# Data processing agreement

> The contract between Deduxer S.R.L. and the businesses that use Onist: what the receptionist does, what you pay, what each side is responsible for.

_Deduxer S.R.L. · Onist · The short version_

- This section is the data processing agreement under Article 28 of the GDPR between you, as controller, and us, as processor, for the personal data of your callers, customers and staff that we process to provide the service ("customer data"). We can sign it as a standalone document on request.

## 14. Data processing agreement

This section is the data processing agreement under Article 28 of the GDPR between you, as controller, and us, as processor, for the personal data of your callers, customers and staff that we process to provide the service ("customer data"). We can sign it as a standalone document on request.

Subject matter and duration. We process customer data to run the receptionist, the app and the messages for you, for as long as your account exists plus the deletion period below.

What we process. Phone numbers, names, vehicle details and plates, what callers say (audio, transcripts, summaries), appointments, messages sent and received, consent flags, and the notes you and your staff add. The people concerned are your callers, your customers and the staff you invite into the app.

Your instructions. We process customer data only to provide the service, as described in these terms and as you configure the app. Your settings in the app are your written instructions. We tell you if we think an instruction breaks the law.

Confidentiality. Only people who need access to help you have it, and they are bound by confidentiality. We may listen to a recording to fix a problem you reported or to check quality, never to build profiles.

Security. Tenant access is enforced by database policies. Files are private and recording links expire after sixty seconds. Changes are audited and application logs omit caller content. Encryption, staff access and backup settings are verified as part of production deployment; regional storage alone does not eliminate international transfers.

Sub-processors. We use the providers listed in the Privacy Policy, under contracts that impose the same obligations on them. We tell you by email at least 30 days before adding or replacing one. If you object on reasonable data protection grounds and we cannot offer an alternative, you may cancel with a refund of any prepaid period you have not used.

Transfers. Where a provider processes data outside the European Economic Area, it does so under Standard Contractual Clauses or another mechanism recognised under Chapter V of the GDPR.

No training. We do not use customer data, including recordings and transcripts, to train AI models, and our providers may not either.

Help with your obligations. We help you answer requests from data subjects, and we give you the information you need for a data protection impact assessment or for a supervisory authority. If we become aware of a breach affecting customer data, we tell you without undue delay and at the latest within 48 hours, with what we know.

Audits. Once a year, on 30 days' notice, you may ask us for evidence of our compliance, including reports from our providers. If that evidence is not enough, you may audit us at your cost during working hours, without disrupting the service.

Deletion and return. Contact us to request export or deletion of customer data. We verify authority, carry out the request and document any legal retention obligation. Audio follows the configured automatic retention period. Backup recovery must reapply deletions before access reopens; database backups do not contain the stored audio files.

---

[HTML](https://onist.ro/en/dpa) · [https://onist.ro](https://onist.ro/en)
