Legal

Data Processing Agreement

Last updated: July 30, 2026

This Data Processing Agreement ("DPA") forms part of the Redialog Terms of Service (the "Terms") between BOOTHIC SMPC, a single-member private company incorporated in Greece, GEMI No. 153029403000, VAT No. EL801264656 ("BOOTHIC", "we", "us"), and the organization that holds the Redialog account (the "Customer", "you"). It applies whenever we process personal data on your behalf to provide Redialog and the GDPR — or an equivalent data-protection law — applies to that processing. It is incorporated into the Terms automatically, without signature; request a countersigned copy at [email protected].

1. Roles and scope

You are the controller of Customer Data; we are your processor. "Customer Data" means the content and call data your organization brings to or creates in Redialog — documents, Q&A, Guides, Smart Field definitions and captured values, transcripts, summaries, tasks, notes and follow-up drafts — including the personal data in it. For account, billing, support and website data we are an independent controller, as described in our Privacy Policy; that processing sits outside this DPA. If you use Redialog as a processor for someone else, you warrant that your controller has authorized these terms, and we act as your sub-processor.

2. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3. Instructions

We process Customer Data only on your documented instructions: this DPA, the Terms, the settings your organization configures in the app — visibility, retention, seat assignments and the integrations you connect, each of which instructs us to exchange Customer Data with that tool — and any further written instructions we agree to. We will tell you if we believe an instruction infringes the GDPR, though we are not obliged to run legal checks on your behalf. You remain responsible for the lawfulness of the data you process with Redialog, including informing call participants and securing any consent or other lawful basis needed to transcribe them (Terms, section 5).

4. Confidentiality

Only people who need Customer Data to operate the service can access it, and every one of them is bound by contractual or statutory confidentiality obligations.

5. Security

We implement and maintain the technical and organizational measures in Annex 2 and will not materially weaken them during your subscription. Taking into account the state of the art, the costs of implementation and the risks of the processing, these measures are designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as Article 32 GDPR requires.

6. Sub-processors

You give general written authorization for the sub-processors listed in Annex 3; the current list is always maintained on our Privacy Policy page. Before adding or replacing a sub-processor we will update that list and notify your admins — by email or in the app — at least 30 days in advance. You may object within 15 days of the notice on reasonable data-protection grounds; we will then work with you in good faith on a solution, and if there is none, you may terminate the affected subscription and we will refund any fees prepaid for the period after termination. We impose data-protection obligations materially equivalent to this DPA on every sub-processor by written contract, and we remain fully liable to you for their performance (Article 28(4) GDPR).

7. International transfers

Customer Data is processed in the EEA and the United States (Annex 3). Where a transfer out of the EEA needs safeguards, we rely on adequacy decisions — including the EU–US Data Privacy Framework where the provider is certified — or the European Commission's Standard Contractual Clauses, alongside supplementary measures such as encryption in transit and at rest. For transfers subject to UK or Swiss rules, the UK Addendum or the Swiss amendments apply as required, with the necessary adaptations.

8. Assistance

Taking into account the nature of the processing, we assist you with your own GDPR obligations:

  • Data subject rights (Articles 12–23) — Redialog's export, correction, deletion, visibility and retention tools are the primary means of assistance. If a data subject contacts us directly about Customer Data, we forward the request to you without undue delay and do not answer it ourselves, beyond directing them to you, unless the law requires more.
  • Security, breach notification and impact assessments (Articles 32–36) — we provide reasonable assistance and the information in our control, including for data protection impact assessments and consultations with supervisory authorities.

9. Personal data breaches

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and give you the information Article 33(3) GDPR calls for — the nature of the breach, the categories and approximate numbers affected, likely consequences, and the measures taken or proposed — as it becomes available, so you can meet your own notification duties. Our notification is not an admission of fault.

10. Audits and information

On written request, we will demonstrate compliance with this DPA by providing our current security documentation, summaries of third-party attestations covering our infrastructure, and answers to reasonable written security questionnaires — once in any 12-month period, unless a breach has occurred or a supervisory authority requires more. Where the GDPR gives you a mandatory audit right that this does not satisfy, you or an independent auditor bound to confidentiality (and not a competitor of ours) may audit on at least 30 days' notice, during business hours, without disrupting the service, at your cost.

11. Export, deletion and return

You can export Customer Data at any time during the subscription. Deletion follows the controls you already hold: retention windows set by your admins, the member-departure cleanup described in the Terms, and account or organization deletion. When the agreement ends, we delete remaining Customer Data within 30 days of account closure or your deletion request, except copies the law requires us to keep, which stay protected by this DPA until destroyed. Deleted data leaves backups on their rolling replacement cycle. Call audio is never stored at all — it is transcribed in real time and immediately discarded.

12. Liability, precedence and governing law

Liability under this DPA is subject to the limitations and exclusions in the Terms, applied in aggregate across both documents. If this DPA conflicts with the Terms on data protection, this DPA prevails; where mandatory data-protection law requires something different, that law prevails over both. This DPA is governed by the same law and courts as the Terms. We may update this DPA to reflect changes in law, in the service or in Annex 3; material changes follow the notice process in the Terms and, for sub-processors, section 6 above.

Annex 1 — Details of processing

Subject matter and duration

Provision of Redialog, the AI sales call assistant, for the term of the Terms and until deletion under section 11.

Nature and purpose

Real-time speech-to-text of call audio captured on the Customer's side (with immediate discard of the audio); retrieval of answers from Customer knowledge; AI generation of Live Answers, Smart Field values, summaries, tasks and follow-up drafts; storage, search and display of Customer Data according to workspace settings; synchronization with systems the Customer connects; and support.

Categories of data subjects

The Customer's members and users; participants in the Customer's calls, such as prospects, clients and colleagues; and individuals who appear in documents the Customer uploads or are mentioned in conversations.

Types of personal data

Identity and contact data (names, email addresses); professional data (role, employer); the content of communications — everything said on transcribed calls and written in documents, notes and drafts; commercial details captured in Smart Fields (needs, budgets, timelines); and member usage data. The service is not intended to process special categories of data or children's data; if participants volunteer such information it may appear in transcripts incidentally, and the Customer is responsible for the lawfulness of processing it.

Annex 2 — Technical and organizational measures

  • Encryption in transit and at rest across the entire pipeline.
  • Zero audio retention by design: call audio is transcribed in real time and immediately discarded, never written to storage.
  • Integration credentials encrypted with AES-256-GCM.
  • Authentication and MCP access secured with OAuth through WorkOS, including single sign-on.
  • Workspace isolation and role-based visibility; private calls and private notes enforced across every surface, including search and integrations.
  • Least-privilege access: production data is accessible only to the few people who need it to run the service, under confidentiality obligations.
  • SOC 2 Type II certified infrastructure providers with multi-region, replicated backups.
  • Customer-controlled retention: admin-set auto-deletion windows, member-departure cleanup, anonymization of organization records.
  • Logging and monitoring of production systems; a documented incident-response process with customer notification under section 9.
  • Vendor management: written data-processing agreements with every sub-processor.

Annex 3 — Sub-processors

Sub-processors of Customer Data as of the date above; the current list is always on the Privacy Policy page:

  • Convex, Inc. (United States) — database and backend infrastructure.
  • Soniox, Inc. (United States) — real-time speech-to-text; receives live call audio solely to return the transcript.
  • Google LLC (United States / EEA) — Gemini AI models generating Live Answers, Smart Field values, summaries and drafts.
  • WorkOS, Inc. (United States) — authentication and single sign-on for your users.

Polar, our merchant of record, is an independent controller of payment data, and the analytics and form providers used on the marketing website do not touch Customer Data — none of them are sub-processors under this DPA.

Contact

BOOTHIC SMPC — single-member private company incorporated in Greece
29 Tavoulari Str., Greece · GEMI No. 153029403000 · VAT No. EL801264656
Operating Redialog · [email protected]