Data Processing Agreement
Effective Date: May 13, 2026
This Data Processing Agreement ("DPA") is entered into between MindBotics, LLC ("Processor") and the business entity or individual ("Controller" or "Client") that has agreed to the MindBotics Terms of Service. This DPA governs the processing of personal data by MindBotics on behalf of the Client.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person processed in connection with the Services.
- Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
- Controller: The Client who determines the purposes and means of processing personal data.
- Processor: MindBotics, who processes personal data on behalf of the Controller.
- Sub-processor: Any third party engaged by MindBotics to process personal data.
2. Scope and Purpose of Processing
MindBotics processes personal data solely to provide the contracted Services, which may include:
- AI Voice Receptionist call handling, recording, and transcription
- Automated lead capture, CRM integration, and follow-up messaging
- Analytics, reporting, and service improvement using anonymized data
- Security monitoring and fraud prevention
3. Categories of Data Processed
- Contact information: names, phone numbers, email addresses
- Voice recordings and transcriptions from AI Receptionist interactions
- Chat logs and text-based interaction records
- Metadata: call duration, timestamps, interaction frequency
- Business-provided CRM data and customer records
4. MindBotics Obligations
As Processor, MindBotics shall:
- Process personal data only on documented instructions from the Controller.
- Ensure that authorized personnel are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures (including AES-256 encryption at rest and in transit, and restricted access controls).
- Not engage a new sub-processor without informing the Controller and providing an opportunity to object.
- Assist the Controller in fulfilling data subject rights requests (access, correction, deletion) within a reasonable timeframe.
- Notify the Controller of any personal data breach without undue delay upon becoming aware of it.
- Delete or return all personal data upon termination of the Services, at the Controller's election.
5. Client (Controller) Obligations
The Client agrees to:
- Ensure a lawful basis exists for providing personal data to MindBotics for processing.
- Obtain all required consents from end-users, including consent to recording where required by law.
- Notify end-users that they are interacting with an AI system.
- Use the Services in compliance with all applicable data protection laws (GDPR, CCPA, BIPA, TCPA, and other applicable regulations).
- Provide accurate and current instructions to MindBotics regarding data processing preferences.
6. Sub-processors
MindBotics may engage the following categories of sub-processors to deliver the Services:
- Cloud Infrastructure: Hosting and data storage providers (e.g., AWS, Google Cloud).
- Speech-to-Text / AI Providers: Specialized voice synthesis and transcription services.
- CRM / Communication Tools: Third-party platforms used to sync interaction data per client configuration.
All sub-processors are bound by DPAs and vetted for compliance with applicable data protection standards.
7. Data Retention and Deletion
MindBotics retains personal data only for as long as necessary to fulfill the contracted Services or as required by law. Voice recordings and transcripts are retained for a period defined in the applicable service agreement. Upon termination or written request, MindBotics will securely delete or return all personal data within 30 days.
8. Security
MindBotics implements the following security measures:
- Encryption of data at rest (AES-256 or equivalent) and in transit (TLS 1.2+)
- Role-based access controls limiting data access to authorized personnel only
- Automated PII redaction tools for transcripts where feasible
- Regular security assessments and vulnerability monitoring
9. Cross-Border Transfers
If personal data is transferred outside the EU/EEA or other restricted jurisdictions, MindBotics will ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses or equivalent mechanisms) to protect the data in compliance with applicable law.
10. Voice Privacy and Biometric Data
Where applicable, biometric privacy laws (such as Illinois' BIPA) may govern the collection and use of voiceprints or similar identifiers. MindBotics maintains strict data retention and deletion policies for audio recordings and does not use voiceprints for identification purposes without explicit disclosure and consent.
11. Governing Law
This DPA is governed by the laws of the State of Florida. Where applicable, it is intended to satisfy the requirements of GDPR Article 28 and equivalent provisions under CCPA and other applicable data protection regulations.
12. Contact
For DPA inquiries or to execute a signed DPA for enterprise accounts, please contact:
MindBotics Legal Department
Email: legal@mindbotics.ai
Website: mindbotics.ai
