Toolie Data Processing Agreement.
Last updated: 2 October 2026
This Data Processing Agreement (“DPA”) forms part of the Toolie Terms of Service between STRUTH LTD (company number 17085039) (“we”, “us”, the processor) and the business that holds a Toolie account (“you”, the controller). It applies whenever we process personal data on your behalf through Toolie, and meets the requirements of Article 28 of the UK GDPR. By accepting the Terms of Service, you accept this DPA.
1. Definitions
Words such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that replaces them. “Customer Personal Data” means personal data you put into Toolie, or that Toolie collects for you, such as your contacts, conversations and bookings.
2. Roles and scope
You are the controller of Customer Personal Data and we are your processor.
The details of the processing (subject matter, duration, purpose, types of data and data subjects) are set out in Annex 1.
You’re responsible for having a lawful basis for the processing, including any consent needed to send marketing, and for the accuracy of the data you upload.
3. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are these Terms, this DPA and your use of Toolie’s settings and features, unless the law requires otherwise (and if so, we’ll tell you first unless the law prevents it)
- tell you straight away if we think an instruction breaks Data Protection Law
- make sure everyone authorised to process Customer Personal Data is bound by confidentiality
- keep appropriate technical and organisational security measures in place, as described in Annex 3
- help you, taking into account the nature of the processing, to respond to data subject requests such as access, correction and deletion. Most of these can be handled directly in Toolie, and we’ll forward any request we receive straight to you
- help you with security, breach notifications, data protection impact assessments and consultations with the ICO, where these relate to our processing
- give you the information reasonably needed to show we’re meeting this DPA, and allow audits as set out in section 7
4. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex 2.
We’ll give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you have a reasonable data protection objection, tell us within that time. If we can’t resolve it, you may cancel your subscription before the change takes effect.
We’ll put a written contract in place with each sub-processor giving the same level of protection as this DPA, and we remain responsible to you for their performance.
Services you connect to Toolie under your own account, such as your Meta (WhatsApp, Facebook, Instagram), Google, Microsoft or Stripe accounts, are your own providers and are not our sub-processors.
5. International transfers
Toolie is hosted in the United States. We’ll only transfer Customer Personal Data outside the UK where a lawful transfer mechanism is in place. This includes UK adequacy regulations (such as the UK-US Data Bridge for certified organisations), the ICO’s International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
6. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we’ll tell you without undue delay, and within 48 hours where possible. We’ll share what we know about the breach, the likely impact and the steps we’re taking, and update you as we learn more. This helps you meet your own 72-hour deadline for reporting to the ICO.
7. Audits
We’ll answer reasonable written questions about our data protection practices and share relevant information, including our sub-processors’ security certifications where available. If that isn’t enough to show we’re meeting this DPA, you may carry out an audit once a year, on 30 days’ notice, at your own cost and in a way that doesn’t disrupt our business or other customers’ data.
8. Return and deletion
When your Toolie account closes, you can export your data for 30 days. After that, we’ll delete Customer Personal Data, unless the law requires us to keep it. Backups are deleted in their normal cycle.
9. Liability and general
Each party’s liability under this DPA is subject to the limits in the Terms of Service.
If this DPA and the Terms of Service conflict about personal data, this DPA wins.
This DPA is governed by the law of England and Wales, and lasts for as long as we process Customer Personal Data for you.
Contact us about this DPA at team@struth.uk.
Annex 1: Details of the processing
| Detail | Description |
|---|---|
| Subject matter | Providing the Toolie platform to you |
| Duration | For as long as your subscription runs, plus the deletion period in section 8 |
| Nature and purpose | Hosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support |
| Types of personal data | Names, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store |
| Special category data | Not intended. Only if you choose to collect it and have a lawful basis to do so |
| Data subjects | Your customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie |
| Sub-processor | What they do | Location | Transfer safeguard |
|---|---|---|---|
| HighLevel, Inc. (LeadConnector) | Platform software, hosting, email and SMS delivery infrastructure | United States (hosted on Google Cloud and Amazon Web Services) | EU-US Data Privacy Framework and UK Extension |
| HighLevel's own sub-processors | Infrastructure, messaging and support services used to run the platform | United States, India and other countries | As listed and safeguarded by HighLevel |
| Google Workspace | Our support email and internal documents | United States / EU | UK-US Data Bridge, IDTA Addendum |
- Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
- Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
- Two-factor authentication and role-based permissions for user accounts
- Staff access limited to what's needed to provide support, under confidentiality
- Regular backups and the ability to restore data
- Logging and monitoring of platform activity
- A breach response process in line with section 6
Annex 2: Sub-processors
| Detail | Description |
|---|---|
| Subject matter | Providing the Toolie platform to you |
| Duration | For as long as your subscription runs, plus the deletion period in section 8 |
| Nature and purpose | Hosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support |
| Types of personal data | Names, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store |
| Special category data | Not intended. Only if you choose to collect it and have a lawful basis to do so |
| Data subjects | Your customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie |
| Sub-processor | What they do | Location | Transfer safeguard |
|---|---|---|---|
| HighLevel, Inc. (LeadConnector) | Platform software, hosting, email and SMS delivery infrastructure | United States (hosted on Google Cloud and Amazon Web Services) | EU-US Data Privacy Framework and UK Extension |
| HighLevel's own sub-processors | Infrastructure, messaging and support services used to run the platform | United States, India and other countries | As listed and safeguarded by HighLevel |
| Google Workspace | Our support email and internal documents | United States / EU | UK-US Data Bridge, IDTA Addendum |
- Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
- Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
- Two-factor authentication and role-based permissions for user accounts
- Staff access limited to what's needed to provide support, under confidentiality
- Regular backups and the ability to restore data
- Logging and monitoring of platform activity
- A breach response process in line with section 6
Annex 3: Security measures
| Detail | Description |
|---|---|
| Subject matter | Providing the Toolie platform to you |
| Duration | For as long as your subscription runs, plus the deletion period in section 8 |
| Nature and purpose | Hosting, storing, organising and displaying your data; sending and receiving email, SMS, WhatsApp and social messages; running automations, bookings, forms, invoices and payments; providing support |
| Types of personal data | Names, email addresses, phone numbers, postal addresses, business details, message and call content, call recordings, notes, appointment details, form answers, invoice and payment records (not full card numbers), website activity, and any other data you choose to store |
| Special category data | Not intended. Only if you choose to collect it and have a lawful basis to do so |
| Data subjects | Your customers, leads, enquirers, subscribers and website visitors, plus your staff and team members who use Toolie |
| Sub-processor | What they do | Location | Transfer safeguard |
|---|---|---|---|
| HighLevel, Inc. (LeadConnector) | Platform software, hosting, email and SMS delivery infrastructure | United States (hosted on Google Cloud and Amazon Web Services) | EU-US Data Privacy Framework and UK Extension |
| HighLevel's own sub-processors | Infrastructure, messaging and support services used to run the platform | United States, India and other countries | As listed and safeguarded by HighLevel |
| Google Workspace | Our support email and internal documents | United States / EU | UK-US Data Bridge, IDTA Addendum |
- Data encrypted in transit (TLS) and at rest on our hosting providers' infrastructure
- Hosting on Google Cloud and Amazon Web Services data centres with recognised security certifications (such as ISO 27001 and SOC 2)
- Two-factor authentication and role-based permissions for user accounts
- Staff access limited to what's needed to provide support, under confidentiality
- Regular backups and the ability to restore data
- Logging and monitoring of platform activity
- A breach response process in line with section 6
