Data Processing Agreement
Effective Date: September 24, 2026
This Data Processing Agreement (“DPA”) is entered into between i3Simple (“Processor”) and the customer (“Controller”) and governs the processing of personal data by i3Simple on behalf of the customer. It is incorporated into the Terms of Service. In the event of conflict, this DPA prevails on data processing matters.
Definitions
Personal Data: Any information relating to an identified or identifiable natural person under applicable data protection law, including the GDPR and CCPA/CPRA.
Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
Data Subject: The individual whose personal data is processed.
Sub-processor: Any third party engaged by i3Simple to process personal data on the customer’s behalf.
Scope of Processing
Nature and Purpose: i3Simple processes personal data solely to provide the Service. Activities include: storing contacts and calling lists uploaded by the customer; carrying, recording and transcribing calls; generating AI summaries and, where enabled, analysis of call content; recording which staff member handled which call; providing analytics and reporting; and facilitating integrations the customer connects.
Categories of Data: Contact names, business names and phone numbers; email addresses; call recordings and voice data; conversation transcripts; AI-generated summaries and, where enabled, sentiment analysis; appointment details; notes and outcomes recorded by staff; the customer’s own staff details (name, email, mobile number, role, availability); and any custom fields the customer configures.
Duration: For the subscription term and 90 days after termination, after which personal data is permanently deleted unless retention is required by law.
No training use: i3Simple does not use customer personal data, call recordings, transcripts or contacts to train machine learning models, and contracts with its sub-processors on the same basis.
Customer Obligations
The customer as Controller represents and warrants that it: has a lawful basis for all personal data it submits; has given all required notices to data subjects, including any recording disclosure; has obtained all required consents where consent is the basis; is responsible for the conduct of its own staff accounts; and complies with all applicable data protection and telephone consumer law.
i3Simple Obligations
i3Simple as Processor agrees to: process personal data only on the customer’s documented instructions; ensure anyone with access is bound by confidentiality; implement the security measures described below; assist the customer in responding to data subject requests; notify the customer of a personal data breach without undue delay and within 72 hours of becoming aware; delete or return personal data on termination; and make available the information reasonably necessary to demonstrate compliance with this DPA.
Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Telnyx LLC | Telephony, phone numbers, SIP | United States |
| ElevenLabs Inc. | AI voice and conversation handling | United States |
| OpenAI Inc. | Post-call text analysis, where enabled | United States |
| Google LLC | Calendar, Sheets and Drive, where the customer connects them | United States |
| Stripe Inc. | Payment processing | United States |
| Contabo GmbH | Server infrastructure | Germany |
i3Simple will give at least 30 days notice of any intended change to this list. The customer may object within 14 days, and if the objection cannot be resolved may terminate the affected part of the Service without penalty.
Data Subject Rights
i3Simple will assist the customer in fulfilling access, rectification, erasure, restriction, and portability requests. If i3Simple receives a request directly from a data subject, it will forward it to the customer promptly rather than respond itself.
Security Measures
- Encryption of data in transit using TLS 1.2 or higher
- Encryption at rest on database backups
- Role-based access control, enforced server-side, so each user reaches only what their role permits
- Separate telephony credentials per user, so access can be withdrawn individually and calls are attributable
- Access to production systems limited to authorised personnel on a need-to-know basis
- Logging and monitoring of platform activity, with a daily operational review
- Documented incident response and restoration procedure, with regular tested backups
- Security-relevant dependencies reviewed and updated on an ongoing basis
i3Simple is a small company and does not currently hold SOC 2 or ISO 27001 certification, nor conduct third-party penetration testing. We state this plainly rather than imply otherwise.
International Data Transfers
Personal data is stored on servers in Germany and processed by sub-processors in the United States. For customers in the EEA and UK, transfers are made under Standard Contractual Clauses adopted by the European Commission. Copies available from legal@i3simple.com.
Contact
i3Simple · legal@i3simple.com