Phone.inc

Effective September 10, 2026

Data Processing Agreement

Phone Incorporated ApS (CVR 46213564)

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between Phone Incorporated ApS, CVR 46213564, Højbro Plads 10, 1200 Copenhagen K, Denmark (“Phone.inc”) and the customer that has accepted the Agreement (“Customer”). It applies when Phone.inc processes personal data on Customer’s behalf in providing the Service. By accepting the Agreement, Customer accepts this DPA.

Definitions and roles

  1. Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in Regulation (EU) 2016/679 (“GDPR”). “Customer Personal Data” means personal data processed by Phone.inc on behalf of Customer through the Service, as described in Annex 1.
  2. Customer is the controller and Phone.inc is the processor of Customer Personal Data.
  3. Phone.inc is an independent controller, and this DPA does not apply, for: (a) account, billing, support and security data about Customer and its users; and (b) traffic data, location data and other data Phone.inc processes as a provider of electronic communications services under Danish law, including data it must retain or disclose under that law. That processing is described in Phone.inc’s Privacy Policy.

Processing on instructions

  1. Phone.inc processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to third countries, unless EU or Danish law requires otherwise. In that case Phone.inc informs Customer of the requirement before processing, unless that law prohibits it.
  2. The Agreement, this DPA and Customer’s use and configuration of the Service are Customer’s complete instructions. Additional instructions must be agreed in writing.
  3. Phone.inc informs Customer promptly if, in its opinion, an instruction infringes the GDPR or other data protection law.

Confidentiality

  1. Phone.inc ensures that everyone authorised to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

Security

  1. Phone.inc implements and maintains the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
  2. Phone.inc may update the measures in Annex 2 provided the overall level of security is not reduced.

Sub-processors

  1. Customer gives Phone.inc general authorisation to engage sub-processors. The current sub-processors are listed in Annex 3.
  2. Phone.inc gives at least 30 days’ notice of any new or replacement sub-processor by email to Customer’s account owner.
  3. Customer may object on reasonable data protection grounds within the notice period. If the parties cannot resolve the objection, Customer may terminate the affected part of the Service with effect from the date the change takes effect and receive a refund of prepaid fees for the remaining term. This is Customer’s sole remedy for the objection.
  4. Phone.inc imposes data protection obligations on each sub-processor by written contract that are no less protective than those in this DPA, and remains liable to Customer for each sub-processor’s performance of those obligations.

Call recordings and transcriptions

  1. Activation. Call recording and transcription are configured per business number and can be enabled or disabled independently of each other. Call recording is enabled by default when a business number is created, and Customer can disable it at any time. Where transcription is enabled and call recording is disabled, Phone.inc records the call transiently for the sole purpose of producing the transcription and deletes that recording immediately after the transcription is completed, typically within minutes. An AI summary is produced for every call that is transcribed.
  2. Customer’s responsibilities. Customer is solely responsible for having a lawful basis for recording and transcribing calls, including obtaining any consent required, and for informing call participants, including external callers, before recording starts. Customer can inform callers through the welcome message it configures in the Service. Phone.inc displays a warning in the Service when call recording is enabled. Where only transcription is enabled, the call is not retained as a recording.
  3. How transcriptions and summaries are produced. Calls are transcribed after the call has ended by a speech-to-text sub-processor, and summaries are produced by a language model operated by Phone.inc’s hosting provider. Both sub-processors are listed in Annex 3, and all of this processing takes place in the EU/EEA. The language model provider does not retain call content, and the speech-to-text provider does not retain call audio, after processing.
  4. No model training. Phone.inc does not use, and does not allow its sub-processors to use, call recordings, transcriptions or summaries to train or improve AI models, or to build test or evaluation datasets.
  5. Retention and deletion. Recordings and transcriptions are kept until Customer deletes them, either individually in the Service or through automatic deletion rules Customer configures in the Service. Customer can set separate deletion rules for recordings and for transcriptions. Where Customer has set no deletion rule, recordings and transcriptions are deleted 12 months after the call. Summaries follow the deletion rules for transcriptions. Deleted recordings are removed from non-current S3 versions within 30 days. Deleted transcriptions and summaries are removed from database backups within 7 days.
  6. Access by Phone.inc personnel. Access to recordings, transcriptions and summaries is limited to designated Phone.inc personnel. They access them only to provide support at Customer’s request, to investigate and fix errors in the Service, or where required by law. The reason for each access is recorded, and all access is logged in an audit trail. Customer can obtain the audit trail for its account on request to compliance@phone.inc.
  7. Sensitive content. Customer must not enable call recording or transcription on business numbers used for calls in which special categories of personal data within the meaning of Article 9 GDPR are discussed. The Service is not designed to process such data in recordings, transcriptions or summaries, and Customer is responsible for any such data recorded or transcribed in breach of this clause. Phone.inc encrypts recordings, transcriptions and summaries at rest.
  8. Requests from authorities. If Phone.inc receives a request from a public authority for recordings, transcriptions or summaries, it handles the request in accordance with Danish law and in cooperation with its telecommunications supplier, and each request is handled by Phone.inc’s CEO. Phone.inc notifies Customer of the request in every case where it is legally permitted to do so, and discloses only what the request legally requires.

Assistance

  1. Taking into account the nature of the processing, Phone.inc assists Customer through the functionality of the Service and appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Chapter III GDPR. Phone.inc forwards any such request it receives directly to Customer and does not respond to it except on Customer’s instructions.
  2. Phone.inc provides reasonable assistance to Customer with data protection impact assessments and prior consultation with supervisory authorities under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to Phone.inc.
  3. Phone.inc may charge reasonable fees for assistance that goes beyond the functionality of the Service.

Personal data breaches

  1. Phone.inc notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
  2. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not yet available, Phone.inc provides it in phases without undue further delay.
  3. Phone.inc’s notification of or response to a breach is not an acknowledgement of fault or liability.

Audits and information

  1. Phone.inc makes available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, in the form of responses to reasonable security questionnaires and, once obtained, certifications and third-party audit reports.
  2. Customer agrees that providing this information fulfils Phone.inc’s obligation to allow for and contribute to audits. Where a supervisory authority requires an audit or inspection of Phone.inc, Phone.inc will cooperate with it, subject to reasonable notice and confidentiality. Where the audit concerns Customer, Customer bears all costs of the audit, including any auditor’s fees and Phone.inc’s own costs, such as the time its personnel spend on the audit, charged at Phone.inc’s then-current rates.

International transfers

  1. Phone.inc’s core backend infrastructure, including storage of recordings, transcriptions and summaries, is hosted in Ireland. Calls involving European phone numbers are routed through telephony infrastructure in the EU (Ireland, Sweden and Germany). Calls involving phone numbers outside Europe may be routed through telephony infrastructure outside the EU/EEA, in the AWS region that serves the country of the phone number. Those transfers rely on the SCCs in the Amazon Web Services data processing addendum. Calls are carried to and from the public telephone network by interconnecting telecommunications operators, which act as independent providers of electronic communications services and not as sub-processors. Phone.inc transfers Customer Personal Data to a third country only in accordance with Chapter V GDPR.
  2. Where Phone.inc engages a sub-processor outside the EU/EEA, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework where the sub-processor is certified) or on the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (“SCCs”).
  3. Where Customer is located outside the EU/EEA in a country without an adequacy decision, the SCCs are incorporated into this DPA by reference: Module 4 (processor to controller) applies to transfers from Phone.inc to Customer. Annex 1 and Annex 2 complete the SCC annexes. For the SCCs, the governing law is Danish law and the competent courts are the courts of Denmark.
  4. Transfers subject to UK data protection law are governed by the SCCs as amended by the UK International Data Transfer Addendum. Transfers subject to the Swiss Federal Act on Data Protection are governed by the SCCs with the amendments required by that Act, with the FDPIC as competent supervisory authority.
  5. In case of conflict, the SCCs prevail over this DPA.

Return and deletion

  1. On termination of the Agreement, Customer may export Customer Personal Data using the Service’s export functionality for 30 days.
  2. After that period, Phone.inc deletes Customer Personal Data within 30 days, unless EU or Danish law requires retention. Deleted database data is removed from backups within 7 days. Deleted recordings, voicemails and greeting audio are removed from non-current S3 versions within 30 days. Phone.inc confirms deletion in writing on request.

Liability, term and changes

  1. Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where the SCCs or applicable law provide otherwise.
  2. This DPA remains in force for as long as Phone.inc processes Customer Personal Data on Customer’s behalf.
  3. In case of conflict, this DPA prevails over the Agreement with respect to the processing of Customer Personal Data.
  4. Phone.inc may update this DPA by giving at least 30 days’ notice. Updates will not materially reduce the protection of Customer Personal Data unless required by law.
  5. This DPA is governed by Danish law, and disputes are subject to the jurisdiction set out in the Agreement.

Annex 1: Description of processing

Subject matter: provision of the Phone.inc business phone service under the Agreement.

Duration: the term of the Agreement plus the deletion period in the Return and deletion section.

Nature and purpose: Phone.inc processes personal data only to provide the Service the Customer configures, including:

  • hosting and operating the Service, and authenticating the Customer’s users
  • routing inbound and outbound calls, including over the public telephone network and in the browser and mobile apps
  • storing call records: numbers, direction, timestamps, duration, and outcome
  • playing greetings the Customer writes, and generating greeting audio from that text
  • recording calls and storing voicemails where the Customer enables those features
  • transcribing recordings and voicemails where enabled, producing a short summary of a transcribed call, and, where a matching contact has no name, suggesting a name from the transcription and saving it on that contact
  • storing contacts the Customer keeps in the Service
  • showing caller context during a call by retrieving data from integrations or endpoints the Customer connects, and storing that context with the call
  • searching calls, transcriptions, summaries, voicemails, and contacts
  • sending the Customer the call and account events it chooses to receive by webhook
  • delivering push notifications that wake the Customer’s mobile apps for an incoming call
  • logging and error monitoring needed to run and secure the Service
  • provisioning numbers, including submitting business and identity details where a regulator requires them for a number
  • providing support for the Customer’s account

Call recordings, voicemails, transcriptions, summaries, and other communications content are processed to provide these features to the Customer. They are not used to train general-purpose AI models.

Categories of data subjects:

  • the Customer’s employees and other users of the Service
  • persons who call, or are called by, the Customer’s users
  • the Customer’s contacts
  • persons whose details are returned by an integration or endpoint the Customer connects
  • the Customer’s representatives identified for number registration, where that registration is required

Types of personal data:

  • user account data: name, email address, phone numbers, role, sign-in times, and IP address
  • authentication data: hashed passwords and two-factor secrets
  • device data: device name, app version, and push-notification token
  • contact data: name, phone number, email address, company name, and notes
  • call metadata: calling and called numbers, direction, timestamps, duration, and call outcome
  • communications content, where enabled: call recordings, voicemail audio, greeting text and greeting audio, transcriptions, and summaries
  • caller context retrieved for a call, which may include a name, email address, company, notes, and other details the connected service returns
  • number-registration data, where required: name, business address, contact email and phone, company and VAT identifiers, and identity or address documents a regulator requires for that number

Special categories of data: the Service does not ask for special categories of data and has no separate store for them. A recording, voicemail, transcription, summary, contact note, or caller-context field can still contain them if a person says them or the Customer stores them. The Customer must not record or transcribe calls in which special categories of data are discussed, and must not put special categories of data into the Service (see the Call recordings and transcriptions section).

Frequency of transfer (for the SCCs): continuous for the term of the Agreement.

Retention: as set out in the Call recordings and transcriptions section and the Return and deletion section.

Competent supervisory authority (for the SCCs): Datatilsynet (the Danish Data Protection Agency).

Annex 2: Technical and organisational measures

Encryption in transit and at rest. The web application, API, and mobile apps require HTTPS. Production refuses plain HTTP. Cloudflare and the load balancer terminate TLS in front of the application.

Call recordings, voicemails, and greeting audio are stored in a private Amazon S3 bucket in Ireland. The bucket blocks public access, has versioning turned on, and encrypts objects with SSE-S3 (AES-256). Non-current versions are deleted after 30 days.

Transcriptions, transcription segments, summaries, and cached caller context are encrypted at rest in the database with application-level encryption. The same protection covers contact names, email addresses, company names and notes, user email addresses, sign-in IP addresses, two-factor secrets, and integration credentials. Phone numbers on calls, voicemails, contacts, and users are stored unencrypted so the Service can look them up.

Access control, authentication and MFA. Each customer is a separate tenant. A user only reaches that customer’s account. Passwords are stored hashed. Two-factor authentication is mandatory for Phone.inc admin accounts in production. A customer can require it for its own users.

Phone.inc staff reach production AWS through IAM Identity Center. The application uses instance roles, and secrets are kept in AWS Secrets Manager. Deploy and infrastructure access is split across separate roles.

Opening a recording, transcription, summary, or caller context in the admin tools requires a written reason. That access is written to an append-only log, which cannot be changed or deleted. Signing in as a customer user is logged the same way.

Logging and monitoring. Application and telephony logs and traces go to ClickHouse Cloud in Ireland (eu-west-1) and are viewed in ClickStack. Those logs are kept for 30 days. Passwords, tokens, and similar secrets are filtered out of application logs. Errors are reported to Sentry, with ingestion in the EU.

Backup and recovery. Database backups are managed by PlanetScale. The database is in PlanetScale’s eu-west region, which runs on AWS in Ireland (eu-west-1), and backups are kept for 7 days.

Vulnerability management and secure development. A daily scan audits dependencies and runs dependency scanning against the application. The scan fails when it finds a known vulnerability.

Incident response. A written incident response policy, owned by the CEO.

Personnel. Confidentiality undertakings in employment contracts, security training, and removal of access when staff leave.

Hosting and physical security. The application, telephony, file storage, and call-summary models run on Amazon Web Services in Ireland (eu-west-1). The database runs on PlanetScale in that same AWS region. Logs run on ClickHouse Cloud there. Cloudflare serves the website and terminates TLS for the application, and can relay call media. Amazon Web Services is responsible for the physical security of its data centres and holds ISO/IEC 27001 certification and SOC 2 reports for them.

Certifications. None at the effective date of this DPA. Phone.inc is working towards ISO/IEC 27001 and SOC 2.

Annex 3: Sub-processors

At the effective date of this DPA, Phone.inc uses the following sub-processors. For each sub-processor established outside the EU/EEA, transfers rely on SCCs or Data Privacy Framework certification under that sub-processor’s data processing agreement.

Sub-processor Purpose Location
Amazon Web Services EMEA SARL Application and telephony hosting; storage of recordings, voicemails and greetings (Amazon S3); language model processing for call summaries and caller-name extraction (Amazon Bedrock). EU for European calls; for calls involving non-European numbers, the AWS region serving the country of the phone number.
PlanetScale Primary production database, including accounts, calls and contacts, and database backups. EU
ElevenLabs Transcription of call recordings and voicemails, and text-to-speech for greetings. EU
Turbopuffer Search index of transcriptions, summaries, voicemails and contact details. EU
ClickHouse Cloud Application and telephony logs and traces. EU
Sentry Error and performance monitoring. EU
Cloudflare Application proxying and TLS termination; relay of call media (TURN) when a direct connection is blocked; provision of all DNS services. Cloudflare’s global network, at the location nearest the user.
Resend Transactional email sent by the Service. EU
Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging) Push notifications that wake the mobile apps for incoming calls, including device tokens and call notification data. Global

Calls are carried to and from the public telephone network by the following interconnecting telecommunications operators, which act as independent providers of electronic communications services and not as sub-processors: Telnyx, DIDWW and inMobile.