Legal
Data processing agreement
The terms on which CallAgent processes personal data on your behalf: what we are allowed to do with it, who else touches it, how it is protected, and what happens to it when you leave.
A working draft, not a final text
This text describes the system accurately and has not been reviewed by a lawyer. Read it as the engineering half of a data processing agreement — the half that says what actually happens — rather than as a signed contract. If you need a counter-signed DPA to buy, ask, and expect the conversation to start from this page.
Who is the controller
You are the controller. You decide which calls happen, what the assistant says, whether the call is recorded and how long anything is kept. CallAgent is your processor and acts on your instructions.
There is a second layer that most voice DPAs skip and it changes the analysis, so it is stated first. Transcription, model and speech vendors are configured with your own API keys. When your assistant sends audio to ElevenLabs it is sent on your account, under your contract with that vendor — CallAgent is passing it on, not sub-contracting it. Where the platform's own key is used instead, the vendor is our sub-processor in the ordinary sense. The sub-processor page marks which is which.
For the personal data of the people who work for you — names, addresses, roles, sign-in records, billing — CallAgent is the controller, and the privacy policy covers that.
| Controller | You, for everything about a call and everybody on one. |
|---|---|
| Processor | CallAgent, acting on your documented instructions. |
| Your keys | A vendor you configured with your own key is your processor, not our sub-processor. |
| Account data | CallAgent is the controller for your users, billing and audit records. |
Subject matter, duration and categories
The processing is the operation of a voice platform: placing and answering telephone calls, converting speech to text and text to speech, running a language model over the conversation, recording the audio if you have turned recording on, and keeping the resulting records available to you in the console and over the API.
It lasts for as long as your account does, plus whatever retention window you have configured for each category of record.
The categories below are not a template list. They are what a call actually leaves behind in this system, taken from the tables the call writes to.
| Data subjects | Everybody on a call: your customers, your staff, and anybody a caller mentions. |
|---|---|
| Identifiers | E.164 telephone numbers on both legs, caller names when the carrier supplies them, call and session ids. |
| Content | The transcript, the messages exchanged with the model, tool arguments and results, and the audio recording when enabled. |
| Technical | Timestamps to the millisecond, event payloads, latency metrics, costs per provider, the ended reason. |
| Special categories | Not intended, and not filtered out. A caller can say anything, and in a clinic or a lender they will. See the retention and redaction controls. |
| Your users | Name, email address, role, organization membership, API key metadata, audit records. |
What we do without being asked
Personal data is processed only to run the service and only on your instructions, which are given by your configuration: an assistant, a phone number, a recording policy, a retention policy, a set of tools.
Three things happen without a per-call instruction, and each is listed because a processor that acts on its own initiative has to say so. A scheduled job applies your retention policy every night at 03:15 and deletes what is past it. Personal-data redaction, if you have switched it on, rewrites transcripts after the call. And an audit record is written whenever a member of your organization changes something, which we keep because a processor that cannot say who changed what is not a processor anybody should use.
Call content is not used to train any model of ours, because there is no model of ours. What the vendors you configure do with it is governed by your contract with them, and it is worth reading: the default for a consumer-grade API key is often not the default for a business one.
| Retention job | Daily, 03:15. Applies your policy without asking. |
|---|---|
| Redaction | Post-call, only if you enabled it. Off by default. |
| Audit log | Always on. Entries cannot be deleted, only aged out — and no retention window currently covers them. |
| Training | We train nothing on your calls. Vendor behaviour is your contract with the vendor. |
Who can reach the data, honestly
Article 28 asks for a commitment that everybody authorised to process the data is under a duty of confidentiality. Here is the true position rather than the clause.
CallAgent is written and operated by one person. There is no support team, no offshore operations desk and no queue of contractors with production access — and equally, there is no separation of duties, no second pair of eyes on a production query, and nobody to escalate to at three in the morning. Whether that is better or worse than a rota of twelve people you have never met depends on what you are worried about, and you should decide which with the facts rather than with a clause that implies a staff.
Within your own organization, access is by role over a catalogue of permissions, every model that belongs to a customer carries an organization scope applied at query level, and reading a recording goes through a signed URL that expires in fifteen minutes.
| Platform staff | One person, who is also the developer and the operator. |
|---|---|
| Separation of duties | None. Stated because the absence is the risk. |
| Your side | Roles and permissions, scoped per organization. |
| Recording access | Signed URL, 15 minutes, and the request is audited. |
The measures that actually exist
Isolation between organizations is a global query scope on every customer-owned model rather than a filter written into each controller, so a query with no tenant bound returns nothing rather than everything. Tenant resolution runs before route-model binding, which is the order that stops a request for another organization's id from resolving a real row before a policy runs. Queued work binds its tenant explicitly, because a job running an hour later has no request to inherit one from.
Customer storage credentials and provider API keys are encrypted with a key that is deliberately not the application key, so rotating one does not lock you out of your own recordings and leaking the other does not hand over every tenant's S3 account.
What is missing is on the security page and is not repeated softly here: no SOC 2, no ISO 27001, no third-party penetration test, no HIPAA or PCI attestation, and the compliance mode flags on an organization are inert.
| Isolation | Global scope at query level; middleware ordered so binding cannot precede the tenant. |
|---|---|
| Credentials | Encrypted under a separate credential key, not the application key. |
| Transport | TLS to every provider endpoint; SRTP available on the media path. |
| Object access | Signed URLs expiring in 15 minutes; no public bucket path. |
| Certification | None. No audit has been started. |
Sub-processors, and the gap in the chain
The live list is published, generated from the same registry the console reads, so it cannot describe a vendor that is no longer selectable or omit one that has just become selectable.
General authorisation is what this agreement assumes: you authorise the vendors on that list, and we tell you before a new one is added. The notice period we are willing to commit to is thirty days, and the honest qualification is that the mechanism today is a person sending an email to the account owner. There is no automated sub-processor notification and no subscribe button. When there is one it will be on that page.
The gap that a template would not mention: there is no signed Article 28(4) agreement between CallAgent and any of these vendors. For the ones you configure with your own key that matters less, because your contract with them is the one in force. For anything running on a platform key it matters, and it is the reason this document is not offered as a finished DPA.
| The list | Published and generated from the registry, not written by hand. |
|---|---|
| Notice | 30 days before a new sub-processor, by email to the account owner. |
| Objection | You may object in writing; if we cannot avoid the change you may terminate. |
| Onward agreements | None signed. Stated plainly rather than implied. |
Helping you answer, and telling you when it breaks
When somebody exercises a right against you, we help you answer it. What that help consists of today is on the data-rights page in detail, and the summary is that call search by telephone number works, recording deletion works, and there is no one-click export of everything the system holds about one person.
On a personal data breach: we will tell you without undue delay and within seventy-two hours of becoming aware, with what we know at the time rather than waiting for a complete picture. There is no automated detection that would find a breach for us, so "becoming aware" means what it says.
We will also tell you if an instruction of yours looks to us like it infringes the Regulation, which is the clause nobody reads until the day it matters.
| Rights requests | Assisted, partly manual. Details on the data-rights page. |
|---|---|
| Breach notice | Without undue delay, at most 72 hours after we become aware. |
| Detection | No automated breach detection. Health monitoring is not the same thing. |
| Unlawful instruction | We will say so rather than carry it out quietly. |
The data leaves the Union
Say it in one sentence, because a document that makes a buyer hunt for this has already lost their trust: with the default configuration, the audio of every call goes to a vendor in the United States, and so does the text of every turn.
The installation's own database and object storage sit in the region it is configured for, which starts as the European Union. That covers the copy we hold. It does not cover the vendors, and the vendors are where the speech actually goes: the default pipeline is ElevenLabs for transcription and speech, Anthropic for the model and Twilio for the carrier, all of them United States companies.
The transfer mechanism is therefore whatever your own contract with each vendor provides — standard contractual clauses, an adequacy decision, or a certification. We have not carried out a transfer impact assessment on your behalf and we do not hold one. If EU-only processing is a requirement rather than a preference, the honest answer today is that this configuration does not give it to you, and the first thing to look at is a European transcription vendor and a model endpoint in an EU region.
| Our copy | Region-configured; European Union by default. |
|---|---|
| Default vendors | ElevenLabs, Anthropic and Twilio. All United States. |
| Mechanism | Your contract with each vendor. We hold no onward agreement. |
| Transfer impact assessment | Not carried out. No document to send you. |
Return and deletion
On termination, your choice: everything deleted, or made available to you for export first and then deleted. The export path is the API, which pages through calls, transcripts and events, and — if you brought your own bucket — your own bucket, which already holds the recordings and the artefacts and does not need our permission.
The erasure that runs is real rather than a status change. Message content, tool arguments and results, event payloads, transcripts, summaries and structured outputs are set to null; recordings and artefacts are deleted from the object store and the row is marked purged. What survives is the shape of the call: its identifiers, the two telephone numbers, timestamps, duration, billable seconds, the ended reason, cost rows and the audit log.
That last sentence is the one to argue with your DPO about, because it is a deliberate design decision and it is not what "deleted" sounds like. The numbers survive so that a billing dispute can be answered and so that an audit record is not orphaned. If you need the numbers gone too, say so before you sign; today that is a manual database operation rather than a button.
| Content | Nulled: transcripts, messages, tool arguments and results, event payloads, summaries. |
|---|---|
| Audio | Deleted from the object store; the artefact row survives marked purged. |
| Survives | Call ids, both E.164 numbers, timestamps, duration, cost rows, the audit log. |
| Export | Over the API, and directly from your bucket if you brought one. |
| Deadline | 30 days from termination unless you ask for the export window first. |
What this agreement cannot promise yet
Collected in one place rather than distributed through the clauses above, because a reader who skims should still meet them.
No signed onward agreements with sub-processors. No transfer impact assessment. No certification of any kind and no audit started. No automated sub-processor notification. No self-service data-subject export. Deleting a call over the API is a soft delete and leaves the content in place — erasure runs through retention, not through that endpoint. And there is no interface for a customer to set their own retention policy: today it is set for you, from the platform side.
Any one of those may be a reason not to buy. They are here so that it can be a reason now rather than in the third week of a procurement review.
| Onward DPAs | None signed with any sub-processor. |
|---|---|
| Retention self-service | No customer-facing interface. Set from the platform side. |
| Call deletion API | Soft delete. Content and audio survive it. |
| Subject export | Not built. |
| Certification | None. |
A route to a person, which is the point of publishing this
A DPA nobody can ask a question about is a PDF. If your review turns up something this page does not cover, or something it gets wrong, the form reaches the person who wrote it.
The other European documents
None of the seven documents in this set has been through a lawyer. They are engineering statements about a running system, published because a wrong description is worse than a missing one, and they will be reviewed before anybody is asked to sign anything.