phonemyagent
How it works Pricing Blog
  • English
  • Deutsch
Sign in

Data Processing Agreement

Last updated: July 28, 2026

1. Scope and roles

This agreement governs our processing of personal data on your behalf, and forms part of the Terms of Service between you and CodeShant Technologies (UDYAM-BR-26-0188408), the operator of PhoneMyAgent ("we", "us"). It is the agreement required by Article 28(3) of the GDPR.

You are the controller and we are the processor for everything your agent handles: the calls it answers, the transcripts and summaries it produces, and the documents you give it. You decide why the data is processed and for how long. We process it only to run the service for you.

We are a separate and independent controller for a narrow set of data that is ours rather than yours: your account and login details, your invoices and the usage totals behind them, and the security logs we keep to protect the platform. Our handling of that data is described in the privacy policy, not here.

This agreement takes effect when you accept it in your dashboard. We record which version you accepted, when, and by which user. You cannot provision a phone number until it is accepted, because from the first call onward we are processing personal data belonging to people who never signed anything.

2. Processing only on your instructions

We process personal data only on your documented instructions, including in relation to transfers, unless a law we are subject to requires otherwise. If that happens we will tell you before processing, unless that same law forbids telling you.

Your instructions are: this agreement, the Terms of Service, and the configuration you set in the dashboard. That configuration is an instruction in the operative sense: the agent prompt and greeting, whether recording is on, the retention window, the disclosure line, the documents you index, and the numbers you route to. Changing a setting changes your instruction, and the change applies from that moment.

If we consider an instruction to infringe the GDPR or other Union or Member State data protection law, we will inform you. We may suspend the affected processing until it is resolved.

We will not use your call content, transcripts, or documents to train models, to build any product other than the service we provide to you, or for any purpose of our own.

3. Confidentiality

Everyone we authorise to process your data is bound by a duty of confidentiality that survives the end of their engagement with us. We limit access to those who need it to operate, support, and secure the service.

4. Security of processing

We implement appropriate technical and organisational measures under Article 32, described in Annex II. Those measures reflect the state of the art, the cost of implementation, and the risk to the people whose data is processed.

We may change the measures as the service evolves. We will not reduce the overall level of security below what Annex II describes.

5. Subprocessors

You give us general written authorisation to engage subprocessors. Those engaged today are listed in Annex III. Each is engaged to deliver a defined part of the service and may process your data only for that purpose and only on our instructions.

Before we add or replace a subprocessor we will update Annex III and notify you by email at least 30 days beforehand. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you to find a resolution. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any prepaid fees for the unused period.

Every subprocessor is bound by data protection obligations no less protective than those in this agreement. We remain fully liable to you for their performance.

6. Helping you answer data subject requests

Callers exercise their rights against you, not against us, because you are the controller. We help you answer them.

The dashboard is the first line of that help: you can search calls, read and export transcripts, and delete a call, a caller, or a recording yourself, without asking us and without waiting. Where the dashboard is not enough, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing.

If a caller contacts us directly, we will not answer for you. We will tell them to contact you, identify you to them where it is appropriate to do so, pass the request on, and act on your instruction.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event in time for you to meet your own 72-hour obligation under Article 33.

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we do not have all of it at once, we will send what we have and follow up rather than wait.

Notifying your supervisory authority and, where required, the affected people is your decision and your obligation. We will give you the information you need to make it.

8. Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments under Article 35 and prior consultation with a supervisory authority under Article 36. Annex I and Annex II are written to be usable directly in such an assessment.

9. Return and deletion

By accepting this agreement you instruct us to delete your personal data at the end of the service, rather than return it. This matches how account closure already works: closing your account erases your calls, transcripts, recordings, caller records, and documents immediately, with no export window and no undo.

If you want a copy, take it before you close the account. The dashboard lets you export your data at any time while the account is open, and you can ask us for an export at any point before termination and we will provide one. Once the account is closed the data is gone and we cannot recover it.

Two things survive deletion because law requires it, and we hold them as controller rather than as your processor: the invoices we issued you and the usage totals they are based on, which contain no caller and no call content, and the business name on the closed account, because an invoice must say who it was issued to.

10. Information and audits

We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate.

In practice, please start by asking us: for most questions the answer is in this agreement, the privacy policy, or a written response we can give you quickly. Where that is not enough, an on-site or remote audit may be conducted once per calendar year, on at least 30 days written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. You may audit more often if a supervisory authority requires it or following a personal data breach affecting your data. You bear your own audit costs.

11. International transfers

Read this section before you accept. It is the part of the service most likely to matter to your own data protection assessment.

Your data is stored in the European Union, on servers in Germany. Speech processing is not. To answer a call, the call audio and the resulting transcript are processed in the United States by the subprocessor identified in Annex III.

By accepting this agreement you instruct and authorise that transfer. It is necessary for the performance of the service.

We contract for these services with OpenAI Ireland Limited, so our own contractual relationship sits within the EEA, and the onward transfer to the United States takes place under that provider's data processing terms and Article 46 transfer mechanisms. Where we engage a subprocessor outside the EEA directly, we put Standard Contractual Clauses or another Article 46 mechanism in place.

What this means for you. Your own privacy notice should tell callers that call handling involves a transfer to the United States. If you process special category data under Article 9, such as health information in a clinic, take advice on whether this arrangement meets your requirements before you route real calls through it.

Where a European processing option becomes available for these services, we will update this section and Annex III and notify you.

12. Term, liability, and governing law

This agreement takes effect when you accept it and continues for as long as we process personal data on your behalf. Sections 9 and 12 survive its termination.

The limitations of liability in the Terms of Service apply to this agreement, except where the GDPR does not permit them to.

Governing law. This agreement is governed by the laws of India, and the courts there have jurisdiction over disputes between us.

The GDPR applies regardless. Nothing in the preceding paragraph, and nothing else in this agreement, limits or excludes any right a data subject has under the GDPR, any obligation the GDPR places on us as processor, or the powers of a supervisory authority. Where a term of this agreement conflicts with the GDPR, the GDPR prevails and the conflicting term is read down to the extent needed. Choosing Indian law settles which courts hear a contract dispute between you and us; it does not and cannot move the processing outside European data protection law.

If we update this agreement we will notify you and ask you to accept the new version in the dashboard. Material changes will be reflected in the "Last updated" date above.

Annex I: Description of the processing

Subject matter and nature. Answering inbound telephone calls on your behalf with an AI voice agent, and the processing needed to do so: understanding what the caller says, answering from the material you provide, booking appointments, taking messages, producing transcripts and summaries, extracting the key details a caller gave, and notifying you.

Purpose. Providing the PhoneMyAgent service to you, and nothing else.

Duration. For as long as your account is open, then as set out in section 9. Individual calls and recordings are held for the retention window you configure.

Frequency. Continuous, for the duration of your subscription.

Categories of data subject.

  • People who call the phone number your agent answers.
  • Your own staff who use the dashboard.
  • People named in the documents and web pages you index for your agent.
  • Your own customers, where you import a spreadsheet so the agent can answer them about their own record.

Types of personal data.

  • The caller's telephone number, and the time and duration of the call.
  • Call audio, where you have switched recording on. Recording is off by default.
  • Transcripts of the conversation, AI-generated summaries, and key details the caller gave, such as their name, email address, callback number, and appointment.
  • Appointment and booking details.
  • Names you save for your callers, tags you apply, and notes your team writes about a call.
  • Whatever personal data is contained in the documents and URLs you index.
  • Whatever personal data is in the spreadsheets you import as customer records, typically a name, a phone number, a reference such as an order number, and the details of that order.
  • Your users' email addresses and dashboard activity.

Special categories of personal data. The service is not designed to collect them, and the Terms of Service prohibit using the agent for regulated advice, diagnosis, triage, or medication questions. We cannot prevent a caller from volunteering sensitive information in an open conversation, and if your business is one people call about their health, their finances, or a legal problem, you should assume it will happen and treat the resulting transcripts accordingly. Deciding whether Article 9 applies to your use, and identifying a valid Article 9 condition if it does, is yours to do as controller.

Annex II: Technical and organisational measures

These are the measures in place today. We list only measures we actually operate.

  • Hosting location. Application servers, database, uploaded documents, and recordings are hosted in Germany, inside the European Union. Speech processing is not; see section 11.
  • Encryption in transit. HTTPS for the website, dashboard, and API. Traffic between the service and the providers that carry and process your calls is encrypted in transit.
  • Encryption of stored credentials. Third-party credentials you store with us are encrypted at rest using strong, industry-standard encryption, with key material held separately from the database.
  • Authentication. Passwordless sign-in by one-time code or link. We never store a password, so there is no password database to breach.
  • Tenant isolation. Each account's data is segregated: one customer's calls, documents, and settings are not reachable from another customer's session.
  • Access control. Role-based access within your account. You invite and remove your own team members.
  • Data minimisation by default. Call recording is off unless you switch it on. The AI disclosure to callers is on unless you switch it off.
  • Deletion. Closing an account erases its users, calls, transcripts, caller records, recordings, and documents, including the recording files on disk.
  • Segregation of environments. Development and production run separately, with separate credentials.

We do not currently hold ISO 27001, SOC 2, or an equivalent third-party certification, and we do not claim one.

Annex III: Subprocessors

Each of these processes personal data on our behalf in order to deliver part of the service. This list is the same one published in our privacy policy.

SubprocessorPurposeRegion
OpenAISpeech processing and AI responsesUnited States
TwilioPhone numbers and call carriage, including caller numbersUnited States / EU
SendGridTransactional emailUnited States
StripeCard payments and subscriptionsUnited States / EU
ContaboServer hosting and data storageGermany (EU)
CloudflareWebsite network, DNS, security, and cookieless page-view statisticsUnited States / EU edge
phonemyagent

The phone agent that learned your business from your documents. Day and night, every caller gets an answer.

By industry

Dental clinics Restaurants Salons and spas Tradespeople

Guides

AI phone agent in Vienna Keep your number GDPR and AI calls Cost comparison

Product

Pricing Blog Sign in
© 2026 PhoneMyAgent. All rights reserved.
Privacy Terms Data processing (DPA) Legal notice
EN DE