Data Processing Agreement
Last updated: July 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Controller") and Vendira.ai ("Processor") and applies to Vendira's processing of personal data on the Controller's behalf in the course of providing the Service.
1. Subject matter and duration
Vendira processes personal data (caller/SMS-recipient phone numbers, names, call transcripts, appointment and CRM records) on behalf of the Controller for the duration of the Controller's subscription to the Service.
2. Nature and purpose of processing
Vendira processes data to: answer and route phone calls via AI voice agent, send and receive SMS messages, store call transcripts and logs, manage appointments/CRM/invoicing records the Controller creates, and provide analytics back to the Controller about their own account.
3. Categories of data subjects and data
Data subjects: the Controller's callers, SMS recipients, and customers. Data categories: phone numbers, names (where provided), call audio-derived transcripts, message content, appointment details, and any notes the Controller adds.
4. Sub-processors
Vendira uses the following sub-processors to deliver the Service:
- Twilio, Inc. — telephony/SMS transport
- ElevenLabs — voice AI processing and transcription
- Stripe, Inc. — payment processing (billing data only)
- Supabase, Inc. — database hosting
- Vercel, Inc. — application hosting
Vendira will notify Controllers of any new sub-processor with access to personal data via the dashboard or email, and Controllers may object within a reasonable period (to be defined — e.g. 14 days — with your lawyer).
5. Processor obligations
Vendira agrees to:
- Process personal data only on documented instructions from the Controller (i.e. as configured through the Service)
- Ensure personnel with access are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (encryption in transit, tenant-isolated database access controls)
- Assist the Controller in responding to data subject access/deletion requests
- Notify the Controller without undue delay upon becoming aware of a personal data breach affecting their data
- Delete or return personal data at the end of the engagement, upon Controller request, subject to legal retention requirements
6. Controller obligations
The Controller is responsible for having a lawful basis (consent or otherwise) to collect and have Vendira process the personal data of their own callers/customers, including compliance with TCPA, CASL, and any other applicable law governing how they contact those individuals.
7. International transfers
Sub-processors listed above may process data in the United States. The Controller consents to this transfer as necessary to deliver the Service. [Add SCCs or equivalent transfer mechanism if serving EU customers — confirm with your lawyer.]
8. Liability
Liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.
9. Contact
Data protection inquiries: support@vendira.ai [confirm real contact].