Skip to main content
Call2KOT
How it works Live demo WhatsApp Promotions C2K1
Book a demo
Legal

Data Processing Addendum

Last updated 17 September 2026

When this applies. Only where we host Call2KOT for you. If you run it on your own server we process nothing on your behalf and this addendum is not needed — though you may still want it on file.

1 · Roles

You are the controller. You decide why and how personal data is processed, and you own the relationship with the people it concerns.

We are the processor. We act only on your documented instructions, which are this addendum and the service agreement.

2 · What we process, and why

CategoryDataPurpose
CallersPhone number, name if given, delivery address, order contents, language, transcriptTaking and fulfilling the order
StaffName, work email, roleSigning in, and the audit trail
Call audioOnly where you switch it onImproving recognition accuracy for your menu and your callers' accents

3 · Our obligations

  • Process only on your instructions, and tell you if we believe an instruction breaches applicable law.
  • Keep everyone with access under a duty of confidence.
  • Apply the measures in section 6.
  • Help you respond to requests from individuals, and to regulators.
  • Tell you of a personal data breach without undue delay, and in any case within 48 hours of becoming aware.
  • Delete or return everything at the end of the contract, at your choice.
  • Make available what you need to verify the above.

4 · Sub-processors

We use the following. You may object to a new one, and if we cannot accommodate the objection you may terminate.

WhoWhat forWhere
AnthropicUnderstanding the orderUnited States
DeepgramSpeech recognitionUnited States
Microsoft AzureSpeech synthesisUAE North, where available
Meta PlatformsWhatsApp delivery, if enabledPer Meta's terms

Each is engaged under terms no less protective than these, and none trains models on your data.

5 · International transfers

Where data leaves the UAE it does so under the sub-processor's standard contractual clauses or equivalent safeguards. If your policy requires that nothing leaves the country, deploy on your own server and enable the local model, then nothing does.

6 · Security measures

  • TLS in transit; AES-256-GCM for stored credentials.
  • bcrypt password hashing; multi-factor authentication on operator accounts.
  • Role-based access, with tenant isolation enforced in the query layer.
  • An audit trail of every change, including any access by our support staff, visible to you.
  • Rate limiting, origin validation, and signature verification on inbound webhooks.
  • Regular security review; four audits completed to date.

7 · Audit

Once a year, on reasonable notice, you may audit our compliance — or accept a recent third-party report in place of one. We will answer a security questionnaire at any time.

8 · Liability and term

This addendum takes the liability provisions of the service agreement, and lasts as long as we process anything on your behalf.

9 · Signing it

Email legal@call2kot.com and we will send a countersigned copy. If your organisation has its own DPA, send it. We will review yours rather than insist on ours.

© 2026 Call2KOT · Dubai, UAE · The AI drafts. A human decides.