You own the data from your calls, texts and jobs. We process it for you, only to run SERVALO for you, and never sell it or use it to train AI models. This addendum is part of the Terms you accept at signup.
Version 2026-10-09
1.1 For personal data in Customer Data, the Customer is the controller (and the "business" under the CCPA), and SERVALO is the processor (and the "service provider").
1.2 SERVALO is a controller only of the data it collects for its own business (for example, account billing contacts and website visitors), which its privacy policy covers.
Annex 1 sets out the subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects.
3.1 Documented instructions. SERVALO processes personal data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's settings and use of the Service are those instructions. SERVALO tells the Customer if it believes an instruction breaks the law, and may decline to follow it.
3.2 Legal processing. SERVALO may process personal data where the law requires it. Before doing so it tells the Customer, unless the law forbids that.
3.3 Customer's duties. The Customer is responsible for having a lawful basis and every notice and consent its processing needs beyond what the Service provides (Terms Sections 6.6 and 8.1), for the accuracy of its data, and for its instructions.
3.4 Data the Service is not for. The Customer will not use the Service to collect payment card numbers, Social Security numbers, health information, children's data, or personal data of people in the EU, UK or Switzerland.
4.1 Business purpose only. SERVALO processes personal data only to provide, support, secure and improve the Service for the Customer, as described in Annex 1.
4.2 SERVALO will not:
4.3 Authorized uses. The Customer authorizes these two uses, which serve the Customer:
4.4 De-identified data. Where SERVALO holds de-identified data, it (a) takes reasonable measures so the data cannot be linked to a person or the Customer, (b) publicly commits not to re-identify it, and (c) will not try to re-identify it. The public commitment is on servalo.io/privacy.
4.5 Certification. SERVALO certifies that it understands and will comply with the restrictions in this Section 4.
4.6 Notice of inability. SERVALO will tell the Customer if it can no longer meet its CCPA or other state-law obligations. The Customer may then take reasonable steps to stop and fix unauthorized use, including ending the processing.
SERVALO ensures that every person it authorizes to process personal data (staff, contractors and subprocessors) is bound by a duty of confidentiality, by contract or law, and has access only as their role requires.
SERVALO keeps the technical and organizational measures in Annex 2, appropriate to the risk. SERVALO may update them, but will not reduce the overall level of protection.
7.1 Authorization. The Customer authorizes SERVALO to use the subprocessors listed in the subprocessor list (published at servalo.io/dpa#subprocessors).
7.2 Flow-down. SERVALO puts each subprocessor under a written contract with data protection terms covering confidentiality, security and deletion. SERVALO remains responsible for each subprocessor's performance.
7.3 Changes, with 30 days' notice. SERVALO will tell the Customer at least 30 days before adding or replacing a subprocessor, by email to the account owner and by updating the list.
7.4 Right to object. The Customer may object in writing on reasonable data protection grounds within that 30-day period. The parties will discuss it in good faith. If SERVALO cannot offer a reasonable alternative, the Customer may end the affected Service by notice and receive a refund of prepaid fees for the period after it ends.
7.5 Emergency replacement. If a subprocessor must be replaced urgently for security or continuity, SERVALO may do so first and give notice promptly after, with the same right to object.
8.1 If SERVALO receives a request from a caller or other person about their personal data (to access, delete, correct or opt out), SERVALO tells the Customer without undue delay. The Customer authorizes SERVALO to carry out a deletion request on its behalf within 30 days, as servalo.io/data-deletion promises, unless the Customer tells SERVALO it must keep the data (for example for warranty or legal records). SERVALO forwards other requests to the Customer and does not answer them on its own, except to confirm receipt or as the law requires.
8.2 SERVALO gives the Customer reasonable help to answer requests, including tools in the Service or, where they do not exist, help on request at no extra charge for reasonable volumes.
8.3 A text opt-out (STOP) is applied at once and automatically, and the opt-out record is kept so the number is not texted again, even after deletion of the person's other data.
SERVALO gives the Customer reasonable help with data protection assessments and with consultations with regulators, where the law requires it and the information is within SERVALO's control.
10.1 Notice within 72 hours. SERVALO notifies the Customer in writing within 72 hours after confirming a breach of security that led to unauthorized access to, or loss, disclosure or alteration of, the Customer's personal data.
10.2 Content. The notice says, as far as known: what happened and when; the kinds and rough number of records and people affected; what SERVALO has done to contain it; what the Customer should do; and a contact. SERVALO updates the Customer as it learns more.
10.3 Cooperation. SERVALO cooperates with the Customer's investigation and its notices to individuals and regulators, and does not notify the Customer's callers or regulators about the Customer's data without the Customer's agreement, unless the law requires it.
10.4 Not an admission. A notice is not an admission of fault.
10.5 SERVALO follows its written incident plan.
11.1 On written request, no more than once a year (and also after a breach, or when a regulator requires it), SERVALO gives the Customer the information reasonably needed to show compliance with this DPA, starting with a written security questionnaire and supporting documents.
11.2 If that does not reasonably answer a specific concern, the Customer (or an independent auditor bound by confidentiality, not a SERVALO competitor) may audit, on at least 30 days' notice, during business hours, at the Customer's cost, without access to other customers' data, and without disrupting the Service.
11.3 Instead of an audit, SERVALO may provide an independent assessment by a qualified assessor, if it has one. SERVALO holds no SOC 2 or similar certification today.
12.1 For the CCPA and each other US state privacy law that applies to the Customer's processing (for example the laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others), SERVALO, as processor, will:
12.2 Where a state law gives the Customer a right this DPA does not, the Customer has that right.
13.1 During the Service, the Customer can export its Customer Data on request (Terms Section 13.2).
13.2 After the Terms end, SERVALO keeps Customer Data for 30 days so the Customer can request an export, then deletes it from the Service within the following 30 days, including voicemail recordings held at Twilio.
13.3 Exceptions: data the law requires SERVALO to keep or that is under a legal hold, kept only for that purpose and still protected by this DPA; opt-out records (Section 8.3); and backup copies, which are deleted on the normal rotation, within 30 days, and are never restored except to recover the Service.
13.4 SERVALO confirms deletion in writing on request.
14.1 This DPA lasts as long as SERVALO processes personal data for the Customer.
14.2 If this DPA conflicts with the Terms on personal data, this DPA wins.
14.3 Liability under this DPA is subject to the limits in Terms Section 22.
The companies that process your customers' data for us. We email you at least 30 days before adding or replacing one.
| Company | What it does for SERVALO | Customer data it handles | Location |
|---|---|---|---|
| Twilio Inc. | Phone numbers, inbound call handling, Twilio ConversationRelay (the real-time voice connection to our AI), SMS delivery and A2P 10DLC registration, call transfers, and storage of voicemail recordings | Caller phone numbers, live call audio (passed through, not stored by SERVALO), voicemail recordings, text message content, call and message metadata | United States |
| Deepgram, Inc. (through Twilio) | Speech-to-text during AI-answered calls | Live call audio; the resulting text | United States |
| ElevenLabs (Eleven Labs, Inc.) (through Twilio) | Text-to-speech: produces the assistant's voice | The assistant's replies (which may repeat caller details such as a name or address) | Being confirmed |
| Anthropic, PBC | The AI model that runs the conversation, extracts intake details, writes call summaries, checks safety guidance wording, and grades call quality | Call transcripts and text, caller details spoken on the call, text message content | United States |
| Supabase, Inc. | Primary database, authentication and file storage | All stored Customer Data: transcripts, callers, bookings, jobs, texts, users, audit logs | United States |
| Vercel Inc. | Hosts the web dashboard, technician app and web APIs | Customer Data in transit through the app; server logs | United States |
| Railway Corporation | Hosts the voice server (the live call connection and the call webhooks) | Call text and caller details in transit during calls; server logs | United States |
| Stripe, Inc. | Subscription billing for SERVALO's own fees | Customer's billing contact and payment details (Stripe holds card data; SERVALO does not) | United States |
| Google LLC (Google Maps Platform) | Geocoding and address validation of service addresses; travel times for dispatch | Service addresses | United States |
| Google LLC (Google Workspace) | Sends operational email to Customers from servalo.io mailboxes (booking alerts, account notices) | Customer contact emails; alert content, which can include caller name, number and job details | United States |
| Resend | Email delivery: fallback for operational email when Workspace is not configured | Same as row 10 when used | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | Error reports, which can contain fragments of request data | United States |