pursuant to Art. 28 General Data Protection Regulation (GDPR)
between
the customer of the “SalesFrank” platform (hereinafter the “Client” or “Controller”)
and
Another Side Ventures FZ-LLC
Al Shohada Road 158, Ras Al Khaimah, United Arab Emirates
(hereinafter the “Processor” or “Data Processor”)
— together hereinafter the “Parties” —
EU representative of the Processor pursuant to Art. 27 GDPR:
heyData GmbH (Martin Bastius)
Email: datenschutz@heydata.eu
Version: June 2026
§ 1 Subject Matter and Duration of Processing
This Data Processing Agreement (hereinafter “DPA”) specifies the data protection obligations of the Parties pursuant to Art. 28 GDPR in connection with the Client’s use of the “SalesFrank” SaaS platform (hereinafter the “Platform”).
The Processor processes personal data on behalf of, and on the documented instructions of, the Client. The details of the processing, in particular the nature and purpose of the processing, the type of personal data, and the categories of data subjects, are described in Appendix 1 to this DPA.
The term of this DPA is determined by the term of the main agreement (the Platform usage agreement). This DPA automatically ends upon termination of the main agreement, unless statutory retention obligations require continued storage.
§ 2 Authority to Issue Instructions
The Processor processes personal data exclusively on the documented instructions of the Client, unless the Processor is required to process such data under the law of the European Union or of an EU member state to which it is subject. In such a case, the Processor shall inform the Client of those legal requirements prior to the processing, unless the law in question prohibits such notification on important grounds of public interest.
The Client’s instructions are initially defined by this DPA and the usage agreement and may subsequently be amended in writing or in text form (email). Verbal instructions must be confirmed in writing or text form without undue delay.
The Processor shall inform the Client without undue delay if it considers that an instruction infringes data protection provisions. The Processor is entitled to suspend implementation of the instruction in question until it is confirmed or amended by the Client.
§ 3 Obligations of the Processor
The Processor undertakes, in particular, to:
Process personal data only within the scope of the Client’s documented instructions and the purpose of the main agreement.
Bind all persons with access to personal data to confidentiality, or ensure that they are subject to an appropriate statutory duty of confidentiality. This confidentiality obligation continues to apply after termination of the contractual relationship.
Implement the technical and organizational measures described in Appendix 2 to protect personal data and maintain them throughout the term of the agreement. The Processor warrants that the measures reflect the current state of the art and provide a level of protection appropriate to the risk of the processing (Art. 32 GDPR).
Support the Client in complying with the obligations set out in Art. 32 to 36 GDPR, in particular with regard to:
- Security of processing (Art. 32 GDPR)
- Notification of personal data breaches to the supervisory authority (Art. 33 GDPR)
- Communication of personal data breaches to data subjects (Art. 34 GDPR)
- Data protection impact assessments (Art. 35 GDPR)
- Prior consultation of the supervisory authority (Art. 36 GDPR)
Provide the Client with all information necessary to demonstrate compliance with the obligations set out in Art. 28 GDPR, and enable and contribute to audits — including inspections — conducted by the Client or an auditor mandated by the Client.
Grant access to personal data solely to authorized employees who require such access to perform their tasks (need-to-know principle).
Support the Client in maintaining its record of processing activities pursuant to Art. 30 GDPR by providing the Client, upon request, with the information required for this purpose. This includes, in particular, information on the categories of data processed, the purposes of processing, the sub-processors engaged, the retention periods, and the technical and organizational measures implemented. The information contained in this DPA and its appendices shall serve the Client as a basis for its record of processing activities.
Support the Client in carrying out data protection impact assessments pursuant to Art. 35 GDPR, insofar as the processing carried out by the Processor is concerned. Upon request, the Processor shall provide the Client with the information required for this purpose regarding the nature, scope, circumstances, and risks of the processing. The Processor shall further support the Client in the prior consultation of the supervisory authority pursuant to Art. 36 GDPR, insofar as such consultation is required.
Inform the Client without undue delay — as a rule within 24 hours — if the Processor becomes aware of any unlawful use, unauthorized disclosure, or unauthorized access to personal data processed within the scope of the processing. This notification obligation exists in addition to the obligation to notify personal data breaches under § 6 of this DPA and covers, in particular, cases in which authorized persons access data without authorization, disclose data to third parties without authorization, or use data for unauthorized purposes. The Processor employs appropriate measures to detect such incidents, in particular through access logging and regular review of access logs.
§ 4 Obligations of the Client (Controller)
The Client is solely responsible for the lawfulness of the data processing and for safeguarding the rights of data subjects.
The Client shall ensure that:
- it has a legal basis for the processing of the personal data transmitted to the Processor
- data subjects are informed in accordance with Art. 13 and 14 GDPR
- it issues and documents the instruction for the processing
- it has assessed the technical and organizational measures implemented by the Processor as adequate
The Client shall inform the Processor without undue delay if it identifies errors or irregularities in the processing.
Delineation of responsibilities: The Parties clarify that, with respect to the personal data of contact persons (data that the Client uploads to the Platform and that is processed in the course of automated phone calls), the Processor acts as a processor within the meaning of Art. 4(8) GDPR. The provisions of this DPA apply without restriction to this data.
With respect to the Client’s own master data (registration data, contact details of the point of contact, company data, payment information), however, the Processor acts as an independent controller within the meaning of Art. 4(7) GDPR. The processing of this data is based on Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with a legal obligation, in particular commercial- and tax-law retention obligations). The processing of the Client’s master data is not subject to the Client’s right to issue instructions. Further information can be found in the Processor’s privacy policy at salesfrank.com.
§ 5 Rights of Data Subjects
Insofar as a data subject asserts claims for access, rectification, erasure, restriction of processing, data portability, or objection pursuant to Art. 15 to 21 GDPR directly against the Processor, the Processor shall refer the data subject to the Client and inform the Client without undue delay.
The Processor shall support the Client, to the extent technically possible and reasonable, in fulfilling data subjects’ rights. For this purpose, the Processor provides the Client with the necessary technical functions in the dashboard (including data export and data deletion).
Support in fulfilling standard requests from data subjects (in particular access, deletion, and rectification of individual data records) is covered by the agreed remuneration, insofar as such requests can be handled using the functions provided in the dashboard. Insofar as support in fulfilling data subjects’ rights beyond this causes disproportionate effort (e.g. extensive manual research, special exports), the Processor is entitled to charge separately for the additional effort.
§ 6 Notification of Personal Data Breaches
The Processor shall inform the Client without undue delay, and in any event within 24 hours of becoming aware, of any personal data breach within the meaning of Art. 4(12) GDPR that relates to the processing carried out under this agreement.
The notification shall include at least:
- a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and data records concerned
- the name and contact details of a point of contact
- a description of the likely consequences of the breach
- a description of the measures taken or proposed to address the breach and mitigate its possible adverse effects
- The Processor shall support the Client in fulfilling its notification obligations under Art. 33 and 34 GDPR.
§ 7 Sub-Processing
The Processor engages the sub-processors listed in Appendix 3 to provide the contractually agreed services. By concluding this DPA, the Client grants its general authorization for the engagement of these sub-processors.
The Processor shall inform the Client of any intended change concerning the addition or replacement of sub-processors at least 30 days in advance, to give the Client the opportunity to object to such changes (Art. 28(2) GDPR).
If the Client objects to a new sub-processor, the Parties shall seek an amicable solution. If no agreement can be reached, either Party is entitled to terminate the main agreement with 30 days’ notice to the end of the month.
The Processor shall impose on the sub-processor the same data protection obligations as those set out in this DPA, in particular by concluding a data processing agreement. The Processor remains liable to the Client for the sub-processor’s compliance with its obligations.
The current list of sub-processors can be requested from the Processor at any time and is published as part of the Platform documentation.
§ 8 Data Transfers to Third Countries
Personal data is, in principle, processed within the European Union or the European Economic Area (EU/EEA). The Platform’s core systems (hosting, database, application servers) are operated on Microsoft Azure in the Frankfurt (Germany) region.
Insofar as sub-processors transfer personal data to third countries or access it from there, the Processor shall ensure that one of the following safeguards pursuant to Art. 44 ff. GDPR is in place:
- An adequacy decision of the European Commission pursuant to Art. 45 GDPR (e.g. the EU-U.S. Data Privacy Framework)
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR
- Binding Corporate Rules pursuant to Art. 47 GDPR
For sub-processors established in the USA, the Processor has verified participation in the EU-U.S. Data Privacy Framework and/or concluded Standard Contractual Clauses. In addition, Transfer Impact Assessments (TIAs) have been carried out to assess the level of data protection in the recipient country and, where necessary, to provide for additional technical safeguards (e.g. encryption, pseudonymization, supplementary contractual safeguards).
The Processor has its registered office in the United Arab Emirates (UAE). However, personal data is processed and stored exclusively on servers located within the EU (Microsoft Azure, Frankfurt region). Administrative remote access to the systems by the Processor’s authorized personnel takes place exclusively via encrypted connections (VPN with end-to-end encryption) and using multi-factor authentication. No personal data is stored on end devices outside the EU. Since remote access from the UAE may be classified as a transfer of personal data to a third country within the meaning of Art. 44 ff. GDPR, the Processor has implemented Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914 as the legal basis for such access. In addition, the Processor has carried out a Transfer Impact Assessment (TIA) which, taking into account the exclusively administrative nature of the access, the encryption employed, the multi-factor authentication, and the fact that no data is stored locally, concludes that the Standard Contractual Clauses, in conjunction with the supplementary technical and organizational measures (see Appendix 2), ensure an adequate level of protection.
Pursuant to Art. 27 GDPR, the Processor has appointed a representative in the European Union: heyData GmbH (Martin Bastius), reachable at datenschutz@heydata.eu. The EU representative serves as a point of contact for data subjects and supervisory authorities.
The documented Transfer Impact Assessments — both for the administrative remote access and for the sub-processors engaged — may be inspected by the Client upon request.
The Parties additionally agree to apply the Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 (Module 2: Transfer from controller to processor) as the legal basis for the administrative remote access from the UAE and for any other transfers of personal data to third countries under this DPA. Details are set out in Appendix 4 (Standard Contractual Clauses) to this DPA.
§ 9 Deletion and Return of Personal Data
Upon termination of the main agreement, the Processor shall — at the Client’s discretion — irrevocably delete all personal data processed on behalf of the Client, or return it to the Client, unless a statutory obligation requires continued storage (Art. 28(3)(g) GDPR). The Client shall communicate its choice no later than within the period set out in paragraph 2. If no notification is provided, the data will be deleted. Deletion shall take place within 60 days after expiry of the export period referred to in paragraph 2, and in any event no later than within 90 days after termination of the agreement.
Prior to deletion, the Processor shall grant the Client a period of 30 days from termination of the agreement to secure its data via the export function provided in the dashboard. The data export is made available in a machine-readable, structured, and commonly used format (CSV/JSON).
During the term of the agreement, the Client may at any time, via the dashboard:
- View and export contact data and call data
- Delete individual data records or campaigns
- Delete call recordings and transcripts
Upon completion of deletion, the Processor shall confirm the deletion in writing or text form upon request.
Statutory retention obligations (in particular commercial- and tax-law retention periods for invoicing data) remain unaffected by the foregoing provisions. Insofar as continued storage is required, the data concerned shall be restricted and processed solely for the legally required purpose.
§ 10 Audit Rights of the Client
The Client has the right to verify the Processor’s compliance with the requirements of this DPA and the applicable data protection provisions. The Processor undertakes to provide the Client with the information necessary for this purpose.
On-site inspections shall be made possible following timely notice (as a rule at least 14 days in advance) and with due regard to the Processor’s operational interests. The Client may be represented by a third party bound to confidentiality.
Alternatively, the Processor may provide current certifications, audit reports, or attestations from independent auditors (e.g. SOC 2 reports, ISO 27001 certifications) as evidence.
Audits of sub-processors: Insofar as the Client wishes to audit a sub-processor engaged by the Processor, such audit shall, in principle, be arranged and conducted directly with the respective sub-processor. Upon request, the Processor shall assist the Client in contacting the sub-processor. Insofar as the sub-processor provides its own audit reports, certifications, or compliance documentation (e.g. SOC 2 reports, ISO 27001 certificates, DPA documentation), the Processor shall forward these to the Client upon request, to the extent it is entitled to do so.
Costs and conditions of audits: Inspections and audits shall be conducted in a manner that does not disproportionately interfere with the Processor’s ongoing business operations. The Client shall bear its own costs for conducting audits. Insofar as an audit causes disproportionate effort on the part of the Processor beyond the provision of the information referred to in paragraphs 1 and 3, the Processor is entitled to charge the additional effort at its then-applicable hourly rates. The Processor shall inform the Client of the anticipated effort before the audit begins.
§ 11 Liability
The liability of the Parties is governed by Art. 82 GDPR. Accordingly, each party involved in the processing is liable for damage caused by processing that does not comply with the GDPR.
The Processor shall be liable to data subjects for damage caused by the processing only if it has failed to comply with obligations under the GDPR specifically directed at processors, or if it has acted outside or contrary to lawful instructions given by the Client.
The Processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
In the internal relationship between the Parties, the Client shall be liable for damage resulting from unlawful data processing insofar as the Client is responsible for the unlawfulness of the instruction or the data collection. This includes, in particular:
- the unlawful collection of contact data
- the absence of a legal basis for making telephone contact
- the content configuration of the AI agents
§ 12 Final Provisions
Amendments and supplements to this DPA must be made in text form. This also applies to any waiver of this text-form requirement.
Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions shall remain unaffected.
In the event of any conflict between this DPA and the main agreement (Terms and Conditions), the provisions of this DPA shall prevail with respect to the protection of personal data.
With respect to data protection law, this DPA is governed by the law of the European Union (GDPR) in conjunction with the applicable national data protection law.
Appendix 1: Description of the Data Processing
1. Subject Matter of the Processing
The Processor provides the Client with the SaaS platform “SalesFrank”. Via the Platform, the Processor, on behalf of the Client, carries out automated, AI-powered telephone calls, records the calls, creates transcriptions, and makes the results available to the Client via a dashboard.
2. Purpose of the Processing
Personal data is processed exclusively for the purpose of:
- Carrying out automated inbound and outbound telephone calls on behalf of the Client
- Recording and transcribing the calls conducted
- Displaying call results and campaign data in the dashboard
- Appointment scheduling and calendar integration (where configured by the Client)
- Follow-up tracking and automated follow-up
- Provision and billing of the Platform
2a. Nature of the Processing Operations
In the course of the processing carried out on the Client’s behalf, the Processor performs the following processing operations within the meaning of Art. 4(2) GDPR:
| Processing Operation | Description |
|---|---|
| Collection | Receipt of contact data uploaded by the Client via the Platform (dashboard, API upload, CSV import) |
| Organization and structuring | Structuring of contact data into campaigns, lists, and categories according to the Client’s configuration |
| Storage | Persistent storage of contact data, call recordings, transcripts, and metadata on the Processor’s EU servers (Microsoft Azure, Frankfurt) |
| Adaptation or alteration | Updating contact data and call status based on call outcomes (e.g. “appointment scheduled”, “not interested”) |
| Retrieval | Access to stored data by the Client via the dashboard, and by the Processor’s authorized personnel in the course of operations |
| Use | Use of contact data to carry out AI-powered telephone calls; use of audio data for real-time transcription and AI processing |
| Disclosure by transmission | Transmission of audio data to voice service providers (STT/TTS) for real-time processing; transmission of text data to LLM services for conducting the conversation (see Appendix 3) |
| Combination | Linking of contact data with call results, transcripts, and scheduled appointments |
| Restriction | Restriction of data upon a data subject’s exercise of the right to restriction, or after termination of the agreement |
| Erasure and destruction | Deletion of individual data records on the Client’s instruction (dashboard); complete deletion after termination of the agreement pursuant to § 9 of this DPA |
3. Categories of Personal Data Processed
a) Client Data (User Data)
- First and last name
- Email address
- Telephone number
- Company data (company name, address)
- Payment information (processed via Stripe)
- Login credentials / user account information
b) Contact Person Data (uploaded by the Client)
- Telephone number (mandatory field for placing the call)
- Other data optionally provided by the Client, including:
- First and last name
- Email address
- Company data (company name, position, industry)
- Other information uploaded by the Client
c) Call Data
- Call recordings (audio)
- Transcripts of the calls
- Call metadata (date, time, duration, outcome, call status)
- Data extracted from calls (e.g. appointments scheduled, qualification results)
4. Categories of Data Subjects
- Platform users: Employees and representatives of the Client who use the Platform
- Contact persons: Natural persons whose contact data the Client uploads to the Platform and who are contacted by the AI agents. These are typically business contacts (B2B) such as managing directors, sales managers, or other decision-makers.
5. Duration of the Processing
Processing takes place for the duration of the main agreement. After termination of the agreement, the data is deleted in accordance with § 9 of this DPA.
Retention periods during the term of the agreement:
| Type of Data | Retention | Deletion |
|---|---|---|
| Contact data | For the duration of the agreement | At any time by the Client in the dashboard, or no later than 90 days after termination of the agreement |
| Call recordings (audio) | For the duration of the agreement | At any time by the Client in the dashboard, or no later than 90 days after termination of the agreement |
| Transcripts | For the duration of the agreement | At any time by the Client in the dashboard, or no later than 90 days after termination of the agreement |
| Call metadata | For the duration of the agreement | No later than 90 days after termination of the agreement |
| Invoicing data | In accordance with statutory retention periods | After expiry of the statutory retention period (generally 10 years) |
Appendix 2: Technical and Organizational Measures (TOMs)
pursuant to Art. 32 GDPR
The Processor has implemented the following technical and organizational measures to protect personal data. The measures are reviewed regularly and adapted to the state of the art.
1. Physical Access Control
Measures to prevent unauthorized persons from gaining physical access to data processing facilities.
- The Platform is operated entirely on cloud infrastructure (Microsoft Azure, Frankfurt region). The Processor does not maintain its own data centers.
- Microsoft Azure meets the requirements of ISO 27001, SOC 1/2/3, and C5 (BSI) and ensures physical access control to its data centers (biometrics, video surveillance, security personnel, access logs).
2. System Access Control
Measures to prevent data processing systems from being used by unauthorized persons.
- Authentication via individual user accounts with strong password policies (minimum length, complexity)
- Multi-factor authentication (MFA) for all administrative access
- Automatic lockout after repeated failed login attempts
- Encrypted VPN connection for all remote access to production systems
- Regular review and updating of access permissions
3. Data Access Control
Measures to ensure that authorized persons can access only the data subject to their access authorization.
- Role-based access control (RBAC) with strict separation of responsibilities
- Need-to-know principle: access to personal data only for employees who require such access to perform their tasks
- Administrative access is limited to the development and operations team
- No external developers or service providers have access to personal data
- Logging of all administrative access to production systems
4. Transfer Control
Measures to ensure that personal data cannot be read, copied, altered, or removed without authorization during transmission or storage.
- Encryption of all data in transit using TLS 1.2 or higher (Transport Layer Security)
- Encryption of all data at rest using AES-256 on Azure infrastructure
- Encrypted database connections (MongoDB with TLS)
- Encrypted API communication between all system components
- No storage of personal data on employees’ local devices
5. Input Control
Measures to ensure that it can be verified retroactively whether and by whom personal data has been entered, altered, or removed.
- Logging of data entries, changes, and deletions in the system (audit logging)
- User-specific attribution of all actions via authenticated user accounts
- Tamper-evident logging of administrative access
6. Job Control
Measures to ensure that personal data processed on behalf of the Client is processed solely in accordance with the Client’s instructions.
- Written data processing agreements with all sub-processors
- Careful selection of sub-processors based on data protection criteria
- Regular review of sub-processors’ compliance with their contractual obligations
- Binding instructions applicable to the Processor’s employees
7. Availability Control
Measures to ensure that personal data is protected against accidental destruction or loss.
- Hosting on Microsoft Azure with geo-redundant infrastructure in the Frankfurt region
- Automated daily backups of the database (MongoDB), retained for at least 30 days
- Backups are stored encrypted and kept in a geographically separate Azure availability zone within the EU
- Redundant system architecture to avoid single points of failure
- Monitoring and alerting for system outages and anomalies (24/7)
- Disaster recovery concept with defined recovery objectives (RTO: 24 hours, RPO: 24 hours)
- Regular testing of recovery procedures
8. Separation Control
Measures to ensure that data collected for different purposes can be processed separately.
- Logical multi-tenant separation: each customer’s data is stored and processed separately using individual tenant identifiers
- Strict separation of production, staging, and development environments
- Test environments use exclusively anonymized or synthetic data
9. Organizational Measures
- Written commitment of all employees to data secrecy and confidentiality
- Regular awareness training for employees on data protection and information security
- Documented process for handling data protection incidents (incident response process):
- Detection and classification of the incident
- Immediate containment measures
- Analysis and assessment of the impact
- Notification of the Client (within 24 hours)
- Remediation and documentation
- Follow-up and derivation of improvement measures
- Regular review and update of the technical and organizational measures (at least annually)
Appendix 3: Approved Sub-Processors
As of: June 2026
The Processor engages the following sub-processors to provide the contractually agreed services:
| No. | Sub-Processor | Location | Processing Location | Purpose of Processing | Legal Basis for Third-Country Transfer |
|---|---|---|---|---|---|
| 1 | Microsoft Ireland Operations Ltd (Microsoft Azure) | Ireland (EU) | Frankfurt (Germany) | Hosting of the Platform, compute, storage, database (MongoDB), LLM processing (Azure OpenAI Service, Azure AI) | Processing within the EU — no third-country transfer |
| 2 | Twilio Ireland Ltd | Ireland (EU) | EU (Ireland) | Provision of telephone numbers, telephony infrastructure, call setup | Processing within the EU — no third-country transfer |
| 3 | Stripe Payments Europe Ltd | Ireland (EU) | EU | Payment processing, subscription management, invoicing | Processing within the EU — no third-country transfer. With respect to payment data, Stripe acts as an independent controller (see note to No. 3). |
| 4 | ElevenLabs, Inc. | USA | USA/EU | Speech synthesis (text-to-speech) and, where applicable, speech recognition (speech-to-text) for AI phone calls | EU-U.S. Data Privacy Framework; supplemented by SCCs pursuant to Art. 46(2)(c) GDPR; TIA carried out |
| 5 | Deepgram, Inc. | USA | EU | Speech recognition (speech-to-text) — real-time transcription of calls | Processing via EU hosting region — no third-country transfer |
| 6 | Cartesia, Inc. | USA | USA | Speech synthesis (text-to-speech) for AI phone calls | SCCs pursuant to Art. 46(2)(c) GDPR; TIA carried out |
| 7 | Microsoft Ireland Operations Ltd (Microsoft Azure) | Ireland (EU) | Frankfurt (Germany) | Hosting of the self-hosted LiveKit instance — the primary real-time voice communication infrastructure for orchestrating AI phone calls (connecting telephony, STT, LLM, and TTS) | Processing within the EU — no third-country transfer (self-hosted open-source software) |
Notes on the Sub-Processors
On No. 1 — Microsoft Azure: All core services (hosting, database, application servers, LLM processing) are operated in the Azure Frankfurt (Germany) region. The use of Azure OpenAI Service and Azure AI likewise takes place within the EU region. No transfer of personal data to third countries occurs.
On No. 2 — Twilio: Twilio Ireland Ltd operates the telephony infrastructure for the European market with servers located in Ireland. Telephone numbers are provisioned via the Irish entity.
On No. 3 — Stripe: Stripe Payments Europe Ltd processes payment data exclusively within the EU. Stripe is PCI DSS Level 1 certified. Note on data protection role: With respect to payment data (credit card data, bank details, transaction data), Stripe acts as an independent controller under Art. 4(7) GDPR and is therefore not subject to the Client’s right to issue instructions in this respect. Stripe is listed in this Appendix for the sake of completeness and transparency, although it is not, strictly speaking, a sub-processor. Stripe’s processing is based on Stripe’s own privacy policy (stripe.com/privacy).
On No. 4–6 — Voice service providers (ElevenLabs, Deepgram, Cartesia): These providers are engaged for the real-time processing of voice data during calls. Processing takes place as real-time stream processing:
- Audio data is transmitted to the providers in real time and processed immediately
- The providers do not permanently store the audio data — processing occurs transiently in memory
- Transmission is encrypted (TLS 1.2+)
- Data processing agreements (DPAs) and, where applicable, Standard Contractual Clauses (SCCs) have been concluded with all providers
- A Transfer Impact Assessment (TIA) has been carried out for each US provider, concluding that, in conjunction with the technical and contractual measures described, an adequate level of protection is ensured
- For Deepgram, the EU hosting region has been activated; processing takes place exclusively on EU servers, and no third-country transfer occurs
On No. 7 — LiveKit (self-hosted on Azure EU): The Processor operates a self-hosted instance of the open-source software LiveKit on Microsoft Azure in the Frankfurt (Germany) region. LiveKit serves as the primary real-time communication infrastructure for orchestrating AI phone calls and coordinates the connection between telephony (Twilio), speech recognition (STT), the language model (LLM), and speech synthesis (TTS). As this is a self-hosted open-source solution, no personal data is transmitted to LiveKit, Inc. as a company. Data processing takes place exclusively on the Azure EU infrastructure controlled by the Processor. The Processor has full technical control over this instance, including configuration, updates, and access management. No third-country transfer occurs.
Calendar integration (e.g. Cal.com, Calendly): Calendar service integrations are set up independently by the Client. The Client connects its own calendar provider to the Platform. The Processor is not a processor with respect to these third-party services; data protection responsibility for the use and configuration of these services lies with the Client.
Appendices to this DPA:
- Appendix 1: Description of the Data Processing
- Appendix 2: Technical and Organizational Measures (TOMs)
- Appendix 3: Approved Sub-Processors
- Appendix 4: Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914 (separate document: sccs-salesfrank.md)
Signature of Client:
Place, date: ____________________________
Name, position: ____________________________
Signature: ____________________________
Signature of Processor:
Another Side Ventures FZ-LLC
Place, date: ____________________________
Name, position: ____________________________
Signature: ____________________________