← Callora home
Legal · DPA

Data Processing Agreement

Effective: 2026-07-07 · Governed under Callora, operated by Metis Gold.

This DPA supplements the Terms of Service between Customer (“Controller”) and Metis Gold operating Callora (“Processor”, “we”). It applies whenever we process personal data on your behalf. By using the service on Pro or Business tier, you accept this DPA. Enterprise customers may request a countersigned copy: legal@call.metis.gold.

1. Roles

Customer determines the purposes and means of processing personal data (“Controller” under GDPR Art 4). Callora processes personal data on Customer’s documented instructions (“Processor”).

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of AI voice-agent services.
  • Duration: the term of the Terms of Service plus retention windows in our Privacy Policy.
  • Nature and purpose: hosting, transmitting, transcribing, analyzing, and storing voice/telephony data to deliver the service.

3. Types of personal data and categories of data subjects

  • Data subjects: end callers, Customer’s employees using the dashboard.
  • Data types: names, phone numbers, email addresses, voice recordings (biometric), transcripts, appointment details, IP addresses, account credentials.

4. Processor obligations

Callora will:

  • Process personal data only on documented instructions from Customer (the Terms + this DPA + Customer configuration in the dashboard).
  • Ensure personnel with access to personal data are bound by confidentiality.
  • Implement the technical and organizational security measures listed in Annex II.
  • Assist Customer with data subject requests (Art 15–22), DPIAs (Art 35), and consultation with supervisory authorities.
  • Notify Customer without undue delay (target: within 24 hours) after becoming aware of a personal-data breach.
  • Return or delete personal data at end of provision (per Privacy Policy retention), except where retention is required by law.
  • Make available all information necessary to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality obligations.

5. Subprocessors

Customer authorizes Callora to engage the subprocessors listed at /trust and in Annex III below. Callora will notify Customer at least 30 days before adding or replacing a subprocessor; Customer may object on reasonable grounds and, if objection cannot be resolved, terminate the affected service.

6. International transfers

Where personal data is transferred outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (Module 2 Controller-to-Processor, Decision 2021/914) and, where applicable, the UK IDTA / UK Addendum. These are incorporated by reference and executed by acceptance of this DPA.

7. Data subject rights

Callora will provide tools within the dashboard (Access, Rectify, Delete, Export) that Customer can use to fulfill DSAR obligations directly. Where Customer needs assistance, we will support within 30 days for no additional fee up to Business-tier volumes.

8. Liability

Liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA excludes liability that cannot be excluded under applicable data-protection law (including GDPR Art 82).

Annex I — Data processing details

  • Categories of data subjects: callers contacted by Customer’s agents; recipients of Customer’s outbound calls; Customer’s employees using the dashboard.
  • Categories of personal data: as listed in Section 3.
  • Sensitive categories: voiceprints (biometric); potentially health data if Customer configures a healthcare use case (see BAA on Business tier).
  • Frequency of transfer: continuous.
  • Retention: per Privacy Policy Section 4.

Annex II — Technical and organizational measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256-GCM for sensitive fields, WiredTiger/KMS for volumes).
  • Access control: least privilege, MFA for admins, tenant-scoping enforced via repository layer.
  • Immutable, cryptographically hash-chained audit log.
  • Web application firewall, rate limiting, CSRF protection, DDoS mitigation.
  • Regular vulnerability scanning; annual third-party penetration test.
  • Backups tested quarterly (PITR + off-region snapshot).
  • Documented incident response plan, 72-hour breach notification workflow.

Annex III — Approved subprocessors

Current list at /trust. As of the effective date: OpenAI, Twilio, Stripe, Google, Cloudflare, MongoDB Atlas, Emergent, Resend (transactional email), Sentry (error tracing, PHI-scrubbed).