Third Party Index

Snapshot 36018

Document
Data processing addendum
URL
https://www.calilio.com/legal/data-processing-agreements
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
131001 bytes
SHA-256 (raw)
00ecfce4680c1ec2e6ff8dde2e7c11cec2a4309e42ba088a74c847c7146e354d
SHA-256 (normalized text)
8ee624c78caf6a03e9b1720aed4d92080cc915862eefbd8a9e4013a90b7cc479

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Sales:
Support:
Log in
Skip to content
This agreement applies automatically to every customer. No signature is required, though we will sign a copy on request.
This Data Processing Agreement governs Calilio's processing of personal data on your behalf. It forms part of your agreement with CALILIO PTE. LTD. (UEN 202433643W) and takes effect automatically when you start using the service.
It is written to satisfy Article 28(3) of the EU and UK General Data Protection Regulation, and to work alongside Singapore's Personal Data Protection Act 2012.
Who is who
For the data in your workspace, you are the controller and Calilio is the processor. You decide what to collect and why. We act on your instructions. For our own billing, website and fraud prevention, Calilio is the controller and our Privacy Policy applies instead.
1. What this covers
Subject matter. Our provision of the Calilio cloud phone system to you.
Duration. From the day you start using the service until the day your account is deleted, plus any period we are legally required to retain records.
Nature and purpose. Hosting, transmitting, storing, recording, transcribing, analysing and making available the voice, message and contact data you and your users create, so that we can deliver the service you bought.
Your instructions. Your documented instructions are your use of the service through its normal features and settings, this agreement, and any further written instruction you give us. We will tell you if we believe an instruction breaks data protection law.
2. Categories of data and people
Types of personal data we process on your behalf:
Names, email addresses, phone numbers and job titles of your users
Contact records you store, including postal addresses, companies, tags and notes
Call detail records: numbers, timestamps, duration and outcome
Call recordings and voicemail audio, where you enable recording
Transcripts, call summaries and sentiment analysis output, where you enable those features
Message content and attachments, including WhatsApp messages
Technical data such as IP addresses, device identifiers, browser details and session records
Categories of people whose data is processed:
Your employees, contractors and other users you invite
Your customers, prospects, suppliers and anyone else your users call, message or store as a contact
Special category data. Calilio is not designed for health, biometric or other special category data. If your use will involve it, tell us first at [email protected] so we can agree the additional measures required.
3. Our obligations
We commit to the following, which mirror Article 28(3)(a) to (h).
We process only on your documented instructions, including for any transfer outside your country, unless a law we are subject to requires otherwise. Where that happens we will tell you before processing, unless the law forbids us from telling you.
Everyone who handles your data is bound to confidentiality, by contract and by a statutory duty where one applies. Access is limited to staff who need it for their role.
We apply appropriate technical and organisational security measures, described in Annex II.
We engage sub-processors only under the conditions in the Sub-processors section.
We help you answer requests from individuals, using the tools in the product and, where those are not enough, with our direct assistance.
We help you meet your own obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and what we know.
At the end of the service we delete or return your personal data, at your choice, and delete existing copies, unless a law requires us to keep something.
We make available the information you need to demonstrate compliance, and we allow and contribute to audits, as set out in the Audits and information section.
We will immediately tell you if, in our opinion, an instruction you give us infringes data protection law.
4. Your obligations
You are responsible for having a lawful basis for the personal data you put into Calilio, and for telling the people concerned what you are doing.
Call recording is your decision. You determine whether recording a call is lawful where you and the other party are, and you must obtain any consent or give any announcement the law requires. We provide the controls; the lawful basis is yours.
You must keep your account secure, manage who has access, and remove users who leave.
You must not put special category data into the service without agreeing it with us first.
You must give your users and contacts the privacy information the law requires.
5. Sub-processors
You give us general authorisation to engage sub-processors, subject to the conditions in this section.
Our current sub-processors are published in our Sub-processor List, which forms part of this agreement.
We email the account administrator on every affected account at least 30 days before a new sub-processor starts processing your data. That happens automatically. You do not have to subscribe, ask, or watch the published page. The notice names the company, says what it will do, where it processes data and on what legal basis it receives transfers. If your privacy or procurement team should also receive these notices, send the addresses to [email protected].
Every sub-processor is bound by a written contract imposing data protection obligations equivalent to those in this agreement.
We remain fully liable to you for a sub-processor's performance of its obligations.
You may object within the notice period, giving your reason. We will work with you to find an alternative. If no reasonable alternative exists and the change would genuinely harm you, you may terminate the affected part of the service without penalty and receive a refund of unused prepaid fees.
6. Security
We apply the measures in Annex II. Those measures are reviewed at least annually and whenever we make a material change to the service.
We may update a measure, provided the overall level of security is not reduced.
7. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event within 48 hours of confirming it.
Our notification describes what happened, the categories and approximate number of people and records affected, the likely consequences, the measures we have taken, and a contact point for more information. Where we cannot give everything at once, we give what we have and follow up.
We do not notify individuals or regulators on your behalf for data where you are the controller. That decision is yours, and we give you what you need to make it.
Where Calilio is the controller, we notify the Personal Data Protection Commission no later than 3 calendar days after assessing that a breach is notifiable, and we notify affected individuals without undue delay.
We keep a record of every personal data breach and make it available to you.
8. Requests from individuals
The Calilio product lets you find, export, correct and delete the personal data in your workspace yourself. In most cases that is the fastest route.
If a request reaches us directly from one of your users or contacts, we will not respond to it on your behalf. We will pass it to you promptly and tell the person we have done so, unless the law requires otherwise.
Where you cannot fulfil a request with the product's own tools, we will help, taking into account the nature of the processing. We do not charge for reasonable assistance.
9. Audits and information
Documentation first. We publish this agreement, our Sub-processor List, our Data Security Policy and Annex II. We also answer security questionnaires. In most cases this satisfies an audit requirement.
Audit on request. Where documentation is genuinely not sufficient, you may audit our compliance with this agreement once in any 12-month period, or more often if a regulator requires it or following a personal data breach affecting your data.
How an audit works. Give us at least 30 days written notice, agree the scope with us, use an independent auditor who is not our competitor, and have the auditor sign a confidentiality agreement. Audits happen during business hours and must not unreasonably disrupt the service.
Limits. We will not give access to other customers' data, to our internal pricing or commercial information, or to any part of our systems where access would compromise another customer's security.
Each side bears its own costs, unless the audit finds a material breach by us, in which case we bear the reasonable cost.
10. International transfers
Calilio and its sub-processors process data in more than one country. The Sub-processor List states the processing locations.
10.1 Transfers from the European Economic Area
Where personal data is transferred from the European Economic Area to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission on 4 June 2021 (Decision (EU) 2021/914) are incorporated into this agreement and form part of it. The selections are made as follows, and are not left open.
Item	Selection
Modules	Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are yourself a processor for your own customer.
Clause 7, docking clause	Included.
Clause 9(a), sub-processors	Option 2, general written authorisation. The notice period is 30 days, as set out in the Sub-processors section.
Clause 11(a), independent dispute resolution	Not included.
Clause 13, supervisory authority	As identified in Annex I.
Clause 17, governing law	Option 1. These Clauses are governed by the law of Ireland, which allows for third-party beneficiary rights.
Clause 18(b), forum	The courts of Ireland.
Annexes I, II and III	Completed by Annex I, Annex II and the Sub-processor List of this agreement.
Why Irish law and Irish courts. The Clauses require the law and the courts of a European Economic Area member state that permits third-party beneficiary rights. Singapore law cannot be selected for this purpose, and any statement to the contrary in an earlier version of this agreement does not apply. This selection governs the Clauses only. The rest of your agreement with Calilio remains governed by Singapore law.
10.2 Transfers from the United Kingdom
Where personal data is transferred from the United Kingdom, the Information Commissioner's International Data Transfer Addendum to the Standard Contractual Clauses, version B1.0 in force 21 March 2022, is incorporated into this agreement, and the Clauses above are read with the Addendum's amendments.
Table	Content
Table 1, Parties	The customer as Exporter, CALILIO PTE. LTD. as Importer. Details and contacts as set out in Annex I.
Table 2, Selected SCCs	The Clauses and selections in the European Economic Area transfers section above.
Table 3, Appendix information	Annex I, Annex II and the Sub-processor List of this agreement.
Table 4, Ending the Addendum	Neither party may end the Addendum when the Approved Addendum changes.
Where the Addendum conflicts with the Clauses, the Addendum prevails for United Kingdom transfers.
10.3 Transfers from Switzerland
Where personal data is transferred from Switzerland, the Clauses apply with the amendments published by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the Commissioner is the supervisory authority, and the Clauses protect the data of legal entities until Swiss law provides otherwise.
10.4 Transfer risk assessment
Before we engage a sub-processor outside the European Economic Area or the United Kingdom, we assess whether the laws of the destination country would prevent it from meeting the Clauses, taking into account the type of data, the length of the processing chain, the destination country's surveillance laws and any practical experience of government access requests.
We record that assessment and make it available to you on request. If an assessment shows the Clauses cannot be met, we do not make the transfer, or we apply supplementary measures such as encryption where we hold the keys.
We reassess when the destination country's law changes materially, and at least every two years.
10.5 Government access requests
We tell you if we receive a legally binding request from a public authority for your data, unless the law prohibits us from doing so, in which case we use reasonable efforts to have the prohibition lifted.
We challenge a request that appears unlawful, overbroad or excessive, and we provide only the minimum the request requires.
We keep a record of the requests we receive and make summary information available to you.
10.6 If a mechanism fails
If a transfer mechanism is invalidated, suspended or withdrawn, we will work with you in good faith to put a lawful alternative in place without undue delay. If no lawful alternative exists, we will suspend the affected transfer rather than continue it.
11. Deletion and return
You can export your data at any time using the product's own tools, for as long as your account is open.
On termination, we delete your personal data, or return it to you first if you ask within 30 days of the account closing.
Deletion is initiated 30 days after a deletion request, which gives you time to withdraw the request and to save anything you need.
What we keep, and why. Invoices and tax records for 5 years from the end of the financial year, as required of a Singapore company by the Companies Act 1967 section 199, the Income Tax Act 1947 section 67, and the Goods and Services Tax Act 1993 section 46. Call detail records and security logs for 12 months. A record of the deletion request itself for 3 years. Backups exist only so we can recover from a failure: they are never searched, restored or read to answer a request, deleted data in a backup is not returned to the live service, and it is overwritten in the ordinary course.
Retained data is not used for any purpose other than the one that requires it to be kept.
12. United States state privacy law
Where United States state privacy law applies to your use of Calilio:
Calilio acts as a service provider, processor or contractor, as those terms are defined in the applicable state law, and not as a business or third party in its own right.
We do not sell or share your personal information, as those terms are defined by the California Consumer Privacy Act, and we do not retain, use or disclose it for any purpose other than performing the service for you.
We do not combine your personal information with personal information we receive from another source, except as permitted to perform the service, to detect security incidents, or to prevent fraud or illegal activity.
We certify that we understand these restrictions and will comply with them.
You may take reasonable steps to confirm that we use your data appropriately, using the documentation and audit routes in the Audits and information section.
If we can no longer meet these obligations, we will tell you promptly and stop the processing concerned.
13. Data protection contact and records
Calilio has designated a Data Protection Officer, as every organisation in Singapore is required to do by section 11(3) of the Personal Data Protection Act 2012.
The Data Protection Officer's business contact address is [email protected], published as required by section 11(5) of that Act. Writing to that address reaches the person responsible for our compliance with this agreement.
We maintain records of the processing we carry out on your behalf, as required by Article 30(2) of the GDPR, and we will provide them to you or to a supervisory authority on request.
Where the law requires us to appoint a representative in the European Union or the United Kingdom, we will appoint one and publish the details here.
14. Assistance with assessments
Where you carry out a data protection impact assessment or consult a supervisory authority about processing that involves Calilio, we will give you the information you reasonably need, taking into account the nature of the processing and what is available to us.
The documentation in this agreement, the Sub-processor List and the Data Security Policy is normally sufficient. Where it is not, write to [email protected] and tell us what the assessment requires.
We do not charge for reasonable assistance.
15. Singapore
Where Singapore's Personal Data Protection Act 2012 applies, Calilio acts as your data intermediary under a contract made in writing, namely this agreement. As data intermediary we are directly bound by the Protection Obligation in section 24, the Retention Limitation Obligation in section 25, and the duty to notify you of a data breach without undue delay. You remain responsible under section 4(3) for personal data processed on your behalf as if you had processed it yourself.
16. Liability, term and precedence
Each party's liability under this agreement is subject to the limits in the Terms of Service, except where data protection law does not allow that limit. This agreement lasts as long as we process personal data on your behalf.
Which document wins if two disagree. This order is identical in the Terms of Service, so there is only one answer:
The European Standard Contractual Clauses and the United Kingdom Addendum, where they apply to a transfer.
This Data Processing Agreement, for anything about how personal data is handled.
Your signed order form, for anything commercial.
The Terms of Service.
The other Calilio policies.
In short: this agreement outranks the Terms of Service on personal data, and the Terms outrank this agreement on everything else.
Annex I — Details of processing
Item	Details
Data exporter	The customer, acting as controller.
Data importer	CALILIO PTE. LTD., UEN 202433643W, 14 Robinson Road, #08-01, Far East Finance Building, Singapore 048545, acting as processor.
Contact	[email protected]
Purpose	Provision of the Calilio cloud phone system: voice calling, messaging, WhatsApp business messaging, contact management, recording, transcription and analysis.
Categories of people	The customer's users, and the customer's contacts and anyone they call or message.
Categories of data	Identity and contact details, call detail records, recordings, voicemail, transcripts, message content and attachments, technical and device data.
Special categories	None by default. Any such processing must be agreed in advance.
Frequency	Continuous, for the duration of the service.
Retention	As set out in the Deletion and return section.
Sub-processors	As published in the Calilio Sub-processor List.
Competent supervisory authority under the Clauses	Determined by Clause 13. Where you are established in the European Economic Area, it is the supervisory authority of that member state. Where you are not established in the European Economic Area but are subject to the GDPR and have appointed an Article 27 representative, it is the supervisory authority of the member state where that representative is established. Where you are subject to the GDPR without a representative, it is the supervisory authority of a member state in which the affected individuals are located.
Supervisory authority for United Kingdom transfers	The Information Commissioner's Office.
Supervisory authority for Calilio's own processing	Personal Data Protection Commission, Singapore.
Annex II — Technical and organisational measures
Measure	Description
Encryption	Data encrypted in transit using current industry-standard protocols. Data at rest encrypted in our hosting provider's storage services.
Access control	Role-based access, least privilege, individual named accounts, multi-factor authentication for staff, and prompt removal of access when a role changes or ends.
Authentication	Multi-factor authentication available to all customers, device recognition, and session expiry.
Network security	Segregated environments, restricted administrative access, and monitoring of traffic for abuse.
Fraud prevention	Automated fraud scoring, device fingerprinting at sign-up, blocking of abusive addresses and numbers, and rate limits on unverified accounts.
Logging	Access and administrative actions logged, with logs retained for 12 months.
Resilience	Data replicated within the hosting region, with regular backups and documented restore procedures.
Development	Code review before release, dependency scanning, and separation of development, staging and production environments.
Staff	Confidentiality obligations in every contract, background checks where lawful, and security training.
Suppliers	Security assessment before engagement, contractual data protection obligations, and annual review.
Incident response	A documented process covering detection, containment, assessment, notification and review.
Deletion	Documented deletion procedures with retention periods enforced and recorded.
Annex III — Sub-processors
The current list is published as the Calilio Sub-processor List and forms part of this agreement. Notice of changes is given as set out in the Sub-processors section.
Questions
For a signed copy, a completed security questionnaire, or a copy of our transfer safeguards, write to [email protected].
CALILIO PTE. LTD. · UEN 202433643W · 14 Robinson Road, #08-01, Far East Finance Building, Singapore 048545