Data processing addendum
Draft — early access · Last updated: 11 October 2026
Draft — early access
This addendum is a working draft while Otone is in early access. The company that will operate Otone has not been registered yet. Its legal name, registered address and company number, the governing law, and the details of any representatives the law requires are marked “to be completed with the registered business details” and will be filled in on this page before paid plans go on sale.
In short
- Your business decides how your callers' data is used. We process it only to run Otone for you, on your instructions.
- No call audio is kept. Transcripts, summaries and callers' numbers are erased automatically after 90 days.
- We tell you in advance about new subprocessors, and you can object.
- We tell you about a personal data breach without undue delay.
- Your callers' data is never sold, never shared for advertising and never used for our own purposes.
1. About this addendum
This Data Processing Addendum (“addendum”) forms part of the Otone Terms of use between Otone and the business that uses it. It applies whenever we process personal data for you as your processor — above all, your callers' data. You accept it when you accept the Terms of use, for example by creating an account or by continuing to use Otone after it takes effect; no separate signature is needed. If you need a signed copy, write to hi@otone.tech.
It is written to meet Article 28 of the GDPR and of the UK GDPR, Article 12 of KVKK (Turkish Law No. 6698), and the service provider rules of US state privacy laws such as the California Consumer Privacy Act (CCPA). Terms such as “personal data”, “controller”, “processor”, “data subject” and “personal data breach” have their GDPR meaning, and the matching terms of KVKK and of US state laws (such as “business” and “service provider” under the CCPA) are read the same way.
2. Parties and roles
- You — the business that accepted the Terms of use — are the controller of the personal data processed through your Otone account. If you use Otone for another controller (for example, to answer a client's line), you act as its processor, we act as your subprocessor, and you confirm that the controller has authorised this addendum.
- Otone — operated by [legal name, registered address and company number: to be completed with the registered business details] — is your processor; under US state privacy laws, your service provider.
- For your own account data (name, email, billing contact, usage) Otone is a controller. That processing is outside this addendum and is described on the Privacy page.
3. Subject matter, duration, nature and purpose
- Subject matter: providing the Otone service — an AI voice assistant that answers your business's phone calls, checks availability, takes bookings, and shows calls and bookings in your dashboard.
- Duration: for as long as the Terms of use apply to you, and afterwards until the data is deleted or returned under section 13.
- Nature: receiving calls; turning speech into text live; understanding the caller and writing replies with a language model; turning replies into speech; storing transcripts, summaries and bookings; showing them in your dashboard; and erasing them. The audio is processed live only and is not recorded or kept.
- Purpose: only to provide the service to you, as the Terms of use describe and as you set it up — never for our own purposes, for advertising, or for sale.
4. Personal data and data subjects
- Data subjects: people who call your business on a line Otone answers; people whose details a caller gives for a booking; your team members whose phone numbers you enter (for example owner and transfer numbers); and you or your team when you try the assistant from the browser.
- Categories of data: phone numbers; the time and length of calls; what callers say (processed live and turned into text); call transcripts; short AI-written call summaries; booking details such as name, date and time, number of people and notes; and the owner and transfer numbers you set up.
- Special categories: Otone is not designed to collect sensitive data, but when a clinic in Türkiye or the EU uses it, callers may give details about their health — for example the reason for an appointment — which then appear in transcripts, summaries and booking notes. These are special category data under GDPR Article 9 and sensitive personal data under KVKK Article 6. You are responsible for having a condition for processing them and for telling callers what your law requires; we protect them with the measures in section 8 and erase transcripts and summaries after 90 days like all others. In the United States Otone must not be used for protected health information under HIPAA (see the Terms of use).
- Frequency: continuous, whenever a call comes in.
5. Your instructions and responsibilities
- Your instructions are the Terms of use, this addendum, and what you set up and do in your dashboard (for example opening hours, services and transfer numbers). You can give further instructions by email; if one needs a change to the service that we cannot make, we will tell you, and you may stop using Otone.
- You are responsible for having a lawful basis for the processing; for giving callers the notices your law requires (the assistant's opening notice is not a full privacy notice); for any consent your law requires; and for the accuracy of the information you enter.
- The opening notice: every call starts with the assistant saying, in English, “Hello, and thanks for calling [business name]. I'm an AI assistant, and this call is transcribed for booking and service quality purposes.” (an assistant that speaks Turkish says the same in Turkish). This meets the transparency duty of the EU AI Act (Article 50). You must not remove or change it.
6. Our obligations as processor
Following GDPR Article 28(3) and the UK GDPR, we:
- (a) follow your instructions: we process the data only on your documented instructions, including for transfers abroad, unless the law requires otherwise — and then we tell you first, unless the law forbids it. We tell you straight away if we think an instruction breaks data protection law;
- (b) keep it confidential: see section 7;
- (c) keep it secure (GDPR Article 32): see section 8;
- (d) use subprocessors only as agreed: see section 9;
- (e) help with data subject requests: see section 11;
- (f) help you meet your own duties on security, breach notification (section 12), data protection impact assessments and prior consultation with an authority, by giving you the information about the service that you reasonably need;
- (g) delete or return the data at the end: see section 13;
- (h) give you information and allow audits: see section 14.
Following KVKK Article 12, we also:
- take, together with you, the technical and administrative measures needed to prevent unlawful processing of and access to the data and to keep it safe;
- do not disclose the personal data we learn or use it for any purpose other than the service — a duty that continues after the Terms of use end;
- tell you without undue delay if the data is obtained by others unlawfully, so that you can notify the Personal Data Protection Board and the people concerned.
7. Confidentiality
Only people who need the data to run, secure or support the service can access it, and each of them is bound to confidentiality by contract or by law. Today that is the founder; anyone who joins later is bound the same way before getting access. The duty continues after the Terms of use end.
8. Security measures
- Encryption in transit: the website, the dashboard and our servers are reached only over HTTPS (TLS), and our servers connect to the database over TLS with the certificate verified.
- Separation between businesses: each business's data is kept apart in the database with row-level security, enforced by the database itself. The service connects with a database role that cannot bypass it, so one business's account cannot read another's data.
- Least-privilege access: people and system components get only the access they need; administrative database access is kept separate from the access the service uses.
- Encrypted backups: database backups are encrypted.
- No audio kept: recording is switched off in our voice platform; call audio is processed live only.
- Short retention: transcripts, summaries and callers' numbers are erased automatically after 90 days.
- No card data: card details are entered at Polar and never reach Otone.
We review these measures as the service grows and will not lower the overall level of protection.
9. Subprocessors
- General authorisation: you authorise us to use the subprocessors listed on the Privacy page.
- Same obligations: each subprocessor works under a written contract that gives at least the protection this addendum and the law require. We remain responsible to you for their work.
- Advance notice: before a new or replaced subprocessor starts processing your data, we update the list and email the account owner at least 30 days in advance. If a change is urgent — for example to keep the service secure or running — we tell you as soon as we can, and you keep your right to object.
- Right to object: you can object in writing, on reasonable data protection grounds, within the notice period. We will look in good faith for a solution, such as not using that subprocessor for your data. If we cannot find one, you may end the Terms of use by closing your account before the change applies to you.
10. International transfers
Our hosting and database are in Frankfurt, Germany. Vapi, Twilio and OpenAI process call data in the United States, and some other subprocessors may process data outside the European Economic Area (EEA) and Türkiye. The operating company may itself be established outside the EEA, the UK or Türkiye. Wherever personal data goes to a country without an adequacy decision — from you to us, or from us to a subprocessor — the transfer is made under one of these safeguards:
- From the EU/EEA: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this addendum by reference — Module 2 where you are a controller, Module 3 where you are a processor. Clause 9(a) Option 2 applies, with the notice period in section 9; the optional wording of Clause 11(a) does not apply; the governing law and courts of Clauses 17 and 18 are to be completed with the registered business details. Annex I is completed by sections 2 to 4, Annex II by section 8, and Annex III by the subprocessor list. Where the recipient is certified under the EU–US Data Privacy Framework, the transfer may rely on that adequacy decision instead.
- From the UK: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, with its tables completed by the information in this addendum, or the UK International Data Transfer Agreement (IDTA); or, for a certified US recipient, the UK Extension to the Data Privacy Framework.
- From Türkiye (KVKK Article 9, as amended by Law No. 7499): unless the Personal Data Protection Board has made an adequacy decision for the country, the standard contract published by the Board for the relationship concerned (for example controller to processor, or processor to processor), signed by the parties concerned and notified to the Personal Data Protection Authority within five business days of signing by the party the law requires; or another appropriate safeguard listed in Article 9. Where the KVKK standard contract is needed between you and us, we sign it with you. Explicit consent is not relied on for these regular transfers.
If any of these instruments conflicts with this addendum, the instrument prevails.
11. Help with data subject requests
- If a caller or anyone else asks us directly about personal data we process for you, we pass the request to you without undue delay and do not answer it ourselves unless you ask us to.
- Taking into account the nature of the processing, we help you answer requests to access, correct, delete, restrict, object to or port data, and the matching rights under KVKK Article 11 and US state laws. On your written request we find, export, correct or delete a person's data that we still hold.
12. Personal data breaches
- We notify you without undue delay after becoming aware of a personal data breach that affects your data, by email to the account owner.
- As the facts become available — in stages if needed — we tell you what happened, the categories and approximate number of people and records concerned, the likely consequences, the measures taken or proposed, and who to contact.
- We take reasonable steps to contain and investigate the breach, and help you notify the authorities and the people concerned where your law requires it — for example within 72 hours to the supervisory authority under GDPR Article 33, or as soon as possible to the Personal Data Protection Board under KVKK.
- Our notice is not an admission of fault.
13. Deletion or return at the end
- While you use Otone, transcripts, summaries and callers' numbers are erased automatically after 90 days. Booking records are kept until you ask us to delete them or close your account.
- When the Terms of use end or you close your account, we delete the personal data we process for you. If you ask before closing, we first return a copy of what we still hold in a common machine-readable format. If the law requires us to keep some of it, we keep protecting it and use it only for that purpose.
- Copies in encrypted backups disappear as the backups expire. On request we confirm the deletion in writing.
14. Information and audits
- We make available the information needed to show that we meet this addendum: the addendum itself, the description of our security measures, the subprocessor list, and written answers to reasonable security and privacy questions.
- If that is not enough, if an authority requires it, or after a personal data breach, you — or an independent auditor bound to confidentiality who is not our competitor — may audit our compliance. Audits take place on at least 30 days' notice, normally no more than once a year, at your cost, without disrupting the service or exposing other customers' data.
- We cooperate with inspections by competent data protection authorities.
15. US state privacy laws
Where the CCPA or a similar US state privacy law applies to the personal information we process for you, we act as your service provider (or processor, as the law calls it), and:
- the business purpose for which you disclose it to us is providing the Otone service, as described in section 3;
- we do not sell or share it, including for cross-context behavioural advertising;
- we do not keep, use or disclose it for any purpose other than that business purpose, or outside our direct business relationship with you, except as the law allows;
- we do not combine it with personal information we receive from or for others, or collect from our own dealings with people, except as the law allows;
- we comply with the obligations these laws place on us, give it the level of protection they require, and tell you if we can no longer meet them;
- you may take reasonable steps to make sure we use it in line with your obligations and, after telling us, to stop and fix any unauthorised use;
- we bind our subprocessors to the same restrictions by written contract;
- we understand these restrictions and will comply with them.
Otone is not a HIPAA business associate and must not be used to handle protected health information.
16. Precedence, liability and changes
- Precedence: for data processing, this addendum takes precedence over the Terms of use where they differ; the transfer instruments in section 10 take precedence over both.
- Liability under this addendum follows the limits in the Terms of use, except where the law or a transfer instrument does not allow them.
- Changes: we may update this addendum, for example to follow changes in the law or in our subprocessors. The current version, with its date, is always on this page. We tell you by email before a material change takes effect, and no change will lower the overall protection of your data.
- End: this addendum ends when the Terms of use end and the data has been deleted or returned; confidentiality and other duties that by their nature continue survive it.
17. Details to complete and contact
- Operator (legal name), registered address, company number: to be completed with the registered business details.
- Governing law and courts (including for Clauses 17 and 18 of the EU Standard Contractual Clauses): to be completed with the registered business details.
- Representatives: where the law requires, we appoint a representative in the EU (GDPR Article 27) and in the UK (UK GDPR Article 27), register with VERBİS and appoint a data controller representative in Türkiye; their details will be published here.
- Privacy contact: hi@otone.tech