Legal
Data Processing Addendum
Last updated: August 26, 2026
Purpose of This Addendum
This Data Processing Addendum, referred to in this document as the "DPA," sets out the terms under which Vampo, operator of ReceptionEase and referred to in this document as the "Processor," "we," or "us," processes personal data on behalf of a business using the Service, referred to in this document as the "Client" or "Controller," and addressed directly as "you" in the Terms of Service and Privacy Policy. Its purpose is to define, in a single document, each party's responsibilities regarding the personal data that passes through the Service, including, but not limited to, callers' and contacts' information, and the safeguards, notifications, and rights that apply to that data.
The ReceptionEase website, our AI-powered virtual answering platform, and the support services we provide to Clients are together referred to in this document as the "Service." This DPA governs the Processing of personal data in connection with the Service, in accordance with applicable Data Protection Laws.
This DPA forms part of both the Terms of Service and the Privacy Policy, and takes effect automatically when the Client creates an account or otherwise uses the Service. The Terms of Service, the Privacy Policy, and this DPA are together referred to in this document as the "Legal Terms." The Client's acceptance of the Legal Terms supersedes any prior agreements or understandings between the Client and the Processor regarding the Service. A standalone signed copy of this DPA is available on request by writing to contact@receptionease.com.
1. Definitions
- Personal data means any information relating to an identified or identifiable natural person, including, but not limited to, a caller's name or phone number.
- Processing means any operation performed on personal data, including, but not limited to, its collection, storage, use, disclosure, or deletion.
- Data subject means the natural person to whom personal data relates, including, but not limited to, a Controller's callers, contacts, and personnel.
- Sub-processor means a third party engaged by the Processor to process personal data in connection with the Service.
- Personal data breach means an incident resulting in the accidental or unlawful loss, alteration, or unauthorized disclosure of, or access to, personal data.
- Applicable law means Albanian Law No. 124/2024 "On the Protection of Personal Data," together with applicable United States federal and state privacy laws, including, but not limited to, the California Consumer Privacy Act as amended by the California Privacy Rights Act, referred to in this document as the "CCPA." Section 20 sets out how these laws apply together.
2. Roles of the Parties
The Client acts as the Controller and determines the purposes and means of processing personal data through the Service. The Processor processes personal data solely to provide the Service and only on the Controller's instructions.
The Processor will not use personal data for its own purposes, will not sell or share it, and will not disclose it for advertising purposes. The Processor will not retain, use, or disclose personal data outside the scope of providing the Service, except where required by law.
Where the Processor considers that an instruction from the Controller would infringe applicable law, it will notify the Controller promptly rather than carry out that instruction.
This DPA remains in effect for as long as the Processor processes personal data on the Controller's behalf under the parties' agreement. Refer to Section 12 for what occurs to the Controller's personal data once the Controller ceases to use the Service.
3. Nature and Scope of Processing
Processing activities. In providing the Service, the Processor's processing activities include, but are not limited to, the following:
- Answers, routes, and forwards inbound calls placed to the Controller's business.
- Records calls, and generates call summaries and text transcripts using speech-to-text and artificial intelligence technology.
- Books clients, including, but not limited to, creating a dedicated calendar in the Controller's Google account and writing appointment events to it, as described below.
- Stores contact records provided by the Controller or its callers.
- Sends SMS and MMS text message alerts to the mobile number the Controller nominates, as described below.
- Sends the Controller follow-up messages arising from calls with the Processor, independently of account notifications, as described below.
- Processes billing and subscription information for the Controller's account.
Data subjects. The Controller's callers and contacts, the Controller's personnel, and, where applicable, the Controller's own customers referenced in call or appointment records.
Categories of personal data. The categories of personal data processed include, but are not limited to, the following:
| Category | Examples (non-exhaustive) |
|---|---|
| Account and personnel data | Name, business email, phone number, the mobile number nominated for SMS and MMS text message alerts and the record of consent to receive them, hashed password, role |
| Callers and contacts | Name, phone number, email address, notes |
| Call content | Audio recordings, AI-generated summaries, intent and urgency classifications, text transcripts |
| Appointment data | Contact name, date and time, service type, calendar event details |
| Billing data | Plan, payment status, and invoices (payment card details are handled by the Processor's payment processor and are not stored by the Processor) |
| Usage and technical data | IP address, browser or device type, authentication tokens, server logs |
Sources of personal data. Personal data reaches the Processor through several distinct channels. It may be entered directly by the Controller or its personnel when configuring or operating the Service; it may be provided by individuals who call the Controller's business; it may be produced by the Service itself in the course of operation, including, but not limited to, a call summary or transcript; or it may be collected automatically as a byproduct of the Controller's ordinary use of the Service. This description is illustrative rather than exhaustive.
Call recordings. The Processor records calls handled on the Controller's behalf and retains both the audio recording and a text transcript, which is what allows the Service to generate call summaries and support the Controller's dashboard. The audio recording is retained for up to 6 months from the date of the call on a fixed schedule, as described in Section 12; the text transcript is not subject to that 6-month limit and is instead retained under the general rule in Section 12. At the outset of every call, before the caller reaches the receptionist, the Processor informs the caller that the call is recorded and transcribed. That disclosure is delivered by the Service on every call and cannot be disabled, removed, or modified, and it is the mechanism by which consent is obtained in jurisdictions requiring the consent of every party to the call. The Controller remains responsible for any disclosure or consent required of it in addition to that disclosure, and for giving effect to a caller's request not to be recorded.
Text message alerts. The Service sends SMS and MMS text message alerts to the mobile number the Controller nominates, telling it when a visit request taken by the receptionist is confirmed for dispatch, and giving the customer's name, contact number, the agreed time, and the job and service address. Alongside these account notifications, the Processor sends the Controller follow-up messages arising from a call with the Processor or from something the Controller consented to. Those can include, but are not limited to, a follow-up to the call, a meeting link, a solicited link or demo for a product the Controller asked for or agreed to receive on the call, or an answer to something the Controller asked. These are transactional messages relating to the Controller's account and are not unsolicited marketing. The Processor records the Controller's agreement to receive them, the wording shown at the time, and the date and time it was given, and retains that record as described in Section 12. The Controller may stop the alerts at any time by any reasonable means. The messages are delivered through a messaging sub-processor engaged under Section 9.
Google account data. Where the Controller connects a Google account, the Processor acts on the Controller's instruction to create one dedicated calendar named "ReceptionEase" in that account and to write, update, and delete appointment events within it. The Processor holds the credentials issued by Google, the identifier of the calendar it created, and the email address of the connected account. The permission requested is limited to calendars the Processor itself creates, so no other calendar in the Controller's Google account is accessible to the Processor. The Processor does not sell data received from Google APIs, use it for advertising, or use it to develop, improve, or train generalized artificial intelligence or machine learning models, and its use and transfer of that data adheres to the Google API Services User Data Policy, including the Limited Use requirements. On disconnection the Processor deletes that calendar, the events within it, and the stored credentials.
The Processor does not intentionally collect special or sensitive categories of personal data, and the Controller must not transmit such data through the Service.
4. Obligations of the Processor
The Processor shall:
- Process personal data only on the Controller's documented instructions, including, but not limited to, this DPA and the Controller's configuration of the Service, unless otherwise required by law.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations and receive appropriate training.
- Implement the security measures described in Section 10.
- Engage sub-processors only in accordance with Section 9.
- Provide reasonable assistance to the Controller in responding to data subject requests, as described in Section 7.
- Provide reasonable assistance to the Controller in meeting its own obligations regarding security, breach notification, and data protection assessments.
- Delete or return personal data upon termination of the Service, as described in Section 12.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and permit audits as described in Section 13.
- Refrain from selling or sharing personal data, and refrain from using or disclosing it beyond the scope of providing the Service, in accordance with the CCPA and comparable laws.
5. Obligations of the Controller
The Controller warrants that:
- It has a valid legal basis for the personal data it processes through the Service, and has provided any required notices and obtained any required consents. Consent to the recording of calls is addressed by the disclosure the Service itself delivers on every call, as described in Section 3. The Controller remains responsible only for any disclosure or consent required of it in addition to that disclosure, and for giving effect to a caller's request not to be recorded.
- Where it nominates a mobile number belonging to any person other than itself to receive text message alerts, it has that person's agreement to receive them, and it will remove the number when that agreement is withdrawn.
- Its instructions to the Processor, and any personal data it supplies, comply with applicable law.
- It is responsible for the accuracy and lawfulness of the personal data it provides.
- Where it operates its own website, mobile application, or other digital tool that connects to the Service, it keeps a privacy notice on that tool that meets the standard required by law, and separately informs and gains consent from individuals whose data it gathers there.
- It is responsible for responding to requests from data subjects and supervisory authorities concerning personal data processed through the Service, with the Processor's assistance as described in Section 7.
6. Processor Personnel
Access to personal data is limited to Processor personnel who require it to perform their duties. Such personnel are subject to confidentiality obligations and receive training on data protection principles.
7. Data Subject Requests
Where the Processor receives a request from a data subject to access, correct, or delete personal data, it will not respond to that request directly. Instead, it will notify the Controller within 5 business days, so that the Controller may respond in its capacity as Controller.
Where the Controller instructs the Processor to assist with a request, including, but not limited to, exporting or deleting specified records, the Processor will do so within 30 calendar days, or sooner where necessary for the Controller to meet its own statutory deadline (45 days under the CCPA, for example).
Where the Service provides self-service tools for managing contact records, the Controller should use those tools directly.
8. Government and Law Enforcement Requests
A government agency, law enforcement body, or court may occasionally direct a demand for personal data at the Processor rather than the Controller, whether through a subpoena, warrant, court order, or similar instrument. When this happens, the Processor's first step is to point the requesting party toward the Controller, since the Controller is best placed to respond, and the Processor may pass along the Controller's contact details for that purpose. If the Processor has no choice but to comply, it will do what it reasonably can to warn the Controller ahead of time so the Controller has a chance to challenge the request or seek a court order limiting it, unless doing so would itself be against the law.
9. Sub-processors
The Controller acknowledges and agrees that the Processor relies on third-party sub-processors to help deliver the Service. Upon a reasonable, documented request tied to the Controller's own compliance obligations or a comparable legitimate purpose, the Processor will disclose details of its current sub-processors to the Controller.
The Processor's relationship with each sub-processor is governed by an agreement formed by accepting that sub-processor's own terms of service and, where offered, its standard data processing terms, in the same way a Client enters into this DPA by using the Service. Each sub-processor's access to personal data is limited to what its specific function requires, and no sub-processor is permitted to use personal data for its own promotional or marketing purposes, or to disclose it beyond what is necessary to perform that function. Regardless of which sub-processor is involved, the Processor remains fully responsible to the Controller for how that sub-processor handles personal data.
10. Security Measures
The Processor maintains technical and organizational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the risk presented by the Processing. These measures address areas including, but not limited to, credential and account protection, encryption of data in transit, restricted and role-based access to systems and data, ongoing maintenance of the Processor's infrastructure, and routine data backups.
The Processor reviews these measures at least annually and following any security incident, and updates them whenever necessary.
11. Personal Data Breaches
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe, to the extent known, information including but not limited to: the nature of the breach; the categories and approximate number of affected data subjects and records; the likely consequences; and the measures taken or proposed in response. The Processor will provide further information as it becomes available.
The Controller is responsible for notifying any supervisory authority, regulator, or affected data subjects where required by applicable law.
12. Data Retention and Deletion
Audio call recordings are retained for up to 6 months from the date of the call, after which they are automatically and permanently deleted. This 6-month limit applies only to the audio recording, on a fixed schedule, regardless of the status of the Controller's subscription and regardless of when or whether the Controller deletes its account.
All other personal data (including, but not limited to, contacts, call transcripts, call summaries, appointment data, and business information) is retained for as long as the Controller's account remains active. Cancelling the Controller's subscription alone does not trigger deletion of this data.
Upon deletion of the Controller's account, the Processor will permanently delete all remaining personal data within 30 calendar days. Two categories sit outside that 30 day window, and nothing else does.
Audio call recordings continue on the fixed 6-month schedule described above. A recording made shortly before the account was deleted is therefore deleted at the end of its own 6 months rather than within the 30 days.
Records the Processor is required by law to retain, being the Controller's billing and tax records and the record of the Controller's consent to receive text message alerts. The consent record is retained for four years after the account closes, and billing and tax records for as long as tax law requires. These records are kept only for those purposes, are never used to contact the Controller, and are deleted once the period ends. The Processor restricts further processing of them accordingly. Where any other longer retention period is required by law, the Processor will inform the Controller.
Upon request, the Processor will confirm deletion in writing.
13. Audits
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA. The Controller may request a more extensive audit no more than once every 12 months, absent a documented breach or legal requirement necessitating a more frequent review, upon 30 days' written notice, during normal business hours, and subject to confidentiality safeguards. Such audits may be satisfied through a recent security report, questionnaire response, or documented review, at the Processor's discretion, in lieu of an on-site inspection.
14. International Transfers
Personal data is stored on the Processor's database, hosted on cloud infrastructure located in the United States. The Processor's sub-processors are also located in the United States, and process personal data solely for the specific functions they perform. The Processor will not transfer personal data to a new jurisdiction without an appropriate safeguard in place.
15. United States Privacy Law
For purposes of the CCPA and comparable state laws, the Processor acts as a "service provider" and not a "third party." A data subject covered by the CCPA and comparable state laws may hold statutory rights that include, but are not limited to, obtaining access to their data, having inaccurate data corrected, requesting its deletion, declining certain uses of it, and being free from discrimination for exercising any of the foregoing. The Processor does not sell or share personal data and does not use or disclose it beyond the scope of providing the Service. The Processor will notify the Controller if it determines it can no longer meet these obligations. The Controller may take reasonable steps, including, but not limited to, the audit rights in Section 13, to verify compliance and to address any unauthorized use.
16. Confidentiality
Each party will keep the terms of this DPA, and the personal data processed under it, confidential, and will not disclose them to third parties without the other party's prior written consent, except as required by law or a competent authority, or as necessary to enforce this DPA.
17. Liability
Liability arising under this DPA is subject to the limitations set out in the parties' agreement. Where a party has compensated a data subject or regulator for damage resulting from the other party's breach of this DPA or applicable law, it may seek indemnification from that party to the extent of its responsibility for the damage.
18. No Third-Party Beneficiaries
This DPA exists solely between the Controller and the Processor; a data subject, caller, or any other outside party gains no independent right to enforce it. A claim under this DPA can be pursued only against Vampo as the contracting Processor, not against a subsidiary, affiliate, or sub-processor individually. If Vampo faces a fine, penalty, or other liability tied to personal data because the Controller failed to meet its own duties under this DPA or applicable law, that amount offsets what Vampo would otherwise owe the Controller under the Agreement.
19. Amendments
This DPA may be updated whenever necessary to reflect changes to the Service, its sub-processors, or applicable law. Independently of any such update, the Processor will review this DPA at least once every six months to confirm it remains consistent with applicable law. When we make material changes to this DPA, we will notify the Controller when those changes take effect, the same as for material changes to the Terms of Service and the Privacy Policy.
20. Governing Law
This DPA is governed primarily by the laws of the Republic of Albania, consistent with the Terms of Service. Where United States federal or state privacy law, including, but not limited to, the CCPA, applies to personal data processed on the Controller's behalf, such law applies to the extent relevant to that data. In the event of a conflict between Albanian law and United States law on any matter addressed by this DPA, Albanian law shall prevail. Any dispute arising under this DPA is subject to the exclusive jurisdiction of the courts of Tiranë, Albania, without prejudice to any rights a data subject may separately hold under the law of their own jurisdiction.
If any provision of this DPA is held unenforceable, the remaining provisions remain in full force and effect.
21. Legal Effect
This DPA is legally binding on the Client once agreed to. Agreement is deemed given automatically, without any further action or signature, at the moment the Client creates an account or otherwise begins using the Service, as this DPA forms part of the Terms of Service to which such account creation constitutes acceptance.
22. Processing Outside This DPA
This DPA governs personal data that the Processor processes on the Controller's behalf. It does not govern the personal data of businesses the Processor contacts before they become Clients, including, but not limited to, a business contact's name and phone number and the record of any permission given on such a call to receive text messages. In respect of that data the Processor acts as a controller in its own right and not as a processor, no Controller instruction is involved, and the obligations in this DPA do not attach to it. That processing is described in Section 6 of the Privacy Policy, and it forms no part of the Service.
Nothing in this Section limits Section 3 or Section 9 in respect of personal data processed on the Controller's behalf.
23. Relationship to the Legal Terms
This DPA, the Terms of Service, and the Privacy Policy are equal parts of a single agreement, together forming the Legal Terms, and together constitute the entire agreement between the Controller and the Processor regarding the Service. None of the three documents takes precedence over the others. It does not reduce any protection given to the Controller or to data subjects under either of the other two documents. Where this DPA and the Privacy Policy address the same subject matter, they shall be read together and interpreted consistently; this DPA provides the additional detail specific to the Processor's processing of personal data on behalf of a business Controller. Should any provision of this DPA appear to conflict with the Terms of Service or Privacy Policy, all three documents making up the Legal Terms shall be interpreted, so far as possible, to give effect to all three.
Contact and Company Details
ReceptionEase is operated by:
Vampo Address: Rruga Ibrahim Rugova, Building No. 28, Entrance 9, Ap. 7, Tiranë, Albania 1019 Email: contact@receptionease.com
Inquiries regarding this DPA, requests for a signed copy, and data protection concerns may be directed to the email address above.