orb22 Data Processing Addendum
Effective date: September 30, 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between DSBC LLC ("DSBC", "Processor") and the Customer ("Customer", "Controller"). It applies when DSBC processes Personal Data on the Customer's behalf through orb22. It is accepted when the Customer accepts the Terms. A countersigned copy is available on request at support@22floor.com. If this DPA conflicts with the Terms, this DPA controls for data protection matters. If the Standard Contractual Clauses or other transfer terms in Section 10 conflict with this DPA, those transfer terms control.
1. Definitions
- Data Protection Laws: all laws that apply to the processing of Personal Data under the Terms, including, as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR") and national laws implementing the ePrivacy Directive 2002/58/EC; the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003; the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations ("CCPA") and other US state consumer privacy laws; Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and Quebec's Act respecting the protection of personal information in the private sector ("Quebec Privacy Act"); Australia's Privacy Act 1988 and the Australian Privacy Principles ("APPs"); Israel's Protection of Privacy Law, 5741-1981, and its regulations, including the Protection of Privacy (Data Security) Regulations, 5777-2017 ("Israeli Privacy Law"); Brazil's Lei Geral de Proteção de Dados, Law 13,709/2018 ("LGPD"); Japan's Act on the Protection of Personal Information; Singapore's Personal Data Protection Act 2012; and India's Digital Personal Data Protection Act, 2023.
- Personal Data: information relating to an identified or identifiable natural person, including "personal information" under the CCPA and equivalent terms under other Data Protection Laws, that DSBC processes on the Customer's behalf. Mainly Visitor Data as defined in the Terms.
- Controller, Processor, Data Subject, Processing, Personal Data Breach, Supervisory Authority: as defined in the GDPR, and read as the equivalent terms under other Data Protection Laws (for example, "business" and "service provider" under the CCPA, "controller" and "holder" under the Israeli Privacy Law, "data fiduciary" and "data processor" under Indian law, and "organization" and "data intermediary" under Singapore law). "Sell", "Share", and "Business Purpose" have the meanings in the CCPA.
- Subprocessor: a third party DSBC engages to process Personal Data.
- SCCs: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, or any successor clauses the Commission adopts.
2. Roles and scope
- The Customer is the Controller (and the Business) and DSBC is the Processor (and the Service Provider) for Personal Data. Where the Customer is itself a processor for a third party, DSBC is its subprocessor, and the Customer confirms that its instructions are authorized by that third party.
- DSBC is a separate controller only for Customer account data, as described in its Privacy Policy. This DPA does not apply to that data.
- Details of processing are in Annex 1.
3. Customer obligations
- The Customer is responsible for the lawfulness of the Personal Data and its instructions, including providing Visitors with a privacy notice, having a lawful basis, and obtaining every consent required by Data Protection Laws and by wiretap, eavesdropping, and call recording laws before a conversation is processed.
- The Customer is responsible for any consent required for storing or reading information on a Visitor's device beyond what is strictly necessary to provide the conversation the Visitor requested, and for honoring the choices made in its own cookie or consent tools.
- The Customer will not instruct DSBC to process special categories of data under GDPR Article 9, sensitive personal information under the CCPA, consumer health data under Washington's My Health My Data Act or similar laws, particularly sensitive information under the Israeli Privacy Law, protected health information, or data of children, except under a separate signed addendum.
- The Customer will keep the in-widget AI disclosure, notice, and Start step enabled and link its own privacy policy.
- The Customer will obtain any marketing consent required before instructing DSBC to send Visitor email addresses to a marketing tool.
- The Customer will carry out any data protection impact assessment, privacy impact assessment, transfer assessment, or risk assessment that Data Protection Laws require of it, and will consult Supervisory Authorities where required.
4. DSBC obligations (GDPR Article 28(3))
- Instructions. DSBC processes Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required by law to do otherwise, in which case it will inform the Customer first unless the law prohibits it. The Terms, this DPA, and the Customer's configuration of the Service (including enabled integrations and deletions) are the Customer's complete instructions. DSBC will tell the Customer promptly if it believes an instruction infringes Data Protection Laws.
- Confidentiality. DSBC ensures that persons authorized to process Personal Data are bound by confidentiality.
- Security. DSBC implements the technical and organizational measures in Annex 2, as required by GDPR Article 32 and equivalent provisions of other Data Protection Laws, including the Israeli Protection of Privacy (Data Security) Regulations to the extent they apply to DSBC as a holder.
- Subprocessors. DSBC engages Subprocessors only as set out in Section 6.
- Data Subject requests. Taking into account the nature of the processing, DSBC assists the Customer by appropriate measures to respond to requests to exercise Data Subject rights. The Service lets the Customer view and delete call records. On the Customer's request to support@22floor.com, DSBC will locate, export, correct, or delete Visitor Data, including by searching for a Visitor's email address. If DSBC receives a request directly, it will forward it to the Customer without undue delay where it can identify the Customer, and will not respond itself except to direct the requester to the Customer.
- Assistance. DSBC assists the Customer with its obligations under GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments, and prior consultation) and equivalent provisions of other Data Protection Laws, including privacy impact assessments under the Quebec Privacy Act and risk assessments under the CCPA regulations, taking into account the information available to DSBC.
- Records. DSBC keeps a record of the processing it carries out for customers, as required by GDPR Article 30(2).
- Deletion or return. At the end of the Service, DSBC deletes or returns Personal Data as set out in Section 9.
- Audits. DSBC makes available the information necessary to demonstrate compliance with this DPA and allows for audits as set out in Section 8.
5. No independent use
- DSBC will not use Personal Data for its own purposes. In particular, DSBC will not use transcripts, intake answers, or other Personal Data to train, fine-tune, or improve any AI model, to build profiles of Visitors, to target advertising, or to enrich other datasets, and will not combine it with personal data from other customers or sources, except as allowed by the CCPA regulations for a permitted business purpose such as security and fraud prevention.
- DSBC does not create voiceprints or other biometric identifiers or templates from Visitor audio, does not store audio, and does not use the Service to identify Visitors by their voice or to recognize emotions.
- DSBC requires its AI Subprocessors to process Personal Data only to provide their services to DSBC, and uses them under API terms under which inputs and outputs are not used to train their models.
- DSBC may create operational metrics that contain no conversation content and do not identify any person (such as call counts, durations, and error rates) to operate, bill for, and maintain the Service.
6. Subprocessors
- The Customer gives general authorization for DSBC to engage the Subprocessors listed at voice.22floor.com/legal/subprocessors.html. Integrations the Customer enables (such as Klaviyo or a webhook) are recipients chosen by the Customer, not DSBC Subprocessors, and the Customer's own contract with that provider governs the data once it is delivered.
- DSBC will give at least 30 days' notice of a new or replacement Subprocessor by updating the list and emailing the account owner. The Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid unused fees. In an emergency, such as a provider outage or security issue, DSBC may replace a Subprocessor at once and will give notice as soon as possible.
- DSBC imposes data protection obligations on each Subprocessor that are no less protective than this DPA, as required by GDPR Article 28(4), and remains liable to the Customer for its Subprocessors' performance.
7. Personal Data Breach
- DSBC will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. This is designed to let the Customer meet short regulatory deadlines, such as 72 hours under the GDPR, three working days under the ANPD's incident regulation in Brazil, and prompt reporting under the Israeli Data Security Regulations.
- The notice will describe, as far as then known, the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. DSBC will provide further information as it becomes available, take reasonable steps to contain and remedy the breach, and give the Customer what it reasonably needs to assess the breach, including under Australia's Notifiable Data Breaches scheme.
- Notification is not an admission of fault. The Customer is responsible for notices to Supervisory Authorities and Data Subjects that apply to it as Controller, and DSBC will not notify them on the Customer's behalf unless required by law or agreed.
8. Audits
- On written request, no more than once a year, DSBC will answer a reasonable security questionnaire and provide a summary of its security measures and any relevant third-party certifications or reports of its Subprocessors.
- If that is not sufficient to show compliance, or if a Supervisory Authority requires it, the Customer may carry out an audit, at its cost, on at least 30 days' notice, during business hours, in a way that does not disrupt operations or expose other customers' data, by an auditor bound by confidentiality. This section is how the parties will meet Clause 8.9 of the SCCs.
9. Retention, deletion, and return
- DSBC automatically deletes Visitor transcripts and call records, including AI summaries, 90 days after the call, or sooner if the Customer deletes them. Purchase records are deleted 90 days after the purchase; when a call is deleted sooner, its purchase keeps no link to the call and no email address. Short-lived abuse limit counters, including IP addresses, expire within 2 days. DSBC does not store call audio.
- On termination, the Customer may request an export of Personal Data for 30 days. DSBC then deletes it from the live Service within 30 days and from backups within a further 30 days, unless law requires DSBC to keep it, in which case DSBC will protect it and process it only as the law requires. On request, DSBC will confirm deletion in writing.
10. International transfers
- DSBC and its Subprocessors process Personal Data in the United States, in Israel (for DSBC staff access), and in the other locations listed on the subprocessor page. The Customer authorizes these transfers.
- EEA. For transfers of Personal Data from the EEA to DSBC in a country without an adequacy decision, the SCCs are incorporated by reference and completed as follows: Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor; Clause 7 (docking clause) applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 6 of this DPA; the optional language in Clause 11 does not apply; in Clause 13, the supervisory authority is the one determined under that Clause; in Clause 17, Option 1 applies and the law of Ireland governs; in Clause 18, the courts of Ireland have jurisdiction; Annex I is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by the subprocessor list. The Customer is the data exporter and DSBC is the data importer. Transfers to Israel rely on the European Commission's adequacy decision for Israel.
- UK. For transfers from the UK, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0, in force March 21, 2022, as it may be revised) applies, with Tables 1 to 3 completed by this DPA and either party able to end it as allowed under Table 4.
- Switzerland. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the FADP, the competent authority being the Swiss Federal Data Protection and Information Commissioner, and "member state" including Switzerland, so that Data Subjects in Switzerland can enforce their rights there.
- Brazil. For transfers of Personal Data subject to the LGPD to a country without an ANPD adequacy decision, the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024 are incorporated without change, with the Customer as exporter and DSBC as importer, and prevail over this DPA for those transfers. A signed copy is available on request.
- Israel. For transfers from Israel, DSBC undertakes, as required by the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001, to take adequate measures to protect the Personal Data and not to transfer it onward to any person except its Subprocessors bound by the same obligations.
- Canada, including Quebec. DSBC will protect Personal Data transferred from Canada with a level of protection comparable to that required under PIPEDA and the Quebec Privacy Act, and will give the Customer the information it reasonably needs to complete the assessment required by section 17 of the Quebec Privacy Act.
- Australia. DSBC will handle Personal Data subject to the Privacy Act 1988 in a way consistent with the APPs (other than APP 1), so that the Customer can meet APP 8.
- Other countries. Where other Data Protection Laws (such as those of Japan, Singapore, or India) require specific measures for transfers, DSBC will protect Personal Data to a standard comparable to that law and cooperate with the Customer to put any required terms in place.
- DSBC ensures onward transfers to Subprocessors are covered by the SCCs, or by the EU-US Data Privacy Framework (and its UK and Swiss extensions) where the Subprocessor is certified. If a transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.
- If DSBC receives a government request for Personal Data, it will, where legally allowed, notify the Customer, challenge the request where there are reasonable grounds, and disclose only the minimum required.
11. CCPA and US state privacy law terms
For Personal Data subject to the CCPA, DSBC is a Service Provider, and the Customer discloses Personal Data to DSBC only for the limited and specified Business Purposes of providing the Service described in the Terms and Annex 1 (performing services on the Customer's behalf, security and integrity, and debugging). DSBC:
- will not Sell or Share Personal Data;
- will not retain, use, or disclose Personal Data for any purpose, including any commercial purpose, other than those Business Purposes, or as otherwise permitted by the CCPA and its regulations;
- will not retain, use, or disclose Personal Data outside the direct business relationship between DSBC and the Customer;
- will not combine Personal Data with personal information it receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by the CCPA regulations;
- will comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses;
- grants the Customer the right to take reasonable and appropriate steps to ensure DSBC uses Personal Data consistently with the Customer's CCPA obligations, including through the audits in Section 8;
- will notify the Customer if it determines it can no longer meet its CCPA obligations, and the Customer may then take reasonable and appropriate steps to stop and remediate unauthorized use, including by suspending transfers or terminating the Service;
- will assist the Customer in responding to consumer requests, including by deleting, correcting, or providing access to Personal Data on the Customer's instruction;
- will give the Customer information it reasonably needs for any risk assessment, cybersecurity audit, or automated decisionmaking technology requirement under the CCPA regulations that applies to the Customer;
- will require any Subprocessor to meet these same obligations in a written contract.
For other US state privacy laws (such as those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island), DSBC acts as a processor, follows the Customer's instructions, keeps Personal Data confidential, deletes or returns it at the end of the Service, makes available information needed to demonstrate compliance, allows reasonable assessments, and binds Subprocessors to the same obligations by written contract with notice to the Customer and an opportunity to object. DSBC certifies that it understands and will comply with the restrictions in this Section.
12. Other jurisdictions
- Quebec. This DPA is the written mandate required by section 18.3 of the Quebec Privacy Act. DSBC will use Personal Data only for the mandate, will not keep it after the mandate ends, and will notify the Customer's person in charge of the protection of personal information without delay of any violation or attempted violation of confidentiality.
- Israel. DSBC acts as a holder of the Customer's database. This DPA sets out the matters required by regulation 15 of the Protection of Privacy (Data Security) Regulations, including the permitted data and purposes (Annex 1), the security measures (Annex 2), confidentiality, return and deletion (Section 9), and incident reporting (Section 7). DSBC will provide an annual report on its compliance with these obligations on request.
- Brazil. DSBC acts as an operator under the LGPD and processes Personal Data according to the Customer's lawful instructions.
- Singapore and India. DSBC acts as a data intermediary or data processor, protects Personal Data with reasonable security arrangements, keeps it only as long as instructed, and notifies the Customer of breaches as set out in Section 7.
13. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow such limits toward Data Subjects. This DPA lasts as long as DSBC processes Personal Data for the Customer.
Annex 1: Details of processing
- Parties. Data exporter: the Customer, at the contact details in its account, acting as controller (or processor). Data importer: DSBC LLC, [MAILING ADDRESS], support@22floor.com, acting as processor (or subprocessor). Signature and date: by acceptance of the Terms.
- Categories of Data Subjects. Visitors to the Customer's websites and hosted pages who use an Agent. Customer staff who test Agents.
- Categories of Personal Data. Voice audio (processed in real time, not stored by DSBC); conversation transcripts; answers to intake questions; name and email address if provided; website, page, and traffic source; the version and time of the notice accepted; call timing and interaction events (cards and offers shown or clicked); AI-written summaries or assessments; a random device ID; IP address (in short-lived abuse counters only). If the Customer turns on purchase tracking: order number, total, currency, and discount codes of purchases matched to a call, a random first-party visitor ID and call reference (stored as a hash with the call), and the email address only when it matches the one the Visitor typed in the call (otherwise a salted hash).
- Sensitive data. None intended. The Customer must not configure the Service to collect it. Visitors may volunteer it in conversation. Safeguards: the notice asks Visitors not to share sensitive information; masking of email addresses and long number sequences in stored transcripts; restricted access; automatic deletion after 90 days; deletion of individual calls on demand.
- Frequency. Continuous, for each conversation.
- Nature and purpose. Real-time speech recognition and generation for AI sales conversations; answering questions from the Customer's knowledge; extracting intake answers; writing summaries (labeled as AI) and assessments; matching purchases to calls when the Customer turns on purchase tracking, honoring cookie consent where the Customer asks for it and Global Privacy Control always; storing and displaying transcripts and analytics to the Customer; sending data to integrations the Customer enables; abuse prevention and security.
- Retention. As in Section 9.
- Subprocessors. As listed on the subprocessor page, for the purposes and locations shown there.
Annex 2: Technical and organizational security measures
- Encryption. TLS for all data in transit, including WebRTC audio (DTLS-SRTP). Data at rest encrypted by the hosting provider (Cloudflare).
- Consent gate. No microphone access or audio transfer until the Visitor taps Start after seeing the AI disclosure and notice. The notice version and call start time are stored with each call.
- Data minimization. No audio storage. No voiceprints or biometric templates. IP addresses kept only in abuse counters that expire within 2 days and are never stored with transcripts. Email addresses and long number sequences masked in stored transcripts. Automatic daily deletion of transcripts and call records older than 90 days.
- Access control. Workspace separation on every query. Role-based access. Staff access to production data limited to named personnel who need it for support or security, with multi-factor authentication on provider accounts. Passwords stored as salted PBKDF2 hashes. Session cookies marked HttpOnly, Secure, and SameSite.
- Application security. Per-call tokens, optional domain allowlists for embedded Agents, per-device, per-network, per-day, and per-workspace rate limits, call length caps, input size limits, and short-lived credentials for voice sessions so API keys never reach the browser.
- Secrets management. API keys stored as encrypted environment secrets, not in code, and rotated on staff changes or suspected exposure.
- Logging. Operational logs avoid conversation content and personal data where practical and are retained for a short period.
- Resilience. Managed database with point-in-time recovery. Globally distributed hosting with DDoS protection.
- Vendor management. Subprocessors bound by written data protection terms, and AI providers used under business API terms with no training on inputs or outputs.
- Incident response. A documented process to detect, contain, investigate, and notify, with the timelines in Section 7.
- Personnel. Confidentiality obligations and privacy and security training for anyone with access to Personal Data.