This Data Processing Addendum ("Addendum") is entered into by and between DoorCall AI, Inc., a Delaware corporation ("Processor," "DoorCall AI," "we," "us," or "our"), and the Customer identified in, and a party to, the Terms of Service ("Controller," "Customer," or "you"), and forms part of, and is incorporated by reference into, the Terms of Service entered into between the parties (the "Agreement"). This Addendum applies automatically, without further action by either party, from the date on which Customer first processes Personal Data through the Services and for so long as DoorCall AI processes Personal Data on Customer's behalf. Capitalized terms not defined in this Addendum have the meanings given in the Agreement or the Privacy Policy.
1. Definitions
1.1 "Applicable Data Protection Law" means all data protection and privacy law applicable to the processing of Personal Data under this Addendum, including, as applicable, the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other United States state comprehensive privacy statutes.
1.2 "Controller," "Processor," "Data Subject," "Personal Data," "Processing" (and "process," "processes," and "processed" as the grammar requires), "Special Categories of Personal Data," and "Supervisory Authority" have the meanings given in the GDPR, and the terms "Business," "Service Provider," "Consumer," and "Sale" (and their cognates) have the meanings given in the CCPA, in each case as the context of this Addendum requires and without duplication of obligation.
1.3 "Data Subject" as used in this Addendum includes a Caller and any other natural person whose Personal Data is processed by DoorCall AI on Customer's behalf.
1.4 "EU SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
1.5 "Personal Data" means Caller Data and Account Data, as those terms are defined in the Privacy Policy, to the extent such data constitutes personal data or Personal Information under Applicable Data Protection Law and is processed by DoorCall AI on Customer's behalf in the provision of the Services.
1.6 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by DoorCall AI under this Addendum.
1.7 "Subprocessor" means a third party engaged by DoorCall AI to process Personal Data on Customer's behalf in connection with the Services, including an affiliate of DoorCall AI where such affiliate processes Personal Data.
1.8 "UK Addendum" means the International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018, version B1.0, in force from 21 March 2022.
2. Roles and Scope of Processing
2.1 Roles of the Parties. As between the parties, and with respect to Personal Data processed in connection with the Services, Customer is the Controller (or, under the CCPA, the Business) and DoorCall AI is the Processor (or, under the CCPA, the Service Provider). Where Applicable Data Protection Law characterizes Customer as a Processor with respect to particular Personal Data, DoorCall AI is a Subprocessor with respect to that Personal Data, and the parties will cooperate in good faith to give effect to the terms of this Addendum consistently with that characterization.
2.2 Details of Processing. The subject matter, duration, nature, and purpose of processing, the categories of Personal Data, and the categories of Data Subjects are set out in Schedule 1 to this Addendum, which forms part of, and is incorporated into, this Addendum.
2.3 Processing Instructions. DoorCall AI will process Personal Data only: (a) in accordance with Customer's documented instructions, which consist of the Agreement, this Addendum, Customer's configuration of the Services, and any further written instruction given by Customer and acknowledged by DoorCall AI; (b) as necessary to provide, secure, and support the Services; and (c) as required by applicable law, in which case DoorCall AI will, unless prohibited from doing so by that law, inform Customer of the legal requirement before processing, or, where prior notice is prohibited, as soon as that prohibition is lifted.
2.4 Notification of Unlawful Instruction. DoorCall AI will promptly notify Customer if, in its reasonable opinion, an instruction given by Customer infringes Applicable Data Protection Law, and DoorCall AI may suspend performance of that instruction pending Customer's confirmation or modification of it.
2.5 No Sale or Sharing. DoorCall AI will not sell Personal Data, will not share Personal Data for cross-context behavioral advertising, and will not retain, use, or disclose Personal Data for any purpose other than the specific purpose of providing the Services under the Agreement, including any commercial purpose other than that specific purpose, except as permitted by Applicable Data Protection Law. DoorCall AI certifies that it understands and will comply with the restrictions in this Section 2.5.
3. Personnel
DoorCall AI will ensure that personnel authorized to process Personal Data have committed themselves to confidentiality, whether by contractual or statutory obligation, and that access is limited to personnel for whom access is necessary to perform their duties in connection with the Services.
4. Security Measures
4.1 Technical and Organizational Measures. DoorCall AI will implement and maintain the technical and organizational measures described in Schedule 2 to this Addendum, designed to ensure a level of security appropriate to the risk presented by the processing, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
4.2 Assessment of Risk. DoorCall AI has taken into account the risks presented by processing, including from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, in designing the measures described in Schedule 2.
4.3 No Diminishment. DoorCall AI will not materially diminish the overall security of the Services during the term of the Agreement.
5. Subprocessors
5.1 General Authorization. Customer provides general written authorization for DoorCall AI to engage Subprocessors to process Personal Data in connection with the Services, subject to the requirements of this Section 5.
5.2 Current Subprocessors. The Subprocessors currently engaged by DoorCall AI, identified by name, function, and location of processing, are listed at doorcall.ai/legal/subprocessors ("Subprocessor List"), which is incorporated into this Addendum by reference.
5.3 Notice of New Subprocessors. DoorCall AI will update the Subprocessor List, and will provide Customer notice by electronic mail or through the Services, at least fifteen (15) days before authorizing a new Subprocessor to process Personal Data, except where a shorter period is necessary to address an urgent operational or security requirement, in which case DoorCall AI will provide notice as far in advance as reasonably practicable.
5.4 Objection. Customer may object to DoorCall AI's engagement of a new Subprocessor on reasonable data protection grounds by notifying DoorCall AI in writing within ten (10) days of the notice described in Section 5.3. Where Customer objects, the parties will discuss the objection in good faith with a view to reaching a resolution. Where the parties do not reach a resolution within thirty (30) days of Customer's objection, either party may terminate the Agreement solely to the extent it relates to the Services that cannot be provided without the objected-to Subprocessor, by written notice to the other party, without further liability to either party other than for fees accrued prior to the effective date of termination and any refund due under Section 6.5 of the Terms of Service.
5.5 Subprocessor Obligations. DoorCall AI will engage each Subprocessor under a written agreement imposing data protection obligations materially no less protective of Personal Data than those imposed on DoorCall AI under this Addendum, appropriate to the nature of the services provided by that Subprocessor. DoorCall AI remains liable to Customer for the acts and omissions of its Subprocessors in connection with the processing of Personal Data to the same extent DoorCall AI would be liable if performing the Subprocessor's services directly under this Addendum.
6. Assistance to Controller
6.1 Data Subject Requests. Taking into account the nature of the processing, DoorCall AI will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to enable Customer to respond to a request from a Data Subject to exercise rights under Applicable Data Protection Law. Where DoorCall AI receives a request directly from a Data Subject concerning Personal Data it processes on Customer's behalf, DoorCall AI will not respond to that request other than to acknowledge receipt and direct the Data Subject to Customer, except where DoorCall AI is legally required to respond, and will promptly forward the request to Customer.
6.2 Data Protection Impact Assessments. DoorCall AI will provide reasonable assistance to Customer with any data protection impact assessment, and any related consultation with a Supervisory Authority, that Customer reasonably considers necessary in connection with the processing of Personal Data under the Agreement, taking into account the nature of processing and the information reasonably available to DoorCall AI.
6.3 Security and Breach Obligations. DoorCall AI will provide reasonable assistance to Customer in complying with Customer's obligations under Articles 32 through 36 of the GDPR, or equivalent provisions of other Applicable Data Protection Law, taking into account the nature of processing and the information reasonably available to DoorCall AI.
7. Personal Data Breach Notification
7.1 Notification. DoorCall AI will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer's behalf.
7.2 Content of Notification. The notification will describe, to the extent then known and as subsequently supplemented as further information becomes available: the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned; the name and contact details of a point of contact from whom further information may be obtained; the likely consequences of the Personal Data Breach; and the measures taken or proposed to be taken by DoorCall AI to address the Personal Data Breach, including measures to mitigate its possible adverse effects.
7.3 Cooperation. DoorCall AI will cooperate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation, and remediation of a Personal Data Breach.
7.4 No Admission. Notification of, or response to, a Personal Data Breach under this Section 7 is not an acknowledgment by DoorCall AI of fault or liability with respect to the Personal Data Breach.
8. Audit Rights
8.1 Information and Compliance Reports. DoorCall AI will make available to Customer, on written request not more than once in a twelve (12) month period, information reasonably necessary to demonstrate DoorCall AI's compliance with this Addendum, which may consist of a summary of DoorCall AI's then-current security certifications, audit reports, or equivalent documentation.
8.2 Audit. Where the information provided under Section 8.1 is not reasonably sufficient to demonstrate compliance, or where required by a Supervisory Authority, Customer, or an independent third-party auditor bound by confidentiality obligations and reasonably acceptable to DoorCall AI, may conduct an audit of DoorCall AI's data processing facilities and records relevant to the processing of Personal Data under this Addendum, subject to: (a) not less than thirty (30) days' prior written notice; (b) execution of a mutually acceptable confidentiality agreement; (c) the audit being conducted during normal business hours, in a manner designed to minimize disruption to DoorCall AI's business, and not more than once in a twelve (12) month period, except following a Personal Data Breach or where required by a Supervisory Authority; and (d) Customer bearing its own costs of the audit and reimbursing DoorCall AI's reasonable costs of facilitating it, unless the audit identifies a material non-compliance with this Addendum, in which case DoorCall AI will bear its own reasonable costs of facilitating that audit.
8.3 Regulatory Audits. Where a Supervisory Authority with jurisdiction over Customer exercises a statutory audit right directly against DoorCall AI in respect of Personal Data processed under this Addendum, DoorCall AI will cooperate with that audit to the extent required by Applicable Data Protection Law.
9. International Data Transfers
9.1 Application. This Section 9 applies where Customer's transfer of Personal Data to DoorCall AI, or DoorCall AI's onward transfer of Personal Data to a Subprocessor, is a restricted transfer under Applicable Data Protection Law, meaning a transfer from a jurisdiction whose law restricts transfer of personal data to a jurisdiction not recognized by the exporting jurisdiction as providing an adequate level of protection.
9.2 EU and Swiss Transfers. Where the GDPR applies to the transfer, the parties adopt and incorporate by reference the EU SCCs, and complete them as follows: Module Two (Controller to Processor) applies to the transfer of Personal Data from Customer to DoorCall AI, and Module Three (Processor to Processor) applies to DoorCall AI's onward transfer of Personal Data to a Subprocessor acting as a processor on Customer's behalf; the optional docking clause in Clause 7 is not incorporated; in Clause 9, Option 2 (general written authorization) applies, and the time period for prior notice of Subprocessor changes is as set out in Section 5.3 of this Addendum; in Clause 11, the optional language concerning an independent dispute-resolution body is not incorporated; the governing law for purposes of Clause 17 is the law of Ireland, and the competent courts for purposes of Clause 18(b) are the courts of Ireland; Annex I of the EU SCCs is populated with the information in Schedule 1 to this Addendum; and Annex II of the EU SCCs is populated with the information in Schedule 2 to this Addendum. Where the Swiss Federal Act on Data Protection applies to the transfer, the EU SCCs apply as adapted to the extent required by that Act, including that references to the GDPR are read as references to the Swiss Federal Act on Data Protection where required, and that the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
9.3 United Kingdom Transfers. Where the UK GDPR applies to the transfer, the parties adopt and incorporate by reference the UK Addendum, and the EU SCCs as modified by the UK Addendum apply to the transfer in place of the EU SCCs described in Section 9.2, with the EU SCCs completed as set out in Section 9.2 for purposes of the UK Addendum's incorporation mechanism.
9.4 Alternative Transfer Mechanism. Where a new, amended, or replacement transfer mechanism is approved for use under Applicable Data Protection Law, the parties will negotiate in good faith to adopt that mechanism in place of the mechanism described in this Section 9, to the extent required to maintain a lawful basis for the transfer.
9.5 Supplementary Measures. DoorCall AI has implemented the supplementary technical measures described in Schedule 2 to this Addendum, including encryption of Personal Data in transit and at rest, to address the risk that Personal Data transferred internationally may be accessed by a public authority in the recipient jurisdiction, and will notify Customer promptly if DoorCall AI becomes aware that it is unable to comply with the EU SCCs, the UK Addendum, or an obligation under this Section 9.
10. Deletion and Return of Personal Data
10.1 During the Term. DoorCall AI will delete Personal Data in accordance with the retention schedule set out in Section 15 of the Privacy Policy and Customer's configuration of retention settings within the Services, where such configuration is made available.
10.2 On Termination. Upon termination or expiry of the Agreement, and following the thirty (30) day recovery period described in Section 15.5 of the Terms of Service, DoorCall AI will delete all Personal Data processed on Customer's behalf, except to the extent applicable law requires DoorCall AI to retain some or all of the Personal Data, in which case DoorCall AI will isolate that Personal Data from further processing and delete it once the applicable retention requirement lapses. Customer may request, prior to the expiry of the recovery period, an export of its Personal Data in the format made available through the Services.
10.3 Certification. DoorCall AI will, upon Customer's written request, confirm in writing that it has complied with its obligations under this Section 10.
11. California Consumer Privacy Act
11.1 Service Provider Certification. DoorCall AI certifies that it understands the restrictions in Section 2.5 of this Addendum and will comply with them, and processes Personal Information disclosed by Customer under the Agreement solely as a Service Provider for the specific business purpose of providing the Services, and not for any other commercial purpose.
11.2 Assistance with Consumer Requests. DoorCall AI will assist Customer in responding to a verifiable consumer request under the CCPA to the extent required by Section 6.1 of this Addendum, and will delete, correct, or provide access to Personal Information held on Customer's behalf upon Customer's instruction, in accordance with the CCPA's requirements applicable to a Service Provider.
11.3 No Combination. DoorCall AI will not combine Personal Information received from Customer with Personal Information received from another source, except as permitted under the CCPA, including to detect security incidents, to protect against fraudulent or illegal activity, or to perform a service on behalf of another business consistent with the CCPA.
12. Liability
12.1 Application of Agreement. The liability of each party arising under or in connection with this Addendum, including under the EU SCCs and the UK Addendum incorporated pursuant to Section 9, is subject to the limitations and exclusions of liability set out in Section 13 of the Terms of Service, to the maximum extent such limitations and exclusions are permitted under Applicable Data Protection Law. Nothing in this Section 12 limits the rights of a Data Subject as a third-party beneficiary under Clause 3 of the EU SCCs, to the extent such rights cannot lawfully be limited.
12.2 Aggregate Liability. Each party's liability arising out of or relating to this Addendum, whether in contract, tort, or otherwise, is subject to the aggregate liability cap set out in Section 13.2 of the Terms of Service, applied jointly and not in addition to any liability arising under the Agreement generally.
13. Order of Precedence
Where a conflict exists between the terms of this Addendum and the terms of the Agreement, this Addendum controls with respect to the processing of Personal Data. Where a conflict exists between the terms of this Addendum and the EU SCCs or the UK Addendum incorporated under Section 9, the EU SCCs or the UK Addendum, as applicable, control to the extent of the conflict.
14. Term
This Addendum takes effect on the date it becomes applicable under the preamble to this Addendum and remains in effect for so long as DoorCall AI processes Personal Data on Customer's behalf under the Agreement, notwithstanding termination or expiry of the Agreement, until such processing ceases in accordance with Section 10.
Schedule 1 — Details of Processing
A. List of Parties
Data Exporter: Customer, as identified in the Agreement, acting as Controller. Contact details are as provided in Customer's Account. Activities relevant to the transfer: receipt of the Services described in the Agreement. Role: Controller.
Data Importer: DoorCall AI, Inc., a Delaware corporation with its registered offices in the State of Delaware and its principal place of business address as published at doorcall.ai/legal/contact, acting as Processor. Contact: privacy@doorcall.ai. Activities relevant to the transfer: provision of an artificial-intelligence call-answering and appointment-scheduling platform. Role: Processor.
B. Description of Transfer
Categories of Data Subjects: Callers who contact Customer's business by telephone or SMS; Customer's authorized personnel who access the Services.
Categories of Personal Data: Name; telephone number; electronic mail address; service address; description of service request; call audio recordings, where enabled; call transcripts and AI-generated summaries; appointment details; SMS message content and consent records; Customer personnel account and role information.
Special Categories of Personal Data: None are intentionally collected. Health-related information may be incidentally disclosed by a Caller during an unstructured conversation where relevant to the urgency of a service request. Frequency of transfer: continuous, for the duration of the Agreement. Nature of processing: collection, recording, transcription, classification, storage, and disclosure as described in the Privacy Policy. Purpose of processing: provision of the Services. Retention period: as set out in Section 15 of the Privacy Policy. Subprocessors: as identified in the Subprocessor List.
C. Competent Supervisory Authority
The supervisory authority of the member state in which Customer is established, or, where Customer is not established in a member state, the supervisory authority of the member state identified in accordance with Clause 13 of the EU SCCs.
Schedule 2 — Technical and Organizational Security Measures
DoorCall AI implements and maintains the following measures, appropriate to the nature and risk of the processing described in Schedule 1:
1. Encryption. Encryption of Personal Data in transit using current industry-standard transport-layer cryptographic protocols, and encryption of Personal Data at rest. Integration credentials for third-party services are encrypted using authenticated symmetric encryption and are never transmitted to or accessible from a client application.
2. Access Control. Role-based access control enforcing least-privilege access; multi-factor authentication for administrative access to production infrastructure; logical tenant isolation enforced at both the application layer and, in the production database, through row-level security policies scoped to each Customer's workspace; and authenticated, workspace-scoped access controls for call recordings, such that recordings are never available at a persistent public address.
3. Integrity and Confidentiality. Cryptographic verification of the authenticity of inbound webhook requests from third-party providers; structured application logging with automatic redaction of credentials, tokens, and recording locations; and written confidentiality obligations binding all personnel with access to Personal Data.
4. Availability and Resilience. Rate limiting and abuse-detection controls; hard, code-enforced usage ceilings that bound the operational and financial consequences of anomalous or abusive activity; and separation of production credentials from application source code.
5. Testing and Evaluation. Ongoing monitoring for security events and error conditions; and periodic review of access privileges and security configuration.
6. Incident Response. Documented procedures for detecting, investigating, and responding to a Personal Data Breach, including the notification procedure described in Section 7 of this Addendum.
7. Data Minimization and Retention. Collection limited to the categories of Personal Data described in Schedule 1 as necessary to provide the Services; and enforcement of the retention and deletion schedule described in Section 15 of the Privacy Policy, including verified, programmatic deletion of an entire Customer workspace upon a confirmed deletion request.
8. Subprocessor Oversight. Written agreements with each Subprocessor imposing data protection and security obligations materially consistent with this Addendum, and maintenance of the current Subprocessor List referenced in Section 5.2.
Schedule 3 — Subprocessors
The current list of Subprocessors, including the identity, function, and location of processing of each, is maintained at doorcall.ai/legal/subprocessors and is incorporated into this Addendum by reference as of the date it is accessed. DoorCall AI will provide a copy of the then-current Subprocessor List to Customer upon written request to privacy@doorcall.ai.