Data Processing Addendum
When this applies. Only where we host Call2KOT for you. If you run it on your own server we process nothing on your behalf and this addendum is not needed — though you may still want it on file.
1 · Roles
You are the controller. You decide why and how personal data is processed, and you own the relationship with the people it concerns.
We are the processor. We act only on your documented instructions, which are this addendum and the service agreement.
2 · What we process, and why
| Category | Data | Purpose |
|---|---|---|
| Callers | Phone number, name if given, delivery address, order contents, language, transcript | Taking and fulfilling the order |
| Staff | Name, work email, role | Signing in, and the audit trail |
| Call audio | Only where you switch it on | Improving recognition accuracy for your menu and your callers' accents |
3 · Our obligations
- Process only on your instructions, and tell you if we believe an instruction breaches applicable law.
- Keep everyone with access under a duty of confidence.
- Apply the measures in section 6.
- Help you respond to requests from individuals, and to regulators.
- Tell you of a personal data breach without undue delay, and in any case within 48 hours of becoming aware.
- Delete or return everything at the end of the contract, at your choice.
- Make available what you need to verify the above.
4 · Sub-processors
We use the following. You may object to a new one, and if we cannot accommodate the objection you may terminate.
| Who | What for | Where |
|---|---|---|
| Anthropic | Understanding the order | United States |
| Deepgram | Speech recognition | United States |
| Microsoft Azure | Speech synthesis | UAE North, where available |
| Meta Platforms | WhatsApp delivery, if enabled | Per Meta's terms |
Each is engaged under terms no less protective than these, and none trains models on your data.
5 · International transfers
Where data leaves the UAE it does so under the sub-processor's standard contractual clauses or equivalent safeguards. If your policy requires that nothing leaves the country, deploy on your own server and enable the local model, then nothing does.
6 · Security measures
- TLS in transit; AES-256-GCM for stored credentials.
- bcrypt password hashing; multi-factor authentication on operator accounts.
- Role-based access, with tenant isolation enforced in the query layer.
- An audit trail of every change, including any access by our support staff, visible to you.
- Rate limiting, origin validation, and signature verification on inbound webhooks.
- Regular security review; four audits completed to date.
7 · Audit
Once a year, on reasonable notice, you may audit our compliance — or accept a recent third-party report in place of one. We will answer a security questionnaire at any time.
8 · Liability and term
This addendum takes the liability provisions of the service agreement, and lasts as long as we process anything on your behalf.
9 · Signing it
Email legal@call2kot.com and we will send a countersigned copy. If your organisation has its own DPA, send it. We will review yours rather than insist on ours.