Data Processing Addendum
Fifteen sections under the Digital Personal Data Protection Act 2023. This addendum prevails over the Terms of Service on anything to do with data protection. Processing is located in India; breach notification is within 72 hours; there is an audit right once every twelve months.
Jump to section
- 1. Scope
- 2. Subject matter and duration
- 3. Nature and purpose of processing
- 4. Categories of data subject
- 5. Categories of personal data
- 6. Processor obligations
- 7. Security measures
- 8. Sub-processors
- 9. Retention, return and deletion
- 10. Location of processing
- 11. Personal data breach
- 12. Data-subject requests
- 13. Audit
- 14. Controller responsibilities
- 15. Contact
Pre-launch note. This document is written and in force as published, but it has not yet been dated and reviewed by external counsel. We would rather say that here than leave you to discover it. If you are running a procurement or security review and need the counsel-reviewed version, email us and we will tell you exactly where it stands.
1. Scope
This addendum applies where Simption (“Processor”) processes personal data on behalf of a customer (“Controller”) in the course of providing Telecaller24. It is governed by the Digital Personal Data Protection Act, 2023 and other applicable Indian law, and forms part of the Terms of Service. Where the two conflict on data protection, this addendum prevails.
2. Subject matter and duration
Processing continues for the duration of the Controller's subscription, plus the 30-day post-termination retention window described in section 9.
3. Nature and purpose of processing
Collection, storage, organisation, retrieval and display of sales-activity data for the purpose of providing call tracking, follow-up reminders, target management, reporting and — on the Field plan — work-hours route history to the Controller.
4. Categories of data subject
- The Controller's employees, contractors and agents whose devices run the application.
- The Controller's customers and prospects, whose phone numbers appear in call metadata.
- The Controller's administrative users.
5. Categories of personal data
NOT PROCESSED, UNDER ANY CONFIGURATION
Call audio · message content · browsing history · address-book contents · numbers excluded on the device
- Identifiers: name, employee ID, mobile number, email address.
- Call metadata: counterparty number, direction, timestamp, duration and outcome.
- User-entered content: statuses, tags, notes and follow-up times.
- Location data: coordinates recorded during the configured work-hour window, on the Field plan only.
- Device diagnostics: model, OS version, app version and crash reports.
Not processed: call audio, message content, browsing history, or the contents of the device address book. Numbers a user has excluded are filtered on the device and never reach us.
6. Processor obligations
- Process personal data only on the Controller's documented instructions, including this addendum, unless required otherwise by law.
- Ensure personnel authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures, as described in section 7.
- Not sell, rent or use the data for our own marketing, profiling or model training.
- Assist the Controller in responding to data-subject requests, and in meeting its own security and breach-notification obligations.
- Make available the information reasonably necessary to demonstrate compliance with this addendum.
7. Security measures
- Encryption of data in transit using TLS, and encryption of backups at rest.
- Role-based access control: team members see their own activity, administrators see their organisation only.
- One-way hashing of passwords.
- Access to production customer data by our personnel restricted to those who need it for support, under logged access controls.
- Regular backups, with restoration tested periodically.
8. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors for hosting, push notification delivery, transactional email and payment processing. Each is bound by written obligations no less protective than those in this addendum.
We maintain a current list of sub-processors and will give the Controller at least 30 days' notice of any addition or replacement. The Controller may object on reasonable data-protection grounds, in which case the parties will work in good faith towards a resolution; failing that, the Controller may terminate the affected service and receive a pro-rata refund of the unused term.
Request the current sub-processor list at hello@telecaller24.com.
9. Retention, return and deletion
On termination, data remains available to the Controller for 30 days for export, after which it is deleted from live systems. Encrypted backups are purged on their normal rotation cycle, not exceeding 90 days. The Controller may request immediate deletion in writing, and we will confirm once it is complete.
10. Location of processing
Personal data is stored and processed on infrastructure located in India. We will give notice before processing personal data outside India, and will put appropriate safeguards in place where we do.
11. Personal data breach
We will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences and the measures taken.
12. Data-subject requests
Where a data subject contacts us directly, we will not respond substantively but will promptly refer them to the Controller, and will assist the Controller in fulfilling the request.
13. Audit
On reasonable written notice, and no more than once in any twelve-month period unless required by a regulator or following a breach, the Controller may request information reasonably necessary to verify our compliance with this addendum.
14. Controller responsibilities
The Controller warrants that it has a lawful basis for the processing it instructs, that it has informed each affected individual as required by law, and that it will not instruct processing that would put the Processor in breach of applicable law. The Employee Consent Notice is provided to help meet the notification obligation.
15. Contact
Simption, B-32, IT Park, Bhopal, Madhya Pradesh
Email: hello@telecaller24.com
Questions about this document? hello@telecaller24.com · +91 93401 88163 · Simption, B-32, IT Park, Bhopal, Madhya Pradesh.
Start with 5 numbers, free for 15 days
No credit card. Android 8.0+. Set up in an afternoon.