Data Processing Agreement

DATA PROCESSING AGREEMENT (DPA): Baydar Digital

E-mail: [email protected] Website: www.baydardigital.com

DATA PROCESSING AGREEMENT (DPA)

Baydar Digital

E-mail: [[email protected]](mailto:[email protected])

Website: [www.baydardigital.com](http://www.baydardigital.com)

Chamber of Commerce (KvK): 93519702

Established in The Hague, the Netherlands

This Data Processing Agreement ("DPA") forms part of the agreement between Baydar Digital and the Customer concerning the provision of services by Baydar Digital.

1. Parties and Definitions

1.1 Parties

Controller:

The Customer that has entered into an agreement with Baydar Digital and determines the purposes and means of the processing of Personal Data.

Processor:

Baydar Digital, established in The Hague, the Netherlands, Chamber of Commerce number 93519702.

The Controller and Processor are collectively referred to as the "Parties."

1.2 Definitions

For the purposes of this DPA:

Personal Data:

Any information relating to an identified or identifiable natural person.

Processing:

Any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, deletion or destruction.

Controller:

The natural or legal person that determines the purposes and means of Processing Personal Data.

Processor:

The natural or legal person that Processes Personal Data on behalf of the Controller.

Sub-processor:

A third party engaged by the Processor that Processes Personal Data on behalf of the Controller.

Data Subject:

An identified or identifiable natural person whose Personal Data is Processed.

Personal Data Breach:

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

GDPR:

Regulation (EU) 2016/679, the General Data Protection Regulation.

EEA:

European Economic Area.

2. Purpose of this Agreement

This DPA governs the Processing of Personal Data by Baydar Digital on behalf of the Controller in connection with the services provided by Baydar Digital.

The Parties intend this DPA to satisfy the requirements applicable to processor agreements under Article 28 of the GDPR.

Baydar Digital shall Process Personal Data solely for the purpose of providing the agreed services and in accordance with documented instructions from the Controller, unless Processing is otherwise required by applicable law.

3. Scope of Processing

3.1 Subject Matter

Baydar Digital may provide services including:

* AI voice agents;

* AI telephone assistants;

* AI receptionists;

* AI chatbots;

* appointment and reservation systems;

* workflow automation;

* customer-service automation;

* lead qualification;

* CRM integrations;

* calendar integrations;

* e-mail and messaging integrations;

* API integrations;

* digital automation services;

* related implementation, maintenance and support services.

3.2 Nature and Purpose of Processing

Personal Data may be Processed for purposes including:

* handling incoming and outgoing customer communications;

* answering customer enquiries;

* processing telephone conversations;

* making and managing appointments or reservations;

* qualifying leads;

* forwarding calls or requests;

* generating responses through AI systems;

* executing automated workflows;

* transferring information between authorized business systems;

* sending confirmations or notifications;

* providing technical support;

* monitoring service performance;

* detecting technical errors;

* improving the configuration and reliability of the services;

* fulfilling other documented instructions of the Controller.

Baydar Digital shall not Process Personal Data for purposes that are incompatible with the Controller's documented instructions.

4. Categories of Personal Data

Depending on the services selected by the Controller, Personal Data may include:

* first and last names;

* e-mail addresses;

* telephone numbers;

* addresses;

* appointment information;

* reservation information;

* dates and times;

* customer enquiries;

* voice recordings, where recording is enabled;

* audio streams required for real-time voice processing;

* transcripts of conversations;

* chat messages;

* call metadata;

* customer service notes;

* information voluntarily provided by callers or users;

* CRM data;

* calendar information;

* technical identifiers;

* IP addresses where applicable;

* workflow and integration data;

* other information submitted by Data Subjects through the AI systems.

The exact categories of Personal Data Processed depend on the services and configuration requested by the Controller.

5. Special Categories of Personal Data

The services are not intended by default to Process special categories of Personal Data within the meaning of Article 9 GDPR.

However, depending on the Controller's business activities, Data Subjects may voluntarily provide information that could constitute special-category Personal Data.

Examples may include:

* allergy information;

* medical dietary restrictions;

* health-related appointment information;

* disability-related information;

* religious dietary requirements;

* other sensitive information voluntarily disclosed during a conversation.

The Controller is responsible for determining whether the collection of such information is necessary and lawful.

Baydar Digital shall configure systems, where reasonably possible, according to the principle of data minimisation and shall not intentionally collect special-category Personal Data unless required for the agreed service and instructed by the Controller.

6. Categories of Data Subjects

Personal Data may relate to:

* customers of the Controller;

* prospective customers;

* callers;

* website visitors;

* end-users interacting with AI agents;

* individuals making appointments or reservations;

* employees or representatives of the Controller;

* suppliers or business contacts;

* other persons communicating with the Controller through systems operated by Baydar Digital.

7. Obligations of Baydar Digital as Processor

Baydar Digital shall:

* Process Personal Data only on documented instructions from the Controller;

* comply with applicable GDPR processor obligations;

* ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations;

* implement appropriate technical and organizational measures;

* restrict access to Personal Data to persons who require such access;

* assist the Controller with Data Subject requests where reasonably required;

* assist the Controller with its obligations relating to security, data breaches and data protection impact assessments where applicable;

* notify the Controller of Personal Data Breaches without undue delay after becoming aware of them;

* provide information reasonably necessary to demonstrate compliance with this DPA;

* delete or return Personal Data after termination of the services in accordance with Section 18;

* inform the Controller if, in Baydar Digital's reasonable opinion, an instruction infringes applicable data protection legislation.

8. Obligations of the Controller

The Controller shall:

* ensure that Personal Data is collected and Processed lawfully;

* determine and document the appropriate lawful basis for Processing;

* provide Baydar Digital with lawful and documented Processing instructions;

* ensure that Data Subjects receive appropriate privacy information;

* determine whether additional consent or notification is required for telephone recording or AI-based interactions;

* ensure that only Personal Data necessary for the intended purpose is collected;

* determine appropriate retention periods;

* ensure that the use of AI systems is appropriate for the Controller's business activities;

* ensure the accuracy and legitimacy of Personal Data supplied to Baydar Digital;

* promptly inform Baydar Digital of instructions concerning deletion, restriction or correction of Personal Data.

The Controller remains responsible for determining the purposes and essential means of the Processing.

9. AI Voice Agents and Retell AI

9.1 Use of Retell AI

Where AI voice services are included in the services, Baydar Digital may use Retell AI, Inc. ("Retell AI") as a Sub-processor and technology provider.

Retell AI may provide infrastructure required to:

* receive and make telephone calls;

* process voice communications;

* convert speech to text;

* generate AI-powered responses;

* convert text into speech;

* route telephone communications;

* execute functions and integrations;

* create conversation transcripts;

* process call metadata;

* store call-related information where storage is enabled;

* facilitate integrations with external systems.

9.2 Data Processed Through Retell AI

Depending on the configuration, information Processed through Retell AI may include:

* telephone numbers;

* names;

* e-mail addresses;

* voice/audio data;

* transcripts;

* call start and end times;

* call duration;

* call identifiers and metadata;

* appointment or reservation details;

* questions and information provided during calls;

* AI agent responses;

* information transmitted to authorized integrations.

The exact Personal Data Processed depends on the configuration of the AI Agent and the information voluntarily provided by the Data Subject.

9.3 Retell AI Security and Compliance

Baydar Digital shall take reasonable steps to ensure that Retell AI provides appropriate contractual, technical and organizational safeguards applicable to its role as a Sub-processor.

Where required, Baydar Digital shall maintain an appropriate data processing agreement with Retell AI.

Baydar Digital may use security and privacy functionality made available by Retell AI, where appropriate for the relevant service, including:

* access controls;

* authentication;

* data encryption;

* configurable data-retention controls;

* Personal Identifiable Information (PII) redaction;

* role-based access controls;

* logging and monitoring;

* other available enterprise security controls.

The availability and configuration of individual security features may depend on the Retell AI service plan and configuration used.

9.4 Voice Recording

Call recording shall not be enabled solely because it is technically available.

Where voice recordings are stored, the Controller shall determine that there is a lawful purpose and legal basis for such storage.

Where required by applicable law, callers shall receive appropriate information regarding the recording and Processing of their calls.

Baydar Digital may, on instruction from the Controller and where technically supported:

* disable recording;

* limit storage;

* configure retention;

* enable PII redaction;

* delete recordings;

* restrict access to recordings.

9.5 Transcripts

AI conversations may produce transcripts for purposes including:

* execution of the requested service;

* appointment or reservation processing;

* workflow automation;

* troubleshooting;

* quality assurance;

* service monitoring.

Transcript retention shall be limited according to the agreed service requirements and configured retention policy.

10. Data Minimisation

Baydar Digital shall apply the principle of data minimisation.

AI Agents shall, where reasonably possible, be configured to request only information necessary to perform their designated task.

Personal Data shall not knowingly be collected solely because the AI Agent is technically capable of collecting it.

The Controller is responsible for identifying the information necessary for its business process.

11. Sub-processors

11.1 General Authorization

The Controller grants Baydar Digital general written authorization to engage Sub-processors where reasonably necessary to deliver the services.

Baydar Digital shall ensure that Sub-processors that Process Personal Data on its behalf are subject to data protection obligations providing an appropriate level of protection.

11.2 Sub-processor Changes

Baydar Digital may add, replace or remove Sub-processors.

Where required under applicable data protection law, the Controller shall be informed of material additions or replacements of Sub-processors before the relevant change takes effect.

The Controller may object to a new Sub-processor on reasonable and documented data-protection grounds.

The Parties shall cooperate in good faith to resolve such objection.

If no reasonable alternative can be provided, Baydar Digital may be entitled to discontinue the affected service subject to the applicable service agreement.

11.3 Current Sub-processors

The Sub-processors and supporting technology providers that may be used are listed in Annex 2.

Not every Sub-processor listed in Annex 2 will necessarily Process data for every Controller. Their use depends on the services, integrations and configuration selected.

12. International Data Transfers

Some Sub-processors used by Baydar Digital may Process or store Personal Data outside the EEA.

Where Personal Data is transferred to a country outside the EEA, Baydar Digital shall ensure that an appropriate transfer mechanism is available where required by GDPR.

Such mechanisms may include:

* an adequacy decision adopted by the European Commission;

* Standard Contractual Clauses adopted by the European Commission;

* another valid transfer mechanism permitted under Chapter V GDPR.

Where Standard Contractual Clauses are required, Baydar Digital shall take reasonable steps to ensure that the appropriate SCC module is implemented between the relevant parties.

Where appropriate, supplementary technical, organizational or contractual measures may be implemented following an assessment of the relevant transfer.

13. Security of Processing

Baydar Digital shall implement appropriate technical and organizational measures taking into account:

* the state of the art;

* implementation costs;

* the nature, scope, context and purposes of Processing;

* the likelihood and severity of risks to Data Subjects.

Measures may include, where appropriate:

* encrypted transmission using TLS/HTTPS;

* encryption at rest where supported by the relevant service provider;

* authentication controls;

* role-based access controls;

* least-privilege access;

* multi-factor authentication where available;

* password and credential protection;

* API-key protection;

* secure storage of credentials;

* separation of customer environments where technically applicable;

* security logging;

* monitoring;

* backups where necessary;

* software updates;

* access revocation procedures;

* incident-response procedures;

* data-retention controls;

* PII redaction or masking where appropriate.

Further measures are set out in Annex 1.

14. Data Subject Rights

Baydar Digital shall, taking into account the nature of the Processing, reasonably assist the Controller in responding to requests concerning:

* access;

* rectification;

* erasure;

* restriction of Processing;

* objection;

* data portability;

* rights relating to automated decision-making where applicable.

Where Baydar Digital receives a Data Subject request relating to Personal Data Processed on behalf of the Controller, Baydar Digital may refer the request to the Controller unless otherwise required by law.

The Controller remains responsible for responding to Data Subjects and determining the validity of such requests.

15. Personal Data Breach

In the event Baydar Digital becomes aware of a Personal Data Breach involving Personal Data Processed under this DPA, Baydar Digital shall notify the Controller without undue delay.

Where reasonably available, the notification shall include:

* the nature of the incident;

* the categories of Personal Data affected;

* the categories of Data Subjects affected;

* approximate numbers where known;

* likely consequences;

* measures taken or proposed to mitigate the incident;

* relevant contact information.

Baydar Digital shall reasonably cooperate with the Controller in investigating and mitigating the incident.

The Controller remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is legally required.

16. Confidentiality

Baydar Digital shall ensure that persons authorized to Process Personal Data:

* receive access only where necessary;

* are subject to confidentiality obligations;

* are informed of relevant data-protection requirements.

Confidentiality obligations shall continue after termination of the person's involvement with the relevant Processing activities.

17. Audits and Compliance Information

Baydar Digital shall make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

The Controller may request reasonable information concerning:

* security measures;

* Sub-processors;

* Processing activities;

* data-retention practices;

* relevant compliance documentation.

Where a formal audit is reasonably required, the Parties shall agree in advance on its scope, timing and confidentiality arrangements.

Audits shall not unreasonably disrupt Baydar Digital's operations or compromise the confidentiality or security of other customers.

18. Data Retention, Return and Deletion

Personal Data shall not be retained longer than necessary for the purposes for which it is Processed, subject to:

* Controller instructions;

* applicable legal requirements;

* legitimate technical requirements;

* agreed retention schedules.

Upon termination of the services, Baydar Digital shall, at the Controller's choice and where technically feasible:

* return relevant Personal Data; or

* delete relevant Personal Data,

unless applicable law requires continued retention.

Data stored within third-party Sub-processors shall be deleted or allowed to expire in accordance with the applicable configuration, contractual arrangements and retention mechanisms of those providers.

Backup copies may remain temporarily until overwritten according to normal backup cycles, provided such copies remain protected and are not used for another purpose.

19. AI Processing and Model Training

Personal Data submitted through AI Agents may be transmitted to authorized AI, speech-processing or language-model providers where necessary to generate or process responses.

Baydar Digital shall configure such providers, where supported, to prevent customer data from being used for model training or fine-tuning.

Baydar Digital shall not intentionally authorize Personal Data Processed on behalf of the Controller to be used for general AI model training unless:

* the Controller has expressly instructed or authorized such use;

* an appropriate lawful basis exists; and

* applicable transparency and GDPR requirements have been satisfied.

Aggregated or effectively anonymized data that can no longer reasonably identify a Data Subject may be used for legitimate technical or statistical purposes subject to applicable law.

20. Automated Decision-Making

Unless expressly agreed otherwise, Baydar Digital's AI Agents are intended to support communication, automation and administrative processes and are not intended to make decisions producing legal or similarly significant effects solely through automated Processing.

If the Controller intends to use the services for such automated decisions, the Controller shall inform Baydar Digital before implementation so that the Parties can assess applicable requirements under Article 22 GDPR and related legislation.

21. Data Protection Impact Assessments

Where the Controller determines that a Data Protection Impact Assessment ("DPIA") is required under Article 35 GDPR, Baydar Digital shall provide reasonable assistance concerning Processing performed through its services.

The Controller remains responsible for determining whether a DPIA is required and for conducting the DPIA.

22. Duration

This DPA enters into force when the Parties' service agreement becomes effective or when Baydar Digital begins Processing Personal Data on behalf of the Controller, whichever occurs first.

It remains effective for as long as Baydar Digital Processes Personal Data on behalf of the Controller.

Provisions intended by their nature to survive termination, including confidentiality and data deletion obligations, shall continue to apply.

23. Liability

Each Party shall be responsible for its obligations under this DPA and applicable data protection legislation.

Nothing in this DPA shall exclude or limit liability where such exclusion or limitation is prohibited by applicable law.

Any contractual limitations of liability contained in the main service agreement shall apply to this DPA to the extent permitted by applicable law.

24. Order of Precedence

If there is a conflict between this DPA and the main service agreement concerning the Processing or protection of Personal Data, this DPA shall prevail with respect to such Processing.

Mandatory provisions of applicable data protection legislation shall prevail over conflicting contractual provisions.

25. Governing Law

This DPA shall be governed by the laws of the Netherlands.

The competent Dutch courts shall have jurisdiction, subject to any mandatory rights or jurisdiction provided under applicable data protection legislation.

26. Signatures

Controller

Name: ______________________________________

Company: ___________________________________

Position: ____________________________________

Signature: __________________________________

Date: _______________________________________

Processor

Name: ______________________________________

Company: Baydar Digital

Position: ____________________________________

Signature: __________________________________

Date: _______________________________________

-

ANNEX 1 – TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

Baydar Digital applies technical and organizational measures appropriate to the nature of its services.

These may include:

Access Security

* restricted access to production systems;

* role-based access where available;

* least-privilege access principles;

* individual user accounts where practical;

* strong passwords;

* multi-factor authentication where available;

* periodic removal of unnecessary access.

Network and Transmission Security

* TLS/HTTPS encryption for supported communications;

* secure API connections;

* protected webhook endpoints;

* secure management of API keys and credentials.

Data Protection

* encryption at rest where supported by the applicable provider;

* PII redaction or masking where appropriate;

* data-minimisation controls;

* configurable retention settings;

* deletion procedures;

* separation of customer data where supported.

AI Voice Security

Where Retell AI is used:

* access to Retell AI accounts shall be restricted;

* credentials and API keys shall be protected;

* call recording may be disabled where unnecessary;

* retention settings may be configured according to Controller requirements;

* PII redaction may be enabled where appropriate and technically supported;

* access to recordings and transcripts shall be limited;

* only authorized integrations shall receive call data.

Operational Security

* monitoring of relevant systems;

* logging where available;

* incident-response procedures;

* periodic software and integration updates;

* backup procedures where appropriate;

* access revocation when personnel no longer require access.

Supplier Security

Baydar Digital shall take reasonable steps to select service providers that provide appropriate security safeguards for the type of Processing concerned.

ANNEX 2 – SUB-PROCESSORS AND TECHNOLOGY PROVIDERS

Baydar Digital may use the following providers depending on the services purchased and configured by the Controller.

Retell AI, Inc.

Service:

Voice AI and AI Agent infrastructure.

Purpose:

Processing telephone conversations, speech, AI Agent interactions, transcripts, call metadata and authorized integrations.

Potential data:

Voice/audio, telephone numbers, names, e-mail addresses, transcripts, call metadata, appointment or reservation information and other information provided during calls.

International Processing:

Processing may occur outside the EEA. Appropriate transfer safeguards shall be used where required.

OpenAI

Service:

Artificial intelligence and language-model processing, where used.

Purpose:

Generating or processing AI responses and related functionality.

Potential data:

Relevant conversation content and instructions required for response generation.

Use depends on the AI configuration selected for the relevant service.

n8n

Service:

Workflow automation.

Purpose:

Transferring data between authorized applications and executing automated workflows.

Potential data:

Contact information, appointment or reservation information, workflow data and other information required by the configured automation.

Make

Service:

Workflow automation and integration platform.

Purpose:

Executing integrations between connected services.

Potential data:

Personal Data necessary to execute the configured workflow.

Replit

Service:

Development and hosting environment, where used.

Purpose:

Hosting or operating custom applications, APIs or integration components.

Potential data:

Depends on the relevant application and configuration.

-

Calendar and Scheduling Providers

Examples may include Cal.com, Calendly, Google Calendar, Microsoft Outlook or another scheduling service selected by the Controller.

Purpose:

Creating and managing appointments and reservations.

Potential data:

Name, e-mail address, telephone number, date, time, appointment details and notes.

Communication Providers

Providers may be used for:

* telephone routing;

* SMS;

* e-mail;

* WhatsApp or other messaging services.

The specific provider depends on the Controller's configuration.

Hosting and Infrastructure Providers

Cloud infrastructure may be provided directly or indirectly through providers used by Baydar Digital or its Sub-processors.

The applicable provider depends on the deployed architecture.

Baydar Digital shall maintain or make available an up-to-date Sub-processor list upon reasonable request.

ANNEX 3 – AI-SPECIFIC PROCESSING DISCLOSURE

AI-Driven Services

Baydar Digital provides AI-powered services that may include:

* voice conversations;

* AI telephone receptionists;

* AI chatbots;

* appointment booking;

* reservation management;

* lead qualification;

* customer support;

* workflow automation;

* automated routing and escalation.

Data Flow

Depending on the implementation, Personal Data may flow between:

Data Subject → Controller → Baydar Digital → Retell AI / AI provider → authorized automation platform → Controller's CRM, calendar or other business system.

Only providers necessary for the relevant implementation should receive Personal Data.

Voice Processing

Voice conversations may require real-time transmission of audio to voice-processing providers.

Audio may be:

* processed in real time;

* converted into text;

* analyzed for conversation context;

* converted into AI responses;

* transmitted to other authorized systems where necessary.

Storage of audio is separate from real-time Processing and should be limited according to the Controller's requirements.

Conversation Logging

Depending on system configuration, conversations may generate:

* call logs;

* transcripts;

* recordings;

* technical logs;

* AI outputs;

* workflow execution records.

Logging shall be limited to what is reasonably necessary for service delivery, troubleshooting, security and agreed quality-control purposes.

Model Training

Baydar Digital shall not intentionally use Controller Personal Data to train general-purpose AI models.

Where third-party AI providers are used, Baydar Digital shall use available enterprise/API configurations designed to prevent customer data from being used for general model training wherever reasonably available.

Human Access

Human access to recordings, transcripts or other conversation information shall be limited to authorized persons where necessary for:

* support;

* troubleshooting;

* configuration;

* security;

* quality control;

* Controller-requested services.

Data Retention

Retention periods should be determined according to the service and Controller requirements.

Where technically possible, Baydar Digital shall configure data-retention settings according to those agreed requirements.

Personal Data shall not be retained indefinitely solely because the underlying platform permits indefinite storage.

Controller Responsibility

The Controller remains responsible for:

* determining the lawful basis;

* providing required privacy information;

* determining which information the AI Agent may request;

* deciding whether conversations may be recorded;

* defining appropriate retention periods;

* ensuring that AI processing is appropriate for its business.

Processor Responsibility

Baydar Digital is responsible for:

* following documented Controller instructions;

* implementing the agreed AI Agent configuration;

* maintaining reasonable security safeguards;

* managing its Sub-processors in accordance with this DPA;

* assisting the Controller with applicable GDPR obligations.

ANNEX 4 – PROCESSING INSTRUCTIONS

Unless otherwise documented by the Parties, the Controller instructs Baydar Digital to Process Personal Data solely to:

1. provide the contracted AI and automation services;

2. operate and maintain the relevant integrations;

3. perform customer-requested workflows;

4. provide technical support;

5. maintain security and service reliability;

6. comply with applicable law.

Any materially different Processing purpose requires additional documented instructions from the Controller.

Drawn up on 5 September 2026.