https://myphoneflow.com/legal/dpa/v1.0/
PhoneFlow Data Processing Addendum
Version 1.0 · Effective: 2026-09-27 · Last updated: 2026-09-26
Summary (not a substitute for the terms below):
- You decide what happens to your callers' and visitors' personal data. We process it only to run PhoneFlow for you, and only on your instructions.
- We do not sell or share that data, we do not use it for anyone else, and PhoneFlow does not train AI models on it.
- Our subprocessors are listed at https://myphoneflow.com/legal/subprocessors/. We email you 30 days before adding a new one, and you can object.
- If a security breach affects your data, we tell you without undue delay, and within 72 hours after we confirm it.
- Deletion is on written request. After your account closes you have 30 days to ask for an export; we then delete your data, including recordings held at Twilio, within 60 days after closure.
- If EU, UK or Swiss personal data is involved, the EU Standard Contractual Clauses and the UK Addendum apply.
1. Scope, roles and precedence #
1.1 How this DPA applies #
This Data Processing Addendum ("DPA") is part of the Agreement between Customer and Electric Software LLC, a Michigan limited liability company doing business as PhoneFlow ("PhoneFlow", "we", "us"). It takes effect when Customer accepts the PhoneFlow Master Customer Agreement (https://myphoneflow.com/legal/customer-agreement/) ("MCA"), and no separate signature is needed. Capitalized terms not defined here have the meanings given in the MCA.
1.2 Definitions #
- Data Protection Laws: every law on privacy or the processing of personal data that applies to processing under the Agreement, as amended. This includes:
- the California Consumer Privacy Act as amended by the CPRA (Cal. Civ. Code 1798.100 et seq.) and its regulations (11 CCR 7000 et seq.) ("CCPA");
- other US state comprehensive privacy laws;
- the EU General Data Protection Regulation 2016/679 ("GDPR");
- the UK GDPR and the Data Protection Act 2018;
- the Swiss Federal Act on Data Protection of 25 September 2020 ("Swiss FADP");
- Canadian federal and provincial privacy laws.
- Personal Data: information that identifies, relates to, or can reasonably be linked to an individual, including "personal data" and "personal information" as those laws define them.
- Customer Personal Data: Personal Data within Customer Data that PhoneFlow processes on Customer's behalf to provide the Services.
- PhoneFlow Account Data: Personal Data that PhoneFlow processes for its own purposes. This covers Customer Users' login and account details, billing contacts and payment records, support and sales communications, marketing, website use, and records of acceptance of the Agreement.
- Controller, Processor, Data Subject, Business, Service Provider, Consumer, Sell and Share have the meanings given in the applicable Data Protection Laws. "Controller" includes a "business". "Processor" includes a "service provider". "Data Subject" includes a "consumer".
- Personal Data Breach: a breach of security that leads to the accidental or unlawful destruction, loss or alteration of Customer Personal Data held on systems that PhoneFlow or its Subprocessors control, or to unauthorized disclosure of or access to that data. Unsuccessful attempts and activities that do not compromise the data are not Personal Data Breaches. Examples are pings, port scans, blocked log-in attempts and denial-of-service attacks.
- Subprocessor: a third party, including a PhoneFlow affiliate, that PhoneFlow engages to process Customer Personal Data to help provide the Services. Third-Party Services that Customer selects or configures are not Subprocessors (Section 9.6).
- Subprocessor List: the PhoneFlow Subprocessor List at https://myphoneflow.com/legal/subprocessors/.
- EU SCCs: the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum: the International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended.
- Restricted Transfer: a transfer of Customer Personal Data that is subject to the GDPR, the UK GDPR or the Swiss FADP to a country that the relevant authority has not found to provide adequate protection.
1.3 Roles #
For Customer Personal Data, Customer is the Controller (or Business) and PhoneFlow is the Processor (or Service Provider). If Customer itself processes the data for another controller, Customer is a processor and PhoneFlow is its subprocessor. In that case Customer confirms that the controller has authorized PhoneFlow's processing as described in this DPA, including the use of Subprocessors. Customer remains PhoneFlow's only point of contact, and passes on any information that controller needs.
1.4 PhoneFlow as controller #
PhoneFlow is a Controller of PhoneFlow Account Data. The PhoneFlow Privacy Notice (https://myphoneflow.com/legal/privacy/) governs that data, not this DPA. PhoneFlow is also a Controller of Personal Data from its own phone lines and its own demonstration widget.
1.5 Order of precedence #
On the processing of Customer Personal Data, this DPA prevails over every other part of the Agreement except a signed Order Form that expressly names the DPA section it changes. For Restricted Transfers, the EU SCCs and the UK Addendum prevail over this DPA (Section 15.5).
2. Customer's responsibilities #
Customer is responsible for the following:
- Lawful basis. Customer has, and keeps, a lawful basis for the Customer Personal Data it causes PhoneFlow to process, and for its instructions.
- Notices and consents. Customer gives every notice, and obtains every consent, that Data Protection Laws and Communications Laws require for PhoneFlow and its Subprocessors to process Customer Personal Data as described in this DPA. That includes the recording of calls, transcription, and processing by AI providers. Customer keeps the caller-facing disclosures described in the PhoneFlow AI & Telephony Service Terms (https://myphoneflow.com/legal/service-terms/).
- Prohibited Data. Customer does not configure the Services to ask for or collect Prohibited Data, and does not upload it into Customer Materials.
- Customer's own tools. Customer is responsible for the Third-Party Services it connects, and for the data it directs the Services to send to them.
- Account security. Customer is responsible for the security of Customer Users' credentials, for the roles it assigns, and for removing access for people who leave.
3. Processing on instructions #
3.1 Instructions #
PhoneFlow processes Customer Personal Data only on Customer's documented instructions, including instructions on transfers. Customer's instructions are:
- the Agreement, including this DPA;
- Customer's configuration and use of the Services, including agents, greetings, call types, recording settings, knowledge base, transfer targets and integrations. This includes configuration that PhoneFlow staff build as Setup Services and Customer approves or uses;
- any other written instruction from an authorized Customer administrator that PhoneFlow accepts in writing.
PhoneFlow may decline an instruction that the Services cannot carry out, or that goes beyond them. If that happens, the parties may agree in writing on a reasonable fee for the extra work. The only exception is processing that applicable law requires. In that case PhoneFlow tells Customer about the legal requirement before processing, unless the law forbids that notice.
3.2 Instructions that appear unlawful #
PhoneFlow will tell Customer promptly if, in its opinion, an instruction infringes Data Protection Laws. PhoneFlow may suspend the affected processing until Customer confirms or changes the instruction. PhoneFlow has no general duty to review Customer's instructions for legal compliance.
3.3 Permitted internal uses #
As part of providing the Services to Customer, PhoneFlow may process Customer Personal Data to:
- operate, maintain and support the Services for Customer, including finding and repairing errors that affect them, and perform Setup Services;
- calculate fees and Wallet usage;
- detect, prevent and investigate security incidents, fraud, spam, abuse, AUP violations and illegal activity;
- comply with the law and with valid legal process.
PhoneFlow will not use Customer Personal Data to provide services to any other customer or person, or to build or change a profile of any individual for use outside Customer's own account.
3.4 Telemetry and de-identified data #
PhoneFlow may use Telemetry to operate, secure, support, bill for and improve the Services. Across customers, PhoneFlow uses Telemetry only in aggregated or de-identified form that does not identify Customer, any Customer User or any End User.
PhoneFlow does not create de-identified or aggregated data from Customer Personal Data, other than Telemetry as described above.
When PhoneFlow aggregates or de-identifies Telemetry, it will:
- take reasonable measures to make sure the data cannot be linked to an individual;
- keep and use the data only in de-identified form, and not try to re-identify it. This DPA is PhoneFlow's public commitment to do so;
- contractually require anyone it shares the data with to do the same.
3.5 No training #
PhoneFlow does not use Customer Data, including recordings, transcripts, knowledge-base content, Caller information and Output, to train, fine-tune or otherwise improve any artificial-intelligence or machine-learning model, whether its own or a third party's. Creating embeddings or search indexes of Customer's knowledge-base content, solely so that Customer's own agents can use it, is processing to provide the Services, not training. Any exception needs a written amendment signed by Customer.
4. California (CCPA) service-provider terms #
When PhoneFlow processes Customer Personal Data that is "personal information" under the CCPA, PhoneFlow acts as Customer's Service Provider. PhoneFlow will:
- Specified purposes. Process that personal information only for the business purposes of providing the Services described in the Agreement and Annex I, and for the internal uses in Section 3.3. The parties specify those purposes here.
- No selling or sharing. Not Sell or Share it.
- No other purposes. Not retain, use or disclose it for any other purpose, including any commercial purpose, except as the CCPA permits a service provider to do.
- Direct business relationship only. Not retain, use or disclose it outside the direct business relationship between Customer and PhoneFlow.
- No combining. Not combine it with personal information PhoneFlow receives from, or on behalf of, anyone else, or collects from its own interactions with a consumer. The only exception is where the CCPA regulations permit it, for example to detect security incidents or prevent fraud.
- Same protection. Comply with the CCPA's obligations that apply to service providers, and give the personal information the same level of privacy protection the CCPA requires of Customer. That includes reasonable security under Cal. Civ. Code 1798.81.5.
- Notice if it can no longer comply. Tell Customer within 10 business days if PhoneFlow determines that it can no longer meet its CCPA obligations.
- Customer's rights to act.
- Customer may take reasonable and appropriate steps to make sure PhoneFlow uses the personal information consistently with Customer's CCPA obligations. This includes the reviews and audits in Section 14, at least once every 12 months.
- On notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use. Examples are requiring PhoneFlow to stop the processing, to provide records, or to delete the data concerned.
- Consumer requests. Help Customer respond to consumer requests (Section 11.1). When Customer tells PhoneFlow that a consumer has made a request, PhoneFlow will act on it as the CCPA requires.
- Audits, assessments and ADMT. Cooperate reasonably, and provide the information PhoneFlow has, when Customer carries out a cybersecurity audit or risk assessment, or needs to meet its obligations on automated decision-making technology (11 CCR 7050(h)).
- Subcontractors. Tell Customer about each subcontractor that processes the personal information (through the Subprocessor List and Section 9), and make sure each one is engaged under a written contract that imposes the CCPA's service-provider restrictions on it, as Section 9.2 describes.
PhoneFlow certifies that it understands the restrictions in this Section 4 and will comply with them.
5. Other US state privacy laws #
Other US state privacy laws may apply to Customer Personal Data. These include the laws of Virginia, Colorado, Connecticut, Texas and Oregon, and other states with comparable processor requirements. Where one of them applies, PhoneFlow will:
- process the data only on Customer's instructions, as set out in the Agreement and Annex I. Annex I describes the nature and purpose of the processing, the types of data, and the duration;
- make sure every person who processes the data is bound by a duty of confidentiality (Section 7);
- engage Subprocessors only under a written contract that flows down these obligations, and after giving Customer notice and a chance to object (Section 9);
- help Customer with consumer requests, security, breach notification and data protection assessments (Sections 8, 10 and 11);
- delete or return the data at the end of the Services, unless the law requires PhoneFlow to keep it (Section 13);
- give Customer the information it needs to show compliance, and allow reasonable assessments (Section 14). As the law allows, PhoneFlow may instead arrange an independent assessment and give Customer the report.
6. Canadian privacy law #
Customer Personal Data is processed and stored mainly in the United States. There, it may be accessible to courts, law enforcement and national security authorities under US law. Customer, as the organization accountable for the data, tells individuals about this processing where Canadian law requires it. PhoneFlow will give Customer the information it reasonably needs about the processing to complete any assessment that Quebec's privacy law requires before data is communicated outside Quebec.
7. Personnel confidentiality #
PhoneFlow gives access to Customer Personal Data only to personnel who need it to operate, secure or support the Services, or to carry out Customer's requests. PhoneFlow requires every such person to keep Customer Personal Data confidential.
8. Security #
PhoneFlow implements and maintains the technical and organizational measures described in Annex II. They are designed to protect Customer Personal Data against Personal Data Breaches, taking account of:
- the state of the art;
- the cost of implementation;
- the nature, scope, context and purposes of the processing;
- the risks to individuals.
PhoneFlow may update these measures over time, but will not materially reduce the overall protection they give.
Customer has reviewed Annex II. Customer agrees that, together with the exclusion of Prohibited Data, the measures are appropriate for the Customer Personal Data it will process. Customer is responsible for its own security measures under Section 2, item 5.
9. Subprocessors #
9.1 General authorization #
Customer gives general authorization for PhoneFlow to engage Subprocessors. That includes the Subprocessors on the Subprocessor List as at the date Customer accepts the Agreement.
9.2 Flow-down and responsibility #
Before a Subprocessor processes Customer Personal Data, PhoneFlow will make sure it is engaged under written terms, which may be the provider's standard business or data-processing terms. Those terms will impose data protection obligations that provide a level of protection appropriate to the service and substantially similar to this DPA, as Data Protection Laws require. Providers that PhoneFlow reaches through Twilio (Deepgram, and ElevenLabs for text-to-speech) are engaged by Twilio under Twilio's terms with PhoneFlow. PhoneFlow remains responsible to Customer for its Subprocessors' processing of Customer Personal Data as if it were PhoneFlow's own, subject to Section 16.
9.3 Notice of new Subprocessors #
PhoneFlow will give at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data. The notice will be:
- emailed to Customer's account administrators;
- added to the change log on the Subprocessor List.
Anyone may also subscribe to change notices as the Subprocessor List describes.
9.4 Objection #
- How to object. Customer may object to a new Subprocessor on reasonable data protection grounds. It does so by writing to [email protected] within the 30-day notice period, and explaining its grounds.
- Resolution. The parties will discuss the objection in good faith. PhoneFlow may offer a reasonable way to avoid the new Subprocessor processing Customer's data. Examples are a configuration change, or a different provider for Customer's account.
- Termination. If the parties cannot resolve the objection within the notice period, Customer may terminate the affected Services, or the Agreement, by written notice. Customer must give that notice before the new Subprocessor begins processing Customer's data. Customer pays no termination fee. Unused Purchased Minutes are refunded under Section 11.10(h) of the MCA.
- Silence. If Customer does not object within the notice period, it has authorized the new Subprocessor.
9.5 Urgent replacement #
Sometimes PhoneFlow must replace a Subprocessor urgently, for reasons of security, service continuity or law, for example when a provider suddenly fails. In that case PhoneFlow may give notice as soon as reasonably practicable instead of 30 days in advance. Customer's objection right under Section 9.4 still applies, and runs from the date of the notice.
9.6 Customer's own Third-Party Services #
The following receive data because Customer configured or appointed them, and are not PhoneFlow Subprocessors:
- integrations, webhooks and custom HTTP tools;
- CRMs, calendars and other Third-Party Services that Customer connects;
- Customer's own AI-provider API keys;
- the email and text-message recipients that Customer designates;
- authorized PhoneFlow partners that resell the Services to Customer or support Customer, which may access Customer's account to provide that support as Section 4.5 of the MCA describes. A partner accessing the account acts for Customer. Customer may ask PhoneFlow to remove a partner's access at any time.
Sending data to them is Customer's own disclosure, made on Customer's instruction. Their processing is governed by Customer's own terms with them.
10. Personal Data Breach #
- Notice. PhoneFlow will notify Customer of a Personal Data Breach without undue delay after becoming aware of it, and in any event within 72 hours after PhoneFlow confirms that it has occurred.
- Where notice goes. PhoneFlow sends notice by email to Customer's account administrators, and to any privacy contact Customer has given to [email protected].
- Content of the notice. As far as the information is available, the notice will describe:
- the nature of the breach;
- the categories and approximate number of Data Subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address it;
- a contact point. PhoneFlow may give this information in stages as it learns more.
- Response. PhoneFlow will take reasonable steps to contain, investigate and mitigate the breach. It will cooperate reasonably with Customer so that Customer can meet its own notification duties.
- Who notifies. As Controller, Customer decides whether to notify regulators, End Users or other people, and is responsible for doing so. PhoneFlow will not notify Customer's End Users directly, unless the law requires it or Customer asks it to. PhoneFlow may make any notifications that the law requires of PhoneFlow itself.
- No admission. Notice of a breach, or a response to one, is not an admission of fault or liability.
- Notification costs. Section 18.2 of the MCA governs the costs of notifications the law requires after a Personal Data Breach.
11. Assistance #
11.1 Data Subject requests #
- How PhoneFlow helps. The Services do not currently offer a self-serve export or deletion tool. Customer sends requests to access, export, correct or delete specified Customer Personal Data to [email protected]. PhoneFlow will carry out a complete request promptly, taking account of Customer's legal deadlines, and in any event within 60 days after receiving it.
- Requests sent to PhoneFlow. If a Data Subject contacts PhoneFlow directly about Customer Personal Data, PhoneFlow will pass the request to Customer promptly. PhoneFlow will not respond itself, except to direct the person to Customer, unless the law requires otherwise.
11.2 Assessments and consultations #
PhoneFlow will give Customer reasonable assistance with its data protection impact assessments, its risk assessments, and any prior consultation with a supervisory authority. That assistance takes account of the nature of the processing and the information available to PhoneFlow. PhoneFlow may meet this obligation first by providing this DPA, its Annexes, the Documentation and answers to reasonable written questions.
11.3 Cost #
Assistance under this Section 11 is free when it is reasonable in scope. Requests that need significant extra work may be charged at reasonable rates, agreed in advance. PhoneFlow will not charge where the request arises from PhoneFlow's own breach of this DPA.
12. Requests from authorities #
A court, law enforcement agency or other public authority may seek Customer Personal Data from PhoneFlow. When that happens, PhoneFlow will:
- direct the authority to request the data from Customer where reasonably possible;
- notify Customer promptly, unless the law forbids it, so that Customer can seek a protective order or another remedy;
- disclose only what the law requires.
For Restricted Transfers, Clause 15 of the EU SCCs also applies.
13. Retention, return and deletion #
13.1 During the term #
PhoneFlow does not automatically delete Customer Personal Data after set periods. PhoneFlow keeps Customer Personal Data for the life of Customer's account, unless Customer deletes it or asks PhoneFlow to delete it. When Customer asks in writing at [email protected], PhoneFlow will delete the Customer Personal Data specified within 60 days. That includes recordings stored at Twilio.
13.2 After termination #
- Export. For 30 days after the Agreement ends, Customer may ask PhoneFlow to export its Customer Data. PhoneFlow will provide the export within a reasonable time, in a commonly used electronic format.
- Deletion. PhoneFlow will delete Customer Personal Data, including recordings stored at Twilio, within 60 days after the Agreement ends. The 30-day export window runs inside that period.
13.3 Exceptions #
- Backups. Backups held by PhoneFlow's hosting providers are not edited item by item. They are deleted when they roll off under those providers' schedules. Until then they remain protected under this DPA, and PhoneFlow will not restore them for any purpose other than recovering from a failure.
- Operational logs. Operational logs, which may contain fragments of Customer Personal Data, are kept to operate, secure and troubleshoot the Services and are not edited item by item. They remain protected under this DPA for as long as they are kept.
- Legal obligations. PhoneFlow may keep Customer Personal Data where the law requires it, or where it is subject to a legal hold. It keeps the data confidential and protected, and uses it for no other purpose.
- PhoneFlow's own records. Records of acceptance of the Agreement, billing records, and Telemetry (including aggregated or de-identified Telemetry) are not Customer Personal Data subject to deletion. PhoneFlow keeps acceptance and billing records as legal records.
13.4 Certification #
On written request, PhoneFlow will confirm in writing that deletion under this Section 13 has been completed.
14. Audits and information #
- Information first. On written request, PhoneFlow will give Customer the information reasonably necessary to show that it complies with this DPA. That information is this DPA, Annex II, answers to a reasonable security questionnaire once every 12 months, and any third-party assessment reports PhoneFlow holds.
- When Customer may audit. Customer may carry out an audit, remotely or on-site, in any of these cases:
- the information in item 1 does not reasonably satisfy an obligation that Data Protection Laws place on Customer;
- a supervisory authority requires an audit;
- a Personal Data Breach has occurred. Audits are limited to once in any 12-month period, unless a regulator requires more or a Personal Data Breach has occurred.
- Conditions. Every audit must meet these conditions:
- Customer gives at least 30 days' written notice.
- The scope, timing and duration are agreed in advance.
- The audit takes place during normal business hours and avoids unreasonable disruption.
- The auditor is Customer, or an independent auditor that is not a PhoneFlow competitor and is bound by confidentiality obligations.
- The audit gives no access to other customers' data, to privileged material, or to the facilities of Subprocessors. Subprocessors are reviewed through the information they make available.
- Costs and results.
- Customer bears its own audit costs. If an audit needs more than one business day of PhoneFlow staff time, PhoneFlow may charge its reasonable rates for the extra time, agreed in advance. PhoneFlow will not charge for audits that follow a Personal Data Breach it caused.
- Audit results are PhoneFlow's Confidential Information. Customer may use them only to confirm compliance and to meet its legal obligations.
- PhoneFlow will address any confirmed material non-compliance within a reasonable time.
- Relationship to the SCCs. This Section 14 is how audits under Clause 8.9 of the EU SCCs are carried out, as far as that is consistent with the EU SCCs.
15. International transfers #
15.1 Location #
PhoneFlow and its main Subprocessors process Customer Personal Data in the United States, as shown on the Subprocessor List. The Services are intended for US and Canadian numbers and callers. Using them for other countries needs PhoneFlow's written approval. This Section 15 applies to any Restricted Transfer, whether or not it was approved.
15.2 EU transfers #
For Restricted Transfers of Customer Personal Data subject to the GDPR, the parties enter into the EU SCCs, which are incorporated by reference, as follows:
- Modules. Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is a processor.
- Parties. Customer is the data exporter and PhoneFlow is the data importer.
- Clause 7. The optional docking clause applies.
- Clause 9(a). Option 2 (general written authorization) applies, with the 30-day notice period in Section 9.3.
- Clause 11(a). The optional independent dispute-resolution wording does not apply.
- Clause 13. The competent supervisory authority is the one identified in Annex I, Part C.
- Clauses 17 and 18. Option 1 applies, with Irish law governing, and the courts of Ireland hear disputes.
- Annexes. Annex I.A and I.B of the EU SCCs are Annex I of this DPA. Annex II is Annex II of this DPA. Annex III does not apply, because Customer has given general authorization, and the Subprocessor List applies instead.
- Signature. Customer's acceptance of the Agreement counts as each party's signature of the EU SCCs and their Annexes.
15.3 UK transfers #
For Restricted Transfers subject to the UK GDPR, the UK Addendum applies, and is incorporated into and supplements the EU SCCs as completed in Section 15.2.
- Table 1: the parties' details are in Annex I.
- Table 2: the selected modules and clauses are those in Section 15.2.
- Table 3: the appendix information is in Annexes I and II and the Subprocessor List.
- Table 4: PhoneFlow, as importer, may end the UK Addendum as its Section 19 allows.
15.4 Swiss transfers #
For Restricted Transfers subject to the Swiss FADP, the EU SCCs apply as completed in Section 15.2, with these changes:
- the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority;
- references to the GDPR mean the Swiss FADP;
- "Member State" in Clause 18(c) does not prevent Data Subjects in Switzerland from bringing claims where they usually live.
15.5 Conflict #
If this DPA or the Agreement conflicts with the EU SCCs or the UK Addendum, those clauses prevail for the Restricted Transfer concerned.
15.6 Other mechanisms #
If a transfer mechanism is invalidated or replaced, the parties will cooperate in good faith to put a lawful replacement in place. PhoneFlow may adopt an alternative mechanism recognized by Data Protection Laws by giving notice to Customer.
16. Liability #
EACH PARTY'S LIABILITY ARISING OUT OF OR RELATED TO THIS DPA, INCLUDING THE EU SCCS AND THE UK ADDENDUM TO THE EXTENT THE LAW PERMITS, IS SUBJECT TO THE EXCLUSIONS AND LIMITATIONS OF LIABILITY IN THE MCA, AND COUNTS TOWARD THE SAME AGGREGATE CAP. THIS SECTION DOES NOT LIMIT A PARTY'S LIABILITY TO DATA SUBJECTS UNDER THE THIRD-PARTY-BENEFICIARY PROVISIONS OF THE EU SCCS, OR ANY LIABILITY THAT APPLICABLE LAW DOES NOT ALLOW TO BE LIMITED. EACH PARTY IS RESPONSIBLE FOR ANY FINE THAT A SUPERVISORY AUTHORITY IMPOSES ON IT.
17. General #
- Duration. This DPA lasts for as long as PhoneFlow processes Customer Personal Data, including after the Agreement ends.
- Changes. Any change to this DPA is a Material Change, and follows the MCA's process: 30 days' notice, re-acceptance, and Customer's right to reject and terminate. An update to the Subprocessor List is not a change to this DPA; Section 9 governs it.
- Disputes and governing law. The MCA governs disputes and governing law, except where Clauses 17 and 18 of the EU SCCs apply.
- Severability. If any provision is unenforceable, the rest of this DPA remains in effect.
- Notices. Notices to PhoneFlow under this DPA go to [email protected], and privacy requests go to [email protected]. PhoneFlow's postal address for notices is 120 N Washington Square, Suite 300, Lansing, MI 48933.
Annex I — Description of the processing #
A. Parties #
- Data exporter: Customer, as identified in its PhoneFlow account or Order Form. Contact: Customer's account administrator. Role: controller, or processor where Section 1.3 applies. Activity: use of the Services.
- Data importer: Electric Software LLC d/b/a PhoneFlow, 120 N Washington Square, Suite 300, Lansing, MI 48933. Contact: [email protected]. Role: processor, or subprocessor where Customer is a processor. Activity: providing the Services.
B. Description of the transfer and processing #
- Categories of Data Subjects:
- Callers;
- Widget Visitors;
- message recipients: people who receive texts, emails, notifications or calendar invitations sent through the Services;
- Customer Users and other Customer personnel named in Customer Data, such as directory entries, transfer targets and calendars;
- other people named in a conversation or in Customer Materials.
- Categories of Personal Data:
- calling and called phone numbers, and caller-ID names where the carrier provides them;
- names and contact details that Callers give, such as email and postal or service addresses;
- voice audio of calls and widget sessions, including recordings and voicemail;
- transcripts, and Output such as summaries, extracted fields and call-type classifications;
- text-message and other message content;
- information that Callers volunteer, such as the reason for their call and their appointment preferences;
- booking and scheduling details;
- call metadata, such as timestamps, durations, routing, and transfer outcomes;
- Widget Visitors' IP addresses and browser information, used for rate limiting and optional bot protection;
- Customer personnel directory information, such as names, extensions, phone numbers, email addresses, and calendar availability where Customer enables a calendar integration;
- Personal Data in knowledge-base content, or returned by Customer's integrations during a call.
- Sensitive data: None intended. Customer must not configure the Services to collect Prohibited Data. The Services do not use voice audio to create voiceprints or to identify people by their voice. If a Caller volunteers sensitive information anyway, it is processed only as part of that conversation, under the measures in Annex II.
- Frequency: Continuous, while Customer uses the Services.
- Nature of the processing:
- receiving, routing, recording and transferring calls;
- speech-to-text and text-to-speech;
- analysis by large language models to understand Callers and respond to them;
- classification, summarization and field extraction;
- storage and retrieval, including semantic search of the knowledge base;
- sending texts, emails and notifications;
- export and deletion.
- Purpose:
- providing the Services to Customer: answering, handling and routing calls and widget sessions, taking messages, booking appointments, and sending notifications;
- giving Customer call logs, recordings, transcripts and reports;
- Setup Services and support;
- security and fraud prevention;
- calculating fees.
- Retention: For the life of Customer's account, unless Customer deletes the data or asks PhoneFlow to delete it. After termination, Section 13 applies.
- Transfers to Subprocessors: As shown on the Subprocessor List. The subject matter and nature are the part of the processing above that each Subprocessor performs, for the same duration.
C. Competent supervisory authority #
- EU: the authority determined under Clause 13(a) of the EU SCCs. That is the authority where Customer is established. If Customer is not established in the EU, it is the authority where Customer's Art. 27 representative is, or the authority that Clause 13 otherwise names.
- UK: the Information Commissioner.
- Switzerland: the Federal Data Protection and Information Commissioner.
Annex II — Technical and organizational measures #
PhoneFlow maintains the following measures:
- Encryption in transit. Connections between browsers, the PhoneFlow application and PhoneFlow's services use TLS. Connections from PhoneFlow to Subprocessors go over TLS-protected APIs.
- Encryption at rest. Customer Personal Data is encrypted at rest by PhoneFlow's hosting providers (Supabase, Amazon Web Services and Twilio).
- Credentials. Integration credentials are encrypted in the database. The dashboard shows only whether a secret has been saved, never its value. Platform API keys used by the real-time call relay are kept in a managed secrets store.
- Tenant isolation. Database row-level security policies limit each account's records to that account's authorized users.
- Role-based access. Roles within Customer's account limit what each Customer User can see and change. Customer controls which roles its users have.
- PhoneFlow personnel. PhoneFlow personnel have access to production systems only to operate, support and secure the Services, under the confidentiality requirement in Section 7.
- Sessions. Customer User sessions are held in browser session storage rather than persistent storage.
- Web widget protections.
- Widget sessions are rate-limited. The IP addresses recorded for rate limiting are purged once they are more than 24 hours old, the next time a widget session is requested.
- Customer may turn on bot protection (Cloudflare Turnstile) for its widget.
- Audit logging. An audit log records certain account and configuration changes.
- Data minimization.
- Prohibited Data is excluded under the Agreement.
- PhoneFlow does not train AI models on Customer Data (Section 3.5).
- Telemetry excludes audio, transcripts, message bodies and knowledge-base content.
- Subprocessor management. Subprocessors process data under written terms (Section 9). They are published on the Subprocessor List, and new ones are announced 30 days in advance.
- Breach response. PhoneFlow investigates, contains and notifies under Section 10.
- Deletion. Deletion on request and after termination is handled under Section 13, including recordings held at Twilio.
- Resilience. The Services run on managed cloud infrastructure, with database backups managed by the hosting provider.
Annex III — Subprocessors #
The Subprocessor List at https://myphoneflow.com/legal/subprocessors/, as updated under Section 9.
