Data Processing Addendum
Version: stated in the page header and in the release record for this document · Effective: the effective date of the approved agreement bundle or signed order.
1. Parties, scope and precedence
This DPA forms part of the Terms between Mawlawi Tech Solutions LLC ("Provider") and the customer identified in the accepted registration record or order ("Customer"). It governs personal data Provider processes on Customer's behalf through Everaide ("Customer Personal Data"). Applicable Data Protection Law means the privacy/data-protection law applicable to that processing, including, where applicable, EU GDPR, UK GDPR and UK Data Protection Act 2018 as amended, and relevant US state laws.
Customer acts as controller or, where it has documented authority, as processor appointing Provider as subprocessor. Provider acts as processor/subprocessor for Customer Personal Data. Provider's independent account, security and billing purposes are separately described in the Privacy Notice and are not permission to repurpose call content. Roles follow applicable law and actual conduct.
This DPA prevails over inconsistent general Terms for personal-data processing. Mandatory transfer clauses prevail over inconsistent provisions in either. Nothing reduces individuals' statutory rights, supervisory authority powers or mandatory transfer-clause remedies.
2. Documented instructions and purpose limits
Provider processes Customer Personal Data only on documented instructions, including the agreement, supported settings and written instructions consistent with it. Provider will notify Customer if an instruction appears to infringe applicable data-protection law and may suspend the affected processing while the issue is resolved. If law requires other processing, Provider will notify Customer beforehand unless prohibited.
Provider will not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for unrelated advertising or profiling, or train/fine-tune its own general-purpose models with it. Necessary retrieval and indexing for Customer's service are within instructions. Subprocessors must be subject to restrictions consistent with this DPA and applicable law; Provider may not authorize a use inconsistent with those obligations merely because a vendor's public terms permit it.
Where US service-provider/contractor rules apply, Provider will process data only for the specified business purposes, within the direct business relationship, and subject to statutory restrictions and permitted exceptions. Provider certifies it understands and will comply with these restrictions, will notify Customer if it can no longer do so, and will permit reasonable steps to monitor, stop and remediate unauthorized use. These terms do not create an exception to stricter applicable law.
3. Confidentiality and security
Provider limits access to authorized personnel and approved providers with a need to process the data and appropriate confidentiality duties. Provider maintains the measures in Annex B, tests their effectiveness, and will not materially reduce overall protection during the processing term. Changes do not remove a specifically negotiated safeguard without lawful agreement.
Customer is responsible for lawful collection, content accuracy, necessary transparency and permissions, secure account administration and supported configuration. Provider assists with its own service controls; these allocations do not transfer Provider's legal obligations to Customer.
4. Subprocessors
Customer generally authorizes only the subprocessors in the approved, dated Subprocessor List for their stated purposes. Provider remains responsible for their performance of its processor obligations and enters enforceable written terms with protections required by applicable law before processing begins. Vendor website claims alone are insufficient evidence of those terms.
Provider will give at least 30 days' prior written notice of an intended new or replacement subprocessor, with function, data and location information sufficient for assessment. Customer may object on reasonable data-protection grounds within that period. The parties will seek a reasonable alternative; if none is available, Customer may stop the affected service before the change and obtain a refund of unused prepaid fees for that service. Provider will not treat silence as overriding a valid objection. Urgent changes must follow applicable law and any signed transfer clauses, with prompt notice and protective steps.
Notice of an intended new or replacement subprocessor is given by publishing a dated revision of the Service Providers page at least 30 days before the change, with the change summarized at the top of that page; earlier dated lists remain available from the archive. Customers may ask support@geteveraide.com to receive such notices by email.
5. Individual requests and compliance assistance
Provider will promptly forward requests concerning Customer Personal Data to Customer and assist with secure access, correction, portability, restriction, objection and deletion. Provider will not disclose another person's information to an unverified requester. Stop-calling requests are promptly routed to suppression without requiring identity evidence unnecessary for that action.
Taking into account its role and information available, Provider assists Customer with security obligations, breach response, impact assessments, prior consultation and regulator enquiries. Each party remains responsible for its own obligations and deadlines. Provider will not delay assistance until a fee dispute is resolved; reasonable exceptional assistance charges require advance agreement where lawful.
6. Personal-data incidents
Provider notifies Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Provider aims to give the initial notice within 24 hours and in any event within 72 hours, or sooner if required by an applicable school schedule or law. It may be preliminary and will include then-known nature, affected categories/approximate counts, likely consequences, contact point and containment/remedial actions. Provider supplies updates as material facts become known, preserves relevant evidence, cooperates and does not wait for a completed investigation.
Customer normally handles notices required in its controller role; Provider handles duties applicable to Provider and assists Customer. Neither party may prevent the other from making a legally required notification. A notice does not itself admit liability.
Security notices reach Provider at support@geteveraide.com. Provider's monitoring alerts are delivered to a mailbox its responsible person monitors; Provider escalates to the affected supplier through that supplier's support channel as part of containment.
7. Return, deletion and retention
At Customer's choice on termination, Provider returns Customer Personal Data by export and deletes it as described in this section, subject only to a documented lawful retention requirement and the backup schedule below. Customer has a 30-day export/request window following termination unless law or the applicable school schedule requires another arrangement. Following the window or an earlier valid deletion instruction, Provider deletes call content and the records derived from it under its automatic retention purge (the organization's window, 360 days by default, or a shorter window set for the organization), deletes uploaded documents and their extracted passages, and deletes or de-identifies each other data class on the date and by the mechanism stated for that class in the Retention section of the Privacy Notice. A class that section states is retained is retained only for the stated reason and period, and Provider names it in the completion record. Provider does not describe data as deleted that it has not deleted, and does not promise a deletion mechanism it does not yet operate.
The Retention section of the Privacy Notice distinguishes owner SMS program evidence, Customer-controlled call data and necessary suppression records. An independent purpose must be documented and disclosed; not all records become Provider-controlled because an account closes.
Retained legal/compliance records are minimized, segregated or access-restricted, used only for their permitted purpose, and deleted when the justification ends. Billing retention does not justify keeping call content. Provider tells Customer the categories, justification and duration of residual retention; schema constraints alone are not a legal basis.
Backup data is isolated from normal use; local copies are removed once their off-site copy is confirmed, and off-site copies are currently retained without automatic expiry, which Provider will replace with a stated expiry period when an automatic schedule is in force. Before restoring normal operations from backups, Provider re-applies the deletions and suppression records recorded since that backup, by a documented procedure using the deletion register it keeps for that purpose. Provider requests deletion or return from each subprocessor through that subprocessor's support process, records the request and the answer, and reports lawful residuals. On request it supplies an accurate completion record; it will not certify complete deletion when exceptions remain.
8. Demonstrating compliance and audits
Provider makes available information reasonably necessary to demonstrate compliance and allows and contributes to audits, including inspections, by Customer or its mandated independent auditor as required by applicable law. The parties normally start with current reports, questionnaires and remote evidence, using reasonable confidentiality, scope and scheduling measures that protect other customers.
Routine reviews may ordinarily be coordinated once annually with reasonable notice. That arrangement does not bar additional audits required by law, a regulator, a breach, reasonable evidence of noncompliance or the transfer clauses. A blanket ban on inspections does not apply. Fees and logistics cannot frustrate mandatory audit rights.
9. International transfers
Provider processes only in documented locations using approved subprocessors. Before a restricted transfer, the parties complete the applicable International Transfer Schedule required for the actual transfer, official clauses and required assessment. No UK/EU-exclusive residency is promised unless an explicit, technically verified order provides it.
Customer authorization to use the service is not an Article 49 derogation or a replacement for an Article 46 mechanism. Provider will not use routine consent to bypass an unavailable transfer safeguard. If safeguards cannot be maintained, affected transfers are suspended and the parties implement the required return/deletion or termination procedure.
10. Term and signatures
This DPA continues while Provider processes Customer Personal Data. Agreement liability provisions apply only to the extent consistent with mandatory law and the applicable transfer clauses. An approved electronically accepted bundle can incorporate this DPA; a signed cover can document the same version for procurement. Neither a public summary nor a vendor's DPA substitutes for Customer's agreement with Provider.
Customer completion records
The approved DPA body is the same for electronic acceptance and procurement. The procurement cover and completed customer schedules identify the customer, authority, exact document versions and any completed processing/transfer schedules. Completed records are private contract records; they are not part of the public DPA page. An electronic acceptance must link equivalent completed records to its exact agreement bundle. A signature on a cover does not complete a missing mandatory annex or permit an unsupported use.
Annex A — Processing description
Subject: AI-assisted organizational call answering, approved outbound AI voice campaigns including permitted marketing, document retrieval, messages and callback requests, booking, optional transactional owner SMS and supporting administration. Owner SMS consent/compliance data processed for Provider’s own program must be role-mapped separately from Customer-controlled caller data. Nature: receive, transcribe, structure, retrieve, generate responses, store, display, export, restrict and erase. Purpose: provide the instructed service, not unrelated analytics or model training.
Duration: service term and agreed return/deletion period, with narrowly justified restricted legal records and finite backup expiry. Transfers occur continuously or as calls, uploads and support interactions require.
Data subjects: authorized staff, callers, campaign contacts and individuals named in authorized customer material. Student/child processing is excluded until the School Addendum and relevant schedule are approved.
Data: business contact/account identifiers, call audio processed at the telephony provider (no independent Everaide audio archive), transcripts, summaries, telephone numbers, message/booking details, uploaded text, consent/suppression evidence and associated service metadata. Special categories and criminal-offense data are not intended in the standard service; any approved exception must identify a lawful basis, safeguards and minimization in a signed schedule.
The customer completion record specifies the authorized purposes, enabled workflows, relevant countries, applicable data categories and customer privacy contact. It may narrow this baseline; an expansion requires express approval and any additional safeguards before processing. The general description above does not substitute for required customer-specific particulars.
Annex B — Technical and organizational measures
- Organization-scoped authorization and retrieval; owners/members; server-side permissions; restricted database roles and audited privileged access.
- HTTPS and authenticated internal/vendor paths; signed telephony-provider webhooks; protected secrets; no provider keys in client bundles.
- Data minimization in prompts and logs; scoped excerpts; selective sensitive-data redaction; limited operator access with confidentiality obligations.
- Backup archives are encrypted on Provider's server before off-site upload; the decryption key is held only on that server with restricted access and an encrypted escrow copy, and the storage provider never holds it. No unencrypted archive is kept. An automated weekly restore drill verifies recoverability. Local copies are removed after their off-site copy is confirmed; off-site expiry is stated in section 5.
- At-rest protection for live data: field-level encryption is enforced for designated sensitive columns (caller and contact identifiers, consent evidence and similar), and uploaded documents are stored with server-side encryption under keys held in a separate key service. Database and cache volumes are not disk-encrypted; supplier copies are protected under each supplier's own controls. Provider does not claim that every database column or supplier copy is encrypted by Provider.
- Scheduled purge and redaction of call content and derived call records, tested against a real database; suppression records protected from deletion; subprocessor deletion by request through each supplier's process; after any restore, deletions and suppressions re-applied by a documented procedure.
- Vulnerability management, logging without unnecessary PII, incident response and monitored security contacts: dependency and container-image scanning at build time and on a weekly schedule, with dated exceptions; application logs redacted at the logger and periodically scanned for caller identifiers, retained 14 days; a documented incident procedure exercised by tabletop; security contact support@geteveraide.com.
- Tenant isolation does not mean Provider lacks administrator access. No Everaide SOC 2/ISO certification is claimed.
Annex C — Transfers
The completed International Transfer Schedule and unmodified applicable official instruments are attached or incorporated by a precisely identified version. They are not deemed completed by this heading.