Data Processing Addendum
Last updated: August 22, 2026
1. Roles
For personal data relating to your customers, you are the controller and we are the processor. You decide why and how that data is processed; we process it on your documented instructions, which are the Terms of Service, your order form, and your configuration of the service.
For data about your own staff's use of our dashboard and portal, we act as controller.
2. Scope of processing
- Categories of data subject: your customers and prospective customers who contact your business; your staff who use the service.
- Categories of personal data: name, phone number, service address, email where provided, call audio and recordings where enabled, call transcripts, appointment and job history, and message history.
- Purpose: answering and triaging calls, booking appointments, sending transactional messages, and reporting to you on what happened.
- Duration: for the term of the agreement, plus the deletion window in section 6.
- Special category data:not requested and not required. Callers sometimes volunteer health or vulnerability information in an emergency call (“my child is in the house”); this is incidental and is not processed for any separate purpose.
3. Our obligations
- Process personal data only on your documented instructions.
- Ensure anyone who accesses the data is bound by confidentiality.
- Implement appropriate technical and organisational security measures (section 5).
- Assist you with data subject requests, and with security and breach obligations.
- Notify you without undue delay on becoming aware of a personal data breach.
- Delete or return personal data at the end of the agreement (section 6).
- Make available the information reasonably needed to demonstrate compliance.
4. Subprocessors
You authorise the subprocessors listed on our compliance page, which we keep current. We will give you reasonable notice before adding or replacing a subprocessor, and you may object on reasonable data-protection grounds.
5. Security
- Data encrypted in transit and at rest.
- Per-client isolation enforced at the database level rather than only in application code, so a bug in our software cannot expose one client's data to another.
- Access limited to those who need it to operate the service.
- Public endpoints authenticate their sender and rate-limit.
- Credentials held in environment configuration, never in source control.
6. Return and deletion
You can request a full export of call records, transcripts and customer data at any time. On termination we provide an export and delete your personal data from our systems within 30 days, except where we are required to retain it by law.
7. International transfers
Pending review. Our subprocessors are predominantly US-based. The appropriate transfer mechanism for clients or data subjects outside the US is one of the specific questions going to counsel, and we will not state a position here until it has been answered properly.
8. Contact
Data protection questions go to hello@serviceedgedigital.com.