the Controller's leads) submits a data request (access, erasure, portability, rectification), the following process applies:

  1. Data subjects can submit requests at salesjet.co.uk/data-request.html
  2. The Processor will notify the Controller within 5 working days
  3. The Processor will assist in locating the relevant data
  4. The Controller is responsible for the formal response to the data subject within 30 days

11. Liability

Each party shall be responsible for its own compliance with UK GDPR. The Processor shall not be liable for any failure of the Controller to comply with its obligations as a data controller, including failure to establish a lawful basis for processing or to provide adequate privacy notices to data subjects.

12. Governing Law

This agreement is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

For any queries relating to this agreement:

Elevyn Systems Ltd
Email: admin@elevynsystems.com
Website: salesjet.co.uk