Data Processing Addendum
Last updated July 21, 2026
This Data Processing Addendum (“DPA”) supplements the RevenueCallout Terms of Service or other agreement (the “Agreement”) between the customer identified in the account or Order Form (“Customer”) and RevenueCallout(“Processor”). It applies when Processor handles personal information in Customer Content on Customer's behalf. It becomes effective when referenced in an Order Form, accepted by an authorized Customer representative, or otherwise incorporated into the Agreement.
1. Roles and applicable law
Customer is the business/controller and Processor is the service provider/contractor/processor for Customer Content, as those terms are used in applicable U.S. privacy laws. Each party will comply with its own obligations. For account administration, security, billing, support, and Processor's independent legal obligations, Processor may act as a separate business/controller as described in the Privacy Policy.
2. Processing details and instructions
Processor will process Customer Content only to provide, secure, maintain, and support the Service; follow the Agreement, product configuration, and documented Customer instructions; and comply with law. Processor will notify Customer if an instruction appears unlawful unless prohibited from doing so.
Duration: the Agreement plus the deletion and backup period.
People: Customer users, personnel, prospects, clients, meeting participants, CRM contacts, and other people represented in Customer Content.
Data: identifiers, business contact data, audio/video if enabled, transcripts, meeting metadata, CRM data, sales statements, inferences, feedback, usage, and integration identifiers.
Operations: collection, hosting, organization, retrieval, transcription, AI analysis, generation, transmission to enabled integrations, support, security, deletion, and return.
Sensitive data: not intended. Customer must not submit regulated or highly sensitive data unless expressly authorized in writing.
3. Processing restrictions
Processor will not sell or share Customer Content for cross-context behavioral advertising; retain, use, or disclose it outside the business relationship and permitted purposes; combine it with information from another source except as allowed by applicable law to provide the Service; or use it to train a public foundation model. Processor will not attempt to identify de-identified data received from Customer. Processor will notify Customer if it can no longer meet applicable service-provider restrictions and will allow reasonable steps to stop and remediate unauthorized use.
4. Confidentiality and personnel
Processor will limit access to personnel and contractors who need it for the Service, are informed of its confidential nature, and are bound by appropriate confidentiality obligations. Processor remains responsible for their compliance with this DPA.
5. Security
Processor will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Content, including the measures in the Security Overview. Processor may update measures without materially decreasing overall protection during the subscription.
6. Subprocessors
Customer generally authorizes the subprocessors on the Subprocessor List. Processor will impose data-protection obligations appropriate to their services and remains responsible for their processing to the extent required by law. Processor will provide notice of material additions and a reasonable opportunity to object on documented data-protection grounds.
7. Individual requests
Considering the nature of processing, Processor will provide reasonable assistance for Customer to respond to verified access, correction, deletion, portability, opt-out, or appeal requests. If Processor directly receives a request concerning Customer Content, it will refer the person to Customer unless law requires otherwise.
8. Security incidents
Processor will notify Customer without undue delay after confirming unauthorized access to or acquisition, disclosure, alteration, loss, or destruction of Customer Content managed by Processor (a “Security Incident”). Notice will include known facts reasonably needed for Customer's response and will be updated as information becomes available. Processor will take reasonable containment and remediation steps. Unsuccessful attempts, scans, blocked attacks, and events that do not compromise Customer Content are not Security Incidents.
9. Assessments and audits
On reasonable written request no more than annually, Processor will provide information reasonably necessary to demonstrate compliance, such as completed questionnaires or available summaries. Additional audits require reasonable advance notice, confidentiality, scope that avoids other customers' data, and reimbursement of Processor's reasonable costs unless an audit identifies a material breach. Regulators retain any audit rights provided by law.
10. Return and deletion
During the subscription, Customer may use available export and deletion functions. After termination and on written request, Processor will delete or return Customer Content unless law requires retention. Copies in backups will be isolated from ordinary use and deleted on the normal cycle. Processor may retain limited security, billing, consent, and dispute records subject to continued protection.
11. Government demands and international data
Processor will notify Customer of a legally binding demand for Customer Content where permitted and will disclose only what is legally required. This DPA covers U.S. processing. Customer must not submit data requiring European or other international transfer mechanisms until the parties execute the applicable terms, such as standard contractual clauses.
12. Conflict and contact
This DPA controls over conflicting Agreement terms concerning its subject. Liability is subject to the Agreement unless law prohibits that allocation. Data-protection questions may be sent to hello@revenuecallout.com.