VeillantVeillantBack to home

Data Processing Agreement

Effective as of: July 9, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Servicebetween Veillant ("Veillant", "we", "us") and the customer using the Service ("Customer", "you"). It governs Veillant's processing of personal data on your behalf under Article 28 of the EU General Data Protection Regulation ("GDPR"). Where this DPA conflicts with the Terms on data protection, this DPA prevails. Capitalized terms not defined here have the meaning given in the Terms or the GDPR.

1. Roles of the parties

In respect of the personal data of the people who call the phone assistants you deploy ("Caller Data"), you are the controller and Veillant is the processor. Veillant processes Caller Data only to provide the Service and only on your documented instructions, which include the Terms, this DPA, and your configuration of the Service. For your own account data, Veillant is an independent controller as described in the Privacy Policy, and that processing is not governed by this DPA.

2. Subject matter, duration, nature & purpose

  • Subject matter: Veillant's processing of Caller Data to operate the AI phone assistants you configure.
  • Duration: for the term of the Terms, plus the limited retention described in the Privacy Policy.
  • Nature & purpose: receiving and answering calls in real time; and, where you enable analytics, deriving generic, aggregated, non-identifying analytics at the end of a call.

3. Types of data & categories of data subjects

  • Data subjects: the individuals who call your assistants.
  • Types of data: the content a caller chooses to speak during the call, processed transiently in memory to respond. Veillant does not store call audio, raw transcripts, or caller phone numbers. Where analytics is enabled, Veillant stores only decoupled, non-identifying aggregate counters.
  • Special categories: callers may volunteer special-category data (e.g. health information). You must ensure you have a valid Article 9 condition for such processing. The end-of-call analysis is instructed to bucket topics generically and never to output specific health or other sensitive detail.

4. Veillant's obligations (Art. 28(3))

  • Instructions. We process Caller Data only on your documented instructions, including for international transfers, unless required by law (in which case we will inform you unless the law prohibits it).
  • Confidentiality. Personnel authorized to process Caller Data are bound by confidentiality obligations.
  • Security. We implement appropriate technical and organizational measures under Article 32 (see Section 6).
  • Sub-processors. We engage sub-processors under Section 5.
  • Assistance with data-subject rights. Taking into account the nature of the processing, we assist you with appropriate measures to respond to requests to exercise data-subject rights. Because we hold no caller identifiers, most requests are handled by you directly as controller.
  • Assistance with Art. 32–36. We assist you, taking into account the information available to us, with security, breach notification, data protection impact assessments, and prior consultation.
  • Deletion or return. On termination, we delete or return Caller Data at your choice, except where storage is required by law. Given our design, little to no Caller Data persists; account data deletion is described in the Privacy Policy.
  • Audits & information. We make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, subject to reasonable confidentiality and security safeguards.

5. Sub-processors

You give Veillant general authorization to engage the sub-processors listed on our Subprocessors page to process Caller Data. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will update the Subprocessors page before adding or replacing a sub-processor; you may object on reasonable data-protection grounds by contacting us, and if we cannot resolve the objection you may stop using the affected feature.

6. Security measures (Art. 32)

Our measures include, and by design are strengthened by data minimization:

  • No sensitive data at rest by design: no call audio, no raw transcripts, and no caller phone numbers are stored.
  • Decoupling: analytics are stored as separate per-dimension counters, never as a per-call record that could re-identify a caller.
  • Tenant isolation: each account's data is scoped to that account and never shared across customers.
  • Encryption in transit and at rest, access controls, and audit logging on administrative actions.

7. International transfers

Some sub-processors process data outside the EEA. Where required, such transfers are covered by the EU Standard Contractual Clauses or another lawful transfer mechanism. See the Subprocessors page for locations.

8. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting Caller Data, and provide the information reasonably available to help you meet your notification obligations.

9. Liability & contact

Each party's liability under this DPA is subject to the limitations of liability in the Terms. For any data-protection question or to exercise a right under this DPA, contact us at thomas.romero@veillant.eu.

Legal

Terms of ServicePrivacy PolicyData Processing AgreementCookies PolicyAI PolicySubprocessors