YOURCALLS — DATA PROCESSING ADDENDUM
Version 1.0 · Effective from 3 September 2026. Superseded versions are available on request from hello@s4w.com.
YOURCALLS — DATA PROCESSING ADDENDUM
Version 1.0
This Data Processing Addendum is published at https://s4w.com/yourcalls/dpa.
Parties
This DPA is entered into between:
(1) S4W L.L.C-FZ, a company registered in the United Arab Emirates with licence number 2529741, whose registered address is Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. (S4W); and
(2) the customer that accepts the Agreement (the User),
each a party and together the parties.
Data protection contact for S4W: hello@s4w.com (marked for the attention of the Data Protection Contact), or by post to the registered address above.
Data protection contact for the User: an Administrator registered in the User's account, or such other contact as the User notifies to S4W in writing.
UK Article 27 representative: S4W has appointed Dial Square Consultancy Ltd, 131 Finsbury Pavement, London, England, EC2A 1NT, as its representative in the United Kingdom for the purposes of Article 27 of the UK GDPR. The representative may be contacted at hello@s4w.com.
Payment collection agent. Dial Square Consultancy Ltd, a company registered in England and Wales with company number 17317079, whose registered address is 131 Finsbury Pavement, London, England, EC2A 1NT, acts as S4W's payment collection agent and merchant of record for the collection of Fees. Dial Square Consultancy Ltd is not a party to this DPA, does not contract with the User, and is not a reseller of the Platform. Personal Data processed in connection with the collection of Fees falls within clause 2.4 (S4W as independent Controller) and is described in the Privacy Notice at https://s4w.com/yourcalls/privacy.
Status of this DPA
This DPA forms part of the Agreement and is incorporated into it. It takes effect on the Commencement Date. No signature is required: the DPA is formed by the User's acceptance of the Agreement in accordance with its terms, and applies from the Commencement Date for so long as S4W Processes Personal Data on the User's behalf.
1. Definitions
1.1 Capitalised terms not otherwise defined in this DPA have the meaning given to them in the Agreement, and all rules of interpretation set out in the Agreement apply to this DPA, unless the context otherwise requires.
1.2 In this DPA:
Affiliate: in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with, that party, where "control" means the ownership of more than 50% of the voting share capital or the ability to direct the management of that entity.
Agreement: the S4W YourCalls Platform Terms and Conditions published at https://s4w.com/yourcalls/terms, as accepted by the User, together with the documents incorporated into them (including this DPA).
Anonymised and Aggregated Data or AAD: data derived from User Inputs which has been irreversibly anonymised and aggregated in accordance with clause 2.5.
Appropriate Safeguards: such legally enforceable mechanism(s) for transfers of Personal Data as may be permitted under the Data Protection Law from time to time, including the UK Addendum along with the EU SCC (as applicable), or any other mechanisms as set out in Article 46 of the EU GDPR and the UK GDPR (as applicable).
Business Purposes: the products and services to be provided by S4W to the User as described in the Agreement, comprising the Platform and any other purpose specifically identified in Annex A.
Call Participant: has the meaning given to "Call Participants" in the Agreement.
Commencement Date: has the meaning given to it in clause 1.3 of the Agreement.
Data Processing Particulars: the particulars set out in Annex A, which describe the Processing of Personal Data carried out in connection with the Agreement.
Data Protection Law: (i) to the extent the UK GDPR applies, the law of the United Kingdom or of a part of the United Kingdom which relates to the protection of Personal Data; (ii) to the extent the EU GDPR applies, the law of the European Union or any member state of the European Union to which S4W or the User is subject, which relates to the protection of Personal Data; and (iii) any other applicable national, provincial, federal, state and local legislation, and any associated regulations and secondary legislation, as amended or updated from time to time.
Data Subject Rights Requests or DSRR: a request, complaint or other communication from a Data Subject (or their authorised representative) to exercise any of their rights under Data Protection Law in relation to Personal Data processed under this DPA, including rights of access, rectification, erasure, restriction, data portability, objection and rights relating to automated decision-making.
EU GDPR: the General Data Protection Regulation 2016/679.
EU Standard Contractual Clauses or EU SCC: the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of Personal Data to third countries not otherwise recognised as offering an adequate level of protection for Personal Data by the European Commission (as amended and updated from time to time).
Personnel: in relation to a party, its Affiliates, stakeholders, directors, employees, agents, consultants, subcontractors, third-party vendors, or other persons authorised by (i) that party; (ii) its Affiliates; and/or (iii) its subcontractors, in each case engaged in the provision or receipt of the relevant products and services. Sub-processors are governed by clause 5.5 in addition to clause 5.1(d).
Platform: the S4W YourCalls platform as defined in the Agreement, comprising the AI-enabled voice, chat and messaging assistants, workflow automation, integrations, application programming interfaces and related functionality made available to the User.
Privacy Notice: the S4W privacy notice published at https://s4w.com/yourcalls/privacy, as amended from time to time.
Sub-processor: any S4W Affiliate or third-party vendor Processing Personal Data on S4W's behalf in connection with the Agreement, as set out in clause 5.5 and Annex D.
Supervisory Authority: a governmental or government-chartered regulatory body having binding legal authority over a party for matters relating to the Processing of Personal Data.
Third Country: a country or territory that is not part of the United Kingdom or the EEA.
UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) UK DPA 2018, Version B1.0, in force as of 21 March 2022. References in this DPA to the UK Addendum are references to that instrument and not to the ICO's separate standalone International Data Transfer Agreement.
UK DPA 2018: the UK Data Protection Act 2018.
UK GDPR: the EU GDPR as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018, together with the UK DPA 2018.
User Inputs: data submitted to the Platform by or on behalf of the User, whether through a user interface, application programming interface, file upload, lead ingest endpoint, integration or any other means, together with the AI-Generated Outputs as defined in the Agreement (which include call and chat recordings, transcripts, summaries, scores and extracted fields) and the message logs generated by the Platform in connection with the User's account.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: have the meanings given to them in the Data Protection Law.
2. Personal data types and processing purposes
2.1 The parties agree that, in respect of the products and services provided pursuant to the Agreement, S4W will be the Processor of Personal Data contained in or derived from User Inputs, and that the User will be the Controller. S4W acts as Processor, on the customer's instructions, for all call, chat, contact, lead and messaging data submitted to or generated by the Platform.
2.2 The User retains control of the Personal Data and remains responsible for its compliance obligations under the Data Protection Law, including but not limited to providing any required notices and obtaining any required consents from end users such as Call Participants, website visitors who interact with a chat assistant embedded on the User's website and recipients of messages, and for the written processing instructions it gives to S4W, as applicable. S4W shall immediately notify the User if, in S4W's reasonable opinion, the User's instructions in respect of any Processing of Personal Data by S4W are unlawful.
2.3 The Data Processing Particulars in Annex A describe the subject matter, duration, nature and purpose of the Processing, and the Personal Data categories and Data Subject types in respect of which S4W may Process the Personal Data to fulfil the Business Purposes. The Data Processing Particulars take effect on the Commencement Date.
2.4 S4W acts as an independent Controller for: customer account and Authorised User data, billing and payment data, support communications, website and product analytics, and marketing data. S4W also acts as an independent Controller where it reviews records for the purpose of investigating suspected fraud, abuse or breach of the Agreement by the User. Processing of that Personal Data is governed by the Privacy Notice and not by this DPA. The Processor-role Processing is described in clause 2.1. Data that has been irreversibly anonymised in accordance with clause 2.5 is not Personal Data and falls outside this allocation of roles.
2.5 The User instructs S4W to transform User Inputs into Anonymised and Aggregated Data. Anonymisation under this clause 2.5 must be irreversible: direct and indirect identifiers must be removed or masked, and the resulting data must be aggregated with data derived from other users of the Platform such that no individual can be identified from that data, taking account of all means reasonably likely to be used by S4W or any other person. S4W shall not attempt, and shall not permit any Sub-processor to attempt, to re-identify any individual from AAD. Once User Inputs have been irreversibly converted into AAD in accordance with this clause 2.5, that AAD is no longer Personal Data and S4W may use it for its own legitimate business purposes, including improving and developing the Platform and related services. This clause 2.5 operates as a documented instruction from the User for the purposes of clause 5.1(a).
2.6 Where the User configures the Platform to transmit data to an endpoint, integration or third-party system nominated by the User (including webhooks, workflow HTTP steps, customer relationship management systems and other business applications), those transmissions are made on the User's instruction. The recipients of those transmissions are not S4W Sub-processors, and the User is solely responsible (as between the parties) for the lawfulness of those transfers, for any onward transfer safeguards required under the Data Protection Law, and for the acts and omissions of those recipients. S4W applies server-side request forgery protections to customer-nominated outbound endpoints as described in Annex B, but does not verify the identity, security or compliance posture of the recipient.
2.7 Nothing in this DPA relieves S4W of the obligations that apply to it directly as a Processor under the Data Protection Law.
2.8 Where the User uses the Platform on behalf of a third party whose business is being represented (a Permitted Client, as contemplated by limb (2) of the definition of "Purpose" in the Agreement), and the User acts as a processor for that Permitted Client, the User enters into this DPA both on its own behalf and as agent for and on behalf of that Permitted Client as Controller. The User warrants that it has that Permitted Client's authority to do so. The obligations owed by S4W to the User under this DPA are owed to that Permitted Client mutatis mutandis, and the rights exercisable by the User under this DPA (including under clauses 5.2, 5.4 and 5.6) are exercisable in respect of that Permitted Client's Personal Data by the User alone. Nothing in this clause 2.8 increases S4W's obligations or liability under this DPA, and S4W is entitled to deal exclusively with the User in respect of all matters arising under it.
3. User obligations
3.1 The User warrants and represents that it has all necessary and appropriate consents and notices, in any form required by the Data Protection Law, and that the Personal Data has been collected or otherwise obtained in compliance with the Data Protection Law, and may be lawfully Processed, disclosed and transferred as described in or in connection with this DPA.
3.2 The User will ensure and warrants that, where the User uses the products and services or their configuration to initiate or instruct any transfer of Personal Data outside the EEA or the UK, adequate measures will be taken by the User so that the Personal Data is protected to an adequate level and the Data Subjects' rights under the Data Protection Law will not be prejudiced by such a transfer. This is without prejudice to S4W's obligations in respect of Restricted Transfers of Personal Data carried out by S4W (including via its Sub-processors) in connection with this DPA.
3.3 The User will ensure and warrants that it utilises appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from its use of the products and services, including, as appropriate, the measures referred to in the Data Protection Law.
3.4 The User confirms that it has assessed the security measures in place at the time of this DPA, and that it will continue to do so on an ongoing basis to ensure compliance with its obligations under this DPA. Nothing in this clause 3.4 or clause 3.3 relieves S4W of, or transfers to the User, S4W's own obligations under clause 5.1(c), Annex B and Article 32 of the UK GDPR (and, where applicable, Article 32 of the EU GDPR).
3.5 The User undertakes and confirms that any information required to be provided to a Data Subject has been so provided, or that an applicable exemption is available and is being relied upon by the User.
3.6 The User will immediately notify S4W if any necessary appropriate consents and notices required to enable lawful transfer of Personal Data to S4W for the duration and purposes of this DPA have been breached, terminated, withdrawn, or are otherwise no longer valid.
3.7 The Platform is not designed for, and the User shall not submit, special category Personal Data (within the meaning of Article 9 UK GDPR) or Personal Data relating to criminal convictions and offences (within the meaning of Article 10 UK GDPR). Where the User submits Personal Data through file upload, application programming interface, lead ingest endpoint or any other means, S4W does not inspect, validate or control the categories of data submitted, and the User warrants that those submissions do not include special category or criminal offence data unless expressly agreed in writing between the parties. The User acknowledges that fields it submits may be transmitted to the artificial intelligence model providers listed in Annex D and to any endpoint the User configures under clause 2.6.
3.8 Where the User embeds a chat assistant on a website operated by or on behalf of the User, the User warrants that it will: (a) obtain any consent required under the Data Protection Law (including the Privacy and Electronic Communications (EC Directive) Regulations 2003) for the storage of, and access to, information on visitors' terminal equipment, including the persistent visitor identifier written by the chat widget to the visitor's browser local storage; and (b) provide visitors with the information required by Articles 13 and 14 UK GDPR at the point of collection.
3.9 The User acknowledges that calls made or received through the Platform are recorded and transcribed by default, that no per-assistant, per-campaign or account-level setting is available to disable recording or transcription, and that any disclosure of recording or of the automated nature of the call must be configured by the User within the assistant or flow it builds. The User is responsible for making those disclosures and for obtaining any consent required. By accepting the Agreement and using the Platform, the User instructs S4W to record and transcribe every call made or received through the Platform, and that instruction is a documented instruction of the User for the purposes of clause 5.1(a). The User shall not use the Platform for any purpose for which its own lawful basis, or its obligations under Article 25 UK GDPR, require the ability to disable recording or transcription.
3.10 The User shall indemnify S4W against all liabilities, costs, expenses, damages and losses (including reasonable legal fees) suffered or incurred by S4W arising out of or in connection with any third-party claim, or any investigation, enforcement action or penalty imposed by a Supervisory Authority or other regulator, arising from: (a) breach of any warranty given by the User in this clause 3; (b) the provenance and lawfulness of contact, lead or other data submitted to the Platform; or (c) the User's failure to give any notice, or obtain any consent, required under the Data Protection Law, including in respect of call recording, automated or AI-generated calling and messaging, and direct marketing communications.
4. Data protection: general obligations
4.1 Each party shall comply with all applicable requirements of the Data Protection Law. This DPA is in addition to, and does not relieve, remove or replace, a party's obligations under the Data Protection Law.
4.2 The User and S4W agree that, to the extent each party processes any Personal Data of the other party's Personnel in connection with entry into the Agreement or the management of their business relationship, that party processes such data as an independent Controller.
5. S4W's obligations
5.1 In addition to the obligations above, to the extent that the UK GDPR and/or the EU GDPR applies, and S4W Processes Personal Data in the course of providing the products and services as a Processor, S4W shall:
(a) process that Personal Data only on the written instructions of the User and as set forth in this DPA and the Agreement, except to the extent S4W is required to process data by applicable law. Where S4W is relying on applicable law as the basis for Processing Personal Data, S4W shall without undue delay notify the User unless applicable law prohibits S4W from so notifying the User;
(b) not access or use, or disclose to any third party, any Personal Data, except, in each case, as necessary to maintain or provide the products and services, or as necessary to comply with applicable law or a valid and binding order of a governmental body (such as a subpoena or court order);
(c) implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and accidental loss, destruction, damage, theft or disclosure, having regard to the harm which might result from any unauthorised or unlawful Processing, accidental loss, destruction, damage or theft of the Personal Data and having regard to the nature of the Personal Data which is to be protected. Such measures are further set out in Annex B;
(d) ensure that all Personnel authorised to Process the Personal Data under the Agreement have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and take reasonable steps to ensure that they understand their obligations when handling Personal Data in accordance with this DPA; and
(e) provide reasonable assistance to the User to meet its obligations to:
(i) respond to DSRR;
(ii) meet its legal obligations in relation to the security of Processing of Personal Data;
(iii) notify Personal Data Breaches to Supervisory Authorities and Data Subjects upon the specific written request of the User in its role as a Controller or otherwise as required under applicable law; and
(iv) undertake data protection impact assessments and prior consultation with applicable Supervisory Authorities in relation to high-risk Processing, as applicable.
5.2 Assistance with Data Subject Rights Requests
5.2.1 The assistance described in clause 5.1(e)(i) is provided by a documented operational process and not by self-service tooling. The Platform does not currently offer the User a facility to locate, export or erase all Personal Data relating to a particular individual, and the User should not rely on the Platform's contact-deletion or record-deletion functions as achieving erasure of associated call, chat, message or workflow records.
5.2.2 Where the User requires assistance with a DSRR, it shall send a written request to hello@s4w.com identifying the individual and the identifiers by which that individual can be located (such as telephone number or email address). S4W shall acknowledge the request within 2 Working Days and shall provide the requested assistance, or a written explanation of why it cannot do so, within 10 Working Days of the request, unless the request is of such volume or complexity that a longer period is reasonably required, in which case S4W shall notify the User of the expected timescale.
5.2.3 Where S4W receives a DSRR directly from a Data Subject in relation to Personal Data Processed on the User's behalf, S4W shall not respond to that request other than to acknowledge it and direct the Data Subject to the User, and shall notify the User of the request without undue delay.
5.3 Personal Data Breach management and notification
5.3.1 S4W shall notify the User of a Personal Data Breach affecting Personal Data Processed under this DPA without undue delay after becoming aware of it, and in any event in sufficient time to allow the User to meet its own obligations under Article 33 UK GDPR (and, where applicable, Article 33 EU GDPR). The notification shall include such information as is then available to S4W as to the source and nature of the breach, the type of data affected and the identity or categories of the affected Data Subjects, and S4W shall supplement that notification in phases as further information becomes known.
5.3.2 S4W is not obligated to report unsuccessful incidents or incidents that result in no unlawful or accidental destruction, loss, alteration, disclosure of, or unauthorised access to Personal Data or any of S4W's equipment or facilities storing Personal Data. Such non-reportable incidents may include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorised access to traffic data that does not result in access beyond headers), or similar incidents, provided in each case that the incident does not result in the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data, including any loss of availability of Personal Data.
5.3.3 S4W's obligation to report or respond to a security incident under this clause 5.3 is not and will not be construed as an acknowledgement by S4W of any fault or liability of S4W with respect to the incident.
5.4 Security programme and audit
5.4.1 S4W maintains an information security programme comprising the technical and organisational measures set out in Annex B, which S4W reviews periodically. S4W does not currently hold ISO 27001 certification, a SOC 2 report or any equivalent third-party attestation, and makes no representation that it does.
5.4.2 S4W shall maintain adequate records of its Processing activities under this DPA and, on the User's written request (no more than once in any 12-month period, unless required more frequently by the Data Protection Law or following a Personal Data Breach affecting the User), S4W shall provide the User with a written description of its technical and organisational measures and shall respond to a reasonable security questionnaire.
5.4.3 Where the User cannot reasonably satisfy itself as to S4W's compliance with this DPA through the materials provided under clause 5.4.2, or where required by the Data Protection Law, the User may, on not less than 30 days' written notice, conduct an audit of S4W's applicable controls, either itself or through an appropriately qualified independent third-party representative bound by obligations of confidentiality. The parties shall mutually agree the details of the audit, including its reasonable start date, scope and duration, and the security and confidentiality controls applicable to it. The audit shall be limited to information relevant to the User and shall not include any data relating to S4W's other customers. Audits shall be conducted during normal business hours, shall not unreasonably interfere with S4W's operations, and shall be at the User's cost save where the audit reveals a material breach by S4W of this DPA.
5.4.4 Any audit, and any information arising from it or from clause 5.4.2, is S4W's confidential information. The User may disclose it to: (a) any Controller on whose behalf the User Processes Personal Data through the Platform; (b) the User's professional advisers; and (c) any Supervisory Authority or other regulator, and otherwise where required by law, in each case (other than where required by law) under equivalent obligations of confidentiality and on a need-to-know basis. Any other disclosure to a third party requires S4W's prior written agreement.
5.5 Sub-processors
5.5.1 The User agrees that S4W may use Sub-processors to fulfil its contractual obligations under this DPA or to provide certain services on its behalf, and consents to the use of Sub-processors as described in this clause 5.5. The User authorises the Sub-processors listed in Annex D (the Sub-processor List). Annex D constitutes Annex III / Appendix 3 to the Standard Contractual Clauses, if and as applicable.
5.5.2 At least 30 calendar days prior to the date on which any new Sub-processor commences Processing Personal Data in relation to this DPA, S4W shall update Annex D and shall notify the User of that update by email sent to an Administrator, in accordance with clause 18.4 of the Agreement. It is the User's responsibility to keep each Administrator's contact details current in its account.
5.5.3 If the User objects to a new Sub-processor, the User must notify S4W in writing within 15 days of S4W's notice of the change, setting out the reasons for its objection (without prejudice to any termination rights the User has under the Agreement). In the absence of such a notice, the User is deemed to have consented to the new Sub-processor's appointment.
5.5.4 Where the User raises a reasonable, documented objection under clause 5.5.3, the parties shall discuss it in good faith for a period of 30 days. Within that period S4W may: (a) propose an alternative Sub-processor; or (b) refrain from using the objected-to Sub-processor in connection with the User's Personal Data; or (c) propose a change to the affected functionality that resolves the objection. If the objection is not resolved within that period, the User may terminate the affected part of the products and services on written notice, and S4W shall refund a pro-rata portion of any Fees prepaid by the User in respect of the terminated functionality for the period after termination.
5.5.5 S4W shall not appoint any Sub-processor to Process the Personal Data on its behalf unless it enters into a written contract with the Sub-processor that contains terms substantially the same as those set out in this DPA, in particular in relation to requiring appropriate technical and organisational data security measures, and S4W shall remain liable to the User for that Sub-processor's performance of its obligations.
5.6 Retention, deletion, return and destruction
5.6.1 During the term of the Agreement, S4W retains Personal Data Processed on the User's behalf for the life of the User's account. The Platform does not currently provide automated retention, expiry or purge functionality, and any retention setting exposed in the Platform's configuration interface should not be relied upon as effecting deletion.
5.6.2 For a period of 30 days following termination or expiry of the Agreement (the return window), the User may request return of the Personal Data in a commonly used machine-readable format. The Platform's self-service export functions cover contact records and call records only; return of other categories of Personal Data (including chat transcripts, call recordings, workflow run data and usage records) is performed by documented manual process on written request to hello@s4w.com.
5.6.3 At the choice of the User, S4W shall delete the Personal Data Processed on behalf of the User. Deletion is performed by documented manual process and shall be completed within 60 days of the User's written request to hello@s4w.com. Where the User makes no request, S4W shall delete the Personal Data within 12 months of termination or expiry of the Agreement. This clause 5.6.3 does not apply to the extent S4W is required to retain the Personal Data to comply with applicable law.
5.6.4 S4W may retain Personal Data in backup systems for a limited period, provided that such Personal Data is protected in accordance with this DPA and is not actively Processed. Personal Data may persist in encrypted backups for up to 7 days after its deletion from the live system, after which those backups are overwritten in the ordinary course. Backups are not used for any Processing purpose.
5.6.5 S4W's deletion obligations under this clause 5.6 extend to Personal Data held by S4W and, on the User's written request, S4W shall use reasonable endeavours to procure the deletion of Personal Data held by the Sub-processors listed in Annex D in accordance with those Sub-processors' own retention practices. S4W does not control, and does not warrant, the retention periods applied by those Sub-processors or by any recipient nominated by the User under clause 2.6.
5.7 Personnel and internal access
5.7.1 A limited group of authorised S4W Personnel may access the User's account and the Personal Data Processed on the User's behalf where necessary to provide, support, administer and secure the products and services, or where required by applicable law.
5.7.2 Where authorised S4W Personnel access the User's account by impersonating an Authorised User, that access is recorded in an audit log. Those audit records are retained for the life of the User's account and, following termination or expiry of the Agreement, in accordance with clause 5.6. S4W does not currently maintain record-level access logging of direct reads of Personal Data, and makes no representation that it does.
5.7.3 All S4W Personnel with access to Personal Data are bound by contractual or statutory obligations of confidentiality that survive the end of their engagement.
6. Restricted transfers
6.1 Where any Processing of the Personal Data would involve a transfer of Personal Data to a recipient located in a Third Country, and would otherwise be in breach of the Data Protection Law (a Restricted Transfer), S4W shall only undertake such Processing if:
6.1.1 the transfer is to a country approved under the applicable Data Protection Law as providing adequate protection; or
6.1.2 there are Appropriate Safeguards in place pursuant to the applicable Data Protection Law, including the UK Addendum (incorporating the EU Standard Contractual Clauses as base clauses) as set out in Annex C; or
6.1.3 one of the derogations for specific situations in the applicable Data Protection Law applies to the transfer.
6.2 Where the Processing of Personal Data would involve a Restricted Transfer to a party to this DPA, the parties shall ensure that the Appropriate Safeguards are in place pursuant to the applicable Data Protection Law, including the UK Addendum (incorporating the EU Standard Contractual Clauses as base clauses) as set out in Annex C to this DPA, the terms of which are incorporated into this DPA.
6.3 Pursuant to clauses 6.1 and 6.2 above, where the UK GDPR applies, and the transfer of Personal Data is from the United Kingdom, either directly or via onward transfer, to any country or recipient outside of the UK not based on adequacy regulations pursuant to section 17A of the UK DPA 2018, Annex C shall apply.
6.4 Any election of governing law or forum made in Annex C, or arising under the Mandatory Clauses of the UK Addendum, applies solely to the transfer mechanism set out in Annex C. It does not vary, displace or otherwise affect the governing law and jurisdiction of the Agreement, which remain the law of England and Wales and the exclusive jurisdiction of the English courts.
6.5 S4W is established in the United Arab Emirates. The User acknowledges that access to Personal Data by S4W Personnel located in the United Arab Emirates constitutes a Restricted Transfer and is made subject to the safeguards set out in Annex C. The location of each Sub-processor is set out in Annex D. Transfers made to recipients nominated by the User under clause 2.6 are the User's responsibility.
7. Liability
7.1 Liability for breach of this DPA shall be subject to the relevant clauses of the Agreement. For the avoidance of doubt, the limitations and exclusions of liability and the cap on liability set out in clause 17 of the Agreement and, in respect of obligations owed by S4W in respect of access at the PAYG Tier, clause 4.9 of the Agreement, apply to all liability arising under or in connection with this DPA and to all claims in respect of the Processing of Personal Data, save to the extent that liability may not lawfully be limited.
7.2 Each party shall indemnify the other against the losses, liabilities, damages, costs and expenses payable to or claimed by a third party (including the reasonable costs of responding to an investigation by a Supervisory Authority) suffered or incurred by that other party as a result of the indemnifying party's breach of the Agreement or of this DPA. That indemnity does not extend to the amount of any fine or penalty imposed on the indemnified party itself by a Supervisory Authority. This clause 7.2 applies equally to both parties and is subject to clause 7.1.
8. Duration, changes and versioning
8.1 This DPA takes effect on the Commencement Date and continues for so long as S4W Processes Personal Data on behalf of the User, and thereafter in respect of clauses 3.10, 5.2, 5.4.4, 5.6, 5.7.3, 6, 7, 8 and 9, which survive termination, for so long as S4W holds any Personal Data Processed on the User's behalf.
8.2 This DPA is versioned. The version number and effective date appear at the head of this document. S4W may amend this DPA in accordance with the change-of-terms provisions of the Agreement, and shall give the User not less than 30 days' notice by email to an Administrator, in accordance with clause 18.4 of the Agreement, of any amendment that materially reduces the protections afforded to Personal Data. Superseded versions are archived and available on request from hello@s4w.com.
8.3 If a change to this DPA is required in order to comply with a change in the Data Protection Law, or with a decision of a Supervisory Authority or court, S4W may make that change on such shorter notice as is required to achieve compliance.
8.4 In the event of a conflict between this DPA and the remainder of the Agreement in relation to the Processing of Personal Data, this DPA prevails.
9. Notices
9.1 Notices under this DPA shall be given: to S4W, by email to hello@s4w.com marked for the attention of the Data Protection Contact, or by post to the registered address in the Parties section above; and to the User, by email to an Administrator, in accordance with clause 18.4 of the Agreement.
ANNEX A — DATA PROCESSING PARTICULARS
This Annex A describes the Processing that S4W performs on behalf of the User in order to provide the Platform, as required by Article 28(3) UK GDPR and equivalent provisions in other Data Protection Law. In accordance with clause 2.1, S4W Processes Personal Data as follows. This Annex A constitutes Annex I.B of the EU Standard Contractual Clauses.
A.1 Subject matter of the Processing
The provision of the Platform, as described in the Agreement.
A.2 Duration of the Processing
From the Commencement Date and for the duration of the term of the Agreement, followed by the retention and deletion periods set out in clause 5.6.
A.3 Nature and purpose of the Processing
S4W Processes Personal Data in order to perform the Business Purposes. The Platform comprises:
(a) Inbound voice — receiving and handling calls to telephone numbers operated by or rented to the User using AI voice assistants, and receiving and handling Web Calls placed to an assistant from a web browser, without use of the public switched telephone network and without a telephone number, in each case including capturing call context and urgency, answering queries from knowledge-base content supplied by the User, routing and transferring calls, and creating records of the call;
(b) Outbound voice — placing calls to individuals whose details the User uploads, imports or submits to the Platform, including speed-to-lead dialling of leads submitted to an ingest endpoint and reactivation campaigns run against contact lists supplied by the User;
(c) Call recording, transcription and analysis — recording and transcribing calls (which occurs on every call and cannot be disabled), generating summaries, extracting structured outcomes, and scoring calls against criteria the User configures;
(d) Chat — operating an AI chat assistant embedded on a website operated by or on behalf of the User, including capturing messages exchanged with website visitors, lead-gate form data and session context, and creating contact records for visitors;
(e) Messaging — sending and receiving SMS messages in connection with the User's account, and metering, recording and billing them;
(f) Workflow automation and integrations — executing workflows the User configures, including transmitting call, chat, contact and lead data to endpoints and third-party systems the User nominates, and reading data from those systems;
(g) In-product AI assistance — providing an AI assistant to the User's own Authorised Users which Processes the User Inputs held in the User's account in order to answer their questions and perform tasks within the account;
(h) Telephone number provisioning — obtaining, configuring and maintaining telephone numbers on the User's behalf, including the submission of business identity information to the telecommunications provider where regulatory verification is required;
(i) Service administration and security — administering the User's account and securing the Platform.
A.4 Processing activities
Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, in each case in order to provide the Business Purposes.
A.5 Categories of Personal Data
Depending on the User's use of the Platform, the Personal Data Processed by S4W (and its Sub-processors) on behalf of the User may include:
Account and configuration data (to the extent Processed on the User's behalf)
(a) account configuration information, including access roles, routing rules, assistant prompts, flow configurations and knowledge-base content, to the extent it contains Personal Data;
Voice channel data
(b) call audio recordings and stereo recordings;
(c) call transcripts, including everything spoken during a call by any participant;
(d) call summaries, extracted fields, structured outcomes, AI-generated scores and analysis;
(e) call metadata, including call time, duration, originating and destination telephone numbers (for a Web Call, no originating or destination telephone number is processed), direction, queue, outcome, disposition and routing information;
(f) any additional Personal Data disclosed in conversation by a Call Participant, including identifiers, personal circumstances, opinions and free-text information;
Chat channel data
(g) chat message bodies exchanged between a website visitor and a chat assistant, and the full chat transcript of a session;
(h) a persistent visitor identifier written to and read from the visitor's browser local storage;
(i) the Origin (web address) of the website on which the chat assistant is embedded;
(j) the visitor's full browser user-agent string;
(k) a salted, truncated hash of the visitor's IP address (which is pseudonymised, not anonymised, data);
(l) lead-gate form data submitted by the visitor (such as name, email address, telephone number and free-text message), and any enrichment data supplied by an endpoint the User nominates;
Messaging channel data
(m) message bodies, sender and recipient telephone numbers, direction, segment counts, delivery status and timestamps;
Contact, lead and campaign data
(n) contact lists uploaded or imported by the User (such as names, telephone numbers, email addresses and postal addresses);
(o) lead records submitted to an ingest endpoint, including arbitrary additional fields determined by the User, which are stored with the contact record, transmitted to the AI model providers listed in Annex D as part of the call context, and republished to any endpoint the User configures;
(p) notes, tags, custom fields and other annotations added by the User in relation to particular calls, contacts, leads or accounts;
(q) campaign membership, attempt history, call outcomes and callback times;
Integration and workflow data
(r) data synchronised with, or transmitted to, third-party systems the User integrates or nominates, including customer relationship management systems and business applications;
(s) workflow execution records, including the event payloads that carry contact records, transcripts, summaries and recording locations,
and any other Personal Data that the User chooses to submit to the Platform.
For the avoidance of doubt, and in accordance with clause 2.4, S4W's Processing of customer account and Authorised User data, billing and payment data, support communications, website and product analytics (including platform usage and service administration data such as IP addresses, device and browser information, login times, configuration actions and settings changes), and marketing data is carried out by S4W as an independent Controller and is governed by the Privacy Notice rather than by this DPA.
A.6 Special category and criminal offence data
S4W does not require special category Personal Data or criminal offence data in order to provide the Business Purposes, and the User is not required to provide it in order to use the Platform.
The User shall not submit special category or criminal offence data to the Platform, whether through file upload, application programming interface, lead ingest endpoint, contact import or otherwise, unless expressly agreed in writing between the parties (see clause 3.7).
The parties nevertheless record, for the purposes of Article 28(3) UK GDPR and Annex I.B of the EU Standard Contractual Clauses, that Personal Data within the special categories in Article 9 UK GDPR, and Personal Data relating to criminal convictions and offences within the meaning of Article 10 UK GDPR, may be captured incidentally in call audio, call transcripts and chat messages where a Call Participant or a website visitor volunteers it in the course of a conversation, and may therefore be Processed within the categories described at paragraphs A.5(b), (c), (f) and (g). The technical and organisational measures set out in Annex B apply to that data as they apply to all other Personal Data Processed under this DPA. Before deploying the Platform in a use case in which such data is likely to be disclosed, the User shall carry out any data protection impact assessment required of it and shall identify the condition under Article 9(2) or Article 10 UK GDPR on which it relies.
S4W does not inspect, validate, monitor or control the categories of data submitted by the User. Where the User configures and uses the Platform in contexts in which special category or criminal offence data is nonetheless submitted, or is generated incidentally in call recordings, transcripts or chat messages, the User remains solely responsible for determining whether and how that data is Processed, including selecting an appropriate legal basis, carrying out any required data protection impact assessment and providing all necessary notices to Data Subjects. S4W accepts no responsibility for any such data that the User chooses to submit, beyond performing the Processing activities set out in this DPA in accordance with the User's documented instructions.
A.7 Categories of Data Subject
Personal Data Processed under this DPA relates to the following categories of Data Subject:
(a) Call Participants, including participants in a Web Call and individuals whose details are uploaded, imported or ingested by the User whether or not they are ultimately called;
(b) website visitors who interact with a chat assistant embedded on a website operated by or on behalf of the User;
(c) recipients and senders of SMS messages sent or received in connection with the User's account;
(d) the User's own customers, prospects and leads;
(e) contacts of the User held in third-party systems that the User integrates with the Platform; and
(f) any other individuals whose Personal Data the User submits to the Platform.
A.8 Frequency of the transfer
Continuous, as necessary to provide the Business Purposes.
A.9 Retention
As set out in clause 5.6: Personal Data is retained for the life of the User's account; the User may request its return within 30 days of termination or expiry; it is deleted within 60 days of the User's written deletion request, and in any event deleted within 12 months of termination or expiry, save where retention is required by applicable law and save for backup copies dealt with under clause 5.6.4. Retention periods applied by Sub-processors are determined by those Sub-processors and are not controlled by S4W.
A.10 Competent Supervisory Authority
The Information Commissioner's Office (ICO), United Kingdom.
ANNEX B — TECHNICAL AND ORGANISATIONAL MEASURES
This Annex B describes the technical and organisational measures implemented by S4W under clause 5.1(c). It constitutes Annex II of the EU Standard Contractual Clauses. The measures described are those in place as at the effective date of this DPA. S4W's information security programme comprises the measures set out in this Annex B, which S4W reviews periodically; S4W does not hold ISO 27001 certification or any equivalent third-party attestation.
B.1 Hosting and data residency
- The primary data store for the Platform — including contact records, call records, transcripts, summaries, chat sessions and messages — is a managed PostgreSQL database and object storage service hosted in Amazon Web Services' London region (eu-west-2), United Kingdom.
- Call recordings are stored in a private object storage bucket controlled by S4W within that same environment. Call audio, transcripts and call metadata are also held by S4W's voice orchestration provider, which is identified in Annex D and is located in the United States.
- Application services are hosted with the providers identified in Annex D.
- Conversation content is transmitted to the artificial intelligence, telephony and orchestration providers identified in Annex D, some of which are established outside the UK and EEA. Those transfers are made subject to Annex C.
B.2 Access control and tenant isolation
- Access to the Platform by the User's Authorised Users is authenticated by JSON Web Tokens issued by S4W's third-party identity provider (identified in Annex D). Authentication is passwordless, using email one-time codes or Google single sign-on; S4W does not store user passwords.
- Tokens are verified by the Platform on every request, and authenticated requests are scoped to the caller's company membership.
- Client-side database access is restricted by row-level security policies scoped to company membership. Server-side service components connect to the database with elevated privileges that are not subject to those policies; for those components, tenant isolation is enforced in application code within the service and repository layers.
- Callbacks from third-party platforms are authenticated using shared secrets.
- Internal and private runtime endpoints are protected by API-key middleware.
- Public-facing and private/internal application programming interfaces are architecturally separated to reduce the exposure of privileged operations.
B.3 Encryption and secret protection
- Personal Data is encrypted in transit using TLS.
- Personal Data at rest is encrypted using the encryption-at-rest facilities of the underlying hosting and storage providers.
- Sensitive integration secrets (for example telephony sub-account authentication tokens) are encrypted using AES-256-GCM with a random 12-byte initialisation vector and a 16-byte authentication tag before storage.
- API keys are never stored in plaintext. Only a keyed HMAC-SHA256 hash of the key, together with a non-sensitive key prefix and the final four characters, is persisted. The plaintext key is displayed once at creation and is not recoverable.
- Payment card details are entered directly into the payment provider's hosted checkout and are not stored by S4W. S4W retains only the card brand, the final four digits, the expiry month and year, and the payment provider's payment-method reference.
- Secrets are injected at runtime through environment variables and secret managers in runtime and continuous-integration environments, and are not hard-coded in application source.
B.4 Secure application and interface controls
- Input validation is enforced using typed schema validation (Zod) for environment configuration and request payloads.
- Error responses returned to clients are sanitised: stack traces, internal identifiers and third-party provider names are not exposed.
- Limits are applied to multipart and file uploads to reduce abuse risk.
- Outbound requests to endpoints nominated by the User are subject to server-side request forgery protections, including blocking of private, loopback and link-local address ranges. Additional carrier-grade NAT blocking and DNS pinning to protect against rebinding are applied on the workflow HTTP step.
- Error handling is centralised so that security responses are consistent across the application.
B.5 Personnel and internal access
- A limited group of authorised S4W Personnel may access customer accounts and the Personal Data Processed within them where necessary to provide, support, administer and secure the products and services.
- Where authorised Personnel access a customer account by impersonating an Authorised User, that session is recorded in an audit log. Direct reads of individual records by authorised Personnel are not individually logged.
- All Personnel with access to Personal Data are bound by contractual or statutory obligations of confidentiality that survive the end of their engagement.
B.6 Traceability
- Structured application logging with request identifiers is used for traceability and incident investigation.
B.7 Operational and organisational controls
- Development and production environments are separated, with environment-scoped secrets.
- Application builds fail closed on compilation and type errors: the hosting providers' build steps run a full TypeScript compile before a release is promoted.
- Database schema and function changes are version-controlled through migrations and deployment workflows.
- Backups of the primary data store are taken by the managed hosting provider in accordance with that provider's standard backup regime.
- Deletion, return of data and assistance with Data Subject Rights Requests are performed by documented operational process as described in clauses 5.2 and 5.6.
B.8 Measures not currently implemented
For the avoidance of doubt, and so that the User can conduct its own assessment under clause 3.4, S4W confirms that as at the effective date of this DPA it does not operate:
- any third-party security certification or attestation programme (including ISO 27001 certification and SOC 2 reporting);
- a penetration testing or vulnerability scanning programme;
- multi-factor authentication for Authorised Users, whether optional or mandatory;
- record-level access logging of reads of Personal Data, security anomaly detection or automated security alerting;
- automated retention, expiry or purge processing of Personal Data;
- self-service tooling for the location, export or erasure of an individual Data Subject's Personal Data across the Platform.
Where the User's own risk assessment requires any of these measures, it should raise that with S4W before submitting Personal Data to the Platform.
ANNEX C — TRANSFERS OF PERSONAL DATA: UK INTERNATIONAL DATA TRANSFER ADDENDUM
The parties agree that, with respect to Restricted Transfers subject to the UK GDPR, the EU Standard Contractual Clauses (incorporating the selections set out in paragraph C.1 below) are incorporated into the Agreement by reference and are deemed amended by the provisions of Part 2 (Mandatory Clauses) of the UK Addendum. The EU Standard Contractual Clauses are incorporated for that purpose only, as the base clauses that the UK Addendum amends, and do not apply as a standalone transfer mechanism.
C.1 Selections in the incorporated Standard Contractual Clauses
(i) Module Two (Controller to Processor) applies, where the User is a Controller of Personal Data and data exporter and S4W is its Processor and data importer. No other Module applies.
(ii) In Clause 7, the optional docking clause does not apply.
(iii) In Clause 9, Option 2 (general written authorisation) applies, and the time period for giving notice of Sub-processor changes shall be as set out in clause 5.5.2 of this DPA.
(iv) In Clause 11, the optional independent dispute resolution language does not apply.
(v) In Clause 17 and Clause 18, and as required by the Mandatory Clauses of the UK Addendum, the Standard Contractual Clauses as incorporated and amended by the UK Addendum are governed by the laws of England and Wales, and any dispute arising from them shall be resolved by the courts of England and Wales. That election applies solely to the transfer mechanism set out in this Annex C and does not vary or displace the governing law and jurisdiction of the Agreement, which are the same (see clause 6.4 of this DPA).
(vi) Annex I.A (List of Parties) is completed with the information set out in the Parties section of this DPA.
(vii) Annex I.B (Description of Transfer) is completed with the information set out in Annex A of this DPA. The frequency of the transfer is continuous, as necessary to deliver the products and services, and retention is as set out in clause 5.6 and paragraph A.9 of Annex A.
(viii) Annex I.C (Competent Supervisory Authority) is completed as set out in paragraph A.10 of Annex A.
(ix) Annex II (Technical and Organisational Measures) is completed with the information set out in Annex B of this DPA.
(x) Annex III (List of Sub-processors) is completed with the information set out in Annex D of this DPA.
C.2 Information required for Part 1 (Tables) of the UK Addendum
(a) Table 1 (Parties): the exporter is the User and the importer is S4W. The parties' full legal names, registered addresses, roles and data protection contacts are as set out in the Parties section of this DPA and, in the case of the User, as recorded in the User's account. The start date is the Commencement Date.
(b) Table 2 (Selected SCCs, Modules and Selected Clauses): the EU Standard Contractual Clauses as set out in paragraph C.1 above, Module Two (Controller to Processor), with the clause selections at paragraph C.1 items (ii) to (v).
(c) Table 3 (Appendix Information): Annex I.A of the EU Standard Contractual Clauses (as incorporated and amended by the UK Addendum) is completed with the Parties section of this DPA; Annex I.B is completed with Annex A of this DPA; Annex I.C is completed with paragraph A.10 of Annex A (the competent supervisory authority being the Information Commissioner's Office); Annex II is completed with Annex B of this DPA; and Annex III is completed with Annex D of this DPA.
(d) Table 4 (Ending this Addendum when the Approved Addendum changes): Importer and Exporter. Either party may accordingly end the UK Addendum in accordance with Section 19 of its Mandatory Clauses.
(e) The parties agree that the governing law and choice of forum and jurisdiction for the Agreement, this DPA and the transfer mechanism set out in this Annex C are those of England and Wales.
ANNEX D — SUB-PROCESSORS
This Annex D is the Sub-processor List referred to in clause 5.5.1 and constitutes Annex III / Appendix 3 to the Standard Contractual Clauses. The User authorises the Sub-processors listed below. This Annex D is current as at the effective date stated at the head of this DPA.
The "Location" column states the region in which Personal Data is stored or primarily processed by the Sub-processor concerned. A number of the Sub-processors listed are incorporated in a country other than that region, and their authorised personnel may access Personal Data from a country other than that region.
S4W will give the User not less than 30 days' notice, by email to an Administrator in accordance with clause 18.4 of the Agreement, before a new Sub-processor commences Processing Personal Data in connection with the Agreement. The User may object in accordance with clause 5.5.3, and the consequences of an unresolved objection are set out in clause 5.5.4.
Dial Square Consultancy Ltd acts as S4W's payment collection agent and merchant of record and is not a Sub-processor of Personal Data Processed on the User's behalf under this DPA.
Sub-processors engaged by S4W
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Supabase | Managed database, object storage and hosting of the primary data store for the Platform | All Platform Personal Data, including contacts, leads, call records, transcripts, summaries, chat sessions and messages, call recordings and usage records | AWS eu-west-2 (London, United Kingdom) |
| Clerk | Identity provider — authentication of Authorised Users (email one-time code and Google single sign-on), session management | Authorised User name, email address, Google account profile, session and device data, IP address | United States |
| VAPI | Voice assistant orchestration — call handling, transcription pipeline, knowledge-base hosting and call artefact storage | Call audio, transcripts, call metadata, telephone numbers, knowledge-base content, variables passed into the call | United States |
| Twilio | Telephony and SMS carriage; provisioning of telephone numbers; regulatory business identity verification | Telephone numbers, call and message metadata, message bodies, call audio in transit, business identity and verification data | United States |
| Groq | Large language model inference for the majority of production assistants | Assistant prompts and conversation content, including anything spoken by a Call Participant, and variables passed into the call | United States |
| OpenAI | Large language model inference; call scoring (receives full call transcripts directly); in-product AI assistance | Call transcripts, chat transcripts, summaries, assistant prompts, account data submitted to in-product AI features | United States |
| xAI | Large language model inference where selected for an assistant | Assistant prompts and conversation content | United States |
| Anthropic | Large language model inference where selected for an assistant | Assistant prompts and conversation content, including anything spoken by a Call Participant or written by a website visitor | United States |
| Large language model inference (Gemini) for all knowledge-base content — this applies to every knowledge base and cannot be disabled by the User — and for assistants where a Gemini model is selected | Knowledge-base documents and content supplied by the User and the queries run against them; and, where selected for an assistant, assistant prompts and conversation content | United States and other Google processing locations | |
| ElevenLabs | Text-to-speech synthesis | Text generated by the assistant for speech synthesis, which may contain Personal Data | United States |
| Deepgram | Speech-to-text transcription | Call audio and resulting transcript text | United States |
| Inngest | Durable workflow and event orchestration | Event payloads carrying contact records, telephone numbers, transcripts, summaries and recording locations | United States |
| Stripe | Payment processing and subscription billing of the User's own Fees | Billing contact details, card brand, last four digits and expiry, payment-method tokens, transaction records | United States and Ireland |
| Resend | Transactional email delivery | Recipient name and email address, message content | United States |
| Trello | Support ticket management. S4W is migrating support ticketing to Asana; at the effective date of this DPA this provider still receives support tickets, and this row will be removed once migration completes | Submitter name, email address, company, free-text support message and any attachments or screenshots supplied, which may contain Personal Data | United States |
| Asana | Support ticket management, on and from completion of the migration described in the Trello row above | Submitter name, email address, company, free-text support message and any attachments or screenshots supplied, which may contain Personal Data | United States |
| Slack | Internal notifications and operational alerting | Notification content, which may contain contact details, call outcomes and lead data | United States |
| Algolia | Documentation search and in-product "Ask AI" search | Search queries and question text submitted by Authorised Users | United States and European Union |
| Zapier | Integration platform; partner SDK loaded within the Platform interface | Integration payload data where the User configures a Zapier integration; page interaction data for Authorised Users | United States |
| Vercel | Hosting of the Platform's web application and S4W's websites | Request data, IP addresses and application telemetry | United States (with edge processing in multiple regions) |
| Railway | Hosting of S4W's application programming interface and worker services | All Platform Personal Data processed in transit by those services | United States |
| GitHub | Source control and content management for S4W's websites | Website content, which is not intended to contain customer Personal Data | United States |
| MamoPay | Payment processing and subscription billing for existing subscriptions that have not yet been migrated to Stripe. At the effective date of this DPA this provider still processes the majority of existing subscriptions. This row will be removed once migration completes. | Billing contact details, payment-method metadata, transaction records | United Arab Emirates |
| Sentry (Functional Software, Inc.) | Application error monitoring for the customer dashboard. Not used for the Platform's call, chat or messaging processing. Conversation content, prompts and completions are not intentionally sent to it, although error diagnostics may incidentally include fragments of request data. | Error and diagnostic events, which are configured to include the user's IP address, request headers and user identifier. | European Union (Germany) |