Data Processing Addendum (DPA)
PRE-RELEASE DRAFT FOR LEGAL REVIEW
This document sets forth the data processing terms governing Customer Personal Data processed by the Hisenbug voice platform prepared for the commercial pilot release. Subject to qualified legal counsel review.
Effective Date: [To be confirmed upon publication]
Last Updated: September 15, 2026
Data Importer / Processor: [Hisenbug Legal Entity — to be confirmed] ("Hisenbug")
Data Exporter / Controller: The Customer entering into the Terms of Service ("Customer")
Contact: hello@hisenbug.com
1. Scope, Purpose & Precedence
- Contractual Framework: This Data Processing Addendum ("DPA") supplements and forms an integral part of the Hisenbug Terms of Service or other executed master agreement governing Customer's use of the Services (the "Agreement").
- Standard & Enterprise Availability: This DPA applies automatically to all customer accounts where the processing of Customer Personal Data is governed by Applicable Data Protection Law. Enterprise customers may execute a signed, standalone counterpart of this DPA upon request.
- Order of Precedence: In the event of any conflict between the terms of this DPA and the Agreement, the terms of this DPA shall govern with respect to the processing of Personal Data, except where an executed custom Order Form explicitly amends this DPA.
2. Definitions
For the purposes of this DPA, capitalized terms not otherwise defined herein shall have the meanings assigned to them in the Agreement:
- "Applicable Data Protection Law" means all worldwide privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including the European Union General Data Protection Regulation (2016/679) ("EU GDPR"), the United Kingdom Data Protection Act 2018 and UK GDPR ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), and the Australian Privacy Act 1988 (Cth).
- "Customer Personal Data" means any Personal Data processed by Hisenbug on behalf of Customer in connection with the provision of the Services, as described in Annex I.
- "Data Controller" (or "Business") means the entity that determines the purposes and means of the processing of Personal Data.
- "Data Processor" (or "Service Provider") means the entity that processes Personal Data on behalf of the Data Controller.
- "Personal Data Breach" means a confirmed security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed by Hisenbug.
- "Subprocessor" means any third-party processor engaged by Hisenbug who receives Customer Personal Data for processing activities on behalf of Customer.
3. Roles & Processing Instructions
- Role Allocation:
- Customer acts as the Data Controller (or Business) with respect to Customer Personal Data processed through the voice agent platform (including caller telephone numbers, call audio, transcripts, extracted lead records, and scheduling requests).
- Hisenbug acts as the Data Processor (or Service Provider) with respect to Customer Personal Data.
- Drafting Qualification: Final legal characterization of roles across specific jurisdictions remains subject to qualified legal counsel review.
- Customer Warranties: Customer warrants that it has established all necessary lawful bases, provided all mandatory statutory disclosures, and obtained all required consents (including all-party wiretap consents where applicable) to authorize Hisenbug to process Customer Personal Data pursuant to the Agreement and this DPA.
- Documented Instructions: Hisenbug shall process Customer Personal Data solely in accordance with Customer's documented instructions, including:
- To deliver, maintain, and support the Services;
- As configured by Customer via portal settings, prompt guidelines, and scheduling rules;
- In compliance with Customer-initiated deletion requests; and
- As required by applicable statutory law, in which case Hisenbug will notify Customer unless prohibited by law on important public interest grounds.
- CCPA/CPRA Service Provider Commitments: Hisenbug covenants that it:
- Shall not "sell" or "share" (as defined under the CCPA/CPRA) Customer Personal Data;
- Shall not retain, use, or disclose Customer Personal Data for any purpose other than for the business purposes specified in the Agreement; and
- Shall not combine Customer Personal Data with personal data received from or on behalf of other third parties, except as expressly permitted under the CCPA/CPRA.
4. Confidentiality
Hisenbug shall ensure that all personnel (including employees, contractors, and agents) authorized to access or process Customer Personal Data:
- Are informed of the confidential nature of the data;
- Have received appropriate training on data protection and confidentiality; and
- Are bound by written confidentiality obligations or professional statutory duties of confidentiality that survive termination of their engagement.
5. Subprocessors
- General Authorization: Customer grants Hisenbug general written authorization to engage the Subprocessors listed in the Subprocessor Disclosure and Annex III of this DPA.
- Direct vs. Indirect Subprocessors:
- Direct Infrastructure Providers: Hisenbug directly contracts with Vapi (voice orchestration), Supabase (database), Vercel (web hosting), Oracle Cloud Infrastructure (VPS compute), Groq (QA inference), and Jina AI / Elastic (vector embeddings).
- Indirect Downstream Providers: Conversational speech recognition (Deepgram), language modeling (OpenAI), speech synthesis (ElevenLabs), and Vapi downstream telecommunications, carrier, and media infrastructure providers are engaged by Vapi under Vapi's contractual framework. Specific downstream providers and processing locations may depend on Vapi's applicable service architecture, routing, and contractual documentation.
- Subprocessor Obligations: Hisenbug maintains appropriate contractual data-protection arrangements with its direct Subprocessors and relies on the applicable contractual framework of relevant upstream providers for downstream providers engaged through those providers, to the extent permitted and required by Applicable Data Protection Law.
- Advance Notice of Subprocessor Changes:
- Hisenbug will provide Customer with at least thirty (30) days' advance written notice of any intended material addition, replacement, or change to its Subprocessor list via portal notification or email.
- Customer Objection Mechanism:
- Customer may object to a new Subprocessor on reasonable, documented data protection grounds by notifying Hisenbug in writing within the 30-day notice window.
- If Customer submits a timely objection, the parties will consult in good faith to resolve the concern. If a mutually satisfactory resolution cannot be achieved, Customer may terminate the affected Services without penalty by providing written notice prior to the expiration of the notice period.
6. Technical & Organizational Security Measures
- Implementation of Safeguards: Hisenbug shall implement and maintain appropriate technical and organizational measures ("TOMs") designed to ensure a level of security appropriate to the risk of processing Customer Personal Data, as set forth in Annex II.
- Review & Updates: Hisenbug may update its technical security measures from time to time, provided that such modifications do not materially degrade the overall security of the Services.
7. Assistance with Data Subject Rights
- Assistance Mechanism: Taking into account the nature of the processing, Hisenbug shall provide reasonable technical assistance to Customer to enable Customer to fulfill its statutory obligations to respond to consumer requests exercising rights under Applicable Data Protection Law (including access, rectification, erasure, data portability, and objection).
- Self-Service Portal Controls: Customer shall utilize the self-service tools available in the portal (such as the asynchronous lead deletion interface) to fulfill data subject erasure requests directly.
- Direct Inquiries: If Hisenbug receives a data subject request directly from a caller or prospective lead, Hisenbug shall promptly direct the individual to submit their request to Customer, and shall not respond directly except to confirm that the request relates to Customer.
8. Personal Data Breach Notification & Incident Response
- Notification Commitment: Hisenbug will notify Customer account administrators:
Without undue delay and, where reasonably practicable, within forty-eight (48) hours after confirming a Personal Data Breach affecting Customer Personal Data.
- Notification Details: To the extent known at the time of notification, the notice shall include:
- A description of the nature of the breach, including categories of data and approximate number of affected data subjects;
- Likely consequences of the breach;
- Corrective measures taken or planned to mitigate potential adverse effects; and
- Contact details of Hisenbug's privacy operations team.
- Breach Mitigation: Hisenbug shall take prompt commercial steps to investigate, contain, and remediate any confirmed Personal Data Breach.
- Customer Reporting Duties: Customer remains responsible for determining whether the incident triggers mandatory statutory reporting to supervisory authorities or affected individuals under applicable laws.
9. Data Deletion, Return & Retention Schedules
- Automated Data Purge Lifecycle: Hisenbug enforces programmatic lifecycle schedules governing Customer Personal Data:
- Call Audio Recordings: Programmatically deleted from upstream telephony storage at sixty (60) days post-call.
- Conversation Transcripts & QA Quotes: Programmatically scrubbed from operational databases at one hundred twenty (120) days post-call.
- Direct Caller Phone Numbers: Operational caller identifiers stored in the telephony ledger are anonymized after twelve (12) months (specifically,
calls.caller_numberand relationalcalls.lead_idare permanently set toNULL). In contrast, Customer CRM records are retained according to customer configuration, customer deletion instructions, the Agreement, and applicable law, subject to the stated service lifecycle and legal/operational retention requirements. - Operational Telephony Ledger: Anonymized metrics (duration, timestamps, disposition, cost metrics) retained for up to thirty-six (36) months for carrier reconciliation and dispute defense, after which they are deleted or further aggregated.
- Post-Termination Deletion: Following termination, Hisenbug will delete or return Customer Personal Data in active systems within the period specified in the Agreement [COUNSEL TO CONFIRM POST-TERMINATION DELETION PERIOD], subject to applicable law and limited operational records expressly identified in the retention schedule.
- Database Backups Disclosure: The production database operates on the Supabase Free plan. Hisenbug does not maintain customer-accessible automated database backups or point-in-time recovery on this plan. Data deletion from active production storage is not supplemented by a Hisenbug-managed customer backup system.
10. Audits & Compliance Verification
- Information Verification: Hisenbug will provide Customer with reasonable documentation necessary to demonstrate compliance with the obligations laid down in this DPA upon written request, not more than once per twelve-month period.
- Audit Procedures: If Applicable Data Protection Law requires a formal audit, Customer (or an independent third-party auditor bound by customary confidentiality agreements) may conduct an inspection of Hisenbug's data processing policies, provided that:
- Customer provides at least thirty (30) days' advance written notice;
- The audit is conducted during normal business hours without disrupting operations; and
- Customer bears all costs associated with the audit.
11. International Cross-Border Data Transfers
- International Processing Locations: Customer acknowledges that Customer Personal Data will be processed across international infrastructure, including the United States, Saudi Arabia (OCI Jeddah VPS), and global edge distribution points.
- International Transfer Mechanism: Where required by Applicable Data Protection Law, the parties intend to implement an appropriate international transfer mechanism, which may include the EU Standard Contractual Clauses and/or the UK International Data Transfer Addendum, as applicable to the relevant transfer. The applicable module, party details, appendices, transfer details, and supplementary measures must be completed and validated by qualified counsel before execution.
12. Limitation of Liability
The liability of each party and its affiliates arising out of or related to this DPA (whether in contract, tort, or under any other theory of liability) shall be subject to the limitations and exclusions of liability set forth in the Terms of Service.
Annex I — Details of Processing
- Subject Matter: The provision of artificial intelligence voice agent call answering, conversation transcription, showing scheduling, and CRM lead synchronization services.
- Duration of Processing: The duration of the Agreement plus applicable retention purge cycles (up to 36 months for operational telephony records).
- Nature and Purpose of Processing:
- Inbound telephone call answering and routing;
- Real-time automated speech-to-text tokenization and speech synthesis;
- Conversational dialogue reasoning and appointment scheduling;
- Extraction and structuring of lead preferences;
- Delivery of notification alert cards to Customer Slack channels; and
- Quality assurance scoring and price-guard verification.
- Categories of Data Subjects: Inbound telephone callers, property inquiry leads, prospective buyers, renters, sellers, and Customer authorized personnel.
- Categories of Personal Data: Caller names, telephone numbers, digital voice audio recordings, conversation transcripts, property preferences, budget parameters, appointment timestamps, and post-call evaluation quotes.
- Special Categories of Data: The Services are not designed or intended for processing special categories of personal data, protected health information, payment-card data, or biometric identification data. Customer must not intentionally submit or configure the Services to process such data except as expressly agreed in writing.
Annex II — Technical & Organizational Security Measures (TOMs)
Hisenbug implements and maintains the following technical and organizational security measures:
- Access Control & Identity Isolation:
- Application user authentication enforced via Supabase Auth.
- Supabase Auth, application-level authorization, tenant-scoped queries, and database-level access controls are used to enforce tenant isolation.
- Access to production servers restricted to authorized administrative personnel via public-key authentication.
- Encryption Safeguards:
- HTTPS/TLS is used to encrypt applicable web and API communications in transit.
- Stored Slack OAuth access tokens are encrypted using AES-256-GCM before persistence.
- Presigned, short-lived URLs utilized for secure call audio playback.
- Network & Host Hardening:
- Production tool servers hosted on Oracle Cloud Infrastructure running hardened Ubuntu 24.04 ARM64.
- Caddy reverse proxy terminates TLS and manages automatic certificate renewals.
- Background workflow container (n8n) strictly bound to internal loopback (
127.0.0.1:5678), shielded from public ingress. - Backend Node.js process managed under systemd with non-root service execution.
- Data Minimization & Automated Lifecycle:
- Automated scheduled service (systemd timer on production host) programmatically deletes call recordings at 60 days.
- Automated scheduled service scrubs dialogue transcripts and QA quotes at 120 days.
- Automated scheduled service anonymizes direct caller phone numbers at 12 months.
- Automated container log pruning clears n8n workflow execution data after 72 hours.
- Asynchronous deletion outbox worker ensures resilient deletion propagation across multi-system pipelines.
Annex III — International Data Transfer Framework
[COUNSEL TO COMPLETE AND VALIDATE APPLICABLE MODULES, TABLES, AND SUPPLEMENTARY MEASURES BEFORE EXECUTION]
Where required by Applicable Data Protection Law, the parties intend to implement an appropriate international transfer mechanism, which may include the EU Standard Contractual Clauses and/or the UK International Data Transfer Addendum, as applicable to the relevant transfer. The applicable module, party details, appendices, transfer details, and supplementary measures must be completed and validated by qualified counsel before execution.
- EU Standard Contractual Clauses (EU SCCs):
- Where transfers from the European Economic Area are governed by EU GDPR, the parties intend to incorporate the Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914.
- The applicable module (e.g., Module 2: Controller-to-Processor), docking clause, subprocessor authorization option, governing law, and competent jurisdiction must be confirmed and completed by qualified counsel prior to execution.
- UK International Data Transfer Addendum:
- Where transfers from the United Kingdom are governed by UK GDPR, the parties intend to incorporate the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0).
- The required mandatory tables, selections, and alternative commercial provisions must be completed and validated by qualified counsel before execution.
Data Processing Addendum incorporated by reference into Hisenbug Customer Agreements.