Data Processing Agreement

Version 2026-08-19. Last updated: 19 August 2026. Provided in English; the German translation is under review and the English version remains legally authoritative.

This agreement is concluded under Article 28(3) GDPR between your organisation (the controller) and us (the processor). It governs our processing of your end users' personal data — the people who call, chat with or email the agents you set up. It forms part of the Terms and takes effect when an organisation owner accepts it while creating the organisation.

It deliberately points at the privacy policy and Terms rather than repeating them. Where it links, the linked text is part of this agreement and is binding, not background reading.

Negotiated agreements. If your organisation signed a separate, negotiated data processing agreement with us, that one governs and this one does not apply to you. Partners who run the platform in their own cloud environment conclude their own agreements with their customers; we are not a party to those.

1. The parties

Your processor is the visibleIT company that invoices your organisation, set by the country in your organisation profile: visibleIT GmbH for the EU, UK, EEA and Switzerland, visibleIT Inc. for the United States and rest of world. Company details and the intra-group arrangement between them are in the privacy policy §1.

The controller is your organisation as named in your profile. When you accept, we record which company is your processor, the version you accepted and the date.

2. Scope

What we process and why is set out in Annex I. Processing lasts for the term of your subscription plus the retention windows described there.

This agreement covers your end users' data only. Data about you and your colleagues — account profiles, billing contacts, support email — is processed by us as controller under the privacy policy, not under this agreement.

3. We act on your instructions

We process your end users' personal data only on your documented instructions, including for international transfers, unless law requires otherwise — in which case we tell you first, unless that law forbids it.

Your instructions are this agreement, the Terms, and how you configure the platform: your agents' behaviour instructions, knowledge base, tables, tools, retention and channel settings. Using a documented feature is an instruction.

We will tell you if we think an instruction breaches data protection law.

We never use your end users' data for our own purposes, never sell it, and never train AI models for other customers on your conversations.

4. Confidentiality

Everyone we authorise to process this data is bound by confidentiality, by contract or statutory duty, and gets access only to what their role requires.

5. Security

We implement the Article 32 measures listed in Annex II. We may improve them as the platform develops; we will not reduce the level of protection.

6. Sub-processors

You give us general authorisation to use the sub-processors in Annex III. Each is engaged under a written contract no less protective than this agreement, and we stay fully liable to you for what they do.

Adding or replacing one triggers the 30 days' advance notice and objection right set out in the privacy policy §5, which applies as a term of this agreement.

Your own integrations are not sub-processors. When you connect your mailbox, calendar or another system, data flows there under your own contract with that provider.

7. How we help you meet your obligations

  • End-user rights requests. You answer them; we assist with the technical means — transcript export, per-agent retention controls, deletion. A request that reaches us directly is forwarded to you rather than answered by us.
  • Breaches. We notify you without undue delay after becoming aware of a breach affecting your end users' data, with what you need for your own duty under Articles 33 and 34. Our own authority-notification commitment is in the privacy policy §11.
  • Impact assessments. We give reasonable assistance with assessments and prior consultations under Articles 35 and 36, given the nature of the processing and what we know.

8. Deletion and return

You can export your data at any time while the subscription is active. Export what you want to keep before closing your organisation — after that the timetable in the Terms §13 applies: soft delete, a 90-day window in which we can restore it, then permanent deletion.

Retention during the subscription follows the privacy policy §7. We keep data past these points only where law requires it, principally statutory invoice retention.

9. Information and audits

We make available what you need to demonstrate Article 28 compliance, and allow for and contribute to audits by you or an auditor you mandate. In the first instance we do this with our own documentation and our infrastructure providers' certifications (ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3), as noted in the Terms §15.

10. International transfers

Where this data leaves the EEA, UK or Switzerland we rely on the Standard Contractual Clauses and the EU-US Data Privacy Framework as described in the privacy policy §6, which applies as a term of this agreement.

11. Precedence and liability

On a data protection matter this agreement prevails over the Terms; on everything else the Terms prevail. A signed, negotiated agreement prevails over both.

The liability provisions of the Terms apply here too. Nothing in this agreement limits a data subject's rights or either party's liability under Article 82 GDPR.

12. Term and changes

This agreement runs from your acceptance for as long as we process your end users' personal data.

We may update it for changes in law, in the platform, or in our sub-processors. Material changes are notified at least 30 days ahead, and we record which version your organisation accepted, so what was agreed and when is always clear.

Annex I — What we process

Subject matter
Running AI agents on your behalf that handle voice calls, web chat and email with your end users.
Nature and purpose
Receiving and transcribing conversations; generating replies; retrieving from your knowledge base; reading and writing your data tables; extracting structured fields such as an appointment time or a lead; sending follow-up email you configure; and analysing your inbound conversations.
Categories of data subjects
Your end users — callers to your voice agents, web-chat visitors, people who email your agents, and anyone whose details appear in a conversation or in data you upload.
Types of personal data
Caller phone number; call audio and transcript; chat transcript and visitor IP address; email address, message content and attachments; fields the agent extracts (a name, an appointment time, a lead score); and whatever else an end user chooses to say or write. Call audio is held only for as long as it takes to transcribe the call and is then deleted.
Special categories
Not processed deliberately. If an end user volunteers such data — health information, say — it is processed only as needed to deliver the service. Do not configure agents to solicit special-category data without your own legal basis.
Duration and retention
The term of your subscription, plus the retention windows in the privacy policy §7 (365 days by default for conversations, or a shorter window you set per agent).
Frequency
Continuous, for as long as your agents are active.

Annex II — Technical and organisational measures

The measures we implement under Article 32 GDPR. This is the same list published as §11 of the privacy policy — one set of measures, stated there as a notice and here as a contractual commitment.

  • All traffic is encrypted in transit (TLS 1.2 or higher).
  • Data at rest is encrypted using our infrastructure provider's built-in encryption.
  • Sign-in supports passkeys (WebAuthn) and authenticator-app codes. Operator-level access requires a passkey.
  • Tenant isolation is enforced by the platform — one organisation cannot read or write another organisation's data.
  • Secrets (API keys, OAuth refresh tokens) are held in a dedicated secrets manager, not in the database.
  • Every state-changing action by our operators is logged with a reason and is auditable.
  • We never reuse customer conversations to train AI models for other customers.
  • No voiceprints, no biometric identifiers. We do not extract, generate or store voiceprints, faceprints or any other biometric identifier from your end users' audio, and we do not use audio to recognise the same person across calls. Our underlying infrastructure providers inherit the same instruction.
  • Contact details are masked in stored transcripts by default — phone numbers, email addresses and long numbers are replaced with markers in the saved conversation. The after-call steps that need the real values run first, on a short-lived unmasked working copy that is then deleted and is never readable from the application.

We may improve these over time; we will not reduce the level of protection.

Annex III — Approved sub-processors

The sub-processors you authorise under section 6 — the same list published as §5 of the privacy policy, so the two can never disagree. Processing locations and transfer mechanisms are described there and in §6.

Google Ireland Limited / Google LLC
Cloud infrastructure — hosting, databases, authentication, file storage, scheduling and logging — together with speech-to-text and the AI models behind our voice, email and analysis features. Processing takes place in the European Union; individual AI features may be served from the provider's global infrastructure. Certified under the EU-US Data Privacy Framework.
cloud.google.com/terms/cloud-privacy-notice · policies.google.com/privacy
Twilio Ireland Limited
Telephone numbers and call connectivity for voice agents.
twilio.com/legal/privacy
ActiveCampaign, LLC (Postmark)
Sending and receiving email for the platform and for agents' mailboxes. Certified under the EU-US Data Privacy Framework.
postmarkapp.com/eu-privacy · postmarkapp.com/privacy-policy
Cloudflare, Inc.
Protection and delivery of our public website. Only public marketing pages pass through it.
cloudflare.com/privacypolicy
Stripe Payments Europe Limited
Card payments and invoicing for customers contracted with visibleIT GmbH.
stripe.com/privacy
Stripe, Inc.
Card payments and invoicing for customers contracted with visibleIT Inc.
stripe.com/privacy