Data Processing Agreement (DPA)

Effective date: [SERVICE START DATE]

Between [COMPANY NAME] (Processor) and the Customer (Controller)

This DPA forms part of, and is incorporated into, the main service agreement/order between the parties.

1. Parties

  • Processor: [COMPANY NAME], [REGISTERED SEAT], Tax ID [TAX ID], [DPA EMAIL].
  • Controller (Customer): [CUSTOMER NAME], [CUSTOMER ADDRESS/SEAT], Tax ID [CUSTOMER TAX ID], [CUSTOMER EMAIL].

2. Subject matter, duration, nature, and purpose

Processing concerns provision of the AI phone receptionist service as described in the Terms and the order/subscription. Processing lasts for the term of the Customer's use, plus any period needed for return or deletion of data after termination as set out herein.

3. Types of data and categories of data subjects

Data may include:

  • caller and contact identity and contact data (name, phone number, email as spoken or dictated),
  • Call Content (recordings, transcripts, notes, summaries),
  • call metadata (timestamps, duration, numbers, routing),
  • Customer user account data (email, roles, settings),
  • scripts, instructions, and operational data provided by the Customer.

Data subjects may include callers, the Customer's clients and prospects, employees or contractors, and any other person participating in a call.

4. Controller obligations

The Customer:

  • determines the purposes and means of processing,
  • ensures a lawful basis and provides all required notices and consents, including clear disclosure that callers interact with an AI system and, where recording is enabled, disclosure that calls are recorded and the related privacy information,
  • ensures compliance with confidentiality of communications (Greek Law 3471/2006) and any sectoral or professional obligations,
  • provides documented instructions to the Processor.

5. Processor obligations

The Processor:

  • processes personal data only on documented instructions of the Customer, as reflected in the agreement, settings, and written instructions,
  • immediately informs the Customer if it considers that an instruction infringes the GDPR or other data-protection law,
  • ensures authorised persons are bound by confidentiality,
  • implements appropriate technical and organisational measures as described in Section 10,
  • assists the Customer with data subject requests, to the extent feasible given the nature of processing,
  • assists with security, breach notifications, and DPIAs/prior consultations, to the extent required and feasible,
  • makes available information reasonably necessary to demonstrate compliance and allows audits under Section 12.

6. Sub-processors

The Customer authorises the Processor to use sub-processors to provide the Service. The Processor ensures sub-processors are bound by data-protection obligations substantially equivalent to this DPA.

A list of sub-processors is available at [SUBPROCESSORS URL] and includes, where used, ElevenLabs for voice AI functionality.

The Processor will notify the Customer of material changes via [NOTICE METHOD], allowing a reasonable objection period of [DAYS] days. Where a substantiated objection cannot be resolved, the parties will seek a good-faith solution, including disabling the affected feature.

7. Transfers outside the EEA – United States – ElevenLabs

Where processing involves transfers outside the EEA, including to the United States via ElevenLabs, the parties agree that such transfers will be covered by an appropriate transfer mechanism, which may include:

  • the European Commission adequacy decision 2023/1795, where applicable to the specific recipient/certification and data flow,
  • and/or the European Commission Standard Contractual Clauses (SCC), implemented via an addendum/contract between Controller and Processor and/or with the sub-processor, depending on roles and data flows.

Upon request, the Processor will make available relevant transfer commitments to the extent permitted by confidentiality and trade secrets.

8. Special category data

The Service is not intended to process special category data. The Customer must not configure the Service to solicit such data unless it has ensured all lawful conditions and appropriate safeguards and has informed the Processor in writing. The Processor may refuse or restrict such processing for compliance and security reasons.

9. Return and deletion

During the term, the Processor will make Customer Data available via export features provided by the Service.

After termination, the Processor will delete or return Customer Data within [DELETION PERIOD] days unless retention is required by law.

Backups may be retained for a limited period under backup policies and will be deleted or overwritten in due course.

10. Technical and organisational measures (TOMs)

The Processor maintains measures which may include, depending on availability and architecture:

  • role-based access control and least privilege,
  • encryption in transit (TLS) and, where applicable, encryption at rest,
  • audit logging and security monitoring,
  • environment segregation and change controls,
  • vulnerability management and security testing,
  • backup and recovery procedures,
  • staff training and confidentiality controls.

The Processor may update measures provided the overall security level is not materially reduced.

11. Personal data breach

The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data and will provide available information on the nature, impacted data, and mitigation measures, to the extent feasible.

12. Audits and compliance evidence

Upon written request at reasonable intervals, the Processor will provide information reasonably necessary to demonstrate compliance.

Any on-site or exceptional audit will be performed:

  • with [DAYS] days' prior notice,
  • during business hours,
  • under confidentiality and with minimal service disruption,
  • at the Customer's cost unless material non-compliance of the Processor is demonstrated.

13. Confidentiality

Each party must keep confidential the information received under this DPA, including security measures, unless disclosure is required by law.

14. Precedence

In case of conflict between this DPA and the main agreement, this DPA prevails regarding data protection.

15. Signatures

[PLACE], [DATE]

  • For the Customer: [NAME/TITLE/SIGNATURE]
  • For [COMPANY NAME]: [NAME/TITLE/SIGNATURE]