Data Processing Addendum

How Ciaomatic processes caller personal data on behalf of its customers, under the GDPR and similar laws.

Version 1.0 (draft) · 11 July 2026

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between the customer ("Controller", "you") and [[ENTITY_LEGAL_NAME]] ("Processor", "Ciaomatic", "we"). It applies where we process personal data on your behalf in providing the Service and reflects the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and equivalent laws.

For the personal data contained in the calls your agents handle — call recordings, transcripts, and caller phone numbers, and related metadata — you are the controller and we are your processor. For your own account, billing, and usage data we act as controller, as described in our Privacy Policy.

Capitalized terms not defined here have the meaning given in the GDPR or the Terms. In case of conflict on data-protection matters, this DPA prevails over the Terms.

1. Details of the processing

Subject matter and duration

We process caller personal data to provide the Service for the duration of your subscription and any post-termination period described below.

Nature and purpose

Receiving and answering inbound calls with an AI voice agent; converting speech to text and generating spoken responses; optionally recording calls where you enable it; storing transcripts and call metadata; performing the actions you configure (such as creating bookings or sending emails through your connected integrations); and making this data available to you in the dashboard and via search, webhooks, and downloads.

Types of personal data

  • Caller phone numbers and the number dialed.
  • Audio recordings of calls (only where you enable recording).
  • Transcripts and derived text of conversations.
  • Any personal data a caller volunteers during a call (for example, name, appointment details, or reason for calling), and call metadata such as time, duration, and outcome.

You are responsible for what your agents ask for. You should not configure agents to collect special-category data (such as health information) unless you have a lawful basis under Article 9 and appropriate safeguards.

Categories of data subjects

The individuals who call the phone numbers you connect to the Service (your callers), and any third parties they mention.

2. Our obligations as processor

  • Process caller personal data only on your documented instructions, including the instructions embodied in your use of the Service and its configuration, unless required by law (in which case we will inform you unless prohibited).
  • Ensure that persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see Security below).
  • Respect the conditions for engaging subprocessors set out below.
  • Assist you, taking into account the nature of the processing, in responding to data-subject requests and in meeting your obligations regarding security, breach notification, data protection impact assessments, and prior consultation.
  • At your choice, delete or return caller personal data at the end of the provision of the Service, and delete existing copies unless retention is required by law.
  • Make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as described below.

We will inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.

3. Subprocessors

You authorize us to engage the following subprocessors to process caller personal data in providing the Service:

  • Twilio — telephony, call routing, and optional call recording.
  • OpenAI — AI voice models processing call audio and text in real time.
  • Cloudflare — hosting, storage of recordings and transcripts, and infrastructure.
  • Stripe — payment processing (billing and usage metadata; not call content).
  • Clerk — authentication (account users; not call content).
  • Resend — transactional email delivery (notifications; not call content).

We impose data-protection obligations on each subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give you reasonable notice of any intended addition or replacement of a subprocessor and an opportunity to object on reasonable data-protection grounds.

4. International transfers

Some subprocessors process data outside the European Economic Area or the United Kingdom, including in the United States. Where such transfers occur, they are made under appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

5. Retention of caller data

Retention windows for caller data are configurable per organization so you can align them with your own retention policy and legal basis:

  • Call recordings: recording is off by default; when enabled, recordings are retained for an organization-configurable period, which defaults to 30 days, after which they are deleted automatically.
  • Transcripts and call records: retained for an organization-configurable period, which defaults to 365 days, after which they are deleted automatically.

You are responsible for choosing retention periods consistent with your obligations. On termination of the Service, or on your instruction, we will delete or return caller personal data as described in our obligations above, subject to any short technical delay for backups and to any retention required by law.

6. Data subject requests

The Service gives you tools to access, search, export, and delete caller data. If a data subject contacts us directly with a request relating to data we process on your behalf, we will refer them to you and, where appropriate, notify you, and we will assist you in responding.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting caller personal data we process for you, and provide information reasonably available to us to help you meet your notification obligations.

8. Security

We maintain technical and organizational measures appropriate to the risk, including: encryption of integration secrets and credentials; access controls and least-privilege administration; separation of customer organizations; signed, time-limited access tokens for stored media; audit logging of administrative actions; and use of reputable infrastructure providers. Recordings are stored access-controlled and served only through signed, expiring links.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA. Where you reasonably require an audit, we may satisfy it through documentation and, where genuinely necessary, a supervised review, subject to reasonable notice, confidentiality, and cost arrangements, and without compromising other customers' data or our security.

10. Liability and governing law

Each party's liability under this DPA is subject to the limitations of liability in the Terms. This DPA is governed by the law and jurisdiction stated in the Terms ([[GOVERNING_LAW]]; courts of [[JURISDICTION_VENUE]]), except where mandatory data-protection law requires otherwise. For DPA questions, contact [[PRIVACY_CONTACT_EMAIL]].