Data Processing Agreement (DPA)
This Data Processing Agreement (the "DPA") governs the processing of personal data that Aspen Blue Capital LLC ("Aspen", the "Processor") carries out on behalf of and under the instructions of the customer (the "Customer", the "Controller") when providing AIBI and other platforms. It forms an integral part of the Platform Terms of Service and prevails over them on matters of personal data.
Why this document exists: when an AIBI agent calls a person, that person has usually never visited our site or accepted our terms. Their data — their number, their name, their voice, what they said — is supplied by the Customer and processed on their behalf. This DPA defines who answers for what towards that person.
1. Roles of the parties
- The Customer is the Controller of the personal data of its contacts and End Users: it determines the purpose, decides who is contacted and guarantees the legal basis.
- Aspen is the Processor and processes that data solely to provide the Platform in accordance with the Customer's documented instructions.
- In relation to Service Data (telemetry, metrics, billing, security) and Aggregated and De-identified Data, Aspen acts as Controller, in accordance with clause 5 of the Terms and the Privacy Policy.
2. Subject matter, duration and nature of the processing
- Subject matter: providing the Platform (conversational agents by phone and video call, flows, transcription, summaries and integrations).
- Duration: for the term of the contract, plus the retention periods in clause 10.
- Nature: collection, storage, use, transmission, transcription, analysis and deletion, by automated means.
- Purpose: exclusively the performance of the contracted service and the Controller's instructions.
3. Categories of data subjects and data
Data subjects: contacts, customers, prospects, users and other natural persons the Customer decides to contact or whose data it uploads.
Categories of data processed (depending on the Customer's configuration):
- Identification and contact: name, phone number, and any other fields the Customer uploads into its databases or datasets.
- Communication content:audio recordings of calls, video in video calls, transcripts and AI-generated summaries.
- Communication metadata: date, time, duration, origin and destination number, call status and outcome.
- Voice samples uploaded by the Customer for cloning, where it uses that feature.
- Any other data the End User discloses during the conversation or that the Customer decides to send to the Platform.
Warning on sensitive and biometric data: a voice may constitute biometric data and be subject to heightened regulation (for example, US state biometrics laws and the sensitive data regime of Law 1581 of 2012 in Colombia). The Customer must not process sensitive data or minors' data through the Platform without meeting the applicable heightened requirements and without agreeing it with Aspen in advance.
4. Customer (Controller) obligations
- Guaranteeing that it holds a valid legal basis and authorisation for the processing and for Aspen to carry it out on its behalf.
- Obtaining the required contact consents (TCPA in the US, Law 2300 of 2023 and Law 1581 of 2012 in Colombia, or equivalent regulations).
- Meeting the notice and consent requirements for recording communications in every applicable jurisdiction.
- Providing data subjects with the corresponding privacy notice and handling the exercise of their rights.
- Not sending the Platform data beyond what is necessary for the contracted purpose.
- Properly maintaining its access credentials and users.
5. Aspen (Processor) obligations
Aspen undertakes to:
- Process the data solely in accordance with the Controller's documented instructions, including those on transfers, unless a rule requires otherwise (in which case it will give notice, where legally possible).
- Not sell, assign or commercialise the personal data processed on the Customer's behalf, nor use it for its own purposes other than providing the Platform, except (i) irreversibly aggregated and de-identified data, which ceases to be personal data, or (ii) whatever the Customer authorises in writing in a separate agreement. Aspen's access to review or monitor content is limited to security, quality, compliance and service improvement purposes, under least privilege and confidentiality.
- Not use identifiable Customer Data to train or fine-tune models, save with the Customer's express prior authorisation (opt-in, off by default).
- Ensure authorised personnel are subject to confidentiality duties and access data only under the principle of least privilege.
- Adopt the security measures in clause 7.
- Reasonably assist the Controller in handling data subject rights (clause 8) and its security, breach notification and impact assessment duties.
- Make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA.
- Delete or return the data on termination of the contract (clause 10).
6. Sub-processors
The Customer gives general authorisation for Aspen to use sub-processors to provide the Platform. The current list, with their purpose and the data they process, is published and kept up to date at Sub-processors.
- Aspen imposes on each sub-processor, by contract, protection obligations no less demanding than those of this DPA.
- Aspen remains liable to the Customer for its sub-processors' compliance.
- Aspen will announce the addition or replacement of sub-processors with reasonable notice, allowing the Customer to object on reasonable data protection grounds. If the objection cannot be resolved, the Customer may terminate the affected service without penalty, as its sole remedy.
7. Security measures
Aspen applies technical and organisational measures that are reasonable and appropriate to the risk, including:
- Encryption in transit using standard protocols (TLS/HTTPS and equivalents in telephony and streaming).
- Authentication via signed tokens and role-based access control, with strict separation between accounts (multi-tenant): a customer's data and cloned voices are reachable only from their own account.
- Two barriers for administrative functions (role check in the token and revalidation against the database, deny-by-default) and an audit log of administrative actions.
- Secrets management outside the source code and rotation upon any sign of compromise.
- File upload validation and controls against unauthorised requests to internal resources.
- Technical logs, monitoring and information backups.
- The principle of least privilege and staff confidentiality.
Aspen describes here the measures it actually applies. Aspen does not claim to hold, as at today's date, third-party certifications (such as SOC 2 or ISO 27001) or external security audits. Any certification requirement must be agreed in writing.
8. Data subject rights
Requests for access, update, rectification, erasure, withdrawal or objection must be directed to the Customer, which is the Controller. If a data subject approaches Aspen directly, Aspen will not handle the substance of the request and will forward it to the Customer without delay, unless the law provides otherwise.
Aspen will reasonably assist the Customer, through Platform features or, where necessary, with manual support, to locate, export, rectify or delete a data subject's data.
9. Security incidents
- Aspen will notify the Customer without undue delay after becoming aware of a security breach affecting Customer Data.
- The notification will include, to the extent available: the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences and the measures adopted or proposed.
- Aspen will reasonably cooperate with the Customer in the investigation and in any notifications the Customer must make to authorities or data subjects.
- Notifying an incident does not imply an admission of fault or liability.
10. Retention, return and deletion
- Aspen retains Customer Data for the term of the contract; once it ends, the periods in this clause apply.
- On termination, the Customer has thirty (30) days to request the export of its data, which Aspen will handle with assistance.
- Once that period expires, Aspen will proceed to delete or anonymise it, unless it must retain it under a legal obligation, for the exercise or defence of claims, or in backup copies, which are overwritten in line with their rotation cycles.
- Aggregated and De-identified Data is not subject to return or deletion, as it does not identify any person.
11. International transfers
The Platform is operated from Contabo and Amazon Web Services (AWS) infrastructure, located mainly in the United States, and relies on sub-processors situated mainly in that country. Data may therefore be transferred and processed outside the data subject's country of residence, including countries whose legislation may offer a different level of protection from the country of origin.
For transfers from Colombia, Aspen and the Customer rely on the data subject's authorisation and/or on the other grounds and safeguards provided in Law 1581 of 2012 and in the decisions of the Superintendency of Industry and Commerce; Aspen undertakes contractually to maintain the required level of protection. For transfers subject to other regimes, the parties will execute whatever clauses or mechanisms are required.
12. Audit
Aspen will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. Audits will be carried out with reasonable notice, during business hours, no more than once a year (save for an authority's requirement or a material incident), without disrupting operations, under confidentiality and at the Customer's cost.
13. Liability
Liability arising from this DPA is subject to the limits in clause 18 of the Platform Terms of Service, unless mandatory law provides otherwise.
14. Contact
For data protection matters and to request the execution of a signed DPA, write to us at business@aspenbluecapital.com.