Legal

Toolie Data Processing Agreement.

Last updated: 2 October 2026

This Data Processing Agreement (“DPA”) forms part of the Toolie Terms of Service between STRUTH LTD (company number 17085039) (“we”, “us”, the processor) and the business that holds a Toolie account (“you”, the controller). It applies whenever we process personal data on your behalf through Toolie, and meets the requirements of Article 28 of the UK GDPR. By accepting the Terms of Service, you accept this DPA.

1. Definitions

Words such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that replaces them. “Customer Personal Data” means personal data you put into Toolie, or that Toolie collects for you, such as your contacts, conversations and bookings.

2. Roles and scope

You are the controller of Customer Personal Data and we are your processor.

The details of the processing (subject matter, duration, purpose, types of data and data subjects) are set out in Annex 1.

You’re responsible for having a lawful basis for the processing, including any consent needed to send marketing, and for the accuracy of the data you upload.

3. Our obligations

We will:

  • process Customer Personal Data only on your documented instructions, which are these Terms, this DPA and your use of Toolie’s settings and features, unless the law requires otherwise (and if so, we’ll tell you first unless the law prevents it)
  • tell you straight away if we think an instruction breaks Data Protection Law
  • make sure everyone authorised to process Customer Personal Data is bound by confidentiality
  • keep appropriate technical and organisational security measures in place, as described in Annex 3
  • help you, taking into account the nature of the processing, to respond to data subject requests such as access, correction and deletion. Most of these can be handled directly in Toolie, and we’ll forward any request we receive straight to you
  • help you with security, breach notifications, data protection impact assessments and consultations with the ICO, where these relate to our processing
  • give you the information reasonably needed to show we’re meeting this DPA, and allow audits as set out in section 7

4. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 2.

We’ll give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you have a reasonable data protection objection, tell us within that time. If we can’t resolve it, you may cancel your subscription before the change takes effect.

We’ll put a written contract in place with each sub-processor giving the same level of protection as this DPA, and we remain responsible to you for their performance.

Services you connect to Toolie under your own account, such as your Meta (WhatsApp, Facebook, Instagram), Google, Microsoft or Stripe accounts, are your own providers and are not our sub-processors.

5. International transfers

Toolie is hosted in the United States. We’ll only transfer Customer Personal Data outside the UK where a lawful transfer mechanism is in place. This includes UK adequacy regulations (such as the UK-US Data Bridge for certified organisations), the ICO’s International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

6. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we’ll tell you without undue delay, and within 48 hours where possible. We’ll share what we know about the breach, the likely impact and the steps we’re taking, and update you as we learn more. This helps you meet your own 72-hour deadline for reporting to the ICO.

7. Audits

We’ll answer reasonable written questions about our data protection practices and share relevant information, including our sub-processors’ security certifications where available. If that isn’t enough to show we’re meeting this DPA, you may carry out an audit once a year, on 30 days’ notice, at your own cost and in a way that doesn’t disrupt our business or other customers’ data.

8. Return and deletion

When your Toolie account closes, you can export your data for 30 days. After that, we’ll delete Customer Personal Data, unless the law requires us to keep it. Backups are deleted in their normal cycle.

9. Liability and general

Each party’s liability under this DPA is subject to the limits in the Terms of Service.

If this DPA and the Terms of Service conflict about personal data, this DPA wins.

This DPA is governed by the law of England and Wales, and lasts for as long as we process Customer Personal Data for you.

Contact us about this DPA at team@struth.uk.

Annex 1: Details of the processing

DetailDescription
Subject matterProviding the Toolie platform to you
DurationFor as long as your subscription runs, plus the deletion period in section 8
Nature and purposeHosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support
Types of personal dataNames, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store
Special category dataNot intended. Only if you choose to collect it and have a lawful basis to do so
Data subjectsYour customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie
Sub-processorWhat they doLocationTransfer safeguard
HighLevel, Inc. (LeadConnector)Platform software, hosting, email and SMS delivery infrastructureUnited States (hosted on Google Cloud and Amazon Web Services)EU-US Data Privacy Framework and UK Extension
HighLevel's own sub-processorsInfrastructure, messaging and support services used to run the platformUnited States, India and other countriesAs listed and safeguarded by HighLevel
Google WorkspaceOur support email and internal documentsUnited States / EUUK-US Data Bridge, IDTA Addendum
  • Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
  • Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
  • Two-factor authentication and role-based permissions for user accounts
  • Staff access limited to what's needed to provide support, under confidentiality
  • Regular backups and the ability to restore data
  • Logging and monitoring of platform activity
  • A breach response process in line with section 6

Annex 2: Sub-processors

DetailDescription
Subject matterProviding the Toolie platform to you
DurationFor as long as your subscription runs, plus the deletion period in section 8
Nature and purposeHosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support
Types of personal dataNames, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store
Special category dataNot intended. Only if you choose to collect it and have a lawful basis to do so
Data subjectsYour customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie
Sub-processorWhat they doLocationTransfer safeguard
HighLevel, Inc. (LeadConnector)Platform software, hosting, email and SMS delivery infrastructureUnited States (hosted on Google Cloud and Amazon Web Services)EU-US Data Privacy Framework and UK Extension
HighLevel's own sub-processorsInfrastructure, messaging and support services used to run the platformUnited States, India and other countriesAs listed and safeguarded by HighLevel
Google WorkspaceOur support email and internal documentsUnited States / EUUK-US Data Bridge, IDTA Addendum
  • Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
  • Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
  • Two-factor authentication and role-based permissions for user accounts
  • Staff access limited to what's needed to provide support, under confidentiality
  • Regular backups and the ability to restore data
  • Logging and monitoring of platform activity
  • A breach response process in line with section 6

Annex 3: Security measures

DetailDescription
Subject matterProviding the Toolie platform to you
DurationFor as long as your subscription runs, plus the deletion period in section 8
Nature and purposeHosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support
Types of personal dataNames, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store
Special category dataNot intended. Only if you choose to collect it and have a lawful basis to do so
Data subjectsYour customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie
Sub-processorWhat they doLocationTransfer safeguard
HighLevel, Inc. (LeadConnector)Platform software, hosting, email and SMS delivery infrastructureUnited States (hosted on Google Cloud and Amazon Web Services)EU-US Data Privacy Framework and UK Extension
HighLevel's own sub-processorsInfrastructure, messaging and support services used to run the platformUnited States, India and other countriesAs listed and safeguarded by HighLevel
Google WorkspaceOur support email and internal documentsUnited States / EUUK-US Data Bridge, IDTA Addendum
  • Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
  • Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
  • Two-factor authentication and role-based permissions for user accounts
  • Staff access limited to what's needed to provide support, under confidentiality
  • Regular backups and the ability to restore data
  • Logging and monitoring of platform activity
  • A breach response process in line with section 6