# Data Processing Addendum

**Data Processing Addendum ("DPA") — under Art. 28 of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the California Consumer Privacy Act as amended ("CCPA/CPRA")**

Version: **1.0**
Language: English (authoritative for Customers onboarded in English)
Effective: from the date of electronic acceptance by the Customer, recorded in the platform's records (`clients.dpa_signed_at`).

---

## Between

**CR OÜ** — a company incorporated under Estonian law, registry code 16936108, registered office in Tallinn, Estonia ("**LeadEvoke**" or the "**Processor**"), operator of the SaaS platform "LeadEvoke" available at `leadevoke.com` and its subdomains;

**and**

**the Customer** — the legal entity holding the business account registered on the LeadEvoke platform, whose identification details are recorded in the account and onboarding data (the "**Customer**" or the "**Controller**").

Each a "**Party**", together the "**Parties**". This DPA forms an integral part of the LeadEvoke Terms of Service (the "**Terms**").

---

## Recitals

a) The Customer owns a base of commercial contacts ("**Leads**") acquired through its own marketing, sales and lead-generation activity, which it wishes to re-engage.

b) LeadEvoke provides a SaaS platform which, on the Customer's instruction, contacts the Leads uploaded by the Customer through an AI voice assistant, qualifies remaining interest, books, confirms and verifies appointments.

c) The performance of the Service entails processing of the Leads' personal data on the Customer's behalf. The Customer appoints LeadEvoke as its Processor; this DPA sets the terms of that appointment.

d) The Parties acknowledge that the identification of a valid legal basis, the collection of any required consents (including, for United States campaigns, **prior express written consent** under the TCPA for AI/prerecorded-voice calls) and compliance with do-not-call registries are the **sole responsibility of the Controller**, as further set out in Article 3 and Annex D.

---

## 1. Definitions

"**personal data**", "**processing**", "**controller**", "**processor**", "**sub-processor**", "**data subject**", "**personal data breach**" have the meaning given by the GDPR. "**Service**", "**Platform**", "**AI Assistant**" have the meaning given in the Terms. For Customers subject to the CCPA/CPRA, "personal data" includes "personal information", and LeadEvoke acts as a "**service provider**".

"**Declared Legal Basis**": the legal basis the Customer declares for each batch of Leads at import (field `legal_basis` with evidence metadata; admitted values `consent`, `legitimate_interest`, `pre_washed`).

"**Annex D Declaration**": the representation and warranty in Annex D, given by the Customer at every Lead import.

## 2. Subject matter and instructions

2.1 The Customer, as Controller, instructs LeadEvoke, which accepts, to process the personal data of Leads strictly as necessary to provide the Platform, per the Terms and the Customer's documented instructions. The processing operations, categories of data and of data subjects, purposes and duration are detailed in **Annex A**.

2.2 The Customer's documented instructions consist of: these terms; the configuration chosen in the dashboard (verticals, workflows, calling windows within statutory limits, scripts, FAQ); the act of uploading each batch of Leads; and any written instruction sent to `privacy@leadevoke.com`. LeadEvoke shall inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.

2.3 LeadEvoke processes personal data only on such instructions, unless required to process by EU or Member State law (in which case it informs the Controller unless prohibited).

## 3. Roles and allocation of responsibility

3.1 The Customer is and remains the Controller of Lead data. LeadEvoke does not determine purposes; it does not use Lead data for its own marketing, profiling or model training, and does not sell or share Lead data within the meaning of the CCPA/CPRA.

3.2 **The lawfulness of contacting each Lead rests solely with the Controller**: legal basis under Art. 6 GDPR and/or valid consent under applicable telemarketing law (for US numbers: TCPA/TSR, including PEWC for AI-voice calls and DNC scrubbing except documented exemptions), transparency duties (Art. 13–14 GDPR; state notice-at-collection rules), and the lawfulness of call recording in all-party-consent jurisdictions.

3.3 LeadEvoke provides technical safeguards (statutory calling windows in the Lead's time zone, attempt caps, immediate opt-out capture and suppression, AI self-identification). These safeguards assist but do not transfer the Controller's responsibility.

3.4 **Indemnity.** The Customer shall indemnify and hold LeadEvoke harmless from any claim, sanction, statutory damages or cost arising from the inaccuracy of an Annex D Declaration or from the absence of a valid legal basis or required consent for Leads uploaded by the Customer, per Section 6.8 of the Terms.

## 4. Confidentiality

LeadEvoke ensures that persons authorised to process personal data are bound by confidentiality obligations and receive appropriate data-protection instruction. Access is limited to what is necessary per role.

## 5. Security

LeadEvoke implements the technical and organisational measures described in **Annex B**, taking into account the state of the art, costs, and the risks of the processing. LeadEvoke may update Annex B provided the overall level of protection is not reduced.

## 6. Sub-processors

6.1 The Customer gives **general authorisation** to the engagement of the sub-processors listed in **Annex C**. LeadEvoke will inform the Customer (dashboard notice or email) of intended additions or replacements at least 15 days in advance; the Customer may object on reasonable data-protection grounds, in which case the Parties will seek a solution in good faith and, failing that, the Customer may terminate the affected Service pro-rata.

6.2 LeadEvoke imposes on each sub-processor data-protection obligations materially equivalent to this DPA and remains liable to the Customer for their performance.

## 7. International transfers

7.1 Personal data is hosted in the **EU** (Annex A). Certain sub-processors (Annex C) process voice traffic, transcripts or LLM inference in the **United States**; such transfers rely on the **EU Standard Contractual Clauses (2021/914)** and, where the sub-processor is certified, the **EU–US Data Privacy Framework**, with supplementary measures where appropriate.

7.2 For US-market Customers whose Leads are US residents, GDPR transfer rules typically do not apply to the Lead data itself; the CCPA/CPRA service-provider terms of Article 12 apply instead.

## 8. Assistance to the Controller

8.1 Taking into account the nature of the processing, LeadEvoke assists the Controller with appropriate technical and organisational measures in fulfilling data-subject rights requests (access, erasure, rectification, objection, portability, restriction). The dashboard provides self-service export and deletion (GDPR worker); requests can also be sent to `privacy@leadevoke.com` and are actioned without undue delay and at most within 15 days.

8.2 An in-call opt-out ("do not call me again") is honoured immediately: the number is suppressed platform-wide for the Customer and recorded with timestamp and source.

8.3 LeadEvoke assists the Controller, insofar as reasonably possible, with security, breach notification, DPIAs and prior consultations (Art. 32–36 GDPR), given the information available to it.

## 9. Personal data breach

LeadEvoke notifies the Customer **without undue delay and in any case within 48 hours** of becoming aware of a personal data breach affecting Lead data, providing the information required by Art. 33(3) GDPR as it becomes available, and cooperates in mitigation and in any notification the Controller must make to authorities or data subjects.

## 10. Audits

10.1 LeadEvoke makes available the information necessary to demonstrate compliance with this DPA (documentation, Annexes, sub-processor list, security summaries).

10.2 The Customer may audit compliance at most **once per 12 months** with 30 days' written notice, during business hours, without access to other customers' data, at its own cost, either through documentation review or — where strictly necessary — a remote or on-site inspection under confidentiality. Regulator-mandated audits are always permitted.

## 11. Retention and deletion

11.1 Lead data, call recordings and transcripts are retained for the duration of the Service and per the retention window configured for the account (default in Annex A).

11.2 Upon termination of the Service, the Customer may export its data for **30 days**; thereafter LeadEvoke deletes or irreversibly anonymises all Lead personal data (including backups within the backup cycle), unless retention is required by law (e.g. billing records). Deletion is certified on written request.

## 12. CCPA/CPRA service-provider terms (US campaigns)

Where the CCPA/CPRA applies to Lead data: (a) LeadEvoke acts as **service provider**; (b) LeadEvoke shall not sell or share personal information, nor retain, use or disclose it for any purpose other than performing the Service or as permitted by the CCPA; (c) LeadEvoke shall not combine Lead personal information with data received from other sources except to perform the Service; (d) LeadEvoke certifies that it understands and will comply with these restrictions; (e) LeadEvoke assists the Customer in responding to verifiable consumer requests; (f) the Customer may take reasonable steps to remediate unauthorised use.

## 13. Term and precedence

This DPA applies as long as LeadEvoke processes Lead personal data. In case of conflict with the Terms on data-protection matters, this DPA prevails.

---

# Annex A — Details of processing

| Item | Description |
|---|---|
| **Data subjects** | Leads uploaded by the Customer (adults, business or consumer contacts of the Customer); the Customer's own users of the dashboard. |
| **Categories of data** | Identification and contact data (name, phone in E.164, optional email), language, time zone, commercial attributes supplied by the Customer (product of interest, request date, amounts), call metadata (timestamps, duration, outcome), **call recordings and transcripts**, appointment data, consent/opt-out records. No special categories are intended to be processed; the Customer must not upload them. |
| **Operations** | Hosting, organisation, automated dialling, AI voice conversation (speech-to-text, LLM inference, text-to-speech), recording, transcription, outcome classification, appointment scheduling and reminders, reporting, deletion. |
| **Purpose** | Re-engagement and qualification of the Customer's own Leads and appointment management, on the Customer's instruction. |
| **Duration** | Duration of the Service plus the export window (Art. 11). Default retention of recordings/transcripts: as configured per account (platform default 12 months, adjustable on request). |
| **Location** | Primary hosting and database in the EU (Germany/EU region). Voice-pipeline sub-processors in the US (Annex C). |

# Annex B — Technical and organisational measures

- Encryption in transit (TLS 1.2+ everywhere, HSTS; origin certificates between CDN and origin).
- Encryption at rest at storage layer for database and object storage.
- **Multi-tenant isolation enforced in the database itself** (PostgreSQL row-level security on all tenant-scoped tables; separate application roles without RLS-bypass; superadmin operations segregated).
- Least-privilege access; per-service credentials stored in restricted server files (mode 600); no secrets in the code repository.
- Passwordless authentication with single-use, expiring magic-link tokens; session cookies with sliding expiry; Argon2id where passwords are used.
- Audit logging of administrative and lifecycle events; webhook signature verification on all inbound provider callbacks.
- Network exposure minimised: databases and queues bound to localhost; public traffic proxied through hardened reverse proxy behind CDN/WAF.
- Backups with defined cycle; deletion routines covering primary data and expiring from backups within the cycle.
- Vendor due diligence and DPAs with all sub-processors (Annex C); staff confidentiality undertakings.
- Incident-response procedure with 48-hour customer notification commitment (Art. 9).

# Annex C — Authorised sub-processors

| Sub-processor | Role | Location / transfer basis |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting of application and storage | Germany (EU) |
| Neon Inc. | Managed PostgreSQL database | EU region hosting; SCCs for support access |
| Cloudflare, Inc. | CDN, TLS, WAF/proxy | Global edge; SCCs / DPF |
| Vapi (Vapi.ai, Inc.) | Voice-call orchestration, telephony via managed carriers (incl. Twilio), call recording | USA; SCCs |
| Deepgram, Inc. (via Vapi) | Speech-to-text | USA; SCCs |
| Anthropic, PBC (via Vapi) | LLM conversation inference (no training on customer data) | USA; SCCs / DPF |
| Cartesia AI, Inc. (via Vapi) | Text-to-speech voice synthesis | USA; SCCs |
| Resend, Inc. | Transactional email delivery | EU sending region; SCCs for support |
| Stripe Payments Europe, Ltd. | Payment processing (acts as independent controller for payment data) | EU/USA; DPF |

# Annex D — Declaration on the lawfulness of each Lead import

**Given by the Customer electronically at every Lead upload (field `legal_basis` and evidence metadata). It is a representation and warranty under the Terms; LeadEvoke relies on it to perform the Service.**

For each batch of Leads uploaded, the Customer declares and warrants that:

1. The Leads originate from the Customer's **own** commercial activity (its forms, quotes, store visits, customer base) and were not purchased, scraped or otherwise acquired without a valid consent chain naming the Customer.

2. Depending on the Declared Legal Basis:
   - **`consent`** — each Lead gave prior express consent to be re-contacted by or on behalf of the Customer for commercial purposes, and — **for United States numbers** — that consent qualifies as **prior express written consent (PEWC)** covering calls made with an artificial/prerecorded or AI-generated voice, is evidenced in a retrievable record (the evidence reference supplied at import), and has not been revoked;
   - **`legitimate_interest`** — the contact takes place within an existing customer or negotiation relationship, a balancing assessment has been performed, and no objection has been received; the Customer acknowledges this basis is **not sufficient by itself for US AI-voice calls**, for which PEWC or a clear statutory exemption is required;
   - **`pre_washed`** — the list has additionally been scrubbed, within the validity window required by law, against the applicable do-not-call registers (for the US: the National DNC Registry and applicable state registries) by the provider indicated in the evidence metadata.

3. None of the numbers belongs, to the Customer's knowledge, to emergency lines, healthcare-critical lines, or persons who previously asked the Customer not to be contacted.

4. The Customer has provided data subjects with the privacy notices required by applicable law, mentioning the use of processors for contact activities.

5. The Customer will retain the consent/relationship evidence for at least **4 years** from the last call and will produce it to LeadEvoke within 5 business days of a request (Art. 6.7 of the Terms).

The Customer acknowledges that an inaccurate Declaration triggers the indemnity in Art. 3.4 of this DPA and Section 6.8 of the Terms, and entitles LeadEvoke to suspend or terminate the Service immediately.

---

*Requests: `privacy@leadevoke.com` · DPO (external, on request): `dpo@leadevoke.com` · Terms: https://leadevoke.com/legal/terms-en.html*
