Legal
Data Processing Addendum
Version 2026-08-01
This Data Processing Addendum (“DPA”) forms part of the agreement between AlwaysGreet LLC (“AlwaysGreet”) and Customer and applies when AlwaysGreet processes Customer Personal Data on Customer’s behalf.
1. Definitions and scope
“Applicable Data Protection Law” means privacy and data-protection laws applicable to the processing. “Customer Personal Data” means personal information contained in Customer Data processed by AlwaysGreet as processor, service provider, or contractor. “Security Incident” means unauthorized access to, acquisition, disclosure, alteration, or destruction of Customer Personal Data, excluding unsuccessful attempts that do not compromise security.
Terms such as controller, processor, business, service provider, contractor, consumer, and personal information have the meanings given by applicable law.
2. Roles and instructions
Customer is controller/business and AlwaysGreet is processor/service provider for Customer Personal Data. Customer instructs AlwaysGreet to process Customer Personal Data to provide, secure, support, and maintain the Services; comply with documented lawful instructions; and perform the agreement.
Customer is responsible for lawful instructions, notices, consents, data accuracy, and minimizing data. AlwaysGreet will notify Customer if an instruction appears to violate Applicable Data Protection Law, unless prohibited from doing so.
3. Processing restrictions
AlwaysGreet will:
- process Customer Personal Data only for the limited and specified purposes in the agreement and Customer’s documented instructions;
- not sell or share Customer Personal Data or retain, use, or disclose it outside the direct business relationship except as permitted by law;
- not combine Customer Personal Data with personal information received from another person or collected from AlwaysGreet’s own consumer interactions, except as legally permitted to provide the Services;
- not use identifiable recordings or transcripts to train general-purpose AI models without separate explicit permission;
- ensure personnel with access are subject to confidentiality obligations; and
- provide the same level of privacy protection required of a service provider or contractor under applicable law.
Customer may take reasonable steps to verify compliance and may require AlwaysGreet to stop and remediate unauthorized processing.
4. Security
AlwaysGreet will maintain a written security program with measures appropriate to the nature and risk of processing, including the measures in Annex B. AlwaysGreet may update safeguards without materially reducing overall protection.
5. Subprocessors
Customer gives general authorization to use subprocessors. AlwaysGreet will maintain a current list, impose written data-protection obligations appropriate to each subprocessor, and remain responsible for its DPA obligations.
AlwaysGreet will provide reasonable advance notice of a material new subprocessor. Customer may object on reasonable, documented data-protection grounds within 10 days. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected feature, and AlwaysGreet will refund prepaid unused fees for that feature.
6. Individual requests
Taking into account the nature of processing, AlwaysGreet will provide reasonable assistance for verified requests to access, correct, delete, restrict, object, or obtain Customer Personal Data. If AlwaysGreet directly receives a request concerning Customer-controlled data, it may direct the requester to Customer and will not independently respond unless authorized or legally required.
7. Security incidents
AlwaysGreet will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include available information reasonably necessary for Customer’s response, such as nature, affected data, likely consequences, mitigation, and contact information. Information may be provided in phases. Notice is not an admission of fault.
AlwaysGreet will take reasonable steps to contain, investigate, remediate, and prevent recurrence and will reasonably cooperate with Customer’s legally required notifications. Customer is responsible for determining whether notification is required, except for AlwaysGreet’s independent legal obligations.
8. Assessments, audits, and cooperation
AlwaysGreet will provide information reasonably necessary to demonstrate compliance, which may include current security summaries, policies, questionnaires, or independent reports when available. No more than once annually, unless required by law or following a Security Incident, Customer may request a reasonable remote audit at Customer’s expense, subject to confidentiality, security, and protection of other customers.
AlwaysGreet will provide reasonable assistance with data-protection impact assessments and regulator consultations considering the nature of processing and information available.
9. Return and deletion
During the term, Customer may export supported data. After termination or Customer instruction, AlwaysGreet will delete or return Customer Personal Data within a commercially reasonable period, unless law requires retention. Data in isolated backups will be protected and deleted under the backup lifecycle. Default call recording and transcript retention is 30 days unless shortened by Customer.
10. International transfers
The launch service is intended for United States customers and processing. Before enabling a restricted international transfer, the parties will implement a legally valid transfer mechanism where required. Customer must not use the Services for regulated international processing until AlwaysGreet confirms support in writing.
11. HIPAA exclusion
This DPA is not a Business Associate Agreement. Customer must not submit PHI or use the Services for a HIPAA-regulated workflow unless the parties execute a separate BAA and AlwaysGreet confirms the applicable configuration.
12. Conflict and liability
This DPA controls over conflicting privacy terms in the underlying agreement. Liability under this DPA is subject to the agreement’s limitations unless a signed order form expressly states otherwise.
Annex A — Processing details
Subject matter: Inbound AI receptionist, message intake, appointment scheduling, account administration, and support.
Duration: Subscription term plus limited retention and deletion period.
Frequency: Continuous or on-demand based on inbound calls and Customer use.
Data subjects: Customer personnel, authorized users, callers, prospective customers of Customer, and appointment participants.
Data categories: Business contact details; telephone numbers; call metadata; voice audio when enabled; transcripts; messages; appointment details; caller-provided statements; authentication and account data; configuration; technical and security logs.
Sensitive data: Not intentionally permitted. PHI, payment-card data, government identifiers, passwords, and authentication codes are prohibited at launch.
Purposes: Provide, secure, maintain, support, troubleshoot, and improve the Services under Customer’s instructions.
Deletion: Recordings and transcripts default to 30 days; earlier Customer deletion supported where available; other data according to account need, agreement, and legal obligations.
Annex B — Minimum security measures
- Role-based and least-privilege access controls
- Multi-factor authentication for privileged systems where supported
- Encryption in transit and appropriate encryption at rest
- Production credential and secret management
- Logging and monitoring of authentication, administrative activity, and security events
- Secure software-development and change-management practices
- Dependency, vulnerability, and patch management
- Backups, restoration testing, and business-continuity planning proportionate to risk
- Incident-response procedures and escalation contacts
- Personnel confidentiality and security-awareness measures
- Subprocessor diligence and written security/privacy obligations
- Data minimization, configurable retention, and secure deletion processes
- Periodic risk review and access review
Annex C — Subprocessor categories
The public Subprocessor Notice must identify the production providers actually enabled before launch, including:
- Vercel — application hosting and delivery
- Clerk — authentication and identity
- Twilio — telecommunications and telephone numbers
- Retell AI — voice-agent, speech, call processing, and related call data
- Production database provider — must be confirmed before publication
- Payment processor — must be confirmed before paid launch
- Transactional email/support provider — must be confirmed before launch
- Monitoring/analytics providers — must be confirmed and configured to avoid call content unless necessary