SquawkVoice
Data Processing Addendum
This Data Processing Addendum (“Addendum”) forms part of the agreement under which SquawkVoice provides the Service to the customer, whether the SquawkVoice Terms of Service or an Order Form under the SquawkVoice Reseller Terms (the “Agreement”), between SquawkVoice.ai, Inc. (“SquawkVoice”) and the customer identified in the Agreement (“Customer”). By using the SquawkVoice services, Customer agrees that this Addendum governs the processing of personal data subject to the EU General Data Protection Regulation (“GDPR”), the UK GDPR (as defined in the UK Data Protection Act 2018), and equivalent data-protection laws.
1. Roles and Scope
Customer acts as data controller or, where it processes personal data on behalf of its own customers, as data processor; SquawkVoice acts as data processor or sub-processor, as applicable. This Addendum applies to the processing of personal data that SquawkVoice performs on behalf of Customer when providing the Service. All capitalized terms not defined here have the meanings given in the Agreement, the GDPR, or the UK GDPR, as applicable.
2. Nature and Purpose of Processing
Purpose: to deliver AI-powered voice and messaging services, including call answering, transcription, routing, and analytics.
Types of Data: caller phone numbers, audio recordings, transcripts, metadata, and user account data.
Data Subjects: Customer’s employees, end-customers, and callers.
Duration: for the term of the Agreement plus any legally required retention period.
3. Processor Obligations
SquawkVoice shall process personal data only on documented instructions from Customer, ensure authorized personnel are bound by confidentiality (including, where applicable, telecommunications secrecy obligations equivalent to Fernmeldegeheimnis under German law), implement appropriate technical and organizational measures, and assist Customer with data subject rights requests. If SquawkVoice believes an instruction from Customer infringes the GDPR, UK GDPR, or other applicable data protection law, it will immediately inform Customer, as required by Article 28(3)(a) GDPR (and the equivalent provision of the UK GDPR).
SquawkVoice shall not use Customer personal data, including voice recordings or transcripts, to train or fine-tune any public or third-party AI/ML models without Customer’s explicit prior written consent.
In the event of a personal data breach, SquawkVoice will notify Customer without undue delay and in any event within 48 hours of becoming aware of the breach, including (to the extent known) the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it.
Upon termination of the Agreement, SquawkVoice will delete or return all Customer personal data within 30 days, unless retention is required by law.
4. Customer Obligations
Customer shall provide personal data only where it has a lawful basis, issue lawful processing instructions, and comply with all relevant data-protection laws.
5. Subprocessors
Customer authorizes SquawkVoice to engage the subprocessors listed at https://squawkvoice.ai/subprocessor-list/ (the “Subprocessor List”). SquawkVoice will update the Subprocessor List and notify Customer by email at least five (5) business days before authorizing any new subprocessor to process Customer personal data. Customer may object to the new subprocessor during that period on reasonable, documented data-protection grounds. If Customer does not object within that period, the new subprocessor is deemed authorized. Customer may provide written authorization at any time before the end of the notice period, in which case SquawkVoice may engage the new subprocessor immediately.
If Customer timely objects, the Parties will work in good faith to address the objection. If SquawkVoice cannot reasonably provide the applicable Service without the objected-to subprocessor, Customer may terminate only the affected Service. SquawkVoice ensures subprocessors are bound by obligations no less protective than those in this Addendum.
6. International Transfers
Customer personal data may be processed in the United States, European Union, and other jurisdictions identified in SquawkVoice’s Subprocessor List. SquawkVoice’s primary cloud infrastructure is provided by Google Cloud Platform.
Transfers of personal data from the EEA to the United States are governed by the EU Standard Contractual Clauses (Module Two: Controller to Processor, where Customer acts as controller; Module Three: Processor to Processor, where Customer acts as processor), incorporated by reference and completed as set out in Schedule 1, and by the EU–U.S. Data Privacy Framework where applicable.
Transfers of personal data from the United Kingdom to the United States are governed by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office under Section 119A of the Data Protection Act 2018 (the “UK Addendum”), incorporated by reference and completed as set out in Schedule 2. The UK Addendum applies the EU SCCs referenced above (Module Two or Module Three, as applicable), as completed in Schedule 1, to processing subject to the UK GDPR, subject to the modifications set out in the UK Addendum itself.
7. Audit and Compliance
Upon written request, SquawkVoice will provide documentation demonstrating compliance, including its SOC 2 Type II report covering Security, Availability, and Confidentiality, and its GDPR attestation report.
Customer may conduct one audit per calendar year, limited to documentation review, upon at least 30 days’ prior written notice, conducted during normal business hours, and at Customer’s expense. If such documentation review, including SquawkVoice’s SOC 2 report, fails to reasonably demonstrate compliance, or following a confirmed security incident, Customer may conduct a reasonable on-site inspection upon reasonable advance written notice. Following a confirmed security incident, or if any review identifies material non-compliance with this Addendum, SquawkVoice will bear the cost of that further audit or inspection.
8. Security Measures
SquawkVoice maintains the technical and organizational security measures described in Annex II of Schedule 1, consistent with its SOC 2 Type II report.
9. Liability
Each party’s liability under this Addendum is subject to the limitations set forth in the Agreement.
10. Governing Law
This Addendum is governed by the laws of Delaware, with disputes resolved through arbitration in Wilmington, Delaware. Notwithstanding the foregoing: (a) the Standard Contractual Clauses incorporated in Schedule 1 are governed by the law of Ireland, as required under Clause 17 of the SCCs, and the parties submit to the jurisdiction of the courts of Ireland for disputes arising under the SCCs specifically, as provided in Clause 18; and (b) the UK Addendum incorporated in Schedule 2 is governed by the laws of England and Wales, and the parties submit to the jurisdiction of the courts of England and Wales for disputes arising under the UK Addendum specifically.
Schedule 1 — Standard Contractual Clauses
The parties incorporate by reference the EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries, Module Two (Controller to Processor) and Module Three (Processor to Processor), as applicable under Section 6. Data exporter: Customer. Data importer: SquawkVoice.ai, Inc.
SCC Optional Clause Selections
- Clause 7 (Docking Clause): applies.
- Clause 9 (Use of Subprocessors): Option 2 (General Written Authorization) applies, with a notice period of five (5) business days as described in Section 5 of this Addendum.
- Clause 11 (Redress): the optional language allowing data subjects to lodge a complaint with an independent dispute resolution body does not apply.
- Clause 17 (Governing Law): the law of Ireland applies.
- Clause 18 (Choice of Forum and Jurisdiction): disputes shall be resolved before the courts of Ireland.
Annex I — Description of Transfer
- Data exporter: Customer, as identified in the Agreement (controller or processor, as applicable).
- Data importer: SquawkVoice.ai, Inc., 20660 Stevens Creek Blvd #248, Cupertino, CA 95014 (processor or sub-processor, as applicable).
- Data subjects: Customer’s employees, end-customers, and callers interacting with the Service.
- Categories of data: caller phone numbers, call audio recordings, transcripts, interaction metadata, user account data, and other personal data submitted or made available by Customer through the Service. Special categories of personal data may be processed where Customer submits or configures the Service to process such data, subject to Customer’s lawful instructions and applicable law.
- Frequency of transfer: continuous, for the duration of the Agreement.
- Nature and purpose: provision of AI-powered voice and messaging services, including call answering, transcription, routing, and analytics.
- Duration of processing: for the term of the Agreement plus any legally required retention period.
- Competent supervisory authority: the supervisory authority of Customer’s EU member state of establishment.
Annex II — Technical and Organizational Security Measures
SquawkVoice maintains the following measures, as further described in its SOC 2 Type II report:
- Encryption of data in transit and at rest.
- Role-based access control and multi-factor authentication for access to sensitive systems.
- Continuous infrastructure logging and monitoring, with automated alerting on anomalous activity.
- Annual independent penetration testing and ongoing vulnerability management.
- Formal incident management, business continuity, and disaster recovery processes, tested annually.
- Background checks, confidentiality obligations, and annual security awareness training for personnel.
- Documented vendor risk management for subprocessors, reviewed at least annually.
Annex III — List of Subprocessors
The current list of subprocessors, including each subprocessor’s identity, purpose, and location of processing, is maintained at https://squawkvoice.ai/subprocessor-list/ and is incorporated into this Annex by reference. Changes are subject to the notice and objection process in Section 5.
Schedule 2 — UK International Data Transfer Addendum
The parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office and laid before the UK Parliament in accordance with Section 119A of the Data Protection Act 2018 (Version B1.0, in force 21 March 2022) (the “UK Addendum”), completed as follows.
Table 1: Parties
- Exporter: Customer, as identified in the Agreement (controller or processor, as applicable).
- Importer: SquawkVoice.ai, Inc., 20660 Stevens Creek Blvd #248, Cupertino, CA 95014 (processor or sub-processor, as applicable).
Table 2: Selected SCCs, Modules, and Selected Clauses
The UK Addendum applies to the EU SCCs (Module Two or Module Three, as applicable) as incorporated and completed in Schedule 1 of this Addendum, including the optional clause selections listed there.
Table 3: Appendix Information
As set out in Annex I (Description of Transfer), Annex II (Technical and Organizational Security Measures), and Annex III (List of Subprocessors) of Schedule 1, which apply equally to transfers under this UK Addendum.
Table 4: Ending the UK Addendum when the Approved Addendum Changes
Neither party may terminate the UK Addendum under Section 19 of the Mandatory Clauses without the written agreement of the other party.
The parties agree that the Mandatory Clauses of the UK Addendum, as issued by the ICO and in force from time to time, are incorporated into and form part of this Schedule 2.
Contact
Contact for privacy matters: privacy@squawkvoice.ai
Entity: SquawkVoice.ai, Inc. | 20660 Stevens Creek Blvd #248, Cupertino, CA 95014 | EIN 99-1952184

