A. LIST OF PARTIES
1. Controller
The “Merchant” (Party using Callsy AI solutions via Shopify app or other integration)
Address:
As set out in the Main Agreement or invoice.
Contact Person:
As set out in the Main Agreement or user account details.
Controller
2. Processor
Callsy AI OÜ
As set out in the Main Agreement.
Processor
B. DESCRIPTION OF TRANSFER
1. Categories of Data Subjects
The personal data transferred concern the following categories of data subjects:
Customers of the Controller
Leads and prospects of the Controller
2. Categories of Personal Data
The personal data transferred concern the following categories of data:
Name and contact details (Phone number, Email)
Order and cart information (e.g., value, items, status)
Any relevant business merchants information (lead status)
Call metadata (e.g., duration, timestamps, call status)
Call recordings and transcripts
Voice inputs (biometric data is not typically processed for ID purposes, but voice audio is processed for communication)
3. Special Categories of Data (if appropriate)
The personal data transferred concern the following special categories of data:
None. The Controller shall not submit special categories of data (e.g., health data, political opinions) unless explicitly agreed in writing.
4. Nature of the Processing
The nature of the processing includes:
Storage, hosting, and transmission of data.
Text-to-Speech (TTS) and Speech-to-Text (STT) conversion.
AI-driven conversation management and automation.
Telephony connection, routing, and SMS transmission.
5. Purpose(s) of the Data Transfer and Further Processing
The processing is necessary for the following purposes:
Providing the Callsy AI Services (automated calling).
Recovering abandoned carts via outbound calls.
Customer support automation.
Analytics, logging, and service improvement.
6. Duration of Processing
The processing will continue for the duration of the Main Agreement. Personal Data is retained only as long as necessary for the provision of services or as required by law.
ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES (TOMs)
As referenced in Section 4.3 of the DPA, the Processor implements the following measures to ensure an appropriate level of security:
1. Confidentiality
Access Control:
Access to production servers and customer data is restricted to authorized personnel via unique IDs and Multi-Factor Authentication (MFA).
Encryption:
Data is encrypted in transit (using TLS 1.2+) and at rest (using AES-256 standards) within the cloud infrastructure.
Logical Separation:
Customer data is logically separated within the multi-tenant database environment to prevent unauthorized cross-client access.
2. Integrity
Change Management:
All code changes and updates undergo testing and code review processes before deployment to production.
Input Validation:
Application inputs are validated to prevent SQL injection, Cross-Site Scripting (XSS), and other common vulnerabilities.
3. Availability and Resilience
Cloud Infrastructure:
The Service is hosted on top-tier cloud providers ensuring high availability and redundancy across multiple availability zones.
Backups:
Automated daily backups of databases are performed to enable data restoration in the event of corruption or loss.
Disaster Recovery:
A business continuity strategy is in place to recover critical services in the event of a major outage.
4. Testing and Evaluation
Security Scans:
Regular automated vulnerability scanning is performed on the infrastructure.
Incident Response:
A documented incident response plan exists to handle and notify the Controller of any data breaches in accordance with GDPR timelines.
ANNEX 3: LIST OF SUB-PROCESSORS
As referenced in Sections 4.4 and 6.1 of the DPA, the Controller authorizes the engagement of the following sub-processors. Callsy can provision hosting and processing in either the European Union or the United States at the Controller's election (see Section 7.3 of the DPA); the regions noted below reflect the default EU configuration.
1. Amazon Web Services (AWS). Provided by Amazon Web Services EMEA SARL. Cloud infrastructure provider: hosting of the application, database storage, and compute. Data region: EU (Frankfurt / Ireland) or United States, selectable per customer. Compliance: https://aws.amazon.com/compliance/
2. ElevenLabs, Inc. (United States). Voice AI provider: text-to-speech, speech-to-text, and voice generation for the AI agent. Audio is processed in the EU or US in line with the Controller's selected data region, with any international transfer covered by Standard Contractual Clauses. Compliance: https://elevenlabs.io/privacy
3. Bland AI, Inc. (United States). AI telephony provider: processing of audio for conversational AI, speech-to-text, and text-to-speech generation. Compliance: https://trust.platform.delve.co/blandai
4. Twilio Inc. (United States / EU). Telephony and SMS infrastructure: PSTN connectivity, call routing, phone-number provisioning, and SMS delivery. Compliance: https://security.twilio.com/
5. DIDWW (EU). Telephony carrier: DID phone-number provisioning, inbound and outbound PSTN connectivity, and call routing. Compliance: https://www.didww.com/
6. UAB Callsy (Lithuania, EU). Technical support and development of the Callsy AI OÜ platform.