Legal

Data Processing Agreement (DPA)

The Art. 28 GDPR terms that apply when Call0 processes caller and communication data for a business customer.

Last updated: July 31, 2026

§1 Parties, Scope and Duration

Processor: Call0 Inc. 447 Broadway, 2nd Floor Suite #3389 New York, NY 10013, United States

Controller: the business customer using the Call0 platform. This DPA governs processing by Call0 on documented instructions from the Controller under Art. 28 GDPR.

The DPA applies for the duration of the customer’s use of Call0 and ends when the customer account is deleted, without affecting legal retention duties.

§2 Nature and Purpose of Processing

Call0 may process the following data on the Controller’s behalf:

  • Caller phone numbers, call time and duration.
  • AI-generated transcripts and call recordings when the Controller enables recording.
  • Caller names, email addresses, appointment details and other information supplied during a conversation.
  • Bookings and orders created during calls.
  • AI-based sentiment data.
  • WhatsApp and email messages processed through configured channels.

Processing provides AI call handling, transcription, booking management, customer-support automation and analytics.

§3 Data Subjects

  • Callers and customers of the Controller.
  • WhatsApp and email contacts of the Controller.
  • Controller employees mentioned in calls or messages.

§4 Subprocessors and Transfers

The Controller authorizes the following subprocessors:

ProviderPurposeLocation / safeguard
Supabase Inc.Database and authenticationUSA; third-country transfer only under an actually applicable transfer mechanism
Stripe Inc.Payment processingUSA; third-country transfer only under an actually applicable transfer mechanism
Twilio Inc.Telephony and SMS deliveryUSA; third-country transfer only under an actually applicable transfer mechanism
OpenAI Inc.Realtime transcription, text generation, tool calls and AI language model (GPT)USA; third-country transfer only under an actually applicable transfer mechanism
Hanabi AI Inc. (Fish Audio)Text-to-speech through the paid s2.1-pro production model; processing and any retention are governed by the applicable Fish contracts and privacy termsUSA; third-country transfer only under an actually applicable transfer mechanism
Composio Inc.Integration connectivity (email, calendars, CRM and other connected tools)USA; third-country transfer only under an actually applicable transfer mechanism
Google LLCOAuth, Calendar, Gmail, Places, Sheets, Drive, Docs, Tasks and MeetUSA; third-country transfer only under an actually applicable transfer mechanism
Vercel Inc.Hosting and CDNUSA; third-country transfer only under an actually applicable transfer mechanism
Railway CorporationVoice and communications infrastructure hostingUSA; third-country transfer only under an actually applicable transfer mechanism

Call0 uses only the paid Fish Audio s2.1-pro production model for processing. Processing and any retention are governed by the Fish contracts and privacy terms that actually apply. Zero Data Retention applies only if it has been separately contracted and enabled for the account; documented Controller instructions also remain controlling.

SCCs means the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR where they are actually executed and applicable to the specific subprocessor. Call0 communicates material changes to subprocessors in accordance with the agreement and applicable law.

§5 Technical and Organizational Measures

Call0 maintains risk-appropriate measures under Art. 32 GDPR, including:

  • Access controls, authorization policies and least-privilege practices.
  • Encryption protections provided by the hosting and service infrastructure.
  • Pseudonymization of caller numbers in customer profiles where configured.
  • Backup, monitoring, availability and incident-response controls appropriate to the service.
  • Periodic review of infrastructure and access controls.

§6 Data-Subject Rights

Call0 assists the Controller with requests under Arts. 12–22 GDPR, including:

  • Access through account data-export functions (Art. 15).
  • Erasure through the account-deletion process, subject to legal retention duties (Art. 17).
  • Machine-readable JSON portability (Art. 20).
  • Deletion of individual customer profiles and call logs through the dashboard.

Requests may be submitted through account settings or the contact page.

§7 Processor Obligations

  • Process personal data only on documented Controller instructions.
  • Bind employees and other authorized personnel to confidentiality.
  • Notify the Controller of a relevant personal-data breach without undue delay as required by Art. 33 GDPR.
  • Delete data at the end of processing, subject to legal retention duties.
  • Assist with data-protection impact assessments (Art. 35 GDPR).
  • Provide information needed to demonstrate compliance (Art. 28(3)(h) GDPR).

§8 AI and Recording Notice

Calls begin with clear identification of the AI interaction. The specific purpose is communicated through the configured greeting or pre-call information. A separate recording notice applies only when recording is enabled, and the Controller obtains any consent required by applicable law before recording starts. Continuing a call is not automatically GDPR consent; the legal basis must be determined for the specific use.

The Controller remains responsible for ensuring that AI, privacy and recording notices and the chosen recording configuration comply with laws applicable to its use case and jurisdiction.

The Controller must not bypass AI identification and remains responsible for a valid legal basis, required notices and consents, appropriate retention and effective human oversight. Call0 and the Controller each take, according to their role as provider or deployer and with regard to technical knowledge, experience, education and training, the context of use and the affected persons, appropriate measures to support the development of AI literacy. Art. 4 EU AI Act does not require a guarantee of any specific level for an individual. Uses that qualify as high-risk under Art. 6 together with Annex I or III EU AI Act may, depending on their intended purpose, include certain recruiting, credit, healthcare, education or public-authority uses and require a separate assessment and appropriate safeguards before use.

§9 Contact and Acceptance

Questions about commissioned processing can be sent to:

Call0 Inc. 447 Broadway, 2nd Floor Suite #3389 New York, NY 10013, United States

Contact Call0 online.

This DPA is accepted by using the Call0 platform. A separately signed copy can be provided on request.
    Data Processing Agreement (DPA) | Call0