Data Processing Addendum
Version: v1.0 · Incorporated into the Vocapable Master Services Agreement.
1. Roles and Scope
1.1 For personal information in Customer Content and call data (contact records, call audio, transcripts, consent records, outcomes), Customer is the business/controller and Vocapable is the service provider/processor, processing solely to provide the Service per the MSA and Customer’s documented instructions (the configuration and use of the Service being such instructions).
1.2 For Vocapable’s own account, billing, security, and usage telemetry data, Vocapable is an independent business/controller per its Privacy Policy.
2. Vocapable’s Obligations
Vocapable will, with respect to personal information processed on Customer’s behalf (the CCPA-required certifications of Cal. Civ. Code § 1798.100(d) and 11 CCR § 7051):
- process it only for the limited and specified purpose of providing the Service described in the MSA, and not for any other purpose;
- not sell it or share it (as those terms are defined by the CCPA/CPRA);
- not retain, use, or disclose it outside the direct business relationship between the parties or for any purpose (including a commercial purpose) other than providing the Service, except as permitted by the CCPA and its regulations;
- not combine it with personal information received from other sources, except as permitted by the CCPA and its regulations;
- comply with all applicable obligations under the CCPA and provide the same level of privacy protection required of businesses;
- notify Customer if it determines it can no longer meet its obligations under the CCPA, and grant Customer the right, upon such notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information;
- permit Customer to take reasonable and appropriate steps to help ensure Vocapable uses personal information consistently with Customer’s CCPA obligations, satisfied by the audit provision in Section 5;
- impose confidentiality obligations on personnel with access;
- maintain reasonable technical and organizational security measures (tenant isolation via row-level security, encryption in transit and at rest, credential vaulting, access logging);
- provide breach notice to Customer without undue delay after confirmation; and
- provide reasonable assistance with data-subject requests and, at Customer’s expense, with assessments.
3. Subprocessors
Customer generally authorizes subprocessors used to provide the Service, currently: Amazon Web Services (hosting and storage), Twilio (platform test-call telephony, and messaging where configured), Stripe (payments), xAI and other model providers as configured (language-model inference), and Resend (transactional email). Vocapable provides the current list on request to support@capstralabs.com, will provide notice of additions, and remains responsible for subprocessors’ performance. Where Customer brings its own provider credentials (BYO Twilio, BYO model keys), that provider processes under Customer’s own agreement with it and is not a Vocapable subprocessor.
4. Deletion and Retention — the Compliance Carve-Outs
4.1 On termination or verified deletion request, Vocapable deletes or de-identifies personal information within 60 days, except:
- Compliance evidence — consent records, scrub results and verdicts, disclosure and opt-out evidence, attestations, and per-call policy snapshots — is retained for at least five (5) years notwithstanding any deletion request, because it is the legal-defense record of both parties and is retained as a legal obligation and for the establishment and defense of legal claims.
- Suppression data — the do-not-call ledger — is retained indefinitely, because deleting it would cause the very contact the record exists to prevent. Suppression entries are minimized to what suppression requires.
4.2 Deleted contacts are tombstoned (no new calls may start to them) with the carve-outs above preserved.
5. Audit
Vocapable will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits if and when such audits exist (none is represented to exist today), no more than annually absent a confirmed incident.
6. Order of Precedence
This DPA controls over the MSA for personal-information processing. Processing takes place in the United States. The Service is offered to U.S. businesses for U.S. calling; if the parties later agree to processing that requires additional transfer mechanisms or state-law addenda, they will execute them before that processing begins.