Data Processing Addendum (DPA)
Last updated: 21 July 2026
This Data Processing Addendum ("DPA") forms part of the Terms & Conditions between [LEGAL ENTITY NAME] ("heyServo", "Processor") and the customer ("Customer", "Controller") and governs heyServo's processing of personal data on the Customer's behalf when providing the Service. Capitalized terms not defined here have the meaning given in the Terms. Where "GDPR" is referenced, equivalent obligations apply under other applicable data-protection laws (e.g., KSA PDPL, UAE, UK GDPR, CCPA).
1. Subject matter & duration
heyServo processes personal data to provide the conversational-AI Service for the duration of the subscription and until deletion or return of data as set out below.
2. Nature & purpose of processing
Receiving, understanding, and responding to end-user conversations across channels; generating AI responses; performing configured actions (e.g., booking, orders, CRM updates); transcription/synthesis for voice; storage, hosting, security, and support — solely to provide the Service.
3. Processor obligations
- Instructions. Process personal data only on the Controller's documented instructions (including via configuration and the Terms), unless required by law (with notice where permitted).
- Confidentiality. Ensure personnel authorized to process data are bound by confidentiality.
- Security. Implement appropriate technical and organizational measures (see Annex II).
- Sub-processors. Use the sub-processors in Annex III; impose equivalent data-protection obligations by contract; give the Controller prior notice of intended changes and an opportunity to object.
- Assistance. Reasonably assist the Controller with data-subject requests and with security, breach-notification, and data-protection-impact-assessment obligations.
- Breach notification. Notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data.
- Deletion/return. On termination, delete or return the Controller's personal data (Controller's choice), subject to legal retention.
- Audits. Make available information reasonably necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and scheduling.
4. Controller obligations
The Controller warrants it has a lawful basis and all necessary consents/notices for the data it routes through the Service (including messaging, call-recording, and marketing consents), and that its instructions comply with applicable law.
5. International transfers
Where personal data is transferred across borders, the parties will rely on an appropriate transfer mechanism (e.g., Standard Contractual Clauses or equivalent), which are incorporated by reference where applicable.
6. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.
Annex I — Details of processing
| Data subjects | The Customer's end-users/customers who contact the agent; the Customer's authorized users. |
|---|---|
| Categories of data | Contact identifiers (name, phone, messaging handle, email); conversation content (messages, call audio/transcripts); metadata (timestamps, channel, language, intent, outcomes); data provided during a conversation; integration data as configured. |
| Special categories | Not intended; the Customer must not submit sensitive data except as lawfully permitted and consented. |
| Frequency | Continuous, for the duration of the subscription. |
| Retention | As configured by the Customer / per the Terms; deleted or returned on termination subject to legal retention. |
Annex II — Security measures
- Encryption of data in transit; access controls and least-privilege; credential/secret vaulting.
- Logging of agent actions; environment separation; monitoring.
- Human-in-the-loop approval available for sensitive actions.
- Vendor management for sub-processors. (SOC 2 / ISO 27001 are on the roadmap and not represented as currently held.)
Annex III — Sub-processors
Current categories: cloud hosting/infrastructure; messaging & telephony providers (e.g., WhatsApp/Meta, SMS/voice carriers); AI model & speech providers; analytics, email, and payment providers. A current, itemized list is available at privacy@heyservo.ai. [Insert named sub-processors and locations before execution.]
This DPA is a general template and does not constitute legal advice. Have it reviewed and finalized by qualified legal counsel for your jurisdiction(s) before use. The English version governs.