Data Processing Addendum
Our obligations when we process personal data on your behalf. This addendum forms part of the Terms of Service.
Who is who
You are the controller. You decide whose devices run Telecaller24, what your team is told, and how long you keep the data.
We are the processor. We process that data only on your documented instructions, to provide the service.
1. Scope
This addendum applies where Simption (“Processor”) processes personal data on behalf of a customer (“Controller”) in the course of providing Telecaller24. It is governed by the Digital Personal Data Protection Act, 2023 and other applicable Indian law, and forms part of the Terms of Service. Where the two conflict on data protection, this addendum prevails.
2. Subject matter and duration
Processing continues for the duration of the Controller's subscription, plus the 30-day post-termination retention window described in section 9.
3. Nature and purpose of processing
Collection, storage, organisation, retrieval and display of sales-activity data for the purpose of providing call tracking, follow-up reminders, target management, reporting and — on the Field plan — work-hours route history to the Controller.
4. Categories of data subject
- The Controller's employees, contractors and agents whose devices run the application.
- The Controller's customers and prospects, whose phone numbers appear in call metadata.
- The Controller's administrative users.
5. Categories of personal data
- Identifiers: name, employee ID, mobile number, email address.
- Call metadata: counterparty number, direction, timestamp, duration and outcome.
- User-entered content: statuses, tags, notes and follow-up times.
- Location data: coordinates recorded during the configured work-hour window, on the Field plan only.
- Device diagnostics: model, OS version, app version and crash reports.
Not processed: call audio, message content, browsing history, or the contents of the device address book. Numbers a user has excluded are filtered on the device and never reach us.
6. Processor obligations
- Process personal data only on the Controller's documented instructions, including this addendum, unless required otherwise by law.
- Ensure personnel authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures, as described in section 7.
- Not sell, rent or use the data for our own marketing, profiling or model training.
- Assist the Controller in responding to data-subject requests, and in meeting its own security and breach-notification obligations.
- Make available the information reasonably necessary to demonstrate compliance with this addendum.
7. Security measures
- Encryption of data in transit using TLS, and encryption of backups at rest.
- Role-based access control: team members see their own activity, administrators see their organisation only.
- One-way hashing of passwords.
- Access to production customer data by our personnel restricted to those who need it for support, under logged access controls.
- Regular backups, with restoration tested periodically.
8. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors for hosting, push notification delivery, transactional email and payment processing. Each is bound by written obligations no less protective than those in this addendum.
We maintain a current list of sub-processors and will give the Controller at least 30 days' notice of any addition or replacement. The Controller may object on reasonable data-protection grounds, in which case the parties will work in good faith towards a resolution; failing that, the Controller may terminate the affected service and receive a pro-rata refund of the unused term.
Request the current sub-processor list at hello@telecaller24.com.
9. Retention, return and deletion
On termination, data remains available to the Controller for 30 days for export, after which it is deleted from live systems. Encrypted backups are purged on their normal rotation cycle, not exceeding 90 days. The Controller may request immediate deletion in writing, and we will confirm once it is complete.
10. Location of processing
Personal data is stored and processed on infrastructure located in India. We will give notice before processing personal data outside India, and will put appropriate safeguards in place where we do.
11. Personal data breach
We will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences and the measures taken.
12. Data-subject requests
Where a data subject contacts us directly, we will not respond substantively but will promptly refer them to the Controller, and will assist the Controller in fulfilling the request.
13. Audit
On reasonable written notice, and no more than once in any twelve-month period unless required by a regulator or following a breach, the Controller may request information reasonably necessary to verify our compliance with this addendum.
14. Controller responsibilities
The Controller warrants that it has a lawful basis for the processing it instructs, that it has informed each affected individual as required by law, and that it will not instruct processing that would put the Processor in breach of applicable law. The Employee Consent Notice is provided to help meet the notification obligation.
15. Contact
Simption, B-32, IT Park, Bhopal, Madhya Pradesh
Email: hello@telecaller24.com
Last Updated: This addendum must be dated and reviewed by counsel before launch.