Data Processing Addendum
The Article 28 terms on which Adoptiv Inc processes personal data for its customers, including sub-processors, security, breach notice, audit and international transfers.
Adoptiv Inc · Updated 2026-08-03
01What this is and when it applies
This Data Processing Addendum forms part of the agreement between Adoptiv Inc and the customer for use of the Adoptiv platform. It applies whenever Adoptiv processes personal data on the customer's behalf.
The customer is the controller. Adoptiv Inc is the processor. Where the customer is itself a processor for someone else, Adoptiv is a sub-processor and this addendum applies as though references to the controller were to the customer's own controller.
Adoptiv Inc is the only Adoptiv contracting entity. It is a Delaware corporation at 2810 N Church St STE 88783, Wilmington, DE 19802, United States. There is no other group entity in the processing chain.
This addendum is offered on standard terms and is accepted when the customer accepts the Terms of Service at /legal/terms. A customer that needs a signed counterpart should write to legal@adoptiv.com and we will execute one. If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails.
Terms defined in the GDPR carry their GDPR meaning here. References to the GDPR include the UK GDPR as it forms part of UK law, and the Swiss Federal Act on Data Protection, each read with the modifications that law requires.
02Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the Adoptiv platform: programmable telephony and call recording, CRM records, connected email and calendar, workflow automation, and the AI features the customer switches on |
| Duration | The term of the agreement, plus the deletion window in the termination section below |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, transcription, analysis, transmission, disclosure to the sub-processors listed at /legal/sub-processors, erasure and destruction |
| Purpose | To deliver the platform to the customer, and for nothing else |
| Instructions | The agreement, this addendum, the configuration the customer sets in the product, and any further written instruction the customer gives |
Adoptiv processes personal data only on the customer's documented instructions, including on international transfers, unless a law it is subject to requires otherwise. If that happens, Adoptiv will tell the customer before processing, unless the law forbids the notice on important grounds of public interest.
Adoptiv will tell the customer if, in its opinion, an instruction infringes data protection law. Adoptiv may suspend the instruction until it is resolved.
03Categories of data subject and personal data
The customer decides what it puts into the platform, so this describes the categories the platform is built for rather than an exhaustive inventory.
| Category of data subject | Typical personal data |
|---|---|
| The customer's employees and authorised users | Name, business email, phone number, job title, role and permissions, authentication credentials, access and audit logs |
| The customer's contacts, leads and prospects | Name, phone numbers, email addresses, employer, job title, postal address, social profiles, custom fields the customer defines, consent and do-not-call status |
| Parties to a call handled through the platform | Phone numbers, call metadata, call recordings where recording is enabled, voicemail audio, transcripts and derived analysis |
| Correspondents in a connected mailbox | Message headers, bodies and attachments, calendar events and attendees, contact entries |
| The customer's billing contacts | Name, email, billing address and tax registration number |
Special categories of personal data. The platform is not designed for special category data within the meaning of Article 9, nor for children's data, payment card numbers, or government identifiers. The customer must not upload them, and must not configure recording or AI analysis in a way that is likely to capture them. If the customer needs to process special category data, it must agree that with Adoptiv in writing first.
Frequency. Processing is continuous for the term of the agreement.
04What the customer is responsible for
- Having a lawful basis for the personal data it puts into the platform, and for the calls, messages and campaigns it runs through it.
- Giving the notices and obtaining the consents its own law requires, including consent to record a call where the jurisdictions of the parties require it.
- Configuring the platform so that it processes only what the customer needs: retention periods, recording settings, which AI features are on, and who can see what.
- The accuracy of the data it uploads, and responding to its own data subjects.
- Keeping its user accounts and credentials secure, and removing users who leave.
Adoptiv provides the controls. Whether they are configured lawfully is the controller's decision, because only the controller knows the purpose.
05What Adoptiv is responsible for
- Processing only on documented instructions, as set out above.
- Confidentiality. Every person authorised to process the personal data is bound by a written duty of confidence that survives the end of their engagement. Access is granted on need, is tied to a named individual, and is logged.
- Security. The measures required by Article 32, described in the next section.
- Sub-processors. Engaging them only on the terms in the sub-processor section, and remaining fully liable to the customer for their performance.
- Assistance with data subject rights, as set out below.
- Assistance with the customer's obligations under Articles 32 to 36, including data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to Adoptiv.
- Deletion or return of the personal data at the end of the agreement.
- Making available the information needed to demonstrate compliance with Article 28, and allowing and contributing to audits, as set out below.
These are the Article 28(3) obligations. They flow down unchanged to every sub-processor Adoptiv engages.
06Security measures
Adoptiv implements appropriate technical and organisational measures under Article 32. The current measures are described at /legal/security-practices, which is incorporated into this addendum by reference and forms the Annex of technical and organisational measures for the purposes of the Standard Contractual Clauses.
The headline controls are these.
| Control | Measure |
|---|---|
| Encryption at rest | AES-256-GCM across databases, backups, call recordings and stored credentials |
| Encryption in transit | TLS for application and API traffic, SRTP for call media |
| Credential storage | OAuth tokens, mailbox passwords and provider API keys encrypted at rest and never returned by an API once stored |
| Tenant separation | Each customer's data is held in its own database schema |
| Access control | Role based permissions, multi-factor authentication, single sign-on through SAML 2.0 and OAuth 2.0, IP allow lists, rate limiting |
| Resilience | Redundant nodes, automatic failover, daily encrypted backups with point-in-time recovery |
| Testing | Third-party penetration testing and continuous vulnerability scanning, with a disclosure route at /legal/vulnerability-disclosure |
Adoptiv may change a measure, but will not reduce the overall level of security during the term.
A SOC 2 Type II examination is in progress. Adoptiv makes no other assurance claim in this addendum and will not describe a control as audited before it has been.
07Sub-processors
The customer gives Adoptiv general written authorisation to engage sub-processors, on these conditions.
- The current sub-processors are named at /legal/sub-processors, with what each one receives and whether it is on by default or only when the customer switches it on.
- Adoptiv gives at least 30 days' notice before adding or replacing a sub-processor. Notice is given by updating that page and emailing the addresses subscribed to it. Subscribe from the page.
- The customer may object on reasonable data protection grounds within those 30 days by writing to legal@adoptiv.com and explaining the grounds.
- If the objection is not resolved, the customer may terminate the affected part of the service without penalty and receive a pro rata refund of fees paid in advance for the unused period.
- Adoptiv imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this addendum, as Article 28(4) requires.
- Adoptiv remains fully liable to the customer for a sub-processor's failure to meet those obligations.
Sub-processors that are engaged only when the customer or the operator switches on a feature are marked as such on that page. A customer that leaves the AI features off does not have its data sent to any AI provider.
08Assistance with data subject requests
The platform lets the customer answer most requests without involving Adoptiv. An administrator can search, export, correct and delete records, export a contact's full history, and delete a call recording and its transcript.
If a data subject contacts Adoptiv directly about data belonging to a customer, Adoptiv will not respond to the substance. It will tell the person to contact the customer, and will tell the customer within 5 business days if the person identifies which workspace they mean.
Where the customer cannot answer a request through the product, Adoptiv will provide reasonable assistance by appropriate technical and organisational measures, taking into account the nature of the processing. Adoptiv responds to a written assistance request within 10 business days. This assistance is included in the fees, unless a request is repetitive or manifestly excessive, in which case Adoptiv may charge a reasonable fee agreed in advance.
This covers requests for access, rectification, erasure, restriction, portability and objection, and equivalent rights under US state law.
09Personal data breach
Adoptiv notifies the customer of a personal data breach affecting the customer's personal data without undue delay, and in any event within 72 hours of becoming aware of it.
Becoming aware means the point at which Adoptiv has a reasonable degree of certainty that a security incident has led to personal data being compromised. Adoptiv will not delay the notice to complete its investigation.
The notice is sent to the security contact the customer has registered, and to the account administrator if none is registered. It will describe, so far as is then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, Adoptiv provides it in phases without undue further delay.
Adoptiv assists the customer with its own notification duties to supervisory authorities and data subjects, and preserves the evidence and logs relevant to the breach.
The customer is responsible for deciding whether to notify a supervisory authority or its data subjects, since it is the controller. Adoptiv will not notify the customer's data subjects on its own initiative unless the law requires it to.
Adoptiv's notification is not an admission of fault or liability.
10Deletion and return on termination
At the customer's choice, Adoptiv deletes or returns the personal data at the end of the agreement, and deletes the existing copies unless a law it is subject to requires it to keep them.
| Stage | Period |
|---|---|
| Export window after termination | 30 days, during which the customer can export its data through the product or ask Adoptiv for an export |
| Deletion from live systems | Within 30 days of the end of the export window, or sooner on written request |
| Expiry from backups | Within 35 days of deletion from live systems, as backups roll over |
| Confirmation | A written certificate of deletion on request |
Adoptiv does not restore a backup in order to reinstate deleted data.
Adoptiv may keep the minimum billing and transaction records that tax and company law require it to keep, for 7 years. Those records are not used for any other purpose and remain subject to the security measures in this addendum.
The full retention schedule is at /legal/retention.
11Audit rights
Adoptiv makes available to the customer the information necessary to demonstrate compliance with Article 28, and allows and contributes to audits, including inspections, conducted by the customer or an auditor it mandates.
In the first instance Adoptiv satisfies this by providing its security documentation, its answers to a standard security questionnaire, a summary of its most recent penetration test, and the SOC 2 Type II report once that examination, which is in progress, has been completed.
If that does not answer the customer's question, the customer may audit on these terms.
- Once in any 12 month period, unless a personal data breach has occurred or a supervisory authority requires more.
- On at least 30 days' written notice, during business hours, and conducted so as not to disrupt Adoptiv's business.
- By the customer or by an independent auditor that is not a competitor of Adoptiv, under a confidentiality agreement.
- Limited to the systems and records relevant to the processing of that customer's personal data. It does not extend to another customer's data, and Adoptiv will redact what it must to protect that.
- At the customer's cost, except where the audit finds a material breach of this addendum, in which case Adoptiv bears the reasonable cost.
Adoptiv will correct any material non-compliance an audit identifies, at its own cost and on an agreed timetable.
12International transfers
Adoptiv Inc is established in the United States. Personal data may be transferred to and processed in the United States and other countries where Adoptiv or its sub-processors operate. Primary hosting is in Germany.
Where a transfer is subject to the GDPR and the destination is not covered by an adequacy decision, the parties rely on the following.
| Transfer | Mechanism | Which terms apply |
|---|---|---|
| EEA to a third country | EU Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914 | Module Two, controller to processor, where the customer is a controller. Module Three, processor to processor, where the customer is itself a processor |
| United Kingdom to a third country | The UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs issued under section 119A of the Data Protection Act 2018 | Whichever the customer selects. The UK Addendum applies by default |
| Switzerland to a third country | EU SCCs as amended for Switzerland under the revised Federal Act on Data Protection | The Federal Data Protection and Information Commissioner is the competent authority, and the clauses protect the data of legal entities as well as individuals |
The Standard Contractual Clauses are incorporated into this addendum by reference and take effect on acceptance, with these selections.
- Clause 7, the docking clause, applies.
- Clause 9, sub-processors: Option 2, general written authorisation, with the 30 day notice period set out in the sub-processor section above.
- Clause 11, redress: the optional independent dispute resolution body is not used.
- Clause 17, governing law: the law of Ireland. For the UK Addendum, the law of England and Wales.
- Clause 18, forum: the courts of Ireland. For the UK Addendum, the courts of England and Wales.
- Annex I is populated by the parties from the sections above on the parties, the categories of data subject and data, and the nature and purpose of the processing. Annex II is /legal/security-practices. Annex III is /legal/sub-processors.
Adoptiv has applied to join the EU-US Data Privacy Framework, its UK Extension and the Swiss-US framework. Those applications are in progress. Adoptiv does not claim active participation, and the Standard Contractual Clauses and the UK IDTA stand on their own whether or not the applications succeed.
Adoptiv has completed a transfer impact assessment and will provide it on request. Adoptiv notifies the customer if it becomes unable to comply with the clauses, or receives a legally binding request from a public authority for the customer's personal data, to the extent it is legally permitted to say so. It challenges requests it considers unlawful or overbroad.
13Liability, term and changes
Each party's liability under this addendum is subject to the limitations and exclusions of liability in the agreement, except where the law does not permit that.
This addendum takes effect when the customer starts using the platform and continues until Adoptiv has deleted or returned the personal data. The obligations of confidentiality, security, breach notice and deletion survive termination for as long as Adoptiv holds any of the customer's personal data.
Adoptiv may update this addendum to reflect a change in law, in a transfer mechanism, or in its sub-processors. Material changes are notified at least 30 days in advance, by email to the account administrator and a notice in the product. A change will not reduce the protection the customer already has.
Questions and signature requests go to legal@adoptiv.com, or Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Our phone number is +1 (636) 556 0022.
Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.