Data Processing Addendum
Article 28 GDPRThis Data Processing Addendum ("DPA") forms part of the agreement (the "Agreement") between CallBotAgent, Inc. ("Processor", "we") and the customer that uses the Service ("Controller", "Customer", "you") and applies whenever Processor processes Personal Data on Controller's behalf in connection with the Service. The Processor has designated an EU representative under Article 27 GDPR; identity and contact details are published in our Legal Notice.
1. Background & Definitions
This DPA governs Processor's processing of Personal Data on Controller's behalf in connection with the Service described in the Agreement. Capitalised terms not defined here have the meaning given to them in the Agreement.
- "Applicable Data Protection Laws": the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (FADP), and any other data-protection law applicable to the processing.
- "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing": as defined in Article 4 GDPR.
- "Customer Personal Data": Personal Data processed by Processor on Controller's behalf as described in Annex 1.
- "SCCs": the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, as amended.
- "UK Addendum": the International Data Transfer Addendum to the SCCs issued by the UK ICO.
- "Restricted Transfer": a transfer of Personal Data from the EU/EEA, UK, or Switzerland to a country not recognised as adequate by the European Commission, the UK ICO, or the Swiss FDPIC respectively.
- "Sub-processors List": the list of approved Sub-processors maintained at /sub-processors.
- "TOMs": the technical and organisational measures described in Annex 4.
2. Roles
The parties acknowledge and agree that, with respect to the Processing of Customer Personal Data:
- Controller is the data controller within the meaning of Article 4(7) GDPR;
- Processor is the data processor within the meaning of Article 4(8) GDPR;
- Each Party is responsible for compliance with the Applicable Data Protection Laws applicable to its role.
For the avoidance of doubt: Customer is the controller of the End-Customer Personal Data processed during Calls. Processor is also a separate, independent controller for limited categories of data described in the Privacy Policy (e.g., Customer's billing and account data); that controller-level processing is outside the scope of this DPA.
3. Subject Matter & Scope
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex 1. Processor will process Customer Personal Data only:
- on documented instructions from Controller, including with regard to Restricted Transfers, unless required to do otherwise by EU or Member State law (in which case Processor will inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest);
- for the purpose of providing the Service, performing the Agreement, and complying with Controller's documented instructions;
- in accordance with the TOMs in Annex 4.
The Agreement, this DPA, the Sub-processors List, and Controller's configuration of the Service (e.g., script approval, recording on/off, retention period) constitute Controller's complete documented instructions. Any additional instructions must be agreed in writing.
If Processor in its reasonable opinion considers that an instruction infringes Applicable Data Protection Laws, it will inform Controller without delay and may pause the processing pending resolution.
4. Categories of Data
The categories of Personal Data and Data Subjects are described in Annex 1. Special categories of Personal Data within the meaning of Article 9 GDPR are not requested by the Service by design. Processor's PII redaction layer detects and replaces sensitive identifiers (e.g., card numbers, national IDs, e-mail addresses) in transcripts before write to long-term storage. If Controller's configuration nonetheless results in special-category data being processed, Controller is solely responsible for the lawful basis under Article 9 GDPR and must notify Processor in writing.
4.1 Voice audio is processed for communication purposes only — not for biometric identification
The Service involves the processing of voice audio (raw audio files and transcripts) for the purpose of conducting, transcribing, and summarising voice conversations on Controller's behalf. Processor does not apply, and shall not apply, any technical processing or analysis of voice audio for the purpose of uniquely identifying a natural person within the meaning of Article 4(14) GDPR (Biometric Data) or for any other purpose that would result in the processing of biometric data within the meaning of Article 9(1) GDPR. Processing of voice data is limited to communication, speech-to-text transcription, intent classification, sentiment indicators (where Controller enables them), and other content-based analytics required to deliver the Service. Voiceprint generation, speaker-recognition, voice-based authentication, and similar identification techniques are not features of the Service. Accordingly, voice audio processed by the Service does not, by itself or as configured under this DPA, constitute special-category data under Article 9 GDPR.
Where Controller wishes to deploy any feature, configuration, or integration that would cause the Service to process voice audio for the purpose of uniquely identifying a natural person, Controller must (a) obtain explicit consent from each Data Subject under Article 9(2)(a) GDPR or rely on another lawful basis under Article 9(2), (b) issue a written instruction to Processor in advance, and (c) execute any additional technical and organisational safeguards that Processor reasonably requires.
5. Processor Obligations
Processor will:
- Confidentiality: ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality;
- Security: implement and maintain the TOMs in Annex 4, including, in accordance with Article 32 GDPR, encryption of Personal Data, ongoing confidentiality, integrity, availability, and resilience of the processing systems, the ability to restore availability and access in a timely manner after an incident, and a process for regularly testing the effectiveness of the TOMs;
- Sub-processing: only engage Sub-processors in accordance with Section 6;
- Assistance with Data Subject requests: taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, in so far as possible, in fulfilling Controller's obligation to respond to requests for exercising Data Subject rights under Articles 12-22 GDPR;
- Assistance with security, breach, DPIA, and prior consultation: assist Controller in ensuring compliance with Articles 32-36 GDPR, taking into account the nature of the processing and the information available to Processor;
- Return or deletion: at Controller's option, delete or return all Customer Personal Data to Controller after the end of the provision of services as described in Section 11;
- Audit: make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as described in Section 8.
6. Sub-processors
6.1 General authorisation
Controller grants Processor general authorisation to engage Sub-processors for the processing of Customer Personal Data, subject to compliance with this Section 6.
6.2 Current list
The current list of Sub-processors is published at /sub-processors and reproduced in Annex 2. Controller acknowledges and approves the Sub-processors listed there as of the Effective Date.
6.3 Notification of changes
Processor will give Controller at least 30 days' prior notice of the addition, replacement, or removal of any Sub-processor by updating the Sub-processors List and either (i) emailing the Customer's primary contact on file or (ii) posting an in-app notice. Processor maintains an opt-in subscription channel for Customers that wish to receive Sub-processor changes by email regardless of materiality.
6.4 Right to object
Controller may object to a proposed Sub-processor change on documented data-protection grounds within 30 days of receiving notice. The Parties will discuss in good faith. If they cannot resolve the objection within a further 30 days, Controller may, as its sole and exclusive remedy, terminate the affected portion of the Service for material breach in accordance with the Agreement and receive a pro-rata refund of any pre-paid fees attributable to the unused period.
6.5 Sub-processor agreements
Processor will enter into a written agreement with each Sub-processor that imposes data-protection obligations no less protective than those in this DPA, including obligations as to security, confidentiality, sub-processing, return/deletion, audit, and assistance with Data Subject rights. Processor remains liable to Controller for the performance of each Sub-processor's data-protection obligations as if Processor performed those obligations itself.
6.6 Zero-retention chain
Sub-processors that act in the AI orchestration, LLM, and TTS layers operate under contractual zero-retention restrictions: they do not store, log, or use Customer Personal Data after the conclusion of each request beyond the minimum necessary to provide the requested response, and they do not use Customer Personal Data to train or fine-tune any model.
7. International Transfers
Processor will only Process Customer Personal Data in a third country if it has implemented appropriate safeguards in accordance with Articles 44-49 GDPR. Where Processor or any Sub-processor processes Customer Personal Data in a country that is not subject to a Commission adequacy decision (or, for UK transfers, an ICO adequacy regulation; for Swiss transfers, an FDPIC adequacy decision), the SCCs (and, where applicable, the UK Addendum and Swiss adaptations) apply as described in Annex 3.
The Parties agree that:
- The SCCs Module 2 (controller-to-processor) applies as between Controller (data exporter) and Processor (data importer) for Restricted Transfers from Controller to Processor;
- The SCCs Module 3 (processor-to-sub-processor) applies as between Processor (data exporter) and any Sub-processor (data importer) for Restricted Transfers further down the chain;
- Annex 3 sets out Annexes I, II, and III to the SCCs;
- The Parties accept the SCCs without modification.
Processor has performed a Transfer Impact Assessment ("TIA") for each Restricted Transfer covered by this DPA, taking into account the laws and practices of the destination country and the supplementary measures in Annex 4. The TIA summary is maintained as an internal compliance record that informs the Processor's safeguard design.
8. Audit Rights
8.1 Documentation
Processor will provide Controller with all information necessary to demonstrate compliance with Article 28 GDPR, including the TOMs, Sub-processors List, breach-response runbook summary, and the most recent third-party security report (where available).
8.2 Audit
If the documentation in Section 8.1 is insufficient, Controller (or an independent auditor mandated by Controller and reasonably acceptable to Processor) may audit Processor's compliance once per twelve-month period (or more frequently following a Personal Data Breach affecting Controller, or as required by a competent supervisory authority), subject to the following:
- at least 30 days' prior written notice;
- during normal business hours and without disrupting Processor's operations;
- under a confidentiality agreement reasonably acceptable to Processor;
- limited to information and personnel relevant to Processor's compliance with this DPA and the SCCs;
- at Controller's expense (Processor will charge reasonable time-and-materials for personnel hours required to support the audit beyond a 1-day default allowance);
- excluding access to other customers' data, Processor's commercially-sensitive information unrelated to compliance, and any system that would expose Sub-processors' confidential information.
Where Processor obtains a SOC 2 Type II report or equivalent third-party certification, Controller agrees that the audit obligation may be satisfied by reference to that certification through the documentation channels described in Section 8.1, except where the supervisory authority requires otherwise.
9. Personal Data Breach Notification
9.1 Notification
Processor will notify Controller without undue delay, and in any event within 24 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data. The initial notification will include the information then available; subsequent updates will follow as more information becomes known. Final detail will be provided within 72 hours where feasible.
9.2 Information provided
The notification will include, to the extent known: the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and personal-data records concerned); the likely consequences; the measures taken or proposed to be taken to address the breach and mitigate possible adverse effects; and the name and contact details of the Processor's contact point.
9.3 No supervisory notification by Processor
Processor will not notify the supervisory authority on Controller's behalf and will not disclose the breach publicly until Controller has had a reasonable opportunity to coordinate communications, except as legally required.
10. Data Subject Requests
Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, in so far as possible, to fulfil Controller's obligation to respond to requests by Data Subjects to exercise their rights under Articles 12-22 GDPR. Where Processor receives a request directly from a Data Subject relating to Customer Personal Data, Processor will (a) not respond on the merits unless authorised by Controller; (b) forward the request to Controller without undue delay; and (c) acknowledge receipt to the Data Subject indicating that Controller is the responsible party.
11. Termination — Return & Deletion
On termination or expiry of the Agreement, Processor will, at Controller's option:
- Return Customer Personal Data to Controller in a structured, commonly-used, machine-readable format (CSV / JSON / WAV for recordings) within 30 days; or
- Delete the Customer Personal Data, subject to legal-retention obligations applicable to the Operator and its merchant of record (e.g., bookkeeping or tax laws that require retention of invoice metadata for several years after the end of the fiscal year).
If Controller does not specify a choice within 30 days of termination, Processor will provide a final 30-day grace period during which Controller may export, after which Processor will delete or anonymise.
Backups containing residual Customer Personal Data are retained in encrypted form for up to 90 days for disaster-recovery and rolled into the deletion cycle automatically.
12. Liability
12.1 Cap inherits from Agreement
12.2 Direct claims by Data Subjects
Notwithstanding Section 12.1, where a Data Subject has a third-party-beneficiary right under the SCCs to bring a direct claim against the Processor or a Sub-processor, the limits of liability in the Agreement do not apply to that claim to the extent prohibited by the SCCs.
12.3 Indemnity for unlawful instructions
Controller indemnifies Processor against any claim, liability, fine, or cost arising out of (a) Controller's failure to provide Processor with documented instructions that are sufficient and lawful under Applicable Data Protection Laws; (b) Controller's processing of Personal Data in violation of Applicable Data Protection Laws; or (c) Controller's failure to obtain consents or provide notices required under Applicable Data Protection Laws.
13. Order of Precedence & Contact
In the event of conflict between the Agreement, this DPA, and the SCCs:
- The SCCs prevail in respect of Restricted Transfers;
- This DPA prevails over the Agreement on data-protection matters;
- The Agreement governs all other matters.
For all questions and notices under this DPA contact [email protected] (Processor) and/or [email protected] (the Operator's designated EU representative — full identity in our Legal Notice).
Annex 1 — Subject Matter, Duration, Nature, Purpose, Categories
A. Subject matter and duration
The Processing concerns Customer Personal Data submitted to or generated by the Service, in the course of placing automated outbound voice Calls to End-Customers on Controller's behalf, for the duration of the Agreement plus the post-termination retention period described in Section 11.
B. Nature and purpose
- Receiving order webhooks from Controller's connected store and triggering qualifying Calls;
- Routing the Call through telephony providers and the voice-AI orchestrator;
- Generating speech, recognising responses, classifying intent, recording (where enabled), transcribing (where enabled), redacting PII, and writing structured outcomes back to Controller's panel and Controller's connected store;
- Generating analytics, reports, and audit logs accessible by Controller via the panel;
- Providing customer support to Controller's Authorized Users.
C. Categories of Data Subjects
- End-Customers of Controller's e-commerce store who placed an order, abandoned a cart, or otherwise interacted with the store in a way that triggers a Call under Controller's configuration;
- Controller's Authorized Users (employees, contractors, agency users) — limited to processor-side metadata when they administer the panel.
D. Categories of Personal Data
- Identification data: name, phone number, e-mail (where supplied by Controller's store);
- Order metadata: order ID, order value, items, delivery address summary, payment method type;
- Communication content: voice recording (where Controller has enabled recording); transcript; AI-generated metadata (intent, outcome, sentiment if enabled);
- Technical data: telephony signalling (call disposition, duration, time-stamps), IP address (only for Controller's Authorized Users when administering the panel);
- Information freely volunteered by the End-Customer during the Call.
E. Special categories
Not requested by the Service by design. PII redaction layer mitigates accidental volunteering. Article 9 special-category data is the responsibility of Controller if it nonetheless arises.
F. Frequency of processing
Continuous, on-demand, for the duration of the Agreement.
G. Sub-processors
See Annex 2.
H. Third-country transfers
See Annex 3.
I. Retention
See Privacy Policy Section 9 and DPA Section 11. Default Call-recording retention 90 days, configurable 7 days–24 months.
J. Competent supervisory authority
For SCC purposes, the competent supervisory authority is the Polish UODO (Urząd Ochrony Danych Osobowych), where Controller is established in the EU/EEA and the EU Representative is in Poland; otherwise, Controller's lead supervisory authority.
Annex 2 — Sub-processors
Authorised Sub-processors as of the Effective Date. The current list is also published at /sub-processors and is updated in accordance with Section 6.
| Function | Sub-Processor | What we send | Region | Safeguards |
|---|---|---|---|---|
| Voice AI engine | ||||
| Voice AI orchestrator | Provider name not disclosed publicly (hidden-vendor policy) | Conversation orchestration: speech-to-text, intent routing, LLM coordination, text-to-speech | EU (zero-retention) | Signed DPA · zero-retention addendum · SCC Module 3 |
| LLM provider | OpenAI, OpenAI Ireland Ltd | Per-Call inference requests for selected GPT models | EU / US (zero-retention mode) | Signed DPA · SCC Module 3 · zero-retention addendum |
| LLM provider | Anthropic PBC | Per-Call inference requests for selected Claude models | US (zero-retention mode) | Signed DPA · SCC Module 3 · zero-retention addendum |
| LLM provider | Google LLC / Google Ireland Ltd | Per-Call inference requests for selected Gemini models | EU / US (zero-retention mode) | Signed DPA · SCC Module 3 · zero-retention addendum |
| TTS provider | ElevenLabs Inc. | Text-to-speech rendering of agent utterances | EU / US | Signed DPA · SCC Module 3 |
| TTS provider | Cartesia Inc. | Text-to-speech rendering of agent utterances | US | Signed DPA · SCC Module 3 |
| TTS provider | OpenAI voices (via OpenAI) | Text-to-speech rendering of agent utterances | EU / US (zero-retention) | See OpenAI row above |
| Telephony | ||||
| Telephony — primary | Twilio Inc. / Twilio Ireland Ltd | Outbound SIP trunking, PSTN delivery, inbound number provisioning, SMS where applicable | EU (Ireland) / US | Signed DPA · SCC Module 3 |
| Telephony — backup | Telnyx LLC | Backup SIP routing in failover scenarios | EU (Netherlands) / US | Signed DPA · SCC Module 3 |
| Telephony — selected markets | Vonage Holdings Corp. | Number provisioning and routing in selected markets | EU / US | Signed DPA · SCC Module 3 |
| Cloud infrastructure & data | ||||
| Hosting | Google Cloud Platform (Google Ireland Ltd / Google LLC) | Application compute, database storage, panel hosting, audit logs, encrypted backups, KMS | EU (Frankfurt eu-central-1, Warsaw europe-central2) | Signed DPA · SCC Module 3 · ISO 27001, SOC 2 Type II (provider) |
| Error monitoring | Sentry GmbH (subject to confirmation) | Application-error logs (PII redacted at SDK level) | EU (Germany) | Signed DPA · SCC Module 3 |
| Product analytics | PostHog Inc. or Plausible Insights OU (subject to selection) | Anonymised panel-usage analytics (consent-gated for marketing site) | EU | Signed DPA · SCC Module 3 |
| Billing & payments | ||||
| Payment processor & merchant of record | Stripe Payments Europe Ltd / Stripe Inc. | Subscription billing, payment-method storage (tokenised — Operator never sees full PAN), invoice generation, tax collection where applicable | EU (Ireland) / US | Signed DPA · SCC Module 3 · PCI DSS Level 1 (provider) · acts as independent controller for payment-card data |
| Communication & transactional messaging | ||||
| Transactional e-mail | Postmark (ActiveCampaign LLC) or Resend Inc. (subject to selection) | Operational e-mails — receipts, password resets, weekly reports, sub-processor change notices | EU / US | Signed DPA · SCC Module 3 |
| Storefront integration (controller, not Sub-Processor) | ||||
| Storefront / OAuth source | Shopify International Ltd / Shopify Inc. | OAuth handshake, order-event webhooks, catalog sync — Customer's relationship with Shopify is independent; Shopify is Customer's data controller for store data, not the Operator's Sub-Processor | Customer-determined (Shopify region) | Out of scope of this list — see Customer's contract with Shopify |
The voice-AI orchestrator's identity is not disclosed publicly per the Operator's hidden-vendor policy. The Operator commits to maintaining a zero-retention contractual relationship with the orchestrator and to switching to a comparable provider with at least 30 days' notice should the relationship change in any way that affects the safeguards in this DPA.
Annex 3 — Standard Contractual Clauses (SCCs) & Transfer Annexes
1. SCCs Modules incorporated
The SCCs in Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference, with the following Modules and elections:
- Module 2 (Controller-to-Processor): Controller is the data exporter; Processor is the data importer. This Module applies whenever Customer (as exporter, in the EU/EEA) transfers Personal Data to Processor in a third country.
- Module 3 (Processor-to-Sub-processor): Processor is the data exporter; Sub-processor is the data importer. This Module applies between Processor and each Sub-processor that is in a third country.
- Optional clauses elected: Clause 7 (Docking Clause); Clause 9(a), Option 2 (general written authorisation for sub-processing, with the 30-day notice and right-to-object mechanism in Section 6 of this DPA).
- Optional clauses NOT elected: Clause 11(a) optional independent dispute-resolution body — the Parties rely on the supervisory authority and competent courts as designated below.
2. UK Addendum
For transfers from the United Kingdom subject to UK GDPR, the UK International Data Transfer Addendum (B.1.0) issued by the ICO is incorporated by reference and modifies the SCCs to apply to UK data transfers. Where the ICO updates the Addendum, the updated version applies from its effective date.
3. Swiss adaptations
For transfers from Switzerland under the FADP, the Parties agree the SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP and revFADP; references to Member State law as Swiss law; the competent supervisory authority is the FDPIC; references to "EU/EEA" include Switzerland; legal entities domiciled in Switzerland are treated as Data Subjects to the extent the FADP grants them protection.
4. Annex I.A — List of Parties
Data exporter: Controller, as identified in the Agreement (Customer's account information).
Data importer: CallBotAgent, Inc., a Delaware corporation, 1111B S Governors Ave STE 39750, Dover, DE 19904, USA; telephone +1 (719) 624-4435. Activities: provision of voice-AI Service to data exporter as described in Annex 1. EU Representative under Article 27 GDPR: as identified in the Operator's Legal Notice.
5. Annex I.B — Description of Transfer
As described in Annex 1 (subject matter, categories of Data Subjects, categories of Personal Data, frequency, nature, purpose, retention, recipients).
6. Annex I.C — Competent Supervisory Authority
For Controllers in the EU/EEA: Polish UODO (Urząd Ochrony Danych Osobowych), as identified through the EU Representative in Poland — unless the Controller has its own lead supervisory authority for the relevant processing, in which case that authority is competent.
For Controllers in the UK: Information Commissioner's Office (ICO).
For Controllers in Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
7. Annex II — Technical and Organisational Measures
See Annex 4 for the description of the TOMs that satisfy the Annex II of the SCCs.
8. Annex III — List of Sub-processors
See Annex 2 and /sub-processors.
9. Local-law transfer impact assessment
Processor has assessed the laws and practices of each destination country relevant to its Sub-processor chain (in particular FISA 702, EO 12333, and CLOUD Act for US transfers; comparable laws elsewhere). Processor has determined that, in combination with the supplementary technical measures (encryption in transit and at rest with keys held under the EU representative's instruction; access controls; zero-retention with the orchestrator; pseudonymisation; redaction of PII in transcripts), the SCCs provide an essentially-equivalent level of protection. The TIA summary is maintained as an internal compliance record that informs the Processor's safeguard design.
Annex 4 — Technical & Organisational Measures (TOMs)
Processor implements and maintains the following measures, as required by Articles 28 and 32 GDPR.
1. Encryption
- Transport encryption: TLS 1.3 for all customer-facing traffic and inter-service traffic, with HSTS for the marketing site.
- At-rest encryption: AES-256 for all production data, including recordings, transcripts, configuration, and database storage.
- Key management: managed KMS (Google Cloud KMS) in the EU region; key rotation every 90 days; hardware-security-module (HSM) backing for production keys.
- Backups: encrypted with a separate key set from production keys (segregation of duties); retained 90 days; automatic destruction thereafter.
2. Access control
- Multi-factor authentication mandatory for admin accounts; Single Sign-On (SAML / OIDC) available for Enterprise on request.
- Role-based access control with least-privilege defaults; quarterly access reviews.
- Session timeouts; secure cookie flags; CSRF protection on all state-changing endpoints.
- Audit logs for access to End-Customer Personal Data, retained at least 12 months.
3. Network and host hardening
- Private networking between services; no direct public exposure of databases.
- Web application firewall and DDoS protection in front of the customer-facing edge.
- Vulnerability scanning of dependencies and base images on every build.
- Security patching SLA for production infrastructure.
- Penetration testing target: annual third-party penetration test (under setup).
4. Data minimisation and PII redaction
- PII redaction layer detects and replaces sensitive identifiers (card numbers, national IDs, e-mail addresses, surnames where configurable) in transcripts before write to long-term storage.
- Recording is opt-in per Customer; default-off for new accounts.
- Retention windows configurable; defaults are short (90 days for recordings).
- Aggregated and de-identified data used for product analytics where individual identifiability is not necessary.
5. Zero-retention with AI provider
- Voice-AI orchestrator and underlying LLM/TTS providers operate under contractual zero-retention restrictions.
- No use of Customer Personal Data to train, fine-tune, or evaluate any AI model.
- Each Sub-processor has signed a zero-retention addendum or equivalent.
6. Personnel
- Background checks for personnel with production access where permitted by local law.
- Confidentiality obligations in employment and contractor agreements.
- Annual security and privacy training; phishing simulations.
- Personnel separation procedure: revocation of access on day of departure.
7. Incident response
- 24/7 on-call rotation for production incidents.
- Documented incident-response runbook covering detection, containment, eradication, recovery, and post-incident review.
- Customer notification within 24 hours of becoming aware of any Personal Data Breach affecting Customer Personal Data (Section 9).
8. Software-development lifecycle
- Code review for all production changes.
- Automated tests run in CI; security scans in the pipeline.
- Separation of development, staging, and production environments.
- Change-management with rollback paths.
9. Business continuity and disaster recovery
- Multi-zone deployment in primary region; automated failover for stateful services.
- Backup verification at least quarterly.
- Recovery time objective (RTO) and recovery point objective (RPO) targets defined and tested annually; details maintained as internal operational documentation.
10. Sub-processor management
- Vetting before engagement: privacy and security questionnaire; review of sub-processor's certifications and DPAs; assessment of data-flow exposure.
- Contractual obligations imposing materially equivalent terms to this DPA on each Sub-processor.
- Annual review of active Sub-processors.
11. Compliance and certifications (status)
- SOC 2 Type II — target, longer term (we will publish a roadmap when committed).
- ISO 27001 — target, longer term.
- HIPAA — not applicable; we do not service the US healthcare market.
- PCI DSS — not applicable to Operator; payment-card data is processed by Stripe (PCI DSS Level 1) under Stripe's own controls.
Where a customer's compliance team requires additional or alternative measures, those can be negotiated in an Enterprise Order Form addendum.