1. 1. Introduction and Scope
1.1 This Data Processing Addendum ("DPA") is entered into between Haven Technologies, Inc. ("Ansabell," "we," "us," or "our"), a Washington State company, and the customer that subscribes to the Ansabell service ("Customer," "you," or "your"). It is incorporated into and forms a part of the agreement between the parties for the provision of the Ansabell service, comprising the Ansabell Terms of Service and any applicable order or subscription (together, the "Agreement").
1.2 The "Ansabell service" is an AI voice receptionist platform that answers inbound business phone calls with a natural AI voice, and that records and transcribes calls, sends and receives SMS text messages, books appointments, integrates with calendars and CRMs, and can take payments, in each case on the Customer's behalf and at the Customer's direction.
1.3 This DPA applies to our processing of Personal Data that we process on the Customer's behalf in the course of providing the Ansabell service, and only to the extent that such processing is subject to Data Protection Laws. It sets out the parties' obligations with respect to that processing.
1.4 In the event of any conflict between this DPA and the remainder of the Agreement with respect to the processing of Personal Data, this DPA controls, except as set out in Section 16 (Order of Precedence, Liability, and General).
1.5 By accepting the Agreement, or by using the Ansabell service, the Customer accepts this DPA on its own behalf and, to the extent required, on behalf of its authorized affiliates and users. Where the Customer requires a signed counterpart, one is available on request to legal@ansabell.com.
2. 2. Definitions
2.1 Capitalized terms used but not defined in this DPA have the meaning given to them in the Agreement. For the purposes of this DPA:
- "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, as applicable: the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); the UK GDPR and the UK Data Protection Act 2018 ("UK GDPR"); the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations ("CCPA"); the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, and Montana Consumer Data Privacy Act; the Washington My Health My Data Act, RCW 19.373 ("MHMDA"); the Washington Consumer Protection Act, RCW 19.86; Washington call-recording law, RCW 9.73; Washington biometric-identifier law, RCW 19.375; the Telephone Consumer Protection Act, 47 U.S.C. 227 ("TCPA"); and the Children's Online Privacy Protection Act, 15 U.S.C. 6501 et seq. ("COPPA"), in each case to the extent applicable.
- "Personal Data" means any information relating to an identified or identifiable natural person (including, under the CCPA, a "consumer") that we process on the Customer's behalf in providing the Ansabell service. This includes "personal data" under GDPR/UK GDPR and "personal information" under the CCPA and other US state privacy laws.
- "Consumer Health Data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status, as defined under the MHMDA, RCW 19.373, and comparable "consumer health data" concepts under other state laws.
- "Controller" means the entity that determines the purposes and means of the processing of Personal Data. Under the CCPA, the analogous term is "Business"; under the MHMDA and other US state laws, the analogous term is "controller."
- "Processor" means the entity that processes Personal Data on behalf of the Controller. Under the CCPA, the analogous term is "Service Provider"; under the MHMDA and other US state laws, the analogous term is "processor."
- "Service Provider" has the meaning given in the CCPA and, for the purposes of this DPA, refers to Ansabell in its role processing End-Caller Personal Data on the Customer's behalf.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including an "End Caller" (a person who telephones the Customer's Ansabell-powered line) and, where applicable, the Customer's own personnel and end users.
- "End Caller" means a person who places or receives a call or message on a phone line answered or handled by the Ansabell service on the Customer's behalf.
- "Subprocessor" means any third party engaged by Ansabell to process Personal Data on the Customer's behalf in connection with the Ansabell service.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Ansabell or a Subprocessor.
- "Sell," "Share," "Sale," "Sharing," "Business Purpose," "Commercial Purpose," and "Cross-Context Behavioral Advertising" have the meanings given to them in the CCPA.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission Implementing Decision (EU) 2021/914, and, for UK transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner ("UK IDTA").
3. 3. Roles of the Parties
3.1 End-Caller and other Customer data. With respect to Personal Data of End Callers and other individuals that Ansabell processes in providing the Ansabell service (including call recordings, transcripts, caller phone numbers, caller names and details, appointment and booking details, SMS content, and related call metadata), the Customer is the Controller / Business and Ansabell is the Processor / Service Provider. The Customer determines the purposes and means of that processing and is responsible for its lawfulness, including obtaining any consents and providing any notices required under Data Protection Laws.
3.2 Account and billing data. With respect to the Customer's own account, contact, authentication, and billing data (including business name, account email, business phone, hashed password, and plan and billing information), Ansabell acts as an independent Controller and processes that data in accordance with the Ansabell Privacy Policy. This DPA does not govern that Controller processing except where expressly stated.
3.3 Customer responsibilities. The Customer represents and warrants that it has all necessary rights, consents, notices, and lawful bases to authorize the processing described in this DPA, including any consent required to record and transcribe calls under applicable all-party-consent laws (see Section 4.5), any TCPA consent required to place calls or send SMS messages to End Callers (see Section 4.8), and any consent or, for a sale, valid written authorization required to collect, use, or disclose Consumer Health Data (see Section 7). Ansabell processes Personal Data only as a Processor / Service Provider acting on the Customer's documented instructions and is not responsible for determining whether the Customer has obtained the consents, authorizations, or notices that the Customer is responsible for.
4. 4. Scope, Nature, and Purpose of Processing
4.1 Subject matter. The subject matter of the processing is the provision of the Ansabell AI voice receptionist service to the Customer, as described in the Agreement and further detailed in Annex 1 (Details of Processing).
4.2 Duration. Ansabell will process Personal Data for the term of the Agreement and thereafter only as set out in Section 12 (Return and Deletion) or as required by applicable law.
4.3 Nature and purpose. The nature and purpose of the processing is to answer, record, and transcribe inbound calls; generate AI voice responses; send and receive SMS messages; book and manage appointments; integrate with the Customer's calendar and CRM where connected; process payments through Stripe; and provide related account, analytics, and support functions, in each case on the Customer's behalf. The categories of Personal Data and Data Subjects are set out in Annex 1.
4.4 Documented instructions. Ansabell will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Ansabell will, where legally permitted, inform the Customer of that legal requirement before processing). The Agreement, this DPA, the Customer's configuration of the Ansabell service (including recording, disclosure, messaging, and jurisdiction settings), and the Customer's use of the service constitute the Customer's complete and final documented instructions. Ansabell will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws, although Ansabell has no obligation to monitor the Customer's compliance.
4.5 Call recording and disclosure. Washington law (RCW 9.73.030) requires the consent of all parties to record a private communication, and other states (including California, Florida, and Pennsylvania) are likewise all-party-consent jurisdictions; calls may cross state lines. Ansabell provides configurable automated recording disclosures and jurisdiction-aware settings so that the Customer can announce recording at the start of a call as the statutory consent mechanism. The Customer is solely responsible for enabling and configuring lawful recording disclosures and for the lawfulness of recording each call. Ansabell records and transcribes calls only as instructed through the Customer's configuration.
4.6 No biometric processing. Ansabell does not enroll, create, capture, or use voiceprints or any other biometric identifier for the purpose of identifying any individual, and does not process Personal Data as a biometric identifier under RCW 19.375 or comparable laws. Call audio is transcribed to text to provide the service; it is not used as a biometric identifier.
4.7 No training of third-party foundation models. Ansabell does not use End-Caller call content, recordings, or transcripts to train third-party foundation models, and its large language model subprocessors process such content transiently under API terms that, by default, do not use API-submitted data to train their foundation models.
4.8 Messaging and opt-out (STOP) handling. Ansabell sends and receives SMS messages only at the Customer's direction and configuration. The Customer is responsible for obtaining any prior express written consent required under the TCPA and FCC rules before messages are sent to End Callers, and Ansabell sends no marketing messages except as directed by the Customer with the required consent. Ansabell provides and honors opt-out (STOP) handling: it recognizes standard opt-out keywords (such as STOP, END, UNSUBSCRIBE, QUIT, and CANCEL), processes the resulting opt-out, and suppresses further non-exempt messaging to that number, and it processes all messaging subject to opt-outs received. The Customer remains responsible for honoring opt-outs across its own systems and for its messaging content and cadence.
4.9 Children (COPPA). The Ansabell service is not directed to children and is intended for use in handling business communications with adults. The Customer must not use the service to knowingly collect, or direct Ansabell to process, Personal Data from children under 13, or, where applicable, minors under 16. Ansabell does not knowingly collect Personal Data from children under 13 (or minors under 16); if Ansabell becomes aware that it has processed such data other than at the Customer's lawful direction, it will take reasonable steps to delete it or notify the Customer.
5. 5. Ansabell's Obligations as Processor
5.1 Processing on instructions. Ansabell will process Personal Data only as necessary to provide the Ansabell service and as set out in Section 4.4, and will not process Personal Data for any other purpose.
5.2 Confidentiality. Ansabell will ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are trained on their data-protection responsibilities, and will limit access to Personal Data to those personnel who need it to provide the service.
5.3 Security. Ansabell will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as further described in Annex 2 (Technical and Organizational Security Measures).
5.4 Assistance. Taking into account the nature of the processing and the information available to it, Ansabell will provide reasonable assistance to the Customer as set out in Sections 8 (Data-Subject Requests), 9 (DPIAs and Consultation), and 10 (Breach Notification).
5.5 Compliance and cooperation. Ansabell will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will cooperate with the Customer and, where applicable, supervisory authorities, as set out in Section 13 (Audits).
6. 6. CCPA Service-Provider Provisions
6.1 Service-provider status. The parties acknowledge that, with respect to End-Caller Personal Data, the Customer is a Business and Ansabell is a Service Provider under the CCPA. Ansabell processes Personal Data on the Customer's behalf for the Business Purposes of providing the Ansabell service as described in the Agreement and Annex 1.
6.2 No sale or sharing. Ansabell will not sell or share Personal Data within the meaning of the CCPA, and will not use Personal Data for Cross-Context Behavioral Advertising. Ansabell receives no monetary or other valuable consideration for Personal Data other than the fees paid by the Customer for the service.
6.3 Business-purpose limitation. Ansabell will not retain, use, or disclose Personal Data for any purpose other than the specific Business Purposes of performing the service specified in the Agreement, including for any Commercial Purpose other than providing the service, except as permitted by the CCPA. Ansabell will not retain, use, or disclose Personal Data outside the direct business relationship between the parties, and will not combine Personal Data received from or on behalf of the Customer with personal information received from or on behalf of any other person, or collected from Ansabell's own interactions with a consumer, except as permitted by the CCPA to perform a Business Purpose.
6.4 Compliance and notice. Ansabell will comply with its obligations as a Service Provider under the CCPA and provide Personal Data the same level of privacy protection required of a Business. Ansabell will notify the Customer if it determines that it can no longer meet its obligations under the CCPA, and the Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
6.5 Right to monitor. The Customer has the right to take reasonable and appropriate steps to help ensure that Ansabell uses Personal Data in a manner consistent with the Customer's obligations under the CCPA, as further described in Section 13 (Audits).
6.6 Other US state laws. Where the Virginia VCDPA, Colorado CPA, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, or Montana Consumer Data Privacy Act applies, Ansabell acts as a "processor" (or equivalent) and will process Personal Data pursuant to the Customer's instructions, assist the Customer with data-subject requests and security obligations, engage subprocessors under written contract with equivalent obligations, and support the Customer's compliance obligations, consistent with the corresponding provisions of this DPA.
7. 7. Consumer Health Data (MHMDA)
7.1 Context and role. Healthcare and health-adjacent businesses (including dental, medical, med spa, veterinary, and chiropractic practices) use the Ansabell service, and calls handled on the Customer's behalf may reveal Consumer Health Data. Where Ansabell processes Consumer Health Data on the Customer's behalf, it does so as a Processor under the MHMDA, at the Customer's direction and only pursuant to this DPA, which constitutes the binding written contract required by RCW 19.373.060.
7.2 Processor duties under RCW 19.373.060. As a Processor of Consumer Health Data, Ansabell will: (a) process Consumer Health Data only pursuant to the Customer's documented instructions and the binding contract formed by this DPA; (b) assist the Customer, taking into account the nature of the processing, in fulfilling the Customer's obligations to respond to consumer requests to access, withdraw consent for, and delete Consumer Health Data; (c) at the Customer's direction, and upon a consumer's valid request that the Customer forwards, delete or de-identify Consumer Health Data unless retention is required by law; (d) assist the Customer in meeting its MHMDA security and notice obligations; and (e) impose the same or materially similar obligations on any Subprocessor that processes Consumer Health Data. Ansabell does not obtain consent from, or make consent or authorization determinations for, the Customer; the Customer is responsible for providing any clear and conspicuous MHMDA notice, for obtaining any MHMDA consent required before collecting or sharing Consumer Health Data, and, for any sale of Consumer Health Data, for obtaining a valid written authorization that is separate from and additional to MHMDA consent.
7.3 No sale of Consumer Health Data. Ansabell does not sell, and will not sell, Consumer Health Data, and receives no consideration for it other than the Customer's service fees. Consistent with RCW 19.373, no sale of Consumer Health Data may occur without the valid written authorization required by that statute, which the Customer alone is responsible for obtaining; Ansabell will not effect any such sale. Ansabell will not process Consumer Health Data except as necessary to provide the service on the Customer's instructions, and will support the Customer in responding to consumer requests to access, withdraw consent for, or delete Consumer Health Data as set out in Section 8.
7.4 HIPAA interaction. Where the Customer is a HIPAA Covered Entity or Business Associate, the HIPAA provisions in Section 15 apply. As set out in Section 15, the Ansabell service is not currently offered for the processing of protected health information, and PHI must not be submitted to the service.
8. 8. Data-Subject Requests
8.1 Assistance. Taking into account the nature of the processing, Ansabell will provide reasonable assistance through appropriate technical and organizational measures, insofar as possible, to help the Customer respond to requests from Data Subjects to exercise their rights under Data Protection Laws, including rights of access, correction, deletion, restriction, portability, and objection, and rights to know, opt out, and withdraw consent.
8.2 Forwarding requests. If Ansabell receives a request from a Data Subject in relation to Personal Data processed on the Customer's behalf, Ansabell will, to the extent legally permitted, promptly inform the Customer and will not respond to the request itself except on the Customer's documented instructions or as required by applicable law. Ansabell will direct the Data Subject to the Customer where appropriate, because the Customer is the Controller / Business responsible for the response.
8.3 Tools. The Ansabell service provides functionality that enables the Customer to access, export, correct, and delete Personal Data within the service in order to fulfill Data-Subject requests. Where the Customer cannot fulfill a request through that functionality, Ansabell will provide additional reasonable assistance on request.
9. 9. Data Protection Impact Assessments and Prior Consultation
9.1 Taking into account the nature of the processing and the information available to it, Ansabell will provide the Customer with reasonable assistance in carrying out data protection impact assessments and in any prior consultation with a supervisory authority that the Customer is required to conduct under Data Protection Laws, in each case where such assessment or consultation relates to Ansabell's processing of Personal Data under this DPA.
10. 10. Personal Data Breach Notification
10.1 Notification. Ansabell will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer's behalf, and in any event no later than forty-eight (48) hours after Ansabell becomes aware of the breach. This timeframe is intended to give the Customer sufficient opportunity to meet its own deadlines, including the GDPR 72-hour notification requirement and any applicable US state-law timelines. Notification may be provided in phases as information becomes available.
10.2 Content. The notification will describe, to the extent then known and as it becomes available, the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects, together with a contact point for further information.
10.3 Cooperation. Ansabell will take reasonable steps to mitigate and remediate the Personal Data Breach and will reasonably cooperate with the Customer so that the Customer can meet its own notification obligations to supervisory authorities and affected individuals. The Customer is responsible for determining whether it is required to notify supervisory authorities or Data Subjects and for making any such notifications; Ansabell's notification to the Customer is not an acknowledgment of fault or liability.
11. 11. Subprocessors
11.1 General authorization. The Customer provides general written authorization for Ansabell to engage Subprocessors to process Personal Data in connection with the Ansabell service. The current Subprocessors and their processing purposes are listed in the table in Section 11.4 and in Annex 3, which form part of that authorization.
11.2 Flow-down obligations. Ansabell will impose on each Subprocessor, by written contract, data-protection obligations that are substantially the same as and no less protective than those set out in this DPA, to the extent applicable to the nature of the Subprocessor's services. Ansabell remains responsible to the Customer for the performance of each Subprocessor's obligations. Where a Subprocessor processes Personal Data outside the United States, Ansabell will ensure that an appropriate transfer mechanism (including, where required, the Standard Contractual Clauses or an equivalent onward-transfer safeguard) is in place, as further set out in Section 14.
11.3 Notice of changes and right to object. Ansabell will maintain an up-to-date list of Subprocessors and will provide the Customer with notice of the addition or replacement of a Subprocessor (for example, by updating Annex 3 or the Subprocessor page on our website and, where the Customer has subscribed, by email) with a reasonable opportunity, of at least thirty (30) days, to object before the new Subprocessor begins processing Personal Data. If the Customer reasonably objects on legitimate data-protection grounds, the parties will work in good faith to resolve the objection; if they cannot, the Customer may, as its sole remedy, terminate the affected portion of the service by written notice.
11.4 Current Subprocessors. The following Subprocessors are authorized as of the effective date of this DPA. "Location" indicates the primary region in which the Subprocessor processes Personal Data; certain Subprocessors may process or route data through other regions, and any such non-US processing is covered by the transfer safeguards in Section 14.
| Subprocessor | Processing Purpose | Location |
|---|---|---|
| Telnyx | Telephony connectivity and SMS message delivery (primary) | United States (may route through other regions) |
| Twilio | Telephony and SMS message delivery (secondary / fallback) | United States (may route through other regions) |
| Deepgram | Speech-to-text transcription of call audio | United States (may process in other regions) |
| Cartesia | Text-to-speech voice generation | United States |
| ElevenLabs | Text-to-speech voice generation | United States / EU (may process in other regions) |
| OpenAI | Large language model reasoning over call text (processed transiently; not used to train foundation models by default) | United States (may process in other regions) |
| Anthropic | Large language model reasoning over call text (processed transiently; not used to train foundation models by default) | United States |
| Stripe | Payment processing (stores tokens and card last-four only) | United States (global payment infrastructure) |
| Amazon Web Services (AWS) | Cloud hosting and encrypted storage (Amazon S3), US region | United States |
| Calendar integration (only where the Customer connects Google Calendar) | United States (global infrastructure) |
12. 12. Return and Deletion of Personal Data
12.1 Election on termination. On termination or expiry of the Agreement, and at the Customer's choice, Ansabell will delete or return to the Customer the Personal Data it processes on the Customer's behalf, and delete existing copies, unless applicable law requires continued storage. The Customer may make its election within thirty (30) days after termination or expiry. Where the Customer does not make an election within that period, Ansabell will delete the Personal Data in accordance with Section 12.2.
12.2 Deletion window. Ansabell will delete Personal Data processed on the Customer's behalf from its active production systems no later than ninety (90) days after termination or expiry of the Agreement (or, where the Customer elects deletion during the term, no later than ninety (90) days after the request). Personal Data residing in encrypted, rotating backups is purged in the ordinary course of Ansabell's backup rotation and in any event no later than one hundred eighty (180) days after it is removed from production. Deletion may be effected by rendering the Personal Data inaccessible and scheduling it for destruction in accordance with these cycles and those of Ansabell's Subprocessors.
12.3 Retention during the term. During the term, and absent other written instruction, Ansabell retains call recordings, transcripts, and related call data for the retention period configured by the Customer or, where the Customer has not configured a period, for a default active-retention period of twenty-four (24) months, after which such data is deleted or de-identified in the ordinary course. The Customer may configure a shorter retention period through the service and may export its call recordings, transcripts, and related data through the service's export functionality during the term and during any wind-down period.
12.4 Legally required retention. Ansabell may retain Personal Data to the extent required by applicable law, and will continue to protect any retained Personal Data in accordance with this DPA and limit its processing to the purpose that requires retention.
13. 13. Audits and Compliance
13.1 Information. Ansabell will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and its obligations as a Processor / Service Provider, which may be satisfied through up-to-date documentation, security summaries, and, where available, third-party audit reports or certifications (such as a SOC 2 report).
13.2 Audits. Ansabell will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, in relation to the processing of Personal Data under this DPA, consistent with GDPR Article 28(3)(h) and Clause 8.9 of the Standard Contractual Clauses where they apply. Audits must be conducted on reasonable prior written notice (not less than thirty (30) days except where a supervisory authority or a Personal Data Breach requires shorter notice), no more than once in any twelve (12) month period except as required by a supervisory authority or following a Personal Data Breach, during normal business hours, subject to reasonable confidentiality obligations, and in a manner that does not disrupt Ansabell's operations or compromise the confidentiality or security of other customers' data. Ansabell may first seek to satisfy an audit request by providing the documentation and reports described in Section 13.1, and the parties agree that such documentation will ordinarily be sufficient where it reasonably demonstrates compliance.
14. 14. International Data Transfers
14.1 US hosting. Personal Data processed through the Ansabell service is hosted and stored in the United States. Where the Customer or a Data Subject is located in the European Economic Area, the United Kingdom, or Switzerland, Personal Data may be transferred to and processed in the United States, and may be processed by certain Subprocessors in other regions as indicated in Section 11.4.
14.2 Transfer mechanism. To the extent that a transfer of Personal Data subject to GDPR or UK GDPR from the EEA, the UK, or Switzerland to Ansabell in the United States, or from Ansabell to a Subprocessor located outside the EEA, the UK, or Switzerland, requires an appropriate safeguard under Chapter V of the GDPR, the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer. For those transfers, Ansabell acts as the data importer and the Customer (and, where applicable, the relevant Controller) acts as the data exporter, and Module Two (Controller to Processor) or Module Three (Processor to Processor) applies as appropriate to the transfer. For onward transfers from Ansabell to a Subprocessor, Ansabell will ensure the Subprocessor is bound by the Standard Contractual Clauses or an equivalent lawful onward-transfer safeguard.
14.3 SCC operative elements. For the purposes of the Standard Contractual Clauses: the docking clause (Clause 7) applies; in Clause 9, Option 2 (general written authorization) applies with the notice period set out in Section 11.3; in Clause 11, the optional independent dispute-resolution language does not apply; in Clause 17, the clauses are governed by the law of Ireland (or, for UK transfers under the UK IDTA, the laws of England and Wales); and in Clause 18, disputes are resolved before the courts of Ireland (or, for the UK IDTA, England and Wales). Annex 1 and Annex 2 of this DPA populate the corresponding annexes to the Standard Contractual Clauses, and the competent supervisory authority is determined in accordance with Clause 13.
14.4 UK and Swiss transfers. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum is incorporated and applies to the Standard Contractual Clauses. For transfers subject to Swiss law, references in the Standard Contractual Clauses are interpreted to give effect to the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner as the competent authority.
14.5 Government access and challenge (supplementary measures). Consistent with Clause 15 of the Standard Contractual Clauses, if Ansabell receives a legally binding request from a public authority (including a law-enforcement or national-security authority) for disclosure of Personal Data transferred under this DPA, Ansabell will, unless legally prohibited: (a) promptly notify the Customer and, where possible, the affected Data Subjects; (b) review the legality of the request; (c) challenge the request where it is unlawful or overbroad, and seek to narrow or suspend disclosure where lawful grounds exist; (d) disclose only the minimum amount of Personal Data reasonably necessary to comply; and (e) document the request and its response. Where legally prohibited from notifying the Customer, Ansabell will use reasonable efforts to obtain a waiver of the prohibition and will provide notice as soon as permitted. Ansabell maintains supplementary technical measures, including encryption in transit and at rest, to protect transferred Personal Data.
14.6 Alternative mechanisms. If a court or supervisory authority holds that the transfer mechanism in this Section is invalid, or if a new valid transfer mechanism becomes available, the parties will work in good faith to implement an alternative lawful transfer mechanism, and Ansabell will take supplementary measures where required to protect the transferred Personal Data.
15. 15. HIPAA Business Associate Agreement
15.1 BAA availability. Ansabell offers a Business Associate Agreement ("BAA") to Customers that are Covered Entities or Business Associates under the Health Insurance Portability and Accountability Act and its implementing regulations ("HIPAA"). Under a mutually executed BAA, Ansabell acts as a Business Associate with respect to the protected health information ("PHI") that the Customer creates, receives, maintains, or transmits through the Ansabell service.
15.2 PHI only under an executed BAA. The Customer may use the Ansabell service to create, receive, maintain, or transmit PHI only after the parties execute a separate written BAA; absent an executed BAA, PHI must not be submitted to the service. Ansabell enters into a BAA or equivalent written commitment with each subprocessor that processes PHI on its behalf, including Amazon Web Services (cloud infrastructure) and its telephony and AI subprocessors.
15.3 Precedence and non-add-on use. Where a BAA is in effect between the parties, the BAA governs the processing of PHI, and in the event of a conflict between the BAA and this DPA with respect to PHI, the BAA controls. Without a BAA in effect, the Customer must not use the Ansabell service to transmit or process PHI in a manner that requires a Business Associate relationship.
16. 16. Order of Precedence, Liability, and General
16.1 Order of precedence. In the event of a conflict between the documents governing the processing of Personal Data, the following order of precedence applies: (a) the Standard Contractual Clauses, where they apply, prevail over this DPA to the extent of any conflict for transfers within their scope; (b) a BAA in effect prevails with respect to PHI as set out in Section 15; (c) this DPA prevails over the remainder of the Agreement; and (d) the remainder of the Agreement applies to all other matters.
16.2 Liability. Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Notwithstanding the foregoing, nothing in this DPA or the Agreement limits or excludes either party's liability to a Data Subject under the Standard Contractual Clauses (including Clause 12 thereof), or any liability that cannot be limited or excluded under Data Protection Laws or other applicable law; and the caps and exclusions in the Agreement do not apply to such liability.
16.3 Governing law and venue. Except where the Standard Contractual Clauses require otherwise for transfers within their scope, this DPA is governed by the laws of the State of Washington, USA, without regard to its conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Thurston County, Washington, consistent with the Agreement.
16.4 Changes. Ansabell may update this DPA from time to time to reflect changes in Data Protection Laws, transfer mechanisms, Subprocessors, or the Ansabell service, provided that no update will materially reduce the protections for Personal Data set out in this DPA. Material changes will be communicated in accordance with the notice provisions of the Agreement.
16.5 Severability and survival. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect. The obligations in this DPA survive termination or expiry of the Agreement for as long as Ansabell processes Personal Data on the Customer's behalf.
16.6 Contact. Questions about this DPA, and requests for a signed counterpart, may be directed to legal@ansabell.com, with privacy matters directed to privacy@ansabell.com. Ansabell's operator is Haven Technologies, Inc., 2103 Harrison Ave SW, Ste 1034, Olympia, WA 98502.
17. Annex 1 — Details of Processing
A. Parties
Data exporter: the Customer (Controller / Business), the business that subscribes to the Ansabell service, together with any relevant Controller on whose behalf the Customer acts. Data importer: Haven Technologies, Inc. (Processor / Service Provider), operator of the Ansabell service.
B. Subject Matter and Duration
Subject matter: provision of the Ansabell AI voice receptionist service. Duration: the term of the Agreement, plus any wind-down and legally required retention period as set out in Section 12, including the default active-retention, deletion, and backup-purge windows specified there.
C. Nature and Purpose of Processing
Answering inbound business calls with an AI voice; recording and transcribing calls; sending and receiving SMS messages (including opt-out/STOP handling); booking and managing appointments; calendar and CRM integration where connected; payment processing through Stripe; and related account, analytics, and support functions, in each case on the Customer's behalf.
D. Categories of Data Subjects
- End Callers who phone or message the Customer's Ansabell-powered line;
- The Customer's customers, prospects, patients, or clients whose details are provided during a call or message;
- The Customer's own personnel and authorized users of the service.
E. Categories of Personal Data
- Call data: audio recordings, transcripts, caller phone numbers (E.164), caller names and details provided during the call, appointment and booking details, and call metadata (time, duration, outcome);
- Messaging data: SMS content sent and received on the Customer's behalf, including opt-out records;
- Payment data: Stripe-issued tokens and card last-four only (Ansabell does not store full card numbers);
- Usage and technical data: log data, device and browser data, cookies, and analytics associated with use of the service.
F. Special Categories / Sensitive Data
The service is not designed to collect special-category or sensitive data, but calls to healthcare and health-adjacent Customers may reveal Consumer Health Data or health-related information. Any such data is processed only as necessary to provide the service on the Customer's instructions and subject to Section 7 (MHMDA) and, where applicable, the BAA under Section 15. The service is not directed to children, and the Customer must not use it to collect data from children under 13 or minors under 16 (Section 4.9).
G. Frequency of Processing
Continuous, on an ongoing basis for the duration of the Agreement, as calls and messages are handled and the service is used.
18. Annex 2 — Technical and Organizational Security Measures
Ansabell maintains a security program with technical and organizational measures appropriate to the risk, including the following, which may be updated over time provided they do not materially reduce the level of protection. These measures populate Annex II to the Standard Contractual Clauses where they apply.
A. Encryption and Key Management
- Encryption of Personal Data in transit using TLS 1.2 or higher with strong cipher suites;
- Encryption of Personal Data at rest using AES-256 or equivalent, including call recordings and transcripts stored in Amazon S3;
- Centralized key management with restricted access to encryption keys, periodic key rotation, and separation of key-management duties from data access;
- Storage of passwords in salted, hashed form and payment card data as tokens (last-four only) via Stripe; Ansabell does not store full card numbers.
B. Access Control and Authentication
- Role-based access controls limiting access to Personal Data to authorized personnel with a need to know, on a least-privilege basis;
- Multi-factor authentication (MFA) required for administrative and remote access to production systems;
- Unique user accounts, prompt deprovisioning on role change or departure, and periodic access reviews;
- Logging and monitoring of access to production systems and Personal Data, with tamper-resistant audit logs and alerting on anomalous access.
C. Infrastructure and Network Security
- Hosting on Amazon Web Services (US region) with network segmentation, security groups, and firewall controls;
- Environment separation between production and non-production systems, with no live Personal Data used in test environments except as necessary and protected;
- Vulnerability management, including regular automated vulnerability scanning (no less than monthly and after material changes) and timely, risk-prioritized application of security patches;
- Independent penetration testing conducted at least annually, with remediation of identified findings according to severity.
D. Organizational Measures and Assurance
- Confidentiality obligations and mandatory security and privacy training for personnel with access to Personal Data;
- Background checks for personnel where legally permitted and appropriate to the role;
- Vendor and subprocessor due diligence and written data-protection contracts;
- Incident-response procedures for detecting, investigating, and responding to Personal Data Breaches, including the notification process in Section 10;
- A formal information-security program aligned to recognized frameworks; Ansabell maintains or is pursuing SOC 2 Type II examination and will make its current report or equivalent certification status available to the Customer under Section 13 as it becomes available.
E. Resilience, Backup, and Deletion
- Regular encrypted backups and measures designed to restore availability of and access to Personal Data in a timely manner after an incident, with periodic restore testing;
- Business-continuity and disaster-recovery planning appropriate to the service;
- Data-retention and secure-deletion practices consistent with Section 12, including deletion from production within the defined window and purge across encrypted, rotating backups within the defined backup-purge interval;
- Periodic review and testing of the effectiveness of the security measures.
19. Annex 3 — Authorized Subprocessors
The following Subprocessors are authorized to process Personal Data in connection with the Ansabell service as of the effective date. This list mirrors Section 11.4 and is maintained current in accordance with Section 11.3. "Location" indicates the primary processing region; certain Subprocessors may process or route data through other regions, and any non-US processing is covered by the transfer safeguards in Section 14, including onward-transfer Standard Contractual Clauses where required.
| Subprocessor | Service / Processing Purpose | Data Processed | Location |
|---|---|---|---|
| Telnyx | Telephony connectivity and SMS delivery (primary) | Caller and recipient phone numbers, call and message content and metadata | United States (may route through other regions) |
| Twilio | Telephony and SMS delivery (secondary / fallback) | Caller and recipient phone numbers, call and message content and metadata | United States (may route through other regions) |
| Deepgram | Speech-to-text transcription | Call audio and resulting transcripts | United States (may process in other regions) |
| Cartesia | Text-to-speech voice generation | Response text converted to voice audio | United States |
| ElevenLabs | Text-to-speech voice generation | Response text converted to voice audio | United States / EU (may process in other regions) |
| OpenAI | Large language model reasoning (transient; no foundation-model training by default) | Call and message text processed to generate responses | United States (may process in other regions) |
| Anthropic | Large language model reasoning (transient; no foundation-model training by default) | Call and message text processed to generate responses | United States |
| Stripe | Payment processing | Payment tokens and card last-four only; billing details | United States (global payment infrastructure) |
| Amazon Web Services (AWS) | Cloud hosting and encrypted storage (Amazon S3) | All hosted Personal Data, including recordings and transcripts | United States |
| Google Calendar integration (only if connected by the Customer) | Appointment and booking details, calendar events | United States (global infrastructure) |
Questions about this document? Email legal@ansabell.com.