Data Processing Agreement

Effective Date: April 5, 2026 Last Updated: July 29, 2026 Version: 2.3


1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller", "Data Controller") and TrentApps LLC, a Missouri limited liability company doing business as hiroi, of 117 S Lexington St, Ste 100, Harrisonville, MO 64701, United States ("hiroi", "Processor", "Data Processor"), for the hiroi omni-channel AI agent platform ("Service").

This DPA takes effect on your acceptance of the Terms of Service and requires no separate signature. If your organization requires a countersigned copy, contact privacy@hiroi.ai.

This DPA applies where hiroi processes personal data on your behalf when providing the Service, including:

  • Contact records you upload or create
  • Conversation data from AI phone calls, SMS messages, email campaigns, and chat interactions
  • Call transcripts
  • Opt-out and consent records

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion)
  • Data Subject: An identified or identifiable natural person whose personal data is processed
  • Sub-Processor: A third party engaged by hiroi to process personal data on behalf of the Controller
  • Communication Data: Call transcripts, SMS content, and email content generated through the Service

3. Scope and Roles

3.1 Controller

You (the registered user) are the Data Controller for:

  • Contact records and lists you import or create
  • Communication data generated by your AI agents (calls, SMS, email)
  • Call transcripts involving your contacts
  • Opt-out and consent records for your contacts
  • End-user conversation data from AI agent chat widgets deployed on your websites

3.2 Processor

hiroi is the Data Processor and will:

  • Process personal data only on your documented instructions
  • Not process personal data for any purpose other than providing the Service
  • Not sell, share, or use personal data for its own commercial purposes
  • Act in accordance with this DPA and applicable data protection law

4. Processing Details

4.1 Subject Matter

Processing of contact data, communication data, and metadata generated through AI-powered calling, SMS, email, and chat features.

4.2 Duration

Processing continues for the duration of the Service agreement and for the retention periods specified in our Privacy Policy.

4.3 Nature and Purpose

Processing Activity Purpose
Contact data storage Store and manage contact records for campaigns and AI agent context
Outbound call initiation Deliver AI phone calls to contacts on your behalf
Inbound call handling Receive and route calls to AI agents
Call transcription Provide call records, transcripts, and AI summaries
SMS sending and receiving Deliver messages and receive replies on your behalf
Email campaign delivery Send outbound email campaigns and receive replies
AI response generation Process conversations through AI providers for response generation
Voice synthesis Convert AI text responses to speech for phone calls
Opt-out processing Record and enforce contact opt-outs across channels
Campaign analytics Provide performance metrics and conversation insights
Microsoft 365 integration Access calendar and email to send messages and manage appointments on your behalf

4.4 Categories of Data Subjects

  • Your business contacts (individuals you contact via calls, SMS, or email)
  • Website visitors who interact with your deployed AI agent chat widgets
  • Any individuals whose data is included in conversations

4.5 Types of Personal Data

  • Contact names, phone numbers, and email addresses
  • Call transcripts (text)
  • SMS message content (sent and received)
  • Email content (sent and received)
  • IP addresses (for chat widget interactions)
  • Browser user agent strings
  • Visitor identifiers (pseudonymous)
  • Consent and opt-out records
  • Interaction history and campaign engagement data

5. Obligations of the Processor

hiroi shall:

5.1 Processing Instructions

  • Process personal data only in accordance with the Controller's documented instructions
  • Inform the Controller if an instruction infringes applicable data protection law before proceeding

5.2 Confidentiality

  • Ensure that persons authorized to process personal data are bound by confidentiality obligations
  • Limit access to personal data to personnel who need it to provide the Service

5.3 Security

Implement appropriate technical and organizational measures, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
  • Storage of call transcripts under the same encryption at rest as all other application data
  • Access controls and organization-level data isolation
  • Automated dependency vulnerability scanning and prompt patching
  • Incident detection and response capabilities

See our Security Policy for detailed measures and Annex II to this DPA for the itemised technical and organisational measures.

5.4 Sub-Processing

  • Not engage a new sub-processor without prior notification to the Controller (at least 30 days)
  • Maintain an up-to-date list of sub-processors at Subprocessors
  • Ensure sub-processors are bound by equivalent data protection obligations
  • Remain liable for sub-processor compliance

5.5 Data Subject Rights

  • Assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection)
  • Provide necessary technical capabilities for data export and deletion
  • Redirect data subject requests received directly by hiroi to the Controller
  • Process opt-out requests (STOP, UNSUBSCRIBE, do-not-call) automatically and notify the Controller

5.6 Breach Notification

In the event of a personal data breach:

  • Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach
  • Provide information about the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
  • Cooperate with the Controller's breach response and regulatory notification obligations
  • Document all breaches in the internal breach register

6. Obligations of the Controller

You shall:

  • Provide lawful processing instructions
  • Ensure a legal basis exists for processing and contacting each data subject (e.g., consent, legitimate interest)
  • Obtain and maintain records of TCPA consent before initiating automated calls or SMS
  • Maintain appropriate privacy notices for contacts and website visitors
  • Respond to data subject requests directed to you as Controller
  • Notify hiroi of any changes to processing instructions
  • Scrub contact lists against the National DNC Registry where required
  • Ensure campaign content complies with CAN-SPAM, CASL, and other applicable laws

7. Sub-Processors

7.1 Current Sub-Processors

See Subprocessors for the current list.

7.2 Changes to Sub-Processors

  • We will notify you at least 30 days before engaging a new sub-processor
  • Notification will be via email and/or through the Service
  • You may object to a new sub-processor within 14 days of notification
  • If you object, we will make reasonable efforts to provide an alternative. If no alternative is available within 30 days of your objection, either party may terminate the affected processing activities with 30 days' written notice. During the resolution period, we will not share your data with the objected-to sub-processor.

8. International Data Transfers

Where personal data is transferred outside the European Economic Area or United Kingdom:

  • Transfers are subject to appropriate safeguards (Standard Contractual Clauses, adequacy decisions, or other approved mechanisms)
  • We assess the data protection laws of recipient countries
  • We implement supplementary measures (encryption in transit and at rest) where necessary

The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: Controller to Processor) are incorporated into this DPA by reference for transfers from the EEA to hiroi, and are completed as follows:

  • Clause 7 (docking clause): does not apply
  • Clause 9 (sub-processors): Option 2, general written authorisation, with the 30-day notice period in Section 7 of this DPA
  • Clause 11 (redress): the optional independent dispute resolution language does not apply
  • Clause 17 (governing law): the law of Ireland
  • Clause 18(b) (forum): the courts of Ireland
  • Annex I and Annex II: as set out in the Annexes to this DPA below

For transfers from the United Kingdom, the UK International Data Transfer Addendum (Version B1.0) to the EU SCCs applies, with Tables 1–4 completed by reference to the Annexes below and "Importer" selected in Table 4. For transfers from Switzerland, the EU SCCs apply with the amendments identified by the Swiss Federal Data Protection and Information Commissioner, and references to the GDPR are read as references to the Swiss FADP.

Where an adequacy decision or certification (including the EU-US Data Privacy Framework, where a recipient participates) covers a transfer, that mechanism may be relied on instead.

8A. California and Other U.S. State Privacy Laws

Where the Controller is a "business" and hiroi processes "personal information" as defined by the California Consumer Privacy Act as amended by the CPRA, hiroi acts as a service provider, and:

  • hiroi processes personal information only to perform the Service under the Terms of Service, and for no other business or commercial purpose
  • hiroi does not sell and does not share personal information, as those terms are defined by the CCPA/CPRA, and does not retain, use, or disclose it outside the direct business relationship with the Controller
  • hiroi will not combine personal information received from the Controller with personal information received from another source, except as permitted for a service provider
  • hiroi will notify the Controller if it determines it can no longer meet its obligations under the CCPA/CPRA
  • The Controller may take reasonable and appropriate steps to stop and remediate unauthorised use of personal information
  • hiroi will pass these obligations to its sub-processors

Equivalent terms apply where the Controller is a "controller" and hiroi a "processor" under comparable U.S. state privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana).

9. Audit Rights

9.1 Audit

The Controller may:

  • Request information necessary to demonstrate compliance with this DPA
  • Conduct or commission audits with reasonable advance notice (at least 30 days), no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, during business hours, without unreasonably disrupting the Service, and at the Controller's expense
  • Request the documentation described in Section 9.2

9.2 Cooperation

hiroi shall:

  • Make available information reasonably necessary to demonstrate compliance
  • Allow and contribute to audits conducted by the Controller or an authorized auditor, subject to Section 9.1
  • Provide our current Security Policy, our sub-processor list, and completed responses to a reasonable security questionnaire on request

hiroi does not hold a SOC 2 report, and none can be provided. Our controls are designed to align with the SOC 2 Trust Service Criteria, but hiroi has not completed an independent audit — see Section 11.1 of our Security Policy. Third-party audit reports covering our infrastructure providers are available directly from those providers. If we complete an audit, we will make the report available under NDA and update this Section.

10. Data Return and Deletion

10.1 During the Agreement

You may request data export at any time through the Service (account settings > Export Data) or by contacting us.

10.2 Upon Termination

Upon termination of the Service agreement:

  • We will make your data available for export for 30 days
  • After the 30-day period, all personal data will be permanently deleted
  • Call transcripts will be deleted from storage within the same 30-day period
  • We will certify deletion upon written request
  • Data in backup systems will be deleted within the backup rotation cycle (typically 30 days)

10.3 Exceptions

We may retain personal data where required by applicable law (e.g., audit logs for tax purposes), but only to the extent and for the period required.

11. Liability

The liability provisions of the Terms of Service apply to this DPA.

12. Term

This DPA is effective for as long as hiroi processes personal data on behalf of the Controller. It survives termination of the Terms of Service to the extent necessary to govern post-termination data handling and deletion.

13. Contact

For DPA-related inquiries:

TrentApps LLC (d/b/a hiroi) — Data Protection 117 S Lexington St, Ste 100 Harrisonville, MO 64701, United States Email: privacy@hiroi.ai


Annex I — Description of the Transfer

A. List of Parties

Data exporter (Controller): the customer entity that accepted the Terms of Service, identified by the account owner's name, email address, and organization name held in its hiroi account. Contact: the account owner's registered email address. Activities: use of the Service as described in the Terms of Service. Role: Controller.

Data importer (Processor): TrentApps LLC (d/b/a hiroi), 117 S Lexington St, Ste 100, Harrisonville, MO 64701, United States. Contact: privacy@hiroi.ai. Activities: provision of the hiroi omni-channel AI agent platform. Role: Processor.

B. Description of Transfer

  • Categories of data subjects: as set out in Section 4.4 of this DPA
  • Categories of personal data: as set out in Section 4.5 of this DPA
  • Sensitive data: not intentionally processed. Conversation and call transcripts may incidentally contain information a data subject chooses to disclose. Restrictions: access limited to members of the owning organization; retention limits per the Privacy Policy; content safety screening before AI processing
  • Frequency of transfer: continuous, for the duration of the Service agreement
  • Nature of processing: as set out in Section 4.3 of this DPA
  • Purpose of processing: provision of the Service on the Controller's instructions
  • Retention period: as set out in Section 6 of the Privacy Policy
  • Sub-processors: as listed at Subprocessors, for the duration and purposes stated there

C. Competent Supervisory Authority

The supervisory authority of the EEA Member State in which the data exporter is established or, where the exporter is not established in the EEA, the supervisory authority of the Member State in which its Article 27 representative is established or in which the relevant data subjects are located.

Annex II — Technical and Organisational Measures

The measures below are those actually implemented. Full detail is in the Security Policy.

Measure Implementation
Pseudonymisation and encryption TLS 1.2+ in transit (TLS 1.3 preferred); AES-256 at rest via Azure SQL Transparent Data Encryption; OAuth, integration, and TOTP secrets encrypted with Fernet; API keys hashed with PBKDF2-SHA256; IP addresses anonymised after 90 days
Confidentiality Organization-scoped access control enforced at query level; role-based access; least privilege; no shared accounts; confidentiality obligations on anyone with access
Integrity Server-side input validation; parameterised queries; CSRF protection on state-changing operations; authenticated webhooks; SSRF protection on outbound requests; content safety screening
Availability and resilience Azure Container Apps with automated deployment and rollback; automated encrypted database backups with point-in-time recovery; Cloudflare CDN and DDoS protection
Restoring availability Documented recovery procedures; point-in-time database restore; container redeploy from image
Testing and evaluation Automated dependency vulnerability scanning; automated test suite in CI; migration verification on deploy. No third-party penetration test has been commissioned
User identification and authorisation OAuth 2.0 (Google, Apple, Microsoft), passkeys (WebAuthn), TOTP two-factor, magic links; server-side sessions with enforced expiry; brute-force lockout; hashed, scoped API keys
Data minimisation Only data needed to deliver the Service is collected; call audio is not recorded or stored; email content is processed in session rather than stored in full
Data quality Controller-managed contact records with self-service correction and deletion
Retention limitation Automated daily retention jobs; per-account configurable conversation retention; deletion on account closure after a 30-day grace period
Accountability Activity and security event logging; audit trail of administrative actions; delivery logs for outbound integrations
Portability and erasure Self-service machine-readable export (JSON) and account deletion; deletion certified on written request
Sub-processor measures Sub-processors bound by equivalent obligations under their own data processing terms; list maintained at Subprocessors

Cookie Preferences

We use essential cookies to make our service work. You can choose to enable optional cookies for a better experience. Learn more

Cookie Preferences

Essential

Required for the service to function

Always On

Analytics

Help us understand how the service is used