Snapshot 36018
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Sales: Support: Log in Skip to content This agreement applies automatically to every customer. No signature is required, though we will sign a copy on request. This Data Processing Agreement governs Calilio's processing of personal data on your behalf. It forms part of your agreement with CALILIO PTE. LTD. (UEN 202433643W) and takes effect automatically when you start using the service. It is written to satisfy Article 28(3) of the EU and UK General Data Protection Regulation, and to work alongside Singapore's Personal Data Protection Act 2012. Who is who For the data in your workspace, you are the controller and Calilio is the processor. You decide what to collect and why. We act on your instructions. For our own billing, website and fraud prevention, Calilio is the controller and our Privacy Policy applies instead. 1. What this covers Subject matter. Our provision of the Calilio cloud phone system to you. Duration. From the day you start using the service until the day your account is deleted, plus any period we are legally required to retain records. Nature and purpose. Hosting, transmitting, storing, recording, transcribing, analysing and making available the voice, message and contact data you and your users create, so that we can deliver the service you bought. Your instructions. Your documented instructions are your use of the service through its normal features and settings, this agreement, and any further written instruction you give us. We will tell you if we believe an instruction breaks data protection law. 2. Categories of data and people Types of personal data we process on your behalf: Names, email addresses, phone numbers and job titles of your users Contact records you store, including postal addresses, companies, tags and notes Call detail records: numbers, timestamps, duration and outcome Call recordings and voicemail audio, where you enable recording Transcripts, call summaries and sentiment analysis output, where you enable those features Message content and attachments, including WhatsApp messages Technical data such as IP addresses, device identifiers, browser details and session records Categories of people whose data is processed: Your employees, contractors and other users you invite Your customers, prospects, suppliers and anyone else your users call, message or store as a contact Special category data. Calilio is not designed for health, biometric or other special category data. If your use will involve it, tell us first at [email protected] so we can agree the additional measures required. 3. Our obligations We commit to the following, which mirror Article 28(3)(a) to (h). We process only on your documented instructions, including for any transfer outside your country, unless a law we are subject to requires otherwise. Where that happens we will tell you before processing, unless the law forbids us from telling you. Everyone who handles your data is bound to confidentiality, by contract and by a statutory duty where one applies. Access is limited to staff who need it for their role. We apply appropriate technical and organisational security measures, described in Annex II. We engage sub-processors only under the conditions in the Sub-processors section. We help you answer requests from individuals, using the tools in the product and, where those are not enough, with our direct assistance. We help you meet your own obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and what we know. At the end of the service we delete or return your personal data, at your choice, and delete existing copies, unless a law requires us to keep something. We make available the information you need to demonstrate compliance, and we allow and contribute to audits, as set out in the Audits and information section. We will immediately tell you if, in our opinion, an instruction you give us infringes data protection law. 4. Your obligations You are responsible for having a lawful basis for the personal data you put into Calilio, and for telling the people concerned what you are doing. Call recording is your decision. You determine whether recording a call is lawful where you and the other party are, and you must obtain any consent or give any announcement the law requires. We provide the controls; the lawful basis is yours. You must keep your account secure, manage who has access, and remove users who leave. You must not put special category data into the service without agreeing it with us first. You must give your users and contacts the privacy information the law requires. 5. Sub-processors You give us general authorisation to engage sub-processors, subject to the conditions in this section. Our current sub-processors are published in our Sub-processor List, which forms part of this agreement. We email the account administrator on every affected account at least 30 days before a new sub-processor starts processing your data. That happens automatically. You do not have to subscribe, ask, or watch the published page. The notice names the company, says what it will do, where it processes data and on what legal basis it receives transfers. If your privacy or procurement team should also receive these notices, send the addresses to [email protected]. Every sub-processor is bound by a written contract imposing data protection obligations equivalent to those in this agreement. We remain fully liable to you for a sub-processor's performance of its obligations. You may object within the notice period, giving your reason. We will work with you to find an alternative. If no reasonable alternative exists and the change would genuinely harm you, you may terminate the affected part of the service without penalty and receive a refund of unused prepaid fees. 6. Security We apply the measures in Annex II. Those measures are reviewed at least annually and whenever we make a material change to the service. We may update a measure, provided the overall level of security is not reduced. 7. Personal data breach We notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event within 48 hours of confirming it. Our notification describes what happened, the categories and approximate number of people and records affected, the likely consequences, the measures we have taken, and a contact point for more information. Where we cannot give everything at once, we give what we have and follow up. We do not notify individuals or regulators on your behalf for data where you are the controller. That decision is yours, and we give you what you need to make it. Where Calilio is the controller, we notify the Personal Data Protection Commission no later than 3 calendar days after assessing that a breach is notifiable, and we notify affected individuals without undue delay. We keep a record of every personal data breach and make it available to you. 8. Requests from individuals The Calilio product lets you find, export, correct and delete the personal data in your workspace yourself. In most cases that is the fastest route. If a request reaches us directly from one of your users or contacts, we will not respond to it on your behalf. We will pass it to you promptly and tell the person we have done so, unless the law requires otherwise. Where you cannot fulfil a request with the product's own tools, we will help, taking into account the nature of the processing. We do not charge for reasonable assistance. 9. Audits and information Documentation first. We publish this agreement, our Sub-processor List, our Data Security Policy and Annex II. We also answer security questionnaires. In most cases this satisfies an audit requirement. Audit on request. Where documentation is genuinely not sufficient, you may audit our compliance with this agreement once in any 12-month period, or more often if a regulator requires it or following a personal data breach affecting your data. How an audit works. Give us at least 30 days written notice, agree the scope with us, use an independent auditor who is not our competitor, and have the auditor sign a confidentiality agreement. Audits happen during business hours and must not unreasonably disrupt the service. Limits. We will not give access to other customers' data, to our internal pricing or commercial information, or to any part of our systems where access would compromise another customer's security. Each side bears its own costs, unless the audit finds a material breach by us, in which case we bear the reasonable cost. 10. International transfers Calilio and its sub-processors process data in more than one country. The Sub-processor List states the processing locations. 10.1 Transfers from the European Economic Area Where personal data is transferred from the European Economic Area to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission on 4 June 2021 (Decision (EU) 2021/914) are incorporated into this agreement and form part of it. The selections are made as follows, and are not left open. Item Selection Modules Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are yourself a processor for your own customer. Clause 7, docking clause Included. Clause 9(a), sub-processors Option 2, general written authorisation. The notice period is 30 days, as set out in the Sub-processors section. Clause 11(a), independent dispute resolution Not included. Clause 13, supervisory authority As identified in Annex I. Clause 17, governing law Option 1. These Clauses are governed by the law of Ireland, which allows for third-party beneficiary rights. Clause 18(b), forum The courts of Ireland. Annexes I, II and III Completed by Annex I, Annex II and the Sub-processor List of this agreement. Why Irish law and Irish courts. The Clauses require the law and the courts of a European Economic Area member state that permits third-party beneficiary rights. Singapore law cannot be selected for this purpose, and any statement to the contrary in an earlier version of this agreement does not apply. This selection governs the Clauses only. The rest of your agreement with Calilio remains governed by Singapore law. 10.2 Transfers from the United Kingdom Where personal data is transferred from the United Kingdom, the Information Commissioner's International Data Transfer Addendum to the Standard Contractual Clauses, version B1.0 in force 21 March 2022, is incorporated into this agreement, and the Clauses above are read with the Addendum's amendments. Table Content Table 1, Parties The customer as Exporter, CALILIO PTE. LTD. as Importer. Details and contacts as set out in Annex I. Table 2, Selected SCCs The Clauses and selections in the European Economic Area transfers section above. Table 3, Appendix information Annex I, Annex II and the Sub-processor List of this agreement. Table 4, Ending the Addendum Neither party may end the Addendum when the Approved Addendum changes. Where the Addendum conflicts with the Clauses, the Addendum prevails for United Kingdom transfers. 10.3 Transfers from Switzerland Where personal data is transferred from Switzerland, the Clauses apply with the amendments published by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the Commissioner is the supervisory authority, and the Clauses protect the data of legal entities until Swiss law provides otherwise. 10.4 Transfer risk assessment Before we engage a sub-processor outside the European Economic Area or the United Kingdom, we assess whether the laws of the destination country would prevent it from meeting the Clauses, taking into account the type of data, the length of the processing chain, the destination country's surveillance laws and any practical experience of government access requests. We record that assessment and make it available to you on request. If an assessment shows the Clauses cannot be met, we do not make the transfer, or we apply supplementary measures such as encryption where we hold the keys. We reassess when the destination country's law changes materially, and at least every two years. 10.5 Government access requests We tell you if we receive a legally binding request from a public authority for your data, unless the law prohibits us from doing so, in which case we use reasonable efforts to have the prohibition lifted. We challenge a request that appears unlawful, overbroad or excessive, and we provide only the minimum the request requires. We keep a record of the requests we receive and make summary information available to you. 10.6 If a mechanism fails If a transfer mechanism is invalidated, suspended or withdrawn, we will work with you in good faith to put a lawful alternative in place without undue delay. If no lawful alternative exists, we will suspend the affected transfer rather than continue it. 11. Deletion and return You can export your data at any time using the product's own tools, for as long as your account is open. On termination, we delete your personal data, or return it to you first if you ask within 30 days of the account closing. Deletion is initiated 30 days after a deletion request, which gives you time to withdraw the request and to save anything you need. What we keep, and why. Invoices and tax records for 5 years from the end of the financial year, as required of a Singapore company by the Companies Act 1967 section 199, the Income Tax Act 1947 section 67, and the Goods and Services Tax Act 1993 section 46. Call detail records and security logs for 12 months. A record of the deletion request itself for 3 years. Backups exist only so we can recover from a failure: they are never searched, restored or read to answer a request, deleted data in a backup is not returned to the live service, and it is overwritten in the ordinary course. Retained data is not used for any purpose other than the one that requires it to be kept. 12. United States state privacy law Where United States state privacy law applies to your use of Calilio: Calilio acts as a service provider, processor or contractor, as those terms are defined in the applicable state law, and not as a business or third party in its own right. We do not sell or share your personal information, as those terms are defined by the California Consumer Privacy Act, and we do not retain, use or disclose it for any purpose other than performing the service for you. We do not combine your personal information with personal information we receive from another source, except as permitted to perform the service, to detect security incidents, or to prevent fraud or illegal activity. We certify that we understand these restrictions and will comply with them. You may take reasonable steps to confirm that we use your data appropriately, using the documentation and audit routes in the Audits and information section. If we can no longer meet these obligations, we will tell you promptly and stop the processing concerned. 13. Data protection contact and records Calilio has designated a Data Protection Officer, as every organisation in Singapore is required to do by section 11(3) of the Personal Data Protection Act 2012. The Data Protection Officer's business contact address is [email protected], published as required by section 11(5) of that Act. Writing to that address reaches the person responsible for our compliance with this agreement. We maintain records of the processing we carry out on your behalf, as required by Article 30(2) of the GDPR, and we will provide them to you or to a supervisory authority on request. Where the law requires us to appoint a representative in the European Union or the United Kingdom, we will appoint one and publish the details here. 14. Assistance with assessments Where you carry out a data protection impact assessment or consult a supervisory authority about processing that involves Calilio, we will give you the information you reasonably need, taking into account the nature of the processing and what is available to us. The documentation in this agreement, the Sub-processor List and the Data Security Policy is normally sufficient. Where it is not, write to [email protected] and tell us what the assessment requires. We do not charge for reasonable assistance. 15. Singapore Where Singapore's Personal Data Protection Act 2012 applies, Calilio acts as your data intermediary under a contract made in writing, namely this agreement. As data intermediary we are directly bound by the Protection Obligation in section 24, the Retention Limitation Obligation in section 25, and the duty to notify you of a data breach without undue delay. You remain responsible under section 4(3) for personal data processed on your behalf as if you had processed it yourself. 16. Liability, term and precedence Each party's liability under this agreement is subject to the limits in the Terms of Service, except where data protection law does not allow that limit. This agreement lasts as long as we process personal data on your behalf. Which document wins if two disagree. This order is identical in the Terms of Service, so there is only one answer: The European Standard Contractual Clauses and the United Kingdom Addendum, where they apply to a transfer. This Data Processing Agreement, for anything about how personal data is handled. Your signed order form, for anything commercial. The Terms of Service. The other Calilio policies. In short: this agreement outranks the Terms of Service on personal data, and the Terms outrank this agreement on everything else. Annex I — Details of processing Item Details Data exporter The customer, acting as controller. Data importer CALILIO PTE. LTD., UEN 202433643W, 14 Robinson Road, #08-01, Far East Finance Building, Singapore 048545, acting as processor. Contact [email protected] Purpose Provision of the Calilio cloud phone system: voice calling, messaging, WhatsApp business messaging, contact management, recording, transcription and analysis. Categories of people The customer's users, and the customer's contacts and anyone they call or message. Categories of data Identity and contact details, call detail records, recordings, voicemail, transcripts, message content and attachments, technical and device data. Special categories None by default. Any such processing must be agreed in advance. Frequency Continuous, for the duration of the service. Retention As set out in the Deletion and return section. Sub-processors As published in the Calilio Sub-processor List. Competent supervisory authority under the Clauses Determined by Clause 13. Where you are established in the European Economic Area, it is the supervisory authority of that member state. Where you are not established in the European Economic Area but are subject to the GDPR and have appointed an Article 27 representative, it is the supervisory authority of the member state where that representative is established. Where you are subject to the GDPR without a representative, it is the supervisory authority of a member state in which the affected individuals are located. Supervisory authority for United Kingdom transfers The Information Commissioner's Office. Supervisory authority for Calilio's own processing Personal Data Protection Commission, Singapore. Annex II — Technical and organisational measures Measure Description Encryption Data encrypted in transit using current industry-standard protocols. Data at rest encrypted in our hosting provider's storage services. Access control Role-based access, least privilege, individual named accounts, multi-factor authentication for staff, and prompt removal of access when a role changes or ends. Authentication Multi-factor authentication available to all customers, device recognition, and session expiry. Network security Segregated environments, restricted administrative access, and monitoring of traffic for abuse. Fraud prevention Automated fraud scoring, device fingerprinting at sign-up, blocking of abusive addresses and numbers, and rate limits on unverified accounts. Logging Access and administrative actions logged, with logs retained for 12 months. Resilience Data replicated within the hosting region, with regular backups and documented restore procedures. Development Code review before release, dependency scanning, and separation of development, staging and production environments. Staff Confidentiality obligations in every contract, background checks where lawful, and security training. Suppliers Security assessment before engagement, contractual data protection obligations, and annual review. Incident response A documented process covering detection, containment, assessment, notification and review. Deletion Documented deletion procedures with retention periods enforced and recorded. Annex III — Sub-processors The current list is published as the Calilio Sub-processor List and forms part of this agreement. Notice of changes is given as set out in the Sub-processors section. Questions For a signed copy, a completed security questionnaire, or a copy of our transfer safeguards, write to [email protected]. CALILIO PTE. LTD. · UEN 202433643W · 14 Robinson Road, #08-01, Far East Finance Building, Singapore 048545