Back to callgentic.com

Data Processing Addendum

Effective 6 October 2026

Callgentic's commitments as a processor and service provider when our agents handle personal data for a business customer. It forms part of our Business Terms.

1. Scope and roles

  1. This Data Processing Addendum ("DPA") applies when Callgentic Inc. ("Callgentic") processes personal data on behalf of a customer ("Customer") under our Business Terms and an Order.
  2. The Customer is the controller (or "business" under California law, or "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023). Callgentic is the processor (or "service provider", or "Data Processor").
  3. "Customer Personal Data" means personal data that Callgentic processes for the Customer through the services. "Data Protection Laws" means the laws that apply to that processing, which can include the GDPR, the UK GDPR, the California Consumer Privacy Act as amended (CCPA), the DPDP Act and other US state privacy laws.

2. Processing on instructions

  1. Callgentic processes Customer Personal Data only on the Customer's documented instructions, which are the agreement, the Order and the Customer's configuration of its agents, unless the law requires otherwise, in which case we will tell the Customer first where allowed.
  2. We will tell the Customer if we believe an instruction breaks Data Protection Laws.
  3. The details of the processing are in Annex 1.

3. Confidentiality

Everyone at Callgentic and its subprocessors who can access Customer Personal Data is bound by confidentiality obligations and accesses it only as needed to provide the services.

4. Security

Callgentic maintains the technical and organisational measures in Annex 2 and on our Security & HIPAA page, and may improve them over time without lowering the overall level of protection.

5. Subprocessors

  1. The Customer gives general authorisation for Callgentic to use the subprocessors listed on our Subprocessors page.
  2. We will give at least 30 days' notice before adding or replacing a subprocessor, by updating that page and emailing customers who ask to be notified. The Customer may object on reasonable data protection grounds; if we cannot resolve the objection, the Customer may end the affected service and receive a refund of prepaid fees for the unused period.
  3. We impose data protection terms on each subprocessor that are at least as protective as this DPA, and remain responsible for their performance.

6. Helping the Customer

  1. We will help the Customer, through the services or on request, to respond to requests from people exercising their rights, such as access, correction and deletion.
  2. If we receive such a request directly, we will pass it to the Customer and not answer it ourselves unless the Customer tells us to.
  3. We will give reasonable help with data protection impact assessments and consultations with regulators, as far as they concern our services.

7. Personal data breaches

We will notify the Customer without undue delay, and within 72 hours after confirming a personal data breach affecting Customer Personal Data. The notice will describe what happened, the data and people likely affected, the likely consequences, and what we are doing about it, and we will update it as we learn more.

8. Deletion and return

When the services end, the Customer may export its Customer Personal Data for 30 days. After that we delete it, unless the law requires us to keep it. Copies in encrypted backups expire within a further 30 days and are not restored in the meantime.

9. Audits

  1. We will make available the information reasonably needed to show compliance with this DPA, including answers to a security questionnaire once a year.
  2. If Data Protection Laws require an audit beyond that, the Customer may carry one out, at its own cost, with at least 30 days' notice, during business hours, without access to other customers' data, and under confidentiality terms.

10. International transfers

Customer Personal Data is stored in the United States by default, or in India where the Customer chooses. Where Data Protection Laws restrict a transfer from the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK International Data Transfer Addendum are incorporated into this DPA by reference, with Callgentic as data importer and Delaware, USA as the place of the governing law where a choice is allowed.

11. California (CCPA) terms

Callgentic will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than providing the services or outside our direct business relationship with the Customer; will not combine it with personal information from other sources except as the CCPA permits; will comply with the CCPA and provide the same level of privacy protection it requires; and will notify the Customer if we can no longer meet these obligations. Callgentic certifies that it understands these restrictions.

12. Health information

Protected health information under HIPAA is processed only under a separate Business Associate Agreement, which takes precedence over this DPA for that information.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Business Terms, except where Data Protection Laws do not allow them. If this DPA conflicts with the Business Terms, this DPA wins for the processing of Customer Personal Data.

Annex 1: Details of processing

  • Subject matter and duration: providing the services for the term of the agreement, and up to 30 days after it ends.
  • Nature and purpose: answering and placing calls, sending and receiving messages, transcribing and understanding speech, generating replies, booking and recording outcomes, and passing data to the Customer's systems, on the Customer's instructions.
  • People concerned: the Customer's callers, customers, patients, leads and contacts, and the Customer's staff.
  • Types of data: names, phone numbers, email addresses, call audio, transcripts, recordings where enabled, messages, appointment and order details, and anything people choose to say during a call.
  • Sensitive data: only as the Customer's use case requires and instructs. Health information only under a Business Associate Agreement.
  • Retention: as the Customer sets in its configuration, and in any case deleted as section 8 describes.

Annex 2: Security measures

  • Hosting on Amazon Web Services, with encryption in transit (TLS) and at rest (AES-256).
  • Network access limited to web traffic and our carriers' addresses; no password logins to servers; administrator access through AWS Systems Manager.
  • Least-privilege access for staff and systems, with credentials kept out of source code.
  • Daily encrypted backups with limited retention.
  • Verification of signed requests from carriers and messaging platforms.
  • Rate limits and abuse controls on public endpoints.
  • Testing of agents before launch, and logging and monitoring in production.
  • An incident response process that includes customer notification under section 7.