Data Processing Addendum
Last updated: June 4, 2026
Template — pending legal review.
This document is the bhildOs starting template. It will be reviewed by counsel before bhildOs takes its first paying customer. If you're evaluating bhildOs and need a counter-signed version, email legal@bhildos.com.
This Data Processing Addendum (the "DPA") forms part of the agreement between bhild Inc. ("bhildOs", the Processor) and the customer identified in the underlying Terms ("Customer", the Controller). For end-callers and other data subjects whose information passes through the Service, Customer is the Controller; bhildOs processes that data solely on Customer's documented instructions, which are reflected in the configuration choices Customer makes inside the bhildOs application and via these terms.
1. Definitions
Capitalized terms not defined here have the meaning given in the underlying Terms or in applicable data protection law (GDPR, UK GDPR, CCPA/CPRA, and similar).
2. Scope and roles
For end-caller data (phone number, voice recording, transcript, extracted lead fields), team member data, contacts, and appointment records, Customer is the Controller and bhildOs is the Processor. For data we collect about the Customer directly (account credentials, billing, marketing-site analytics), bhildOs is the Controller and our Privacy Policy applies.
3. Processing details
- Subject matter: provision of the AI receptionist + intake CRM Service.
- Duration: the term of the underlying Terms plus any retention period required by law or the configured retention settings.
- Nature and purpose: hosting, transmitting, analyzing, and returning Customer Content; conversational AI processing; lead extraction; CRM and ad-platform sync.
- Categories of data subjects: Customer's employees and contractors; end-callers; Customer's customers and prospects.
- Categories of personal data: contact information, voice recordings and transcripts, IP addresses and device data, OAuth tokens for connected services, appointment and estimate records, attribution identifiers.
4. Processor obligations
bhildOs will:
- Process personal data only on Customer's documented instructions, including with regard to international transfers.
- Implement appropriate technical and organizational measures — see Annex A (Security Measures).
- Ensure persons authorized to process personal data are bound by confidentiality.
- Assist Customer in responding to data subject requests and in meeting Customer's obligations under Articles 32-36 of GDPR (security, breach notification, DPIA, prior consultation).
- Notify Customer without undue delay (target: within 72 hours) after becoming aware of a personal data breach affecting Customer Content.
- On termination, at Customer's choice, delete or return all personal data to Customer (subject to legal retention requirements and backup cycles).
- Make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits — reasonable notice required, no more than once per 12 months absent a breach.
5. Subprocessors
Customer authorizes bhildOs to engage the subprocessors listed at /subprocessors. bhildOs imposes equivalent data protection obligations on each subprocessor and remains liable for their performance. bhildOs will give Customer at least 30 days' advance notice (by updating the subprocessors page and notifying account owners) of any intended addition or replacement of a subprocessor. Customer may object; if the parties cannot resolve the objection in good faith, Customer may terminate the affected Service.
6. International transfers
bhildOs is based in the United States. For transfers of personal data from the EEA, UK, or Switzerland to the US, the parties rely on the EU Standard Contractual Clauses (Module Two — Controller-to-Processor, June 4 2021 version, with the UK Addendum where applicable). They are deemed incorporated into this DPA and take precedence in case of conflict.
7. Data subject requests
bhildOs provides Customer with the tools necessary to fulfill data subject requests (access, deletion, correction, portability) through the bhildOs application. If bhildOs receives a request from a data subject directly, we will forward it to Customer without acting on it unless legally required to do so.
8. Audits
bhildOs makes available SOC-2-style audit summaries on its Trust Center page (/trust) and will respond to reasonable, non-disruptive customer audit requests under confidentiality. Independent on-site audits are limited to Customer's direct production-data exposure and may be conducted at Customer's expense.
9. CCPA addendum
For California personal information, bhildOs acts as a "Service Provider" as defined in the CCPA/CPRA. bhildOs will not (i) sell or share personal information, (ii) retain, use, or disclose personal information outside the direct business relationship with Customer, or (iii) combine personal information received from Customer with personal information received from other sources, except as permitted by §1798.140(ag) of the CCPA.
10. Annex A — Security measures
bhildOs maintains the following measures (non-exhaustive):
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
- Postgres row-level security forced on every multi-tenant table.
- Webhook signature verification on every external integration.
- Encrypted storage of integration OAuth tokens with per-environment master key.
- Production access restricted to a small set of engineers; MFA required.
- Quarterly access reviews; immediate revocation on offboarding.
- Logging and monitoring with retention; daily off-site backups.
- Documented incident response plan with 72-hour notification target.
11. Liability
Each party's liability under this DPA is subject to the limitations in the underlying Terms.
12. Order of precedence
In case of conflict between this DPA, the SCCs, and the underlying Terms, the order of precedence is: (1) the SCCs, (2) this DPA, (3) the underlying Terms.
13. Counter-signed copy
To request a counter-signed PDF version of this DPA, email legal@bhildos.com.