Data Processing Agreement (DPA)
This Data Processing Addendum (“DPA”) supplements the PropelRoot AI Master Subscription Agreement / Terms of Service entered into by and between PropelRoot AI (“Processor”) and the subscriber entity or contractor (“Customer” or “Controller”). This DPA governs the processing of Personal Data uploaded, captured, or ingested through the PropelRoot AI Voice, SMS, and Omnichannel Communications Platform.
B2B Enterprise Compliance Guarantee: PropelRoot AI acts strictly as a Data Processor / Service Provider with respect to homeowner and consumer data processed on behalf of Customer. PropelRoot AI never sells, retains, leases, or cross-monetizes consumer phone numbers, call audio, or lead records for advertising or third-party marketing.
1. Roles and Scope of Processing
1.1. Principal Roles: Customer is the Data Controller of Customer Personal Data under Applicable Data Protection Law (including CCPA, CPRA, and GDPR where applicable), and PropelRoot AI is the Data Processor acting solely on Customer's documented instructions.
1.2. Scope: Processor shall process Customer Personal Data exclusively for the purpose of providing, maintaining, and executing automated conversational voice calls, transactional SMS text-backs, appointment booking, and CRM synchronization as authorized under the Principal Agreement.
1.3. CCPA/CPRA Service Provider Certification: Processor certifies that it understands and complies with the restrictions of a Service Provider under the California Consumer Privacy Act. Processor shall not retain, use, disclose, or sell Customer Personal Data outside the direct business relationship with Customer.
2. Categories of Data and Data Subjects
2.1. Data Subjects: Homeowners, commercial property managers, prospective inbound sales leads, service callers, and Customer's personnel.
2.2. Data Categories Processed:
- Contact Identifiers: Consumer name, telephone number (E.164 format), email address, physical service address.
- Communication Metadata: Call start/end timestamps, duration, per-second billing units, SMS delivery states, carrier error codes.
- Audio & Conversation Content: Customer-initiated inbound/outbound call audio streams, dual-channel audio recordings, automated text message transcripts, qualification questionnaire responses.
- Scheduling Details: Calendar appointment slots, service scope descriptions, contractor estimate notes.
3. Technical and Organizational Security Measures (TOMs)
Processor has implemented and maintains comprehensive technical and organizational safeguards designed to protect Customer Personal Data against unauthorized disclosure, alteration, loss, or destruction:
- Cryptographic Vault: All sensitive customer API tokens, carrier credentials, and webhook secrets are stored inside an isolated multi-tenant vault encrypted using AES-256-GCM.
- Encryption in Transit: All web traffic, voice audio streaming, and API integrations utilize TLS 1.3 encryption with strict HTTPS redirection.
- Multi-Tenant Siloing: Strict logical separation prevents any workspace, campaign, contact, or recording from being accessible to another customer account.
- Zero Data Training: Proprietary customer lead data and voice call transcripts are never used to train generalized foundation AI models.
- Deterministic Carrier Guards: Inbound opt-out keywords (STOP, CANCEL, QUIT) trigger sub-0.1ms FlashText execution with immediate outbound HTTP 409 blocking.
4. Authorized Downstream Sub-Processors
Customer provides general written authorization for Processor to engage downstream infrastructure providers (“Sub-Processors”) essential to executing carrier telephony, speech recognition, and cloud database operations:
| Sub-Processor | Role / Service Category | Data Center Region |
|---|---|---|
| Google Cloud Platform (GCP) | Cloud Compute VPS Host & Edge Delivery | Northern Virginia, USA |
| Supabase Inc. (AWS) | Regional PostgreSQL Database & Storage | North Virginia (us-east-1), USA |
| WorkOS Inc. | Enterprise AuthKit, SSO & RBAC | USA |
| Vonage Inc. (Ericsson) | PSTN Voice Trunks & WebSocket Audio | USA |
| SignalWire Inc. | A2P 10DLC SMS Carrier Rails | USA |
| TextGrid LLC | Dedicated Direct REST Messaging Rails | USA (Microsoft Azure) |
| AssemblyAI Inc. | Universal Streaming Speech-to-Text | USA |
| Deepgram Inc. | Aura Neural Text-to-Speech Engine | USA |
| OpenAI LLC | Conversational Reasoning (Zero-Retention) | USA |
| Resend Inc. | Transactional Customer Care Email | USA |
| Svix Inc. | Enterprise HMAC-Signed Webhook Ingest | USA |
5. Security Incident and Data Breach Notification
5.1. Rapid Notification: In the event of a confirmed Security Incident involving Customer Personal Data on Processor systems, Processor shall notify Customer via email without unreasonable delay, and in any event within seventy-two (72) hours of becoming aware of the breach.
5.2. Remediation & Information: Processor shall take prompt remedial action to contain and mitigate the incident, and provide Customer with detailed information regarding the nature of the breach, affected records, and remediation steps.
6. Data Subject Rights (DSR) Assistance
Processor shall provide Customer with reasonable technical assistance to enable Customer to respond to consumer requests to exercise rights of access, correction, deletion, or portability under Applicable Data Protection Law. If a consumer contacts Processor directly, Processor shall redirect the consumer to Customer within forty-eight (48) hours.
7. Deletion and Return of Customer Personal Data
Upon termination of the Principal Agreement or upon Customer's written request, Processor shall securely delete or return all Customer Personal Data within thirty (30) days, except to the extent retention is required by applicable telecommunications regulatory record-keeping laws (e.g. TCPA 4-year consent records or 10DLC campaign audit trails).
8. Governing Law & Precedence
This DPA shall be governed by and construed in accordance with the governing law specified in the Master Subscription Agreement. In the event of any conflict between this DPA and the Master Agreement regarding personal data processing, this DPA shall prevail.
9. Contact & Data Protection Officer
For data protection inquiries, DPA execution requests, or sub-processor notifications, contact:
Data Protection Officer
PropelRoot AI
Email: [email protected] / [email protected]
Address: 8 The Green, Ste B, Dover, DE 19901, United States