This Data Processing Agreement ("DPA") forms part of the agreement between Baydar Digital and the Customer concerning the provision of services by Baydar Digital.
1. Parties and Definitions
1.1 Parties
Controller:
The Customer that has entered into an agreement with Baydar Digital and determines the purposes and means of the processing of Personal Data.
Processor:
Baydar Digital, established in The Hague, the Netherlands, Chamber of Commerce number 93519702.
The Controller and Processor are collectively referred to as the "Parties."
1.2 Definitions
For the purposes of this DPA:
Personal Data:
Any information relating to an identified or identifiable natural person.
Processing:
Any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, deletion or destruction.
Controller:
The natural or legal person that determines the purposes and means of Processing Personal Data.
Processor:
The natural or legal person that Processes Personal Data on behalf of the Controller.
Sub-processor:
A third party engaged by the Processor that Processes Personal Data on behalf of the Controller.
Data Subject:
An identified or identifiable natural person whose Personal Data is Processed.
Personal Data Breach:
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
GDPR:
Regulation (EU) 2016/679, the General Data Protection Regulation.
EEA:
European Economic Area.
2. Purpose of this Agreement
This DPA governs the Processing of Personal Data by Baydar Digital on behalf of the Controller in connection with the services provided by Baydar Digital.
The Parties intend this DPA to satisfy the requirements applicable to processor agreements under Article 28 of the GDPR.
Baydar Digital shall Process Personal Data solely for the purpose of providing the agreed services and in accordance with documented instructions from the Controller, unless Processing is otherwise required by applicable law.
3. Scope of Processing
3.1 Subject Matter
Baydar Digital may provide services including:
* AI voice agents;
* AI telephone assistants;
* AI receptionists;
* AI chatbots;
* appointment and reservation systems;
* workflow automation;
* customer-service automation;
* lead qualification;
* CRM integrations;
* calendar integrations;
* e-mail and messaging integrations;
* API integrations;
* digital automation services;
* related implementation, maintenance and support services.
3.2 Nature and Purpose of Processing
Personal Data may be Processed for purposes including:
* handling incoming and outgoing customer communications;
* answering customer enquiries;
* processing telephone conversations;
* making and managing appointments or reservations;
* qualifying leads;
* forwarding calls or requests;
* generating responses through AI systems;
* executing automated workflows;
* transferring information between authorized business systems;
* sending confirmations or notifications;
* providing technical support;
* monitoring service performance;
* detecting technical errors;
* improving the configuration and reliability of the services;
* fulfilling other documented instructions of the Controller.
Baydar Digital shall not Process Personal Data for purposes that are incompatible with the Controller's documented instructions.
4. Categories of Personal Data
Depending on the services selected by the Controller, Personal Data may include:
* first and last names;
* e-mail addresses;
* telephone numbers;
* addresses;
* appointment information;
* reservation information;
* dates and times;
* customer enquiries;
* voice recordings, where recording is enabled;
* audio streams required for real-time voice processing;
* transcripts of conversations;
* chat messages;
* call metadata;
* customer service notes;
* information voluntarily provided by callers or users;
* CRM data;
* calendar information;
* technical identifiers;
* IP addresses where applicable;
* workflow and integration data;
* other information submitted by Data Subjects through the AI systems.
The exact categories of Personal Data Processed depend on the services and configuration requested by the Controller.
5. Special Categories of Personal Data
The services are not intended by default to Process special categories of Personal Data within the meaning of Article 9 GDPR.
However, depending on the Controller's business activities, Data Subjects may voluntarily provide information that could constitute special-category Personal Data.
Examples may include:
* allergy information;
* medical dietary restrictions;
* health-related appointment information;
* disability-related information;
* religious dietary requirements;
* other sensitive information voluntarily disclosed during a conversation.
The Controller is responsible for determining whether the collection of such information is necessary and lawful.
Baydar Digital shall configure systems, where reasonably possible, according to the principle of data minimisation and shall not intentionally collect special-category Personal Data unless required for the agreed service and instructed by the Controller.
6. Categories of Data Subjects
Personal Data may relate to:
* customers of the Controller;
* prospective customers;
* callers;
* website visitors;
* end-users interacting with AI agents;
* individuals making appointments or reservations;
* employees or representatives of the Controller;
* suppliers or business contacts;
* other persons communicating with the Controller through systems operated by Baydar Digital.
7. Obligations of Baydar Digital as Processor
Baydar Digital shall:
* Process Personal Data only on documented instructions from the Controller;
* comply with applicable GDPR processor obligations;
* ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations;
* implement appropriate technical and organizational measures;
* restrict access to Personal Data to persons who require such access;
* assist the Controller with Data Subject requests where reasonably required;
* assist the Controller with its obligations relating to security, data breaches and data protection impact assessments where applicable;
* notify the Controller of Personal Data Breaches without undue delay after becoming aware of them;
* provide information reasonably necessary to demonstrate compliance with this DPA;
* delete or return Personal Data after termination of the services in accordance with Section 18;
* inform the Controller if, in Baydar Digital's reasonable opinion, an instruction infringes applicable data protection legislation.
8. Obligations of the Controller
The Controller shall:
* ensure that Personal Data is collected and Processed lawfully;
* determine and document the appropriate lawful basis for Processing;
* provide Baydar Digital with lawful and documented Processing instructions;
* ensure that Data Subjects receive appropriate privacy information;
* determine whether additional consent or notification is required for telephone recording or AI-based interactions;
* ensure that only Personal Data necessary for the intended purpose is collected;
* determine appropriate retention periods;
* ensure that the use of AI systems is appropriate for the Controller's business activities;
* ensure the accuracy and legitimacy of Personal Data supplied to Baydar Digital;
* promptly inform Baydar Digital of instructions concerning deletion, restriction or correction of Personal Data.
The Controller remains responsible for determining the purposes and essential means of the Processing.
9. AI Voice Agents and Retell AI
9.1 Use of Retell AI
Where AI voice services are included in the services, Baydar Digital may use Retell AI, Inc. ("Retell AI") as a Sub-processor and technology provider.
Retell AI may provide infrastructure required to:
* receive and make telephone calls;
* process voice communications;
* convert speech to text;
* generate AI-powered responses;
* convert text into speech;
* route telephone communications;
* execute functions and integrations;
* create conversation transcripts;
* process call metadata;
* store call-related information where storage is enabled;
* facilitate integrations with external systems.
9.2 Data Processed Through Retell AI
Depending on the configuration, information Processed through Retell AI may include:
* telephone numbers;
* names;
* e-mail addresses;
* voice/audio data;
* transcripts;
* call start and end times;
* call duration;
* call identifiers and metadata;
* appointment or reservation details;
* questions and information provided during calls;
* AI agent responses;
* information transmitted to authorized integrations.
The exact Personal Data Processed depends on the configuration of the AI Agent and the information voluntarily provided by the Data Subject.
9.3 Retell AI Security and Compliance
Baydar Digital shall take reasonable steps to ensure that Retell AI provides appropriate contractual, technical and organizational safeguards applicable to its role as a Sub-processor.
Where required, Baydar Digital shall maintain an appropriate data processing agreement with Retell AI.
Baydar Digital may use security and privacy functionality made available by Retell AI, where appropriate for the relevant service, including:
* access controls;
* authentication;
* data encryption;
* configurable data-retention controls;
* Personal Identifiable Information (PII) redaction;
* role-based access controls;
* logging and monitoring;
* other available enterprise security controls.
The availability and configuration of individual security features may depend on the Retell AI service plan and configuration used.
9.4 Voice Recording
Call recording shall not be enabled solely because it is technically available.
Where voice recordings are stored, the Controller shall determine that there is a lawful purpose and legal basis for such storage.
Where required by applicable law, callers shall receive appropriate information regarding the recording and Processing of their calls.
Baydar Digital may, on instruction from the Controller and where technically supported:
* disable recording;
* limit storage;
* configure retention;
* enable PII redaction;
* delete recordings;
* restrict access to recordings.
9.5 Transcripts
AI conversations may produce transcripts for purposes including:
* execution of the requested service;
* appointment or reservation processing;
* workflow automation;
* troubleshooting;
* quality assurance;
* service monitoring.
Transcript retention shall be limited according to the agreed service requirements and configured retention policy.
10. Data Minimisation
Baydar Digital shall apply the principle of data minimisation.
AI Agents shall, where reasonably possible, be configured to request only information necessary to perform their designated task.
Personal Data shall not knowingly be collected solely because the AI Agent is technically capable of collecting it.
The Controller is responsible for identifying the information necessary for its business process.
11. Sub-processors
11.1 General Authorization
The Controller grants Baydar Digital general written authorization to engage Sub-processors where reasonably necessary to deliver the services.
Baydar Digital shall ensure that Sub-processors that Process Personal Data on its behalf are subject to data protection obligations providing an appropriate level of protection.
11.2 Sub-processor Changes
Baydar Digital may add, replace or remove Sub-processors.
Where required under applicable data protection law, the Controller shall be informed of material additions or replacements of Sub-processors before the relevant change takes effect.
The Controller may object to a new Sub-processor on reasonable and documented data-protection grounds.
The Parties shall cooperate in good faith to resolve such objection.
If no reasonable alternative can be provided, Baydar Digital may be entitled to discontinue the affected service subject to the applicable service agreement.
11.3 Current Sub-processors
The Sub-processors and supporting technology providers that may be used are listed in Annex 2.
Not every Sub-processor listed in Annex 2 will necessarily Process data for every Controller. Their use depends on the services, integrations and configuration selected.
12. International Data Transfers
Some Sub-processors used by Baydar Digital may Process or store Personal Data outside the EEA.
Where Personal Data is transferred to a country outside the EEA, Baydar Digital shall ensure that an appropriate transfer mechanism is available where required by GDPR.
Such mechanisms may include:
* an adequacy decision adopted by the European Commission;
* Standard Contractual Clauses adopted by the European Commission;
* another valid transfer mechanism permitted under Chapter V GDPR.
Where Standard Contractual Clauses are required, Baydar Digital shall take reasonable steps to ensure that the appropriate SCC module is implemented between the relevant parties.
Where appropriate, supplementary technical, organizational or contractual measures may be implemented following an assessment of the relevant transfer.
13. Security of Processing
Baydar Digital shall implement appropriate technical and organizational measures taking into account:
* the state of the art;
* implementation costs;
* the nature, scope, context and purposes of Processing;
* the likelihood and severity of risks to Data Subjects.
Measures may include, where appropriate:
* encrypted transmission using TLS/HTTPS;
* encryption at rest where supported by the relevant service provider;
* authentication controls;
* role-based access controls;
* least-privilege access;
* multi-factor authentication where available;
* password and credential protection;
* API-key protection;
* secure storage of credentials;
* separation of customer environments where technically applicable;
* security logging;
* monitoring;
* backups where necessary;
* software updates;
* access revocation procedures;
* incident-response procedures;
* data-retention controls;
* PII redaction or masking where appropriate.
Further measures are set out in Annex 1.
14. Data Subject Rights
Baydar Digital shall, taking into account the nature of the Processing, reasonably assist the Controller in responding to requests concerning:
* access;
* rectification;
* erasure;
* restriction of Processing;
* objection;
* data portability;
* rights relating to automated decision-making where applicable.
Where Baydar Digital receives a Data Subject request relating to Personal Data Processed on behalf of the Controller, Baydar Digital may refer the request to the Controller unless otherwise required by law.
The Controller remains responsible for responding to Data Subjects and determining the validity of such requests.
15. Personal Data Breach
In the event Baydar Digital becomes aware of a Personal Data Breach involving Personal Data Processed under this DPA, Baydar Digital shall notify the Controller without undue delay.
Where reasonably available, the notification shall include:
* the nature of the incident;
* the categories of Personal Data affected;
* the categories of Data Subjects affected;
* approximate numbers where known;
* likely consequences;
* measures taken or proposed to mitigate the incident;
* relevant contact information.
Baydar Digital shall reasonably cooperate with the Controller in investigating and mitigating the incident.
The Controller remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is legally required.
16. Confidentiality
Baydar Digital shall ensure that persons authorized to Process Personal Data:
* receive access only where necessary;
* are subject to confidentiality obligations;
* are informed of relevant data-protection requirements.
Confidentiality obligations shall continue after termination of the person's involvement with the relevant Processing activities.
17. Audits and Compliance Information
Baydar Digital shall make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.
The Controller may request reasonable information concerning:
* security measures;
* Sub-processors;
* Processing activities;
* data-retention practices;
* relevant compliance documentation.
Where a formal audit is reasonably required, the Parties shall agree in advance on its scope, timing and confidentiality arrangements.
Audits shall not unreasonably disrupt Baydar Digital's operations or compromise the confidentiality or security of other customers.
18. Data Retention, Return and Deletion
Personal Data shall not be retained longer than necessary for the purposes for which it is Processed, subject to:
* Controller instructions;
* applicable legal requirements;
* legitimate technical requirements;
* agreed retention schedules.
Upon termination of the services, Baydar Digital shall, at the Controller's choice and where technically feasible:
* return relevant Personal Data; or
* delete relevant Personal Data,
unless applicable law requires continued retention.
Data stored within third-party Sub-processors shall be deleted or allowed to expire in accordance with the applicable configuration, contractual arrangements and retention mechanisms of those providers.
Backup copies may remain temporarily until overwritten according to normal backup cycles, provided such copies remain protected and are not used for another purpose.
19. AI Processing and Model Training
Personal Data submitted through AI Agents may be transmitted to authorized AI, speech-processing or language-model providers where necessary to generate or process responses.
Baydar Digital shall configure such providers, where supported, to prevent customer data from being used for model training or fine-tuning.
Baydar Digital shall not intentionally authorize Personal Data Processed on behalf of the Controller to be used for general AI model training unless:
* the Controller has expressly instructed or authorized such use;
* an appropriate lawful basis exists; and
* applicable transparency and GDPR requirements have been satisfied.
Aggregated or effectively anonymized data that can no longer reasonably identify a Data Subject may be used for legitimate technical or statistical purposes subject to applicable law.
20. Automated Decision-Making
Unless expressly agreed otherwise, Baydar Digital's AI Agents are intended to support communication, automation and administrative processes and are not intended to make decisions producing legal or similarly significant effects solely through automated Processing.
If the Controller intends to use the services for such automated decisions, the Controller shall inform Baydar Digital before implementation so that the Parties can assess applicable requirements under Article 22 GDPR and related legislation.
21. Data Protection Impact Assessments
Where the Controller determines that a Data Protection Impact Assessment ("DPIA") is required under Article 35 GDPR, Baydar Digital shall provide reasonable assistance concerning Processing performed through its services.
The Controller remains responsible for determining whether a DPIA is required and for conducting the DPIA.
22. Duration
This DPA enters into force when the Parties' service agreement becomes effective or when Baydar Digital begins Processing Personal Data on behalf of the Controller, whichever occurs first.
It remains effective for as long as Baydar Digital Processes Personal Data on behalf of the Controller.
Provisions intended by their nature to survive termination, including confidentiality and data deletion obligations, shall continue to apply.
23. Liability
Each Party shall be responsible for its obligations under this DPA and applicable data protection legislation.
Nothing in this DPA shall exclude or limit liability where such exclusion or limitation is prohibited by applicable law.
Any contractual limitations of liability contained in the main service agreement shall apply to this DPA to the extent permitted by applicable law.
24. Order of Precedence
If there is a conflict between this DPA and the main service agreement concerning the Processing or protection of Personal Data, this DPA shall prevail with respect to such Processing.
Mandatory provisions of applicable data protection legislation shall prevail over conflicting contractual provisions.
25. Governing Law
This DPA shall be governed by the laws of the Netherlands.
The competent Dutch courts shall have jurisdiction, subject to any mandatory rights or jurisdiction provided under applicable data protection legislation.
26. Signatures
Controller
Name: ______________________________________
Company: ___________________________________
Position: ____________________________________
Signature: __________________________________
Date: _______________________________________
Processor
Name: ______________________________________
Company: Baydar Digital
Position: ____________________________________
Signature: __________________________________
Date: _______________________________________
-
ANNEX 1 – TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)
Baydar Digital applies technical and organizational measures appropriate to the nature of its services.
These may include:
Access Security
* restricted access to production systems;
* role-based access where available;
* least-privilege access principles;
* individual user accounts where practical;
* strong passwords;
* multi-factor authentication where available;
* periodic removal of unnecessary access.
Network and Transmission Security
* TLS/HTTPS encryption for supported communications;
* secure API connections;
* protected webhook endpoints;
* secure management of API keys and credentials.
Data Protection
* encryption at rest where supported by the applicable provider;
* PII redaction or masking where appropriate;
* data-minimisation controls;
* configurable retention settings;
* deletion procedures;
* separation of customer data where supported.
AI Voice Security
Where Retell AI is used:
* access to Retell AI accounts shall be restricted;
* credentials and API keys shall be protected;
* call recording may be disabled where unnecessary;
* retention settings may be configured according to Controller requirements;
* PII redaction may be enabled where appropriate and technically supported;
* access to recordings and transcripts shall be limited;
* only authorized integrations shall receive call data.
Operational Security
* monitoring of relevant systems;
* logging where available;
* incident-response procedures;
* periodic software and integration updates;
* backup procedures where appropriate;
* access revocation when personnel no longer require access.
Supplier Security
Baydar Digital shall take reasonable steps to select service providers that provide appropriate security safeguards for the type of Processing concerned.
ANNEX 2 – SUB-PROCESSORS AND TECHNOLOGY PROVIDERS
Baydar Digital may use the following providers depending on the services purchased and configured by the Controller.
Retell AI, Inc.
Service:
Voice AI and AI Agent infrastructure.
Purpose:
Processing telephone conversations, speech, AI Agent interactions, transcripts, call metadata and authorized integrations.
Potential data:
Voice/audio, telephone numbers, names, e-mail addresses, transcripts, call metadata, appointment or reservation information and other information provided during calls.
International Processing:
Processing may occur outside the EEA. Appropriate transfer safeguards shall be used where required.
OpenAI
Service:
Artificial intelligence and language-model processing, where used.
Purpose:
Generating or processing AI responses and related functionality.
Potential data:
Relevant conversation content and instructions required for response generation.
Use depends on the AI configuration selected for the relevant service.
n8n
Service:
Workflow automation.
Purpose:
Transferring data between authorized applications and executing automated workflows.
Potential data:
Contact information, appointment or reservation information, workflow data and other information required by the configured automation.
Make
Service:
Workflow automation and integration platform.
Purpose:
Executing integrations between connected services.
Potential data:
Personal Data necessary to execute the configured workflow.
Replit
Service:
Development and hosting environment, where used.
Purpose:
Hosting or operating custom applications, APIs or integration components.
Potential data:
Depends on the relevant application and configuration.
-
Calendar and Scheduling Providers
Examples may include Cal.com, Calendly, Google Calendar, Microsoft Outlook or another scheduling service selected by the Controller.
Purpose:
Creating and managing appointments and reservations.
Potential data:
Name, e-mail address, telephone number, date, time, appointment details and notes.
Communication Providers
Providers may be used for:
* telephone routing;
* SMS;
* e-mail;
* WhatsApp or other messaging services.
The specific provider depends on the Controller's configuration.
Hosting and Infrastructure Providers
Cloud infrastructure may be provided directly or indirectly through providers used by Baydar Digital or its Sub-processors.
The applicable provider depends on the deployed architecture.
Baydar Digital shall maintain or make available an up-to-date Sub-processor list upon reasonable request.
ANNEX 3 – AI-SPECIFIC PROCESSING DISCLOSURE
AI-Driven Services
Baydar Digital provides AI-powered services that may include:
* voice conversations;
* AI telephone receptionists;
* AI chatbots;
* appointment booking;
* reservation management;
* lead qualification;
* customer support;
* workflow automation;
* automated routing and escalation.
Data Flow
Depending on the implementation, Personal Data may flow between:
Data Subject → Controller → Baydar Digital → Retell AI / AI provider → authorized automation platform → Controller's CRM, calendar or other business system.
Only providers necessary for the relevant implementation should receive Personal Data.
Voice Processing
Voice conversations may require real-time transmission of audio to voice-processing providers.
Audio may be:
* processed in real time;
* converted into text;
* analyzed for conversation context;
* converted into AI responses;
* transmitted to other authorized systems where necessary.
Storage of audio is separate from real-time Processing and should be limited according to the Controller's requirements.
Conversation Logging
Depending on system configuration, conversations may generate:
* call logs;
* transcripts;
* recordings;
* technical logs;
* AI outputs;
* workflow execution records.
Logging shall be limited to what is reasonably necessary for service delivery, troubleshooting, security and agreed quality-control purposes.
Model Training
Baydar Digital shall not intentionally use Controller Personal Data to train general-purpose AI models.
Where third-party AI providers are used, Baydar Digital shall use available enterprise/API configurations designed to prevent customer data from being used for general model training wherever reasonably available.
Human Access
Human access to recordings, transcripts or other conversation information shall be limited to authorized persons where necessary for:
* support;
* troubleshooting;
* configuration;
* security;
* quality control;
* Controller-requested services.
Data Retention
Retention periods should be determined according to the service and Controller requirements.
Where technically possible, Baydar Digital shall configure data-retention settings according to those agreed requirements.
Personal Data shall not be retained indefinitely solely because the underlying platform permits indefinite storage.
Controller Responsibility
The Controller remains responsible for:
* determining the lawful basis;
* providing required privacy information;
* determining which information the AI Agent may request;
* deciding whether conversations may be recorded;
* defining appropriate retention periods;
* ensuring that AI processing is appropriate for its business.
Processor Responsibility
Baydar Digital is responsible for:
* following documented Controller instructions;
* implementing the agreed AI Agent configuration;
* maintaining reasonable security safeguards;
* managing its Sub-processors in accordance with this DPA;
* assisting the Controller with applicable GDPR obligations.
ANNEX 4 – PROCESSING INSTRUCTIONS
Unless otherwise documented by the Parties, the Controller instructs Baydar Digital to Process Personal Data solely to:
1. provide the contracted AI and automation services;
2. operate and maintain the relevant integrations;
3. perform customer-requested workflows;
4. provide technical support;
5. maintain security and service reliability;
6. comply with applicable law.
Any materially different Processing purpose requires additional documented instructions from the Controller.