Draft — not yet reviewed by a lawyer. This DPA is a starting point modeled on standard SaaS data-processing terms. Have it reviewed before offering it as a signed agreement to customers, particularly if any customer requires GDPR-style terms (EU/UK customers) — this draft is written for a PIPEDA/Law 25 (Quebec) baseline and may need an EU annex added.

Data Processing Agreement

Last updated: July 2, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Controller") and Vendira.ai ("Processor") and applies to Vendira's processing of personal data on the Controller's behalf in the course of providing the Service.

1. Subject matter and duration

Vendira processes personal data (caller/SMS-recipient phone numbers, names, call transcripts, appointment and CRM records) on behalf of the Controller for the duration of the Controller's subscription to the Service.

2. Nature and purpose of processing

Vendira processes data to: answer and route phone calls via AI voice agent, send and receive SMS messages, store call transcripts and logs, manage appointments/CRM/invoicing records the Controller creates, and provide analytics back to the Controller about their own account.

3. Categories of data subjects and data

Data subjects: the Controller's callers, SMS recipients, and customers. Data categories: phone numbers, names (where provided), call audio-derived transcripts, message content, appointment details, and any notes the Controller adds.

4. Sub-processors

Vendira uses the following sub-processors to deliver the Service:

Vendira will notify Controllers of any new sub-processor with access to personal data via the dashboard or email, and Controllers may object within a reasonable period (to be defined — e.g. 14 days — with your lawyer).

5. Processor obligations

Vendira agrees to:

6. Controller obligations

The Controller is responsible for having a lawful basis (consent or otherwise) to collect and have Vendira process the personal data of their own callers/customers, including compliance with TCPA, CASL, and any other applicable law governing how they contact those individuals.

7. International transfers

Sub-processors listed above may process data in the United States. The Controller consents to this transfer as necessary to deliver the Service. [Add SCCs or equivalent transfer mechanism if serving EU customers — confirm with your lawyer.]

8. Liability

Liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.

9. Contact

Data protection inquiries: support@vendira.ai [confirm real contact].