Data Processing Addendum
For practices with data protection obligations beyond HIPAA, including state privacy laws.
Last updated 08/01/2026
This page is a structural draft for the product build, not reviewed legal text. Have counsel review it before you publish or rely on it.
1.Roles
You are the controller of personal information processed through the service. We are the processor, acting only on your documented instructions.
Our Terms of Service, your account configuration, and your use of the product together constitute your documented instructions.
2.Processing
We process personal information only to provide and secure the service, for the duration of your subscription plus the retention window you have configured.
Categories of data subject: your patients and callers, and your staff. Categories of data: contact details, appointment details, insurance carrier, call audio and transcripts.
3.Subprocessors
Our current subprocessors are published on our Trust page. We give 30 days notice before engaging a new one, and you may object during that period.
4.Security and audits
We maintain the technical and organizational measures described in our Trust page and this addendum.
On request, and no more than once per year, we make available information reasonably necessary to demonstrate compliance, including our most recent third-party assessment where one exists.
5.International transfers
All processing takes place in the United States. We do not transfer personal information outside the United States in the ordinary course of providing the service.