Skip to main content

[ Customer Agreements ]

Data Processing Addendum

Effective
August 6, 2026
Version
2026-08-06

This Addendum governs how Syntax Voice processes personal data on your behalf. You are the Controller, and we are the Processor. It forms part of the Terms of Service and applies to every workspace. There is nothing separate to request or sign.

01 / Scope and Nature of Processing

  • Purpose. We process data strictly to operate the omnichannel platform on your behalf: routing calls, generating AI replies, transcribing audio.
  • Data types. We process identifiers, conversation content, derived AI metadata, and transaction details for your end users, personnel, and contacts.
  • Retention. Standard call records, transcripts, and recordings are automatically deleted after 90 days. Messaging consent and opt-out records are retained longer for legal compliance.

02 / Processor Obligations

  • Strict instructions. We process Customer Personal Data exclusively on your documented instructions.
  • No sale or secondary use. We do not sell data, share it for behavioral advertising, or use it for our own commercial purposes.
  • No model training. We do not use Customer Personal Data to train, fine-tune, or evaluate our own or third-party machine learning models.
  • Your obligations. You warrant that you have obtained all necessary privacy notices, consents, and legal bases to record, transcribe, and process end-user data.

03 / Sub-processors

  • Authorization. You authorize the use of the sub-processors listed at Sub-processors.
  • Liability and notice. We remain fully liable for our sub-processors. We will notify you via email 30 days before adding a new sub-processor, giving you the right to object.

04 / Security and Breach Notification

  • Measures. We implement strict tenant isolation, TLS encryption in transit, storage-layer encryption, and PII/PHI redaction in error logs.
  • Breach notice. We will notify you of a personal data breach within 72 hours of awareness. You remain responsible for notifying regulators and individuals.

05 / Data Subject Rights and International Transfers

  • Assistance. You can fulfill most data subject requests, such as access and opt-outs, via the dashboard. We will assist with manual deletion requests within 30 days.
  • Location and SCCs. Processing occurs in the United States. Transfers subject to European or UK laws are governed by the Standard Contractual Clauses. We do not offer EU data residency.

06 / Audits and Deletion

  • Deletion. You may export data for 30 days post-termination. Following a 30-day grace period, deleted workspaces are permanently purged, and backups age out after 30 days.
  • Audits. You may audit our compliance once every 12 months with 30 days’ notice.

Certifications we do not hold

We do not currently hold SOC 2 or ISO 27001 certifications.