Effective Date: May 14, 2026 Last Updated: May 14, 2026 Version: 2.0 Ansa Entity: Ansa LLC Customer: The business or other entity that accepts the Agreement ("Customer")
This Data Processing Addendum ("DPA") forms part of and supplements the applicable Master Services Agreement, Order Form, online Terms of Service, Statement of Work, or other written or electronic agreement governing Customer's use of Ansa's services (the "Agreement").
This DPA is entered into between Customer / Controller and Ansa / Processor. Customer and Ansa are each a "Party" and together the "Parties."
1. Definitions
1.1 Agreement
"Agreement" means the agreement governing Customer's use of the Services, including this DPA, applicable Terms of Service, Order Forms, Statements of Work, incorporated policies, and written amendments.
1.2 AI Voice Agent
"AI Voice Agent" means Ansa's automated voice agent that answers inbound calls, processes caller speech, generates spoken responses, qualifies leads, books appointments, and performs related call-handling functions.
1.3 Account Data
"Account Data" means Personal Data relating to Customer, Customer personnel, billing contacts, authorized users, and account administration, including business contact information, authentication data, support communications, billing metadata, and subscription status. Ansa generally Processes Account Data as an independent controller/business.
1.4 Affiliate
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.
1.5 Ansa-Controlled Data
"Ansa-Controlled Data" means Personal Data for which Ansa determines the purposes and means of Processing independently, including Account Data, Demo-Line Data, website visitor data, marketing prospect data, Security and Abuse Data, billing and payment-administration data, regulatory registration data, Ansa business records, Subscriber Records where Ansa determines purposes required for regulatory or carrier compliance, Flagged Retained Transcripts (see § 1.23), and aggregated or De-identified Data.
Ansa-Controlled Data is not Customer Personal Data and is not governed by the processor obligations in this DPA except where expressly stated.
1.6 Applicable Data Protection Laws
"Applicable Data Protection Laws" means privacy, data-protection, cybersecurity, breach-notification, consumer-protection, electronic-communications, wiretap, biometric, AI-disclosure, and similar laws applicable to Processing under the Agreement, including U.S. state privacy laws, CCPA/CPRA, wiretap/eavesdropping laws, BIPA/CUBI, and GDPR/UK GDPR/Swiss FADP where applicable.
1.7 Business Purpose
"Business Purpose" means the limited purposes for which Ansa Processes Customer Personal Data under the Agreement, including inbound call answering, AI call handling, lead qualification, booking, CRM/calendar synchronization, notifications, platform security, fraud prevention, debugging, support, legally required retention, Data Subject request assistance, prompt and classifier iteration as described in § 10.2, and De-identified or aggregated analytics.
1.8 Caller / Caller Data
"Caller" means an individual who contacts Customer's business line handled by Ansa.
"Caller Data" means Personal Data relating to Callers, including name, phone number, address, service-request details, transcript text, call metadata, booking details, and other information disclosed during a call. Caller Data does not include audio recordings because Ansa does not capture or retain a caller-audio file in its own systems (see § 8.1). Caller Data is Customer Personal Data unless collected through Ansa's public demo line or otherwise identified as Ansa-Controlled Data.
1.9 Customer Content
"Customer Content" means substantive content processed through the Services on Customer's behalf, including transient call audio (processed in real time; not retained as an audio file in Ansa's own systems), transcripts, booking records, call summaries, service-request descriptions, SMS messages sent on Customer's behalf, and Customer-provided business configuration content.
1.10 Customer Personal Data
"Customer Personal Data" means Personal Data Processed by Ansa on behalf of Customer in connection with the Services, including Caller Data, Customer Content, Customer-configured business information, and Customer-authorized integration data. It excludes Ansa-Controlled Data, Demo-Line Data, De-identified Data, Flagged Retained Transcripts, and data independently processed by third-party destinations after transmission at Customer's instruction.
1.11 Customer-Directed Destination
"Customer-Directed Destination" means a third-party service, account, CRM, calendar, job-management platform, or other destination selected, authorized, or configured by Customer to receive Customer Personal Data from the Services, such as a CRM, calendar, or scheduling system.
Customer-Directed Destinations are generally Customer's own processors, service providers, contractors, or independent third-party recipients, not Ansa Subprocessors, unless Ansa separately contracts with the entity to Process Customer Personal Data on Ansa's behalf.
1.12 Controller / Data Subject / Consumer
"Controller" means the entity that determines the purposes and means of Processing Personal Data. For Customer Personal Data, Customer is the Controller, Business, or equivalent role under Applicable Data Protection Laws.
"Data Subject" or "Consumer" means an identified or identifiable natural person whose Personal Data is processed.
1.13 De-identified Data
"De-identified Data" means data that cannot reasonably be linked to an identified or identifiable individual or household and that Ansa commits to maintain and use only in de-identified form, except to test safeguards.
1.14 Demo-Line Data
"Demo-Line Data" means Personal Data collected from individuals who call Ansa's public demo line or otherwise interact with Ansa for a product demonstration outside a Customer relationship. Demo-Line Data is Ansa-Controlled Data. It is Personal Data but is not Customer Personal Data under this DPA.
1.15 Personal Data / Personal Information
"Personal Data" or "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual, household, or device.
1.16 Personal Data Breach / Security Incident
"Personal Data Breach" or "Security Incident" means Ansa's reasonable determination, made in good faith and without undue delay following an initial credible indicator of compromise, that unauthorized access, disclosure, loss, alteration, or unlawful destruction of Customer Personal Data Processed by Ansa or its Subprocessors has occurred. "Confirmation" of a Personal Data Breach under § 15.1 means this reasonable determination; it does not require completion of full forensic investigation. In no event shall Ansa take longer than seven (7) calendar days from receipt of a credible initial indicator of compromise to reach a determination, except where (i) law enforcement directs a longer investigation period in writing or (ii) the additional time is necessary to determine the scope of the incident or to restore data-system integrity, in which case Ansa will document the basis for the extension.
"Reasonable suspicion" of a Personal Data Breach means an indicator of compromise that, in Ansa's good-faith assessment, has more-likely-than-not implications for Customer Personal Data.
A Personal Data Breach does not include unsuccessful access attempts, blocked scans, denial-of-service attempts, or other events that do not result in unauthorized access to Customer Personal Data.
1.17 Processing
"Processing" means any operation performed on Personal Data, including collection, recording, storage, transcription, retrieval, use, disclosure, transmission, redaction, erasure, deletion, or destruction.
1.18 Processor / Subprocessor
"Processor" means an entity that Processes Personal Data on behalf of a Controller. For Customer Personal Data, Ansa acts as Processor, Service Provider, Contractor, or equivalent role.
"Subprocessor" means a third-party processor engaged by Ansa to Process Customer Personal Data on behalf of Customer in connection with the Services.
Downstream telecommunications carriers, PSTN providers, SMS aggregators, mobile network operators, numbering administrators, and similar regulated transmission providers used to route voice calls or SMS messages are not Subprocessors for purposes of this DPA, even if they incidentally transmit or process communications in the ordinary course of regulated telecommunications delivery.
Customer-Directed Destinations are not Ansa Subprocessors unless separately listed as such.
1.19 Security and Abuse Data
"Security and Abuse Data" means data processed by Ansa to secure the Services, prevent fraud, detect abuse, enforce the Agreement, investigate incidents, prevent call-pumping or SMS abuse, detect prompt injection, monitor unauthorized access, and protect Ansa, Customer, Callers, and Subprocessors.
1.20 Sensitive Data
"Sensitive Data" means Personal Data classified as sensitive under Applicable Data Protection Laws, including health information, biometric identifiers, precise geolocation, government identifiers, account credentials, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic data, children's data, and similar categories. Caller transcripts may contain Sensitive Data if Callers voluntarily disclose it.
1.21 Services
"Services" means Ansa's AI voice-agent SaaS platform and related services, including inbound call answering, transient real-time speech processing, call transcription, lead qualification, booking, CRM/calendar synchronization, notifications, dashboard, analytics, export, deletion support, and technical support.
The Services do not capture or retain audio recordings of calls in Ansa's own systems. Real-time audio is streamed to and processed by Ansa's AI Subprocessor to enable conversation and transcription; Ansa captures, retains, or makes available for replay no audio file of the call. Ansa's AI Subprocessor may retain call inputs and outputs (including audio-derived content) for a limited period for abuse and misuse monitoring, as described in § 8.1 and § 10.3.
The Services are designed for inbound call handling and are not emergency, 911, dispatch, life-safety, professional-advice, or guaranteed-booking services.
1.22 Subscriber Records
"Subscriber Records" means telephony, SMS, DID provisioning, A2P 10DLC, STIR/SHAKEN, KYC, regulatory, carrier, or similar records associated with Customer's use of phone numbers, SMS, or carrier services.
1.23 Flagged Retained Transcript
"Flagged Retained Transcript" means a transcript that Ansa has designated for retention beyond the 30-day operational window described in § 8.3 for the purpose of prompt and classifier iteration under § 10.2. At the time of designation, Caller name, phone number, and address are redacted from the transcript, and the resulting redacted record is treated as Ansa-Controlled Data (Service Data) and is no longer Customer Personal Data.
2. Roles of the Parties
2.1 Customer as Controller
For Customer Personal Data, Customer is the Controller, Business, or equivalent role and determines the purposes and lawful basis for Processing, including call handling, notices, consent, transcription, AI disclosure, integrations, retention settings, and Data Subject responses.
2.2 Ansa as Processor / Service Provider / Contractor
For Customer Personal Data, Ansa acts as Processor, Service Provider, Contractor, or equivalent role. Ansa shall Process Customer Personal Data only:
- to provide, secure, support, and maintain the Services as permitted by this DPA;
- according to Customer's documented instructions;
- as required by Applicable Data Protection Laws; or
- as otherwise expressly permitted by this DPA (including the prompt and classifier iteration described in § 10.2).
This DPA is intended to satisfy service-provider, contractor, and processor contract requirements under CCPA/CPRA and other U.S. state privacy laws.
2.3 Ansa as Independent Controller for Excluded Data
Ansa acts as an independent Controller/Business for Ansa-Controlled Data, including Account Data, billing records, Security and Abuse Data, Demo-Line Data, Subscriber Records where Ansa determines regulatory or carrier-compliance purposes, Ansa legal and business records, Flagged Retained Transcripts (created under § 1.23), aggregated data, and De-identified Data.
Demo-Line Data is governed by Ansa's Privacy Policy. If a demo-line caller later becomes a Customer, historical Demo-Line Data does not automatically become Customer Personal Data unless Ansa and the individual agree to link it to the Customer account.
2.4 No Sale or Sharing of Customer Personal Data
Ansa shall not sell or share Customer Personal Data as those terms are defined under CCPA/CPRA. Ansa shall not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by this DPA, the Agreement, or Applicable Data Protection Laws.
2.5 No Cross-Context Behavioral Advertising
Ansa shall not use Customer Personal Data for cross-context behavioral advertising, targeted advertising, or data-broker purposes.
2.6 Training and Model-Improvement Restrictions
Training and model-improvement restrictions are set out in § 10.
3. Scope of this DPA
3.1 Subject Matter
This DPA applies to Ansa's Processing of Customer Personal Data to provide an AI-powered inbound voice-agent service for U.S. businesses.
3.2 Covered Processing
Covered Processing includes receiving inbound calls, routing through telephony and AI infrastructure, transient real-time speech processing, transcript generation, call-detail extraction, booking, CRM/calendar synchronization, notifications, dashboard display, support, debugging, security monitoring, fraud prevention, export, deletion, correction, portability assistance, aggregation, de-identification, prompt and classifier iteration as described in § 10.2, and audit logging.
3.3 Excluded Processing
This DPA does not apply to Demo-Line Data, Ansa marketing leads unrelated to a Customer account, website analytics, Ansa personnel data, payment details Ansa never receives in raw form, Flagged Retained Transcripts (which are Ansa-Controlled Data after redaction), or third-party systems independently controlled by Customer.
3.4 Categories of Data Subjects
Customer Personal Data may relate to Callers, Customer employees, owners, administrators, authorized users, CRM or calendar contacts, and other individuals whose information is provided during inbound calls.
3.5 Categories of Customer Personal Data
Customer Personal Data may include identifiers, service-request details, transient call audio (processed in real time; not retained as an audio file in Ansa's own systems), communications content, transcripts, summaries, call metadata, booking data, Customer configuration data, CRM credentials or tokens, and audit logs. Customer Personal Data may include Sensitive Data if disclosed by Callers.
3.6 Jurisdictional Scope
This DPA is designed primarily for U.S. customers and U.S. callers. Ansa is not currently marketed as a GDPR-targeted product. If Customer is subject to GDPR, UK GDPR, Swiss FADP, or similar non-U.S. data protection laws, Customer must notify Ansa before using the Services and the Parties must execute any required supplementary terms.
3.7 Customer-Directed Destinations and CRM Integrations
When Customer enables a CRM, job-management, or calendar integration, Customer instructs Ansa to transmit specified Customer Personal Data to Customer's account with the selected platform. Customer-Directed Destinations are not Ansa Subprocessors unless separately identified. Customer is responsible for: selecting and authorizing the destination; ensuring agreements are in place; configuring fields and permissions; managing retention/deletion; responding to Data Subject requests for data stored there; and ensuring the destination's processing complies with Applicable Data Protection Laws.
4. Customer Instructions and Lawfulness
4.1 Documented Instructions
Customer instructs Ansa to Process Customer Personal Data as necessary to provide the Services, as described in the Agreement, this DPA, Customer's configuration, integration settings, written instructions, and applicable law. The Agreement and this DPA constitute Customer's documented instructions.
4.2 Refusal of Unlawful Instructions
If Ansa reasonably believes Customer's instruction violates Applicable Data Protection Laws or materially increases legal or security risk, Ansa may notify Customer, request clarification, suspend affected Processing, disable an affected feature, or terminate the affected Service if the issue cannot reasonably be resolved.
4.3 Customer Responsibility for Lawful Instructions
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Laws, Customer notices, consent requirements, transcription laws, AI-disclosure laws, biometric laws, telephony/SMS rules, and Sensitive Data restrictions.
Ansa may provide done-for-you onboarding, configuration assistance, recommended scripts, or operational guidance, but Customer remains responsible for approving its configuration, disclosures, lawful basis, and use of the Services.
5. Details of Processing
The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex I.
6. CCPA/CPRA Service Provider and Contractor Terms
This Section is intended to satisfy CCPA/CPRA service-provider and contractor requirements under Cal. Civ. Code §§ 1798.100, 1798.140, and implementing regulations at 11 CCR § 7050 et seq. Citations to specific subsections (including § 1798.140(ag) and (j)) reflect Ansa's understanding as of this DPA's Effective Date; Customer acknowledges that CCPA/CPRA regulations have been periodically revised by the California Privacy Protection Agency and that the substantive certifications below apply regardless of subsection renumbering.
6.1 Limited and Specified Business Purposes
Ansa shall Process Customer Personal Data only for the limited and specified Business Purposes described in the Agreement, this DPA, and Annex I, including inbound call answering, AI voice-agent operation, transcription, lead qualification, booking, notifications, Customer dashboard functionality, CRM/calendar synchronization at Customer's direction, support, troubleshooting, security, fraud prevention, audit logging, legal compliance, retention, deletion, de-identification, prompt and classifier iteration as described in § 10.2, and use of De-identified Data.
6.2 No Sale or Sharing
Ansa shall not sell or share Customer Personal Data. Ansa's use of authorized Subprocessors to provide the Services is not a sale or sharing if the Subprocessor is bound by written data-processing terms consistent with this DPA.
6.3 No Retention, Use, or Disclosure Outside Business Purpose
Ansa shall not retain, use, or disclose Customer Personal Data for any purpose other than performing the Services, the Business Purposes described in this DPA (including the prompt and classifier iteration described in § 10.2), legal compliance, security, fraud prevention, debugging, Data Subject request assistance, or purposes otherwise permitted for service providers/processors under Applicable Data Protection Laws.
6.4 No Retention, Use, or Disclosure Outside Direct Business Relationship
Ansa shall not retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and Ansa except as permitted by Applicable Data Protection Laws.
6.5 No Combining Except as Permitted
Ansa shall not combine Customer Personal Data with Personal Data from other sources except as permitted under CCPA/CPRA service-provider rules, to detect security incidents or fraud, to debug or repair functionality, to provide services to Customer, or where data has been De-identified or aggregated.
6.6 Certification of Compliance
Ansa certifies that it understands the restrictions set forth in the CCPA/CPRA service-provider and contractor provisions and implementing regulations, and will comply with them. Ansa further certifies it understands and will comply with the restrictions in this Section 6 and the applicable service-provider and contractor restrictions under CCPA/CPRA.
6.7 Same Level of Privacy Protection; Notice of Inability to Comply
Ansa shall comply with all obligations applicable to service providers and contractors under the CCPA/CPRA and implementing regulations. Ansa shall provide at least the same level of privacy protection for Customer Personal Data as required of Customer under Applicable Data Protection Laws, to the extent applicable to Ansa's role. Ansa shall notify Customer if Ansa determines it can no longer meet its obligations under this DPA.
6.8 Customer Monitoring and Remediation
Customer may take reasonable and appropriate steps to ensure Ansa Processes Customer Personal Data consistently with Customer's obligations, using the audit mechanisms in Section 17. Upon discovery of unauthorized Processing, Ansa shall take reasonable steps to stop and remediate it.
6.9 Customer Right to Stop and Remediate
Upon notice of unauthorized Processing, Customer may, in addition to the audit rights in § 17, take reasonable and appropriate steps to stop and remediate such unauthorized Processing, and Ansa shall cooperate in good faith with such steps.
7. U.S. State Processor Clauses
7.1 State-Law Processor Contract Incorporation
To the extent applicable, this DPA is intended to satisfy processor-contract requirements under U.S. state comprehensive privacy laws, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, New Hampshire, New Jersey, Montana, Iowa, Florida (where thresholds met), and substantially similar laws. Ansa adopts core processor-contract protections as contractual commitments even where a specific law may not apply.
7.2 Processor Obligations
Ansa shall Process Customer Personal Data only on Customer's documented instructions, ensure personnel confidentiality, maintain reasonable security measures, assist with consumer rights requests, assist with required assessments and breach obligations, make compliance information reasonably available, return or delete Customer Personal Data as required, bind Subprocessors to equivalent obligations, allow reasonable audits or provide independent assessment materials, and notify Customer if Ansa can no longer comply.
7.3 Customer Obligations
Customer shall provide required notices, establish lawful basis or consent, satisfy sensitive-data, biometric-data, transcription, and AI-disclosure obligations, respond to Data Subject requests, determine whether assessments are required, and avoid unlawful instructions.
8. Transcription, AI Disclosure, and Biometric Data
8.1 No Audio Recording
Ansa does not capture, store, or play back audio recordings of calls in its own systems. Real-time audio is streamed to and processed by Ansa's AI Subprocessor (currently the OpenAI API, Realtime API or successor models/services; see § 10.3) to enable conversation and transcription; Ansa captures, retains, or makes available for replay no audio file of the call. Because Ansa creates and stores no audio recording, Customer is not required to obtain consent for audio recording by Ansa.
Ansa's AI Subprocessor may, however, retain call inputs and outputs (including audio-derived content) for up to thirty (30) days for abuse and misuse monitoring, unless a longer retention period is required by law; the AI Subprocessor's human review of such content is limited to abuse and misuse investigation by authorized personnel and is not used for model training (see § 10.3). This provider-side abuse-monitoring retention is distinct from, and does not create, an Ansa-held audio recording.
8.2 Transcription Used for Core Service
The Services rely on real-time audio processing and transcript generation to perform call handling, lead qualification, booking, summaries, operational review, and support. Operational transcripts are retained with full PII for up to 30 days, then deleted by default. Ansa may designate specific transcripts as Flagged Retained Transcripts (see § 1.23 and § 10.2) before deletion, in which case Caller name, phone number, and address are redacted at the time of designation and the redacted record is retained as Service Data.
8.3 Transcript-as-Recording Issue
Whether automated speech-to-text transcription of a telephone call, without audio retention, constitutes "recording," "interception," "eavesdropping," or equivalent regulated conduct under Cal. Penal Code § 632 or other all-party-consent laws is unsettled and may vary by jurisdiction.
Pending definitive legal guidance, Customer acknowledges that:
- Ansa treats transcripts as call-content records for privacy, retention, and consent-design purposes in strict notice and all-party-consent jurisdictions;
- real-time transcription is a core processing operation;
- Customer is responsible for determining whether caller consent is required;
- where legally required, Customer must use Ansa-provided or Customer-approved disclosure flows;
- Ansa may modify disclosure flows to address emerging legal requirements; and
- Ansa may decline to process calls in jurisdictions or configurations that present unacceptable legal risk.
8.4 Customer Responsibility for Caller Notice and Consent
Customer is responsible for obtaining all legally required notices and consents from Callers, including for AI disclosure, transcription, biometric processing, Sensitive Data, SMS follow-up, and CRM/calendar sharing. Ansa may provide configurable scripts and controls, but Customer remains responsible for legal sufficiency.
8.5 AI Bot and Artificial Voice Disclosure
Ansa's standard practice, regardless of whether any specific AI-disclosure statute is interpreted to apply to Ansa's inbound voice-agent service, is to disclose clearly at the start of each call that the Caller is interacting with an AI assistant. The default disclosure script is set out in the Agreement (Terms of Service § 9.2) and is delivered by Ansa's runtime via a state-aware waterfall (per-DID override → ANI area-code-to-state inference → default).
Where Customer operates in a jurisdiction with specific AI-disclosure, bot-disclosure, automated-voice, or training-data-transparency obligations — including Cal. Bus. & Prof. Code § 22757 et seq. (AB 2013, effective Jan. 1, 2026) — Customer is responsible for confirming that the disclosure script meets those obligations and for instructing Ansa to modify the script if it does not.
The applicability to ordinary inbound voice telephony of California's online-bot disclosure statute (Cal. Bus. & Prof. Code §§ 17940–17943) and Cal. Pub. Util. Code § 2874 (as amended by AB 2905 (2022)) remains an unsettled question of law.
8.6 Biometric Data and Voiceprints
Ansa does not create, store, or use persistent voiceprints, speaker-identification profiles, speaker embeddings, or biometric authentication templates to identify or authenticate callers. The Services rely on third-party AI voice processing which may compute transient acoustic features as a necessary part of speech-to-text and response generation; whether such transient computation constitutes the creation of a regulated biometric identifier under the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq., especially 740 ILCS 14/15(b)), Texas Capture or Use of Biometric Identifier law (Tex. Bus. & Com. Code § 503.001), Washington biometric privacy law (RCW 19.375), or analogous statutes is an unsettled question of law that Ansa monitors and may address through Subprocessor diligence or product changes.
Ansa shall not create or store voiceprints or biometric identifiers for the purpose of uniquely identifying a Caller. Customer shall not use the Service for biometric identification, speaker verification, authentication, profiling, or voiceprint creation.
8.7 Customer Biometric Compliance
If Customer operates in a jurisdiction requiring biometric notice, written consent, or retention policies, Customer is responsible for determining whether AI voice processing or any Customer-enabled feature triggers those requirements.
9. De-identified and Aggregated Data
Ansa may create and use De-identified Data and aggregated data derived from Customer Personal Data for platform improvement, aggregate analytics, benchmarking, security, abuse prevention, performance monitoring, product planning, and aggregate reporting.
Ansa publicly commits to maintain and use De-identified Data only in de-identified form and not to attempt to re-identify De-identified Data, except solely to test whether Ansa's de-identification safeguards are effective. This commitment is intended to align with Cal. Civ. Code § 1798.140(m). Ansa shall maintain reasonable technical, organizational, and contractual safeguards designed to preserve de-identification and prohibit recipients from re-identifying disclosed De-identified Data.
Flagged Retained Transcripts (§ 1.23) are not the same as fully De-identified Data. Although Caller name, phone number, and address are redacted from a Flagged Retained Transcript, contextual details may remain. Ansa shall treat Flagged Retained Transcripts conservatively, restrict access to Ansa personnel performing prompt and classifier iteration, and shall not disclose them to third parties except to subprocessors who need them for that purpose under written confidentiality terms.
10. AI Training and Model Improvement
10.1 No Training on Customer Personal Data
Ansa shall not train, fine-tune, retrieval-augment, or otherwise use Customer Personal Data — including caller audio (whether processed transiently or persisted), transcripts, transcripts after redaction if the redacted record remains linkable to an individual, SMS bodies, and other Customer Content — to develop Ansa-owned models, third-party models, speaker-identification models, biometric-identifier models, or cross-customer AI systems, except with Customer's express written authorization and, where required by law, Caller consent.
This restriction applies to Ansa and is reflected in Ansa's contractual posture with its AI Subprocessor (§ 10.3). It does not extend to De-identified Data created under § 9 and used solely in accordance with § 10.2; nor does it extend to Flagged Retained Transcripts used solely for the prompt and classifier iteration described in § 10.2.
10.2 Permitted Service Improvement
Ansa may use the following data, and only the following data, to improve the Services:
- De-identified Data, aggregated data, operational metrics, prompt-performance metrics, classifier-accuracy metrics, and non-identifying service data;
- Transcripts retained during the 30-day operational window described in § 8.2, for the purpose of identifying edge cases where the AI agent mis-classified an intent, missed a booking field, mishandled a caller, or otherwise underperformed, and for updating Ansa's prompts, call flows, classification rules, and tool descriptions in response; and
- Flagged Retained Transcripts (§ 1.23) for the same purpose as (2) but on an ongoing basis after redaction.
The Service improvement permitted under this § 10.2 is product engineering with data — review, analysis, and revision of prompts and classifier rules by Ansa personnel — and does not include training, fine-tuning, retrieval-augmenting, or otherwise developing AI models, which remain prohibited under § 10.1.
10.3 AI Subprocessor
Primary AI Subprocessor. Ansa's primary AI Subprocessor is OpenAI OpCo, LLC (United States), accessed via the OpenAI API (Realtime API or successor models/services), under the OpenAI Data Processing Addendum (v.010126, effective January 1, 2026) together with OpenAI's applicable business, services, and usage terms (collectively, the "OpenAI Terms"), each as in force at the time of processing.
Under the OpenAI Terms: (a) OpenAI does not use API inputs or outputs to train or improve its models by default, and Ansa has not opted into any data-sharing arrangement that would permit such use; (b) OpenAI may retain API inputs and outputs (including audio-derived content) for up to thirty (30) days for abuse and misuse monitoring, unless a longer retention period is required by law, after which such data is deleted; and (c) OpenAI limits human review of API content to abuse and misuse investigation by authorized personnel (including confidentiality-bound contractors) and does not subject API content to human review for product or model improvement. This posture is contingent on Ansa's OpenAI organization operating under OpenAI's API and business terms and not opting into data sharing.
Standby / failover AI Subprocessor. Ansa's standby AI Subprocessor is Google LLC, accessed via the Google Gemini API on paid (billed) services, under the Data Processing Addendum for Products Where Google is a Data Processor and related Google terms applicable to paid services, each as in force at the time of processing. The failover subprocessor may Process Customer Personal Data (call audio and conversation text) only if and while the primary AI Subprocessor is unavailable. On Google's paid services: Google does not use Ansa's prompts or the responses to train or improve Google's products; Google logs prompts and responses only for a limited period and solely to detect and prevent violations of its Prohibited Use Policy and to maintain the safety and security of the services; and Google does not subject paid-services API content to human review for product improvement.
Ansa's no-training commitment in § 10.1 is supported, for the primary path, by OpenAI's default API data-usage policy and the OpenAI Data Processing Addendum, and, for the failover path, by the Google terms applicable to paid services. Either provider may amend its applicable terms on notice; Ansa monitors each provider's sub-processor list and terms — for the primary path, OpenAI's Sub-Processor List at https://platform.openai.com/subprocessors (which carries its own 30-day objection mechanics) — and will notify Customer of any amendment that materially weakens the no-training or retention position no later than thirty (30) days after the provider publishes the change, and Customer's rights under § 13.5 and § 25 apply.
11. Confidentiality
Ansa shall ensure that personnel authorized to Process Customer Personal Data are bound by contractual, statutory, or professional confidentiality obligations. Ansa shall limit access to personnel with a need to know and shall provide privacy and security training appropriate to personnel roles.
12. Security Measures
12.1 Security Program
Ansa shall implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature, scope, and risk of Processing Customer Personal Data. Current measures are described in Annex II.
12.2 Implementation Status
Annex II identifies implemented, Subprocessor-provided, configuration-dependent, and planned measures. Planned measures are not contractual commitments until deployed or confirmed in writing.
12.3 Current Measures
Ansa's current measures include TLS 1.2+ in transit; encryption at rest through managed providers; Supabase Postgres Row Level Security designed to enforce tenant isolation by account_id; scoped storage paths; encrypted storage for CRM credentials; short-lived scoped runtime tokens where implemented; avoidance of long-lived service-role keys in voice runtime; structured logging designed to redact or avoid PII; audit logging for administrative actions; environment-based secrets management; role-based access controls; default-delete of operational transcripts after 30 days; designation-based redaction for Flagged Retained Transcripts; and deletion processes following churn grace periods.
12.4 Logs and Credentials
Ansa shall use commercially reasonable efforts to prevent raw caller names, phone numbers, addresses, transcripts, and CRM secrets from being written to application logs. Customer is responsible for protecting Customer credentials and managing Customer-user access.
12.5 Security Not Absolute
Ansa's security measures are designed to reduce risk but do not guarantee that the Services are immune from all security incidents or unauthorized access.
13. Subprocessors
13.1 General Authorization
Customer grants Ansa general written authorization to engage Subprocessors to Process Customer Personal Data in accordance with this DPA.
13.2 Current Subprocessor List
Current Subprocessors are listed in Annex III and may also be published at Ansa's public subprocessor page: https://tryansa.ai/subprocessors.
13.3 Subprocessor Flow-Down
Ansa shall enter into a written agreement with each Subprocessor requiring it to Process Customer Personal Data only for services to Ansa, maintain confidentiality, implement reasonable security measures, assist with Data Subject requests, notify Ansa of Personal Data Breaches without undue delay, return or delete Customer Personal Data as required, and impose equivalent obligations on sub-subprocessors.
Each Subprocessor agreement shall require the Subprocessor to comply with applicable obligations under the CCPA/CPRA and implementing regulations, equivalent to those imposed on Ansa under this DPA.
Ansa remains responsible for Subprocessors' acts and omissions to the extent required by Applicable Data Protection Laws and the Agreement.
13.4 Notice of New Subprocessors
Ansa shall provide at least 30 calendar days' advance notice before engaging a new core Subprocessor or materially changing a Subprocessor's role in a way that affects Customer Personal Data. Where Ansa receives less than 30 days' notice of a sub-subprocessor change from an upstream Subprocessor, Ansa will notify Customer promptly upon receipt, and Customer's objection rights under § 13.5 shall apply to the period actually available.
13.5 Customer Objection
Customer may object to a new Subprocessor within 15 calendar days of notice on reasonable data-protection grounds. If Customer objects, the Parties shall work in good faith for up to 30 days to resolve. If unresolved, Ansa may avoid using the Subprocessor for Customer where feasible, propose an alternative, or allow Customer to terminate the affected Services without penalty and receive a pro-rata refund of any prepaid unused fees for the affected Service, subject to export and deletion terms in § 19.
13.6 Emergency Subprocessor Changes
Ansa may engage a replacement Subprocessor without advance notice if reasonably necessary for a security incident, outage, legal requirement, Subprocessor termination, or urgent risk. Ansa shall notify Customer as soon as reasonably practicable and, where feasible, within 24 hours after the emergency engagement decision. Ansa shall provide retroactive objection rights where feasible.
13.7 Telecommunications Providers
Customer acknowledges that voice and SMS communications are transmitted through regulated telecommunications networks and may pass through downstream PSTN carriers, mobile carriers, SMS aggregators, interconnect providers, numbering administrators, and similar entities. Such downstream providers are not Ansa Subprocessors and are not subject to the Subprocessor notice-and-objection process.
13.8 Customer-Directed Destinations Not Subprocessors
Customer-Directed Destinations (CRM, calendar, job-management) are not Ansa Subprocessors. Customer is responsible for its own agreements, notices, consents, and deletion workflows for those destinations.
13.9 Regulatory Registries Not Subprocessors
The Campaign Registry and similar A2P 10DLC, STIR/SHAKEN, numbering, carrier, or regulatory registries are not Subprocessors where they receive only brand, campaign, or regulatory information and not Caller Data.
14. Data Subject Rights Assistance
14.1 Customer as Primary Responder
Customer is responsible for receiving, verifying, and responding to Data Subject requests relating to Customer Personal Data.
14.2 Ansa Assistance
Ansa shall reasonably assist Customer in responding to requests to access, know, delete, correct, port, restrict, opt out, limit sensitive-data use, withdraw consent, or appeal a denial. Assistance may include self-service dashboard tools, search, export, deletion, redaction, metadata export, confirmation of deletion, and reasonable support escalation.
14.3 Self-Service First
Where Ansa makes self-service tools available, Customer shall use those tools as the primary method for responding to Data Subject requests. Manual Ansa assistance is an escalation path.
14.4 Direct Requests to Ansa
If Ansa receives a request directly from a Caller relating to Customer Personal Data, Ansa may direct the Caller to Customer, notify Customer, or act where legally required or authorized by Customer. For Demo-Line Data or Account Data, Ansa may respond directly as Controller/Business.
14.5 Deletion Limitations
Deletion may not apply to De-identified Data, aggregated analytics, Flagged Retained Transcripts (which are Ansa-Controlled Data after redaction), audit logs retained for compliance or security, backups pending ordinary lifecycle expiration, legal holds, data retained by Customer-controlled systems, or data retained by Subprocessors under legal, security, or abuse-monitoring obligations.
15. Personal Data Breach Notification
15.1 Notification Timeline
Confirmation notice. Upon confirmation (as defined in § 1.16) of a Personal Data Breach affecting Customer Personal Data, Ansa shall notify Customer without undue delay and, where feasible, no later than forty-eight (48) hours after confirmation.
Suspicion notice. Where Ansa has formed a reasonable suspicion (as defined in § 1.16) of a Personal Data Breach but has not yet confirmed it, Ansa will use commercially reasonable efforts to notify Customer of the suspicion within seventy-two (72) hours of forming the suspicion if the suspected breach involves (a) transcripts that have not yet been deleted, (b) CRM credentials or other access tokens held in Ansa's vault, (c) payment-card data or financial-account credentials of any Customer end-user, or (d) more than one hundred (100) affected Customer end-user records. The suspicion-notice path exists so that Customer's downstream regulatory timing obligations under state law (including the 30-day-from-discovery clock effective for California breaches on or after January 1, 2026, and the comparable New York SHIELD framework) are not impaired by Ansa's investigation timeline.
15.2 Content of Notice
Ansa's notice shall include, to the extent known and legally permitted, the nature of the breach, categories of Customer Personal Data affected, approximate number of affected Data Subjects or records, timing, known or likely consequences, mitigation steps, Subprocessor involvement, law-enforcement delay if applicable, recommended Customer steps, and Ansa contact information. Ansa may provide notice in phases.
15.3 Customer Responsibility for Data Subject and Regulator Notices
Customer is responsible for determining whether notice to Data Subjects, attorneys general, regulators, consumer reporting agencies, or others is legally required. Ansa shall reasonably cooperate.
15.4 Subprocessor Breaches
Ansa shall require Subprocessors to notify Ansa of Personal Data Breaches without undue delay and shall relay relevant information to Customer.
15.5 Encryption Safe Harbors
Where applicable state law provides a safe harbor or exception for encrypted data, Ansa will evaluate eligibility based on the facts of the incident, including whether encryption keys, credentials, or access controls were compromised. Ansa will not rely on an encryption safe harbor without reasonable factual and legal review.
15.6 No Admission
Ansa's notice of a Security Incident is not an admission of fault, liability, or violation.
15.7 Law Enforcement Delay
Ansa may delay notice where a law-enforcement agency determines that notification would impede a criminal investigation, consistent with applicable law.
16. DPIA, Risk Assessment, and Regulatory Assistance
Ansa shall reasonably assist Customer with data protection assessments, privacy impact assessments, transfer impact assessments, cybersecurity assessments, and similar documentation required by Applicable Data Protection Laws. Ansa may provide Annex I, Annex II, Subprocessor information, data-flow summaries, retention information, available security summaries, and reasonable questionnaire responses.
Ansa shall reasonably assist Customer in responding to regulator inquiries relating to Ansa's Processing of Customer Personal Data.
17. Audit Rights
17.1 Audit Scope
Customer may audit Ansa's compliance with this DPA no more than once per calendar year, unless a Personal Data Breach affecting Customer has occurred, a regulator requires an audit, Ansa materially breaches this DPA, or Applicable Data Protection Laws require more frequent assessment.
17.2 Audit Method
Audits may be satisfied by Ansa's questionnaire responses, policy summaries, security reports or certifications when available, remote audit meetings, and on-site audit only where reasonably necessary.
17.3 Audit Conditions
Audits must be conducted on at least 30 days' prior written notice except urgent regulatory or breach audits, occur during normal business hours, not unreasonably disrupt Ansa, remain subject to confidentiality, exclude other customers' data, and avoid production-system access except where strictly necessary.
17.4 Audit Costs and Remediation
Customer bears its audit costs and shall reimburse Ansa's reasonable costs for direct audits unless the audit reveals Ansa's material breach. If an audit identifies material non-compliance, Ansa shall provide a commercially reasonable remediation plan and timeline.
17.5 SOC 2 Roadmap
Ansa is pursuing SOC 2 Type II audit readiness. Upon completion, Ansa will make the audit report available to Customers under reasonable confidentiality terms.
18. Government, Law Enforcement, and Third-Party Requests
18.1 Notice to Customer
If Ansa receives a subpoena, warrant, court order, civil discovery request, regulator request, law-enforcement request, or other third-party demand for Customer Personal Data, Ansa shall notify Customer unless legally prohibited, impracticable due to emergency, or the request relates to Ansa-Controlled Data.
18.2 Opportunity to Object
Where legally permitted, Ansa shall provide Customer a reasonable opportunity to seek protective treatment, object, narrow the request, or otherwise respond before Ansa discloses Customer Personal Data.
18.3 Minimization
Ansa shall disclose only the Customer Personal Data reasonably required to comply with the request.
18.4 Emergency Requests
Ansa may disclose Customer Personal Data without prior notice if Ansa reasonably believes disclosure is necessary to prevent death, serious physical harm, fraud, security compromise, or unlawful activity, or where legally required.
19. Return and Deletion
19.1 During Term
Upon Customer's written instruction, Ansa shall delete or return Customer Personal Data, subject to technical feasibility, legal retention obligations, security and fraud-prevention needs, audit-log retention, backup lifecycle, Subprocessor limitations, and preservation obligations.
19.2 Termination
Upon termination or expiration of the Agreement, Customer may request export of Customer Personal Data during the 30-day grace period. After the grace period, Ansa shall delete Customer Personal Data in accordance with Annex I and Ansa's retention schedule.
19.3 Retention Exceptions
Ansa may retain audit logs, billing records, records necessary for legal compliance, records subject to legal hold, De-identified Data, Flagged Retained Transcripts (which are Ansa-Controlled Data after redaction), aggregated analytics, backup copies until overwritten, Security and Abuse Data, Subscriber Records, and data Ansa is required or permitted to retain as an independent controller.
19.4 Audit-Log Retention Schedule
Ansa uses a tiered audit-log retention schedule:
| Log Category | Retention |
|---|---|
| Debug/trace logs | 30 days |
| Application logs (PII redacted) | 90 days |
| Routine operational/admin logs (no caller PII) | 36 months |
| Authentication and access logs | 36 months |
| Configuration-change logs | 36 months |
| Data export, deletion, DSAR, subprocessor-change, consent-event logs | 5 years |
| Credential rotation / security-critical events | Credential life + 1 year, minimum 3 years |
| Confirmed breach / incident investigation | 7 years or legal-hold duration |
| Billing and tax records | 7 years |
| Legal hold | Until released |
Logs shall not intentionally contain raw caller content, full transcripts, raw CRM secrets, or raw payment card data.
19.5 Backups
Deleted Customer Personal Data may remain in backups for a limited period under ordinary backup cycles. Ansa shall not restore deleted data except as required for disaster recovery, legal compliance, security investigation, or Customer-authorized restoration.
19.6 Deletion Certification
Upon Customer's reasonable request, Ansa shall provide written confirmation that deletion or de-identification has been completed, subject to retention exceptions.
19.7 Data Export Formats
Ansa may provide data exports in machine-readable formats such as CSV, JSON, TXT, PDF, or ZIP bundles, depending on the data type and retention status.
20. International Transfers and Data Residency
20.1 Primary U.S. Infrastructure
Ansa's primary infrastructure is configured for U.S.-oriented processing where available, including database, storage, telephony, and application infrastructure. Ansa's primary AI Subprocessor (the OpenAI API) offers customer-selectable data residency for certain services; Ansa has not currently enabled a region-pinned configuration, so no U.S.-only processing guarantee is given for AI processing except where agreed in a signed Order Form or DPA amendment. OpenAI, and any failover AI Subprocessor, may accordingly process prompts, responses, and transient audio outside any particular U.S. region.
20.2 No Strict U.S.-Only Warranty
Ansa shall not represent that all Processing is strictly U.S.-only unless relevant Subprocessors provide written contractual commitments confirming U.S.-only Processing for all relevant data categories.
Ansa's customer-facing data-location statement is:
"Ansa's primary infrastructure is configured in U.S. regions where available. Ansa's primary AI Subprocessor (the OpenAI API) offers customer-selectable data residency for certain services, but Ansa has not currently enabled a region-pinned configuration; the AI Subprocessor may therefore process prompts, responses, and transient audio outside any particular U.S. region, and certain operational functions (abuse monitoring, support operations, infrastructure failover, including any failover AI provider) may process data through infrastructure not fully controlled by Ansa. Ansa does not guarantee strict U.S.-only processing unless expressly stated in a signed order form or data residency addendum."
20.3 Subprocessor Retention, Routing, and Abuse Monitoring
Certain AI, telephony, hosting, and infrastructure providers may retain prompts, contextual information, outputs, logs, metadata, or related records for security, safety, abuse monitoring, debugging, service integrity, or legal compliance.
20.4 GDPR / UK GDPR Transfers
If GDPR, UK GDPR, Swiss FADP, or similar transfer restrictions apply, Customer shall notify Ansa before using the Services for GDPR-regulated Personal Data, and the Parties shall execute appropriate transfer mechanisms, including the EU Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, UK International Data Transfer Addendum or UK IDTA, Swiss addendum, supplementary measures, and transfer impact assessment where required.
Until such terms are executed, Customer shall not use the Services for GDPR-regulated Personal Data unless Ansa has agreed in writing.
21. Customer Responsibilities
Customer shall:
- provide required notices at or before collection;
- obtain lawful basis or consent for Processing;
- comply with transcription, AI-disclosure, biometric, telephony, and SMS laws;
- ensure Customer's privacy policy accurately describes Ansa's role and subprocessors where required;
- respond to Data Subject requests;
- maintain its own CRM, calendar, and subcontractor compliance;
- not use the Services for outbound telemarketing unless specifically authorized by Ansa in writing and lawful under applicable telephony and consumer-protection laws;
- not collect regulated data categories through Ansa unless agreed in writing, including HIPAA PHI, financial account credentials, children's data, or regulated advice data;
- configure state-specific disclosures accurately; and
- indemnify Ansa for claims arising from Customer's unlawful instructions, failure to provide notices or obtain consents, or misuse of the Services, subject to § 23.
Customer shall use the Services only for inbound call handling unless Ansa expressly authorizes another use in writing. Customer shall not use the Services for emergency, 911, dispatch, life-safety, medical, legal, financial, or other regulated professional-advice purposes. Customer acknowledges that AI outputs, summaries, classifications, escalation decisions, and bookings may be incomplete or inaccurate and must be reviewed as appropriate for Customer's business.
22. Ansa Responsibilities
Ansa shall Process Customer Personal Data only as instructed, maintain confidentiality and security obligations, provide the service-provider and processor commitments in this DPA, use Subprocessors only as authorized, provide reasonable assistance with consumer rights and regulatory requests, notify Customer of confirmed Personal Data Breaches, return or delete Customer Personal Data as required, not sell or share Customer Personal Data, not use Customer Personal Data for targeted advertising or unrelated marketing, not use Customer Personal Data to build individual consumer profiles for other customers, not use Customer Personal Data to train AI models except as permitted under § 10, and maintain a Subprocessor list and change-notice process.
23. Liability and Indemnity
23.1 Allocation of Regulatory Responsibility
Customer is responsible for controller obligations, including notices, lawful basis, consent, Data Subject responses, emergency/non-emergency use decisions, and legally required consumer or regulator notifications. Ansa is responsible for processor obligations under this DPA and Applicable Data Protection Laws applicable to processors/service providers.
23.2 Mutual Indemnity
Each Party shall indemnify, defend, and hold harmless the other Party from third-party claims, regulatory fines, penalties, damages, and reasonable attorneys' fees arising from the indemnifying Party's: material breach of this DPA; violation of Applicable Data Protection Laws; gross negligence, willful misconduct, or fraud; unauthorized Processing.
23.3 Customer Indemnity
Customer shall indemnify Ansa for claims arising from: Customer's failure to provide required caller notices; failure to obtain transcription, AI, biometric, or sensitive-data consents; use of Ansa in violation of law; CRM provider or other Customer-controlled integration; unlawful instructions.
23.4 Ansa Indemnity
Ansa shall indemnify Customer for claims arising from: Processing outside Customer's documented instructions; failure to implement required security measures; failure to bind Subprocessors as required; sale or sharing of Customer Personal Data in violation of this DPA; training of AI models on Customer Personal Data in violation of § 10.1; Ansa's own confirmed Personal Data Breach caused by Ansa's failure to comply with this DPA.
23.5 Liability Cap
Unless the Agreement states otherwise, liability under this DPA is subject to the Agreement's limitation of liability, except that exclusions for fraud, willful misconduct, confidentiality breaches, indemnity obligations, or violations that cannot be limited by law shall apply as stated in the Agreement.
23.6 No Limitation Where Prohibited
Nothing in this DPA limits liability to the extent such limitation is prohibited by Applicable Data Protection Laws.
24. Order of Precedence
If there is a conflict among documents:
- this DPA governs data protection, privacy, security, breach notification, and data-processing matters;
- the Agreement governs commercial, payment, service, and general liability matters unless expressly modified by this DPA;
- Annexes govern the subject matter of each Annex; and
- Standard Contractual Clauses, if executed, prevail where required by law.
25. Amendments
Ansa may update this DPA to reflect changes in Applicable Data Protection Laws, Subprocessor changes, security improvements, product changes, or operational changes, provided changes do not materially reduce Customer's protections without notice.
Ansa shall provide at least 30 days' notice of material changes where feasible. Non-material updates, such as corrected citations, formatting, contact information, or Subprocessor URL updates, may be made without prior notice. If Ansa materially reduces Customer's rights and Customer reasonably objects, Customer may terminate the affected Service before the update takes effect and receive any pro-rata refund required by the Agreement, unless the change is required by law or necessary for security or service continuity.
26. Term and Survival
This DPA begins on the Effective Date and remains in effect for the duration of the Agreement and for as long as Ansa Processes Customer Personal Data.
Sections relating to confidentiality, security, audit logs, liability, indemnity, De-identified Data, Flagged Retained Transcripts, legal compliance, and deletion/return survive termination as necessary.
Annex I — Details of Processing
| Field | Description |
|---|---|
| Subject matter | AI voice-agent SaaS for inbound business calls. |
| Duration | Term of Agreement plus retention and deletion periods. |
| Nature of Processing | Inbound call answering; transient real-time audio processing (no audio file retained by Ansa; AI Subprocessor may retain call inputs/outputs up to 30 days for abuse monitoring per § 8.1); transcription; summarization; storage of transcripts and call metadata; booking; notification; export; redaction; deletion; security monitoring; audit logging; and prompt and classifier iteration under DPA § 10.2. |
| Purpose | Inbound call answering, lead qualification, booking workflow, non-emergency escalation, spam detection, appointment scheduling, CRM/calendar updates, owner notifications, dashboard display, support, troubleshooting, security, fraud prevention, compliance, prompt and classifier iteration, and De-identified analytics. |
| Data Subjects | Callers, Customer business users, Customer administrators, Customer employees, and Ansa operators in audit logs. |
| Caller Data | Name, phone number, address, service request, transcript, preferred appointment time, call outcome, emergency/spam classification, area-code inference, timestamps, duration, booking metadata, and consent-event metadata. |
| Customer Business Data | Business name, owner/admin contact information, business address, billing status, encrypted CRM credentials, operating state, services offered, business hours, and knowledge-base content. |
| Operational Data | Support tickets, audit logs, access logs, configuration changes, credential rotation records, export events, and deletion events. |
| Sensitive Data | Not intentionally collected; may be incidentally disclosed by Callers, including health, precise location, financial hardship, or children's data. |
| Retention | Caller PII transcripts: up to 30 days, then deleted by default (DPA § 8.2). Ansa may designate specific transcripts as Flagged Retained Transcripts under § 1.23 / § 10.2; designation triggers redaction (Caller name, phone number, address) and the redacted record is retained as Service Data. No audio recordings are captured or stored by Ansa; the AI Subprocessor may retain call inputs and outputs for up to 30 days for abuse monitoring (DPA § 8.1, § 10.3). Churn grace: 30 days (DPA § 19.2). Audit logs: tiered per § 19.4 (no caller PII in routine operational logs by design). De-identified Data: indefinite. Demo-Line Data: governed by Privacy Policy, not this DPA (§ 2.3). |
| Subprocessors | See Section 13 and Annex III; public list at https://tryansa.ai/subprocessors. |
| International transfers | Primary U.S.-oriented architecture; primary AI Subprocessor (the OpenAI API) offers customer-selectable data residency for certain services but Ansa has not enabled a region-pinned configuration, so the AI Subprocessor (and any failover AI provider) may process outside any particular U.S. region. No absolute U.S.-only warranty for all Subprocessors unless expressly agreed. |
Annex II — Technical and Organizational Measures
Ansa maintains reasonable technical and organizational measures appropriate to the Services and Processing risk. Measures may be Implemented, Subprocessor-provided, Configuration-dependent, or Planned / Not active. Planned measures are not contractual commitments unless confirmed in writing.
Current measures include:
- Encryption and transport security: TLS 1.2+ for data in transit; HTTPS for dashboards and APIs; encryption at rest through infrastructure providers; encrypted storage for CRM credentials.
- Tenant isolation: Supabase Postgres Row Level Security,
account_idscoping, scoped storage paths, and dashboard access controlled by account membership. - Authentication and authorization: Supabase Auth, role-based access controls, least-privilege operator access, credential rotation support, and short-lived per-call scoped JWTs where technically feasible.
- Logging and monitoring: audit logs for administrative actions, export events, deletion events, credential rotations, access events, and configuration changes; structured logging designed to redact or avoid PII. Audit-log retention durations are set out in DPA § 19.4.
- Data minimization: collection limited to call handling and booking; no audio recording; transcript deletion at 30 days by default; redaction of Caller name, phone number, and address at the time a transcript is designated as a Flagged Retained Transcript; no intentional plaintext logging of CRM credentials; no raw payment card data handled by Ansa.
- Secure deletion: scheduled purge jobs, deletion of transcripts after the operational retention period, tenant-data deletion after churn grace period, and backup lifecycle deletion through infrastructure providers.
- Incident response: triage, containment, credential rotation, Subprocessor coordination, Customer notification process, and remediation tracking.
- Personnel controls: confidentiality obligations, limited operator access, periodic access review, and privacy/security training.
- Subprocessor controls: written contracts or online DPAs with core Subprocessors, public or customer-accessible Subprocessor list, change notice and objection process, and reasonable vendor security review.
Planned or developing measures may include SOC 2 Type II reports, formal annual penetration testing, expanded MFA requirements, immutable audit storage, dual-approval workflows for sensitive operations, enhanced monitoring integrations, and multi-region failover. Ansa shall not materially reduce implemented security measures protecting Customer Personal Data without providing notice where required.
Annex III — Subprocessors
Current Subprocessors may also be listed at https://tryansa.ai/subprocessors. The public list controls for operational updates unless an Order Form states otherwise.
| Subprocessor | Purpose | Data Processed | Notes | Status / Role |
|---|---|---|---|---|
| Telnyx | SIP, DID provisioning, SMS, telephony routing | Audio stream (transit only), phone numbers, SMS content and recipients, call metadata | Telephony routing depends on carrier networks; downstream carriers are not Ansa Subprocessors. Telnyx's role as processor / independent controller is governed by the Telnyx DPA in force at Ansa's account; Ansa retrieves and reviews this DPA at least annually. | Core |
| OpenAI OpCo, LLC (OpenAI API — Realtime API) | Real-time AI speech processing (primary) | Transient audio stream, prompts, tool parameters, outputs, call context | No training on API data by default; OpenAI may retain API inputs/outputs (including audio-derived content) up to 30 days for abuse monitoring unless longer retention is required by law; human review limited to abuse/misuse investigation. Governed by the OpenAI Data Processing Addendum (v.010126) and OpenAI's applicable business/services/usage terms. Customer-selectable data residency offered but not currently enabled by Ansa. | Core |
| Google LLC (Gemini API — paid services) | Real-time AI speech processing (standby / failover) | Transient audio stream, prompts, tool parameters, outputs, call context — only if and while the primary AI Subprocessor is unavailable | Engaged only on failover. No training on paid-services API data; limited-period logging for policy enforcement and safety; no human review of paid-services API content for product improvement. Governed by the Data Processing Addendum for Products Where Google is a Data Processor and related paid-services terms. | Core (failover) |
| LiveKit Cloud | RTC/WebRTC/SIP infrastructure | Audio stream metadata, room state, transient audio routing | U.S. region configuration where available; strict residency requires contract confirmation. | Core |
| Supabase | Database, auth, storage, edge functions, vault | Structured caller data, transcripts, audit logs, credentials | Ansa project configured in U.S.-East; support, backups, and subprocessor handling subject to Supabase terms. | Core |
| Stripe | Billing and payments | Customer billing data, payment tokens, subscription status | No caller PII intended; Stripe may act independently for fraud, compliance, tax, and payment-network purposes. | Core for billing; independent controller for payment-network purposes |
| Resend | Transactional email | Recipient email, subject, message body, email metadata | Email routing per Resend terms. | Core |
| Vercel | Web app hosting | HTTP metadata, deployment logs, dashboard request metadata | Global edge behavior may apply; logs designed to avoid caller PII. | Core |
| CRM / calendar / scheduling system | CRM sync if enabled | Booking name, phone, address, service, time | Customer-Directed CRM destinations. | Conditional — Customer-Directed Destinations, NOT Ansa Subprocessors (§ 13.8) |
| Sentry | Error monitoring, if enabled | Error metadata only; no PII by design | Not active unless deployed and added to active Subprocessor List. | Planned / Not active |
| The Campaign Registry / A2P 10DLC | SMS registration | Brand and campaign registration data; no caller PII intended | Regulatory / carrier ecosystem recipient. | Conditional / regulatory; not ordinary subprocessor |
Customer-Directed CRM, calendar, or job-management integrations are destinations chosen by Customer and are governed by Customer's relationship with those providers unless Ansa separately lists the provider as an Ansa Subprocessor.
Annex IV — Standard Contractual Clauses Placeholder
If Customer Personal Data is subject to GDPR, UK GDPR, Swiss FADP, or other international-transfer restrictions, the Parties shall execute applicable transfer terms, including:
- EU Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914;
- UK International Data Transfer Addendum or UK IDTA;
- Swiss addendum or equivalent terms; and
- supplementary measures and transfer impact assessment where required.
Until such terms are executed, Customer shall not use the Services for GDPR-regulated Personal Data unless Ansa has agreed in writing.