Data Processing Agreement

Effective date: 6 May 2026 · Last updated: 6 May 2026 · Version 1.0

This Data Processing Agreement ("DPA") forms part of the Terms of Service between COLLINGHAMCO LTD ("RecallIQ", "Processor") and the subscribing garage business ("Controller"). By activating a RecallIQ subscription, the Controller agrees to this DPA.

1. Definitions

Controller means the garage or MOT test station that subscribes to RecallIQ and uploads customer data.

Processor means COLLINGHAMCO LTD (Company No. 15540675), trading as RecallIQ, which processes personal data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person — including customer names, mobile numbers, vehicle registration numbers, and service due dates uploaded to the RecallIQ platform.

Processing means any operation performed on personal data, including storage, retrieval, use, and transmission of SMS messages.

UK GDPR means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.

2. Scope and Purpose

The Processor agrees to process Personal Data solely for the following purposes:

  • Sending automated MOT and service reminder SMS messages to end customers on behalf of the Controller
  • Sending automated Google Review request SMS messages on behalf of the Controller following job completion
  • Providing the Controller with reporting and dashboard analytics relating to reminder performance

The Processor shall not process Personal Data for any other purpose without the express written consent of the Controller.

3. Controller's Obligations

The Controller warrants and represents that:

  • All personal data uploaded to RecallIQ has been collected lawfully and with a valid legal basis under UK GDPR (e.g. legitimate interests or consent)
  • End customers have been informed that their data may be used to send service reminders via SMS, as required by UK GDPR Articles 13–14
  • The Controller's own Privacy Policy accurately reflects the use of SMS reminders and the involvement of third-party processors
  • The Controller will promptly notify RecallIQ of any data subject requests (access, erasure, rectification) relating to personal data held on the platform
  • The Controller complies with PECR 2003 regarding electronic marketing, including maintaining appropriate consent or legitimate interest assessments for SMS communications

4. Processor's Obligations

COLLINGHAMCO LTD (RecallIQ) agrees to:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that all personnel with access to Personal Data are subject to appropriate confidentiality obligations
  • Implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, or destruction
  • Not transfer Personal Data outside the UK without appropriate safeguards in place
  • Assist the Controller in responding to data subject requests within the statutory timeframe (one calendar month)
  • Notify the Controller without undue delay (and no later than 72 hours) upon becoming aware of a personal data breach
  • Delete or return all Personal Data upon termination of the subscription, at the Controller's election
  • Make available all information necessary to demonstrate compliance with this DPA

5. Sub-Processors

The Controller authorises the Processor to engage the following sub-processors to deliver the service:

  • Twilio Inc. — SMS delivery platform (United States; Standard Contractual Clauses in place)
  • Base44 Ltd. — Application hosting and database infrastructure
  • Stripe Inc. — Payment processing (billing data only; no customer personal data shared)

RecallIQ will notify Controllers of any intended changes to sub-processors, giving reasonable opportunity to object.

6. Data Retention

Personal Data uploaded to RecallIQ will be retained for the duration of the active subscription. Upon cancellation:

  • Customer records will be retained for a maximum of 30 days to allow data export
  • After 30 days, all personal data will be permanently deleted from live systems
  • Anonymised aggregate analytics (e.g. total reminders sent) may be retained indefinitely

7. Security Measures

RecallIQ implements the following technical and organisational measures:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls limiting data access to authorised personnel only
  • Regular security reviews of the application infrastructure
  • Secure, isolated data environments per garage account

8. Data Subject Rights

Where an end customer (data subject) contacts the Controller to exercise their rights under UK GDPR (access, erasure, rectification, restriction, portability), the Controller must notify RecallIQ at hello@recalliq.online. RecallIQ will fulfil any data deletion or export request within 5 business days.

End customers may also contact RecallIQ directly at hello@recalliq.online to request erasure of their data from the platform.

9. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

10. Contact

COLLINGHAMCO LTD

21 Fulmar Way, Worksop, S81 8UF

Email: hello@recalliq.online

Company No. 15540675 · Registered in England & Wales