This Data Processing Agreement ('DPA') forms part of the Master Service Agreement or Terms of Service between HulloDesk and the Customer.
"Applicable Data Protection Law" means the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and any other applicable privacy or data protection laws in the jurisdiction(s) where HulloDesk or Customer operates.
The terms "Controller", "Processor", "Data Subject", and "Processing" shall have the meanings given in Applicable Data Protection Law.
"Personal Data" means any information relating to an identified or identifiable natural person (e.g., names, email addresses, phone numbers, IP addresses, call recordings).
"Subprocessor" means any third-party vendor engaged by HulloDesk to assist in Processing Personal Data (e.g., database hosting, AI voice processing, telephony providers).
Customer acts as a Data Controller and HulloDesk acts as a Data Processor. HulloDesk shall process Personal Data only on behalf of and in accordance with the Customer's documented instructions.
HulloDesk implements the following security safeguards in accordance with GDPR Article 32:
Customer provides a general authorization to HulloDesk to engage subprocessors. HulloDesk shall:
HulloDesk shall, to the extent legally permitted, promptly notify Customer if HulloDesk receives a request from a Data Subject to exercise their rights. HulloDesk shall assist Customer in fulfilling its obligations to respond to such requests.
HulloDesk shall make available to Customer all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer.
In accordance with GDPR Article 28(3)(g), upon termination or expiry of the Agreement, HulloDesk shall, at Customer's election:
Upon request, HulloDesk will provide written certification of data deletion to [email protected].
To the extent HulloDesk processes Personal Data originating from the European Economic Area (EEA), Switzerland, or the United Kingdom, the parties agree that the Standard Contractual Clauses (Module Two: Controller-to-Processor), as adopted by the European Commission under Decision 2021/914/EU, are hereby incorporated by reference and shall apply to such transfers. In the event of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail for EEA, Swiss, and UK transfers.
This DPA shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of law provisions, except where otherwise required by Applicable Data Protection Law (e.g., GDPR Article 79 for EU data subjects).
Required under GDPR Article 28(3) and Appendix 1 of Standard Contractual Clauses
HulloDesk processes Personal Data to provide AI voice agent services: automated lead follow-up calls, post-job review calls, inbound receptionist calls, SMS messaging sequences, appointment scheduling, and call analytics.
| Category | Examples | Source |
|---|---|---|
| Contact Information | Names, phone numbers, email addresses, business names | Customer uploads, API integrations |
| Call Data | Audio recordings, AI transcripts, call duration, timestamps, call outcomes | Automated call processing |
| Communication Data | SMS message content, email notifications | Automated SMS sequences |
| Appointment Data | Calendar availability, booking timestamps, meeting links | Calendar integrations |
| Usage Data | IP addresses, browser type, session logs, feature interactions | Platform analytics |
| Billing Data | Payment card details (tokenized), billing addresses, subscription status | Stripe (payment processor) |
| Consent Records | Date/time of consent, IP address, consent method, opt-out requests | TCPA compliance tracking |
This page constitutes the standard Data Processing Agreement for self-serve customers. Enterprise customers are governed by our custom Data Processing Addendum (v2.0), which includes Standard Contractual Clauses (SCCs), custom annexes, and negotiated terms.
EU/UK customers, enterprise accounts, or any customer requiring a countersigned DPA may request the full Data Processing Addendum (v2.0) through our legal portal.
Request Enterprise DPA →