Data Processing Addendum (DPA)

Last updated: 21 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms & Conditions between [LEGAL ENTITY NAME] ("heyServo", "Processor") and the customer ("Customer", "Controller") and governs heyServo's processing of personal data on the Customer's behalf when providing the Service. Capitalized terms not defined here have the meaning given in the Terms. Where "GDPR" is referenced, equivalent obligations apply under other applicable data-protection laws (e.g., KSA PDPL, UAE, UK GDPR, CCPA).

Roles: the Customer is the Controller (or processor for its own controllers) of the personal data processed through its agent; heyServo is the Processor (or sub-processor) acting only on the Customer's documented instructions.

1. Subject matter & duration

heyServo processes personal data to provide the conversational-AI Service for the duration of the subscription and until deletion or return of data as set out below.

2. Nature & purpose of processing

Receiving, understanding, and responding to end-user conversations across channels; generating AI responses; performing configured actions (e.g., booking, orders, CRM updates); transcription/synthesis for voice; storage, hosting, security, and support — solely to provide the Service.

3. Processor obligations

4. Controller obligations

The Controller warrants it has a lawful basis and all necessary consents/notices for the data it routes through the Service (including messaging, call-recording, and marketing consents), and that its instructions comply with applicable law.

5. International transfers

Where personal data is transferred across borders, the parties will rely on an appropriate transfer mechanism (e.g., Standard Contractual Clauses or equivalent), which are incorporated by reference where applicable.

6. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.

Annex I — Details of processing

Data subjectsThe Customer's end-users/customers who contact the agent; the Customer's authorized users.
Categories of dataContact identifiers (name, phone, messaging handle, email); conversation content (messages, call audio/transcripts); metadata (timestamps, channel, language, intent, outcomes); data provided during a conversation; integration data as configured.
Special categoriesNot intended; the Customer must not submit sensitive data except as lawfully permitted and consented.
FrequencyContinuous, for the duration of the subscription.
RetentionAs configured by the Customer / per the Terms; deleted or returned on termination subject to legal retention.

Annex II — Security measures

Annex III — Sub-processors

Current categories: cloud hosting/infrastructure; messaging & telephony providers (e.g., WhatsApp/Meta, SMS/voice carriers); AI model & speech providers; analytics, email, and payment providers. A current, itemized list is available at privacy@heyservo.ai. [Insert named sub-processors and locations before execution.]

This DPA is a general template and does not constitute legal advice. Have it reviewed and finalized by qualified legal counsel for your jurisdiction(s) before use. The English version governs.