Data Processing Addendum
Terms governing Callario's processing of personal data on behalf of its customers.
Purpose and Roles
This Data Processing Addendum ("DPA") forms part of the agreement between Callario and the customer ("Customer") for the Services and applies to Callario's processing of personal data on the Customer's behalf.
For the purposes of this DPA, the Customer acts as the controller (or processor on behalf of its own controllers) and Callario acts as the processor (or subprocessor) with respect to Customer Personal Data processed through the Services. Each party will comply with its respective obligations under applicable data protection laws.
Where Callario processes personal information as a controller for its own purposes, that processing is governed by our Privacy Policy rather than this DPA.
Scope of Processing
Callario will process Customer Personal Data only to provide the Services and in accordance with the Customer's documented instructions, including as set out in the agreement, this DPA, and the Customer's use of the Services' configuration and controls.
The subject matter of processing is the provision of the Services; the duration is the term of the agreement; the nature and purpose are to operate the customer-support platform and its features on the Customer's behalf; the types of personal data and categories of data subjects are determined by the Customer through its use of the Services.
If Callario believes an instruction violates applicable data protection law, it will inform the Customer, unless prohibited from doing so by law.
Confidentiality and Security
Callario will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
Callario will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, the nature of the data, and the risks involved.
These measures may include access controls, encryption in transit, logging and audit capabilities, and governance controls over AI features. Callario's information-security program continues to mature, and its SOC 2 effort is in progress.
Subprocessors
The Customer authorizes Callario to engage subprocessors to assist in providing the Services. Callario maintains a list of subprocessor categories, organized by function, on its Subprocessors page.
Callario will impose data protection obligations on its subprocessors that are substantially similar to those in this DPA and remains responsible for its subprocessors' performance of their obligations.
Callario will provide a mechanism for the Customer to be informed of intended changes to its subprocessors so that the Customer has an opportunity to object on reasonable data protection grounds.
Data Subject Requests and Assistance
Taking into account the nature of the processing, Callario will provide reasonable assistance to enable the Customer to respond to requests from data subjects exercising their rights, to the extent the Customer cannot do so through the Services' own functionality.
Callario will, considering the nature of processing and information available to it, assist the Customer in meeting its obligations relating to security, breach notification, data protection impact assessments, and consultation with supervisory authorities.
If Callario receives a request directly from a data subject relating to Customer Personal Data, it will, where permitted, direct the request to the Customer.
Incident Notification, Deletion, and Audits
Callario will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably available to it to assist the Customer in meeting its notification obligations.
Upon termination or expiry of the Services, Callario will delete or return Customer Personal Data in accordance with the agreement, except where retention is required by law.
Callario will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits as required by applicable law, subject to reasonable confidentiality, security, and scheduling safeguards.
International Transfers
Where Customer Personal Data is transferred across borders, the parties will rely on a lawful transfer mechanism as required by applicable data protection law and will implement supplementary measures where appropriate.
Callario offers EU data residency options for eligible customers as described in its product documentation, enabling certain processing to be located within the relevant region.
In the event of any conflict between this DPA and the agreement regarding the processing of Customer Personal Data, this DPA will prevail to the extent of the conflict.