Document sections
This DPA forms part of the agreement between the Firm (“Controller”) and Workforce AI Corp, operating as Vetted Cases (“Processor”) and governs Processor’s processing of Personal Data on Controller’s behalf. Capitalized terms not defined here have the meaning in the applicable data-protection laws (“Data Protection Laws”), including the GDPR, UK GDPR, and U.S. state privacy laws (e.g., CCPA/CPRA), as applicable.
2.1 Roles and scope
2.1.1 As between the parties, Controller is the controller (and, under CCPA/CPRA, the business) and Processor is the processor (and service provider / contractor) with respect to Caller Personal Data.
2.1.2 Processor shall process Personal Data only on the documented instructions of Controller, including the configuration Controller selects (greeting, intake script, routing, retention). Processor shall inform Controller if, in its opinion, an instruction infringes Data Protection Laws.
2.1.3 Service-provider commitments (CCPA/CPRA). Processor shall not (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Service or as permitted by law; (c) retain, use, or disclose Personal Data outside the direct business relationship; or (d) combine Personal Data with data from other sources except as permitted for a service provider. Processor certifies it understands and will comply with these restrictions.
2.2 Details of processing (Annex A)
- Subject matter: provision of AI voice intake receptionist services.
- Duration: the subscription term plus the retention/deletion periods in §2.6.
- Nature & purpose: answering calls, qualifying PI intake, scheduling, routing, and delivering intake records.
- Categories of data subjects: Callers (prospective clients) and Firm authorized users.
- Categories of Personal Data: identity/contact; volunteered case facts; call audio/transcript (short-retained per schedule); metadata; scheduling data. May include special-category / sensitive data (e.g., health information about injuries) volunteered by Callers.
- Special-category handling: processed only as necessary to deliver intake, subject to the isolation and redaction controls configured and validated for the signed implementation. A BAA can be arranged during implementation where required.
2.3 Security (Article 32-style)
For each signed Firm implementation, Processor shall configure, validate, and maintain appropriate technical and organizational measures before live traffic, including: encryption in transit and at rest; firm-specific logical isolation across approved data paths; PII/PHI redaction rules before storage is enabled; access controls, least privilege, and MFA; audit logging and monitoring; secure development and change management; vulnerability management; and business-continuity and backup practices. CRM delivery, warm-transfer routing, and any legal-hold control are included only when documented, configured, and validated for that implementation. Measures account for the state of the art, the costs of implementation, and the risk to data subjects.
2.4 Sub-processors
2.4.1 Controller provides general authorization for Processor to engage sub-processors, currently in these roles: enterprise voice provider, enterprise language-model provider, scheduling provider, and cloud infrastructure/storage/communications providers.
2.4.2 Processor shall impose data-protection obligations no less protective than this DPA — including the no-training obligation (§2.5) — on each sub-processor by written contract, and remains liable for their performance.
2.4.3 Processor shall maintain a current sub-processor list and give Controller 30 days’ prior notice of any intended addition or replacement, during which Controller may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection, and Controller may terminate the affected Service if it cannot be resolved.
2.5 No training; no independent use
Processor shall not use Personal Data to train, fine-tune, or improve any model, and shall not use Personal Data for its own purposes. Language-model and voice processing occur under enterprise no-training and data-protection terms, including zero-data-retention terms where available. Any analytics for service improvement use only de-identified or aggregated data that is not Personal Data.
2.6 Return and deletion
Processor shall retain Personal Data only per the firm-selectable schedule in Part 1 §1.4. On expiry/termination, or on Controller’s written request, Processor shall return and/or delete Personal Data (Controller’s choice) within 30 days, except copies required by law, which remain subject to this DPA. Where the signed implementation includes a per-matter legal-hold control, an authorized hold suspends deletion for identified matters until released by Controller.
2.7 Assistance to Controller
Processor shall, taking into account the nature of processing, reasonably assist Controller with: (a) responding to data-subject / consumer requests; (b) security, breach notification, and DPIA/consultation obligations; and (c) demonstrating compliance.
2.8 Personal-data breach
Processor shall notify Controller without undue delay and within 72 hours of confirming a breach affecting Personal Data, providing available details and cooperating on remediation and notification.
2.9 Audit
Processor shall make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, by Controller or its mandated auditor, no more than once annually (and after a breach), on reasonable notice, subject to confidentiality and Processor’s security policies. Processor may satisfy audits in part through current third-party reports/certifications where available.
2.10 Confidentiality
Processor ensures persons authorized to process Personal Data are under an appropriate obligation of confidentiality and process only as instructed.
2.11 International transfers
Where Processor transfers Personal Data internationally on Controller’s behalf, it does so under an approved transfer mechanism (Standard Contractual Clauses / UK Addendum, incorporated by reference) with appropriate supplementary measures. The parties agree the applicable modules apply as between Controller (data exporter) and Processor (data importer).
2.12 Liability; precedence
Each party’s liability under this DPA is subject to the limitations of liability in the underlying agreement. In case of conflict between this DPA and the agreement regarding data protection, this DPA controls.