Data Processing

Data Processing Addendum

Last updated: July 7, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service, Master Subscription Agreement, or enterprise Cloud Service Agreement (the "Agreement") between Call-e, Inc., a Delaware corporation doing business as "Call-e" ("Call-e," "Processor") and the customer ("Client," "Controller"). It governs Call-e's processing of Personal Data on Client's behalf. If there is a conflict on data-protection matters, this DPA controls.

1. Definitions

"Applicable Data Protection Laws" means privacy and data-protection laws that apply to a party's processing, including the EU GDPR, UK GDPR, and U.S. state privacy laws (including the CCPA/CPRA). "Personal Data," "Controller," "Processor," "Process/Processing," "Data Subject," and "Supervisory Authority" have the meanings in Applicable Data Protection Laws. "Client Personal Data" means Personal Data within Client Data that Call-e processes on Client's behalf. "Sub-processor" means a third party engaged by Call-e to process Client Personal Data. "Client" is the Customer or counterparty identified in the applicable Agreement (the terms are used interchangeably across Call-e's agreements).

2. Roles and Scope

The parties acknowledge that, for Client Personal Data, Client is the Controller (or a processor acting for another controller) and Call-e is the Processor. Call-e will process Client Personal Data only to provide the Services and as a Processor. The subject matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A.

3. Processing Instructions

Call-e will process Client Personal Data only: (a) on Client's documented instructions (including as set out in the Agreement, this DPA, and Client's use and configuration of the Services); and (b) as required by law (in which case Call-e will, where legally permitted, notify Client). Client's instructions must comply with Applicable Data Protection Laws, and Client is responsible for the lawfulness of the Personal Data it provides and the consents and notices required (including recording consents).

4. Confidentiality

Call-e ensures that personnel authorized to process Client Personal Data are bound by confidentiality obligations and access Personal Data only as needed to provide the Services.

5. Security

Call-e will implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data, as described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, and risks of processing.

6. Sub-processors

Client provides general authorization for Call-e to engage Sub-processors to process Client Personal Data. Call-e's current Sub-processors are listed at its Sub-processor list (Annex C). Call-e will: (a) impose data-protection obligations on each Sub-processor substantially as protective as those in this DPA, including ensuring that each AI Sub-processor that processes Client Personal Data is contractually bound not to use Client Personal Data (including inputs, outputs, and embeddings) to train, fine-tune, or improve any model other than to provide its service to Call-e; (b) remain liable for its Sub-processors' performance; and (c) give Client notice before adding or replacing a Sub-processor, allowing a reasonable period to object on reasonable data-protection grounds. If the parties cannot resolve a documented objection, Client may terminate the affected Services.

7. Assistance to Controller

Taking into account the nature of processing, Call-e will: (a) assist Client, insofar as possible, to respond to Data Subject requests; (b) assist Client with security, breach notification, data protection impact assessments, and prior consultations; and (c) make available information reasonably necessary to demonstrate compliance. Because Call-e processes data on Client's behalf, Call-e will refer Data Subjects who contact it directly back to Client.

8. Personal Data Breach

Call-e will notify Client without undue delay (and in any event within 72 hours where required by applicable law) after becoming aware of a Personal Data Breach affecting Client Personal Data. The notification will include, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it; and a contact point. Call-e will provide information reasonably available to help Client meet its breach-notification obligations. Notification is not an acknowledgment of fault.

9. International Transfers

Where Call-e processes Client Personal Data originating in the EEA, UK, or Switzerland in a country without an adequacy decision, the parties will rely on the Standard Contractual Clauses (and the UK Addendum / Swiss amendments as applicable), incorporated by reference (Annex D) and completed using the details in Annexes A–C. The SCCs prevail over conflicting DPA terms regarding such transfers.

10. Deletion and Return

On termination or expiration of the Agreement, Call-e will, at Client's choice, delete or return Client Personal Data within 30 days, and delete existing copies, except to the extent retention is required by law or as set out in the Agreement's data-retrieval and deletion section. Where Client provides no such instruction within the post-termination window, Call-e's default is to de-identify Client Personal Data using industry-standard, irreversible methods such that it can no longer reasonably be re-identified; to the extent such data meets the anonymisation standard under Applicable Data Protection Laws, it is no longer Client Personal Data and falls outside the scope of this Addendum; where it remains reasonably linkable to an individual it continues to be protected under this Addendum. De-identification by default does not override a Client instruction to delete (including a data-subject erasure request the Client passes through). Call-e may retain and use de-identified data in accordance with the Agreement. Client may export Client Personal Data during the post-termination window described in the Agreement. Limited Personal Data may persist in operational logs and routine encrypted backups, which are retained on standard, time-limited schedules and age out automatically rather than being individually purged; while it persists, it remains protected under this DPA. (Call-e is implementing complete-deletion tooling; in the interim the parties will cooperate in good faith on deletion requests.)

11. Audits

Call-e will make available information reasonably necessary to demonstrate compliance and will allow for and contribute to audits, no more than once per year (absent a regulator requirement or breach), on at least 30 days' prior written notice, during business hours, subject to confidentiality, at Client's expense, and without compromising other customers' data. Call-e may satisfy audit requests by providing third-party reports or certifications where available.

12. CCPA (Service Provider Terms)

For Personal Data subject to the CCPA/CPRA, Call-e acts as a Service Provider (or Processor) and will: (a) process Client Personal Data only to perform the Services and as permitted by the CCPA; (b) not sell or share Client Personal Data; (c) not retain, use, or disclose it outside the direct business relationship or for any purpose other than the Services; (d) not combine it with Personal Data from other sources except as permitted by the CCPA; and (e) notify Client if it can no longer meet its obligations.

13. Liability; Precedence

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA supersedes conflicting data-protection terms in the Agreement.

Annex A — Processing Details

  • Subject matter / nature & purpose: Recording, transcription, and AI-assisted analysis of meetings to provide notes, scorecards, guidance, and analytics, plus account administration and support.
  • Duration: The Subscription Term plus the post-termination deletion period described in the Agreement.
  • Categories of Data Subjects: Client's Authorized Users; meeting participants (including Client's customers, prospects, and clients); contacts in connected systems.
  • Categories of Personal Data: name, business and personal contact details; meeting audio/video, transcripts, and derived insights; CRM context the Client connects; usage and device data; support communications. Client controls what it submits.
  • Special categories: Not intended. Client must not submit special-category or HIPAA-regulated data except as permitted by the Agreement and the Acceptable Use Policy.

Annex B — Security Measures (summary)

Encryption in transit (TLS 1.2+) and at rest (AES-256); access controls and least-privilege; logical multi-tenant isolation by organization identifier; managed identity and authentication (no Call-e-stored passwords); network controls and a private database; logging, monitoring, and alerting; secrets management; vulnerability scanning and dependency monitoring; and incident-response procedures. See the Security & Trust page for detail.

Annex C — Sub-processors

The current Sub-processors are those published at Call-e's Sub-processor list, incorporated into this DPA by reference. That list is the canonical, maintained source of record; Call-e gives notice before adding or replacing a Sub-processor as described in Section 6.

Annex D — Standard Contractual Clauses

The EU SCCs (Commission Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor) and, where applicable, Module Three (Processor-to-Processor), with the UK International Data Transfer Addendum and Swiss amendments, completed using Annexes A–C.