Trust
Data Processing Addendum
Version 2026-09-27 · Effective September 27, 2026
This addendum is part of our Terms of Service. It sets out how Bizefy LLC processes the personal information in your calls and your content on your behalf. The editor who creates a Sona workspace accepts it for the business; it applies from that moment.
1. Roles and scope
“Customer” is the business that uses Sona; “Bizefy”, “we” and “us” mean Bizefy LLC. This addendum applies to personal information that we process on Customer's behalf in providing the Service (“Customer Personal Data”), mainly information about the people who call Customer and information Customer puts in its configuration and knowledge base. Customer is the “business” (or controller) and we are its “service provider” (or processor) under the California Consumer Privacy Act and comparable US state privacy laws. Details of the processing are in Annex 1.
2. Processing only on Customer's instructions
We process Customer Personal Data only to provide, secure and support the Service, as the Terms and Customer's use of the dashboard instruct. We will not:
- sell or share it (as the CCPA defines those terms);
- retain, use or disclose it for any purpose other than providing the Service, or outside our direct business relationship with Customer;
- combine it with personal information we receive from anyone else, except as the CCPA's regulations permit a service provider to;
- use it to train AI models.
We will tell Customer if we can no longer meet our obligations under the privacy laws that apply to this processing, and Customer may then take reasonable steps to stop and remedy unauthorized use. We understand and will comply with these restrictions.
3. Customer's responsibilities
Customer decides why and how the personal information in its calls is processed, and is responsible for that decision. In particular, Customer:
- gives only instructions, and puts only information into the Service, that the law applying to it allows;
- gives callers any notice, and obtains any consent, that the law requires of it beyond the AI disclosure and the recording notice the Service plays, including for recording when it turns recording on;
- decides who has an account in its workspace and with what role, and keeps the sign-in details of those accounts secure;
- does not use the Service to collect the health, payment card or government identification information the Terms rule out; and
- chooses a recording retention period in the dashboard that fits its own legal obligations.
4. Our people
Our staff and contractors who can access Customer Personal Data are bound by confidentiality obligations and access it only as needed to run and support the Service. When our staff open a call's content in our internal console, that access is recorded in Customer's own audit log before the content is shown.
5. Security
We maintain the technical and organizational measures described in Annex 2 and on our security page, and we may improve them over time without reducing the overall level of protection.
6. Sub-processors
Customer authorizes us to use the sub-processors listed in Annex 3 and on our sub-processors page. We bind each of them by written contract to data protection obligations no less protective than this addendum, and we remain responsible to Customer for their performance. Before a new sub-processor starts processing Customer Personal Data, we update that page and email Customer's editors at least 30 days in advance. Customer may object on reasonable data-protection grounds within that period; if we cannot address the objection, Customer may end the affected part of the Service and we will refund any fees it has prepaid for the period after the change.
7. Help with privacy requests
When a caller or other person asks to access, correct or delete their information, Customer decides how to respond. We help Customer do so, taking into account the nature of the processing: we forward to Customer any such request we receive about Customer Personal Data, and we carry out Customer's verified instructions to export or delete it without undue delay and in time for Customer to meet its own legal deadline. Today these steps are carried out by our team, not by an automated process. We also give Customer the information it reasonably needs for a data protection assessment of the Service.
8. Security incidents
If we confirm a security incident that leads to unauthorized access to, or loss or disclosure of, Customer Personal Data, we notify Customer without undue delay and within 48 hours of confirming it. The notice describes what happened, the data involved, what we have done and what we recommend, and we update it as we learn more. We cooperate with Customer's own investigation and any notices Customer has to give. Security contact: security@bizefy.dev.
9. Return and deletion
When the Terms end, Customer has 30 days to ask us for a copy of Customer Personal Data. Within 30 days after that window closes, we delete Customer Personal Data from our active systems, and confirm on request. We may keep billing records, audit records and records of what was agreed, where the law or our legitimate interests require it, and they remain subject to this addendum while we hold them. Recordings are also deleted earlier, on the schedule Customer sets in the dashboard.
10. Demonstrating compliance
On request, and no more than once a year unless an incident or a regulator requires otherwise, we answer Customer's reasonable written questions about our compliance with this addendum. We do not have an independent audit report today; when we do, we will make it available under confidentiality terms, and it will take the place of those questions.
11. Where data is processed
Customer Personal Data is stored in the Service's database and file storage, which are hosted in Ireland, in the European Union (Amazon Web Services region eu-west-1, operated for us by Supabase). Our other sub-processors, including the telephony, speech and language-model providers and the host that runs our voice service, process it where they operate, which includes the United States and may include other countries. We do not currently guarantee that it stays within one country.
12. Health information
This addendum is not a business associate agreement. Customer must not use the Service to process protected health information under HIPAA, and we do not offer business associate agreements at this time (see the Terms).
13. Liability and precedence
Each party's liability under this addendum is subject to the limitations in the Terms. If this addendum and the Terms conflict on the processing of Customer Personal Data, this addendum prevails. Questions: legal@bizefy.dev or privacy@bizefy.dev.
Annex 1: Details of the processing
- Subject matter and duration: providing the Service for as long as Customer uses it, then Section 9.
- Nature and purpose: answering calls on Customer's behalf with an AI receptionist; recording calls if Customer turns that on; transcribing them; taking messages; booking, moving and cancelling appointments; transferring calls; answering from Customer's knowledge base; showing the results in Customer's dashboard; and sending the email alerts Customer switches on.
- People concerned: people who call Customer, and people named in Customer's configuration or knowledge base.
- Types of information: phone numbers and call metadata; call audio, recordings and transcripts; names, callback numbers, appointment details and message contents; questions asked on a call; and whatever Customer puts in its knowledge base.
- Sensitive information: not intended. Customer must not use the Service to collect health, payment card or government identification information (see the Terms), though a caller may volunteer such details on a call.
Annex 2: Security measures
- Row-level security in the database that separates each customer's data, with the same boundary checked again in the application.
- Encryption in transit for all traffic, and encryption at rest provided by our database and storage provider.
- Recordings reachable only through private links that expire after a minute in the dashboard, and after two minutes in our staff console.
- Signature checks on every telephony and payment webhook; a rotatable shared secret between our own services; provider credentials kept out of code.
- Workspace roles (editor and viewer), an audit log of every configuration change, and a record in that log whenever our staff view call content.
- Per-caller rate limits and daily spend limits on inbound calls, and a platform-wide switch to voicemail.
- Changes to the Service's code kept in version control and checked by automated tests, including tests of the database's row-level security whenever the database changes.
- Automatic deletion of recordings on the schedule Customer sets, and removal of the telephony provider's copy once a recording is stored.
Annex 3: Sub-processors
| Provider | What it does | When |
|---|---|---|
| Twilio | Telephony: the phone numbers, inbound call routing, call transfer, the live speech pipeline (ConversationRelay) and, when a business turns recording on, the call recording. | Always |
| Amazon Web Services: Amazon S3 | Stores call recordings: when a business turns recording on, Twilio uploads each finished recording to our storage bucket on Amazon S3, where it is kept and played back from. | When a business turns recording on and the platform stores recordings through Twilio's external storage. |
| Deepgram (through Twilio) | Speech recognition: turns the caller's speech into text during the call. | When a business's receptionist uses a Deepgram speech model (the default). |
| Google (through Twilio) | Speech recognition and synthesized voices. | When a business selects a Google speech model or voice. |
| Amazon Web Services: Amazon Polly (through Twilio) | Synthesized voices. | When a business selects an Amazon Polly voice. |
| ElevenLabs (through Twilio) | Synthesized voices. | When a business selects an ElevenLabs voice. |
| Anthropic | The language model that decides what the receptionist says and which action it takes. | When a business's receptionist uses a Claude model (the default). |
| OpenAI | Embeddings for the knowledge base (turning a business's pages, documents and FAQs, and a caller's question to them, into search vectors), and the language model when a business selects an OpenAI model. | When a business uses the knowledge base, or selects an OpenAI model. |
| Supabase | Database, file storage and sign-in for the dashboard. | Always |
| Vercel | Hosts this website, the customer dashboard and our billing endpoints. | Always |
| Voice service hosting provider (to be named before publication) | Runs the voice service: call routing, the live conversation, the receptionist's tools and the post-call workers. | Always |
| Stripe | Subscription billing, invoices, card payments and wallet credit. Card details are entered in Stripe's own fields and never reach our servers. | When a business subscribes to a paid plan or adds wallet credit. |
| Microsoft (Microsoft 365) | Email: sends the email alerts a business asks for (a post-call summary after each call an agent answers, for agents that have it switched on, and alerts for messages taken and for appointments booked, moved or cancelled) and the account emails (sign-up confirmation and password reset), receives the email sent to our contact addresses, and carries the messages visitors send through the contact form on our home page to that mailbox. | Alerts when a business has email alerts switched on; account emails whenever someone signs up or resets a password; a contact-form message whenever a visitor sends one. |