redplumm

Data Protection & Compliance

Last updated 28 September 2026

This is the page to send to a procurement or compliance team. It says which laws apply to us, what we have in place, and what we can provide on request.

On this page

  1. Which laws apply
  2. Controller or processor
  3. Data Processing Agreement
  4. Sub-processors
  5. International transfers
  6. Security measures
  7. If something goes wrong
  8. Data subject requests
  9. What we can send you

1. Which laws apply

RegimeWhen it appliesOur notice
UK GDPR and Data Protection Act 2018Our default. We are a UK company and most customers are UK basedPrivacy Policy
EU GDPRWhere we process data of people in the EUPrivacy Policy — the same notice, the obligations are materially identical
POPIA (South Africa)Our Johannesburg office, and South African data subjectsPOPIA Notice
PECRElectronic marketing and cookiesWe send no marketing email and set no tracking cookies

There is no separate "GDPR policy", and there should not be. The privacy policy is the notice that Articles 13 and 14 of the GDPR require. A second document covering the same ground would eventually contradict the first.

2. Controller or processor

We are the controller of information about you as our customer — your account, your billing, your correspondence with us.

We are the processor of everything you put into our systems: the records your staff submit, the photographs and signatures they capture, and the calls your customers make to your AI Receptionist. You are the controller of that data. We act only on your instructions.

Under POPIA the equivalent terms are responsible party and operator, and the split is the same.

3. Data Processing Agreement

We have a DPA drafted against Article 28 of the UK GDPR and section 20 of POPIA. It covers our obligations, sub-processor notice, audit rights, breach notification, and return or deletion of data at the end of the agreement.

Request it at privacy@redplumm.com and we will send it the same working day. We are happy to sign yours instead if your legal team prefers their own paper.

4. Sub-processors

The current list is in our Privacy Policy and includes PayPal, SMTP2GO, and — for the AI Receptionist only — Twilio, ElevenLabs and OpenAI.

If we add or replace one, we give you at least 30 days' notice by email. If you object on reasonable data protection grounds, we will either propose an alternative or you may terminate the affected service without penalty.

Each sub-processor is bound by terms no less protective than ours, and we remain liable to you for what they do.

5. International transfers

Some suppliers are outside the UK. Where personal data leaves the UK we rely on a UK adequacy decision where one exists, and otherwise on Standard Contractual Clauses with the UK International Data Transfer Addendum.

For POPIA, section 72 transfers rely on binding written agreements imposing obligations substantially similar to POPIA's conditions.

6. Security measures

Not a generic list — this is what is implemented:

7. If something goes wrong

We will notify you without undue delay on becoming aware of a breach affecting your data, with what we know at the time and what we are doing about it. Where the law requires it we will notify the Information Commissioner's Office within 72 hours, and the South African Information Regulator as soon as reasonably possible.

We will not wait until we have the full picture before telling you. You will hear about it from us.

8. Data subject requests

If one of your staff or customers contacts us directly about data we hold on your behalf, we will refer them to you rather than act on it, because you are the controller. We will tell you promptly and help you respond.

For data we control ourselves, contact privacy@redplumm.com. We respond within one month, free of charge.

9. What we can send you

On request, and usually the same working day:

Email privacy@redplumm.com.