Legal

Data Processing Agreement

Last updated: July 12, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between HandyMack Tech & Home Services LLC, operating the StrideVoice product (“Processor”) and the Customer identified in their StrideVoice account (“Controller”). This DPA is incorporated by reference into the StrideVoice Terms of Service and governs the processing of personal data by StrideVoice on behalf of the Customer.

1. Purpose and Scope

This DPA sets out the terms under which StrideVoice (as data processor) processes personal data on behalf of the Customer (as data controller) in connection with the provision of the StrideVoice AI phone agent platform and related services (the “Services”).

This DPA applies to processing of personal data of the Customer’s callers and end users through the AI phone agent functionality. The processing of Customer account holder data is governed separately by the StrideVoice Privacy Policy (stridevoice.com/privacy) in StrideVoice’s capacity as a data controller.

Terms used in this DPA that are not otherwise defined shall have the meanings ascribed to them under applicable data protection law, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), where applicable.

2. Roles of the Parties

Customer as Controller: The Customer determines the purposes and means of processing personal data of their callers. The Customer decides which calls are recorded, how call data is used, how long data is retained (within platform limits), and is responsible for ensuring a lawful basis for all processing activities and for providing required notices to callers.

StrideVoice as Processor:StrideVoice processes personal data only on documented instructions from the Customer, as set out in the Customer’s account configuration and this DPA. StrideVoice does not process caller personal data for its own independent purposes.

CCPA Context:Under the CCPA, StrideVoice acts as a “Service Provider” with respect to caller personal information processed on the Customer’s behalf. StrideVoice will not sell, share, retain, use, or disclose caller personal information for any purpose other than providing the Services as specified in this DPA and the Terms of Service.

3. Processing Activities

3.1 Subject Matter

Processing of personal data of callers who contact the Customer’s business phone number, as routed through the StrideVoice AI phone agent platform.

3.2 Duration of Processing

Processing occurs for the duration of the Customer’s subscription, plus the post-termination data retention period described in Section 10.

3.3 Nature and Purpose of Processing

  • Answering inbound telephone calls via AI agent;
  • Speech recognition (STT) and text-to-speech (TTS) processing;
  • AI conversation management and natural language understanding;
  • Call recording (if enabled by Customer);
  • Transcript generation and storage;
  • Call summarization and metadata generation;
  • Delivery of call records to the Customer dashboard;
  • SMS notification delivery to Customer;
  • Integration data routing (if Customer has enabled integrations).

3.4 Categories of Data Subjects

Individuals who call the Customer’s AI agent (callers, prospects, customers of the Customer’s business).

3.5 Categories of Personal Data Processed

  • Telephone number (CLID/ANI data);
  • Voice recordings (audio data);
  • Speech transcripts (text data);
  • Name and other identifying information provided by the caller;
  • Service requests, appointment preferences, and other communication content;
  • Call metadata (timestamps, duration, call outcome, AI-inferred data).

4. Customer Instructions

StrideVoice will process personal data only on documented instructions from the Customer. The Customer’s instructions are embodied in: (a) the Customer’s account configuration (agent settings, recording preferences, retention settings, and enabled features); (b) this DPA; and (c) any written instructions provided to StrideVoice support.

StrideVoice will promptly inform the Customer if, in StrideVoice’s reasonable opinion, a Customer instruction violates applicable data protection law. In such cases, StrideVoice reserves the right to refuse to carry out the instruction.

StrideVoice personnel with access to personal data are subject to confidentiality obligations and are authorized to process data only as necessary to provide the Services.

5. Sub-Processors

The Customer hereby provides general authorization for StrideVoice to engage sub-processors as necessary to provide the Services. StrideVoice will ensure that sub-processors are bound by contractual data protection obligations at least as protective as those in this DPA.

The current list of authorized sub-processors is as follows:

Sub-ProcessorRoleData ProcessedLocation
Telnyx LLCTelephony infrastructure, STT/TTS, AI assistant LLM orchestration, call recording storage, cloud storageCall audio, call recordings, transcripts, caller phone numbers, knowledge base documentsUnited States
Stripe, Inc.Payment processingCustomer billing data only (no caller data)United States
Supabase, Inc.Database hosting and authenticationAll structured data: call records, transcripts, agent configurationsUnited States
Cloudflare, Inc.CDN, WAF, DDoS protectionWeb traffic metadataUnited States / Global CDN
Resend, Inc.Transactional email (call summary notifications to Customer)Customer email address, call summary contentUnited States
Anthropic, PBCPost-call analysis onlyCall transcripts, caller statements, conversation contextUnited States
Google LLCSign in with Google (OAuth), Google Calendar integration, Google Sheets call-log sync (each only when enabled by the Customer)OAuth tokens, calendar event data, call summary rows synced to Customer-owned spreadsheetsUnited States
Functional Software, Inc. (Sentry)Application error monitoring (tracing and session replay disabled)Error reports, stack traces, request metadataUnited States
Telegram Messenger Inc.Optional operator messaging bridge (only when enabled by the Customer)Caller phone numbers, SMS message content, call notificationsGlobal (Telegram-operated data centers)
Hetzner Online GmbHCloud server hosting for StrideVoice-managed workflow automationRedacted call transcripts, call metadata, notification content in transitUnited States (Ashburn, Virginia)
Microsoft CorporationMicrosoft Calendar and Microsoft Teams integrationsOAuth tokens, calendar event data, meeting and routing metadataUnited States
Railway CorporationApplication hosting for customer dashboard and backend APICustomer account data, API requests, application logsUnited States
Infisical, Inc.Secrets and environment variable management for application configurationApplication secrets, API keys (no Customer personal data)United States

StrideVoice will provide at least 30 days’ prior written notice before adding any new sub-processors that will process caller personal data. Notice will be provided via email to the Customer’s registered email address and by updating this DPA. If the Customer objects to a new sub-processor on reasonable data protection grounds, the Customer may terminate the affected services by providing written notice within 30 days of receiving the sub-processor notification.

6. Security Measures

StrideVoice implements and maintains appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include, without limitation:

Technical Measures

  • Encryption of personal data in transit using TLS 1.3 on all network connections;
  • Encryption of call recordings at rest using AES-256 by Telnyx;
  • Encryption of sensitive credentials using AES-256-GCM with unique initialization vectors before database storage;
  • Database-level row-level security (RLS) ensuring strict tenant data isolation — no Customer can access another Customer’s data;
  • Cryptographic signature verification on all inbound webhooks, with unsigned requests rejected before processing;
  • Automated vulnerability scanning of application dependencies on every build, with automated security patching;
  • Isolated production environments provided by independently certified cloud hosting providers.

Organizational Measures

  • Principle of least privilege: StrideVoice is a small, founder-led operation, and access to personal data is limited to the personnel who require it to operate the Services;
  • Confidentiality obligations for all personnel with data access;
  • Documented incident response procedures with defined severity levels and notification timelines;
  • Review of each sub-processor’s security posture and certifications before onboarding.

7. Data Subject Rights

StrideVoice will assist the Customer in fulfilling data subject rights requests (access, correction, deletion, restriction, portability, and objection) to the extent technically feasible and within the scope of the data processed by StrideVoice on the Customer’s behalf.

If StrideVoice receives a data subject request directly from a caller, StrideVoice will forward the request to the Customer within 5 business days. StrideVoice will not respond to such requests on the Customer’s behalf without the Customer’s prior written authorization.

The Customer is responsible for responding to data subject rights requests within the timeframes required by applicable law. StrideVoice will provide technical assistance to enable the Customer to respond, such as providing data exports or deletion capabilities through the dashboard.

8. Data Breach Notification

StrideVoice will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer data processed under this DPA, to the extent reasonably practicable. The notification will include:

  • A description of the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned;
  • The name and contact details of StrideVoice’s data protection contact;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.

Where complete information is not available within 72 hours, StrideVoice will provide an initial notification with available information and follow up with additional details as they become known.

The Customer is responsible for determining whether the breach requires notification to data protection authorities or affected individuals under applicable law, and for providing any such notifications.

9. International Data Transfers

StrideVoice’s infrastructure and sub-processors process personal data in the United States: call recordings, transcripts, and the primary database are stored in U.S.-based infrastructure, and StrideVoice-managed workflow automation runs in Hetzner’s Ashburn, Virginia data center. One exception applies: the optional Telegram operator bridge, when enabled by the Customer, routes message content through Telegram’s global infrastructure.

To the extent that Customers are located in or process data from the European Economic Area (EEA), United Kingdom, or Switzerland, and to the extent such data protection laws apply, transfers of personal data to the United States are made pursuant to applicable transfer mechanisms, including the EU Standard Contractual Clauses (SCCs) as adopted by the European Commission, where required. Upon request, StrideVoice will execute the applicable SCCs with the Customer.

Cloudflare’s CDN network distributes content globally; however, personal data (call recordings, transcripts) is stored only in U.S.-based Telnyx and Supabase infrastructure.

10. Data Retention and Deletion

StrideVoice retains caller personal data as configured by the Customer. Default retention periods:

  • Call recordings: 90 days from the date of the call (configurable by Customer within subscription limits);
  • Call transcripts and summaries: 365 days from the date of the call (configurable by Customer), enforced by a nightly retention job;
  • Call metadata: Duration of the subscription plus 30 days post-termination;
  • Knowledge base documents: Retained until deleted by the Customer or for 30 days post-account termination.

Upon termination of the Customer’s account, StrideVoice will:

  1. Provide the Customer with a 30-day window to export their data through the dashboard;
  2. Following the 30-day period, delete all personal data processed under this DPA, except as required to comply with applicable law or legal holds;
  3. Upon request, provide written confirmation of deletion.

StrideVoice retains aggregate, anonymized, de-identified data that does not include personal information indefinitely for service improvement purposes.

11. Audits and Inspections

StrideVoice will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, subject to the following conditions:

  • Audit requests must be submitted in writing at least 30 days in advance;
  • Audits may not occur more than once per calendar year, unless required by a regulatory authority;
  • Audits must be conducted during normal business hours and must not unreasonably disrupt StrideVoice’s operations;
  • The Customer and any third-party auditor must sign a confidentiality agreement before accessing StrideVoice systems or documentation;
  • Audit costs are borne by the Customer.

As an alternative to an on-site audit, StrideVoice may satisfy an audit request by providing relevant security certifications, third-party audit reports, or security questionnaire responses.

12. Liability

Each party’s liability under this DPA is subject to the limitations of liability set out in the StrideVoice Terms of Service. Nothing in this DPA limits StrideVoice’s liability for breaches of the data security obligations in Section 6 to the extent such limitation is not permitted by applicable data protection law.

The Customer acknowledges that StrideVoice processes personal data only as instructed and that the Customer bears primary responsibility for the lawfulness of the processing, including ensuring appropriate legal bases and providing required notices to callers.

13. Term and Termination

This DPA is effective from the date the Customer first uses the Services and continues until the Customer’s subscription is terminated. This DPA terminates automatically upon termination of the Terms of Service.

Provisions that by their nature should survive termination shall survive, including obligations relating to data deletion confirmation, breach notification (for breaches discovered post-termination), and confidentiality.

14. Governing Law

This DPA is governed by the laws of the State of Arizona, consistent with the governing law provision in the Terms of Service. Where GDPR requires the application of EU law to specific provisions, such EU law provisions shall govern those specific obligations to the extent required.

15. Contact

For DPA-related inquiries, data subject rights requests forwarding, or to request execution of Standard Contractual Clauses:

Data Protection — HandyMack Tech & Home Services LLC, operating the StrideVoice product
Phoenix, Arizona
Email: [email protected]