This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (“Controller”) and Figment Imaginative, which operates CoveCall (“Processor,” “we”), and applies where and to the extent we process Personal Data on your behalf in providing the Service. Where there is a conflict, this DPA prevails over the Terms with respect to the processing of Personal Data. Capitalized terms not defined here have the meaning given in the Terms or in applicable data-protection law (including the GDPR, UK GDPR, and U.S. state privacy laws).
1.Roles and instructions
You are the Controller (or “business”) of the Personal Data contained in the calls we handle, and CoveCall is the Processor (or “service provider”). We process Personal Data only on your documented instructions — including as set out in the Terms, this DPA, and your use of the Service's configuration — unless required by law, in which case we will inform you unless legally prohibited.
We will notify you if, in our opinion, an instruction infringes applicable data-protection law.
2.Details of processing
Subject matter and nature: AI-powered answering, transcription, summarization, scheduling, and notification of your business calls. Purpose: to provide the Service. Duration: the term of your subscription plus any retention you configure and legally required retention.
Data subjects: your callers, your team members, and other individuals whose data is included in calls. Categories of Personal Data: phone numbers, call audio, transcripts, summaries, appointment/booking details, and any other information callers choose to provide. You must not use the Service to process special-category data except as strictly necessary and lawful.
3.Confidentiality
We ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and process the data only as needed to provide the Service.
4.Security measures
We implement and maintain appropriate technical and organizational measures to protect Personal Data, including encryption in transit and at rest, access controls and least-privilege, database row-level security, audit logging, multi-factor authentication, and prompt-injection defenses for the AI agent. We may update these measures provided they do not materially reduce the overall level of security.
5.Subprocessors
You provide general authorization for CoveCall to engage subprocessors (including hosting, telephony, voice/AI, payments, calendar, and email providers) to process Personal Data. Our current subprocessors are listed on our Subprocessors page.
We impose data-protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible for their performance. We will provide a mechanism to be notified of new subprocessors and a reasonable period to object on legitimate data-protection grounds before they begin processing your data.
6.International transfers
Where our processing involves transferring Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable.
7.Assistance to the Controller
Taking into account the nature of the processing, we will provide reasonable assistance to help you: respond to data-subject requests to exercise their rights; and meet your obligations for security, breach notification, data-protection impact assessments, and prior consultation. Where a data subject contacts us directly, we will refer them to you unless you instruct otherwise.
8.Personal-data breach notification
We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and will provide information reasonably available to help you meet your notification obligations, together with the measures we are taking to address the breach.
9.Return and deletion
Upon termination of the Service, or on your request, we will delete or return Personal Data in accordance with your retention configuration and instructions, and delete existing copies, except to the extent we are required by law to retain it.
10.Audits and information
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits — including by providing relevant certifications, reports, or a summary of our security measures, or, where reasonably required, an on-site audit no more than once per year (or as required by a supervisory authority).
11.U.S. state privacy terms
Where you are a “business” and we are a “service provider”/“processor” under the California Consumer Privacy Act (as amended) or other U.S. state privacy laws, we will process Personal Data only to provide the Service (the “business purpose”) and not: sell or share it; retain, use, or disclose it outside our direct business relationship with you; or combine it with data from other sources except as permitted by law. We certify that we understand and will comply with these restrictions.
12.Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.
13.Contact
Data-protection inquiries: dpo@covecall.com. Postal: Figment Imaginative, [registered mailing address to be inserted], United States.