Back to coserve.ai

Data Processing Addendum

Last updated: July 22, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between VERACO LLC (“CoServe”) and the customer that accepts them (“Customer”). It applies whenever CoServe processes Personal Data on Customer’s behalf in providing the Service, and it reflects the parties’ agreement on that processing. Capitalized terms not defined here have the meaning in the Terms.

1. Definitions

2. Roles and scope

As between the parties, Customer is the controller/business and CoServe is the processor/service provider for Personal Data. The subject matter of processing is the provision of the Service; the duration is the term of the Terms plus the deletion period below; the nature and purpose are the communication, scheduling, transcription, summarization, and record-keeping functions of the Service; the categories of data subjects are Customer’s callers, contacts, leads, customers, and personnel; and the categories of data are identifiers, communication content and metadata, and appointment and commercial information.

3. CoServe obligations

4. Subprocessors

Customer generally authorizes CoServe to engage subprocessors to provide the Service. CoServe will impose data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance. The current subprocessors are:

CoServe will update this page before adding or replacing subprocessors. If Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period — Customer’s sole remedy.

5. AI providers

CoServe’s AI features use the AI subprocessors listed above to transcribe, respond to, and summarize communications in real time. CoServe’s agreements with AI providers prohibit them from using Personal Data to train or improve their generalized models, and limit their retention to what is needed to provide and secure the service.

6. International transfers

Personal Data is processed in the United States and other countries where subprocessors operate. Where Data Protection Laws require a transfer mechanism (for example, transfers of EEA or UK data), the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2: controller-to-processor) and the UK Addendum by reference, with Customer as data exporter and CoServe as data importer, completed with the details in this DPA.

7. Data subject requests

If CoServe receives a request from a data subject (for example, a caller) relating to Personal Data processed for Customer, CoServe will direct the person to Customer and, at Customer’s reasonable request, assist Customer in responding using the Service’s available tools.

8. Deletion and return

During the term, Customer can access and delete Personal Data through the Service. Upon termination of the Terms, CoServe will delete or de-identify Personal Data within 30 days, except where retention is required by law (for example billing records), with residual copies in backups purged on a rolling schedule thereafter.

9. Order of precedence and contact

If this DPA conflicts with the Terms, this DPA controls for the subject of the conflict. Liability under this DPA is subject to the limitations of liability in the Terms. Questions, breach notices, and signed-copy requests: privacy@coserve.ai.