Data Processing Agreement (DPA)
Last updated: 2026-07-16
Last updated: 16 July 2026
Parties and roles
This Data Processing Agreement ("DPA") forms part of the agreement between the client ("Controller") and AI Fortis Ltd. („ЕЙ АЙ Фортис“ ООД), EIK 208238799 ("Processor" or "AI Fortis") for the processing of personal data under Regulation (EU) 2016/679 (GDPR) in connection with the AI Fortis Voice AI Platform.
Subject matter and duration
Processing of the Controller's end-customer contact and call data for the purpose of operating AI voice agents (making and receiving phone and web calls) through the platform, for the duration of the service agreement.
Nature and purpose of processing
Storage, transmission and analysis of contact data; placing and receiving calls; recording and transcribing calls where enabled by the Controller; producing call summaries and analytics; queueing and campaign management.
Categories of data subjects and personal data
- Data subjects: the Controller's end customers and prospects (call recipients and callers).
- Personal data: phone numbers, names and CRM variables provided by the Controller; call audio, recordings, transcripts, AI-generated analysis, timestamps, duration and outcome.
Processor obligations
- Process personal data only on the Controller's documented instructions, including with regard to international transfers.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Art. 32): TLS in transit, AES-256-GCM encryption of secrets at rest, multi-tenant isolation enforced with row-level security (RLS), role-based access with optional MFA, audit logging, and data deletion on account closure and on verified erasure requests.
- Engage sub-processors only under a written contract imposing equivalent data-protection obligations; the current list is on the Sub-processors page; the Processor gives notice of intended additions or replacements and the Controller may object on reasonable data-protection grounds.
- Assist the Controller, taking into account the nature of the processing, with data subject requests (Arts. 12–23) and with security, breach-notification and impact-assessment obligations (Arts. 32–36). Personal data breaches are notified to the Controller without undue delay.
- At the end of the service, delete or return all personal data at the Controller's choice, and delete existing copies unless EU or member-state law requires storage.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
International transfers
The primary application database is hosted in the EU. Where a sub-processor processes personal data outside the EEA, the transfer is covered by appropriate safeguards, in particular the EU Standard Contractual Clauses, with supplementary measures where needed.
Liability and term
This DPA applies for as long as the Processor processes personal data on behalf of the Controller. Liability follows the main agreement.
This DPA is a draft — the annexes (documented instructions, data categories, sub-processor list, security measures) are completed per order, and the full set must be reviewed by counsel before execution.