Data Processing Agreement
Last updated: 8 Oct 2026
This data processing agreement (the “DPA”) forms an integral part of the Terms of Service and is concluded between the customer of the Telofia service (the “Controller”) and AI AGENT HUB PROSTA SPÓŁKA AKCYJNA, registered office in Katowice, ul. Jana III Sobieskiego 11/E6, 40-082 Katowice, Poland, KRS 0001168165 (the “Processor”), upon acceptance of the Terms. It applies to all personal data processed by the Processor on behalf of the Controller as part of the Telofia service. The Polish version is authoritative.
1. Subject matter and duration
The Controller entrusts the Processor with processing personal data for the purpose of providing the Telofia AI phone assistant service, for the term of the service agreement and for the period necessary to delete or return the data after it ends.
2. Nature and purpose of processing
Answering and conducting phone and web conversations, speech recognition and synthesis, generating responses with language models, booking appointments and transferring calls, sending SMS and e-mails related to the call, making recordings (if enabled by the Controller), transcripts, summaries and quality scores of calls, storing call history and synchronising with integrations connected by the Controller.
3. Categories of data and data subjects
Data subjects: people who call the Controller or speak with its assistant, the Controller’s customers and contacts, and its staff.
Categories of data: phone numbers, names, e-mail addresses, voice recordings, call transcripts and summaries, appointment and request details and other information provided by callers. The Controller should not configure the assistant in a way that leads to the collection of special categories of data (Article 9 GDPR) unless this is necessary and there is a legal basis for it.
4. The Controller’s instructions
The Processor processes data only on documented instructions from the Controller, which include in particular the Terms, this DPA and the settings selected by the Controller in the dashboard (e.g. enabling recording, retention period, integrations). If, in the Processor’s opinion, an instruction infringes data protection law, the Processor informs the Controller immediately.
5. Processor obligations
The Processor: ensures that persons authorised to process data have committed themselves to confidentiality; implements appropriate technical and organisational measures (Article 32 GDPR); assists the Controller in responding to data subject requests and in complying with the obligations under Articles 32–36 GDPR; and does not use the entrusted data for its own purposes, including training artificial intelligence models.
6. Subprocessors
The Controller gives general authorisation for the use of the subprocessors listed on the subprocessors page. The Processor imposes on subprocessors data protection obligations no less stringent than those in this DPA and is liable for their actions as for its own. The Processor gives at least 14 days’ notice of intended changes to the list; within that period the Controller may raise a reasoned objection and, if no agreement is reached, terminate the agreement.
7. Transfers to third countries
Data is stored primarily in the EU (Frankfurt). Data is transferred outside the European Economic Area only on the basis of an adequacy decision (including the EU–US Data Privacy Framework) or standard contractual clauses together with supplementary measures.
8. Security measures
Encryption in transit and at rest, encryption of integration tokens, access control and least privilege, logical separation of customer data, private recording storage accessible via short-lived signed links, event logging, backups, vulnerability management and incident response procedures.
9. Personal data breaches
The Processor notifies the Controller without undue delay, where possible within 48 hours, after becoming aware of a personal data breach and provides the information the Controller needs to notify the supervisory authority and inform the data subjects.
10. Retention, deletion and return of data
Recordings and transcripts are kept for the period set by the Controller in the dashboard (Privacy mode) or until deleted by the Controller. After the agreement ends, the Processor, at the Controller’s choice communicated to support@aiagenthub.pl, returns or deletes the entrusted data within 30 days, unless the law requires further storage.
11. Audits and liability
The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allows audits, including inspections, with at least 14 days’ prior notice and no more than once a year (unless there has been a personal data breach). The parties’ liability is governed by the Terms, subject to Article 82 GDPR.
AI AGENT HUB PROSTA SPÓŁKA AKCYJNA · support@aiagenthub.pl
ul. Jana III Sobieskiego 11/E6, 40-082 Katowice · NIP: 6343054493 · KRS: 0001168165 · REGON: 541503506