LEGAL
Data Processing Addendum
Last updated: June 11, 2026
Terms governing how Sí Call processes personal data on behalf of commercial customers.
Template pending legal review. This addendum is published for transparency and review. To execute a signed copy for your organization, contact legal@sicall.ai.
1. Introduction and Scope
This Data Processing Addendum ("DPA") forms part of the Master Service Agreement or Terms of Service (the "Agreement") between Sí Call("Provider") and the customer entity that has executed or accepted the Agreement ("Customer").
This DPA applies whenever Provider processes Personal Data on behalf of Customer in connection with the services. It is designed to address requirements under the California Consumer Privacy Act (CCPA/CPRA), other US state privacy laws (Virginia, Colorado, Connecticut, Utah, and similar), and general data protection principles.
2. Definitions
"Controller"means the entity that determines the purposes and means of processing Personal Data. Under this DPA, Customer is the Controller (or a "Business" under the CCPA).
"Processor"means the entity that processes Personal Data on behalf of the Controller. Under this DPA, Provider is the Processor (or a "Service Provider" under the CCPA).
"Personal Data" means any information relating to an identified or identifiable natural person that Provider processes on behalf of Customer in connection with the services.
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
"Subprocessor" means any third party engaged by Provider to process Personal Data on behalf of Customer.
3. Roles and Responsibilities
3.1 Customer as Controller
Customer determines the purposes and means of processing and is responsible for:
- Ensuring a lawful basis exists for processing
- Providing required notices to callers and other data subjects
- Obtaining necessary consents (e.g., call recording disclosures)
- Responding to data subject requests directed to Customer
- Complying with privacy laws applicable to Customer's business
3.2 Provider as Processor
Provider processes Personal Data only on behalf of and under the documented instructions of Customer, including:
- Processing only as instructed by Customer or as required by law
- Implementing appropriate technical and organizational security measures
- Assisting Customer with data subject requests
- Notifying Customer of Security Incidents
- Ensuring personnel with data access are bound by confidentiality obligations
4. Scope of Processing
4.1 Purposes
Provider processes Personal Data only for the following purposes:
- Operating the AI voice agent to answer and route calls
- Generating and storing call transcripts and summaries
- Managing appointment scheduling and calendar integrations
- Sending notifications and SMS messages on Customer's behalf
- Providing dashboard access, call logs, and analytics
- Technical support and service operation
4.2 Categories of Personal Data
- Identifiers: Name, phone number, email address
- Audio Data: Call recordings, voicemail (where Customer enables recording)
- Communication Content: Transcripts, messages, appointment details
- Technical Data: Call metadata, timestamps, IP addresses
4.3 Categories of Data Subjects
- Callers who contact Customer via the AI receptionist
- Customer employees and authorized users
- Individuals mentioned in call content
4.4 Processing Restrictions
Provider will NOT:
- Sell Personal Data
- Share Personal Data for cross-context behavioral advertising
- Process Personal Data for purposes other than providing the services
- Combine Personal Data across customers except as permitted by applicable law
- Retain Personal Data longer than necessary for the services
5. Subprocessors
5.1 Authorization
Customer provides general authorization for Provider to engage Subprocessors to assist in providing the services. The current list — including each Subprocessor's purpose, processing region, and data protection terms — is published at /legal/subprocessors and is incorporated into this DPA by reference.
5.2 Subprocessor Obligations
Provider will ensure each Subprocessor is bound by written data protection obligations at least as protective as those in this DPA, and Provider remains responsible for each Subprocessor's performance.
5.3 Changes to Subprocessors
Provider will update the subprocessor list and notify Customer via email or dashboard notice before engaging a new Subprocessor. Customer may object on reasonable data protection grounds within thirty (30) days of notice; if the objection cannot be resolved, Customer may terminate the affected services.
6. Security Measures
Provider implements and maintains appropriate technical and organizational measures designed to protect Personal Data, including:
- Encryption in transit: TLS 1.2 or higher for all data transmission
- Encryption at rest: AES-256 or equivalent for stored data
- Access controls: Role-based access and tenant isolation enforced in code
- Logging: Audit trails for administrative and data-access actions
- Vulnerability management: Dependency scanning, security review, and patching
- Organizational measures: Confidentiality agreements and incident response procedures
A more detailed description of our security program is available on the Security page and in our Trust Center.
7. Security Incident Notification
Provider will notify Customer of a Security Incident affecting Customer's Personal Data without undue delay, and in any event within seventy-two (72) hours of becoming aware of it, unless legally prohibited. The notification will include, to the extent known: the nature of the incident, the categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed, and a contact point for further information.
Provider will cooperate with Customer's investigation and with breach notification obligations that apply to Customer.
8. Data Subject Requests
Taking into account the nature of processing, Provider will assist Customer in responding to requests to exercise rights of access, deletion, correction, and portability. Customer may direct such requests to privacy@sicall.ai; Provider will respond within ten (10) business days. If Provider receives a request directly from a data subject, Provider will redirect it to Customer unless legally required to respond directly.
9. Retention and Deletion on Termination
During the term, Personal Data is retained according to the retention settings Customer configures (e.g., call recording and transcript retention windows). Upon termination of the Agreement:
- Customer may request export of its data within thirty (30) days
- Provider will delete Personal Data within ninety (90) days
- Provider will confirm deletion in writing upon request
Provider may retain Personal Data where required by applicable law (e.g., billing and tax records), limited to what the law requires.
10. Data Location and International Transfers
Personal Data is processed and stored in the United States using infrastructure providers with data centers in the continental United States. Provider does not transfer Personal Data outside the United States as part of normal service delivery.
If Customer's use of the services involves personal data subject to the GDPR or UK GDPR and an international transfer becomes necessary, the parties will execute the European Commission's Standard Contractual Clauses (SCCs) or another lawful transfer mechanism before any such transfer occurs. Contact legal@sicall.ai to put SCCs in place.
11. California-Specific Terms (CCPA/CPRA)
When processing Personal Information of California residents, Provider acts as a "Service Provider" as defined in CCPA Section 1798.140(ag) and will not: sell Personal Information; share it for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with Personal Information from other sources except as permitted by the CCPA. Provider certifies that it understands these restrictions and will comply with them.
12. Audit Rights
Customer may verify Provider's compliance with this DPA by requesting responses to security questionnaires, reviewing Provider's security documentation, and requesting available assessment evidence. On-site audits may be conducted upon at least thirty (30) days' notice, no more than once per year absent a Security Incident, subject to confidentiality obligations and at Customer's cost.
13. Term
This DPA remains in effect for as long as Provider processes Personal Data on behalf of Customer under the Agreement. The deletion provisions of Section 9 and any confidentiality obligations survive termination.
14. Contact Information
To execute this DPA, request a countersigned copy, or ask questions:
Legal/Contracts: legal@sicall.ai
Privacy/Data Protection: privacy@sicall.ai
Security Inquiries: security@sicall.ai