Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service between Polca LLC ("Processor") and the Agency ("Controller") and governs Polca's processing of Agency Personal Data: personal information the Agency submits to or generates through the Service, including lead and client records, call recordings and transcripts, and application-related materials that may contain health-related answers and banking details. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.
1. Roles & instructions
The Agency is the controller/business; Polca is the processor/service provider. Polca will process Agency Personal Data only: (a) to provide, secure, and support the Service as described in the Terms and Annex 1; (b) per the Agency's documented instructions given through the Service's configuration; and (c) as required by law. For governmental or legal demands concerning Agency Personal Data, Polca will review the demand for legal validity, seek to narrow demands it reasonably considers overbroad, disclose only the information legally required, and notify the Agency before disclosure unless prohibited by law. Polca will promptly inform the Agency if, in its opinion, an instruction violates applicable data-protection law.
Agency responsibilities. The Agency is responsible for the lawfulness, accuracy, and quality of Agency Personal Data and of its processing instructions; providing legally required privacy notices; obtaining required consents or other lawful bases, including for sensitive data; responding to Consumers as controller; securing its own credentials, integrations, and user access; and configuring and using the Service lawfully — including not submitting data the Service is not designed and authorized to process.
2. Service-provider certifications
Polca will not: sell or share Agency Personal Data; retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes in Annex 1 (including not for advertising or training generalized AI models); or combine it with data from other sources except to perform the Service. Polca certifies it understands and will comply with these restrictions under the CCPA/CPRA and similar state laws.
3. Confidentiality & personnel
Access to Agency Personal Data is limited to personnel and contractors who need it to perform the Service and who are bound by written confidentiality obligations. Access is least-privilege and logged.
4. Sensitive data; HIPAA
Agency workflows may include health-related and financial information collected by the Agency from its clients. Polca applies Annex 2 safeguards to all Agency Personal Data uniformly. This DPA is not a Business Associate Agreement and does not authorize submission of PHI subject to HIPAA. An Agency that believes its use requires a BAA must contact legal@polca.ai and may not submit such PHI unless and until the parties execute one. To the extent applicable to the Agency or Agency Personal Data, Polca acts as a service provider supporting the Agency's obligations under GLBA-related safeguards requirements and applicable state insurance data-security laws.
5. Sub-processors
The Agency authorizes the sub-processor categories in Annex 3. Polca will: maintain a current named list (available at privacy@polca.ai); bind each sub-processor by written contract to obligations materially equivalent to this DPA, including the service-provider restrictions applicable under state privacy laws (such as the CCPA/CPRA); remain responsible for their performance; and give at least 15 days' notice of additions or replacements, during which the Agency may object on reasonable data-protection grounds — if unresolved, the Agency may terminate the affected portion of the Service prorated.
6. Security
Polca implements and maintains the technical and organizational measures in Annex 2, appropriate to the nature of the data, and will not materially decrease the overall protection during a subscription term.
7. Personal-data breach
"Personal-Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Agency Personal Data; it excludes unsuccessful attempts and incidents that do not compromise the confidentiality, integrity, or availability of Agency Personal Data (such as blocked attacks, failed login attempts, or port scans).
Polca will notify the Agency without undue delay, and in any event within 72 hours, after becoming aware of a Personal-Data Breach affecting Agency Personal Data, providing: the nature and categories affected, approximate volumes, likely consequences, measures taken or proposed, and a contact point — supplemented as information becomes available. Polca will reasonably cooperate with the Agency's own notification obligations. Notification is not an admission of fault.
8. Assistance
Taking into account the nature of processing, Polca will reasonably assist the Agency with: (a) responding to Consumer requests (access, deletion, correction, opt-out) — the Service provides export and deletion tooling, and automated opt-out enforcement; (b) security and impact assessments relating to the Service; and (c) regulator inquiries concerning Agency Personal Data processed by Polca. Assistance beyond built-in tooling may be billed at reasonable rates with advance notice — except that Polca will not charge for assistance reasonably required because of Polca's breach of this DPA, its violation of applicable data-protection law, or a Personal-Data Breach caused by Polca or its sub-processors.
9. Deletion & return
During the term, the Agency may export Agency Personal Data at any time. On termination, the Agency has a 30-day export window, after which Polca deletes Agency Personal Data from production systems; encrypted backups are deleted or overwritten within 35 days thereafter — except, in each case, where retention is required by law, valid legal process, or a documented legal hold, in which case the retained data remains protected under this DPA and is deleted when the retention basis ends. On written request, Polca will confirm deletion in writing.
10. Audits
No more than once annually (and after a confirmed breach affecting the Agency), Polca will, on written request: provide a written description of its security program and this DPA's implementation, complete a reasonable security questionnaire, and make available existing third-party assessments when they exist. If these are insufficient to meet a legal obligation, the parties will agree on a reasonable, scoped remote audit at the Agency's expense, under confidentiality — no more than once annually, except following a material Personal-Data Breach, a material security-control change, or where required by a regulator or applicable law.
11. Liability & term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (Section 17). This DPA is effective for as long as Polca processes Agency Personal Data.
Annex 1 — Processing details
- Subject matter & purpose: operating the appointment-setting platform — placing and answering calls, transcription, summarization, disposition, CRM synchronization, calendaring, reporting, storage, support, security.
- Duration: the subscription term plus the export/deletion period.
- Data subjects: the Agency's leads, clients, and policyholders; Agency users.
- Categories: identifiers and contact details; call audio, transcripts, and summaries; appointment and disposition records; documents the Agency uploads, which may include health-related application answers and banking details; Agency-user account data.
Annex 2 — Security measures
- Tenant isolation enforced at the database layer via forced row-level security on every tenant table; a non-privileged application role that cannot bypass it; automated isolation tests in the deployment pipeline.
- Encryption in transit (TLS); hashed credentials (memory-hard algorithm); secrets stored outside source control with restricted permissions.
- Least-privilege, individually attributed administrative access; audit logging of platform activity.
- Network controls: firewalled databases (application-only access), carrier-restricted SIP ingress, hardened public endpoints.
- Recording lifecycle management with scheduled deletion no later than 90 days after creation, except where an Order Form specifies another period or preservation is required by law or legal hold.
- Vulnerability remediation prioritized by severity; periodic security review against a maintained internal audit.
- Personnel confidentiality obligations; contractor IP/confidentiality agreements; offboarding access revocation.
- Encrypted backups are access-restricted and deleted or overwritten within 35 days after deletion from production systems, except where preservation is legally required.
Annex 3 — Authorized sub-processor categories
- Cloud infrastructure hosting — application hosting, databases, encrypted storage, backups, and related infrastructure in the United States
- Payment processing (currently Stripe) — Agency billing data only
- Telephony carriers and caller-identity/branding registrars — call delivery, number provisioning, attestation
- AI speech and language providers — transcription, speech synthesis, and conversation processing in live call handling