01
Scope & parties
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Amomic-AI (“Processor”, “we”) and the business customer using the platform (“Customer”, “you”). It applies whenever we process personal data of your End Users on your behalf — chat transcripts, call recordings, contact details, email threads and similar (“Customer Personal Data”).
Under India’s DPDP Act you are the data fiduciary and we are the data processor; under the GDPR, you are the controller and we are the processor. Data about your own account (billing, team members) is covered by our Privacy Policy, not this DPA.
02
Our processing instructions
We will process Customer Personal Data only:
- To provide, maintain and secure the Services as described in the Terms and your configuration of the platform;
- Per your documented instructions given through the console, APIs or in writing; and
- As required by applicable law — in which case we will inform you before processing unless the law prohibits it.
We will tell you if, in our view, an instruction violates applicable data-protection law. We do not use Customer Personal Data to train third-party foundation models, and we contractually prohibit our AI providers from doing so.
03
Details of processing
| Item | Description |
|---|---|
| Nature & purpose | Operating AI customer-interaction agents: receiving and generating messages and calls, transcription and speech synthesis, knowledge retrieval, analytics, ticketing and human handoff. |
| Categories of data | Names, phone numbers, email addresses, conversation content (text and audio), metadata such as timestamps and channel, and any data End Users share in conversations. |
| Data subjects | The Customer's end users, customers, prospects and other individuals who interact with the Customer's agents. |
| Duration | For the term of the Customer's subscription, plus the deletion window described in section 8. |
04
Subprocessors
You authorise us to engage subprocessors to help provide the Services — cloud hosting, AI model providers, telephony carriers and messaging platforms. We:
- Maintain the current list at amomic.in/subprocessors;
- Bind each subprocessor to data-protection obligations no less protective than this DPA;
- Update the page before adding a subprocessor that handles Customer Personal Data — if you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected service with a pro-rata refund of prepaid, unused fees; and
- Remain liable for our subprocessors’ performance.
05
Security measures
We implement technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest;
- Per-organisation tenant isolation enforced in our application and data layers;
- Role-based, least-privilege access for our personnel, with audited access to production systems;
- Centralised secrets management and key rotation;
- Logging, monitoring and abuse detection.
Our security practices are described further on the Security page. Our personnel with access to Customer Personal Data are bound by confidentiality obligations.
06
Incident notification
If we become aware of a personal-data breach affecting Customer Personal Data, we will notify you without undue delay, and no later than 72 hours after becoming aware, with the information we have about its nature, scope and the measures taken. We will cooperate with your own notification obligations to authorities and data subjects, which remain yours as the data fiduciary.
07
Data-subject requests & assistance
- If an End User contacts us directly to exercise a privacy right regarding your deployment, we will refer them to you and not respond substantively except as law requires.
- We provide console tools and, where needed, direct assistance so you can access, export, correct and delete End User data to fulfil requests.
- Taking into account the nature of the processing, we will reasonably assist you with security, breach-notification and impact-assessment obligations.
08
Return & deletion
During your subscription you can export Customer Personal Data through the console and APIs. When your account closes:
- We delete Customer Personal Data from active systems within 30 days of account closure, unless law requires longer retention;
- Residual copies in encrypted backups expire on the backup rotation schedule and are not restored except for disaster recovery.
09
Audits & information
On written request (not more than once per year, unless required by a regulator or following a breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation, subprocessor agreements summaries and completed questionnaires. Where that is insufficient, we will accommodate an audit under reasonable confidentiality, scope and scheduling terms, at your cost.
10
International transfers
Customer Personal Data is primarily processed on Google Cloud infrastructure. Certain subprocessors (for example speech-to-text and language-model providers) process data in other jurisdictions, including the United States, as identified on the Subprocessors page. We ensure transfers are covered by appropriate safeguards required by applicable law.
11
Liability & precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails. This DPA terminates automatically when we finish deleting Customer Personal Data after your account closes.
Need a signed copy?
Questions about this policy?
Write to us and mention “Data Processing Agreement” in the subject line — we read and answer every message.
support@amomic.in