Last updated: 13 September 2026
Data processing agreement
This Data Processing Agreement ("DPA") forms part of the Terms of service between the customer ("Controller") and AA ENTERTAINMENT LTD, 152, Office No. 9, Naxxar Road, San Gwann SGN 9030, Malta ("Processor") and reflects the requirements of Article 28 GDPR. It applies whenever the Processor processes personal data on behalf of the Controller through the Ringhum service. A countersigned copy is available on request at [email protected].
1. Subject matter and duration
Provision of AI phone assistants that answer and place calls, exchange text messages, book appointments, take messages and synchronise data with tools the Controller connects, for the duration of the Terms of service plus the deletion period in section 10.
2. Nature and purpose of processing
Real-time transcription and generation of speech, conversation handling by AI systems, storage and display of transcripts, recordings, summaries and structured data, delivery of notifications and transfers to Controller-designated third-party systems.
3. Categories of data subjects and data
- Data subjects: the Controller's callers, customers, patients, tenants, prospects and staff, and members of the Controller's workspace.
- Personal data: telephone numbers, names, email addresses, voice (audio during calls and recordings where enabled), transcripts and their content, appointment details, messages, order information, and any other data the data subject shares during a call.
- Special categories: the Controller may configure assistants in contexts (for example medical practices) where callers volunteer health information. The Controller is responsible for ensuring a valid Article 9 condition and for using retention controls appropriately; the Processor applies the same technical measures to all call data.
4. Controller instructions
The Processor processes personal data only on the Controller's documented instructions, which consist of the Terms of service, this DPA, the settings the Controller chooses in the dashboard (including assistant instructions, retention, integrations and recording) and the use of the API. The Processor will inform the Controller if an instruction, in its opinion, infringes the GDPR.
5. Confidentiality
Persons authorised to process the data are bound by confidentiality obligations and receive data protection training. Access to customer data is limited to staff who need it for support or operations and is logged.
6. Security (Article 32)
The Processor implements the measures in Annex II, including encryption in transit and at rest, encrypted storage of credentials, role-based access with two-factor authentication, audit logging, network isolation of the voice pipeline, signed webhooks, backups with tested restores, vulnerability management and incident response procedures.
7. Sub-processors
The Controller gives general authorisation to the sub-processors listed on the Sub-processors page. The Processor will notify the Controller (by email to workspace owners) at least 30 days before adding or replacing a sub-processor that will process Controller data; the Controller may object on reasonable data protection grounds, in which case the parties will work in good faith to find a solution and, failing that, the Controller may terminate the affected service for a prorated refund. The Processor imposes data protection obligations on sub-processors equivalent to this DPA and remains liable for their performance. Third-party tools the Controller chooses to connect (calendars, CRMs, help desks, stores) are not sub-processors: they are independent recipients acting on the Controller's instruction.
8. Data subject rights
The Processor assists the Controller with appropriate technical measures (export, search, deletion, retention settings, contact records) to respond to data subject requests. Requests received directly by the Processor are forwarded to the Controller without undue delay and not answered directly unless required by law.
9. Assistance, breaches, DPIAs
The Processor notifies the Controller of a personal data breach affecting Controller data without undue delay and no later than 48 hours after becoming aware, with the information required by Article 33(3) as it becomes available. The Processor assists the Controller with data protection impact assessments and prior consultations relating to the service, taking into account the nature of processing and the information available to it.
10. Deletion and return
During the term the Controller can delete calls, contacts, recordings and entire workspaces from the dashboard and configure automatic retention. On termination the Controller may export all data for 30 days, after which the Processor deletes it (backups within a further 60 days) unless EU or Member State law requires storage.
11. Audits
The Processor makes available the information necessary to demonstrate compliance with Article 28, including its security documentation and, where available, third-party audit reports. The Controller may conduct an audit once per year, or after a breach, with 30 days' notice, during business hours, at its own cost and subject to confidentiality; the parties will first attempt to satisfy the audit through documentation and written answers.
12. International transfers
Transfers of Controller data outside the EEA occur only to sub-processors covered by an adequacy decision (including EU–US Data Privacy Framework certification) or by the Standard Contractual Clauses (Commission Decision (EU) 2021/914), module 3 (processor to sub-processor), with transfer impact assessments and supplementary measures as described in the Privacy policy. Where the Controller is itself outside the EEA, the parties incorporate the appropriate SCC module by reference.
13. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of service, except that nothing limits liability towards data subjects under Article 82 GDPR. In case of conflict, this DPA prevails over the Terms of service for data protection matters.
Annex I — Details of processing
As set out in sections 1 to 3. Frequency: continuous, for each call, message and dashboard action. Retention: as configured by the Controller (zero retention, 7 days to 1 year, or indefinite).
Annex II — Technical and organisational measures
- Encryption: TLS 1.2+ for all traffic; AES-256 at rest for databases, files and backups; application-level encryption of integration credentials, two-factor secrets and API keys.
- Access control: role-based permissions (owner, admin, member, viewer), two-factor authentication, single-use magic links, session expiry, audit log of every action with IP address.
- Pseudonymisation: phone numbers are masked in operational logs; call audio is never written to disk unless recording is enabled by the Controller.
- Availability: redundant hosting, daily encrypted backups with periodic restore tests, monitoring and alerting, documented incident response and business continuity plans.
- Development: code review, dependency vulnerability scanning, automated test suite, separation of production and test environments, least-privilege service credentials rotated on staff changes.
- Organisation: confidentiality agreements, data protection training, a documented process for data subject requests and breach handling, annual review of these measures.