Data processing

Ansora Data Processing Addendum (DPA)

For caller data Ansora processes on behalf of the Client business as a processor / service provider

Last updated July 5, 2026 · Ansora, Miami, FL

The short version

This Data Processing Addendum sets the rules for the caller data Ansora handles on your behalf when it runs your AI receptionist. You (the Client) are the controller — it's your callers, your business, your decisions. Ansora is your processor / service provider — we only touch caller data to run the service you hired us for, and never for our own purposes. Below we cover who does what, what data is involved, how we secure it, which subprocessors we use (Vapi, Twilio, Deepgram, an LLM provider such as OpenAI, Stripe, Supabase, Resend, Google Workspace), how we help you answer data-subject and breach questions, and what happens to the data when you leave. This is plain English, it is not legal advice, and you should have your attorney review it before you rely on it.

01Parties and Roles

This Data Processing Addendum (the "DPA" or "Addendum") is entered into between Ansora, a company based in Miami, Florida, USA ("Ansora," "we," "us"), and the client business that has signed up for Ansora's AI receptionist service ("Client," "you"). It is incorporated into and forms part of the agreement between us for that service (the "Terms of Service" or "Agreement").

This DPA governs only the Caller Data that Ansora processes on your behalf when it operates the AI receptionist for your business. For that Caller Data, you are the controller (CCPA/CPRA: the "business") and Ansora is the processor (CCPA/CPRA: the "service provider"). In plain terms: they are your callers and your data, you decide why and how it is processed, and Ansora acts on your documented instructions to deliver the service you hired us for.

This DPA does not cover data for which Ansora is the controller in its own right — for example, marketing-site visitor and prospect data (name, business, phone, email, form messages, first-party analytics) or your own account and billing data. Those are governed by Ansora's Privacy Policy and Terms of Service, not by this Addendum.

If there is any conflict between this DPA and the Terms of Service on the subject of Caller Data processing, this DPA controls. See Section 15 (Liability and Order of Precedence).

  • Client = controller / "business" — owns the caller relationship and sets the purpose of processing.
  • Ansora = processor / "service provider" — processes Caller Data only to run the AI receptionist for you.
  • This DPA is limited to Caller Data; controller-level Ansora data is handled under the Privacy Policy.

02Definitions

Terms used but not defined here have the meaning given in the Terms of Service or in Applicable Data Protection Law. The definitions below are written to line up with both the CCPA/CPRA (California) "service provider / business" model and the GDPR-style "processor / controller" model, so this DPA works under either framing and under comparable US state privacy laws.

  • "Applicable Data Protection Law" means all privacy and data-protection laws that apply to the processing of Caller Data under this DPA, including the California Consumer Privacy Act as amended by the CPRA and comparable US state laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA), and, where relevant, GDPR-style principles applied by analogy.
  • "Controller" (CCPA/CPRA: "Business") means the party that determines the purposes and means of processing Personal Data. For Caller Data, this is the Client.
  • "Processor" (CCPA/CPRA: "Service Provider") means the party that processes Personal Data on behalf of and under the instructions of the Controller. For Caller Data, this is Ansora.
  • "Personal Data" (CCPA/CPRA: "Personal Information") means information relating to an identified or identifiable individual that is processed under this DPA.
  • "Caller Data" means the Personal Data of your callers that Ansora processes to operate the AI receptionist, as scoped in Section 3.
  • "Data Subject" (CCPA/CPRA: "Consumer") means the individual to whom Personal Data relates — here, your callers.
  • "Processing" means any operation performed on Personal Data (collecting, recording, storing, transcribing, summarizing, transmitting, deleting, and the like).
  • "Subprocessor" means a third party engaged by Ansora to process Caller Data on its behalf (see Section 6).
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Caller Data.
  • "Sell" and "Share" have the meanings given under the CCPA/CPRA.

03Scope and Subject Matter of Processing

This section is the required description of the processing Ansora carries out on your behalf. It sets the nature, purpose, duration, the categories of Data Subjects, and the categories of Caller Data.

Nature and purpose. Ansora processes Caller Data solely to provide, operate, maintain, tune, and support the AI receptionist and the closely related services you have contracted for — namely: answering inbound calls 24/7 in your business's voice; booking appointments onto your calendar; texting callers back and running speed-to-lead follow-up; sending review requests; generating call summaries; and the related back-office automation described in the Agreement. Processing also includes securing the service, troubleshooting, and complying with law.

Duration. Processing continues for as long as the Agreement is in effect, plus the limited wind-down window needed to export and delete data on termination as described in Section 12 and subject to the retention defaults in Section 11.

Categories of Data Subjects. The individuals who call, text, or are contacted by your AI receptionist — that is, your callers, prospects, and customers.

Categories of Caller Data. Inbound caller phone numbers; call audio and recordings; call transcripts; AI-generated call summaries; and appointment/booking details, including caller name, phone number, and the service requested. Ansora does not intend to process special-category or highly sensitive data through the AI receptionist by default; where a healthcare or similarly sensitive vertical is involved, Section 13 (HIPAA) and the retention controls in Section 11 apply.

  • Nature/purpose: operate and maintain your AI receptionist and the related follow-up, booking, and summary features.
  • Duration: the life of the Agreement plus the export-and-delete wind-down in Section 12.
  • Data subjects: your callers, prospects, and customers.
  • Data categories: caller phone numbers, call audio/recordings, transcripts, AI-generated summaries, appointment/booking details (name, phone, service requested).

04Processing Only on Documented Instructions

Ansora will process Caller Data only on your documented instructions, including with regard to any transfer of Caller Data, unless required to do otherwise by law that applies to Ansora — in which case Ansora will, where legally permitted, tell you about that requirement before processing.

Your documented instructions are made up of: (a) this DPA and the Agreement; (b) the configuration choices you make and approve during onboarding and in your account (for example, whether calls are recorded, the retention period, whether outbound texts are enabled); and (c) any further written instructions you give that are consistent with the service. Because Ansora builds, provisions, and maintains the system for you, day-to-day operation of the receptionist within these settings counts as acting on your instructions.

If Ansora believes an instruction violates Applicable Data Protection Law, it will inform you (unless prohibited by law). Ansora is not obligated to act on an instruction that would put it in breach of the law, and may pause the affected processing until the issue is resolved.

You are responsible for the lawfulness of the Caller Data you provide or generate through the service and for having an appropriate legal basis and any required notices/consents. In particular — and consistent with the Agreement — you are responsible for ensuring all legally required notices and consents are given, including call-recording consent and TCPA consent for any outbound texts or callbacks. Ansora provides the disclosure tooling (a configurable spoken recording-and-AI disclosure at the start of the call, per client and per state, default-on for two-party-consent states such as Florida) to make this turnkey, but the responsibility for consent remains yours as controller.

  • Ansora processes Caller Data only per your documented instructions (this DPA, the Agreement, your account/config settings, and written directions).
  • If Ansora thinks an instruction is unlawful, it will tell you and may pause that processing.
  • You, as controller, own the legal basis and the required consents (call recording, TCPA outbound); Ansora provides configurable disclosure tooling to make compliance turnkey.

05Confidentiality of Personnel

Ansora ensures that any personnel authorized to process Caller Data are bound by an appropriate duty of confidentiality (whether contractual or statutory) and are made aware of the sensitivity of the data.

Access to Caller Data — and to call recordings in particular — is limited to the staff who need it to build, operate, support, or improve the service for you, on a least-privilege basis. Ansora trains relevant personnel on their obligations under this DPA.

  • Personnel with access to Caller Data are under a binding confidentiality obligation.
  • Access to recordings is limited to staff who genuinely need it (least privilege).

06Subprocessors

You give Ansora general authorization to engage Subprocessors to help deliver the service. Each Subprocessor operates under its own terms and, where applicable, its own data processing agreement / DPA. Ansora imposes data-protection obligations on each Subprocessor that are substantially consistent with those in this DPA, and remains responsible to you for a Subprocessor's performance of those obligations.

Where a Subprocessor supports it, Ansora configures the provider's business/API offering so that Client content is not used to train the provider's models. Ansora cannot and does not give an absolute, standalone guarantee about a third party's internal practices; this is a commitment to use each provider's available no-training configuration where offered.

Current Subprocessors and their roles are listed below. Ansora may add or replace a Subprocessor and will give you advance notice of the change (for example, by email or in-account notice) with enough lead time for you to object. If you have a reasonable, good-faith data-protection objection to a new or replacement Subprocessor, tell Ansora within the notice window; the parties will work in good faith to resolve it, and if it cannot be resolved you may, as your remedy, terminate the affected part of the service.

  • Vapi — real-time AI voice agent orchestration.
  • Twilio — phone numbers, telephony, and SMS.
  • Deepgram — speech-to-text transcription.
  • OpenAI and/or other large-language-model providers — language understanding and AI-generated call summaries.
  • Stripe — payment processing (card data is handled by Stripe; Ansora does not store card numbers).
  • Supabase — database and authentication hosting.
  • Resend — transactional email.
  • Google Workspace — internal Ansora team email and productivity.
  • Change process: advance notice of any new or replacement Subprocessor, a right to raise a reasonable objection, and termination of the affected service as your remedy if an objection can't be resolved.

07Assistance to the Controller

Taking into account the nature of the processing and the information available to it, Ansora will provide reasonable assistance to help you meet your own obligations under Applicable Data Protection Law.

Data-subject / consumer requests. Your callers exercise their privacy rights through you as the controller. If Ansora receives a request directly from a Data Subject relating to Caller Data, it will not respond on its own (except to acknowledge and redirect where appropriate) and will promptly forward it to you. Ansora will provide reasonable technical and organizational assistance so you can respond to requests to access, correct, delete, or port Caller Data, and to opt-out requests, within the timelines the law requires.

DPIAs and consultations. Where Applicable Data Protection Law calls for a data protection impact assessment or a prior consultation with a regulator that involves the processing under this DPA, Ansora will provide reasonable assistance and the information you need that is within its control.

Breach. Ansora will assist you in meeting your own breach-notification and record-keeping obligations, as detailed in Section 8.

Ansora may charge a reasonable fee for assistance that goes beyond the standard support included in your plan, and will tell you before doing so.

  • Caller privacy requests run through you; Ansora forwards any it receives and helps you fulfill access/correction/deletion/portability/opt-out.
  • Ansora reasonably assists with DPIAs and regulator consultations tied to this processing.
  • Ansora assists with your breach obligations (see Section 8).

08Personal Data Breach Notification

Ansora will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Caller Data processed under this DPA.

The notification will describe, to the extent known and as information becomes available: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; and the measures Ansora has taken or proposes to take to address it and mitigate harm. Where Ansora cannot provide all details at once, it will provide them in phases as they become available.

Ansora will take reasonable steps to contain and remediate the breach and will cooperate with you. Because you are the controller, any decision about notifying regulators or affected individuals is yours to make; Ansora's notice to you is not, by itself, an admission of fault or liability.

  • Notice to you without undue delay and within 72 hours of Ansora becoming aware.
  • Notice includes nature, scope, likely consequences, and remediation — phased if needed.
  • You, as controller, decide on any regulator/individual notifications; Ansora cooperates.

09Security Measures

Ansora maintains technical and organizational measures designed to protect Caller Data against a Personal Data Breach, appropriate to the risk and the nature of the data. These measures are reviewed and may be updated over time, provided the overall level of protection is not reduced.

Ansora's current measures include the safeguards listed below. On certifications: Ansora is honest about where it stands — SOC 2 is in progress / on our roadmap, and Ansora does not claim to be SOC 2 certified. Any uptime or availability figures we mention are targets, not guarantees.

  • Encryption of Caller Data in transit (HTTPS/TLS) and at rest.
  • Role-based access controls and least-privilege access; recording access limited to staff who need it.
  • Confidentiality obligations and training for personnel with access.
  • HTTPS-only marketing site with a strict content-security policy and first-party, privacy-friendly analytics (no ad pixels or cross-site trackers).
  • SOC 2: in progress / on the roadmap — not yet certified. Uptime figures are targets, not guarantees.

10International Transfers

Ansora and its Subprocessors are primarily US-based, and Caller Data is generally processed in the United States. Ansora does not intend to transfer Caller Data outside the United States as a routine part of the service.

If a transfer of Caller Data to another country does occur — for example, because a Subprocessor processes or supports data outside the US — Ansora will ensure an appropriate transfer mechanism or safeguard recognized under Applicable Data Protection Law is in place for that transfer, and will act consistently with your instructions. Where Standard Contractual Clauses or an equivalent mechanism are required for a given transfer, they are incorporated by reference to the extent applicable.

  • Caller Data is processed primarily in the United States.
  • Any cross-border transfer uses an appropriate legal safeguard (e.g., SCCs) recognized under Applicable Data Protection Law.

11Audit and Information Rights; Retention Defaults

Ansora will make available to you the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable conditions to protect confidentiality, security, and the data of Ansora's other clients.

In practice, audits are satisfied first by Ansora providing relevant documentation and responses to reasonable questionnaires. On-site or hands-on audits, where genuinely necessary, require reasonable prior written notice (at least thirty (30) days absent a regulator deadline or active incident), happen no more than once per year unless a regulator or a Personal Data Breach requires otherwise, occur during business hours, must not unreasonably disrupt Ansora's operations, and are subject to confidentiality. Where a Subprocessor's own audit reports or certifications reasonably cover the point in question, Ansora may provide those instead.

Retention defaults (which you can adjust). These are sensible defaults; you set the actual retention for your account: call recordings default to roughly 90 days, configurable, with a zero-/short-retention option for sensitive verticals; transcripts, summaries, and appointment data are retained while your account is active; marketing/prospect data (controller-level, not Caller Data) is kept until the person asks for deletion. On termination, deletion follows Section 12.

  • Ansora provides documentation and responses to demonstrate compliance; hands-on audits allowed with reasonable notice, frequency, and confidentiality limits.
  • Subprocessor reports/certifications may satisfy an audit request where relevant.
  • Retention defaults you can change: recordings ~90 days (zero/short option for sensitive verticals); transcripts/summaries/appointments kept while the account is active.

12Return and Deletion on Termination

On termination or expiration of the Agreement, and at your choice, Ansora will make your Caller Data available for export and will then delete the Caller Data it holds within approximately thirty (30) days, unless retention is required by applicable law — in which case Ansora will keep only what the law requires, for only as long as required, and continue to protect it under this DPA.

Deletion extends to copies held by Ansora and, on a reasonable-efforts basis, to copies held by Subprocessors, except for routine backups that are overwritten on their normal cycle and are not readily accessible in the ordinary course. On request, Ansora will confirm in writing that deletion has been completed.

Phone-number handling on termination follows the process in the Agreement: you can port your number out or have an Ansora-provisioned number released per the defined process.

  • You can export your Caller Data on termination; Ansora deletes it within about 30 days unless law requires retention.
  • Deletion covers Ansora copies and, on reasonable efforts, Subprocessor copies (routine backups excepted until overwritten).
  • Number port-out / release follows the Agreement's defined process.

13CCPA/CPRA Service-Provider Terms; HIPAA

For Caller Data that is Personal Information under the CCPA/CPRA, Ansora acts as your Service Provider and Caller Data is disclosed to Ansora only for the limited and specified business purpose of providing the AI receptionist service described in the Agreement. Ansora certifies that it understands and will comply with the following restrictions.

HIPAA. For healthcare clients (dental, medical, med-spa, and similar), any protected health information (PHI) is handled under a separate Business Associate Agreement (BAA), not this DPA. Ansora offers PHI-redaction and short-/zero-retention options for those verticals. Where a BAA is in place and conflicts with this DPA regarding PHI, the BAA controls for PHI.

  • Ansora will not Sell or Share Caller Data.
  • Ansora will not retain, use, or disclose Caller Data for any purpose other than the business purpose(s) in the Agreement, or as otherwise permitted by the CCPA/CPRA.
  • Ansora will not retain, use, or disclose Caller Data outside the direct business relationship with you.
  • Ansora will not combine Caller Data with personal information from other sources, except as permitted by the CCPA/CPRA for a service provider.
  • Ansora will comply with applicable CCPA/CPRA obligations, provide the level of privacy protection the law requires, and notify you if it determines it can no longer meet these obligations.
  • You may take reasonable steps to stop and remediate unauthorized use of Caller Data; Ansora grants you the right to do so.
  • Healthcare PHI is governed by a separate BAA with PHI-redaction and short/zero-retention options.

14General; Governing Law

This DPA is governed by the laws of the State of Florida, USA, consistent with the Agreement, without regard to conflict-of-laws rules and except to the extent Applicable Data Protection Law requires otherwise for a given matter. Dispute resolution follows the Agreement: informal resolution first, then — as a drafted default to be confirmed with counsel — binding arbitration with a class-action waiver, venue in Florida.

If any provision of this DPA is held unenforceable, the rest remains in effect. This DPA takes effect on the effective date of the Agreement (or on the date it is signed, if later) and remains in force for as long as Ansora processes Caller Data on your behalf.

15Liability and Order of Precedence

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a party's liability means aggregate liability under the Agreement and this DPA together.

This DPA supplements the Agreement. If there is a conflict between this DPA and the Terms of Service specifically on the processing of Caller Data / the subject matter of this DPA, this DPA controls. For all other matters, the Terms of Service control. Where a separate BAA applies to PHI, the BAA controls for PHI as stated in Section 13.

  • Liability caps and exclusions from the Agreement apply to this DPA; liability is aggregate across both.
  • Order of precedence for Caller Data: BAA (for PHI) > this DPA > Terms of Service.

16Signature / Acceptance

This DPA may be accepted by signature below or by electronic acceptance as part of signing up for or continuing the Ansora service. By signing or accepting, each party agrees to be bound by it. Each signer represents they are authorized to bind their organization.

CLIENT (Controller / Business): Business name: ____________________ Signed by: ____________________ Title: ____________________ Date: ____________________

ANSORA (Processor / Service Provider): Ansora — Miami, FL, USA Signed by: ____________________ Title: ____________________ Date: ____________________ Contact: hello@ansora.net

Plain-English note: This document is written in plain English to be easy to understand. It is not legal advice, and it may not fit every situation or every law that applies to you. Please have a licensed attorney review it before you rely on it.

This document is written in plain English and isn't legal advice. Have it reviewed by an attorney before relying on it. Questions? Email hello@ansora.net.

Hear it liveBook a call