Legal

Data Processing Addendum

Last updated: 4 August 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the agreement between Estric and the Customer whenever Estric processes personal data subject to the EU or UK GDPR on the Customer’s behalf. For end-customer conversation data, the Customer is the controller and Estric is the processor. For Customer account data, Estric is an independent controller as described in the Privacy Policy.

For Customers in other supported countries, the processor-style commitments in this DPA (documented instructions, confidentiality, security measures, breach notification, subprocessor transparency, deletion and return) apply mutatis mutandis under the data protection law of the Customer’s country, including the New Zealand Privacy Act 2020, Canada’s PIPEDA, US state privacy laws (where Estric acts as a "service provider" as defined in the CCPA), the Singapore PDPA 2012, the Hong Kong PDPO, and the Malaysia PDPA 2010.

2. Processing details

Subject matter: operation of the Estric AI front desk. Duration: the term of the agreement plus the export window. Nature and purpose: receiving, transcribing, generating responses to, storing, and displaying customer conversations; creating bookings, leads, payment links, and CRM records as configured.

Categories of data subjects: the Customer’s end customers and staff. Categories of data: contact details (name, phone, email), conversation content including call audio and transcripts, booking and order details. Call audio is processed in real time for transcription and is not retained; only transcripts are stored. The Service is not intended for special categories of data; the Customer must not configure it to solicit them.

3. Estric’s obligations

Estric processes personal data only on the Customer’s documented instructions (the configuration and use of the Service constitute those instructions), ensures personnel are bound by confidentiality, implements the technical and organisational measures described in the Privacy Policy (encryption in transit and at rest, tenant isolation, server-side credential storage, access controls), assists the Customer with data subject requests and Articles 32 to 36 obligations, notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their data, and deletes or returns personal data at the end of the agreement (export available for 30 days).

4. Subprocessors

The Customer authorises these subprocessors: Google Cloud / Firebase (hosting, storage), Google (Gemini language models), OpenAI and Anthropic (language models, engaged according to the model routing in use), ElevenLabs (speech-to-text and text-to-speech), Twilio (telephony and SMS), Stripe (payments), Meta Platforms (WhatsApp, Messenger, Instagram where enabled), Resend or an SMTP email provider (transactional email), and any shop or CRM provider the Customer connects (acting on the Customer’s own instruction). AI subprocessors are engaged under API terms that prohibit training on the Customer’s data.

We will give at least 14 days notice of new subprocessors (via this page and email to account holders); the Customer may object on reasonable data-protection grounds, in which case the affected feature can be disabled or the Customer may terminate the agreement.

5. International transfers

Where processing involves transfers outside the EEA/UK (including to the United States and Australia), the parties rely on the European Commission’s Standard Contractual Clauses (Module 2, controller to processor), which are incorporated into this DPA by reference, together with the UK Addendum where applicable. Subprocessor transfers are covered by equivalent safeguards in their terms.

6. Audits and liability

Estric will make available information reasonably necessary to demonstrate compliance, including summaries of third-party audits of our infrastructure providers, and will allow audits required by law, at most annually and with reasonable notice. Liability under this DPA is subject to the limitations in the Terms of Service.

To execute a signed copy of this DPA, or for data protection questions, contact [email protected].