Legal
Data Processing Agreement
Template · Last updated: July 1, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer (the "Controller") and 247Aisupports (the "Processor") for the provision of the 247Aisupports AI customer support platform (the "Service"). It governs the Processor's processing of personal data on the Controller's behalf.
1. Definitions
"Personal Data", "Processing", "Data Subject", "Controller", and "Processor" have the meanings given in the Philippines Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules. Where the Controller is subject to other data-protection laws (e.g. the EU/UK GDPR), equivalent terms apply.
2. Roles of the parties
The Controller determines the purposes and means of processing the personal data of its own customers and end-users. The Processor processes that personal data only on the Controller's documented instructions, including as set out in this DPA and the Terms of Service, except where required to do so by law.
3. Subject matter, nature & purpose
- Subject matter: provision of AI voice, chat, and email customer-support agents.
- Nature & purpose: receiving, processing, and responding to customer inquiries; generating AI responses; storing conversation transcripts and configuration for the Controller.
- Duration: for the term of the Controller's account, plus the retention period in Section 9.
4. Categories of data subjects & personal data
Data subjects: the Controller's customers and end-users who interact with its AI agents, and the Controller's own authorized users.
Categories of personal data may include: name and contact details (email, phone) where provided; conversation transcripts; voice recordings for voice calls; language and interaction metadata (timestamps); and technical data such as IP address for security and rate-limiting. The Controller must not submit special-category / sensitive personal data unless it has confirmed the Service is appropriate for that use and has a lawful basis to do so.
5. Processor obligations
- Process personal data only on the Controller's documented instructions.
- Ensure personnel authorized to process personal data are bound by confidentiality.
- Implement the technical and organizational security measures described in Section 7.
- Not use personal data for any purpose other than providing the Service, and not use it to train AI models.
- Assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations.
6. Subprocessors
The Controller authorizes the Processor to engage the following subprocessors:
- Enterprise AI provider — AI response generation (LLM inference) for voice, chat, and email. Conversation content is processed to generate replies and is not used to train models.
- Cloud infrastructure provider — application hosting and infrastructure.
The Processor imposes data-protection obligations on each subprocessor consistent with this DPA and remains responsible for their performance. The Processor will give the Controller reasonable notice of any intended change of subprocessor, giving the Controller the opportunity to object on reasonable data-protection grounds.
7. Security measures
- Encryption in transit (HTTPS/TLS) for all connections.
- Encryption at rest (AES-256-GCM) for stored integration secrets; passwords hashed with bcrypt.
- Logical per-tenant data isolation; access scoped to the authenticated tenant.
- JWT-based access control, optional two-factor authentication, and session revocation.
- Rate limiting, input sanitization, and prompt-injection detection.
A plain-language overview is available on our Trust & Security page.
8. Personal data breach notification
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide information reasonably available to help the Controller meet its own notification obligations (including to the National Privacy Commission and affected data subjects where required).
9. Retention, return & deletion
The Processor retains personal data for as long as the Controller's account is active. On request, or on termination of the account, the Processor will delete the Controller's personal data within 30 days, except where retention is required by law. The Controller may request an export of its data before deletion.
10. Data-subject requests
Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data-subject rights (access, correction, erasure, objection, portability).
11. Audit & information
The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA. The parties will agree in advance on the scope, timing, and cost of any audit, conducted in a manner that does not compromise the security or confidentiality of other customers' data.
12. International transfers
Where processing by a subprocessor involves a transfer of personal data across borders, the Processor will ensure an appropriate lawful transfer mechanism is in place consistent with applicable data-protection law.
13. Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
14. Governing law
This DPA is governed by the laws of the Republic of the Philippines. Any disputes will be resolved in the courts of the Philippines, without prejudice to any mandatory data-protection provisions of the Controller's jurisdiction.
15. Signatures
To execute this DPA, complete the details below. A countersigned copy can be requested at [email protected].
- Company: ______________________
- Name / title: ______________________
- Signature: ______________________
- Date: ______________________
- Name / title: ______________________
- Signature: ______________________
- Date: ______________________
16. Contact
Questions about this DPA can be sent to [email protected].
