DRAFT — pending legal review. These documents are not final and are not yet in effect. Questions: privacy@torklio.com
Data Processing Addendum
========================
SOURCE: Torklio Interim Legal Package v1.0 (owner-prepared interim draft, 2026-09-03). DRAFT - attorney review required; bracketed [FIELDS] must be completed and every statement verified against production before any effective date is set. Loaded into the legal center 2026-09-03.
Data Processing Addendum
Processing terms between Torklio and its business customers
PUBLICATION CONTROL Effective date: [PUBLICATION DATE]. Replace all red bracketed fields and verify the text against production before publication. Internal status: attorney review required.
1. Parties and scope
This Data Processing Addendum ("DPA") forms part of the agreement between Torklio LLC ("Torklio") and Customer. It applies when Torklio processes Personal Data on Customer's behalf in connection with the Service. Capitalized terms not defined here have the meanings in the Terms of Service.
2. Definitions
"Applicable Data Protection Law" means a law applicable to the parties' processing of Personal Data under the agreement. "Controller" means the party that determines the purposes and means of processing. "Processor" means a party that processes Personal Data on behalf of a Controller. "Personal Data" means information relating or reasonably linkable to an identified or identifiable person. "Process" and "processing" include collecting, accessing, using, storing, disclosing, transmitting, deleting, and other operations performed on Personal Data. "Security Incident" means confirmed unauthorized access to, acquisition of, or disclosure of Customer Personal Data in Torklio's possession or control, excluding unsuccessful attempts that do not compromise data.
3. Roles and instructions
Customer is the Controller or business and Torklio is the Processor or service provider for Customer Personal Data, except when Torklio processes account, billing, security, abuse-prevention, and direct business-relationship information for its own lawful purposes. Torklio will process Customer Personal Data only on Customer's documented instructions, including the agreement, configured features, authorized support requests, and instructions required by law.
Customer is responsible for the lawfulness of its instructions, notices, consents, data sources, and use of outputs. Customer will not instruct Torklio to process prohibited data or perform processing that violates the agreement or Applicable Data Protection Law. Torklio may refuse or suspend an instruction it reasonably believes is unlawful or materially unsafe.
4. Processing details
Element
Description
Subject matter
AI-assisted business communications, scheduling, CRM, routing, messaging, integrations, support, security, and related administration.
Duration
For the subscription term and a limited period afterward as needed for deletion, export, backup cycles, security, disputes, or legal obligations.
Nature
Collection, transmission, organization, storage, retrieval, analysis, generation, disclosure to authorized recipients, restriction, deletion, and deidentification.
Purpose
Providing the features selected and configured by Customer; maintaining security and reliability; support; and complying with law.
Individuals
Customer personnel, callers, prospects, customers, appointment participants, website visitors, and other people whose data Customer submits.
Data
Contact information, call and message content, audio, recordings, transcripts, appointments, CRM notes, consent records, calendar data, integration identifiers, files, account information, logs, and diagnostics.
Excluded data
Protected health information, complete card data, passwords, Social Security numbers, bank credentials, biometric templates, and other data prohibited by the AUP.
5. Confidentiality and personnel
Torklio will limit access to Customer Personal Data to personnel and providers who need access to perform the Service, security, support, or legal obligations. Persons authorized to process the data will be subject to confidentiality duties appropriate to their role.
6. Security measures
Taking into account the nature of the Service, implementation costs, and processing risks, Torklio will maintain reasonable administrative, technical, and organizational safeguards. Current measures are intended to include:
authenticated accounts, role-based access, and owner-only controls for sensitive administrative actions;
logical tenant separation and authorization checks;
encryption of network communications where supported;
secret redaction and controls intended to prevent credentials from appearing in user-facing logs or content;
security, incident, and operational logging with access limited to authorized purposes;
backups, integrity checks, monitoring, and recovery procedures;
testing of booking integrity, tenant isolation, failure behavior, and security controls;
incident-response and notification procedures; and
data minimization and restrictions on prohibited sensitive information.
This section does not represent that Torklio holds a particular certification or that every stored data category is encrypted at rest. [VERIFY AND UPDATE THIS SECTION AFTER APPLICATION-LAYER ENCRYPTION AND ENCRYPTED OFFSITE BACKUPS ARE FULLY DEPLOYED.]
7. Security incidents
Torklio will investigate a suspected Security Incident and take reasonable steps to contain, mitigate, and remediate it. Torklio will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data, consistent with applicable law and legitimate law-enforcement restrictions. Notice will include available information reasonably needed for Customer to meet its obligations. Notification is not an admission of fault or liability.
8. Subprocessors
Customer authorizes Torklio to use the subprocessors identified in the Subprocessor List to provide the Service. Torklio will require subprocessors to protect Customer Personal Data through contractual obligations appropriate to their services. Torklio remains responsible for its obligations under this DPA to the extent required by the agreement and Applicable Data Protection Law.
Torklio may update the Subprocessor List. Where required, Torklio will provide reasonable advance notice of a new subprocessor. Customer may object on reasonable data-protection grounds within 30 days after notice. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate the affected feature, subject to the Order Form and applicable law.
9. Individual rights
Taking into account the nature of processing, Torklio will provide reasonable assistance so Customer can respond to verified requests for access, correction, deletion, portability, restriction, or appeal. If Torklio receives a request concerning Customer Personal Data, Torklio may direct the requester to Customer unless law requires a direct response. Customer is responsible for evaluating and responding to the request.
10. Return and deletion
During the subscription, Customer may request a reasonable export through support@torklio.com. Following termination or a verified written instruction, Torklio will delete or return Customer Personal Data within the period specified in 30 days, unless law requires retention. Deletion from backups may occur through ordinary backup rotation rather than immediate overwrite, provided the retained data remains protected and is not restored except for continuity or legal purposes.
11. Compliance information and audits
Upon reasonable written request, Torklio will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and privilege limitations. If that information is insufficient and Applicable Data Protection Law requires an audit, the parties will agree on scope, timing, safeguards, auditor qualifications, and cost. Audits may not unreasonably disrupt operations or expose another customer's information.
12. U.S. state privacy terms
To the extent Customer Personal Data is subject to a U.S. state privacy law that recognizes processors, contractors, or service providers, Torklio will not sell the data, share it for cross-context behavioral advertising, retain/use/disclose it outside the direct business relationship except as legally permitted, or combine it with personal information received from another source except as permitted to provide the Service, security, or another lawful business purpose. Torklio will notify Customer if it determines it can no longer meet an applicable restriction and will allow reasonable steps to stop and remediate unauthorized use.
13. Google user data
For information received from Google APIs, Torklio will follow the applicable Google user-data and Limited Use requirements, including restrictions on advertising, sale, human access, and generalized model training. Customer will request only scopes necessary for enabled functionality and will not instruct Torklio to use Google data for a prohibited purpose.
14. International processing
The Service is intended for eligible U.S. businesses. Customer will not deploy Torklio outside the United States or submit data subject to international-transfer requirements without Torklio's prior written approval and any required transfer mechanism or supplemental terms.
15. HIPAA exclusion
The Service is not offered as a HIPAA-compliant service, Torklio does not enter into a Business Associate Agreement under this DPA, and Customer must not submit protected health information. If the parties later execute a separate written Business Associate Agreement for an approved service, that agreement will control for the covered processing.
16. Priority and liability
If this DPA conflicts with the Terms concerning processing of Customer Personal Data, this DPA controls. Liability arising under this DPA is subject to the exclusions and limitations in the Terms unless Applicable Data Protection Law requires otherwise.
17. Signatures
This DPA is accepted when Customer accepts the Terms or signs an Order Form incorporating it. Contracting party: Torklio LLC. Customer: the entity identified in the applicable account or Order Form.
← Legal Center