Legal

Data Processing Addendum

Last updated: June 2, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Assistable Machine Learning, Inc. (“Assistable”) and the customer (“Customer”) for use of the services, and applies where Assistable processes personal data on behalf of the Customer. Where there is a conflict, this DPA controls over the Terms of Service with respect to the processing of personal data. Capitalized terms not defined here have the meaning given in the Terms of Service.

01Definitions

“Data Protection Laws” means applicable laws governing the processing of personal data, including the EU and UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), and similar state and national laws. “Controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings given in the Data Protection Laws. “Customer Personal Data” means personal data within Customer Data that Assistable processes on the Customer's behalf.

02Roles and scope

For Customer Personal Data, the Customer is the controller (or a processor acting on behalf of its own controllers) and Assistable is the processor (or subprocessor). For purposes of the CCPA, Assistable acts as a service provider and will not retain, use, sell, share, or disclose Customer Personal Data except as necessary to provide the services or as permitted by law. Assistable will not combine Customer Personal Data with data from other sources except as permitted by the CCPA.

03Customer instructions

Assistable will process Customer Personal Data only on the Customer's documented instructions, including as set out in the agreement, this DPA, and the Customer's use of the services, unless required to do otherwise by law (in which case Assistable will inform the Customer unless legally prohibited). The Customer is responsible for the accuracy and legality of its instructions and for having a lawful basis to process Customer Personal Data.

04Confidentiality of personnel

Assistable ensures that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive appropriate data protection and security training.

05Security measures

Assistable implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256).
  • Role-based access controls, least-privilege access, and support for SSO/SAML and SCIM provisioning.
  • Network and application security, including segmentation, hardening, and vulnerability management.
  • Logging, monitoring, and exportable audit trails of access and changes.
  • A documented incident response process and business continuity and disaster recovery practices.
  • Secure software development practices and periodic review of security controls.

06Subprocessors

The Customer authorizes Assistable to engage subprocessors to provide the services, including cloud infrastructure, large language model, speech, and telephony providers. Assistable imposes data protection obligations on its subprocessors substantially similar to those in this DPA and remains responsible for their performance. Assistable maintains a current list of subprocessors available on request and will give notice of intended additions or replacements so the Customer may object on reasonable data protection grounds.

07Data subject requests

Taking into account the nature of the processing, Assistable will provide reasonable assistance, including appropriate technical and organizational measures, to enable the Customer to respond to requests from data subjects to exercise their rights. If Assistable receives such a request directly, it will, where permitted, direct the data subject to the relevant Customer.

08Personal data breach notification

Assistable will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its own breach notification and cooperation obligations.

09Assistance and impact assessments

Taking into account the nature of processing and the information available to Assistable, Assistable will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities where required by the Data Protection Laws.

10International transfers

Where processing involves the transfer of personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated into this DPA by reference and completed by the details in the annexes below. Data residency options are available for eligible plans.

11Audit and compliance

Assistable will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, scope, notice, and frequency conditions. Assistable may satisfy audit requests by providing its then-current security documentation and any available third-party reports.

12Return and deletion of data

On termination or expiry of the agreement, Assistable will, at the Customer's choice, return or delete Customer Personal Data within a reasonable period, and delete existing copies unless retention is required by law.

13Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the agreement.

14Annex A: Details of processing

The processing under this DPA is described as follows:

  • Subject matter: provision of the Assistable platform and related services.
  • Duration: the term of the agreement, plus any period required for return or deletion.
  • Nature and purpose: hosting, routing, answering, transcribing, summarizing, analyzing, and storing conversations across voice, SMS, WhatsApp, and chat in order to provide the services.
  • Categories of data subjects: the Customer's end users, customers, contacts, and personnel who interact with the Customer's agents.
  • Categories of personal data: identifiers and contact details, conversation content (voice recordings, transcripts, and messages), call and message metadata, and any other data the Customer chooses to process through the services.
  • Special categories: not intended; the Customer should not submit special category data except as separately agreed.

15Annex B: Technical and organizational measures

The technical and organizational measures are those described in the Security measures section above, as updated from time to time, provided that updates do not materially reduce the overall level of protection.

16Contact

For DPA execution, subprocessor lists, or data protection questions, contact support@assistable.ai.

Questions about this document? Email support@assistable.ai.