Data Processing Agreement
This agreement, pursuant to Article 28 GDPR, governs the processing of personal data that CallSmarter carries out on behalf of its customers when providing the service. It forms part of the Terms of Service and prevails over them in matters of data protection.
Parties
- Controller: the Customer contracting the service under the Terms of Service.
- Processor: Atiempo.Me SL (trade name: CallSmarter), Tax ID (NIF) B56542111, with its registered address at Calle Timón 58, Centro Comercial Torrequebrada, Oficina 17, 29631 Torrequebrada, España (“CallSmarter”).
The agreement applies to the personal data that CallSmarter processes on the Customer’s behalf when providing the service. It does not apply to data that CallSmarter processes as controller (for example, for invoicing or managing the contractual relationship), which is governed by the Privacy Policy.
Subject matter, nature, purpose and duration
CallSmarter processes the data for the sole purpose of providing the service to the Customer, which comprises:
- making outbound calls on the Customer’s behalf using artificial intelligence voice agents;
- recording and transcribing conversations;
- automatically assessing the quality of each call and producing a short summary using artificial intelligence;
- recording call outcomes;
- CRM features (contacts, deals and tasks);
- managing campaigns and contact lists.
Processing will last for the term of the contract, plus the period required for the deletion or return of data provided for in this agreement.
Categories of data
- Identification and contact data of the Customer’s contacts: name, telephone number, email address and any other fields included in the CSV files uploaded by the Customer.
- Voice and content of conversations: audio recordings and transcripts.
- Call outcomes, summaries, assessments and notes.
- Call metadata: date and time, duration and status.
- Data of the Customer’s dashboard users: name, email address, role and activity log.
The Customer shall not upload special categories of data (Art. 9 GDPR) or data relating to criminal convictions and offences (Art. 10 GDPR) without a specific legal basis and without prior written agreement with CallSmarter.
Categories of data subjects
- The Customer’s contacts, prospective customers (leads) and customers.
- The Customer’s representatives and employees.
- The Customer’s dashboard users.
Controller’s instructions
CallSmarter shall process the data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by Union or Member State law, in which case it shall inform the Customer beforehand, unless that law prohibits it. These terms, the settings the Customer configures in the dashboard and the agents, prompts and campaigns it defines are deemed to be documented instructions.
CallSmarter shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
Confidentiality
CallSmarter ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access the data only to the extent necessary to provide the service.
Security measures
Pursuant to Article 32 GDPR, CallSmarter applies, among others, the following technical and organisational measures:
- encryption of traffic via HTTPS/TLS; web access to the server is open only through the Cloudflare network;
- encryption of integration secrets and two-factor authentication keys using the AES-256-GCM algorithm;
- password storage using a key derivation function (scrypt);
- logical isolation of each organisation’s data at database level (PostgreSQL Row-Level Security);
- two-factor authentication (TOTP), mandatory by default;
- role-based permission model, including masking of telephone numbers for roles without the relevant permission;
- tamper-evident activity (audit) log protected by a hash chain;
- automatic termination of inactive sessions;
- optional per-organisation IP allowlist;
- network restrictions: the SIP port is accessible only to the telecommunications operator’s IP addresses, SSH access is possible only with keys, and brute-force protection is in place.
These measures may be updated as technology evolves, without reducing the overall level of security.
Sub-processors
The Customer grants CallSmarter a general authorisation to engage the following sub-processors:
| Sub-processor | Purpose | Location / transfer |
|---|---|---|
| [hosting provider — to be provided] (VPS hosting) | Server, database and storage of recordings | [server location — to be provided] |
| Cloudflare, Inc. | CDN, DNS, attack protection and TLS for the dashboard | Global network |
| OpenAI | Real-time voice model, tool execution, transcription and call quality assessment (audio and conversation texts) | Possible processing outside the EEA (USA) |
| Octella | Telephony and SIP operator (call signalling and audio) | [region — to be provided] |
| NOWPayments | Processing of the Customer’s cryptocurrency balance top-ups (Customer’s payment data; does not receive data of the Customer’s contacts) | Possible processing outside the EEA |
| Telegram | Internal alerts to the CallSmarter team about telephony incidents and requests received on the website (does not receive data of the Customer’s contacts) | Possible processing outside the EEA |
CallSmarter will inform the Customer of any intended change (addition or replacement of sub-processors) [period — e.g. 30 days, to be confirmed] in advance. The Customer may object on reasonable and justified data protection grounds; if the parties cannot reach a solution, the Customer may terminate the contract with respect to the affected service.
CallSmarter will impose on each sub-processor, by contract, data protection obligations equivalent to those of this agreement and will remain liable to the Customer for the performance of those obligations.
International transfers
Where a sub-processor processes data outside the EEA, the transfer will be carried out in accordance with Chapter V GDPR: on the basis of an adequacy decision of the European Commission, where applicable, or, failing that, the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), together with any appropriate supplementary measures. The Customer may request information about the applicable safeguards at [email protected].
Assistance to the controller
Taking into account the nature of the processing, CallSmarter will assist the Customer:
- in responding to requests from data subjects exercising their rights, mainly through the dashboard tools, which allow contact data to be viewed, rectified, deleted and exported; if a data subject contacts CallSmarter directly, CallSmarter will forward the request to the Customer without delay;
- in carrying out data protection impact assessments and, where applicable, prior consultations with the supervisory authority;
- in complying with the security obligations of Article 32 GDPR.
Personal data breaches
CallSmarter will notify the Customer of any personal data breach without undue delay and, where possible, no later than 48 hours after becoming aware of it, providing the information referred to in Article 33(3) GDPR available to it (nature of the breach, categories and approximate number of data subjects and records concerned, contact point, likely consequences and measures taken or proposed), so that the Customer can, where applicable, meet the 72-hour deadline for notifying the supervisory authority. Information not initially available will be provided in phases.
Retention, deletion and return
Call recordings are kept on the platform by default for 90 days; after that period, they are deleted or anonymised. The Customer may request their earlier deletion. It is for the Customer, as controller, to determine the retention periods of the other data it processes on the platform and to delete such data when it is no longer necessary, for which it has the dashboard tools at its disposal.
On termination of the service, CallSmarter will delete or return to the Customer, at the Customer’s choice, the personal data processed on its behalf within [period — e.g. 30 days, to be confirmed], and will delete existing copies, unless Union or Member State law requires their retention, in which case it will keep them blocked for the statutory period.
Information and audits
CallSmarter will make available to the Customer the information necessary to demonstrate compliance with the obligations of Article 28 GDPR. In addition, it will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by it, upon reasonable request with sufficient prior notice, at the Customer’s expense, without affecting the security or confidentiality of other customers, and no more than once a year, except in the event of a security breach or at the request of a supervisory authority.
Controller’s obligations
The Customer warrants that:
- it has a valid legal basis to make the calls, record them and process its contacts’ data;
- it informs data subjects in accordance with Articles 13 and 14 GDPR, including that the call is made by an artificial intelligence system and, where applicable, that the conversation is recorded and for what purposes;
- it checks its lists against advertising opt-out systems (such as the Robinson List) and its own do-not-call lists, and honours requests not to be called;
- its instructions to CallSmarter comply with applicable law.
Liability and precedence
The parties’ liability arising from this agreement is governed by the Terms of Service, without prejudice to Article 82 GDPR. In the event of any conflict between this agreement and the Terms of Service in matters of data protection, this agreement shall prevail.
Contact
For any matter relating to this agreement or to data protection, the Customer may contact [email protected].
