Skip to content
Back to home

Data Processing Addendum

Last updated: July 18, 2026

This Data Processing Addendum ("DPA") forms part of the ProFront Terms of Service (or a Master Service Agreement, where one is executed) between ProFront ("Processor," "we") and the customer ("Customer," "Controller"). It applies whenever we process Customer Personal Data in providing the Service.

1. Definitions

"Customer Personal Data" means personal information relating to Customer's end customers, callers, contacts, and personnel that we process on Customer's behalf in providing the Service. "Applicable Data Protection Law" means the privacy and data protection laws applicable to the processing, including the California Consumer Privacy Act as amended ("CCPA"). "Controller," "processor," "service provider," "sell," "share," "business purpose," and similar terms have the meanings in Applicable Data Protection Law.

2. Roles and Scope of Processing

  • Customer is the business/controller of Customer Personal Data; ProFront is Customer's service provider/processor.
  • Subject matter and nature: operating an AI-powered front office — handling inbound and outbound conversations (voice, SMS, chat) on Customer's behalf; creating and maintaining contacts, appointments, messages, and related records; recording calls where Customer enables it; automated quality/safety review of conversation records; bounded protective actions; sandboxed replay for validation; support and billing.
  • Duration: the term of the Agreement plus the deletion period in Section 9.
  • Categories of data subjects: Customer's customers, prospective customers, callers, and personnel. Categories of data: identifiers (name, phone, email), conversation content (transcripts, recordings where enabled, messages), appointment and service details, and metadata. Customer must not submit protected health information governed by HIPAA or other data categories the Agreement prohibits.

3. Processing Instructions

We process Customer Personal Data only: (a) on Customer's documented instructions, which consist of the Agreement, this DPA, and Customer's configuration of and requests in the Service; (b) as needed to provide, secure, and support the Service; and (c) as required by law, in which case we will notify Customer unless legally prohibited. We will inform Customer if, in our opinion, an instruction violates Applicable Data Protection Law.

4. CCPA Service-Provider Commitments

We will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than the business purposes in Section 2 or as permitted by the CCPA (including our permitted internal uses such as security, deduplication, and building de-identified/aggregated data); retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal information from other sources except as permitted for the business purposes. We certify that we understand and will comply with these restrictions, and we will notify Customer if we can no longer meet our obligations under Applicable Data Protection Law. Customer may take reasonable steps to stop and remediate unauthorized use.

5. Confidentiality

Persons we authorize to process Customer Personal Data are bound by confidentiality obligations. Access is restricted to what operating the Service requires.

6. Subprocessors

  • Customer generally authorizes our use of subprocessors to provide the Service. The current list is published at /legal/subprocessors and is incorporated here.
  • We will update the published list before adding or replacing a subprocessor that processes Customer Personal Data and provide notice of material changes per the Privacy Policy's notice mechanism. If Customer reasonably objects on data-protection grounds and we cannot offer an alternative, Customer may terminate the affected Service with a prorated refund of prepaid, unused fees for it.
  • We impose data-protection obligations on subprocessors materially no less protective than this DPA and remain responsible for their performance.

7. Security

We maintain administrative, technical, and organizational measures appropriate to the risk, including: encryption of data in transit; logical tenant isolation enforced with row-level security; least-privilege and service-role isolation for sensitive stores; redaction of certain sensitive values in conversation-activity records; access logging and audit trails; automated safety monitoring; backup and recovery procedures; and personnel access limited to operational need. We may improve these measures over time and will not materially reduce overall protection during a subscription term.

8. Security Incidents

We will notify Customer without undue delay, and in any case within 72 hours, after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, affected data categories, likely consequences, and measures taken or proposed. We will reasonably cooperate with Customer's obligations to notify regulators or individuals. Notification is not an admission of fault.

9. Deletion and Return

Upon account deletion or termination, we delete Customer Personal Data within 30 days per the Agreement, except records retained for legal, tax, and audit purposes, de-identified or aggregated data that no longer identifies a person or Customer, and backup copies that age out on the backup cycle and remain protected until deletion. Customer can self-serve a full export before deletion (Settings → Data & Privacy).

10. Assistance

Taking into account the nature of the processing, we will reasonably assist Customer: (a) in responding to data-subject requests (access, deletion, correction, opt-out) concerning Customer Personal Data — self-serve tooling in the dashboard satisfies this where available, and we will route misdirected requests we receive to Customer; (b) with security, breach-notification, and assessment obligations under Applicable Data Protection Law, with information reasonably available to us.

11. Audits and Information

On written request no more than once per 12 months, we will make available information reasonably necessary to demonstrate compliance with this DPA — security summaries, completed questionnaires, and third-party attestations when available. Audits are satisfied by these materials; on-site or technical audits require a separate written agreement, reasonable notice, and Customer bearing costs, and must not access other customers' data.

12. International Transfers

The Service is operated in the United States. This DPA does not currently include EU/UK transfer mechanisms; if we agree in writing to process personal data subject to GDPR or UK GDPR, the parties will execute the applicable standard contractual clauses, which will be incorporated by reference.

13. General

This DPA is effective as long as we process Customer Personal Data under the Agreement and supersedes prior data-processing terms. In conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA controls. Liability under this DPA is subject to the Agreement's limitations of liability. This DPA is governed by the same law and forum as the Agreement.

Data Processing Addendum | ProFront