Skip to content
Boundless
How it works Agents Platform Industries Pricing
Try it live Log in Book a demo

Legal

Data Processing Addendum

Last updated August 7, 2026 · Effective August 7, 2026

On this page

  1. Scope and roles
  2. Details of processing
  3. Processing instructions
  4. Confidentiality
  5. Security measures
  6. Sub-processors
  7. Data subject rights
  8. Personal data breach
  9. Audits
  10. International transfers
  11. Return and deletion
  12. Annexes

1. Scope and roles

This Data Processing Addendum forms part of the Terms of Service between Boundless Labs, Inc. ("Processor") and the customer ("Controller"). It applies where the Processor processes personal data on the Controller's behalf.

Where the two conflict on data protection, this Addendum prevails.

2. Details of processing

Subject matter. Provision of AI call handling.

Duration. The term of the agreement, plus any retention period.

Nature and purpose. Receiving and placing calls, recording, transcription, summarisation, classification, routing, and storage.

Categories of data subject. The Controller's callers, customers, and staff.

Categories of personal data. Telephone numbers, call audio, transcripts, summaries, call metadata, and any information a caller volunteers.

Special category data. Not requested, but callers may volunteer it. The Controller must not use the service to process special category data without our prior written agreement.

3. Processing instructions

The Processor will process personal data only on the Controller's documented instructions, including as to international transfers, unless required otherwise by law — in which case it will inform the Controller first, unless the law forbids it.

The Processor will tell the Controller if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

The Processor ensures personnel authorised to process personal data are bound by confidentiality obligations and receive appropriate training.

5. Security measures

The Processor implements appropriate technical and organisational measures, described in Annex II, and will not materially reduce them during the term.

6. Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors, listed in Annex III. The Processor will give at least 30 days notice of any addition or replacement, and the Controller may object on reasonable data protection grounds.

The Processor remains liable for its sub-processors' performance.

7. Data subject rights

Taking account of the nature of the processing, the Processor will assist the Controller with requests from data subjects. If a request reaches the Processor directly, it will forward it to the Controller rather than respond, unless instructed otherwise.

8. Personal data breach

The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach, with enough information for the Controller to meet its own obligations.

9. Audits

The Processor will make available information necessary to demonstrate compliance and allow audits by the Controller or its auditor. Audits may be carried out once in any 12-month period on 30 days written notice, at the Controller’s cost, during business hours and without unreasonable disruption. The Processor may satisfy an audit request by providing a current third-party assessment where one covers the relevant controls.

10. International transfers

Personal data is processed and stored in the United States. Where personal data is transferred from the EEA, the UK, or Switzerland, the transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, which are incorporated into this Addendum by reference.

11. Return and deletion

On termination, the Processor will delete or return all personal data at the Controller's choice, and delete existing copies unless law requires storage.

During the term, the Controller controls retention directly: it can shorten retention periods or disable retention entirely through the service. Deletion takes place within 30 days of termination, and deleted data expires from encrypted backups within a further 30 days.

12. Annexes

Annex I — Processing details. As set out in section 2.

Annex II — Technical and organisational measures.

  • Encryption. Personal data is encrypted in transit using TLS and encrypted at rest.
  • Access control. Access is limited to personnel who require it, granted on a least-privilege basis, and protected by multi-factor authentication.
  • Logging. Access to personal data is logged and reviewed.
  • Segregation. Each customer's data is logically separated from other customers' data.
  • Personnel. Staff are bound by written confidentiality obligations and receive data protection training.
  • Sub-processor diligence. Sub-processors are bound by written terms no less protective than this Addendum.
  • Resilience. Data is backed up in encrypted form, and restoration is tested periodically.
  • Deletion. Customers can shorten retention or disable it entirely, and can delete data on demand.
  • Incident response. A documented process governs detection, escalation, and notification of personal data breaches.

Annex III — Approved sub-processors.

  • Twilio — telephony and call audio
  • OpenAI — language models, transcription, summarisation
  • ElevenLabs — voice synthesis

All three sub-processors process personal data in the United States.

Questions about this document? [email protected]

Privacy Policy Terms of Service Data Processing Addendum

Boundless

An AI-powered call handling layer for businesses that can't afford to miss a call.

Product

  • Skill agents
  • Routing
  • Transcripts
  • Analytics
  • Pricing

Industries

  • Service trades
  • Medical & dental
  • Legal
  • Sales teams

Company

  • Book a demo
  • Try it live
  • Contact
  • Careers
© 2026 Boundless Labs, Inc. Privacy·Terms·DPA