Effective Date September 2, 2026
This Data Processing Addendum (“DPA”) supplements the Vocaliva LLC Terms of Service, Master Services Agreement, and any applicable proposal, statement of work, order form, checkout terms, accepted service arrangement, or other client agreement between Vocaliva LLC and a business customer.
This DPA applies when Vocaliva LLC processes personal data on behalf of a business customer in connection with Vocaliva’s AI Receptionist, lead capture and follow-up, appointment workflows, CRM or calendar integrations, Review Automation + Reactivation, email/SMS automation, Website Design + Branding, website forms, hosting and maintenance, analytics or reporting, marketing or social media support, consulting, and other related business growth, branding, marketing, automation, or operational support services where personal data is processed on the Customer’s behalf.
Vocaliva LLC is intended for businesses located in the United States. This DPA is provided as a standard customer data-processing addendum and may be updated as Vocaliva’s services, vendors, or legal requirements change.
1. Definitions
“Customer” means the business or organization using Vocaliva services.
“Customer Personal Data” means personal data, personal information, or similar information that Vocaliva processes on behalf of Customer through the services.
“Services” means the Vocaliva services described in the applicable customer arrangement, which may include AI Receptionist, lead intake and call handling, missed-call follow-up, booking workflows, CRM or calendar integrations, email/SMS automation, Review Automation + Reactivation, websites and forms, Website Design + Branding, website hosting and maintenance, analytics or reporting, marketing or social media support, consulting, and other related business growth, branding, marketing, automation, or operational support services.
“Subprocessor” means a third-party service provider engaged by Vocaliva, directly or indirectly, to process Customer Personal Data in connection with the Services.
2. Roles of the Parties
Customer determines what information is collected from callers, leads, prospects, clients, customers, staff, authorized users, or other individuals and how that information should be used in Customer’s business.
To the extent Vocaliva processes Customer Personal Data on behalf of Customer, Customer acts as the controller or business, and Vocaliva acts as the processor or service provider, depending on the applicable law.
Customer is responsible for providing required privacy notices, obtaining legally required consents, choosing appropriate workflows, and ensuring that Customer’s use of the Services complies with laws that apply to Customer’s business or industry. Customer represents that it has the lawful right, authority, and any required consent or other legal basis to provide Customer Personal Data to Vocaliva and to instruct Vocaliva to process that data.
Customer is also responsible for determining and implementing legally appropriate call-recording notices, AI or automated-agent disclosures, SMS and email consent or opt-out requirements, privacy notices, and any other disclosures required for Customer’s callers, customers, clients, prospects, employees, locations, and industry. This responsibility includes customer or lead lists provided for review requests, reactivation campaigns, follow-up, or other messaging workflows.
3. Scope and Purpose of Processing
Vocaliva processes Customer Personal Data only as reasonably necessary to provide, operate, secure, support, improve the quality of, and maintain the Services for Customer; to comply with applicable law; or as otherwise instructed by Customer through use of the Services. Vocaliva does not independently determine the recipients or business purpose of Customer review, reactivation, follow-up, or similar campaigns except as necessary to carry out Customer’s documented instructions.
Processing may include receiving, collecting on Customer’s behalf, recording, transcribing, summarizing, storing, organizing, hosting, routing, displaying, transmitting, matching to workflows, deleting, or otherwise handling Customer Personal Data for the agreed business communication, website, marketing, automation, support, and operational purposes.
4. Details of Processing
| Topic | Description |
|---|---|
| Subject Matter | AI Receptionist and call handling, missed-call and lead follow-up, appointment workflows, CRM or calendar integrations, email/SMS automation, Review Automation + Reactivation, customer or lead-list workflows, website forms, Website Design + Branding, websites/landing pages, website hosting and maintenance, analytics or reporting, marketing or social media support, consulting, and other related services described in the applicable customer arrangement. |
| Duration | For the duration of the customer relationship and any additional retention period reasonably necessary for legal, security, backup, dispute, or operational purposes. |
| Categories of Data Subjects | Customer’s callers, leads, prospects, clients, customers, staff, authorized users, website visitors, past customers or leads included in Customer-provided contact lists, and other individuals who interact with Customer through the Services. |
| Types of Personal Data | Names, phone numbers, email addresses, business or contact details, appointment requests, call information, call recordings, transcripts, summaries, messages, form submissions, CRM notes, customer or lead-list records, workflow and consent or opt-out status where available, review-request and reactivation records, website or marketing interaction data, analytics data, and related service records. |
| Purpose | To answer or support calls, capture and route lead information, support booking workflows, send Customer-directed follow-ups, review requests, or reactivation messages, operate website forms and related hosting or integrations, support approved marketing or communication workflows, maintain service records, notify Customer, troubleshoot issues, improve the quality of Services provided to Customer as permitted by law, and provide the agreed Services. |
5. Customer Instructions
Vocaliva will process Customer Personal Data according to Customer’s documented instructions, including instructions given through configuration, workflows, forms, calendars, call scripts, settings, and other service choices.
Where Customer enables call recording, transcription, AI voice, SMS or email automation, review requests, reactivation, automated follow-up, customer or lead-list workflows, website forms, hosting, analytics, marketing, social media support, or other data-enabled features, Customer instructs Vocaliva LLC to process related Customer Personal Data for those purposes and remains responsible for ensuring that required notices, consents, permissions, opt-out mechanisms, and lawful bases are provided or maintained.
Vocaliva may process Customer Personal Data as required by law, provided that Vocaliva will notify Customer when legally permitted.
6. Sensitive Data
Customer should not submit or instruct Vocaliva to collect sensitive or specially regulated personal information, including medical or health information, financial account or payment-card information, government identification numbers, authentication credentials, legal or emergency information, or similar regulated data, unless Vocaliva has expressly agreed in writing to support that use case.
Vocaliva is not currently offered as a HIPAA-compliant, emergency-response, legal-advice, financial-advice, or regulated medical decision-making service.
7. Security Measures
Vocaliva will use reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data from unauthorized access, disclosure, alteration, or destruction.
These safeguards may include access controls, vendor account security, password or authentication protections, limited internal access, platform security features, reasonable data minimization, recordkeeping, and reasonable review of service providers appropriate to the Services being provided.
No online platform, phone system, AI tool, CRM, email provider, or internet-connected service can guarantee absolute security.
8. Confidentiality
Vocaliva will limit access to Customer Personal Data to personnel, contractors, or service providers who need access to provide, support, secure, or improve the quality of the Services for Customer and who are subject to confidentiality or similar obligations.
9. Subprocessors
Customer authorizes Vocaliva to use Subprocessors to provide the Services. Vocaliva’s current Subprocessor List is available at https://vocaliva.com/subprocessors.
Vocaliva may update the Subprocessor List from time to time. Where required by applicable law or customer agreement, Vocaliva will provide reasonable notice of material changes and allow Customer to raise a reasonable, good-faith objection.
Vocaliva will take reasonable steps to use service providers that maintain appropriate privacy and security commitments for the nature of the services they provide and, where required by applicable law, will impose data-protection obligations appropriate to the processing performed by the Subprocessor.
10. Assistance With Requests
Taking into account the nature of the Services, Vocaliva will provide reasonable assistance to Customer in responding to valid requests from individuals to access, correct, delete, or restrict use of Customer Personal Data, to the extent such assistance is technically and commercially reasonable.
Customer remains responsible for determining whether a request is valid and how to respond.
11. Security Incidents
If Vocaliva becomes aware of a security incident involving Customer Personal Data that requires notice to Customer under applicable law, Vocaliva will notify Customer without undue delay after becoming aware of the incident and will provide reasonable information available to Vocaliva.
Vocaliva’s notice of an incident is not an admission of fault or liability.
12. Return and Deletion
Upon termination of the applicable Services, Customer may request deletion or return of Customer Personal Data, subject to technical feasibility, legal requirements, platform limitations, backup retention, security obligations, and legitimate business recordkeeping needs. Customer is responsible for exporting or retaining any data it wishes to keep before access to a third-party platform, account, website, CRM, or workflow is removed where Customer has the ability to do so.
13. California Service Provider Terms
Where the California Consumer Privacy Act, as amended (“CCPA”), applies to Customer Personal Data, Vocaliva will process applicable personal information as a service provider or contractor only for the limited and specified business purposes described in this DPA and the applicable customer arrangement, including providing, securing, supporting, maintaining, and improving the quality of the Services provided to Customer as permitted by the CCPA.
Vocaliva will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising. Vocaliva will not retain, use, or disclose Customer Personal Data for a commercial purpose outside the limited business purposes described in this DPA or outside the direct business relationship with Customer except as permitted by the CCPA. Vocaliva will not combine Customer Personal Data with personal information received from another customer, source, or Vocaliva’s own interaction with the same individual except as permitted by the CCPA.
To the extent required by the CCPA, Vocaliva will provide the level of privacy protection required of service providers or contractors, will reasonably assist Customer with applicable consumer requests, will notify Customer if Vocaliva determines it can no longer meet applicable CCPA obligations, and will cooperate with reasonable steps by Customer to verify compliance or stop and remediate unauthorized use of Customer Personal Data.
14. International Transfers
Vocaliva and its service providers may process or store Customer Personal Data in the United States or other locations where their personnel, systems, or subprocessors operate. Where required, appropriate transfer mechanisms or vendor terms may apply.
15. Audits and Information
Upon reasonable written request, Vocaliva may provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, legal, and operational limitations.
Any audit or review must be reasonable in scope, scheduled in advance, and conducted in a way that does not compromise security, confidentiality, other customers’ data, or Vocaliva’s operations.
16. Order of Precedence
If there is a conflict between this DPA and the Terms of Service, Master Services Agreement, Order Form, statement of work, checkout terms, or other applicable accepted client agreement regarding the processing of Customer Personal Data on behalf of Customer, this DPA will control for that specific data-processing issue unless the applicable accepted agreement expressly states otherwise.
17. Contact
Questions about this DPA may be sent to:
Vocaliva LLC
Legal and DPA notices: [email protected]
Privacy requests: [email protected]
General inquiries: [email protected]
Website: https://vocaliva.com