Data Processing Agreement (DPA) — Callio
Effective date: 2026-06-04 · Last updated: 2026-06-16
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Callio Terms of Service (the "Terms") between Wojciech Szymański (Alchemicy AI) ("Callio", "we", "us", "Processor", "service provider") and the business customer that accepts the Terms (the "Customer", "you", "Controller", "business"). It governs Callio's Processing of Personal Data on the Customer's behalf in connection with the Callio AI voice receptionist, scheduling, and call-handling service (the "Service").
You accept this DPA when you accept the Terms — including by clicking to accept at onboarding or by using the Service. Where this DPA conflicts with the Terms with respect to the Processing of Personal Data, this DPA controls.
1. Definitions and roles
- "Personal Data", "Processing", "Controller", "Processor", "data subject", and "personal data breach" have the meanings given under Applicable Data Protection Law.
- "Applicable Data Protection Law" means all privacy and data-protection laws applicable to the Processing, including the U.S. state privacy laws (the California Consumer Privacy Act as amended by the CPRA and its regulations ("CCPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), and analogous laws in Oregon, Texas, New Jersey, New Hampshire, Montana, and other states), and, where applicable, the EU/UK GDPR.
- Under the CCPA, the Customer is the "business" and Callio is a "service provider" (and, to the extent any Personal Data is "made available" rather than "disclosed", a "contractor"). Under the VCDPA, CPA, CTDPA, and GDPR, the Customer is the Controller and Callio is the Processor.
- The Customer is, and at all times remains, the Controller / business for all caller Personal Data collected, recorded, transcribed, or generated through the Service (including call audio, transcripts, summaries, caller phone numbers, and appointment details). Callio Processes such Personal Data solely on the Customer's behalf to provide the Service.
2. Subject-matter and scope
This DPA applies to all Processing of Personal Data that Callio carries out on the Customer's behalf under the Terms. The subject-matter, nature, purpose, categories of Personal Data, categories of data subjects, and duration of Processing are described in Annex A. Annex B lists the authorized Subprocessors.
3. Processing only on documented instructions
- Callio will Process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Callio will, where legally permitted, inform the Customer of that legal requirement before Processing).
- The Terms, this DPA, the Customer's configuration of the Service (agent setup, retention settings, integrations), and the Customer's use of the dashboard and APIs constitute the Customer's complete and final documented instructions to Callio for the Processing of Personal Data. Additional or different instructions must be agreed in writing.
- Callio will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Purpose limitation
- Callio will Process Personal Data only for the limited and specified business purpose(s) of providing, maintaining, supporting, and securing the Service (i.e., answering calls, transcribing and summarizing them, recognizing returning callers for the Customer, booking and managing appointments, and related operational and billing functions), as further described in Annex A.
Callio will not Process Personal Data for any other purpose, and specifically:
- will not sell Personal Data and will not share it for cross-context behavioral advertising (as "sell" and "share" are defined in the CCPA);
- will not retain, use, or disclose Personal Data for any purpose other than the business purpose(s) specified in this DPA, or as otherwise permitted by the CCPA;
- will not retain, use, or disclose Personal Data for any commercial purpose other than the specified business purpose(s);
- will not retain, use, or disclose Personal Data outside the direct business relationship between Callio and the Customer;
- will not combine Personal Data received under this DPA with Personal Data received from, or on behalf of, any other source, or collected from Callio's own interaction with the data subject, except as the CCPA permits for a business purpose;
- will not use call audio, transcripts, summaries, or caller data to develop, train, fine-tune, or improve any Callio (or third-party) generalized or foundation AI/ML model or any other product or service, and will not perform cross-customer analytics on call content.
5. CCPA service-provider / contractor certification
Callio certifies that it understands the restrictions in Section 4 and elsewhere in this DPA and will comply with them. Callio will provide the same level of privacy protection for Personal Data as the CCPA requires of the Customer, and will comply with the applicable obligations of the CCPA and other Applicable Data Protection Law. The Customer may take reasonable and appropriate steps under Section 11 to help ensure that Callio uses Personal Data consistently with the Customer's obligations, and (upon notice) reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.
6. Confidentiality
Callio ensures that each person it authorizes to Process the Personal Data (employees, contractors, and agents) is subject to a duty of confidentiality (whether contractual or statutory) and Processes the Personal Data only as necessary to perform under the Terms.
7. Security
Callio will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data — including recorded call audio, transcripts, summaries, and caller profiles — against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. These measures currently include encryption of data in transit, hashed credentials, role-based access controls, JWT-based authentication, tenant isolation, and encrypted storage of integration tokens, as further described in the Privacy Policy. Callio may update its measures provided the level of protection is not materially decreased.
8. Subprocessors
- The Customer authorizes Callio to engage the Subprocessors listed in Annex B to Process Personal Data, and generally authorizes Callio to engage additional Subprocessors subject to this Section.
- Callio will impose on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, including the relevant CCPA service-provider/contractor restrictions and the obligation to Process Personal Data only as needed to provide the contracted service. Callio remains responsible for its Subprocessors' performance.
- Callio will give the Customer reasonable prior notice (e.g., via the Privacy Policy, the dashboard, or email) of the addition or replacement of a Subprocessor, giving the Customer an opportunity to object on reasonable data-protection grounds. If the Customer reasonably objects and the parties cannot resolve the objection, the Customer may terminate the affected Service as its sole remedy.
9. Assistance with data-subject / consumer requests
Taking into account the nature of the Processing, Callio will provide reasonable assistance to the Customer, by appropriate technical and organizational measures and insofar as possible, to enable the Customer to respond to and fulfill data-subject / consumer requests under Applicable Data Protection Law — including requests to know/access, delete, correct, opt out of sale/share, and limit the use of sensitive personal information — for Personal Data Callio holds on the Customer's behalf. If Callio receives such a request directly from a data subject, it will, where permitted, refer the requester to the relevant Customer and not respond independently except to confirm the request relates to the Customer.
10. Personal-data breach and security assistance
- Callio will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Personal Data Processed on the Customer's behalf, and will provide information reasonably available to it to help the Customer meet its own breach-notification obligations.
- Taking into account the nature of Processing and the information available to Callio, Callio will provide reasonable assistance to the Customer with the Customer's obligations regarding security of Processing and breach notification to authorities and data subjects.
11. Audit, information, and demonstration of compliance
- Upon the Customer's reasonable written request (no more than once every 12 months, except following a personal-data breach or where required by a regulator), Callio will make available information in its possession reasonably necessary to demonstrate compliance with this DPA.
- Callio will allow for and contribute to reasonable assessments by the Customer or an auditor mandated by the Customer, or — at Callio's option — arrange a qualified independent assessor to assess Callio's policies and measures and make the report available to the Customer on request. Assessments must occur on reasonable notice, during business hours, subject to confidentiality, and without unreasonably disrupting Callio's operations.
12. Notice of inability to comply
Callio will notify the Customer promptly if it makes a determination that it can no longer meet its obligations under Applicable Data Protection Law (including its CCPA service-provider/contractor obligations). Upon such notice, or where the Customer reasonably determines Callio is engaged in unauthorized Processing, the Customer may direct Callio to take reasonable and appropriate steps to stop and remediate the unauthorized Processing.
13. Deletion or return of Personal Data
On termination or expiry of the Service, and at the Customer's choice, Callio will delete or return all Personal Data Processed on the Customer's behalf, and delete existing copies, unless retention is required by law. In the ordinary course, End-Caller call recordings, transcripts, summaries, and per-caller profiles are deleted or anonymized per the retention period in the Privacy Policy (up to 12 months, or a shorter period the Customer configures). Backup copies are deleted in line with Callio's backup-rotation schedule.
14. International transfers
Callio and its Subprocessors may Process Personal Data in the United States, the EU/EEA, and elsewhere. Where Applicable Data Protection Law requires, such transfers will be made under appropriate safeguards (e.g., the EU Standard Contractual Clauses or other lawful transfer mechanism).
15. Liability and roles
Nothing in this DPA relieves either party of the liabilities or obligations imposed on it in its own role (business/Controller or service-provider/Processor) under Applicable Data Protection Law. The limitations and exclusions of liability in the Terms apply to this DPA to the maximum extent permitted by law.
16. Governing law; order of precedence
This DPA is governed by the law and venue stated in the Terms (the laws of Poland; competent courts of Poland), provided that the CCPA and other U.S. state privacy laws apply to the Processing of the Personal Data of the relevant states' residents as set out herein. In case of conflict regarding the Processing of Personal Data, the order of precedence is: (1) this DPA, (2) the Terms, (3) the Privacy Policy.
Annex A — Description of Processing
- Roles: Customer = Controller / business; Callio = Processor / service provider (contractor where applicable).
- Subject-matter: Processing of Personal Data to provide the Callio AI voice receptionist, transcription, summarization, returning-caller recognition, and appointment-scheduling Service.
- Nature and purpose of Processing: receiving and answering the Customer's inbound business calls with an automated AI assistant; recording and transcribing calls; generating AI summaries for the Customer; maintaining per-caller profiles so the Customer can recognize returning callers; creating, updating, and cancelling appointments (including, where the Customer enables it, on the Customer's own Google Calendar); delivering in-app notifications to the Customer; and related hosting, security, support, and billing.
- Categories of Personal Data:
- Call content: audio recordings and transcripts of calls; AI-generated call summaries.
- Caller identifiers & details: caller phone number; caller name; and other details the caller provides (e.g., pet/owner details, vehicle/appointment details, reason for the call).
- Appointment data: appointment date/time, service type, and related booking details (and, where enabled, the corresponding Google Calendar event data, scope
calendar.events.owned).
- Customer account data: business contact name, business name, business phone number, email, hashed credentials, billing metadata (card data is handled by Stripe; Callio does not store card numbers), and usage data.
- Special / sensitive categories: Callio does not seek special-category or sensitive Personal Data. Callers may volunteer such information in free-form conversation; Callio does not use it beyond providing the Service and does not create voiceprints or any voice biometric identifiers (see the Biometric Data Policy).
- Categories of data subjects: the Customer's End Callers (members of the public who call the Customer's business) and the Customer's own personnel/account users.
- Frequency of Processing: continuous, for the duration of the Service.
- Duration of Processing: the term of the Customer's subscription, plus the retention period stated in the Privacy Policy, after which Personal Data is deleted or anonymized unless retention is required by law.
Annex B — Authorized Subprocessors
Subprocessor list as of 2026-06-16. We will give prior notice of additions or changes as set out in Section 8.
| Subprocessor | Purpose | Location |
| Twilio | Telephony and phone numbers | United States |
| ElevenLabs | AI voice / conversational AI + transcription | United States |
| Anthropic (Claude) | Call summarization | United States |
| Stripe | Payments (card data; Callio does not store card numbers) | United States |
| Hetzner | Hosting / infrastructure | Germany (EU) |
| Google | Optional Google Calendar integration (scope calendar.events.owned), only if the Customer connects it | United States / EU |
Callio will update this Annex and provide notice of changes as described in Section 8.
Wojciech Szymański (Alchemicy AI), Poznań, Poland · [email protected]