Legal
Last updated 15 September 2026
These terms form part of our terms of service. They apply whenever Vitesse Digital Ltd, trading as While You Work (company number 16074150, ICO registration ZC246746, "we"), processes personal data on behalf of a customer ("you") to provide the service. They are the contract required by Article 28 of the UK GDPR. If these terms and the terms of service conflict on data protection, these terms apply.
You are the controller of the personal data of your callers, chat visitors, customers and staff that we handle for you. We are your processor. We are the controller of your own account and billing data, which our privacy notice covers.
Subject matter and purpose: answering phone calls, web chats and other messages sent to your While You Work line; recording and transcribing calls; taking and sending you the caller's details and message; sending the caller a confirmation text; making bookings in your diary if you switch bookings on; and showing all of this in your dashboard.
Duration: for as long as you are a customer, plus the deletion periods in section 12.
Types of personal data: names, phone numbers, email addresses, postcodes and addresses, what the caller wants and how urgent it is, booking details, call recordings, transcripts, and chat, text, WhatsApp and email messages.
People the data is about: your callers and enquirers, your customers, and your staff.
The service is not designed for special category data such as health information. You must not set it up to ask for such data (see section 7 of the terms of service).
We process personal data only on your documented instructions, which are these terms, the terms of service and the settings you choose in your dashboard, unless the law requires otherwise, in which case we will tell you first unless the law forbids it. We will tell you if we think an instruction breaks data protection law.
Everyone we allow to access your data is bound by a duty of confidentiality and only accesses it when needed to provide or support the service.
We protect your data with measures including: encryption in transit; hosting and databases in London (DigitalOcean); nightly database backups encrypted with AES-256, kept on the server for 14 days and in a separate London storage location that deletes them after 90 days; access limited to authorised staff with throttled logins; call recordings played only through time-limited private links; and personal data removed from error reports before they leave our systems.
You give us general authorisation to use the sub-processors listed on our sub-processors page. We will email you at least 30 days before we add or replace a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may end your subscription and we will refund any unused whole months already paid. We put data protection obligations on each sub-processor that are at least as protective as these terms, and we remain responsible to you for them.
Some sub-processors handle data outside the UK. We only allow this where the UK has adequacy regulations for the destination (including the UK Extension to the EU-US Data Privacy Framework), or under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment.
If someone asks us to exercise their rights over data we process for you, we will pass the request to you within 5 working days and not answer it ourselves unless you ask us to. We will help you respond, for example by providing or deleting recordings, transcripts and messages.
We will tell you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting your data, with the information you need to meet your own obligations, and we will keep you updated.
We will give you reasonable help with data protection impact assessments and any prior consultation with the Information Commissioner's Office that relates to the service.
We will make available the information you reasonably need to show that these terms are being met. Once a year, or after a breach, you may audit our compliance on at least 30 days' notice, at your cost, in a way that does not affect other customers' data or confidentiality.
While you are a customer, call recordings are deleted after 30 days and transcripts and messages after 12 months, or sooner if you delete them. You can ask for an export of your call and message records at any time. When your subscription ends we delete your data within 30 days, except where the law requires us to keep it, and encrypted backups expire within a further 90 days.