Skip to content

This Data Processing Agreement (“DPA”) sets out the terms on which Kilij Digital Ltd processes personal data on behalf of its clients. It forms part of the services agreement between Kilij Digital Ltd (“Processor”) and the client (“Controller”) and reflects the requirements of Article 28 of the UK GDPR. It is published here for transparency; where it is incorporated into a signed services agreement, that agreement prevails in the event of any conflict.

1. Roles

Where Kilij Digital processes personal data in order to provide services to a client (for example, operating a lead system that answers and qualifies enquiries), the client is the Controller and Kilij Digital is the Processor. Each party will comply with its obligations under applicable UK data protection law.

2. Scope of processing

  • Subject matter: the provision of the agreed services.
  • Duration: the term of the services agreement.
  • Nature and purpose: capturing, responding to, qualifying and routing enquiries, and related automation, on the Controller’s behalf.
  • Types of personal data: typically names, contact details and the content of enquiries.
  • Categories of data subjects: the Controller’s prospective and existing customers and enquirers.

3. Our obligations as Processor

Kilij Digital will:

  • process personal data only on the Controller’s documented instructions, unless required otherwise by law;
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (Article 32);
  • assist the Controller in responding to data subject rights requests;
  • assist the Controller with security, breach notification and data protection impact assessments;
  • notify the Controller without undue delay on becoming aware of a personal data breach;
  • delete or return personal data at the end of the services, unless retention is required by law;
  • make available the information needed to demonstrate compliance and allow for audits.

4. Sub-processors

The Controller gives general authorisation for Kilij Digital to engage sub-processors to deliver the services. Our current sub-processors are listed on our Sub-processors page. We will inform the Controller of intended changes and give them the opportunity to object. We remain responsible for our sub-processors’ compliance.

5. International transfers

Where personal data is transferred outside the United Kingdom, we put in place an appropriate transfer mechanism, such as the UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses.

6. Security

We maintain measures appropriate to the risk, including access controls, encryption in transit, separation of client data, and regular review of our providers.

7. Contact

For any matter relating to this DPA, contact [email protected].

Last updated: 23 June 2026.