Data Processing Addendum
Last updated: July 22, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between VERACO LLC (“CoServe”) and the customer that accepts them (“Customer”). It applies whenever CoServe processes Personal Data on Customer’s behalf in providing the Service, and it reflects the parties’ agreement on that processing. Capitalized terms not defined here have the meaning in the Terms.
1. Definitions
- “Personal Data” means information relating to an identified or identifiable natural person that CoServe processes on Customer’s behalf — for example caller phone numbers, call recordings, transcripts, messages, and contact and appointment details.
- “Data Protection Laws” means privacy and data-protection laws that apply to the processing, which may include U.S. state privacy laws (such as the CCPA) and, where applicable, the GDPR and UK GDPR.
- The terms “controller,” “processor,” “business,” “service provider,” “data subject,” and “processing” have the meanings given in applicable Data Protection Laws.
2. Roles and scope
As between the parties, Customer is the controller/business and CoServe is the processor/service provider for Personal Data. The subject matter of processing is the provision of the Service; the duration is the term of the Terms plus the deletion period below; the nature and purpose are the communication, scheduling, transcription, summarization, and record-keeping functions of the Service; the categories of data subjects are Customer’s callers, contacts, leads, customers, and personnel; and the categories of data are identifiers, communication content and metadata, and appointment and commercial information.
3. CoServe obligations
- Process Personal Data only on Customer’s documented instructions — which consist of the Terms, this DPA, Customer’s configuration of the Service, and use of its features — and not for any other purpose, unless required by law (in which case CoServe will inform Customer unless prohibited).
- Not sell Personal Data, not share it for cross-context behavioral advertising, and not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service (and as permitted for service providers under the CCPA). CoServe certifies that it understands and will comply with these restrictions.
- Ensure persons authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures, including encryption in transit, access controls and least-privilege permissions, tenant isolation, logging, and vendor due diligence.
- Notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data, and provide information reasonably needed for Customer to meet its own notification duties.
- Taking into account the nature of the processing, assist Customer with data-subject requests and with Customer’s security, breach-notification, and impact-assessment obligations, to the extent the information is available to CoServe.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits (no more than annually, on reasonable notice, subject to confidentiality) which may be satisfied by written responses and third-party reports where available.
4. Subprocessors
Customer generally authorizes CoServe to engage subprocessors to provide the Service. CoServe will impose data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance. The current subprocessors are:
- Google Cloud / Firebase — Cloud hosting, databases, authentication, and file storage (United States).
- Twilio — Telephony, phone numbers, SMS delivery, and A2P campaign registration (United States).
- OpenAI — Real-time speech, transcription, and language-model processing for AI features (United States).
- xAI — Optional alternate real-time voice engine for AI phone answering (United States).
- Stripe — Payment processing, subscriptions, and billing (United States).
- Resend — Transactional and notification email delivery (United States).
CoServe will update this page before adding or replacing subprocessors. If Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period — Customer’s sole remedy.
5. AI providers
CoServe’s AI features use the AI subprocessors listed above to transcribe, respond to, and summarize communications in real time. CoServe’s agreements with AI providers prohibit them from using Personal Data to train or improve their generalized models, and limit their retention to what is needed to provide and secure the service.
6. International transfers
Personal Data is processed in the United States and other countries where subprocessors operate. Where Data Protection Laws require a transfer mechanism (for example, transfers of EEA or UK data), the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2: controller-to-processor) and the UK Addendum by reference, with Customer as data exporter and CoServe as data importer, completed with the details in this DPA.
7. Data subject requests
If CoServe receives a request from a data subject (for example, a caller) relating to Personal Data processed for Customer, CoServe will direct the person to Customer and, at Customer’s reasonable request, assist Customer in responding using the Service’s available tools.
8. Deletion and return
During the term, Customer can access and delete Personal Data through the Service. Upon termination of the Terms, CoServe will delete or de-identify Personal Data within 30 days, except where retention is required by law (for example billing records), with residual copies in backups purged on a rolling schedule thereafter.
9. Order of precedence and contact
If this DPA conflicts with the Terms, this DPA controls for the subject of the conflict. Liability under this DPA is subject to the limitations of liability in the Terms. Questions, breach notices, and signed-copy requests: privacy@coserve.ai.