Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Agreement between Teerya Portal L.L.C ("Processor", "we") and the Client ("Controller", "you") whenever we process personal data on your behalf, for example the personal data of your customers who speak with AI agents we run for you ("Client Personal Data").
1. Roles and instructions
You are the controller (or, under the CCPA, the business) and we are the processor (or service provider). We process Client Personal Data only on your documented instructions, which are the Agreement and your written configuration choices, unless the law requires otherwise, in which case we will tell you first where lawful. We will tell you if we believe an instruction breaks data protection law.
2. Details of processing
- Subject matter and duration: providing the services for the term of the Agreement and any export period.
- Nature and purpose: operating AI voice and messaging agents, transcription, summarisation and data extraction, CRM and calendar integration, reporting and quality optimisation.
- Data subjects: your customers, leads, callers and staff who interact with the agents.
- Personal data: contact details, voice recordings, transcripts, conversation content and data points you configure.
- Special categories: none intended. You will not configure agents to collect special-category, children's or financial account data without our written agreement.
3. Our commitments
- Confidentiality: everyone we authorise to process Client Personal Data is bound by confidentiality.
- Security: we maintain appropriate technical and organisational measures (Annex below).
- Sub-processors: you authorise our current sub-processors (list available on request and summarised on our Sub-processors page). We will give at least 30 days' notice of new sub-processors; you may object on reasonable data protection grounds, and if we cannot address the objection you may terminate the affected service with a pro-rata refund. We impose equivalent data protection obligations on sub-processors and remain liable for them.
- Assistance: we help you respond to data subject requests, carry out data protection impact assessments and consult regulators, taking into account the nature of processing.
- Breach notification: we notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach, with the information you reasonably need.
- Deletion or return: at the end of the services we delete or return Client Personal Data at your choice, within 30 days after the export period, unless the law requires storage.
- Audits: we make available information necessary to demonstrate compliance and allow for audits, on reasonable notice, no more than once a year unless a breach or regulator requires it.
- No selling, sharing or secondary use: we do not sell or share Client Personal Data, retain, use or disclose it outside our direct business relationship with you, combine it with other data except as allowed by the CCPA, or use it to train AI models available to other clients.
4. International transfers
Where Client Personal Data subject to the GDPR, UK GDPR, Swiss law or another law with transfer rules is transferred to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Module 2 controller-to-processor, or Module 3 processor-to-processor where relevant), the UK International Data Transfer Addendum, and any equivalent clauses required by other laws are incorporated into this DPA by reference, with this DPA supplying the required details. The UAE is our country of establishment; for the Clauses the governing law and forum are those of Ireland unless another EU member state is agreed.
5. Your commitments
You are responsible for having a lawful basis for the processing, giving your customers any required privacy notice, AI disclosure and recording notice, and obtaining any consent required, including for outbound contact.
Annex: security measures
- Encryption in transit (TLS) and encryption at rest provided by our infrastructure providers.
- Role-based, least-privilege access with multi-factor authentication for administrative accounts.
- Separation of each client's configuration and data.
- Logging of administrative access and changes; versioned agent configurations with rollback.
- Staged testing of changes before production release.
- Vendor due diligence and contractual data protection terms with sub-processors.
- Incident response procedure with notification timelines above.
Contact
Teerya Portal L.L.C, trading as AhmadAI. Commercial Licence No. 1316315, Commercial Register No. 2234196, issued by the Department of Economy and Tourism, Government of Dubai. Registered address: Office S20, Mohammed Bin Rashid Establishment for SME Development building, Port Saeed, Deira, Dubai, United Arab Emirates. Legal: legal@ahmadai.ai · Privacy: privacy@ahmadai.ai.