AvenDesk

Data Processing Addendum

Your customers’ data,
in our hands.

When your callers tell our receptionist their name and address, that record is yours and we are only holding it. This is the binding version of what that means — what we may do with it, what we must do to protect it, and the one thing this document cannot give you.

Last updated 18 August 2026

The short version

  • It already applies to you. No signature, no request, no PDF — it is part of your Terms from the moment you use the Services. We will countersign a copy if your file needs one.
  • Your callers' data is yours; we are only the processor. We act on your instructions, and your portal settings are those instructions.
  • One use is ours: improving the receptionist from recordings. Set recording to off and it stops immediately — §5.
  • Every subprocessor is named, individually, at /subprocessors, and we tell you before a new one starts.
  • 72 hours to tell you about a breach, with what we know rather than what is convenient.
  • Deleted 30 days after you close, exportable at any time before that, free.
  • It is not a GDPR Article 28 DPA and there are no SCCs. §13 says exactly what this does not cover, because the customer who needs that is the one who will check.

This summary is for orientation only. It is not part of the agreement, and where it differs from the numbered sections below, the numbered sections are what applies.

This applies to you already

This Data Processing Addendum ("Addendum") forms part of the Terms of Service between AvenDesk LLC, a Colorado limited liability company ("we", "us", "the Processor") and the business that opens an account ("you", "the Controller"). It applies automatically, from the moment you first use the Services. You do not have to sign it, request it, or return anything.

We wrote it that way deliberately. A processing agreement that has to be asked for, negotiated and countersigned is one that a plumber with four vans never gets, and the protection in it is worth exactly as much to them as it is to a company with a legal department. If you need a countersigned copy for a file, email Flowonnco@gmail.com and we will sign this document as it stands — what we will not do is make the protection conditional on having asked.

Where this Addendum and the Terms of Service disagree about the processing of personal data, this Addendum wins. On everything else — fees, liability, termination — the Terms govern. Words defined in the Terms or the Privacy Policy carry the same meaning here.

Which of us is which

Two different sets of data pass through the Services, and this Addendum is only about one of them.

Your callers' personal data — you are the Controller and we are the Processor. Their names, telephone numbers, addresses, what they said on the phone, the transcript, the recording, the appointment. You decided to collect it, you decide why, and we act on it only on your instructions. That is what this Addendum governs.

Your own account data — we are the Controller. Your business details, your billing, your usage, your sign-in records. We decide what happens to that, and our Privacy Policy is our account of it, not this document.

You confirm that you have a lawful basis for collecting your callers' data and for having us process it, that you have given whatever notice the law where your callers are requires, and that your instructions to us will not put us in breach of the law.

What we process, and for how long

Subject matter and purpose. Answering, transcribing and — depending on your setting — recording your telephone calls and text messages; conversing with the person on the other end in your business's name; booking, rescheduling and confirming appointments; taking messages; transferring urgent callers; writing to a calendar or CRM you connected; and showing all of it back to you in your portal.

Categories of data subject. The people who call, text or message your business, the people who submit a form on a website you have connected, and any person your callers mention to the receptionist.

Types of personal data. Names; telephone numbers; email addresses; service and home addresses; the content of what somebody said or wrote; call transcripts; call recordings where your setting permits them; appointment details; and any other information a caller volunteers. The receptionist is configured not to solicit payment card numbers, government identifiers or health information, but it cannot stop a caller offering something anyway.

Duration. For as long as your account is open, plus the 30 days described in §11.

We act only on your instructions

We will process your callers' personal data only on your documented instructions, and for no purpose of our own except as §5 sets out. Your instructions are: these terms, this Addendum, the settings you choose in your portal, and anything else you ask us to do in writing.

Your portal settings are instructions, not preferences — your recording mode, your hours, your escalation number, your connected accounts, whether form capture is on. Changing one changes what we are permitted to do, from the moment you change it.

If we believe an instruction of yours breaks the law, we will tell you and we may decline to carry it out. If we are compelled by law to process something outside your instructions, we will tell you before we do it unless that law forbids us from telling you.

The one use that is ours, and how to switch it off

We use call recordings and transcripts to improve the AI receptionist — correcting what it misheard, tuning how it handles a trade like yours, testing changes against real conversations before they reach anybody's phone line, and training and evaluating the models and prompts behind it.

We are naming it here rather than burying it, because it is the one processing we do that is not purely on your instruction. It is a condition of the Services at the price they are sold at, and by using them you instruct and authorise it.

You can switch it off: set your recording mode to off in your portal. We keep the written transcript, you keep the transcript, and there is no audio to learn from. That is a setting, not a request, and it takes effect immediately.

We do not sell your callers' data and we do not use it to advertise to anybody, and we never will under this Addendum.

Confidentiality

We keep your callers' personal data confidential. Access inside our team is limited to the people who need it to run the Services, support you, investigate abuse or answer a lawful demand, and it is logged.

Everyone with that access is under a duty of confidentiality that survives them leaving. Our Privacy Policy sets out exactly what our own staff can do — read it, export it, erase it, hand it over under a warrant — and that every one of those actions is written to a ledger, with a name against it, before it is carried out.

The security measures we actually take

We will keep appropriate technical and organisational measures in place, having regard to the state of the art, the cost, and the risk to the people whose data it is. Concretely, and as of the date at the top:

  • Passwords stored as scrypt hashes with a per-account salt. A leak of our data would not hand anybody a usable password, and we cannot read yours.
  • An authenticator-app second factor available on every portal account.
  • Sign-ins rate-limited per network and locked out per account after repeated failures, before any password check runs.
  • Sessions revoked when an account is closed, and every other session signed out the moment a password is changed or reset — not merely expired, ended.
  • Encryption in transit on everything, with HSTS, and a Content-Security-Policy that refuses third-party script and blocks the browser from sending data anywhere but us.
  • Tenant isolation — one business's data is never reachable from another's session, and that is asserted by an automated test rather than assumed.
  • Least-privilege internal access, logged, with an audited ledger behind every export, erasure and disclosure.
  • Automated screening of what the receptionist says, the texts you send and the wording you give it, against our acceptable-use rules — described in the Privacy Policy, which also says what it does not do.

Subprocessors

You give us general authorisation to engage subprocessors, and the ones we have engaged are named, individually, at /subprocessors. That page is part of this Addendum.

We will update it before a new subprocessor starts handling your callers' data. Ask us at Flowonnco@gmail.com and we will tell you in advance each time rather than leaving you to check. If you object to a new one, you may close your account without penalty and we will refund the unused part of your month.

Here is what we cannot promise, and it is the reason to read §13. A processing addendum normally binds the processor to impose these same obligations on every subprocessor by contract. We have no negotiated agreement with any of ours — we use them on their published terms, as an ordinary customer. So we cannot flow these obligations down, we do not represent that we have, and we remain liable to you for the Services as a whole without being able to promise what a provider does with what reaches it.

We picked the smallest chain that can answer a telephone call, and we publish it. That is the honest extent of the control we have.

Helping you meet your own obligations

Requests from the people whose data it is. Your portal already does most of this yourself: you can find a caller's record, correct it, export it and delete it, immediately and without asking us. Where you cannot, email Flowonnco@gmail.com and we will produce everything we hold about one person, on a telephone number, as a file — or erase every record of them across bookings, messages, calls, texts and customer records, permanently. We do not charge you for either.

A request that comes to us instead of you. If one of your callers asks us directly, we will pass it to you and follow your instruction rather than acting on our own — it is your record, not ours, and a supplier destroying its customer's records on a stranger's say-so is not data protection. If we cannot reach you, we will tell them so.

Assessments and audits. We will give you the information you reasonably need to show your own regulator or customer that the processing is lawful — including what is on this page, the subprocessor register, and answers to a security questionnaire. We do not host on-site audits or give third-party auditors access to production, both because production holds other businesses' customers and because we are too small for it to be anything but theatre. If that is not enough for you, say so before you sign up.

If there is a breach

If we become aware of a personal data breach affecting your callers' data, we will tell you without undue delay and in any event within 72 hours of becoming aware of it — what happened, which categories and roughly how many people are affected, what the likely consequences are, and what we are doing about it.

Where we do not have the full picture within 72 hours we will tell you what we do know and follow up rather than waiting until the account is complete. We will help you meet your own notification duties to regulators and to the people affected.

Notifying your callers and your regulator is yours to do, because you are the Controller and it is your relationship with them. We will give you what you need to do it.

Getting it back, and getting it deleted

While your account is open you can have a copy of it whenever you like, at no charge — bookings, customers and call records. There is no self-serve export button in the portal yet, so today that means emailing Flowonnco@gmail.com and a member of our staff producing the file. We would rather write that down than describe a button you will go looking for and not find.

When you close your account, access ends immediately and everything is destroyed 30 days later. The gap is deliberate: deletion has no undo, and a misclick, a shared login or a departing employee should not be able to obliterate every record a business has. Ask us inside those 30 days and we will restore it. After them it is gone.

Two things outlive it, and neither is your callers' data: invoices and tax records, which we are required to keep, and security and abuse logs for up to 12 months, which record what happened rather than what anybody said.

Where the processing happens

We and our subprocessors are in the United States, and that is where your callers' data is stored and processed — with one exception, named on the subprocessor register: the last language model in our failover chain is operated from China, and receives conversation text only if two US providers have failed mid-call.

If you or your callers are outside the US, using the Services transfers their data there, and US law will not always give it the protections their own country does.

What this Addendum is not

Read this section before you file this document as evidence of anything.

This is not a GDPR Article 28 DPA and it does not pretend to be. It does not include Standard Contractual Clauses, an International Data Transfer Agreement, a UK Addendum, or any other approved transfer mechanism, and we have none in place — with you or with any provider behind us.

We cannot flow these obligations down to our subprocessors (§8), which is the specific commitment an Article 28 chain requires and the specific one we cannot make.

This is not a HIPAA Business Associate Agreement. Do not put protected health information through the Services unless we have signed a BAA with you, which today we have not.

So: if your business is subject to UK or EU data protection law, or your customer's compliance file requires SCCs or a full Article 28 chain, this service cannot satisfy it. Ask us before you sign up rather than after. We would rather lose the sale than have you find this out at an audit.

What this Addendum is is a binding commitment, under US state privacy law, that we process your callers' data only on your instructions, that we secure it as §7 describes, that we help you answer the people it belongs to, that we tell you when something goes wrong, and that we give it back and delete it when you leave.

Liability, changes and law

Our liability under this Addendum is subject to the limitations in the Terms of Service, including the cap on total liability, and the two documents are read together as one agreement rather than as two independent ones.

We may update this Addendum. Where a change materially reduces the protection it gives you, we will email the address on your account at least 30 days before it takes effect, and you may close your account within those 30 days without penalty if you do not accept it. We keep prior versions and will send you one on request.

This Addendum is governed by the law of the State of Colorado and the dispute resolution section of the Terms applies to it. It ends when the Terms end, except that §6, §11, §13 and this section survive.

For your file

Need it signed?

Email us and we will sign this document as it stands and send it back. What we will not do is negotiate a clause we cannot honour — if your compliance file needs Standard Contractual Clauses or a full Article 28 chain, read “What this Addendum is not” first, and then ask us — before you sign up.

Flowonnco@gmail.com

This document

Controller
You, for your callers' data
Processor
AvenDesk LLC
In force
Automatically, no signature needed
Subprocessors
Named individually, notice before a change
Breach notice
Within 72 hours
Deletion
30 days after an account closes
SCCs / Article 28
Not provided — see “What this Addendum is not”
Last updated
18 August 2026

Read alongside our Terms, Privacy Policy and Subprocessors.