Data Processing Agreement (DPA)
Effective date: 2 August 2026
Version: B2B โ applicable to business agreements only
This Data Processing Agreement has been drawn up in accordance with Article 28 GDPR and automatically forms part of every agreement with AIOS Flow. By accepting our quotation or general terms and conditions, you also accept this DPA. Please also refer to our Privacy Policy and Terms & Conditions.
Applicability and Electronic Acceptance
This Data Processing Agreement ("DPA") forms an integral and inseparable part of the agreement between AIOS Flow ("Processor") and the client ("Controller" or "Client") regarding the AI receptionist service ("the Service"). This DPA is a processing agreement as referred to in Article 28(3) GDPR and has been drawn up in electronic form in accordance with Article 28(9) GDPR. It applies by operation of law and is binding as soon as the Client agrees to the Processor's quotation, email proposal and/or general terms and conditions. A handwritten or separate signature is not required.
1. Roles and Purpose Limitation
The Client is the controller; the Processor processes personal data solely on behalf of the Client and on the basis of the Client's documented instructions, as set out in the agreement and this DPA. Processing is strictly limited to providing the Service: the automated answering of telephone calls, general customer service, and appointment management. Processing for any other purpose does not take place.
2. Confidentiality and Security
The Processor binds persons involved in the processing to confidentiality and implements appropriate technical and organisational measures in accordance with Article 32 GDPR, including encryption during transport and storage, need-to-know access controls, and logical separation of data per client. The level of security is matched to the risk of the processing.
3. Sub-processors and Transfers
The Client hereby grants general prior authorisation for the engagement of sub-processors, exclusively for the purpose of the Service, within the following functional categories:
โข Telecommunications and voice connection services;
โข AI language models and speech and document processing;
โข Cloud infrastructure and data storage;
โข Authentication and identity management;
โข Payment, email and communication services.
Processing takes place within the European Economic Area (EEA), or โ where processing occurs outside the EEA โ exclusively on the basis of a valid transfer mechanism such as the Standard Contractual Clauses (SCCs) approved by the European Commission with appropriate supplementary safeguards. An up-to-date list of sub-processors is made available upon request or via a secure URL. The Processor notifies the Client in advance of any intended change and provides an opportunity to object on reasonable grounds. The Processor imposes equivalent obligations on each sub-processor and remains responsible to the Client. The calendar provider connected by the Client (e.g. Cal.com, Google or Microsoft) constitutes a direct relationship and the Client's own account, and falls outside the Processor's sub-processor network.
4. EU AI Act โ Limited Risk
The Service is an AI system with limited risk. The Processor guarantees:
โข Transparency (Art. 50 AI Act): the AI assistant automatically notifies callers at the start of each conversation that they are speaking with an artificial intelligence assistant;
โข No model training: client data, audio recordings and transcripts are not used to train public or external AI models;
โข Purpose limitation and human oversight: the AI is exclusively intended for general customer service and appointment management, with the possibility of escalation to a human agent at all times.
5. Data Breaches and Assistance
The Processor notifies the Client of a personal data breach without undue delay after discovery, with the information available at that time. The Processor provides the Client, to the extent reasonably possible and at cost price, with assistance in responding to data subject requests and in fulfilling obligations under Articles 32 to 36 GDPR. The Processor makes the necessary information available to the Client upon request and cooperates, at most once per year, in a written audit to verify compliance with this DPA, at the Client's expense.
6. Duration, Deletion and Liability
Conversation notes, call data and audio are automatically deleted by default 30 days after the conversation, unless otherwise agreed in writing. This DPA applies for as long as the Processor processes personal data on behalf of the Client. Upon termination of the Service, personal data will be deleted or returned at the Client's choice, unless a statutory retention obligation requires otherwise. The liability of the parties under this DPA is subject to the limitations and exclusions set out in the main agreement and/or general terms and conditions.
Categories of Data Subjects and Data
Categories of data subjects: callers and employees/workers of the Client. Categories of data: name, contact details, conversation content (audio/transcript), appointment data and other data provided by the caller. Special categories of personal data are not intended to be processed.
Contact
For questions about this Data Processing Agreement, please contact us via: