Data Processing Agreement (DPA)
Last updated: 24 July 2026
This DPA forms part of the service agreement between AiAnchor (“Processor”) and the Client (“Controller”) and governs our processing of personal data, in particular caller data, on the Client’s behalf under Article 28 GDPR. A countersigned copy is available on request at info@aianchor.online.
1. Scope and roles
The Client is the controller of personal data processed through its voice agent, automations and portal workspace. AiAnchor processes that data only as processor, on the Client’s documented instructions, for the purposes in section 2. AiAnchor is separately a controller for its own account and billing data, covered by the Privacy Policy.
2. Subject matter, duration, nature and purpose
3. Categories of data subjects and personal data
- Data subjects: the Client’s callers (third parties), and the Client’s staff who use the portal or appear in call flows.
- Personal data: call audio recordings, transcripts, AI-generated summaries and sentiment/lead analysis, caller phone numbers, names and contact details shared during calls, appointment details, portal user accounts.
- Special categories: not intended. The Client must not configure flows that solicit special-category data without a separate written agreement (see Terms, section 6).
4. Processing on instructions
We process personal data only on the Client’s documented instructions (the agreement, the agent configuration, and written directions), unless EU or Member State law requires otherwise, in which case we inform the Client before processing unless the law prohibits it. We inform the Client if an instruction, in our opinion, infringes data protection law.
5. Confidentiality and security (Art. 32)
- Personnel authorised to process the data are bound by confidentiality obligations.
- Encryption in transit (TLS) for all systems; encryption at rest on our database and storage providers.
- Tenant isolation in the portal: each Client’s workspace is segregated (Supabase row-level security). PLACEHOLDER: confirm RLS is enforced on all tables.
- Role-based access on least-privilege; access to production data restricted to authorised personnel. PLACEHOLDER: confirm MFA on admin accounts.
- Webhook payloads between systems are signature-verified. PLACEHOLDER: confirm implementation status.
- Logging of administrative access and processing activity. PLACEHOLDER: confirm audit-log coverage.
6. Subprocessors
The Client grants general authorisation to the subprocessors below. We will give at least 30 days’ notice before adding or replacing a subprocessor (email or portal notice); the Client may object on reasonable data-protection grounds, in which case the parties will seek a solution and the Client may terminate the affected service if none is found. Each subprocessor is bound by data-protection terms no less protective than this DPA.
7. Assistance with data subject rights
Taking into account the nature of the processing, we assist the Client with appropriate technical and organisational measures in fulfilling data subject requests (access, deletion, portability and the rest of Arts. 15–22). If a caller contacts us directly, we forward the request to the Client without undue delay and do not respond on the merits unless instructed. PLACEHOLDER: confirm what the portal supports today for per-caller export/deletion; interim requests are handled manually by support.
8. Personal data breach notification
We notify the Client without undue delay after becoming aware of a personal data breach affecting the Client’s data, and in any case within PLACEHOLDER: confirm commitment (commonly 48 hours), providing the information required by Art. 33(3) GDPR as it becomes available: nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken. Notifying the supervisory authority and data subjects remains the Client’s responsibility as controller; we assist.
9. Deletion and return
On termination, at the Client’s choice, we return the Client’s personal data (portal export) and delete existing copies within PLACEHOLDER: confirm window (e.g. 30 days), unless EU or Greek law requires storage. Deletion extends to subprocessors per their retention terms.
10. Audits
We make available the information necessary to demonstrate compliance with Art. 28 (including subprocessor certifications such as SOC 2 reports where available) and allow for and contribute to audits conducted by the Client or a mandated auditor, on reasonable notice, at most once per year unless a supervisory authority requires otherwise or a breach has occurred, and subject to confidentiality.
11. International transfers
Transfers outside the EEA occur only under Chapter V GDPR safeguards: the subprocessors above rely on EU Standard Contractual Clauses (and the EU–US Data Privacy Framework where certified). We will inform the Client of any change affecting transfer mechanisms.
12. Liability and precedence
Liability follows the service agreement’s limitation of liability. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters. PLACEHOLDER: counsel to confirm.
13. Getting a countersigned copy
Email info@aianchor.online with the subject “DPA request” and your company details; we return a countersigned PDF. The current subprocessor list is always on this page and on Trust & Security.