Data Processing Addendum
Last updated: 6 October 2026. This addendum forms part of the Terms of Service between TechShah Co., 3175 Chawri Bazar, Delhi 110006, India, which operates the Clientager brand (“Clientager”, the processor) and the customer (the controller) and applies when Clientager processes personal data on the customer’s behalf under data protection laws such as the EU and UK GDPR, the CCPA/CPRA, India’s DPDP Act and similar laws. Need a signed copy? Email privacy@clientager.com.
1. Scope and roles
The customer is the controller (or business) of personal data in conversations handled by its AI agent and the customer records stored for it (“Customer Personal Data”). Clientager is the processor (or service provider). The details of the processing are in the annex below.
2. Instructions
Clientager processes Customer Personal Data only on the customer’s documented instructions: the Terms, this addendum, the configuration and settings the customer chooses, and its lawful written requests. Clientager will tell the customer if it believes an instruction breaks data protection law. Clientager will not sell Customer Personal Data, share it for behavioural advertising, or use it outside the direct business relationship, except as the law requires.
3. Confidentiality
People authorised to process Customer Personal Data are bound by confidentiality duties and access it only as needed for their work.
4. Security
Clientager keeps appropriate technical and organisational measures, including encryption in transit; encryption of customer-supplied integration keys; separation of each customer’s data; role-based access to production systems; logging; and a process for finding and fixing vulnerabilities. See the Security page. Measures are reviewed as the service develops.
5. Subprocessors
The customer authorises Clientager to use subprocessors under written contracts that give similar data protection obligations. Current categories and providers: hosting and database (Supabase); real-time voice and media (LiveKit); speech recognition and synthesis (Deepgram, Google Cloud); AI language models (Groq, Anthropic); telephony and SMS (SignalWire, Plivo); email delivery (Resend); payments (PayPal); WhatsApp messaging (Meta, where enabled). Clientager will tell customers by email or in the dashboard at least 30 days before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that time; if the parties cannot agree, the customer may cancel the affected service. Clientager is responsible for its subprocessors’ performance.
6. International transfers
Clientager is based in India and may process data in other countries. Where the law requires a transfer mechanism, the Standard Contractual Clauses (Module 2 controller to processor, and Module 3 where the customer is a processor) are incorporated by reference, with the UK International Data Transfer Addendum for UK data, and the annex below completes them. Clientager may also rely on other lawful transfer mechanisms.
7. Helping the customer
Taking into account the nature of processing, Clientager will help the customer to respond to requests from people exercising their rights, to carry out data protection impact assessments and prior consultations, and to meet security and breach notification duties, at reasonable cost where the help goes beyond what the dashboard provides. If a person contacts Clientager directly about Customer Personal Data, Clientager will refer them to the customer.
8. Personal data breach
Clientager will tell the customer without undue delay, and where possible within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information it has to help the customer meet its duties, and will take reasonable steps to contain and fix it.
9. Return and deletion
On termination, the customer can export Customer Personal Data for 30 days. After that, Clientager deletes or anonymises it within 90 days, unless the law requires it to keep some. Backups are overwritten on their normal cycle.
10. Audits
Clientager will give the customer the information needed to show it follows this addendum, such as written answers to reasonable security questionnaires and summaries of its measures. If that is not enough, or a regulator requires it, the customer may carry out an audit once a year with 30 days’ notice, during working hours, at its own cost, subject to confidentiality and without disrupting other customers.
11. Customer responsibilities
The customer is responsible for having a lawful basis for the data it asks Clientager to process, for telling people about the processing (including AI use and any recording) and getting consents the law requires, and for the accuracy of its instructions.
12. Liability and order of precedence
Liability under this addendum is subject to the limits in the Terms. If this addendum conflicts with the Terms on data protection, this addendum applies. If it conflicts with the Standard Contractual Clauses, the Clauses apply.
Annex: details of processing
- Subject matter and duration: providing the Clientager service for as long as the customer has an account, plus the return and deletion period above.
- Nature and purpose: receiving and answering calls, texts, chats, emails and messages with an AI agent; storing conversations, summaries and customer records; booking, payments links, reminders and follow-ups; reporting in the dashboard.
- Types of personal data: names, phone numbers, email and addresses, conversation content, voice recordings and transcripts where enabled, booking and order details, payment status, identifiers and metadata. Special categories only if the customer’s callers volunteer them.
- People concerned: the customer’s customers, prospects and contacts, and the customer’s staff.
- Frequency: continuous while the service is used.
- Competent supervisory authority and governing law for the Clauses: that of the customer’s EU member state of establishment, or Ireland if none; for the UK, the ICO and the law of England and Wales.
- Contact for data protection: privacy@clientager.com.