Data Processing Agreement

Last updated:

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Service Agreement or Terms of Service ("Agreement") between Salesfinity, Inc. ("Company" or "Processor") and the customer identified in the Agreement ("Customer" or "Controller"). This DPA sets forth the parties’ obligations with respect to the Processing of Personal Data in connection with the Services provided under the Agreement.

This DPA replaces any prior data processing addendum or similar agreement between the parties. Except for the modifications made by this DPA, the Agreement remains unchanged and in full force and effect. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.

1. Definitions

Unless otherwise defined herein, capitalized terms have the meanings set forth in applicable Data Protection Laws.

1.1 "Adequate Data Protection Destination" means a country, territory, or specified sector within a third country, or an international organization determined by a competent supervisory authority under applicable Data Protection Laws as providing an adequate level of protection for Personal Data.

1.2 "CCPA" means the California Consumer Privacy Act of 2018, as amended by the CPRA (Cal. Civ. Code §§ 1798.100 to 1798.199.95), and any related regulations or guidance, as amended or superseded from time to time.

1.3 "Controller" means the entity that determines the purposes and means of Processing Personal Data, as defined in the GDPR.

1.4 "CPRA" means the California Privacy Rights Act of 2020 and its implementing regulations, as amended or superseded from time to time.

1.5 "Customer Personal Data" means any Personal Data that Company Processes on behalf of Customer as a Processor in the course of providing the Services, as more particularly described in Annex I.

1.6 "Data Protection Laws" means all applicable laws and regulations relating to data privacy, data security, or the protection of Personal Data, including: (a) Regulation (EU) 2016/679 (the "GDPR"); (b) the UK Data Protection Act 2018 and the UK GDPR; (c) the CCPA and CPRA; (d) the Virginia Consumer Data Protection Act; (e) the Colorado Privacy Act; (f) the Swiss Federal Act on Data Protection; and (g) any other applicable domestic or foreign data protection legislation, in each case to the extent applicable to the Processing of Customer Personal Data.

1.7 "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

1.8 "EEA" means the European Economic Area, comprising the Member States of the European Union together with Iceland, Norway, and Liechtenstein.

1.9 "Personal Data" means any information relating to an identified or identifiable natural person, as defined in the GDPR or under applicable Data Protection Laws.

1.10 "Personal Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

1.11 "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.

1.12 "Processor" means the entity that Processes Personal Data on behalf of the Controller, as defined in the GDPR.

1.13 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, superseded, or replaced from time to time, which are incorporated into and form part of this DPA via Annex IV.

1.14 "Sub-processor" means any third-party Processor engaged by Company to Process Customer Personal Data on behalf of Customer.

1.15 "UK Addendum" means the International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner’s Office under S.119(A) of the UK Data Protection Act 2018, as may be amended, superseded, or replaced from time to time, incorporated herein via Annex V.

2. Scope and Roles of Processing

2.1 Scope. This DPA applies where and only to the extent that Company Processes Customer Personal Data that is subject to Data Protection Laws on behalf of Customer in the course of providing the Services pursuant to the Agreement.

2.2 Roles. As between Company and Customer, Customer is the Controller of Customer Personal Data, and Company shall Process Customer Personal Data only as a Processor acting on behalf of Customer.

2.3 Customer Responsibilities. Customer agrees that: (a) it shall comply with its obligations as a Controller under Data Protection Laws in respect of its Processing of Customer Personal Data and any Processing instructions it issues to Company; and (b) it has provided notice and obtained (or will obtain) all consents and rights necessary under Data Protection Laws for Company to Process Customer Personal Data and provide the Services pursuant to the Agreement and this DPA.

2.4 Company Processing. Company shall Process Customer Personal Data: (a) only as necessary to provide the Services under the Agreement; (b) in accordance with Customer’s documented instructions (including configuration of optional features); and (c) as required by applicable law, in which case Company shall, to the extent permitted by law, inform Customer of that legal requirement before Processing.

2.5 Optional Features. Customer acknowledges that certain features of the Services (e.g., call recording, transcription, AI summaries, Salesfloor) are optional. If Customer elects not to enable a feature, no associated Customer Personal Data will be transmitted to the relevant Sub-processors for that feature.

2.6 Compliance Notification. Company shall promptly notify Customer if it makes a determination that it can no longer meet its obligations under this DPA or applicable Data Protection Laws. Upon receipt of such notification, Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.

3. CCPA and CPRA Compliance

3.1 Service Provider Status. The parties acknowledge and agree that Company acts as a "Service Provider" as defined in the CCPA in its performance of its obligations pursuant to the Agreement.

3.2 Restrictions. Company shall not: (a) "sell" or "share" Customer Personal Information, as such terms are defined in the CCPA/CPRA; (b) retain, use, or disclose such Personal Information for any purpose other than performing the Services under the Agreement or as otherwise permitted under the CCPA/CPRA; (c) retain, use, or disclose such Personal Information for a commercial purpose other than providing the Services; or (d) retain, use, or disclose such Personal Information outside of the direct business relationship between Customer and Company.

3.3 Compliance Notification. Company shall promptly notify Customer in the event that it makes a determination that it can no longer meet its obligations under the CCPA/CPRA. Customer shall have the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.

3.4 Consumer Rights. At Customer’s request, Company shall assist Customer with its obligation to respond to consumers’ requests to exercise their rights under the CCPA/CPRA, including requests for access, knowledge, deletion, correction, and opt-out.

4. Data Subject Rights

4.1 Requests. Unless otherwise required by applicable law, Company shall promptly notify Customer of any request received from a Data Subject in respect of Customer Personal Data and shall not respond to the Data Subject directly. Company shall assist Customer in fulfilling such requests by implementing appropriate technical and organizational measures, insofar as this is possible.

4.2 Capabilities. Company shall provide Customer with the ability to correct, delete, block, access, or copy Customer Personal Data within the Services, or shall promptly perform such actions at Customer’s written request.

5. Sub-processors

5.1 Authorization. Customer grants Company general authorization to engage Sub-processors to Process Customer Personal Data. The current list of authorized Sub-processors is set forth in Annex III.

5.2 Sub-processor Obligations. Company shall: (a) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA; and (b) remain fully liable for the acts and omissions of its Sub-processors to the same extent Company would be liable for its own acts and omissions under this DPA and Data Protection Laws.

5.3 PII Minimization. Company employs secure hashing (HMAC-SHA512) and data minimization techniques to reduce exposure of sensitive Personal Data before transmitting to Sub-processors.

5.4 Notice of Changes. Company shall notify Customer in writing at least thirty (30) days in advance of any intended addition or replacement of Sub-processors and provide Customer an opportunity to object for legitimate data protection reasons.

5.5 Objection Right. If Customer objects to a new Sub-processor on reasonable data protection grounds within fourteen (14) days of receipt of notice, the parties shall discuss Customer’s concerns in good faith. If the parties cannot resolve the objection, Customer may, as its sole and exclusive remedy, terminate the portion of the Agreement relating to the Services that cannot be reasonably provided without the objected-to Sub-processor by providing thirty (30) days’ prior written notice to Company.

6. Security

6.1 Security Measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Company shall implement and maintain appropriate technical and organizational security measures designed to ensure a level of security appropriate to the risk, as described in Annex II.

6.2 Encryption. Customer Personal Data is encrypted at rest using AES-256 and in transit using HTTPS with TLS 1.2 or later. Sensitive PII fields are hashed using HMAC-SHA512.

6.3 Access Controls. Company restricts access to Customer Personal Data to authorized personnel on a need-to-know basis, enforces multi-factor authentication (MFA) on all critical systems, conducts quarterly access reviews, and promptly revokes access upon personnel termination.

6.4 SOC 2 Type II. Company maintains an annual SOC 2 Type II report covering Security, Availability, and Confidentiality Trust Service Criteria, audited by an independent third-party auditor. Company shall make available a summary or full report to Customer upon written request under NDA.

6.5 Confidentiality. Company shall ensure that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6.6 Vulnerability Management. Company conducts regular vulnerability scans and penetration testing, tracks all identified vulnerabilities, and remediates them in accordance with its vulnerability management policy.

7. Personal Data Breach

7.1 Notification. Company shall notify Customer without undue delay, and in any event within seventy-two (72) hours, upon becoming aware of a Personal Data Breach.

7.2 Notification Content. Such notification shall include, to the extent reasonably available: (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects; and (d) the name and contact details of Company’s point of contact.

7.3 Cooperation. Company shall provide commercially reasonable cooperation in identifying the cause of such breach and take commercially reasonable steps to remediate the cause to the extent within Company’s control.

8. Government and Law Enforcement Requests

8.1 Redirect. If Company receives a request from a government or law enforcement agency for Customer Personal Data (e.g., through a subpoena or court order), Company shall attempt to redirect the agency to request the data directly from Customer.

8.2 Notice. If compelled to disclose Customer Personal Data, Company shall give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy, unless Company is legally prohibited from doing so.

9. Data Protection Impact Assessments

Company shall, to the extent required under applicable Data Protection Laws and at Customer’s expense where legally permitted, provide reasonably requested information regarding the Services to enable Customer to carry out data protection impact assessments or prior consultations with supervisory authorities as required by law.

10. International Data Transfers

10.1 Processing Locations. Company may Process Customer Personal Data anywhere Company, its Affiliates, or its Sub-processors maintain data processing operations, provided that Company shall at all times ensure an adequate level of protection in accordance with applicable Data Protection Laws.

10.2 Transfer Mechanisms. To the extent that the Processing of Customer Personal Data involves the transfer of such data to a country or territory that is not an Adequate Data Protection Destination, such transfer shall be governed by the Standard Contractual Clauses (incorporated via Annex IV), which are hereby part of this DPA. In the event of a conflict between the SCCs and this DPA, the SCCs shall prevail.

10.3 Transfers from the EEA

For transfers of Customer Personal Data originating from the EEA and subject to the GDPR to any country other than an Adequate Data Protection Destination, the SCCs shall apply as follows:

  • Module Two (Controller-to-Processor) shall apply where Customer is the Controller; Module Three shall apply where Customer is itself a Processor.

  • In Clause 7, the optional docking clause shall apply.

  • In Clause 9, Option 2 (General Authorization) is selected; the time period for prior notice of Sub-processor changes shall be thirty (30) days.

  • In Clause 11, the optional language shall not apply.

  • In Clause 17 (Option 1), the SCCs shall be governed by the laws of Ireland.

  • In Clause 18, disputes shall be resolved before the courts of Ireland.

  • Annex I and Annex II shall be deemed completed with the information set forth in Annex I and Annex II to this DPA, respectively.

10.4 Transfers from the UK

For transfers originating from the UK, the SCCs as implemented in Section 10.3 shall apply, as modified and interpreted in accordance with the UK Addendum (Annex V).

10.5 Transfers from Switzerland

For transfers originating from Switzerland, the SCCs shall apply with the modifications required by the Swiss Federal Data Protection Act, including recognition of the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.

10.6 Encryption in Transit and at Rest. All Customer Personal Data shall be encrypted at rest using AES-256 or equivalent and in transit using HTTPS with TLS 1.2 or later.

11. Audits

11.1 Information. Upon reasonable written request, Company shall make available information necessary to demonstrate compliance with this DPA and applicable Data Protection Laws, including its most recent SOC 2 Type II report.

11.2 Customer Audits. Customer may conduct audits, including inspections, in accordance with Data Protection Laws, on at least thirty (30) days’ prior written notice, during normal business hours, no more than once per twelve (12) months (unless otherwise required by a competent data protection authority or following a Personal Data Breach), at Customer’s cost, unless a material breach is identified.

11.3 Cooperation. Company shall cooperate with and provide reasonable assistance to Customer in connection with any such audit.

12. Return or Deletion of Data

12.1 Termination Obligations. Upon termination or expiration of the Agreement, Company shall, at Customer’s written election, return all Customer Personal Data to Customer in a commonly used, machine-readable format (e.g., CSV, JSON) or securely delete all Customer Personal Data within thirty (30) days, and certify such deletion in writing.

12.2 Retention Exception. Company may retain Customer Personal Data to the extent required by applicable law, provided that Company shall continue to protect such data in accordance with this DPA and shall Process it only for the purpose(s) required by such law.

13. General Provisions

13.1 Precedence. This DPA supplements the Agreement. In case of conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict. In the event of conflict between this DPA and mandatory provisions of Data Protection Laws, the Data Protection Laws shall control.

13.2 Governing Law. This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.

13.3 Liability. Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including exclusions and limitations of liability, set forth in the Agreement. Company shall be fully liable for the acts or omissions of its Sub-processors to the same extent it is liable for its own acts or omissions under this DPA.

13.4 Contact. For questions regarding this DPA or data protection matters, contact: hello@salesfinity.co.

ANNEX I — PROCESSING DETAILS

A. List of Parties


Data Exporter (Controller)

Name:

Omni Analytics, Inc.

Address:

375 Alabama St, Unit 350 San Francisco, CA 94110

Contact:

Jonathan Griffiths, jon@omni.co

Role:

Controller


Data Importer (Processor)

Name:

Salesfinity, Inc.

Address:

San Francisco, CA, United States

Contact:

hello@salesfinity.co

Role:

Processor

B. Description of Transfer

Categories of Data Subjects: Any individual: (i) whose Personal Data is provided by Customer for use with the Services; (ii) whose information is stored on or collected via the Services; or (iii) to whom users call, engage, or communicate with via the Services.

Categories of Personal Data: Identification and contact data (name, email address, IP address, telephone number); employment details (employer, job title, geographic location, area of responsibility); call recordings and transcriptions (if enabled by Customer); and such other Personal Data as may be provided by Customer.

Sensitive Data: None, unless Customer uploads sensitive data at its own discretion. Company does not require or request sensitive/special category data.

Frequency of Transfer: Continuous basis for the duration of the Agreement.

Nature of Processing: Transmitting, collecting, storing, analyzing, transcribing (if enabled), and summarizing data in order to provide the Services, including AI-powered parallel dialing, call analytics, and account insights.

Purpose of Processing: The provision of the Services by Company to Customer, as described in the Agreement.

Retention Period: Until termination of the Agreement, subject to Customer’s deletion requests and Section 12 of this DPA.

ANNEX II — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

The following describes the technical and organizational measures implemented by Company to ensure an appropriate level of security. These measures are validated through Company’s annual SOC 2 Type II audit.

Encryption

  • Data at rest: AES-256 encryption on all production databases storing Customer Personal Data.

  • Data in transit: HTTPS with TLS 1.2 or later on all connections. SSH or encrypted VPN for system administration.

  • Sensitive PII fields: Hashed using HMAC-SHA512 before transmission to Sub-processors.

  • Endpoint encryption: All critical endpoints encrypted to protect against unauthorized access.

Access Controls

  • Role-based access control (RBAC) with principle of least privilege.

  • Multi-factor authentication (MFA) required on all critical systems.

  • Quarterly access reviews by the Information Security Officer.

  • Automatic access revocation upon personnel termination.

  • Auto-screen-lock after 15 minutes of inactivity on all endpoints.

  • Production database access restricted from public internet; SSH access protected.

Infrastructure Security

  • Production hosted on AWS and Google Cloud within Virtual Private Clouds (VPCs).

  • Deny-by-default firewall rules on all production hosts.

  • Intrusion detection and continuous security monitoring via Sprinto.

  • Endpoint malware protection on all devices with access to critical systems.

Vulnerability Management

  • Monthly automated vulnerability scans of production systems.

  • Regular penetration testing by external parties.

  • Risk-ranked remediation of identified vulnerabilities per documented policy.

  • Automated software patching and OS update enforcement.

Business Continuity & Disaster Recovery

  • Documented Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP), tested periodically.

  • Defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

  • Daily backups of all critical data, with backup integrity testing performed periodically.

  • Customer data replicated across multiple availability zones.

Personnel Security

  • Background checks on all new hires.

  • Annual security awareness training for all staff.

  • Confidentiality agreements required for all employees, contractors, and Sub-processors.

  • Documented Code of Business Conduct with policy acknowledgment upon hiring and annually.

Change Management

  • Documented change management policy governing all application and infrastructure changes.

  • Version control with mandatory peer code review (pull request approval required from separate reviewer).

  • Automated testing prior to production deployment.

  • Separation of duties between development, testing, and production deployment.

Incident Management

  • Defined incident response procedures with severity classification (Low, Medium, High, Critical).

  • Escalation procedures to privacy, legal, customer, and senior management teams.

  • Post-mortem analysis for critical severity incidents.

  • Documented breach notification guidelines for customers and stakeholders.

Certifications and Audits

  • SOC 2 Type II — Security, Availability, and Confidentiality

  • Annual vendor risk assessments and review of Sub-processor SOC reports.

  • Continuous compliance monitoring via Sprinto.

ANNEX III — LIST OF SUB-PROCESSORS

Sub-processor

Location

Description of Processing

Contact

MongoDB

United States

Database storage for Customer Personal Data

privacy@mongodb.com

Amazon Web Services

United States, Germany

Cloud infrastructure and hosting (compute, storage, networking)

aws-privacy@amazon.com

Cloudflare

United States

CDN, DDoS protection, and hosting services

privacyquestions@cloudflare.com

Twilio

United States

Telecommunications partner for voice services

privacy@twilio.com

Deepgram

United States

Audio transcription (only if Customer enables transcription)

security@deepgram.com

OpenAI

United States

Natural language processing for summaries, account insights, and task automation (only if Customer enables recording/transcription)

privacy@openai.com

Eleven Labs

United States

AI voice synthesis (optional feature)

privacy@elevenlabs.io

Daily

United States

Video communication platform for Salesfloor (optional)

privacy@daily.co

Intercom

United States

Customer support and communication

privacy@intercom.com

HubSpot

United States

CRM and customer relationship management

privacy@hubspot.com

Google Analytics

United States

Product analytics and usage metrics

data-protection-office@google.com

PostHog

United States

Product analytics

privacy@posthog.com

Microsoft Clarity

United States

User experience analytics

privacy@microsoft.com

Sentry

United States

Error monitoring and application performance

privacy@sentry.io

Slack

United States

Internal collaboration and productivity

privacy@slack.com

ANNEX IV — STANDARD CONTRACTUAL CLAUSES

The parties hereby incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available at:

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914

The following selections apply:

SCC Clause

Selection

Module

Module 2 (Controller-to-Processor); Module 3 where Customer is a Processor

Clause 7 (Docking)

Optional docking clause applies

Clause 9 (Sub-processors)

Option 2: General Authorization; 30-day prior notice

Clause 11 (Redress)

Optional language does not apply

Clause 17 (Governing Law)

Option 1: Laws of Ireland

Clause 18 (Jurisdiction)

Courts of Ireland

Annex I

As set forth in Annex I to this DPA

Annex II

As set forth in Annex II to this DPA

Annex III

As set forth in Annex III to this DPA

ANNEX V — UK INTERNATIONAL DATA TRANSFER ADDENDUM

This Annex incorporates the International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner’s Office and laid before Parliament in accordance with Section 119A of the UK Data Protection Act 2018 on 2 February 2022, as revised from time to time.

Part 1: Tables

Table 1: Parties

Exporter

Importer

Party Details

The Customer (Controller)

Salesfinity, Inc. (Processor)San Francisco, CA hello@salesfinity.co

Table 2: SCCs & Modules

Selection

Module 2 (C2P)

In operation: Yes

Clause 7 (Docking)

Yes

Clause 9 (Authorization)

General Authorization; 30-day notice

Clause 11 (Option)

Not applicable

Table 3: Appendix Information

Annex I (Parties and Processing Details), Annex II (Technical and Organizational Measures), and Annex III (Sub-processors) of this DPA serve as the appendix information for the UK Addendum.

Table 4: Ending the Addendum

Neither party may end this Addendum when the Approved Addendum changes.

Part 2: Mandatory Clauses

This Annex incorporates the Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with S.119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses.


Date updated: July 20, 2026

On this page

No headings found on page

Looking for more information?

Visit the Help Center for in depth resources or connect with our support team.