Data Processing Agreement
Last updated: July 27, 2026 | Effective: July 27, 2026
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the AYBIZA Terms of Service. It governs how AYBIZA processes personal data on your behalf as your processor and satisfies the requirements of GDPR Article 28, UK GDPR Article 28, and equivalent data protection laws. By accepting the Terms of Service, you also accept this DPA. Capitalized terms not defined here have the meaning given in the Terms of Service or the GDPR.
1. Roles and scope
You are the controller of the personal data you and your end-users put into the AYBIZA platform. AYBIZA LLC is the processor that handles it on your documented instructions.
This DPA covers Customer Content — the personal data AYBIZA processes to run the Services for you, including data about the people who interact with the AI agents you deploy and end-visitors who chat or speak with a widget agent on your website. The subject matter, categories of data, and categories of data subjects are set out in Schedule 1.
AYBIZA is an independent controller, not a processor, for a separate set of records: account registration data, business verification (KYB) data, billing and subscription records, legal acceptance records, and aggregated usage analytics. Those records are governed by our Privacy Policy, not this DPA.
“SCCs” means the Standard Contractual Clauses in EU Implementing Decision 2021/914, Module 2 (controller to processor). “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the ICO under Section 119A of the Data Protection Act 2018.
2. Instructions
AYBIZA processes Customer Content only on your documented instructions, including on international transfers, unless applicable law requires otherwise — in which case AYBIZA will tell you before processing, unless the law prohibits that notice on public-interest grounds.
Your instructions are the Terms of Service, this DPA, and your platform configuration settings. You confirm they comply with data protection law and that you have given data subjects all required notices and obtained all required consents.
If AYBIZA believes an instruction infringes the GDPR, UK GDPR, or other data protection law, it will tell you promptly and may suspend the affected processing until the instruction is clarified or revised.
3. Confidentiality
AYBIZA ensures that anyone it authorizes to process Customer Content is bound by enforceable confidentiality obligations, processes the data only to perform the Services, and receives appropriate data protection training. These obligations survive that person’s engagement with AYBIZA.
4. Security
AYBIZA implements and maintains the technical and organizational measures set out in Schedule 2, appropriate to the risk of the processing. AYBIZA regularly tests and evaluates those measures and updates them as threats evolve. AYBIZA will not make changes that materially reduce the overall level of protection.
You are responsible for security on your side: your systems, your users’ access credentials, your API key management, and the personal data you send to AYBIZA. AYBIZA’s security program is described at /security.
5. Sub-processors
You give AYBIZA general written authorization to engage the sub-processors listed in Schedule 3. For each one, AYBIZA imposes data protection obligations by written contract at least as protective as this DPA, conducts due diligence before engagement, and remains fully liable to you for its performance.
AYBIZA will give you at least 30 days’ notice of any new or replacement sub-processor by updating Schedule 3 and emailing your registered account contacts. You may object within 14 days on reasonable data protection grounds. If you object, AYBIZA will use commercially reasonable efforts to offer an alternative that avoids that sub-processor. If none is reasonably available and the parties cannot resolve the objection within 30 days, either party may terminate the affected Services on 30 days’ written notice.
BYOK carve-out. When you supply your own provider API keys (“BYOK”) or connect a self-hosted endpoint, data flows directly to the provider you chose, under your own agreement with it. Those providers are not AYBIZA sub-processors for BYOK or self-hosted requests, and you are solely responsible for that relationship and its compliance.
6. Data subject requests and compliance assistance
You are primarily responsible for responding to requests from data subjects exercising their rights (access, rectification, erasure, portability, restriction, and objection). Taking into account the nature of the processing, AYBIZA assists you by:
- Forwarding any data subject request it receives directly to your registered contact within 48 hours.
- Providing reasonable technical assistance to retrieve, correct, or delete the data.
- Not responding to a request itself unless you instruct it to or the law requires it.
At your cost and to a reasonable extent, AYBIZA also assists you with security obligations (Article 32), breach notification (Articles 33–34), data protection impact assessments (Article 35), and prior consultation with supervisory authorities (Article 36), taking into account the information available to AYBIZA.
7. Breach notification
AYBIZA will notify you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting Customer Content. This 48-hour deadline is a contractual commitment; GDPR Article 33(2) otherwise requires a processor to notify the controller without undue delay.
To the extent then known, the notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it, and a contact point. AYBIZA will cooperate in investigating and mitigating the breach and share further detail as it emerges, and will not notify any third party without your prior written consent unless the law requires it. Notifications you owe to supervisory authorities or data subjects remain your responsibility as controller.
8. Deletion and return
On termination or expiry of the Terms of Service:
- Export: AYBIZA makes a complete export of your Customer Content available in machine-readable format (JSON or CSV) for 30 days.
- Deletion: After the export period, AYBIZA permanently deletes Customer Content within 30 days, including copies in production and backup systems, unless the law requires longer retention. AYBIZA provides written certification of deletion on request.
During the term, much of your Customer Content ages out on its own schedule: chat and text messages default to 730 days and call recordings to 90 days, both configurable by your organization. The full retention table is in the Privacy Policy. Separately, AYBIZA keeps the controller records it holds — KYB, billing, and legal acceptance records — for up to seven years to meet its own legal obligations, processed only for compliance.
9. International transfers
AYBIZA hosts Customer Content in the United States. Encrypted backup copies are held with a second cloud provider in the same jurisdiction as the data they protect, so backups introduce no additional cross-border transfer. Where personal data from the EEA, UK, or Switzerland is transferred to AYBIZA in the United States, or to a sub-processor in a country without an adequacy decision, the mechanisms below apply.
EEA transfers. The SCCs (Module 2, controller to processor) are incorporated into this DPA by reference and apply to transfers of EEA personal data to AYBIZA. Their annexes are populated by Schedules 1, 2, and 3. For the SCCs: the docking clause in Clause 7 is included; Clause 9(a) uses Option 2 (general written authorization) with a 30-day notice period; the optional Clause 11 redress language is not included; the governing law under Clause 17 is the law of Ireland; and the forum under Clause 18 is the courts of Ireland.
UK transfers. The UK Addendum (version in force at the date of this DPA) is incorporated and supplements the SCCs for transfers of UK personal data to AYBIZA. Its tables are completed by the parties identified in this DPA and by Schedules 1, 2, and 3.
Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply with the adjustments required by the Swiss Federal Data Protection and Information Commissioner: the Commissioner is the competent supervisory authority and references to the GDPR are read as references to the FADP, as applicable.
Data Privacy Framework. AYBIZA relies on the SCCs as its primary transfer mechanism and does not claim active certification under the EU-US, UK Extension, or Swiss-US Data Privacy Framework. If it self-certifies to the DPF, it will honor the DPF Principles for data received under it and update this section.
AYBIZA applies supplementary measures including encryption in transit and at rest, strict access controls, and a documented process for government access requests, and will notify you of any government request for your Customer Content unless legally barred from doing so.
10. Audit and inspection
In plain language: we normally prove compliance through documents and independent reports, but you keep a bounded audit fallback when those are not enough.
AYBIZA will make available the information reasonably necessary to demonstrate compliance with this DPA and applicable data protection law. AYBIZA may satisfy an ordinary audit request by providing relevant security documentation, completed questionnaires, certifications, and independent assessment reports, where available.
If those materials are not reasonably sufficient for you to meet your legal obligations as controller, you may conduct an additional remote audit. An on-site inspection may be conducted only where:
- a remote audit and the available independent reports are not reasonably sufficient;
- you reasonably believe that AYBIZA has materially breached this DPA;
- a personal data breach affecting Customer Content has occurred;
- a competent supervisory authority requires the inspection; or
- applicable data protection law otherwise requires it.
You may conduct the audit yourself or appoint an independent auditor that is not an AYBIZA competitor and is bound by written confidentiality obligations. You retain the final choice of auditor and audit method, subject to the reasonable safeguards in this Section.
Except where a competent authority requires otherwise, or where an urgent breach investigation makes advance notice impracticable:
- You must give at least 30 days’ written notice.
- Audits may occur no more than once in any 12-month period.
- Audits must occur during normal business hours and avoid unreasonable disruption.
- The audit must be limited to systems, records, personnel, and processing relevant to Customer Content.
- The auditor may not access another customer’s data, source code, information that would materially weaken security, or information AYBIZA is legally prohibited from disclosing.
- AYBIZA may provide a reasonably equivalent method of verification where direct access would create a material security or confidentiality risk, but the alternative must still give you enough information to meet your legal obligations.
You bear your audit costs and AYBIZA’s reasonable documented costs of supporting an audit. AYBIZA will bear its own reasonable support costs if the audit identifies a material breach of this DPA by AYBIZA. AYBIZA will promptly address any material non-compliance an audit establishes.
Nothing in this Section limits the audit, inspection, investigation, or access rights of a competent supervisory authority, or the rights granted by the SCCs or UK Addendum.
11. CCPA
To the extent AYBIZA processes personal information subject to the California Consumer Privacy Act (as amended) on your behalf, it acts as a “service provider” and:
- Processes that personal information only for the business purposes in this DPA and the Terms of Service.
- Does not sell or share (as the CCPA defines those terms) personal information it receives from or for you.
- Does not combine that personal information with data from other sources, except as the CCPA permits.
- Certifies that it understands and will comply with these restrictions.
12. HIPAA
AYBIZA does not receive or process Protected Health Information absent an executed Business Associate Agreement. Do not send PHI to AYBIZA unless a BAA is in place; see the Terms of Service.
13. Term, liability, precedence, and amendments
This DPA takes effect when you accept the Terms of Service and lasts for their duration; ending them ends this DPA, subject to Section 8, any surviving SCC or UK Addendum obligations, and AYBIZA’s controller-record retention. Each party’s liability under this DPA is governed by the limitations in the Terms of Service, except that nothing limits liability that data protection law says cannot be limited by contract.
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA governs; if it conflicts with the SCCs or UK Addendum on international transfers, those clauses govern. AYBIZA may update this DPA for changes in law, regulatory guidance, or its sub-processor list, with at least 30 days’ notice of material changes; continued use after the effective date is acceptance.
14. Contact
Data protection and DSAR inquiries: privacy@aybiza.com. Security inquiries: security@aybiza.com. EU/UK privacy contact: eu-privacy@aybiza.com.
AYBIZA LLC, a Wyoming limited liability company. Business address: 32222 Tamina Rd Ste A5-11, The Woodlands, TX 77354. Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801.
Schedule 1 — Details of processing
Subject matter and duration. Processing of Customer Content to provide the AYBIZA platform, for the duration of the Terms of Service plus the 30-day export period and up to 30 further days for deletion.
Nature and purpose. AYBIZA processes Customer Content to route and conduct AI agent conversations across chat and voice, deliver one-time verification codes, generate transcripts and recordings where you enable them, run speech-to-text and text-to-speech, process text through large language models to generate agent responses, manage your CRM and service-desk records, and deliver other features you configure.
Categories of personal data.
- Agent conversation data: text and voice conversations, including widget end-visitor conversations and one-time-passcode verification data.
- Call recordings and transcripts, where you enable recording.
- CRM records: parties, deals, segments, tickets, and tasks, as entered by you.
- Uploaded files and knowledge-base content you provide to your agents.
- Agent long-term memory derived from conversations (45 days by default, capped at 730 days).
- Contact identifiers: names, email addresses, phone numbers, and postal addresses.
- Interaction metadata: timestamps, channel, duration, outcome, and session identifiers, plus technical identifiers such as IP address and browser type.
- Special-category data only if you deliberately enable it for a regulated use case, subject to a separately executed BAA or equivalent.
Categories of data subjects. Your customers, leads, and contacts; end-visitors who interact with your deployed agents, including website widget visitors; your team members who use the platform; and any other individuals whose personal data you input.
Schedule 2 — Technical and organizational measures
AYBIZA maintains the measures below and reviews them regularly. These measures are the binding commitment; the security page is a plain-language summary of them and does not extend or vary them.
- Encryption: Encryption in transit between clients, the platform, and sub-processors; encryption at rest (AES-256-GCM) for stored Customer Content, with per-record data keys for provider credentials, call recordings, telephony identifiers, and multi-factor secrets, and documented key rotation with an overlap window.
- Tenant isolation: Organization-level isolation enforced at the database layer, so one organization’s data is not accessible to another.
- Access control and authentication: Role-based access on least-privilege principles; multi-factor authentication for administrative access; support for organization-enforced MFA and single sign-on via SAML 2.0; API access authenticated by bearer tokens over encrypted channels.
- Audit logging: Tamper-evident audit logs of administrative actions, data access, configuration changes, and authentication events, retained for a defined period.
- Secrets management: Centralized, access-controlled management of credentials and keys, kept out of application code.
- Vulnerability management: Dependency auditing that fails the build on an unresolved advisory, automated security testing against the platform, static security analysis in the development pipeline, and a responsible-disclosure channel.
- Incident response: Documented procedures with severity levels and escalation paths, the 48-hour breach notice in Section 7, and post-incident review and remediation.
- Backup and recovery: Automated database backups with point-in-time recovery, and a separate restorable backup held with a second cloud provider so recovery does not depend on any single provider remaining available.
- Personnel: Enforceable confidentiality obligations, and security and data protection training for staff with production access.
AYBIZA’s architecture is designed following the SOC 2 Trust Services Criteria; a third-party assessment is planned, and such reports are made available when available.
Schedule 3 — Sub-processors
The following sub-processors are approved as of the effective date. Changes are notified under Section 5.
Infrastructure
- Amazon Web Services, Inc. (AWS) — United States — hosting and compute, object storage (Amazon S3), and transactional email (Amazon SES).
- Cloudflare, Inc. — United States — DNS, content delivery, TLS termination, bot and abuse protection, and the human-verification challenge shown on sign-in and widget sessions.
- Fly.io, Inc. — United States — hosting for the aybiza.com marketing website, which processes visitor request metadata.
- Google Cloud — United States and European Union — encrypted backup storage, held in the same jurisdiction as the data it protects.
Payments
- Stripe, Inc. — United States — payment processing and subscription billing (a PCI DSS Level 1 service provider).
Telephony
- Twilio Inc. — United States — voice call routing, SMS delivery, and one-time-passcode verification.
AI and language models (platform-managed)
- Anthropic — United States — large language model processing for agent conversations and text generation.
- OpenAI — United States — large language model processing and voice realtime processing.
- Google (Gemini) — United States — large language model processing for agent conversations and text generation.
- AWS Bedrock — United States — large language model processing via managed model hosting.
- xAI (Grok) — United States — large language model processing and voice realtime processing.
Speech and voice processing
- Deepgram — United States — speech-to-text and text-to-speech processing.
- AssemblyAI — United States — speech-to-text processing.
- ElevenLabs — United States — text-to-speech voice synthesis.
- Cartesia — United States — text-to-speech voice synthesis.
Web search
- Perplexity — United States — web search for agent research and retrieval.
Business verification (KYB)
These are queried when you register a business, using the company details and authorized-representative name you provide.
- European Commission (VIES) — European Union — VAT number validation.
- U.S. Department of Commerce (International Trade Administration, Consolidated Screening List) — United States — sanctions and restricted-party screening.
- RDAP.org — United States — public domain registration lookup.
Training on Customer Content is not uniform across the platform-managed providers above, and AYBIZA does not represent that it is. Anthropic, AWS Bedrock, Google Gemini, OpenAI and Perplexity each publish terms stating they will not train on content sent on AYBIZA’s accounts. AssemblyAI, Cartesia, Deepgram and xAI publish no position either way. ElevenLabs publishes that it may train on what it is sent and offers an account-level opt-out, which AYBIZA set on its own account on 17 August 2026, effective only for content sent after that date. The Privacy Policy carries the same statement in full. Provider retention is governed by the applicable provider agreement and configuration, including any retention required for security, abuse prevention, or law.
BYOK and self-hosted exclusion. When you use BYOK or a self-hosted endpoint — for example a self-hosted Parakeet speech-to-text model, a self-hosted Coqui text-to-speech model, or your own web-search key — your chosen provider processes the data directly under your own agreement and is not an AYBIZA sub-processor for those requests. You are solely responsible for that relationship.