Data Processing Agreement
Last updated: October 6, 2026
ANNEX B — DATA PROCESSING AGREEMENT
This Data Processing Agreement (“DPA”) is an annex to, and an integral part of, the Enastro General Terms and Conditions (the “Terms”) published at https://dev.enastro.com/legal/terms. It is accepted by you when you register a payment card, and it governs the processing of personal data by SMARTREP S.A. (“SmartRep”, “we”, “us”), as processor, on behalf of the customer identified by the Organization (the “Customer”, “you”), as controller, in connection with the Service. Capitalised terms not defined here have the meanings given in the Terms; “controller”, “processor”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR.
1. Status and details of the processing
1.1 In respect of the personal data contained in the Customer Data, you are the controller and we are the processor. Where you are yourself a processor acting on behalf of your own customers, you warrant that you are authorised to appoint us as sub-processor and that the instructions you issue under this DPA are consistent with those of the relevant controller; references in this DPA to you as controller shall be construed accordingly.
1.2 The subject matter, duration, nature and purpose of the processing and the categories of personal data and of data subjects are as follows:
(a) Subject matter: the processing of personal data contained in the Customer Data in the context of the provision of the Service.
(b) Nature: ingestion from your Audio Sources, transmission, transcoding, hosting, storage, organisation, structuring, consultation, display, automated transcription and speaker separation, automated analysis and metric extraction by means of artificial intelligence models, natural-language querying, export, back-up, restoration, erasure and destruction, as necessary to provide, maintain, secure and support the Service.
(c) Purposes: the provision of the Service to you in accordance with the Terms, including ingestion and processing of recordings, transcription, conversation analysis, Metric extraction, presentation and reporting of results, account and access management, technical support, metering and the security of the Service.
(d) Categories of personal data: audio recordings of customer service conversations and transcoded derivatives; transcripts with word timings; speaker segments and inferred speaker role; call metadata, including call time, direction, queue, customer reference and customer-defined fields; analysis output, including summaries, sentiment, topics, action items and verbatim quotes; Metric results with the model’s reasoning, confidence score and any human correction; identification, contact and account data of Members, including sign-in and access records; access records relating to privileged and cross-tenant access; and support correspondence. Recordings and transcripts routinely contain identifiers, contact details and account references and may, incidentally and unpredictably, contain special categories of personal data within the meaning of Article 9 GDPR or data relating to criminal convictions and offences disclosed by a participant. You shall not deliberately or systematically submit such data to the Service.
(e) Categories of data subjects: the participants in the recorded conversations, including your employees, workers, contractors and agents and your end customers and, where applicable, the personnel and customers of your own customers; your Members and administrators; and any other natural person whose personal data is contained in the Customer Data.
(f) Duration: the term of the Terms, together with the retention window you select under clause 6.5 of the Terms and the retrieval and deletion periods under clause 17.5 of the Terms and paragraph 3.1(j) of this DPA.
1.3 No personal data contained in recordings can be processed while the Organization is on the Free plan, because no recording can be ingested. This DPA takes effect when you register a payment card.
2. General obligations
2.1 Each of us shall comply with the data protection laws applicable to it in respect of the personal data.
2.2 You bear sole responsibility for: (a) the accuracy, quality and lawfulness of the personal data and of the means by which it was obtained, including the lawfulness of the recording of the conversations concerned; (b) establishing and documenting an appropriate legal basis for the processing carried out through the Service, in particular the recording, transcription and analysis of conversations conducted by your employees, workers and contractors; (c) providing all required transparency information to data subjects, including to the participants in the conversations; (d) carrying out any data protection impact assessment and, where required, prior consultation with the competent supervisory authority; (e) complying with Article 88 GDPR, Article 27 of Greek Law 4624/2019 and any equivalent employment-context provisions applicable to you, and with any applicable rules on the confidentiality of communications; and (f) selecting the retention window under clause 6.5 of the Terms and the processing configuration under clause 6.3 of the Terms.
2.3 You warrant that the instructions you give us, and the configuration and use you make of the Service, comply with the data protection laws and do not require us to act in breach of them.
3. Our obligations as processor
3.1 We shall:
(a) process the personal data only in order to provide the Service and in accordance with the Terms, this DPA and your documented written instructions, unless required to do otherwise by European Union or Member State law, in which case we shall inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Terms, including this DPA, the AI Terms and the configuration options you select within the Service, constitute your complete and final documented instructions. Additional or divergent instructions require a written agreement and, where they entail additional cost or effort, may be subject to reasonable charges;
(b) inform you without undue delay if, in our opinion, an instruction infringes the data protection laws, it being understood that we are under no obligation to conduct a legal review of your instructions, of the lawfulness of your recordings or of your use case;
(c) implement and maintain the technical and organisational measures set out in the Schedule to this DPA, ensuring a level of security appropriate to the risk, and keep those measures under review, provided that any modification does not reduce the overall level of protection;
(d) ensure that access to the personal data is limited to authorised personnel who require it for the provision of the Service and who are bound by an appropriate contractual or statutory obligation of confidentiality, and record privileged and cross-tenant access;
(e) notify you without undue delay, and in any event within forty-eight (48) hours, upon becoming aware of a personal data breach affecting the personal data, and provide, in stages as the information becomes available, such information in our possession as you reasonably require in order to comply with Articles 33 and 34 GDPR, including the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Such a notification does not constitute an admission of fault or liability;
(f) not make any public announcement in respect of a personal data breach identifying you without your prior written consent, unless required by applicable law;
(g) notify you without undue delay if we receive a request from a data subject exercising rights under the data protection laws in respect of the personal data, not respond to such a request ourselves except on your documented instructions or as required by applicable law, and, taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond, primarily through the search, export, correction and deletion functionality made available within the Service;
(h) provide you with reasonable assistance, taking into account the nature of the processing and the information available to us, in relation to your obligations under Articles 32 to 36 GDPR; where such assistance exceeds the functionality of the Service or requires material effort, we may charge our reasonable costs;
(i) make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR, in accordance with section 5; and
(j) upon termination of the Terms, and at your choice, delete or return to you all personal data processed under this DPA and delete existing copies, unless European Union or Member State law requires further storage. The export functionality and the periods set out in clause 17.5 of the Terms satisfy this obligation. Back-up copies are deleted in accordance with our documented back-up cycle. This paragraph does not apply to aggregated or anonymised data processed in accordance with clause 9.4 of the Terms, which does not constitute personal data.
3.2 Deletion during the term. Audio, transcripts and results are deleted in accordance with the retention window you select for each Audio Source under clause 6.5 of the Terms. Where your own systems retain the original audio, we hold a copy for no longer than ninety-one (91) days. You are responsible for selecting retention windows consistent with your own retention policy, and we shall have no liability for deletion effected in accordance with your selection.
3.3 We do not use the Customer Data to train, fine-tune or otherwise adapt any model, AI system, product or service, and do not process the Customer Data for our own purposes. Our processing of Service Data and of aggregated and anonymised data, as an independent controller for the purposes described in clause 9.4 of the Terms, is outside the scope of this DPA.
4. Sub-processing
4.1 You grant us a general authorisation to engage our affiliates and third parties as sub-processors for the provision of the Service, including cloud hosting, object storage, messaging and scheduling, identity and authentication, model inference, cloud speech-to-text, metering and invoicing, payment administration, email and notification delivery, product analytics, and network security.
4.2 The current list of sub-processors is set out in the Appendix to this DPA, as published at https://dev.enastro.com/legal/dpa. We shall inform you of any intended addition or replacement of a sub-processor by publishing an updated Appendix at that address and notifying you by email or through the Service at least fifteen (15) calendar days before.
4.3 If you object to a new or replacement sub-processor on reasonable and documented data protection grounds, you may notify us within ten (10) calendar days of the notification and, failing a solution agreed between us within a further thirty (30) calendar days, your sole and exclusive remedy is to cancel under clause 17.1 of the Terms. Absence of a timely objection constitutes consent to the sub-processor concerned.
4.4 We shall impose on each sub-processor, by written contract, data protection obligations substantially no less protective than those set out in this DPA, and shall remain fully liable to you for the performance of each sub-processor’s obligations.
4.5 Model Providers. Transcript text is transmitted through the LLM Router to the Model Provider serving the relevant call, and audio is transmitted to a cloud speech-to-text provider only where you select that option for a Job. We engage each Model Provider on terms which prohibit the use of Customer Data for the training or improvement of that Model Provider’s own models, to the extent such terms are offered by the Model Provider concerned for the service in question.
5. Audit
5.1 We shall make available to you, upon written request and no more than once per calendar year, the information reasonably necessary to demonstrate compliance with Article 28 GDPR, in the form of our security documentation, our most recent penetration test summary, our completed security questionnaire and the information published on our trust page.
5.2 On the Standard plan, the information made available under paragraph 5.1 constitutes the means by which audits and inspections under Article 28(3)(h) GDPR are carried out. Where that information is demonstrably insufficient, or following a personal data breach affecting your personal data, we shall cooperate in good faith with a proportionate additional review, which shall: (a) take place no more than once per calendar year, upon at least thirty (30) calendar days’ prior written notice; (b) be conducted remotely wherever possible, during normal business hours, subject to confidentiality undertakings and in a manner which does not disrupt our operations or compromise the security or confidentiality of other customers’ data; (c) be limited to systems and records relevant to the processing of your personal data and shall not extend to source code, model weights, prompts or other trade secrets of ours or of any third party; and (d) be conducted by you or by an independent auditor who is not a competitor of ours. On-site inspections are available on the Enterprise plan.
5.3 You shall bear the costs of any review under paragraph 5.2 and shall reimburse our reasonable costs of assistance, unless the review reveals a material breach by us of this DPA.
6. Transfers to third countries
6.1 We shall not transfer personal data outside the European Economic Area, and shall not permit any sub-processor to do so, except to a country covered by an adequacy decision of the European Commission, or subject to appropriate safeguards under Chapter V GDPR, including the standard contractual clauses adopted by Implementing Decision (EU) 2021/914 (the “Model Clauses”).
6.2 You acknowledge that model inference is not guaranteed to take place within the European Economic Area, that each Model Provider carries a recorded processing jurisdiction which defaults to global, and that transcript text is accordingly transmitted to Model Providers which may process it in third countries under the transfer mechanisms identified in the Appendix. Where you select a component operated on our own infrastructure for a processing step under clause 6.3 of the Terms, the data processed by that step is not transmitted to any third-party provider for that step.
6.3 Where the Model Clauses apply between us, Module Two (controller to processor) applies and is incorporated by reference; the information required by the Annexes to them is that set out in section 1, the Schedule and the Appendix to this DPA; the optional docking clause applies; the period for sub-processor notification is that set out in paragraph 4.2; the governing law is Greek law and the competent courts are the courts of Athens. In the event of conflict, the Model Clauses prevail over any other term of this DPA.
7. Access by public authorities
7.1 We shall notify you if we receive a legally binding request from a public authority for the disclosure of personal data, or become aware of any direct access by a public authority to personal data processed under this DPA. If prohibited from notifying you, we shall use reasonable efforts to obtain a waiver of that prohibition and, where permissible, provide you with relevant information on the request.
7.2 We shall assess the lawfulness of any such request, challenge it where there are reasonable grounds to consider it unlawful, including by seeking interim measures, not disclose personal data until required to do so under the applicable procedural rules, and disclose the minimum amount of information permissible on a reasonable interpretation of the request.
8. Liability
8.1 The liability of each of us under or in connection with this DPA is subject to the limitations and exclusions set out in Article 15 of the Terms, save to the extent that such limitation is prohibited by the data protection laws. Any compensation paid under Article 82 GDPR counts towards the cap in clause 15.4 of the Terms.
SCHEDULE TO ANNEX B — SECURITY MEASURES
We implement and maintain, as a minimum, the following technical and organisational measures. We may modify them provided that the overall level of protection is not reduced.
| Measure | Description |
|---|---|
| Identity and access management | Access shall follow least privilege and need-to-know principles, using individually attributable personnel accounts and multi-factor authentication for privileged production administration. Rights shall be reviewed periodically and promptly adjusted or revoked when responsibilities change or access is no longer required. |
| Tenant segregation and authorization | Logical segregation and authorization controls shall prevent unauthorized access between Clients and access levels. Privileged and cross-tenant access shall be restricted to authorized service purposes and logged. Controls shall be tested periodically and after material changes. |
| Encryption at rest and in transit | Personal Data shall be encrypted at rest in production databases, object storage and back-ups, and in transit over public or untrusted networks, including Client Audio Sources and third-party services. Supported cryptographic protocols, including TLS or SSH as applicable, and controlled key and credential management shall be maintained. |
| Service access and credential management | Distinct service identities and permissions shall be limited to authorized functions. Secrets and credentials shall be access-controlled, excluded from application source code and public repositories, and replaced or revoked upon actual or reasonably suspected compromise or cessation of need. |
| Data retention and secure deletion | Documented procedures shall implement Client retention and deletion instructions for audio, transcripts, results, temporary copies, logs and back-ups, with separate retention rules for transcripts and results. Deletion failures shall be remedied and unnecessary temporary copies deleted. Back-up expiry, versioning and recovery shall support these obligations; restoration shall not return deleted data to ordinary use contrary to instructions. Termination deletion remains governed by the DPA. |
| Network security and infrastructure hardening | Managed infrastructure shall use network access controls, secure configurations and workload hardening, with exposure limited to necessary interfaces and protection against malicious traffic and disruption. Production shall be logically segregated from development/testing, including identities, secrets and messaging. Production Personal Data shall require effective anonymization or express Client authorization with equivalent safeguards before development/testing use. |
| Audit logging and security monitoring | Security-relevant activities, including privileged and cross-tenant access, shall be logged for investigation. Logs shall be access-controlled, protected against unauthorized alteration and retained for documented, proportionate periods, excluding credentials and unnecessary conversation content. Monitoring and escalation shall address anomalies and control failures. |
| Vulnerability, patch and change management | SmartRep shall maintain regular automated vulnerability scanning, risk-prioritized patching and pre-release review/testing of material changes. Independent penetration testing shall occur at risk-appropriate intervals and after material changes where warranted. Findings shall be recorded, remediated and verified or retested as appropriate. |
| Back-up, business continuity and disaster recovery | Encrypted recovery back-ups shall have restricted access and appropriate separation from primary systems. Documented continuity and recovery procedures shall assign responsibilities and recovery objectives, with periodic restoration and recovery testing. Binding availability and recovery targets shall be specified in an agreed Service Level Schedule, without limiting DPA obligations. |
| Physical and environmental security | Hosting providers shall maintain physical access and environmental safeguards against unauthorized access, environmental threats and utility interruptions. SmartRep shall review relevant assurance information. Provider certifications do not certify SmartRep or the Service. |
| Personnel security and organizational governance | Personnel shall be bound by confidentiality obligations and receive role-appropriate security and data-protection training, including secure AI use. SmartRep shall assign security responsibilities and periodically review compliance with acceptable-use, secure-working, access-management and incident-reporting policies. |
| Data minimization and controls over disclosure | Processing and access shall be limited to authorized purposes and need. Billing, metering, payment and notification providers shall receive only necessary identifiers, contact, transaction and operational data, excluding conversation content. Model and transcription disclosures shall comply with the Agreement and Appendix. Pseudonymization or anonymization shall be used where appropriate. |
| Security incident management | Documented, tested procedures shall assign responsibilities for detection, escalation, containment, assessment, remediation and review. Clients shall be notified without undue delay and within forty-eight (48) hours of awareness of a Security Breach under DPA paragraph 3.1(e); information may follow in stages. Evidence shall be preserved and corrective actions tracked to completion. |
APPENDIX TO ANNEX B — LIST OF SUB-PROCESSORS
This Appendix is the current list of sub-processors and is updated in accordance with paragraph 4.2. As at the date of this DPA:
| Sub-processor / legal entity | Purpose and scope | Processing locations | Transfer safeguards |
|---|---|---|---|
| Google Cloud Platform (GCP); Google Cloud EMEA Limited | Cloud infrastructure; Identity Platform/Firebase authentication; Vertex AI inference where selected or used as an authorized fallback. | European regions for the agreed cloud services, in accordance with the applicable regional configuration. | Google Cloud DPA: applicable adequacy decision or SCCs for restricted and onward transfers. |
| Microsoft Azure OpenAI; Microsoft Ireland Operations Limited | Model inference and embeddings for analysis, Metric extraction, queries and search. Azure embeddings may be used independently of the selected conversational model. | European regions for the agreed Azure services, in accordance with the applicable deployment configuration. | Microsoft Products and Services DPA: SCCs for restricted transfers, where applicable. |
| ElevenLabs — cloud transcription; Eleven Labs Inc. | Transcription where selected by the Client. Self-hosted transcription uses GCP infrastructure without disclosure to ElevenLabs. | European Union, in accordance with the agreed data residency arrangement. | Applicable DPA, including Section 11 of the standard DPA where incorporated: adequacy decision or SCCs, as applicable. |
| Stripe — payment and billing services; Stripe Payments Europe, Limited | Payment and billing processing on SmartRep’s behalf. Stripe’s independent-controller activities shall be separately identified in the applicable privacy information. | Ireland (European Union) and the United States for payment and billing operations. | Stripe Data Transfers Addendum: EU–US Data Privacy Framework where applicable, with SCCs as a fallback. |
| Metronome — usage metering and invoicing; Metronome Technologies, Inc. | Usage metering, rating and maintenance of invoicing records. | Locations designated under the applicable account agreement for usage metering and invoicing. | Transfers are subject to the mechanism provided under the applicable customer DPA. |
| Twilio SendGrid — transactional email; Twilio Ireland Limited | Account and service emails, including verification messages, invitations and report-sharing notifications. | European Union for transactional email services configured under the applicable EU data residency arrangements. | Twilio DPA, Schedule 3: EU–US Data Privacy Framework where applicable, with SCCs as a fallback. |
| PostHog — product analytics; PostHog, Inc. | Analytics of Members’ use of the Service, where a Member consents to analytics: pages viewed and actions taken, the Member’s name, email address and role, and recordings of the Service’s screens in which Customer Data is masked in the Member’s browser before transmission. Usage events about the Organization sent from our servers, which identify the Organization and no natural person. | European Union (PostHog Cloud EU, Frankfurt, Germany). | PostHog DPA: EU SCCs for restricted transfers, including access from the United States. |
| Cloudflare — network delivery for product analytics; Cloudflare, Inc. | Reverse proxy that carries the analytics data described for PostHog from the Member’s browser to PostHog, through an address on our own domain. | Cloudflare’s global network. | Cloudflare DPA: EU–US Data Privacy Framework where applicable, with SCCs as a fallback. |