This agreement governs our processing of personal data on your behalf, and forms part of the Terms of Service between you and CodeShant Technologies (UDYAM-BR-26-0188408), the operator of PhoneMyAgent ("we", "us"). It is the agreement required by Article 28(3) of the GDPR.
You are the controller and we are the processor for everything your agent handles: the calls it answers, the transcripts and summaries it produces, and the documents you give it. You decide why the data is processed and for how long. We process it only to run the service for you.
We are a separate and independent controller for a narrow set of data that is ours rather than yours: your account and login details, your invoices and the usage totals behind them, and the security logs we keep to protect the platform. Our handling of that data is described in the privacy policy, not here.
This agreement takes effect when you accept it in your dashboard. We record which version you accepted, when, and by which user. You cannot provision a phone number until it is accepted, because from the first call onward we are processing personal data belonging to people who never signed anything.
We process personal data only on your documented instructions, including in relation to transfers, unless a law we are subject to requires otherwise. If that happens we will tell you before processing, unless that same law forbids telling you.
Your instructions are: this agreement, the Terms of Service, and the configuration you set in the dashboard. That configuration is an instruction in the operative sense: the agent prompt and greeting, whether recording is on, the retention window, the disclosure line, the documents you index, and the numbers you route to. Changing a setting changes your instruction, and the change applies from that moment.
If we consider an instruction to infringe the GDPR or other Union or Member State data protection law, we will inform you. We may suspend the affected processing until it is resolved.
We will not use your call content, transcripts, or documents to train models, to build any product other than the service we provide to you, or for any purpose of our own.
Everyone we authorise to process your data is bound by a duty of confidentiality that survives the end of their engagement with us. We limit access to those who need it to operate, support, and secure the service.
We implement appropriate technical and organisational measures under Article 32, described in Annex II. Those measures reflect the state of the art, the cost of implementation, and the risk to the people whose data is processed.
We may change the measures as the service evolves. We will not reduce the overall level of security below what Annex II describes.
You give us general written authorisation to engage subprocessors. Those engaged today are listed in Annex III. Each is engaged to deliver a defined part of the service and may process your data only for that purpose and only on our instructions.
Before we add or replace a subprocessor we will update Annex III and notify you by email at least 30 days beforehand. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you to find a resolution. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any prepaid fees for the unused period.
Every subprocessor is bound by data protection obligations no less protective than those in this agreement. We remain fully liable to you for their performance.
Callers exercise their rights against you, not against us, because you are the controller. We help you answer them.
The dashboard is the first line of that help: you can search calls, read and export transcripts, and delete a call, a caller, or a recording yourself, without asking us and without waiting. Where the dashboard is not enough, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing.
If a caller contacts us directly, we will not answer for you. We will tell them to contact you, identify you to them where it is appropriate to do so, pass the request on, and act on your instruction.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event in time for you to meet your own 72-hour obligation under Article 33.
Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we do not have all of it at once, we will send what we have and follow up rather than wait.
Notifying your supervisory authority and, where required, the affected people is your decision and your obligation. We will give you the information you need to make it.
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments under Article 35 and prior consultation with a supervisory authority under Article 36. Annex I and Annex II are written to be usable directly in such an assessment.
By accepting this agreement you instruct us to delete your personal data at the end of the service, rather than return it. This matches how account closure already works: closing your account erases your calls, transcripts, recordings, caller records, and documents immediately, with no export window and no undo.
If you want a copy, take it before you close the account. The dashboard lets you export your data at any time while the account is open, and you can ask us for an export at any point before termination and we will provide one. Once the account is closed the data is gone and we cannot recover it.
Two things survive deletion because law requires it, and we hold them as controller rather than as your processor: the invoices we issued you and the usage totals they are based on, which contain no caller and no call content, and the business name on the closed account, because an invoice must say who it was issued to.
We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate.
In practice, please start by asking us: for most questions the answer is in this agreement, the privacy policy, or a written response we can give you quickly. Where that is not enough, an on-site or remote audit may be conducted once per calendar year, on at least 30 days written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. You may audit more often if a supervisory authority requires it or following a personal data breach affecting your data. You bear your own audit costs.
Read this section before you accept. It is the part of the service most likely to matter to your own data protection assessment.
Your data is stored in the European Union, on servers in Germany. Speech processing is not. To answer a call, the call audio and the resulting transcript are processed in the United States by the subprocessor identified in Annex III.
By accepting this agreement you instruct and authorise that transfer. It is necessary for the performance of the service.
We contract for these services with OpenAI Ireland Limited, so our own contractual relationship sits within the EEA, and the onward transfer to the United States takes place under that provider's data processing terms and Article 46 transfer mechanisms. Where we engage a subprocessor outside the EEA directly, we put Standard Contractual Clauses or another Article 46 mechanism in place.
What this means for you. Your own privacy notice should tell callers that call handling involves a transfer to the United States. If you process special category data under Article 9, such as health information in a clinic, take advice on whether this arrangement meets your requirements before you route real calls through it.
Where a European processing option becomes available for these services, we will update this section and Annex III and notify you.
This agreement takes effect when you accept it and continues for as long as we process personal data on your behalf. Sections 9 and 12 survive its termination.
The limitations of liability in the Terms of Service apply to this agreement, except where the GDPR does not permit them to.
Governing law. This agreement is governed by the laws of India, and the courts there have jurisdiction over disputes between us.
The GDPR applies regardless. Nothing in the preceding paragraph, and nothing else in this agreement, limits or excludes any right a data subject has under the GDPR, any obligation the GDPR places on us as processor, or the powers of a supervisory authority. Where a term of this agreement conflicts with the GDPR, the GDPR prevails and the conflicting term is read down to the extent needed. Choosing Indian law settles which courts hear a contract dispute between you and us; it does not and cannot move the processing outside European data protection law.
If we update this agreement we will notify you and ask you to accept the new version in the dashboard. Material changes will be reflected in the "Last updated" date above.
Subject matter and nature. Answering inbound telephone calls on your behalf with an AI voice agent, and the processing needed to do so: understanding what the caller says, answering from the material you provide, booking appointments, taking messages, producing transcripts and summaries, extracting the key details a caller gave, and notifying you.
Purpose. Providing the PhoneMyAgent service to you, and nothing else.
Duration. For as long as your account is open, then as set out in section 9. Individual calls and recordings are held for the retention window you configure.
Frequency. Continuous, for the duration of your subscription.
Categories of data subject.
Types of personal data.
Special categories of personal data. The service is not designed to collect them, and the Terms of Service prohibit using the agent for regulated advice, diagnosis, triage, or medication questions. We cannot prevent a caller from volunteering sensitive information in an open conversation, and if your business is one people call about their health, their finances, or a legal problem, you should assume it will happen and treat the resulting transcripts accordingly. Deciding whether Article 9 applies to your use, and identifying a valid Article 9 condition if it does, is yours to do as controller.
These are the measures in place today. We list only measures we actually operate.
We do not currently hold ISO 27001, SOC 2, or an equivalent third-party certification, and we do not claim one.
Each of these processes personal data on our behalf in order to deliver part of the service. This list is the same one published in our privacy policy.
| Subprocessor | Purpose | Region |
|---|---|---|
| OpenAI | Speech processing and AI responses | United States |
| Twilio | Phone numbers and call carriage, including caller numbers | United States / EU |
| SendGrid | Transactional email | United States |
| Stripe | Card payments and subscriptions | United States / EU |
| Contabo | Server hosting and data storage | Germany (EU) |
| Cloudflare | Website network, DNS, security, and cookieless page-view statistics | United States / EU edge |