Data Processing Agreement (DPA)
Contents
- Art. 1 - Purpose
- Art. 2 - Data processed
- Art. 3 - Purposes
- Art. 4 - Duration
- Art. 5 - Softcallia's obligations
- Art. 6 - Authorized sub-processors
- Art. 7 - Transfers outside the EU
- Art. 8 - Rights of data subjects
- Art. 9 - Breach notification
- Art. 10 - Audit
- Art. 11 - Return and deletion
This Data Processing Agreement (hereinafter the “DPA” or “Agreement”), entered into pursuant to Article 28 of Regulation (EU) 2016/679 of 27 April 2016 (GDPR), sets out the conditions under which Softcallia(hereinafter the “Processor”) processes personal data on behalf of the Customer (hereinafter the “Controller”).
This Agreement forms an integral part of Softcallia's Terms of Service and Sale and applies from the moment they are accepted.
Article 1 — Purpose
The purpose of this Agreement is to define the conditions under which the Processor undertakes to carry out, on behalf of the Controller, the personal data processing operations necessary to provide the Softcallia service.
Softcallia processes personal data solely on the documented instructions of the Controller, unless a legal obligation requires different processing. In that case, the Processor will inform the Controller of that legal obligation before processing, unless legally prohibited from doing so.
Article 2 — Data processed
In the course of providing the Service, the Processor processes the following categories of personal data:
| Category | Data concerned | Data subjects |
|---|---|---|
| Telephone calls | Audio stream of incoming calls, processed in real time solely for transcription purposes and not retained, caller's number, call duration, timestamp | Customers and prospects of the Controller (callers) |
| Transcriptions | Text transcriptions of calls, AI-generated summaries, urgency classification, type of issue detected | Customers and prospects of the Controller (callers) |
| Customer contact details | First and last name, phone number, address (when provided during the call) | Customers and prospects of the Controller |
| Appointments | Date, time, reason, customer contact details | Customers of the Controller |
| Account data | First and last name, email, phone, company name, SIRET, address of the Controller | Users of the Service (the Controller and its staff) |
Article 3 — Purposes of processing
Personal data is processed by the Processor exclusively for the following purposes, on the instructions of the Controller:
- Receiving and processing calls by AI: automated answering of incoming calls, voice transcription (speech-to-text), summary generation, urgency-level classification, categorization of the type of issue.
- Appointment management:proposing available slots to the caller, creating and tracking appointments in the Controller's calendar.
- Emergency handling: automatic detection of urgent situations, triggering of real-time alerts (push notifications, email, SMS) to the Controller.
- Dashboard and history: making the call history, transcriptions, statistics and management tools available to the Controller.
- Transactional notifications: sending alerts, appointment reminders and operational notifications.
Article 4 — Duration of processing
This Agreement takes effect on the date the Controller accepts the Terms and remains in force for the entire duration of the Softcallia service contract.
At the end of the contract (termination, non-renewal or expiry), personal data is retained for a maximum period of 30 days to allow the Controller to export its data, and is then deleted in accordance with Article 11 of this Agreement.
Data subject to legal retention obligations (in particular billing data — 10 years, Article L.123-22 of the French Commercial Code) is retained for the period required by law.
Article 5 — Softcallia's obligations (Article 28 of the GDPR)
The Processor undertakes to:
5.1. Documented instructions
Process personal data solely on the documented instructions of the Controller, including with regard to transfers of data to a third country, unless required to do so by law.
5.2. Confidentiality
Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3. Security
Implement the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, including in particular:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Data isolation per company (Row Level Security)
- Role-based access control (RBAC)
- Protection against brute-force attacks (rate limiting)
- Password hashing (bcrypt with individual salting)
- Authentication via JWT tokens with automatic rotation
- HTTP security headers (CSP, HSTS, X-Frame-Options)
- Webhook validation via HMAC signature
5.4. Further sub-processing
Not engage another sub-processor without the prior written authorization, whether general or specific, of the Controller. The list of authorized sub-processors is set out in Article 6 of this Agreement. The Controller is informed of any change of further sub-processor and has a period of 30 days to raise objections.
5.5. Assistance
Assist the Controller, through appropriate technical and organizational measures, in fulfilling its obligation to respond to requests to exercise the rights of data subjects (Articles 15 to 22 of the GDPR).
5.6. Deletion or return
At the Controller's choice, delete or return all the personal data at the end of the provision of services, and destroy existing copies, unless there is a legal retention obligation.
5.7. Information and audit
Make available to the Controller all the information necessary to demonstrate compliance with the obligations set out in this article and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by it.
Article 6 — Authorized further sub-processors
The Controller authorizes the use of the following further sub-processors. Each of them has entered into a data processing agreement (DPA) compliant with Article 28 of the GDPR:
| Sub-processor | Function | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database hosting, authentication, file storage | Company established in the USA — AWS infrastructure located in the European Union | SCCs, DPA, AES-256, RLS, SOC 2 Type II |
| Stripe Inc. | Payment processing and billing | USA (Irish entity for the EU) | EU-US DPF, SCCs, PCI DSS Level 1 |
| OpenAI Inc. | Voice transcription (Whisper), call analysis and summary (GPT), conversational response | USA | Specific DPA, zero data retention (API), SCCs |
| Twilio Inc. | Telephony (receiving incoming calls), sending SMS | USA | SCCs, DPA, SOC 2 Type II, ISO 27001 |
| Vercel Inc. | Application hosting (HTTP requests, headers, IP address) | USA (global CDN, EU Edge functions) | SCCs, DPA, SOC 2 Type II |
| n8n GmbH | Automation workflows (call orchestration, notifications) | Germany | GDPR-native, self-hosted on a VPS located in the EU |
| Brevo (Sendinblue) | Sending transactional emails (alerts, confirmations, reminders) | France | GDPR-native, ISO 27001, EU hosting |
| Upstash Inc. | Ephemeral application cache (rate limiting, sessions) | EU (Frankfurt, Germany) | GDPR-native, data exclusively in the EU |
| Functional Software Inc. (Sentry) | Monitoring of technical errors | USA | SCCs, DPA, SOC 2 Type II, minimized data |
In the event of the addition or replacement of a further sub-processor, the Processor will inform the Controller by email at least 30 days before the change takes effect. The Controller may object to it in writing within that period. In the event of an unresolved legitimate objection, the Controller may terminate the contract without penalty.
Article 7 — Transfers of data outside the European Union
Some further sub-processors are located in the United States. In accordance with Chapter V of the GDPR, these transfers are governed by the following mechanisms:
- EU-US Data Privacy Framework (DPF): adequacy decision of the European Commission of 10 July 2023, for certified sub-processors (Stripe).
- Standard Contractual Clauses (SCCs): approved by the European Commission (implementing decision 2021/914 of 4 June 2021), incorporated into the DPA of each further sub-processor.
- Additional measures: encryption in transit (TLS 1.3) and at rest (AES-256), minimization of transferred data, regular risk assessment.
The Processor undertakes to inform the Controller of any regulatory change likely to affect the validity of these transfer safeguards.
Article 8 — Rights of data subjects
The Processor undertakes to assist the Controller in responding to requests to exercise the rights of data subjects (Articles 15 to 22 of the GDPR):
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Rights related to automated decisions (Article 22)
The Processor makes the necessary tools available to the Controller in the dashboard (GDPR tab): data export (portability), deletion request (erasure), consent management (withdrawal).
In the event of a request received directly by the Processor from a data subject, the Processor will inform the Controller within 5 business days without responding directly, unless instructed otherwise.
Article 9 — Personal data breach notification
In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, the Processor undertakes to:
- Notify the Controller within a maximum of 48 hoursafter becoming aware of it, by email to the Controller's contact address.
- Provide all available information enabling the Controller to notify the breach to the CNIL within the 72-hour period provided for in Article 33 of the GDPR, in particular:
- The nature of the breach (categories and number of data subjects and records concerned)
- The likely consequences of the breach
- The measures taken or proposed to remedy the breach
- The contact details of the point of contact for further information
- Immediately take all necessary measures to remedy the breach and limit its consequences.
- Document any data breach, including the facts, its effects and the remedial measures taken.
Article 10 — Audit
The Controller has the right to carry out, or have carried out by an independent auditor mandated by it, audits of the Processor's compliance with the obligations set out in this Agreement and the GDPR.
Audits are subject to the following conditions:
- The Controller notifies its audit request in writing with a minimum notice of 30 days.
- The audit takes place during business hours and must not disproportionately disrupt the Processor's activities.
- The costs of the audit are borne by the Controller, unless the audit reveals a failure by the Processor.
- The auditor is bound by a confidentiality obligation covering the information to which it has access.
- A maximum of 1 audit per year may be carried out, except in the event of a confirmed data breach or a request from the CNIL.
The Processor undertakes to cooperate fully during the audit and to provide all necessary information and access.
Article 11 — Return and deletion of data
At the end of the service contract, the Processor undertakes, at the Controller's choice, to:
- Returnall the personal data processed in a structured, commonly used and machine-readable format (JSON, CSV), via the dashboard's export feature.
- Delete all the personal data and all existing copies within a maximum of 30 days after the end of the contract.
The Processor will provide the Controller with a written certificate of deletion on request.
Data whose retention is required by law is excluded from deletion (in particular billing data retained for 10 years pursuant to Article L.123-22 of the French Commercial Code).
Contact
For any question relating to this Data Processing Agreement:
- Data contact: dpo@softcallia.com
- Support: support@softcallia.com
- Address: Softcallia — Côme Bruchet — 24 rue David, 51100 Reims
Questions?
contact@softcallia.comSIRET 102 453 487 00013