Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of the service agreement between the business customer ("Controller") and Fraxbit Digital ("Processor") and governs the processing of personal data under the GDPR (Regulation (EU) 2016/679).
1. Subject matter and duration
The Processor operates AI voice agents that answer the Controller's inbound phone calls and records the resulting transcripts, booking requests, and caller details in a dashboard. The DPA applies for the duration of the service agreement.
2. Nature and purpose of processing
- Real-time transcription and automated conversation handling of inbound calls.
- Storage of transcripts, call metadata, appointments, and captured leads.
- Optional synchronisation of appointments with the Controller's calendar.
3. Categories of data and data subjects
- Data subjects: callers to the Controller's phone lines; the Controller's staff users.
- Data: phone numbers, names, appointment details, message content, call metadata. Voice recordings are disabled by default.
- No special categories of data are intentionally collected; callers may nonetheless volunteer such information in conversation.
4. Obligations of the Processor
- Process personal data only on the Controller's documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures: encryption in transit, encrypted credential storage, role-based access, EU-region hosting where available.
- Assist the Controller with data-subject requests and with obligations under Articles 32–36 GDPR.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return all personal data at the end of the service, at the Controller's choice.
- Make available information necessary to demonstrate compliance and allow audits with reasonable notice.
5. Sub-processors
The Controller grants general authorisation to engage sub-processors for telephony, speech processing, language models, and hosting. The current list is available on request; the Processor will give prior notice of changes, and the Controller may object on reasonable grounds. Where a sub-processor is located outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
6. Liability
Liability under this DPA follows the limitations agreed in the Terms of Service, except where the GDPR mandates otherwise.
To countersign this DPA or request the sub-processor list, email contact@fraxbit.com.
Questions? Email contact@fraxbit.com.