This Data Processing Agreement applies to every Acastia client. It sets out how Acastia processes personal data on the client's behalf, as Article 28 of the GDPR requires, and it incorporates the European Commission's standard contractual clauses for controllers and processors.
1. Parties and scope
1.1 This Data Processing Agreement (the "DPA") is made between the customer (the "Controller") and Acastia (the "Processor"), together the "Parties". It forms part of the agreement under which Acastia provides its services to the customer, consisting of Acastia's Terms of Service and the customer's plan (together the "Agreement").
1.2 This DPA applies whenever the Processor processes personal data on the Controller's behalf in providing the services, as described in Annex II.
1.3 This DPA applies for as long as the Processor processes such personal data. It survives the end of the Agreement until the data has been deleted or returned under section 9.
1.4 Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given to them in Regulation (EU) 2016/679 (the "GDPR").
2. The EU standard contractual clauses
2.1 The standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (the "Clauses") are incorporated into this DPA by reference and form part of it. The Clauses are available in every official EU language on EUR-Lex.
2.2 The appendices to the Clauses are completed by Annexes I to IV of this DPA.
2.3 The Parties make the following choices under the Clauses:
- Clause 5 (docking clause): does not apply.
- Clause 7.7(a): Option 2, general written authorisation. The Processor shall inform the Controller in writing of any intended addition or replacement of a sub-processor at least 30 days in advance.
2.4 The other sections of this DPA supplement the Clauses. They are to be read consistently with the Clauses and do not limit them. If anything in this DPA or the Agreement conflicts with the Clauses, the Clauses prevail (Clause 4).
3. Instructions and responsibilities
3.1 The Processor processes the personal data only on the Controller's documented instructions (Clause 7.1). These instructions are:
- this DPA and the Agreement;
- the set-up of the Controller's agents and services as approved by the Controller, for example what its agents say and do, which tools they may use (such as booking appointments or sending messages), whom they call, and where messages and summaries are sent;
- any further instructions the Controller gives in writing, in the dashboard or by email to privacy@acastia.com.
3.2 If an instruction requires work beyond the services covered by the Agreement, the Parties agree on any cost before the Processor carries it out.
3.3 The Processor informs the Controller immediately if, in its opinion, an instruction infringes the GDPR or other EU or member state data protection law (Clause 7.1(b)). It is not required to carry out that instruction until the Controller has confirmed or changed it.
3.4 The Processor does not use the personal data for its own purposes. It does not sell the data or use it for its own marketing, and it does not use it, or allow its sub-processors to use it, to train AI models. Reviewing the Controller's calls and conversations to improve the Controller's own agents is part of the services (Annex II). The Processor may use aggregated figures that identify no one, such as numbers of calls, call lengths and costs, to bill, run and improve its services.
3.5 The Controller is responsible for the lawfulness of the processing it instructs. In particular, the Controller is responsible for:
- having a legal basis for the processing;
- informing the people its agents deal with about the processing of their personal data (Articles 13 and 14 GDPR);
- making sure that the people its agents call, text or email may lawfully be contacted, including any prior consent required by the rules on direct marketing calls and messages in each person's country, and keeping the records that show it;
- making sure that the personal data it provides, such as contact lists for call campaigns, is accurate and lawfully obtained.
3.6 Where the Controller's use of the services involves special categories of personal data (Article 9 GDPR), for example the reason for an appointment at a clinic, the Controller tells the Processor before that use starts, and the restrictions and safeguards set out in Annex II apply (Clause 7.5).
4. Sub-processors
4.1 The Controller gives the Processor general written authorisation to engage sub-processors (Clause 7.7(a), Option 2). The Controller authorises the sub-processors listed in Annex IV, which are those engaged on the date of this DPA. Some of them are alternatives, used only when the main provider for a task is unavailable or when one of them is chosen for a particular agent, for example for its voice.
4.2 The Processor informs the Controller in writing of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the Controller's account email address. The notice states the sub-processor's name, what it will do, where it will process the data and the safeguard for any transfer outside the EEA. The current list is published with this DPA on the Processor's website.
4.3 The Controller may object to the change in writing within those 30 days, giving reasons related to data protection. The Parties then try in good faith to find a solution, such as not using that sub-processor for the Controller's services. If they find none before the change takes effect, the Controller may terminate the services affected by the change, with effect from the date of the change and without any termination fee; the Processor refunds any fees paid in advance for the period after termination.
4.4 The Processor engages each sub-processor under a written contract that imposes, in substance, the same data protection obligations as this DPA (Clause 7.7(b) and Article 28(4) GDPR). The Processor remains fully responsible to the Controller for each sub-processor's performance of those obligations (Clause 7.7(d)). At the Controller's request, the Processor provides a copy of such a contract; commercial information may be removed (Clause 7.7(c)).
5. Transfers outside the EEA
5.1 The Processor stores the Controller's personal data in the EU: the platform and its database run on servers in Germany, and backups are kept in the Netherlands.
5.2 To provide the services, some sub-processors process personal data outside the European Economic Area (EEA), mainly in the United States, for example while a caller's speech is converted into text or the agent's reply is generated. Annex IV shows, for each sub-processor, where it processes the data and on what basis.
5.3 By entering into this DPA, the Controller instructs the Processor to make these transfers (Clause 7.8(a)). Each transfer complies with Chapter V of the GDPR, through either:
- an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for recipients certified under it; or
- the standard contractual clauses for transfers to third countries set out in Commission Implementing Decision (EU) 2021/914, as Clause 7.8(b) allows, with supplementary measures where needed.
5.4 For transfers based on standard contractual clauses, the Processor keeps a transfer impact assessment and gives the Controller a summary on request.
6. Assistance to the Controller
6.1 If the Processor receives a request from a data subject concerning personal data it processes for the Controller, it notifies the Controller promptly and forwards the request. It does not respond to the request itself unless the Controller has authorised it to (Clause 8(a)).
6.2 The Processor assists the Controller in responding to data subjects' requests to exercise their rights, by finding, exporting, correcting or deleting the personal data concerned, taking into account the nature of the processing (Clause 8(b)).
6.3 The Processor assists the Controller in meeting its obligations under Articles 32 to 36 GDPR, on security of processing, personal data breaches, data protection impact assessments and prior consultation of the supervisory authority, taking into account the nature of the processing and the information available to it (Clause 8(c)). For an impact assessment, it provides among other things a description of how the agents work, this DPA and its Annexes.
6.4 The Processor does not charge for forwarding requests, for assistance the services already provide, or for assistance needed because of its own breach of this DPA. For other assistance that requires significant work, the Parties agree on any cost in advance.
7. Personal data breaches
7.1 The Processor notifies the Controller without undue delay after becoming aware of a personal data breach concerning the Controller's personal data, and where possible within 48 hours, so that the Controller can meet its own deadline under Article 33 GDPR (Clause 9.2).
7.2 The notification is sent to the Controller's account email address and contains at least the information Clause 9.2 requires: a description of the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; a contact point (privacy@acastia.com); its likely consequences; and the measures taken or proposed to address the breach and limit its effects. Information that is not yet available is provided as soon as it is, without undue further delay.
7.3 The Processor promptly takes the measures needed to contain the breach and limit its effects, and documents every breach, its effects and the measures taken.
7.4 The Controller decides whether to notify the supervisory authority and the data subjects, and the Processor assists it in doing so. The Processor does not inform supervisory authorities or data subjects about a breach of the Controller's personal data unless the Controller instructs it to.
8. Information and audits
8.1 The Processor deals promptly and adequately with the Controller's questions about the processing, and makes available all information necessary to demonstrate compliance with this DPA and Article 28 GDPR (Clause 7.6(a) and (c)).
8.2 The Processor allows for and contributes to audits of the processing, including inspections, by the Controller or by an independent auditor the Controller mandates (Clause 7.6(d) and (e)). Unless there are indications of non-compliance, or a supervisory authority requires otherwise:
- the Controller gives at least 30 days' written notice;
- audits take place during normal business hours and no more than once a year;
- audits cover only the processing carried out for the Controller.
The auditor must be bound by confidentiality.
8.3 The data centres and systems of sub-processors are audited through the audit reports and certifications the sub-processors make available, which the Processor provides on request.
8.4 Each Party bears its own costs of an audit. If an audit shows that the Processor has materially breached this DPA, the Processor remedies the breach without delay and at its own cost.
9. Deletion and return
9.1 During the Agreement, the Processor deletes specific personal data at the Controller's request without undue delay, and no later than 14 days after the request. Copies in backups are deleted as the backups expire (Annex III).
9.2 When the Agreement ends, the Processor deletes all personal data processed on behalf of the Controller or, at the Controller's choice, returns it to the Controller and then deletes the remaining copies (Clause 10(d)). The Controller can make its choice up to 30 days after the end of the Agreement. Returned data is provided in a common, machine-readable format, such as CSV or JSON.
9.3 The Processor deletes the personal data from its live systems no later than 60 days after the end of the Agreement, and copies in backups as the backups expire, no later than 30 days after that. The Processor confirms the deletion to the Controller in writing.
9.4 The Processor keeps personal data only where EU or member state law requires it to be stored. Until that data is deleted, the Processor protects it, processes it only for the purpose of that requirement and continues to comply with this DPA (Clause 10(d)).
10. Liability, precedence and changes
10.1 Liability between the Parties arising from this DPA is subject to the limitation of liability in the Agreement. Nothing in this DPA limits either Party's liability towards data subjects under Article 82 GDPR, or any liability that cannot be limited by law.
10.2 If this DPA conflicts with any other part of the Agreement regarding the processing of personal data, this DPA prevails. The Clauses prevail over both (section 2.4).
10.3 The Processor may update this DPA to reflect changes in the law, in the guidance of supervisory authorities or in its services, by giving the Controller at least 30 days' written notice. An update may not reduce the protection of the personal data or change the Clauses (Clause 2). Changes to the sub-processors follow section 4.
10.4 This DPA is governed by the law that governs the Agreement, and disputes are settled by the courts specified in the Agreement.
10.5 Notices under this DPA are sent to privacy@acastia.com for the Processor, and to the Controller's account email address for the Controller.
Annex I: List of parties
Controller
- Name: the customer named in its Acastia account and plan.
- Address: as stated in the account.
- Contact person: the account owner, or another contact the Controller names in writing.
- Activities relevant to the processing: the Controller uses Acastia's AI agents and platform in its business, to answer and make calls, chat with visitors to its website, book appointments, send messages and keep records of these interactions.
- Signature and date: the Controller accepts this DPA as part of the Agreement when it orders or pays for its plan; the date of that order or payment is the date of acceptance.
Processor
- Name: Acastia, as identified in the Terms of Service.
- Address: the registered address stated in the Terms of Service.
- Contact person: Alexander Hansen, privacy@acastia.com.
- Activities relevant to the processing: provides, sets up and manages the AI agents and the platform for the Controller.
- Signature and date: the Processor is bound by this DPA from the date of the Controller's acceptance.
Annex II: Description of the processing
Categories of data subjects
- people who call the Controller, or whom the Controller's agents call: customers, patients, prospective customers and other contacts;
- people who chat with the Controller's agent on its website;
- people who book, change or cancel appointments with the Controller through the agents;
- people whose details the Controller provides, for example in contact lists for call campaigns;
- people who exchange emails with the Controller, where the Controller connects a mailbox to the platform;
- the Controller's staff, as far as their details are used in the services, for example to transfer calls to them or send them messages.
Categories of personal data
- Identity and contact details: name, phone number, email address, company, and address where given.
- Call data: phone numbers, the time and length of calls, the audio of the call (processed while the call takes place, not stored by the Processor), transcripts, summaries, and the details the agent records from the call, such as the reason for calling and the outcome.
- Chat data: the messages exchanged and any details left in the chat, for example a request to be called back.
- Appointments: date, time, service and notes.
- Messages: SMS and emails sent by the agents, and emails in a mailbox the Controller connects.
- Campaign data: contact lists and the outcome of each call.
- Any other information people choose to share with an agent.
Sensitive data and the safeguards that apply
The services are not designed to collect special categories of personal data, but people may share them with an agent, and some Controllers' services involve them, for example the reason for a dental or medical appointment. Where that is the case (section 3.6):
- the agents are set up to ask only for what is needed to handle the request;
- access to the transcripts and records is limited to the Controller's users and to the Processor's staff who manage the Controller's agents;
- the data is used for no other purpose;
- the measures in Annex III apply.
Nature of the processing
Answering, making and transferring phone calls; converting speech to text, generating the agents' replies with language models and converting the replies to speech, in real time; chatting with visitors on the Controller's website; checking calendars and booking appointments; sending confirmations and other messages by SMS and email; searching the Controller's knowledge base to answer questions; storing call records, transcripts, summaries, chats, contacts and appointments, and showing them to the Controller in its dashboard; notifying the Controller; reviewing calls and conversations to monitor and improve the Controller's agents; support, backups and deletion.
Purposes
To provide and manage the services the Controller has chosen under the Agreement: handling calls and chats on the Controller's behalf, booking appointments, taking messages, qualifying leads, keeping the Controller informed, and monitoring and improving the Controller's agents.
Duration and retention
For the term of the Agreement and until the personal data has been deleted or returned under section 9. During the Agreement:
- call audio is not stored by the Processor;
- transcripts, summaries, chats, contacts, appointments and messages are kept until the Controller deletes them or asks the Processor to delete them (section 9.1), unless the Parties agree a shorter period;
- backups expire after no more than 30 days.
Processing by sub-processors
As described in Annex IV, for the duration of the Agreement.
Annex III: Technical and organisational measures
The Processor maintains the following measures and reviews them as the services and the risks change.
Hosting and network
- The platform, its database and the voice processing run on cloud servers of Hetzner Online GmbH in Falkenstein, Germany. The physical security of the data centre is managed by Hetzner (Annex IV).
- A firewall admits only web traffic from the internet. Servers can be administered only from approved network addresses with key-based login; password login and direct root login are disabled.
- The servers communicate with each other over a private network. The interface the agents use to reach the platform requires a secret key.
- The database, the cache and the search index are not accessible from the internet.
- Security updates are installed on the servers automatically.
Encryption
- Connections to the website, the dashboard and the sub-processors' services are encrypted with TLS.
- Passwords are stored only as one-way hashes. Access tokens for connected calendars, mailbox passwords and two-factor recovery codes are stored encrypted (AES-256).
Access control
- Every record belongs to one customer account. Users see only the data of the accounts they belong to, and the Controller decides who on its team has access.
- Two-factor authentication is available to every user, and the Controller can require it for its whole team.
- The Processor's staff have access to the Controller's data only as far as needed to manage the Controller's agents and provide support. They are bound by confidentiality (Clause 7.4(b)), and their administrator accounts are protected by two-factor authentication.
- Each agent can use only the tools and information the Controller has approved for it, and only within the Controller's own account.
Data minimisation and retention
- Calls are not recorded: the audio is processed while the call takes place and is not stored by the Processor.
- Sub-processors are set up so that they do not use the data to train their models.
- Personal data is deleted as set out in section 9. Backups expire after no more than 30 days.
Availability and resilience
- The database is backed up every hour. Backups are kept on the server for seven days and copied to object storage in Amsterdam that only the Processor can access.
- Restoring from a backup is tested at least once a year.
- The availability of the website and the platform is monitored continuously.
- Every change to the platform is checked by an automated test suite before release, and a release can be rolled back.
Incidents
- Errors and rejected access attempts are logged, and the logs are kept to detect and investigate incidents.
- Personal data breaches are handled and notified as set out in section 7.
Assistance with data subjects' rights (Clause 8(d))
- Requests can be sent to privacy@acastia.com. The Processor can find, export, correct and delete the personal data of a given person by name, phone number or email address.
Sub-processors
- Sub-processors are chosen for their ability to protect the data, and each is bound by written data processing terms (section 4).
Annex IV: Sub-processors
The Controller authorises the following sub-processors (section 4). Services the Controller connects itself, such as its own Google Calendar or mailbox, are the Controller's own providers, not sub-processors of the Processor.
| Sub-processor | What it does | Personal data | Where the data is processed | Basis for transfers outside the EEA |
|---|---|---|---|---|
| Hetzner Online GmbH, Germany | Hosts the platform, the database and the voice processing | All personal data in the services | Germany (Falkenstein) | Not needed: EU |
| The Constant Company, LLC (Vultr), USA | Stores the backups | All personal data in the database | Netherlands (Amsterdam) | Stored in the EU; the company is certified under the EU-US Data Privacy Framework |
| LiveKit Incorporated, USA | Carries the audio of calls between the phone network and the agents in real time, and detects when a caller has finished speaking | Call audio while the call takes place; phone numbers and call details | LiveKit's global network, including the USA | EU-US Data Privacy Framework |
| Telnyx LLC, USA | Provides the phone numbers and connects calls to the telephone network | Phone numbers, call audio while the call takes place, call details | USA and EU | EU-US Data Privacy Framework |
| Deepgram, Inc., USA | Converts callers' speech into text | Call audio and its transcript | USA | Standard contractual clauses |
| Groq UK Limited, United Kingdom | Language models that understand callers and write the agents' replies; call summaries; reading the Controller's website to set up its agents | Transcripts and the text of conversations | USA | UK adequacy decision; standard contractual clauses for the onward transfer to the USA |
| OpenAI Ireland Ltd, Ireland | Writes the website chat agent's replies; prepares the knowledge base for search; back-up language model and voice | Chat messages, transcripts, knowledge base content and the agents' replies | USA | Standard contractual clauses |
| Eleven Labs Inc., USA | Turns the agents' replies into speech (main voice provider) | The text of the agents' replies, which may include names, times and other details | USA | EU-US Data Privacy Framework |
| Cartesia AI, Inc., USA | Turns the agents' replies into speech (alternative voice provider) | The text of the agents' replies | USA | Standard contractual clauses |
| Theai, Inc. (Inworld AI), USA | Turns the agents' replies into speech (alternative voice provider) | The text of the agents' replies | USA | Standard contractual clauses |
| One.com Group AB, Sweden | Sends emails, such as confirmations, notifications and call summaries | Email addresses and the content of the emails | Denmark (Copenhagen); technical monitoring partly from India | EU; standard contractual clauses for the monitoring from India |
| Xtreme Internet Solutions B.V. (Smstools), Belgium | Sends SMS messages, such as confirmations and reminders | Phone numbers and the content of the messages | EU | Not needed: EU |