Jently jently.io
Call Center Voice Agent Features Pricing Documentation
Log In
Get Started

Data Processing Addendum

Effective date: 28 July 2026 · Last updated: 28 July 2026

Contents
  1. Scope and how this DPA applies
  2. Definitions
  3. Roles and processing instructions
  4. Confidentiality of personnel
  5. Security
  6. Sub-processors
  7. Data subject requests
  8. Personal data breaches
  9. Impact assessments and consultations
  10. Retention, deletion and return
  11. Audits and information
  12. International transfers
  13. Liability, precedence and term
  14. Annex I — Details of processing
  15. Annex II — Technical and organizational measures
  16. Annex III — Sub-processor categories

1. Scope and how this DPA applies

This Data Processing Addendum (“DPA”) is entered into between TECHERO LLC, a Delaware limited liability company (1111B S Governors Ave #21885, Dover, DE 19904, USA), operating the Jently platform (“Jently”, “we”), and the customer identified in the applicable agreement (“Customer”). It forms part of the Jently Terms of Service and, for reseller program participants, the White-Label Reseller Agreement (together, the “Agreement”). No signature is required — this DPA applies automatically to every Customer whose use of the Service involves the processing of personal data within the scope of Data Protection Laws; a countersigned copy is available on request to legal@mail.jently.io.

This DPA governs processing we perform on Customer's behalf (as processor or sub-processor). Processing for which we are an independent controller — Customer account and billing data, security and fraud prevention, legal compliance — is described in the Privacy Policy and is out of scope here.

2. Definitions

  • Data Protection Laws — all laws applicable to the processing of personal data under the Agreement, including the EU GDPR (2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, Türkiye's Law No. 6698 (KVKK) and its secondary legislation, and applicable U.S. state privacy laws (including the CCPA/CPRA).
  • Customer Personal Data — personal data contained in Customer Data (as defined in the Agreement) that we process on Customer's behalf, as further described in Annex I.
  • Sub-processor — a third party we engage to process Customer Personal Data on our behalf.
  • SCCs — the EU standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914.
  • “controller”, “processor”, “data subject”, “processing”, “personal data breach” have the meanings given by the applicable Data Protection Laws (for KVKK: veri sorumlusu, veri işleyen, ilgili kişi, işleme, veri ihlali).

3. Roles and processing instructions

  • As between the parties, Customer is the controller of Customer Personal Data and Jently is Customer's processor. Where Customer itself acts as a processor for a third-party controller (for example, a reseller processing on behalf of its end customers), Jently is a sub-processor, and Customer warrants that (i) its own controller has authorized Jently's engagement and the instructions given, and (ii) it will promptly relay to Jently any relevant instructions or objections of that controller.
  • We process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required otherwise by law (in which case we inform Customer of that legal requirement before processing, unless the law prohibits it). Customer's documented instructions are: the Agreement, this DPA, Customer's configuration of the Service (agents, retention, recording, announcements, integrations), and written instructions sent to support.
  • We will inform Customer without undue delay if, in our opinion, an instruction infringes Data Protection Laws; we may suspend the affected processing until the instruction is confirmed or amended.
  • We do not sell Customer Personal Data, do not use it for advertising, and do not use it to train foundation models. To the extent the CCPA applies, we act as a “service provider” and process Customer Personal Data only for the business purposes described in Annex I.

4. Confidentiality of personnel

We ensure that all personnel authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations, receive appropriate data-protection training, and access Customer Personal Data only to the extent required for their role (least privilege).

5. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, we implement and maintain the technical and organizational measures described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. We may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.

6. Sub-processors

  • Customer grants a general authorization to engage Sub-processors for the categories listed in Annex III. The current categories are also disclosed in the Privacy Policy; a named list is provided on request under confidentiality.
  • We will give Customer at least 15 days' advance notice (via the dashboard or email) of the addition or replacement of a Sub-processor. Customer may object on reasonable data-protection grounds within that period; if we cannot offer a reasonable alternative, Customer may terminate the affected part of the Service with a pro-rata refund of prepaid fees for the unused period.
  • We impose data-protection obligations on Sub-processors that are materially no less protective than this DPA, and we remain liable to Customer for their performance to the same extent as for our own.

7. Data subject requests

  • Taking into account the nature of the processing, we assist Customer through appropriate technical and organizational measures — export, deletion, retention configuration and search tooling in the Service — in fulfilling Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection; KVKK art. 11 rights).
  • If a data subject contacts us directly about Customer Personal Data, we will (unless prohibited by law) promptly forward the request to Customer and will not respond substantively except to direct the data subject to Customer or as required by law.

8. Personal data breaches

We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide reasonable cooperation with Customer's notification obligations toward authorities and data subjects. Our notification is not an admission of fault or liability.

9. Impact assessments and consultations

Taking into account the nature of the processing and the information available to us, we provide reasonable assistance with Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent they concern processing under this DPA.

10. Retention, deletion and return

  • During the term, retention of call recordings, transcripts and related content follows Customer's configuration of the Service.
  • Upon termination or expiry of the Agreement, Customer may export Customer Data for 30 days (as per the Agreement). After that window we delete Customer Personal Data, and residual copies in backups are purged in the ordinary backup rotation within a further 30 days, unless retention is required by law (in which case the data remains protected under this DPA and is isolated from further processing).
  • On request, we confirm deletion in writing.

11. Audits and information

  • We make available information reasonably necessary to demonstrate compliance with this DPA — including responses to reasonable security questionnaires and summaries of independent assessments or penetration tests, under confidentiality.
  • Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by the above, Customer (or an independent auditor bound by confidentiality that is not our competitor) may audit our relevant processing operations at most once per 12 months, on at least 30 days' written notice, during business hours, at Customer's cost, without access to other customers' data or to information that would compromise our security. Findings are confidential.

12. International transfers

  • Customer authorizes processing of Customer Personal Data in the countries in which we and our Sub-processors operate, subject to this Section.
  • EU/EEA: transfers to countries without an adequacy decision are governed by the SCCs, which are incorporated into this DPA by reference: Module Two (controller → processor) where Customer is a controller, Module Three (processor → processor) where Customer is a processor; with Clause 7 (docking) included, Clause 9 Option 2 (general authorization, 15 days), Clause 17 governed by Irish law and Clause 18 courts of Ireland; Annexes I and II of the SCCs are populated by Annex I and Annex II of this DPA.
  • UK: the UK International Data Transfer Addendum to the SCCs applies, with the tables populated by this DPA. Switzerland: the SCCs apply as adapted for the FADP (references to the GDPR read as the FADP, competent authority the FDPIC).
  • Türkiye (KVKK): where a transfer abroad of personal data subject to KVKK is required, the parties rely on the instruments of KVKK art. 9 as amended — primarily the standard contract published by the Turkish Data Protection Authority, executed as published; the party required by the applicable regulation notifies the Authority within five business days of signature. Where Customer needs the KVKK standard contract executed with us, we will execute it on request.
  • If a transfer mechanism relied on is invalidated or amended, the parties will cooperate in good faith to implement a lawful replacement without interrupting the Service.

13. Liability, precedence and term

  • Each party's liability under this DPA (including the SCCs, to the extent permitted) is subject to the exclusions and the aggregate cap of the Agreement; nothing in this Section limits a data subject's rights against either party under Data Protection Laws.
  • In case of conflict: the SCCs prevail over this DPA; this DPA prevails over the Agreement with respect to the processing of Customer Personal Data.
  • This DPA takes effect with the Agreement and remains in force as long as we process Customer Personal Data. It is governed by the law governing the Agreement, except where the SCCs or mandatory Data Protection Laws require otherwise.

Annex I — Details of processing

  • Subject matter and nature: operation of AI voice agents for Customer — receiving and placing telephone calls; speech recognition; response generation via language models; speech synthesis; call recording and transcription (where enabled); appointment scheduling; knowledge-base retrieval; campaign dialing; analytics and reporting for Customer; storage and hosting.
  • Duration: the term of the Agreement plus the deletion windows of Section 10.
  • Purposes: providing the Service as configured by Customer; no other purposes.
  • Categories of data subjects: End Users (callers and call recipients); Customer's staff and agents; persons whose details appear in Customer Data (e.g. appointment attendees, contacts in uploaded lists and knowledge bases).
  • Categories of personal data: identity and contact data (name, phone number, email); call content (audio, recordings, transcripts, AI-generated summaries and notes); appointment and request details; campaign contact lists; knowledge-base content supplied by Customer; technical and usage metadata (call times, durations, numbers, quality metrics).
  • Special categories: not intended to be processed. The Service is not designed for special-category data; Customer must not configure agents to collect it without a lawful basis and appropriate safeguards (Agreement §6), and must not use the Service for biometric identification (no voiceprinting).
  • Frequency: continuous, as driven by Customer's use.

Annex II — Technical and organizational measures

  • Encryption: TLS 1.2+ for data in transit; encryption at rest for stored content and recordings.
  • Tenant isolation: multi-tenant architecture with tenant-scoped data access enforced at the application and repository layer for every query.
  • Access control: role-based access control; unique accounts; strong password policy with history and lockout; session limits; token revocation on password change; administrative access separated from customer accounts and restricted to authorized personnel.
  • Network and infrastructure: firewalled services; management interfaces on private networks; secrets management via environment isolation; provider-level physical security for hosting.
  • Monitoring and logging: centralized structured logging with PII redaction, metrics and alerting; audit trails for sensitive operations.
  • Vulnerability management: dependency and image updates; periodic internal security reviews and hardening; incident response runbooks.
  • Resilience and backups: replicated data stores, scheduled backups with retention and rotation, disaster-recovery procedures.
  • Data minimization: configurable retention; recording and transcription only where enabled by Customer; announcement/consent tooling for calls.
  • Personnel: confidentiality undertakings, least-privilege access, security awareness.

Annex III — Sub-processor categories

  • Cloud hosting, compute and storage (including recording storage)
  • Telephony and SIP carriers / communications infrastructure
  • Speech-to-text (transcription) providers
  • Large language model (AI response generation) providers
  • Text-to-speech (voice synthesis) providers
  • Vector database / retrieval infrastructure for knowledge bases
  • Transactional email delivery
  • Observability and error-tracking tooling

The named list of Sub-processors, with locations, is available on request under confidentiality from legal@mail.jently.io. Payment processing (Stripe) occurs in our capacity as an independent controller and is covered by the Privacy Policy.

Jentlyjently.io

The all-in-one solution for modern contact centers.

Product

  • Call Center
  • Voice Agent
  • Features
  • Use Cases
  • Pricing
  • Documentation

Company

  • support@mail.jently.io

© 2026 jently.io. All rights reserved. Jently is a product of TECHERO LLC.

Privacy PolicyTerms of ServiceCancellation & Refunds
All systems operational