Data protection
Data Processing Agreement (DPA)
Agreement under Art. 28 GDPR between the customer, as controller, and Agent On Demand, as processor.
1. Subject matter and duration
This agreement governs the processing of personal data that Agent On Demand carries out on behalf of the customer in connection with the provision of AI voice agents, dedicated phone numbers and the management platform. The duration matches that of the main contract.
2. Categories of data subjects and data
- Callers, customers and prospective customers of the controller
- Employees and collaborators of the controller involved in call transfers
- Identification and contact data, phone number, conversation content
- Text transcripts, summaries, metadata and call outcomes; no audio recordings
- Additional data transmitted through integrations configured by the controller
3. Processor's obligations
- Process data solely on documented instructions from the controller
- Bind all persons authorised to process data to confidentiality
- Implement appropriate technical and organisational measures under Art. 32 GDPR
- Assist the controller with data subject requests and impact assessments
- Notify any data breach without undue delay, and in any case within 48 hours
- Delete or return data at the end of the contract, subject to retention obligations
4. Security measures
- Infrastructure hosted in the European Union
- Encryption in transit (TLS 1.2+) and at rest
- Named access control with multi-factor authentication
- Logical data segregation per customer and access logging
- Encrypted backups and tested restore procedures
- Full audit log available on the Enterprise plan
5. Sub-processors
The controller authorises the use of sub-processors for hosting, cloud telephony, speech synthesis and recognition, language models, technical monitoring and order management. Each sub-processor is bound by obligations equivalent to those in this agreement. An up-to-date list is provided on request and changes are communicated with at least 30 days' notice, with the controller's right to object.
6. Transfers outside the EEA
Any transfers to third countries take place only where an adequacy decision, the European Commission's Standard Contractual Clauses, or other safeguards under Chapter V of the GDPR apply, with supplementary measures where necessary.
7. Audit rights
The controller may verify compliance by requesting documentation of the measures adopted and, with reasonable notice, an audit no more than once a year, except in the case of documented incidents.
8. Acceptance
This agreement is deemed accepted upon activation of the service. For a signed copy, write to info@agent-ondemand.com.
