Legal
Data Processing Agreement
Ajora
- Version 1.0 · Last updated: 20 April 2026
This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement") between:
Ajora B.V., a Dutch besloten vennootschap (private limited company) registered in the Handelsregister under KvK number 42138300, with its registered office at Poortstraat 28, 3572 HJ Utrecht, the Netherlands, operating the Ajora service ("Ajora", "Processor"),
and
the Account Holder who has entered into the Agreement ("Customer", "Controller").
Each a "Party" and together the "Parties".
This DPA governs the processing of Personal Data by Ajora on behalf of the Customer in connection with the Ajora service (the "Service"). It is designed to meet the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR") and the Dutch Uitvoeringswet AVG.
By accepting the Agreement, the Customer enters into this DPA. A signed PDF version is available on request via [email protected] for Customers that require a countersigned copy.
1. Definitions
Terms used but not defined in this DPA have the meaning given in the GDPR or the Agreement. The following terms have the following meanings:
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Ajora on behalf of the Customer in connection with the Service.
- "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the GDPR.
- "Sub-processor" means any third party engaged by Ajora to process Personal Data on its behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Implementing Decision (EU) 2021/914.
- "EU-US Data Privacy Framework" or "DPF" means the framework approved by the European Commission in Implementing Decision (EU) 2023/1795.
- "Applicable Data Protection Law" means the GDPR, the Uitvoeringswet AVG, the ePrivacy Directive 2002/58/EC as implemented locally, and any other data protection law applicable to the Processing under this DPA.
2. Scope, Roles, and Instructions
- 2.1 Roles. For the purposes of this DPA, the Customer is the Controller of the Personal Data and Ajora is the Processor. Each Party is responsible for its own compliance with Applicable Data Protection Law in its respective role.
- 2.2 Subject matter and purpose. Ajora processes Personal Data solely for the purpose of providing the Service to the Customer, as described in Annex A.
- 2.3 Duration. This DPA applies for the duration of the Agreement and for any further period during which Ajora processes Personal Data on behalf of the Customer.
- 2.4 Documented instructions. Ajora shall process Personal Data only on the documented instructions of the Customer, as set out in this DPA, the Agreement, the Privacy Policy, and the Customer's use of the Service through its configuration and account. Any additional instructions require mutual written agreement and may be subject to additional fees.
- 2.5 Compliance with law. If Ajora is required by Union or Member State law to process Personal Data outside the Customer's instructions, Ajora shall inform the Customer of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
- 2.6 Unlawful instructions. Ajora shall inform the Customer without delay if, in its opinion, an instruction from the Customer infringes Applicable Data Protection Law. Ajora is not obliged to verify the lawfulness of Customer instructions beyond a reasonable assessment.
3. Customer Obligations
- 3.1 The Customer warrants that:
- It has a valid legal basis under GDPR Article 6 for the Processing instructed, including for the recording of telephone calls and the processing of other parties to those calls.
- It has provided all notices and obtained all consents required under Applicable Data Protection Law, including any consent from other parties to a call before a recording begins.
- Its instructions to Ajora comply with Applicable Data Protection Law.
- 3.2 The Customer acknowledges and accepts that the recording, transcription, and AI-processing of call content creates specific legal obligations in the Customer's capacity as Controller, including those described in the Terms of Service §3 and the Privacy Policy §6.
4. Confidentiality
- 4.1 Ajora shall ensure that all personnel authorised to process Personal Data:
- Are informed of the confidential nature of the Personal Data.
- Are bound by appropriate contractual or statutory obligations of confidentiality that survive termination of their engagement.
- Receive appropriate training on data protection and information security.
- 4.2 Access to Personal Data is limited to personnel who need access to fulfil their duties under the Agreement.
5. Security
- 5.1 Ajora shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32. The measures in place as at the effective date of this DPA are set out in Annex B.
- 5.2 Ajora may update the technical and organisational measures from time to time, provided that the updated measures do not materially reduce the level of security. The current measures are available on request.
- 5.3 The Customer acknowledges that the measures in Annex B are appropriate for the nature of the Service and the Personal Data processed, taking into account the state of the art, the costs of implementation, and the risks of varying likelihood and severity to Data Subjects.
6. Sub-processors
- 6.1 General authorisation. The Customer provides general written authorisation for Ajora to engage Sub-processors to process Personal Data on its behalf. The Sub-processors engaged as at the effective date of this DPA are listed in Annex C.
- 6.2 Sub-processor obligations. Ajora shall:
- Enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA.
- Remain fully liable to the Customer for the acts and omissions of its Sub-processors as if they were its own.
- Assess each Sub-processor's data protection and security practices before onboarding.
- 6.3 Changes to Sub-processors. Ajora shall notify the Customer at least 30 days before adding or replacing a Sub-processor involved in processing call content, by email to the address associated with the Customer's account and by updating the sub-processor list in the privacy policy.
- 6.4 Objection. The Customer may object, on reasonable data protection grounds, to a new Sub-processor within 15 days of notification. If the objection cannot be resolved within a reasonable period, the Customer may terminate the Agreement before the new Sub-processor begins processing, and Ajora shall refund any prepaid fees for the unused portion of the subscription term. For clarity, objections based on commercial preference are not considered reasonable grounds under this clause.
7. International Transfers
- 7.1 The Customer authorises Ajora to transfer Personal Data outside the European Economic Area to the Sub-processors listed in Annex C, subject to the safeguards set out in that Annex.
- 7.2 Each transfer shall be covered by an adequate safeguard under GDPR Chapter V, including:
- EU-US Data Privacy Framework certification, where the Sub-processor is certified; or
- Standard Contractual Clauses (Module 2 or Module 3 as applicable), where DPF certification is unavailable.
- 7.3 Ajora shall periodically verify the continued availability of these safeguards and shall notify the Customer of any material change.
8. Assistance with Data Subject Rights
- 8.1 Taking into account the nature of the Processing, Ajora shall assist the Customer, by appropriate technical and organisational measures, in responding to requests from Data Subjects exercising their rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated decision-making).
- 8.2 Where Ajora receives a Data Subject request directly that relates to Personal Data processed on behalf of the Customer, Ajora shall:
- Not respond to the request directly (except to acknowledge receipt and redirect the Data Subject).
- Forward the request to the Customer without undue delay.
- Provide reasonable assistance to the Customer in responding.
- 8.3 Ajora provides the following self-service capabilities through the Customer's account dashboard:
- Export of all transcripts and summaries in a machine-readable format.
- Deletion of individual transcripts, call records, or the entire account.
- Access to account and usage data.
- 8.4 Where Ajora's assistance beyond these self-service capabilities requires disproportionate effort, Ajora may charge a reasonable fee, communicated to the Customer in advance.
9. Assistance with Controller Obligations
Ajora shall provide the Customer with reasonable assistance in fulfilling the Customer's obligations under GDPR Articles 32 to 36, including:
- Responding to reasonable requests for information necessary to demonstrate compliance with GDPR Article 32 (security).
- Notifying the Customer of Personal Data Breaches under Article 33 (see §10 below).
- Providing information reasonably required for the Customer to conduct a Data Protection Impact Assessment under Article 35, or to consult the Supervisory Authority under Article 36.
10. Personal Data Breach Notification
- 10.1 Ajora shall notify the Customer of a Personal Data Breach affecting Personal Data processed on behalf of the Customer without undue delay and in any event within 72 hours of becoming aware of the breach.
- 10.2 The notification shall, to the extent information is available, describe:
- The nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and mitigate its adverse effects.
- Contact details for further information.
- 10.3 Ajora shall cooperate with the Customer and provide reasonable assistance in investigating, mitigating, and remediating the breach and in notifying the Supervisory Authority and Data Subjects where required.
- 10.4 Notifications to the Customer shall be sent to the email address associated with the Customer's account. The Customer is responsible for keeping this address up to date.
11. Audits
- 11.1 The Customer has the right to audit Ajora's compliance with this DPA once per calendar year, at the Customer's cost, subject to the following conditions:
- The audit is carried out by a qualified, independent third-party auditor reasonably acceptable to Ajora, who is bound by written confidentiality obligations.
- The Customer gives Ajora at least 30 days' prior written notice.
- The audit is conducted during normal business hours, in a manner that does not unreasonably interfere with Ajora's operations.
- The audit does not access data belonging to other customers, trade secrets, or information that would compromise the security of other customers.
- The Customer and its auditor execute a confidentiality agreement reasonably acceptable to Ajora.
- 11.2 Where Ajora holds a current SOC 2 Type II, ISO 27001, or equivalent third-party security certification or audit report, Ajora may satisfy the audit obligation in §11.1 by providing a copy of the relevant report, provided the report adequately addresses the Customer's concerns.
- 11.3 In the event of a confirmed Personal Data Breach or an enforcement action by a Supervisory Authority, the 30-day notice period and once-per-year limitation do not apply.
- 11.4 Ajora is not required to disclose information that is subject to confidentiality obligations owed to third parties, legal privilege, or applicable law.
12. Return or Deletion of Personal Data
- 12.1 On termination or expiry of the Agreement, Ajora shall, at the Customer's choice communicated within 30 days of termination:
- Return all Personal Data to the Customer in a commonly used, machine-readable format; or
- Delete all Personal Data and provide written confirmation of deletion.
- 12.2 In the absence of Customer instruction within 30 days, Ajora shall delete all Personal Data in accordance with the retention schedule in the Privacy Policy §4.
- 12.3 Ajora may retain Personal Data to the extent required by Applicable Law, in which case it shall continue to protect that data in accordance with this DPA for as long as it is retained.
- 12.4 Personal Data held in encrypted backups shall be deleted within 90 days of termination, consistent with the Privacy Policy.
13. Liability
- 13.1 Each Party's liability under or in connection with this DPA is subject to the limitation of liability clause in the Agreement. The liability cap in the Agreement applies to the combined liability of the Parties under the Agreement and this DPA taken together, and is not increased or duplicated by this DPA.
- 13.2 Notwithstanding §13.1, nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Law, including liability toward Data Subjects under GDPR Article 82.
14. Term and Termination
- 14.1 This DPA enters into force on the effective date of the Agreement and continues until the Agreement terminates, subject to §2.3.
- 14.2 Termination of the Agreement terminates this DPA, except for those provisions that by their nature survive termination, including Sections 4 (Confidentiality), 10 (Breach Notification in relation to breaches occurring before termination), 12 (Return or Deletion), and 13 (Liability).
15. Miscellaneous
- 15.1 Order of precedence. In the event of a conflict between this DPA and the Agreement or any other agreement between the Parties in relation to data protection matters, this DPA prevails, except where the conflicting term provides a higher level of protection for Data Subjects.
- 15.2 Changes. Ajora may update this DPA to reflect changes in Applicable Data Protection Law, regulatory guidance, or the Service. Material changes will be communicated to the Customer at least 30 days in advance. If the Customer reasonably objects to a material change, the Customer may terminate the Agreement before the change takes effect.
- 15.3 Governing law. This DPA is governed by the laws of the Netherlands. The courts of Rechtbank Midden-Nederland, location Utrecht, have exclusive jurisdiction, subject to appeal as provided by Dutch law.
- 15.4 Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in full effect.
- 15.5 Entire agreement. This DPA, together with the Agreement and its incorporated documents, constitutes the entire agreement between the Parties regarding the processing of Personal Data and supersedes any prior understanding.
- 15.6 Language. This DPA is available in Dutch and English. In the event of any discrepancy between the two versions, the Dutch version prevails.
Annex A: Description of Processing
Subject matter
Processing of Personal Data by Ajora as Processor for the purpose of providing the Ajora call intelligence service to the Customer.
Duration
For the term of the Agreement and any period thereafter during which Ajora retains Personal Data, subject to §12.
Nature and purpose of Processing
- Recording of telephone calls initiated by the Customer.
- Transmission of call audio to a transcription service.
- Generation and storage of encrypted transcripts.
- AI-generated summarisation, action point extraction, key decision identification, and sentiment analysis.
- Delivery of debriefs to the Customer by email and through the account dashboard.
- Storage of account, billing, and usage data.
Categories of Data Subjects
- The Customer (if a natural person) and authorised users of the Customer's account.
- Other parties to telephone calls recorded by the Customer.
- Any natural persons whose Personal Data is incidentally captured in call content.
Categories of Personal Data
- Identification and contact data: name, email address, phone number.
- Authentication data: hashed password, session tokens.
- Call content: audio (transient), transcripts, summaries, action points, decisions, sentiment assessments.
- Call metadata: date, time, duration, phone number that initiated the call.
- Usage data: IP address, timestamps, API response codes.
- Billing data: processed directly by Mollie; Ajora does not receive payment card details.
Special categories of Personal Data
The Service is not intended for, and must not be used for, the processing of special categories of Personal Data within the meaning of GDPR Article 9 (for example, data concerning health, political opinions, religious beliefs, or biometric data for identification). The Customer is responsible for ensuring that such data is not submitted to the Service, and acknowledges that the technical and organisational measures in Annex B are calibrated to standard business call content, not to special category data.
Frequency
Continuous for the duration of the Agreement.
Annex B: Technical and Organisational Measures
Ajora implements the following technical and organisational measures under GDPR Article 32. These measures supplement and reflect the security commitments in the Privacy Policy §7.
Encryption
- Transcripts and summaries are encrypted at rest using AES-256 with per-account data keys.
- Master keys are managed by AWS Key Management Service (KMS) in the EU (Frankfurt) under strict access controls and are never stored in plaintext in the Ajora application.
- All data in transit is encrypted using TLS 1.2 or higher.
Access control
- Access to production systems is restricted to a small number of authorised personnel.
- Multi-factor authentication is enforced for all personnel with access to production systems.
- Access to key material is fully logged via AWS CloudTrail and reviewed periodically.
- Access reviews are conducted on a regular basis.
Confidentiality
- Personnel with access to Personal Data are bound by confidentiality obligations that survive termination of their engagement.
- Personnel receive data protection and security awareness training.
Data minimisation and segregation
- Call audio is deleted from Ajora's systems immediately after transcription.
- Customer data is logically segregated by account and encryption key.
- Usage logs are automatically purged after 90 days.
Availability and resilience
- Database backups are encrypted at rest and stored in the same EU region (Nuremberg).
- Production systems are hosted on Hetzner with standard availability and disaster recovery features.
Integrity
- Application dependencies are monitored for known vulnerabilities.
- Security patches are applied within a reasonable timeframe based on severity.
Sub-processor management
- Sub-processors are assessed for security and privacy controls before onboarding.
- Data Processing Agreements and transfer safeguards are reviewed on a regular basis.
Incident response
- A documented incident response procedure covers detection, containment, forensic review, notification, and post-incident review.
- Personal Data Breach notifications to the Customer and the Supervisory Authority follow GDPR timelines.
Deletion
- Account deletion destroys the per-account encryption key first, rendering existing transcripts cryptographically inaccessible, followed by permanent erasure from production systems within 30 days and from backup systems within 90 days.
Annex C: Sub-processors
The following Sub-processors are authorised under §6 of this DPA as at the effective date. The current list is maintained in the Third-Party Processors chapter of the privacy policy.
| Sub-processor | Location | Purpose | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL (Bedrock) | EU (Frankfurt, eu-central-1) | AI processing of transcripts (Claude) | N/A: EU processing |
| Amazon Web Services EMEA SARL (KMS) | EU (Frankfurt, eu-central-1) | Encryption key management | N/A: EU processing |
| Hetzner Online GmbH (Hosting) | EU (Nuremberg) | Application hosting, database | N/A: EU processing |
| Twilio Inc. | Ireland | Call routing and recording | EU-US Data Privacy Framework |
| ElevenLabs Ltd. | United States | Speech-to-text transcription | EU-US Data Privacy Framework |
| Mollie B.V. | The Netherlands | Payment processing | N/A: EU processing |
| Google Ireland Limited | EU / United States (where applicable) | Website analytics (consent-based) | EU-US Data Privacy Framework |
Ready to upgrade your phone calls?
Your account first, then the app
You set up your account and subscription here on the site. Then you download the app from the App Store or Google Play and log in with the same details.