Legal · for clients · Last updated 17 August 2026

Data processing for client work

Automation systems usually touch personal data – customer emails, CRM records, call transcripts. This page sets out how we handle that data on a client's behalf, so procurement and data-protection questions can be answered before a proposal, not after.

1. Roles

For systems we build or run for a client, the client is the controller and TelarLabs Ltd is the processor: we act on the client’s documented instructions and for the client’s purposes. Where we decide purposes ourselves – our own enquiries, invoicing, this website – we are the controller, and our privacy notice applies instead.

2. Data processing agreement

We sign a written data processing agreement (DPA) before any personal data is processed. Our standard DPA follows Article 28 of the UK GDPR and, for controllers in the EU, Article 28 of the EU GDPR; we are equally happy to work from the client’s own template. Request a copy at connect@telarlabs.co.uk.

In substance the DPA commits us to:

  • process personal data only on the client’s documented instructions and only for the agreed system;
  • keep the data confidential and limit access to people who need it for the work;
  • apply security appropriate to the risk – least-privilege credentials, secrets kept out of code and logs, per-client isolation;
  • help the client respond to data-subject requests and, where needed, with impact assessments;
  • tell the client about a personal-data breach without undue delay after becoming aware of it;
  • keep an up-to-date list of subprocessors for the engagement and give notice before changing it;
  • return or delete the personal data at the end of the engagement, as the client instructs, and confirm in writing;
  • provide the information reasonably needed to demonstrate compliance, including reasonable audits.

3. Subprocessors

Every engagement gets its own subprocessor list in the DPA annex – we add only what the system actually needs, and where the client prefers, systems run entirely inside the client’s own accounts and regions. Typical categories:

CategoryTypical providersNotes
Language-model providersAnthropic, OpenAI, Google – or the client’s own enterprise accountsAPI terms under which inputs are not used for training; UK/EU endpoints where the provider offers them
Model routing / observabilityOpenRouter, where used for non-sensitive workloadsNamed per project; not used for regulated or special-category data
Automation platformsn8n, Make, Zapier – cloud or self-hostedSelf-hosted in the client’s environment where data residency requires it
Hosting and databasesNetlify, Supabase, AWS or Google Cloud in UK/EU regionsRegion fixed in the DPA annex
Voice and telephony (voice-AI systems)Telephony carrier and speech providers named per projectCall recording and transcription only with the client’s lawful basis and disclosure in place

4. Where data lives, and transfers

UK or EU hosting is the default. Providers based in the United States are used only where the client agrees, and then under the provider’s data-processing terms with the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses in place.

5. No training on client data

Client data is not used to train models – ours or anyone else’s. We use model providers’ API terms under which inputs and outputs are not used for training, or the client’s own enterprise agreements. Prompts, evaluation sets and logs built for a client belong to that engagement.

6. Built-in safeguards

  • AI discloses itself at the start of every conversation it takes part in, with a human escalation path.
  • Evaluation gates before go-live: systems are tested against unseen inputs before they touch real customers.
  • Logs are scoped to what operations need; personal data is kept out of them where feasible.
  • Credentials are per client and least-privilege; nothing is shared across engagements.

7. End of engagement

On the client’s instruction we return or delete the personal data we hold for the engagement – normally within 30 days – and confirm it in writing. Anything we must keep for our own legal obligations (for example invoices) is limited to that purpose.

8. Contact

Data-protection questions, DPA requests and security questionnaires: connect@telarlabs.co.uk. TelarLabs Ltd, company number 17273713, Waterhouse Gardens, 1 Dutton Street, Manchester M3 1AJ, United Kingdom.