← Back to home
Version v1.0-2026-05-12. This Data Processing Agreement is the in-product processor DPA. Acceptance is recorded in onboarding (step-dpa). Enterprise customers may execute a separate master services agreement and DPA instead of relying on this web acceptance flow.

Data Processing Agreement (DPA) — Version 1.0

STATUS: APPROVED v1.0. This file is the canonical in-product Data Processing Agreement. Material changes require a new Version string, a Change Log entry, and coordinated updates to onboarding acceptance and /legal/dpa.

Effective Date: [Date the customer accepts in onboarding] Version: v1.0-2026-05-12 Parties:

This Data Processing Agreement ("DPA") forms part of and supplements the Master Services Agreement, Order Form, or other written agreement between the Parties (the "Agreement") under which AutoShop Voice AI provides its AI-powered phone receptionist service (the "Service") to Customer. In the event of a conflict between this DPA and the Agreement on data- protection matters, this DPA controls.


1. Definitions

For purposes of this DPA:

2. Roles and Subject Matter

3. Categories of Data and Data Subjects

4. Customer Instructions and Compliance

5. Security

6. Sub-processors

7. Data Subject Rights

8. Security Incidents

9. Return or Deletion of Personal Information

10. Audits

11. International Transfers

12. Liability and Term

13. Miscellaneous


Schedule A — Authorized Sub-processors

The current authoritative list is published at /legal/sub-processors and updated under Section 6.2 of this DPA. As of the version date above:

Sub-processorServiceRegionCategories of Data
Google LLC (Gemini Live API)Voice AI inferenceUnited States (us-central1)Call audio (transient, not retained by Sub-processor), transcripts
Twilio Inc.Telephony (PSTN), SMS deliveryUnited StatesCaller phone numbers, call audio, SMS content
Stripe, Inc.Subscription billingUnited StatesCustomer (Controller) billing data only — no caller Personal Information
Akamai Technologies, Inc. (Managed PostgreSQL)Application database (PostgreSQL)United StatesAll categories listed in §3.2
Akamai Technologies, Inc. (Linode Compute)Application hosting and execution (Node.js / Next.js)United StatesAll categories listed in §3.2
Selzy SAS (UniOne)Transactional email delivery to CustomerUnited States / EU edge (delivery only)Customer email address and message content only — no caller Personal Information

Authentication. Primary shop sign-in uses first-party httpOnly session cookies (HS256 JWTs issued by AutoShop Voice); there is no separate Sub-processor solely for customer identity beyond the email provider used for password reset and notices.


Schedule B — Customer Acceptance Block

By accepting this DPA in the AutoShop Voice AI onboarding flow, Customer warrants that the individual accepting has authority to bind Customer.

FieldCaptured at acceptance
DPA Versionv1.0-2026-05-12 (this document)
Acceptance timestampUTC server time at acceptance
Signer nameProvided by signer
Signer titleProvided by signer
Signer emailTied to authenticated AutoShop Voice AI account
IP addressSource IP of the acceptance request

Electronic acceptance. Customer's acceptance through the AutoShop Voice AI in-product flow (authenticated account, designated checkbox, captured UTC timestamp, and source IP address) constitutes Customer's agreement to this DPA and constitutes an electronic signature where permitted by the Agreement and Applicable Law, including the U.S. Electronic Signatures in Global and National Commerce Act (E-SIGN) and the Uniform Electronic Transactions Act (UETA) as adopted in the governing jurisdiction.


Change Log

VersionDateNotes
v1.0-DRAFT2026-04-25Initial draft.
v1.0-DRAFT (r2)2026-04-25Resolved codebase-confirmable [REVIEW] items: Sensitive PI scope (none captured by schema), GDPR addendum path, Schedule A finalized from package.json + DEPLOYMENT.md, /legal/sub-processors page live, U.S.-only region confirmation. Items still requiring outside counsel: legal entity name, CCPA Service-Provider carve-out wording, background-check scope, SOC 2 commitment, governing law, E-SIGN/UETA enforceability, liability carve-outs.
v1.0-2026-05-122026-05-12Counsel-approved v1.0: Processor identified as AutoShop Voice AI, Inc. (Delaware); CCPA Service Provider / no-model-training clause finalized; background-check, audit-report, liability, governing-law, and E-SIGN/UETA acceptance language finalized. Supersedes v1.0-DRAFT for in-product acceptance.