Data Processing Agreement
Incorporated by reference into the Terms of Service.
This Data Processing Agreement (the DPA) is between the customer identified in the Terms of Service (the Customer) and Callper SRL, registered in Romania, VAT RO55481408, trade register number J2026050795000, registered office at Aeroportului Street no. 1D, building III, 4th floor, apt. 38, 700384 Iași, Romania (Callper). It forms part of the Terms of Service (the Agreement) and applies wherever Callper processes personal data on the Customer's behalf under Article 28 of Regulation (EU) 2016/679 (the GDPR). The factual statements in the Annexes come from the Callper decision record (ADR 0002, 0005, 0011, 0012, 0013, 0014) and the operational documents named there.
1. Definitions
1.1 "Personal data", "controller", "processor", "data subject", "processing", "personal data breach", "special categories of personal data" and "supervisory authority" have their GDPR meanings.
1.2 Service means the Callper AI phone-answering service and its dashboard. Customer Data means personal data Callper processes on the Customer's behalf in providing the Service (categories in Annex 2). Caller means any person who telephones, or is telephoned by, an assistant the Customer operates through the Service. Sub-processor means a third party Callper engages to process Customer Data.
1.3 Zero Data Retention (ZDR) means the per-organisation option on the Business plan under which no conversation content is written to durable storage at Callper or any Sub-processor after a call completes (clause 9). Business Records means contacts and appointments (clause 9.5).
2. Roles and scope
2.1 For Customer Data the Customer is the controller and Callper is the processor. The Customer decides why the assistant exists, what it says, what it asks for and where callers' details go. Callper processes Customer Data only to deliver the Service.
2.2 Callper is an independent controller, under its Privacy Policy and not this DPA, for the Customer's account and staff identity (log-ins, organisation membership, roles), billing records, correspondence with Callper, and security and audit logs of administrative actions.
2.3 Stripe. Payments are processed by Stripe Payments Europe, Ltd and its affiliates. For regulated payment processing (anti-money-laundering, know-your-customer, fraud and card-scheme rules) Stripe is a joint controller under its own legal obligations, which Callper cannot instruct. Stripe is therefore not a Sub-processor of Customer Data and is outside this DPA. No Caller data and no health data ever enters Stripe; Callper enforces this as a technical invariant (ADR 0005).
2.4 Cal.com. Where the Customer connects its own Cal.com account, Cal.com is the Customer's own processor under the Customer's own contract. Callper sends booking data to Cal.com on the Customer's instruction, with a credential the Customer supplied and can revoke; Cal.com is not a Sub-processor under this DPA (ADR 0012). Appointments booked this way are stored in the Customer's Cal.com account as well as in the Service.
3. Subject matter, duration, nature and purpose
3.1 Subject matter. Answering, handling, transferring and following up telephone calls on the Customer's behalf with an AI assistant, and operating the dashboard through which the Customer configures the assistant and reviews its work.
3.2 Duration. The term of the Agreement plus the 30-day deletion archive in clause 12. Confidentiality, deletion and audit-record obligations survive termination.
3.3 Nature. Real-time capture of speech, speech-to-text, response generation by a language model, text-to-speech, storage of transcripts, summaries, contacts and appointments, and transmission of confirmations by email or SMS.
3.4 Purpose. Providing the Service as the Customer configures it. Callper has no purpose of its own in Customer Data: it does not use Customer Data for advertising, profiling, resale, or to train or fine-tune machine-learning models, and requires the same of its Sub-processors (clause 8.5).
4. Customer's instructions and responsibilities
4.1 Callper processes Customer Data only on the Customer's documented instructions: this DPA, the Agreement, the configuration the Customer sets in the dashboard (assistant instructions, greeting, hours, knowledge base, plan and retention options, connected calendar, imported contacts), and any further written instruction the parties agree. Callper will inform the Customer if it believes an instruction infringes data-protection law, and may suspend it until clarified.
4.2 If Union or Member State law requires Callper to process Customer Data otherwise, Callper will inform the Customer before processing unless that law prohibits it on important grounds of public interest.
4.3 The Customer is responsible for the lawfulness of the processing it instructs, including the lawful basis for any special categories of data callers disclose (clause 10).
4.4 Transparency and recording notices toward callers (ADR 0013). The Customer, as controller and as the deployer of the assistant, is responsible for telling callers that they are speaking with an AI system and, where applicable, that the call is transcribed, in the language and form the law of its market requires (including Article 50 of Regulation (EU) 2024/1689 and national ePrivacy rules). Callper publishes the Customer's greeting verbatim and neither inserts nor checks disclosure wording. Callper supports the Customer by naming the duty in the greeting editor, by offering starter greetings in every language whose opening sentence already discloses the assistant, and by instructing the assistant never to claim to be human; the Customer must not instruct otherwise.
4.5 Contact import. On every import the Customer attests that it holds a lawful basis to process each contact for the purposes of the Service. A named person at the Customer makes the attestation on the upload panel, and Callper records that name, the signed-in user and the time with the batch (contacts-import.md §4).
4.6 Voice clone samples and number paperwork. Where the Customer uploads a voice sample, it confirms it holds the recorded consent of the person whose voice it is, for as long as the clone exists. Identity documents and company certificates filed to obtain telephone numbers are the Customer's own regulatory paperwork; Callper passes them to the telephony provider and keeps no copy (Annex 2, row 8).
5. Confidentiality
5.1 Every person Callper authorises to process Customer Data is bound by a contractual or statutory duty of confidentiality and instructed in handling Customer Data appropriately to their role.
5.2 Access to Customer Data at Callper is limited to personnel who need it to operate, support or secure the Service. Callper is a small company: at the date of this DPA that is a single operator, and the list grows only as the company does.
5.3 Requests from public authorities. Callper does not disclose Customer Data to a court, supervisory authority, law-enforcement body or other public authority except under a legally binding obligation. On receiving a request Callper (a) reviews its legal basis before disclosing anything and refuses a request that lacks one; (b) discloses only the Customer Data the request lawfully requires and nothing more; (c) records the request, the review, what was disclosed and who at Callper was involved; and (d) informs the Customer of the request without undue delay and before disclosure where possible, unless the law prohibits it, consistent with clause 4.2. Where the request should have been addressed to the Customer, Callper says so and refers the authority to the Customer.
6. Security (Article 32)
6.1 Callper implements and maintains the technical and organisational measures in Annex 1, and such further measures as the risk requires, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.
6.2 Callper may update Annex 1 provided the overall level of protection is not materially reduced.
7. Personal data breach
7.1 Callper will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data, describing so far as known the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point. Information may follow in phases.
7.2 Callper will reasonably assist the Customer with its duties under Articles 33 and 34, and will not notify a supervisory authority or data subjects on the Customer's behalf unless instructed or required by law.
7.3 A breach at a Sub-processor counts as a breach at Callper from the moment Callper becomes aware of it.
8. Sub-processors
8.1 The Customer gives general written authorisation for the Sub-processors in Annex 3 and in the register it points to.
8.2 Callper gives at least 30 days' notice before adding or replacing a Sub-processor, by updating the public register and by email to the Customer's owner address, stating the name, country, role and transfer footing.
8.3 The Customer may object in writing within the notice period on reasonable data-protection grounds. The parties discuss the objection in good faith; if Callper cannot reasonably accommodate it, the Customer may terminate the affected part of the Service, or the Agreement, without penalty before the change takes effect, with fees already paid for the period after the termination refunded pro rata. That refund is an exception, agreed here, to section 8.4 of the Agreement, under which the remainder of a paid period is otherwise not refunded.
8.4 Callper binds each Sub-processor by written contract to data-protection obligations in substance the same as this DPA, including Article 32 measures, and remains fully liable to the Customer for each Sub-processor's performance.
8.5 For Sub-processors that process conversation content, Callper requires that Customer Data is not used to train or improve models and that retention is limited to what the Service needs. With the telephony Sub-processor this rests on three things. (a) Its own agreement, which is part of its terms and binds it without a signature: it does not use call content to train models offered to anyone else, except with the customer's opt-in, which Callper has not given, or on data it has first de-identified, which it may use to improve its own products. (b) Retention under Callper's configuration: that agreement leaves retention to the settings Callper fixes on every assistant template (Annex 1). (c) No further recipient: the speech-to-text, language and voice models that handle a call run on that Sub-processor's own infrastructure, so no other company's terms apply to a call (clause 8.6). The Sub-processor gives no separate written assurance to individual customers beyond its published agreement and documentation, and Callper holds none. Callper asked it on 2026-10-02 to document an opt-out from the use of de-identified content as well, and will state the answer in the register. A Customer that cannot accept the remaining difference has Zero Data Retention (clause 9), under which no conversation content is written at the Sub-processor at all.
8.6 Where a Sub-processor engages its own further processors, Annex 3 discloses them so far as Callper knows them, under the Sub-processor's own contract. For conversation content there are none: the telephony Sub-processor runs the speech-to-text, the language model and the voices on its own infrastructure, and the companies whose models those are receive nothing from a call (stated by that Sub-processor in its published documentation and in writing to Callper on 2026-10-02). Callper offers Customers only engines that the Sub-processor documents as run on its own infrastructure, and withdrew on 2026-10-05 the one voice vendor it documents as an outside service.
9. Retention, Zero Data Retention and Business Records
9.1 Callper retains Customer Data for the periods in Annex 2, which differ by data class and by plan. The plan description, this DPA and the public register carry the same boundary (ADR 0011).
9.2 What ZDR means. With ZDR on, no conversation content (audio, transcripts, summaries, extracted entities, language-model prompts and completions carrying content, or copies in logs, traces and queues) is written to durable storage at Callper or any Sub-processor after a call completes. "Not written" means never written, not deleted afterwards. ZDR does not cover billing records, account and identity data, call metadata carrying no content (times, duration, direction, outcome, cost), configuration the Customer supplied (including a voice clone sample), or Business Records.
9.3 What ZDR does not change. Conversation content still transits the telephony Sub-processor's speech-to-text, language model and text-to-speech engines in real time on every call, at the locations stated in Annex 3. ZDR removes the storage window, not the processing, and the Customer's notice to callers should describe the processing either way (ADR 0011, second amendment of 2026-08-20).
9.4 ZDR runs forward only. Switching it on governs calls from that moment and does not remove transcripts already stored at Callper or conversations the telephony Sub-processor already holds. A Customer who needs the past removed uses the erasure paths in clauses 11 and 12. The dashboard says so beside the control, and the switch cannot succeed silently: if the Sub-processor does not confirm, ZDR stays off and the Customer is told.
9.5 Business Records (contacts and appointments) are retained as the Customer's business records on every plan. Membership is decided by authorship: data the Customer typed, imported or booked against, or that a transaction required (an appointment needs an attendee), is a Business Record; anything the assistant heard that no transaction required stays conversation content under clause 9.2. The contact notes field is written only by the Customer, never by the assistant or a summariser (ADR 0011, amendment of 2026-08-17).
9.6 Callper may use a Customer's retained transcripts to diagnose faults in that Customer's assistant and, on the Customer's instruction, to tune that Customer's own assistant. Callper does not use one Customer's content to improve the Service for others: a transcript is worked on for the account it belongs to or not at all, and what Callper learns from it and carries elsewhere is never the content.
10. Special categories of personal data
10.1 Callers may say anything. Where the Customer is a clinic, practice or other health or care provider, or callers otherwise disclose health, religious, sexual-orientation or similar data, call content may carry special categories of personal data under Article 9 GDPR, of which the Customer is the controller.
10.2 Callper's position on such data: it has no purpose of its own in it (clause 3.4); it does not use it to train models and requires the same of its Sub-processors (clause 8.5); it is retained only as Annex 2 states for the Customer's plan; and no audio recording is ever kept (Annex 2, row 1). ZDR is available to Customers who need no content retained.
10.3 The Customer determines and documents its Article 9(2) condition, gives the caller notices that condition requires, and carries out a data protection impact assessment where Article 35 requires one, with Callper's assistance under clause 11.5.
11. Assistance with data-subject rights and impact assessments
11.1 Taking into account the nature of the processing, Callper assists the Customer with appropriate technical and organisational measures in responding to data-subject requests under Chapter III GDPR.
11.2 Self-service first. The dashboard lets the Customer read, correct and delete a contact and its appointment attendee (per data subject; the appointment fact survives with the attendee removed, CALL-201), read transcripts where retained, and delete the account.
11.3 Requests Callper receives directly from a data subject are forwarded to the Customer within 5 business days without a substantive reply, unless the law requires Callper to answer.
11.4 Erasure that reaches Sub-processors. Where a request requires deletion of a conversation held by the telephony Sub-processor, Callper deletes it there on the Customer's instruction. There is no dashboard control for a single conversation: the Customer names the call in writing and Callper resolves it to the Sub-processor's own record and deletes it, within 5 business days. Account deletion does the same for every conversation at once (clause 12.6).
11.5 Callper assists with data protection impact assessments and prior consultation (Articles 35 and 36) by providing this DPA, its Annexes, the register, the transfer impact assessments, and reasonable further information only Callper holds, at no charge. Assistance that goes materially beyond this — bespoke questionnaires, workshops, or work for the Customer's own assessors — is charged at cost, quoted and agreed in writing before it begins.
12. Deletion and return at the end of the Service
12.1 On termination or on the Customer's deletion request, Callper immediately cancels the subscription, releases telephone numbers, deletes voice clones at the provider, and deletes the Customer's organisation and staff log-ins at the identity provider.
12.2 The Customer's remaining data at Callper is archived for 30 days: unreachable from every authenticated path, restorable on written request (released numbers excepted), and erased unconditionally at the end of the window by a scheduled job (account-deletion.md; CALL-385).
12.3 The Customer may request immediate erasure within the window in place of the archive, where it is discharging an erasure obligation rather than closing its account. There is no dashboard control for it: the Customer asks in writing and Callper runs the same erasure by hand, which ends the restore right in clause 12.2.
12.4 Return. Before requesting deletion the Customer may ask for its contacts, appointments, call records and retained transcripts. There is no self-service export: Callper prepares the copy on written request and delivers it within one month, tabular records as CSV and the rest as JSON. Asking for it does not start the deletion. A Customer that deletes first has not lost it: while the 30-day archive in clause 12.2 stands, Callper restores it on written request and prepares the copy then.
12.5 What survives erasure: invoices and the payment-provider customer record (statutory financial retention), the record of the deletion request and of what was destroyed at each provider, cancellation feedback with the organisation name as a snapshot, and the provider event log kept as proof of what Callper did and when — a delivery identifier, an event type and an outcome per row, naming nobody. None of these is conversation content.
12.6 Deletion at Sub-processors follows their contracts. The hosting Sub-processor's own backups of the server rotate on its cycle, so a row erased under 12.2 or 12.3 may persist in one of them, inaccessible to Callper, for up to 31 days after the erasure (Annex 1, Backups). The identity provider deletes on organisation deletion and within 90 days of termination at the latest; telephony conversations held for ordinary plans are deleted with the account — the same run that releases the numbers and deletes the voice clones asks the telephony Sub-processor for each conversation it still holds for the account's calls and deletes it, and records what it deleted and anything that failed.
13. Audit and information
13.1 Callper makes available all information necessary to demonstrate compliance with Article 28, beginning with this DPA, Annex 1, the register, the transfer impact assessments, and written answers to a reasonable security questionnaire.
13.2 The Customer, or an independent auditor it mandates who is bound by confidentiality and is not a competitor, may audit Callper's compliance once in any twelve-month period on at least 30 days' written notice, during business hours, without disrupting the Service or exposing other Customers' data. A further audit may follow a breach affecting the Customer or a supervisory-authority demand. The Customer bears its own costs and Callper's reasonable costs beyond the first day.
13.3 Audits of Sub-processors run through Callper, relying on their own audit reports and certifications where they exist.
14. International transfers
14.1 Customer Data at rest is stored in the European Union: in Romania on Callper's own host, as the encrypted nightly backup in the eu-central-1 region of the telephony Sub-processor's object storage, and in the host's own backups of the server, which stay in Romania or, encrypted, in Germany (Annex 1, Backups). Callper transfers Customer Data outside the EEA only to the Sub-processors in Annex 3, on the footing stated there.
14.2 For a Sub-processor in the United States that holds no certification under clause 14.3, Callper relies on the Standard Contractual Clauses of Commission Decision (EU) 2021/914, Module 3 (processor to processor), between Callper and the Sub-processor, with a transfer impact assessment and the supplementary measures it records. The telephony Sub-processor's agreement incorporates those Clauses, and they are the fallback for it under clause 14.3.
14.3 Where a vendor holds an EU-U.S. Data Privacy Framework certification, Callper may rely on the Commission's adequacy decision of 2023-07-10, with the SCCs in that vendor's DPA as the fallback. At 2026-10-05 this applies, for Customer Data, to the telephony Sub-processor, Telnyx LLC (an active listing, read on 2026-09-28); and, for data of which Callper is controller (clauses 2.2 and 2.3) rather than Customer Data, noted for completeness, to Clerk, Inc., Stripe, Inc., Google LLC and HubSpot, Inc.
14.4 The Customer authorises these transfers. If a transfer mechanism is invalidated, Callper will notify the Customer and either implement an alternative or suspend the affected transfer.
15. Liability, precedence and law
15.1 Each party's liability under this DPA is subject to the limitations in the Agreement, except that nothing limits liability toward data subjects under Article 82 GDPR or for fines a supervisory authority imposes on a party.
15.2 If this DPA conflicts with the Agreement, this DPA prevails for Customer Data. If it conflicts with the SCCs, the SCCs prevail.
15.3 This DPA is governed by the law of Romania, with exclusive jurisdiction in the courts of Bucharest, as section 24 of the Agreement provides, and without prejudice to data subjects' rights or supervisory authorities' competence.
15.4 Callper may update this DPA to reflect changes in law, the Service or the Annexes on at least 30 days' notice; a change that materially reduces the Customer's protection gives the termination right in clause 8.3.
Annex 1: Technical and organisational measures (Article 32)
As of 2026-09-22, each measure read back from the running system on that date.
| Area | Measure |
|---|---|
| Hosting and location | Application, dashboard and PostgreSQL run on a virtual server at TES EURO MEDIA SRL (Gazduire.Net; the machine is labelled DirectHost) in Datacenter M247, Bucharest, Romania. Everything Callper stores at rest is on this host, with one exception: the encrypted copy of each nightly database dump, which is pushed off the host to an EU region of a Sub-processor's object storage (Backups below). No CDN sits in front of callper.ai. |
| Encryption in transit | TLS on every public endpoint, terminated by the Caddy reverse proxy; application processes listen on localhost only; all provider connections are HTTPS. The proxy negotiates TLS 1.3 with current clients and accepts nothing below TLS 1.2. No media leg reaches Callper at all: call audio flows between the caller and the telephony Sub-processor's own infrastructure and never touches Callper's servers, and a test call placed from the dashboard runs over WebRTC, whose media is encrypted by construction. |
| Encryption at rest | Customer-supplied credentials (Cal.com keys, webhook secrets) are encrypted per row with a key held outside the database, distinct per environment. The host's disk is not encrypted at block level and database dumps on it are not encrypted either, so what protects data at rest there is the host's own access control, the per-row encryption above, and the 30-day life of a dump (Backups below). The copy that leaves the host is encrypted first, on the host: GPG symmetric AES-256 under a passphrase held in Infisical and not at the destination, so the object store holds ciphertext and the key to it lives somewhere else. Plaintext on the host, ciphertext once it leaves — both halves are the position today. The host's own backups of the server are encrypted before any copy leaves its data centre, with keys the host alone holds; whether the copies kept inside the data centre are encrypted at rest is not stated in its agreement. |
| Secrets | All application secrets live in Infisical (EU instance) and reach processes as environment variables at launch; none is in the repository. Deploys and scheduled jobs authenticate with machine identities (ADR 0008). |
| Identity and access | Dashboard sign-in and organisation membership through Clerk with verified email; sessions in Secure; HttpOnly; SameSite cookies, no tokens in browser storage; roles enforced server-side. Authorisation is resource-based: every API path scopes on the organisation that owns the row, and a request for another organisation's resource answers an indistinguishable 404. Tenancy lives in Callper's own database, never at a provider (ADR 0003, ADR 0014). |
| No audio at rest | Call recording is set to off, explicitly, on every assistant template that answers a Customer's calls; a drift check asserts the value and treats an unset value as not off (ADR 0011, 2026-08-18). The one template that records is the one answering Callper's own public voice demo in English, under Callper's privacy policy; no Customer call is routed to it, and the same drift check holds it apart from the rest (2026-10-06). |
| ZDR templates | ZDR is a separate provider template per language with retention off, so a ZDR tenant's transcript is redacted at the source and nothing exists to delete. The switch fails closed (ADR 0011, 2026-08-20). |
| Pass-through documents | Number-order documents stream through the API to the provider and are dropped with the request; only a label and the provider's ids persist, and nothing on that path logs a request body (ADR 0014). |
| Minimisation | The assistant collects only what a transaction requires; the contact notes field has no automated writer; auto-created contacts hold the number and time only; no email address is taken by voice; health data never enters the billing provider. |
| Backups | A database dump is taken nightly and before every deployment, verified by reading its table of contents back, and kept on the host. Since 2026-09-22 a copy of each nightly dump also leaves the host: it is encrypted on the machine (GPG symmetric AES-256, passphrase from Infisical) and pushed to Telnyx Cloud Storage, region eu-central-1 — Telnyx LLC, United States, SCCs Module 3, the Sub-processor that already carries the call content these dumps contain (Annex 3). Dumps are pruned at 30 days off the host as well as on it — the same clock as the deletion archive in clause 12.2, so that no backup outlives an erasure Callper has promised — with two exceptions, each so that a dump run failing unnoticed cannot destroy the last copy: the seven most recent are always kept on the host, and the off-host prune runs only for a database whose dump reached the bucket on that same run, so a push that has stopped working cannot go on emptying a bucket it is no longer filling. The destination bucket keeps no versions and carries no object lock, so a pruned object leaves nothing behind it and, outside those two exceptions, the 30 days are a limit rather than an intention (measured 2026-09-22). The push writes a timestamp only when it succeeds, and the next run raises if that timestamp is more than 48 hours old, so a copy that quietly stopped leaving the machine is visible before it is needed. The path was accepted by restoring and not by uploading: on 2026-09-22 the newest production object was fetched back, decrypted, restored into a scratch database and read against live production, which is what distinguishes a backup from a copy. Separately from Callper's dumps, the hosting Sub-processor takes its own daily and weekly backup copies of the whole virtual server, kept at Datacenter M247 in Bucharest and, where it uses the option its agreement reserves, at Impossible Cloud GmbH (Hamburg, Germany), encrypted before transfer with keys the host alone holds. They rotate on the host's own cycle, whose depth it has not stated; its agreement deletes operational backups within 31 days of a production deletion, which Callper takes as the outer bound. A row erased from the live database may therefore persist in a host backup for up to 31 days beyond the erasure, inaccessible to Callper and usable only to restore the server (clause 12.6). ZDR content is never written to Callper's database, so it is absent from every backup — Callper's dumps and the host's copies alike — by construction. |
| Deletion | Account deletion runs externals first (billing, numbers, voice clones, identity provider), then archives the organisation; a scheduled sweep erases archived organisations after 30 days and records the erasure. The sweep runs daily in production as well as in the development environment (installed 2026-09-22). A second scheduled sweep erases a trial account that never subscribed, 90 days after its trial ended. |
| Logging | Logs carry identifiers and provider error strings, not conversation content or request bodies on sensitive paths. Application and proxy logs go to the host's system journal, which is bounded by the space it may take on disk rather than by a date — about a month in practice — while the logs of the scheduled jobs are rotated daily and kept 90 days. The check that would assert automatically that no conversation content ever reaches a log is not yet written (ADR 0011 open item 6); today this is a review rule, not a test. |
| Operations and change control | Provider webhooks are signature-verified against the raw body and deduplicated. Branch-per-ticket with review; automated API and dashboard test suites; scripted deployments with a pre-deploy backup and recorded rollback; scheduled provider-configuration drift check; server access by SSH key only as a named user, with password authentication disabled and no direct root login, services under an unprivileged account. Every vendor evaluation records the vendor's retention answer, and DPF listings are re-checked at signing and yearly. |
Annex 2: Data classes and retention, by plan
Data subjects: Callers (members of the public, patients and customers of the Customer, in its contacts or not) and Customer staff so far as their names, voices or identity documents appear in Customer Data. Staff log-in data is processed by Callper as controller (clause 2.2).
| # | Data class | Ordinary plans (Basic, Pro, Business without ZDR) | Business with ZDR on | Erasure |
|---|---|---|---|---|
| 1 | Call audio (caller's and assistant's speech) | In transit only: processed in real time by the telephony Sub-processor's speech-to-text and text-to-speech; no recording is kept anywhere (recording off on every template that answers a Customer's calls, ADR 0011, 2026-08-18; the template answering Callper's own English voice demo records, under Callper's privacy policy, and carries no Customer Data) | Same | Nothing to erase |
| 2 | Transcripts (turn-by-turn text) | Retained at Callper (EU) and at the telephony Sub-processor until account erasure or per-conversation deletion | Not retained at Callper or at the Sub-processor; redacted at the source. Forward-only: transcripts from before the switch remain until erased (clause 9.4) | Account deletion; per-conversation deletion at the provider on written request, by hand (clause 11.4) |
| 3 | Summaries and extracted outcomes (summary, outcome code, escalation flag, inferred entities) | Retained with the transcript | Not produced; the Calls view says "not retained by your plan" | With the transcript |
| 4 | Call metadata (caller's number and country, times, duration, direction, outcome, cost) | Retained as the record that a call happened; needed for invoicing | Retained (outside ZDR, clause 9.2) | Account deletion |
| 5 | Contacts (Business Record: name, numbers, email, address, language, Customer-typed notes, import attestation) | Retained as the Customer's business record | Retained | Per data subject in the dashboard (CALL-201); account deletion |
| 6 | Appointments (Business Record: time, service, attendee) | Retained; also in the Customer's own Cal.com account under the Customer's contract (clause 2.4) | Retained: an appointment is a Business Record and ZDR does not remove it. Where the Customer has connected its own Cal.com account, the booking also sits there under the Customer's own contract (clause 2.4), which ZDR does not reach either | Deleting a contact removes the attendee and keeps the fact; account deletion |
| 7 | Business identity and configuration (name, address, hours, greeting, instructions, knowledge-base text as extracted text only, voice clone sample) | Retained while the account exists; the voice sample stays at the provider until the clone is deleted | Retained (clause 9.2) | Dashboard edit or delete; account deletion deletes clones at the provider immediately |
| 8 | Number-order documents (government ID, company certificate, address proof) | Pass-through: never at rest at Callper; held in the provider's Documents API until the requirement group is deleted (ADR 0014) | Same | Delete the requirement group in the dashboard |
| 9 | Transactional messages (appointment confirmations and reminders by email or SMS) | Sent through the email Sub-processor (EU) or the telephony Sub-processor; message logs per that Sub-processor's retention. The email Sub-processor states no period and offers no deletion: measured on 2026-09-22, its log still held every message Callper had ever sent, the oldest from 12 August 2026 | Same. ZDR does not reach a sent message, because a message carries its own text to whoever sends it. A booking confirmation to an attendee is sent by the Customer's own Cal.com account under the Customer's own contract (clause 2.4), not by Callper | Per Sub-processor |
The deletion archive (clause 12.2) holds rows 2 to 7 for 30 days after a deletion request, unreachable, then erases them.
Annex 3: Sub-processors
The authoritative list is the sub-processor register, with its change log and the transfer impact assessments. Clause 8.2's notice updates the register, not this Annex. Current Sub-processors of Customer Data, as of 2026-11-07:
| Sub-processor | Country | Role | Transfer footing |
|---|---|---|---|
| Telnyx LLC — the United States entity, which is the one that invoices Callper; no EU affiliate is interposed | United States for the company. Processing in flight takes place at the provider's site that gives the call the least delay, which the provider does not guarantee to be in the European Union and may move during a failure or a shortage of capacity. Storage at rest is in the provider's Germany region, which Callper's account selects: call detail records and, for ordinary plans, conversation content. The backup objects named alongside are written to the provider's eu-central-1 region. Both stay in the European Union | Telephone numbers, calls, the AI assistant (speech-to-text, language model and text-to-speech, all run on Telnyx's own infrastructure), voice clones, number paperwork, SMS, and the encrypted nightly database backups — every class in Annex 2, as ciphertext: Telnyx holds the objects and not the passphrase (Telnyx Cloud Storage, eu-central-1; Annex 1 Backups) | EU-U.S. Data Privacy Framework certification (clause 14.3), with SCCs, Module 3, and a transfer impact assessment as the fallback. No further recipient of conversation content: the speech-to-text models (Deepgram's), the language model (an open-weight model) and the voices (the provider's own, and Resemble AI's) are run by the provider on its own infrastructure, and their authors receive nothing (clause 8.6). The provider's usage records label some of its own voices with another company's model name; the provider states that they are its in-house voices and are sent to no third party |
| Scaleway SAS | France | Transactional email to callers and to the Customer | Intra-EU |
| Anthropic Ireland, Limited (the contracting entity for a customer in the European Economic Area), with Anthropic, PBC (United States) behind it; from 2026-11-07 | Ireland for the contract; every request is run in the United States, where Callper pins it | One purpose only: when the Customer asks Callper to build an assistant from the Customer's own website, the model reads the extracted text of up to six public pages of that website and returns the business profile the assistant is built from, which the Customer confirms before it is used (Annex 2 row 7, business identity and configuration, as extracted text). It receives no caller data, no uploaded document and no call content; it deletes inputs and outputs within 30 days and may not train its models on them (register row 10 and its transfer impact assessment) | SCCs, Module Two, in Anthropic's data processing addendum; not certified under the Data Privacy Framework |
| TES EURO MEDIA SRL (Gazduire.Net; the host of the server labelled DirectHost), CUI RO 14612719 | Romania (Datacenter M247, Bucharest) | Hosting of the API, dashboard, database and the backups kept on the host: Callper's dumps (a copy of each nightly dump also goes to the row above, encrypted) and the host's own daily and weekly backups of the server. Its own sub-processor for backup storage, where used: Impossible Cloud GmbH, Hamburg, Germany, holding encrypted copies without the keys | Intra-EU |
In the register for completeness, processing data for which Callper is controller rather than Customer Data: Clerk, Inc. (US, staff sign-in; DPF-certified, SCCs as fallback), Stripe (Ireland and US, billing; joint controller for regulated payment processing, DPF-certified, clause 2.3), Google Cloud EMEA Limited (Ireland, Callper's mailboxes on Google Workspace, with Google LLC in the United States behind it; DPF-certified, SCCs as fallback), Infisical Inc. (EU instance, secrets, no personal data), Anthropic Ireland, Limited with Anthropic, PBC behind it (United States; the AI model that reads and answers replies to Callper's own outreach emails, and that reads the public pages of a website a visitor names in the builder on Callper's own site, register row 10; SCCs; for the one purpose in the table above it is a Sub-processor of Customer Data, and for these two it holds none), Bouncer Sp. z o.o. (Poland; checks once that a prospect's published email address exists before Callper's first outreach email, register row 11; EU processing, no transfer; holds no Customer Data) and HubSpot, Inc. (Callper's own CRM and website analytics, register row 8; data hosted in the European Union (Germany); holds Callper's prospects and dashboard users and no Customer Data, ADR 0017 rule 2).
Not Sub-processors: Cal.com as the Customer's own calendar (the Customer's own processor, clause 2.4). Callper's own Cal.com account — its earlier demo booking page, which takes no new bookings and holds only prospects' past bookings and no Customer Data, until it is closed — is register row 9 and Callper's processor as controller, outside this DPA; demos are now booked on a page HubSpot hosts (register row 8, likewise outside this DPA). The assistant's language model runs on the telephony Sub-processor's own hardware (the Telnyx row above), and no hosted third-party language-model API ever receives a caller's words. The one hosted language-model API that processes Customer Data is Anthropic's, for the single purpose in its row above and nothing else, and the register changes before any other does. For the replies to Callper's own outreach emails and for the public pages of websites that visitors name in the builder on Callper's own site, before any account exists, Anthropic (register row 10) acts as Callper's processor, outside this DPA.
Signature
Accepted electronically under the Terms of Service on the date recorded at checkout or first sign-in.
| For Callper SRL | For the Customer |
|---|---|
| [Name, title] | [Name, title, company, registration number] |
| Date: | Date: |