Data Processing Addendum

Your customers' data, handled your way

You own the data from your calls, texts and jobs. We process it for you, only to run SERVALO for you, and never sell it or use it to train AI models. This addendum is part of the Terms you accept at signup.

Version 2026-10-09

1. Roles

1.1 For personal data in Customer Data, the Customer is the controller (and the "business" under the CCPA), and SERVALO is the processor (and the "service provider").

1.2 SERVALO is a controller only of the data it collects for its own business (for example, account billing contacts and website visitors), which its privacy policy covers.

2. Processing details

Annex 1 sets out the subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects.

3. Customer's instructions and duties

3.1 Documented instructions. SERVALO processes personal data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's settings and use of the Service are those instructions. SERVALO tells the Customer if it believes an instruction breaks the law, and may decline to follow it.

3.2 Legal processing. SERVALO may process personal data where the law requires it. Before doing so it tells the Customer, unless the law forbids that.

3.3 Customer's duties. The Customer is responsible for having a lawful basis and every notice and consent its processing needs beyond what the Service provides (Terms Sections 6.6 and 8.1), for the accuracy of its data, and for its instructions.

3.4 Data the Service is not for. The Customer will not use the Service to collect payment card numbers, Social Security numbers, health information, children's data, or personal data of people in the EU, UK or Switzerland.

4. Limits on SERVALO's use of personal data

4.1 Business purpose only. SERVALO processes personal data only to provide, support, secure and improve the Service for the Customer, as described in Annex 1.

4.2 SERVALO will not:

4.3 Authorized uses. The Customer authorizes these two uses, which serve the Customer:

4.4 De-identified data. Where SERVALO holds de-identified data, it (a) takes reasonable measures so the data cannot be linked to a person or the Customer, (b) publicly commits not to re-identify it, and (c) will not try to re-identify it. The public commitment is on servalo.io/privacy.

4.5 Certification. SERVALO certifies that it understands and will comply with the restrictions in this Section 4.

4.6 Notice of inability. SERVALO will tell the Customer if it can no longer meet its CCPA or other state-law obligations. The Customer may then take reasonable steps to stop and fix unauthorized use, including ending the processing.

  • (a) sell or share personal data (as the CCPA defines those words), or use it for targeted or cross-context behavioral advertising;
  • (b) retain, use or disclose it for any purpose other than the business purposes in this DPA, including any commercial purpose of its own;
  • (c) retain, use or disclose it outside the direct business relationship between SERVALO and the Customer;
  • (d) combine it with personal data SERVALO receives from or for anyone else, or collects itself, except as the CCPA regulations permit for a service provider and except for de-identified, aggregate statistics under 4.4;
  • (e) use it to train, fine-tune or improve any AI or machine-learning model, and SERVALO will not let a subprocessor do so wherever that subprocessor's terms let SERVALO choose.
  • (a) Quality grading. SERVALO grades the Customer's calls, by software and staff, to improve the Customer's receptionist. Scores stay in the Customer's account.
  • (b) De-identified call stories (Terms Section 7.4). SERVALO may describe a call in its own words for its marketing, as text only, with no audio and no quotation of the caller, after removing the caller's name, phone number, street, house number, ZIP code, town and any other detail that could identify a person, and without naming the Customer unless it has separately consented in writing. A person at SERVALO approves each one. The Customer can turn this off in Settings at any time, effective for posts not yet published.

5. Confidentiality

SERVALO ensures that every person it authorizes to process personal data (staff, contractors and subprocessors) is bound by a duty of confidentiality, by contract or law, and has access only as their role requires.

6. Security

SERVALO keeps the technical and organizational measures in Annex 2, appropriate to the risk. SERVALO may update them, but will not reduce the overall level of protection.

7. Subprocessors

7.1 Authorization. The Customer authorizes SERVALO to use the subprocessors listed in the subprocessor list (published at servalo.io/dpa#subprocessors).

7.2 Flow-down. SERVALO puts each subprocessor under a written contract with data protection terms covering confidentiality, security and deletion. SERVALO remains responsible for each subprocessor's performance.

7.3 Changes, with 30 days' notice. SERVALO will tell the Customer at least 30 days before adding or replacing a subprocessor, by email to the account owner and by updating the list.

7.4 Right to object. The Customer may object in writing on reasonable data protection grounds within that 30-day period. The parties will discuss it in good faith. If SERVALO cannot offer a reasonable alternative, the Customer may end the affected Service by notice and receive a refund of prepaid fees for the period after it ends.

7.5 Emergency replacement. If a subprocessor must be replaced urgently for security or continuity, SERVALO may do so first and give notice promptly after, with the same right to object.

8. Help with data subject requests

8.1 If SERVALO receives a request from a caller or other person about their personal data (to access, delete, correct or opt out), SERVALO tells the Customer without undue delay. The Customer authorizes SERVALO to carry out a deletion request on its behalf within 30 days, as servalo.io/data-deletion promises, unless the Customer tells SERVALO it must keep the data (for example for warranty or legal records). SERVALO forwards other requests to the Customer and does not answer them on its own, except to confirm receipt or as the law requires.

8.2 SERVALO gives the Customer reasonable help to answer requests, including tools in the Service or, where they do not exist, help on request at no extra charge for reasonable volumes.

8.3 A text opt-out (STOP) is applied at once and automatically, and the opt-out record is kept so the number is not texted again, even after deletion of the person's other data.

9. Other assistance

SERVALO gives the Customer reasonable help with data protection assessments and with consultations with regulators, where the law requires it and the information is within SERVALO's control.

10. Personal data breach

10.1 Notice within 72 hours. SERVALO notifies the Customer in writing within 72 hours after confirming a breach of security that led to unauthorized access to, or loss, disclosure or alteration of, the Customer's personal data.

10.2 Content. The notice says, as far as known: what happened and when; the kinds and rough number of records and people affected; what SERVALO has done to contain it; what the Customer should do; and a contact. SERVALO updates the Customer as it learns more.

10.3 Cooperation. SERVALO cooperates with the Customer's investigation and its notices to individuals and regulators, and does not notify the Customer's callers or regulators about the Customer's data without the Customer's agreement, unless the law requires it.

10.4 Not an admission. A notice is not an admission of fault.

10.5 SERVALO follows its written incident plan.

11. Audits

11.1 On written request, no more than once a year (and also after a breach, or when a regulator requires it), SERVALO gives the Customer the information reasonably needed to show compliance with this DPA, starting with a written security questionnaire and supporting documents.

11.2 If that does not reasonably answer a specific concern, the Customer (or an independent auditor bound by confidentiality, not a SERVALO competitor) may audit, on at least 30 days' notice, during business hours, at the Customer's cost, without access to other customers' data, and without disrupting the Service.

11.3 Instead of an audit, SERVALO may provide an independent assessment by a qualified assessor, if it has one. SERVALO holds no SOC 2 or similar certification today.

12. US state privacy laws

12.1 For the CCPA and each other US state privacy law that applies to the Customer's processing (for example the laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others), SERVALO, as processor, will:

12.2 Where a state law gives the Customer a right this DPA does not, the Customer has that right.

  • (a) follow the Customer's documented instructions;
  • (b) keep personal data confidential and bind its people to confidentiality;
  • (c) at the Customer's choice, delete or return personal data at the end of the Service (Section 13), unless the law requires it to keep it;
  • (d) make available the information needed to show compliance, and allow reasonable assessments (Section 11);
  • (e) engage subprocessors only under a written contract with the same obligations, after notice and a chance to object (Section 7);
  • (f) take appropriate security measures (Annex 2) and help the Customer meet its security and breach notice duties (Section 10);
  • (g) help the Customer respond to consumer rights requests (Section 8) and with data protection assessments (Section 9).

13. Deletion and return

13.1 During the Service, the Customer can export its Customer Data on request (Terms Section 13.2).

13.2 After the Terms end, SERVALO keeps Customer Data for 30 days so the Customer can request an export, then deletes it from the Service within the following 30 days, including voicemail recordings held at Twilio.

13.3 Exceptions: data the law requires SERVALO to keep or that is under a legal hold, kept only for that purpose and still protected by this DPA; opt-out records (Section 8.3); and backup copies, which are deleted on the normal rotation, within 30 days, and are never restored except to recover the Service.

13.4 SERVALO confirms deletion in writing on request.

14. Term, order and liability

14.1 This DPA lasts as long as SERVALO processes personal data for the Customer.

14.2 If this DPA conflicts with the Terms on personal data, this DPA wins.

14.3 Liability under this DPA is subject to the limits in Terms Section 22.

Annex 1: Processing details

  • Subject matter: SERVALO's provision of the Service to the Customer: AI call answering, intake, scheduling and booking, dispatch, technician app, texting, review requests and records.
  • Duration: The term of the Terms, plus the deletion period in Section 13.
  • Nature of processing: Receiving and answering calls; converting speech to text and text to speech in real time (audio not stored for AI-answered calls); recording voicemail when the Customer turns it on (stored at Twilio); storing transcripts and summaries; extracting intake details with an AI model; detecting safety hazards in code; geocoding service addresses; scheduling; sending and receiving texts; sending one review request per completed job; quality grading; de-identified call stories (Section 4.3(b)); export and deletion.
  • Purpose: To provide, support, secure and improve the Service for the Customer, and the authorized uses in Section 4.3.
  • Types of personal data: Caller name; phone number; service address and its map coordinates; email if given; the service need, equipment details, urgency and safety answers; appointment details; call transcripts and summaries; voicemail recordings (audio) when turned on; text message content; opt-out status; call and message metadata (time, duration, numbers, outcome); quality scores. For the Customer's own staff and technicians: name, email, phone, role, schedule, job assignments, and job location updates.
  • Sensitive data: Not intended. Callers may mention health or other sensitive facts on their own (for example a medical need for heat); SERVALO does not ask for them. No voiceprints or other biometric identifiers are created.
  • Data subjects: People who call or text the Customer's line; the Customer's customers and prospective customers; the Customer's owners, staff and technicians who use the Service.
  • Frequency: Continuous, as calls, texts and jobs occur.
  • Retention: While the Customer uses the Service; then Section 13.
  • Subprocessors: the subprocessor list.
  • Location: United States.

Annex 2: Security measures

  • Encryption in transit. All traffic between users, Callers' carriers, SERVALO's servers and its providers uses TLS (HTTPS and secure WebSockets).
  • Encryption at rest. The database and file storage are encrypted at rest by SERVALO's database provider.
  • Tenant isolation. Every customer table carries a tenant identifier, and Postgres row-level security is enabled and forced with deny-by-default policies, so one customer's users cannot read another's data. New tables get these controls in the same change that creates them.
  • Access control and least privilege. Customers' users sign in and act only within their own company, with roles (for example owner, dispatcher, technician) limiting what each can see and do. SERVALO staff access to customer workspaces is limited to an operator boundary. Server-only keys are kept out of the browser, and server-only database functions are locked from client access.
  • Audit logs. Consequential actions in the platform, including operator actions, exports and offboarding, are written to an audit log.
  • Secrets. API keys and tokens live in the hosting providers' environment settings, not in source code. Exposed keys are rotated under the incident plan.
  • Webhook verification. Inbound Twilio webhooks are signature-verified.
  • Minimization. The AI-answered call path does not store audio. No voiceprints are made. Call stories carry no caller details (Section 4.3(b)).
  • Safety controls in code. Hazard detection and required safety steps are enforced by deterministic code, not left to the AI model.
  • Monitoring. Errors are reported to an error-monitoring service and failures surface visibly, never as a false success.
  • Change control. Code changes pass automated type checks and tests, including legal and compliance checks, before deployment. Voice changes pass a call simulator.
  • Incident response. A written plan with a 72-hour customer notice deadline.
  • Vendors. Subprocessors under written data terms (Section 7).
  • People. Staff and contractors with access are bound by confidentiality in their signed agreements.
  • Backups. Daily backups by the database provider, kept no longer than 30 days.

Subprocessors

The companies that process your customers' data for us. We email you at least 30 days before adding or replacing one.

CompanyWhat it does for SERVALOCustomer data it handlesLocation
Twilio Inc.Phone numbers, inbound call handling, Twilio ConversationRelay (the real-time voice connection to our AI), SMS delivery and A2P 10DLC registration, call transfers, and storage of voicemail recordingsCaller phone numbers, live call audio (passed through, not stored by SERVALO), voicemail recordings, text message content, call and message metadataUnited States
Deepgram, Inc. (through Twilio)Speech-to-text during AI-answered callsLive call audio; the resulting textUnited States
ElevenLabs (Eleven Labs, Inc.) (through Twilio)Text-to-speech: produces the assistant's voiceThe assistant's replies (which may repeat caller details such as a name or address)Being confirmed
Anthropic, PBCThe AI model that runs the conversation, extracts intake details, writes call summaries, checks safety guidance wording, and grades call qualityCall transcripts and text, caller details spoken on the call, text message contentUnited States
Supabase, Inc.Primary database, authentication and file storageAll stored Customer Data: transcripts, callers, bookings, jobs, texts, users, audit logsUnited States
Vercel Inc.Hosts the web dashboard, technician app and web APIsCustomer Data in transit through the app; server logsUnited States
Railway CorporationHosts the voice server (the live call connection and the call webhooks)Call text and caller details in transit during calls; server logsUnited States
Stripe, Inc.Subscription billing for SERVALO's own feesCustomer's billing contact and payment details (Stripe holds card data; SERVALO does not)United States
Google LLC (Google Maps Platform)Geocoding and address validation of service addresses; travel times for dispatchService addressesUnited States
Google LLC (Google Workspace)Sends operational email to Customers from servalo.io mailboxes (booking alerts, account notices)Customer contact emails; alert content, which can include caller name, number and job detailsUnited States
ResendEmail delivery: fallback for operational email when Workspace is not configuredSame as row 10 when usedUnited States
Functional Software, Inc. (Sentry)Error monitoringError reports, which can contain fragments of request dataUnited States