Legal
Data Processing Agreement
Last updated: August 2, 2026
This DPA is incorporated by reference into Dorazo's Master Service Agreement and governs all processing of personal data by Dorazo on behalf of the Customer. Have your legal counsel review this document before signing.
Definitions
- “Controller” means the Customer — the entity that determines the purposes and means of processing personal data.
- “Processor” means Dorazo — the entity that processes personal data on behalf of the Controller.
- “Personal Data” means any information relating to an identified or identifiable natural person processed in connection with the Services.
- “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- “Sub-processor” means any third party engaged by Dorazo to process Personal Data on the Controller's behalf.
- “Applicable Data Protection Law” means the GDPR, CCPA, and any other applicable privacy or data protection legislation.
Roles and Scope
The Customer is the Controller of Personal Data submitted to the Dorazo platform. Dorazo acts solely as a Processor, processing such data only as instructed by the Customer and as necessary to provide the Services.
This DPA applies to Personal Data that Dorazo processes on the Customer's behalf, including:
- Business owner and staff contact information
- Caller names, phone numbers, and call records
- Call transcripts and appointment data containing personally identifiable information
- Communications data (SMS, email, and voice call records)
Processing Instructions
Dorazo shall process Personal Data only on documented instructions from the Customer, including as set out in the Master Service Agreement and this DPA, unless otherwise required by applicable law. Dorazo will promptly inform the Customer if any instruction violates Applicable Data Protection Law.
Dorazo personnel authorized to process Personal Data are bound by confidentiality obligations.
Sub-processors
The Customer authorizes Dorazo to engage the following sub-processors to assist in delivering the Services. Dorazo shall impose data protection obligations on each sub-processor equivalent to those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic, PBC | AI language model processing (chat, voice scripts) | USA |
| Supabase, Inc. | Database hosting and storage | USA |
| Twilio Inc. | SMS and voice call delivery | USA |
| Resend, Inc. | Transactional email delivery | USA |
| Stripe, Inc. | Payment processing | USA |
| Railway Corp. | Application hosting and compute | USA |
Dorazo will notify the Customer with at least 30 days' notice before engaging a new sub-processor. If the Customer objects, Dorazo will use commercially reasonable efforts to accommodate the objection; if it cannot, the Customer may terminate the Services for cause.
Security Measures
Dorazo shall implement and maintain technical and organizational security measures appropriate to the risks presented by the Processing, including:
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls limiting Personal Data access to authorized personnel on a need-to-know basis
- Regular security assessments and vulnerability scanning
- Logical separation of customer data environments
- Incident response and breach notification procedures
Data Breach Notification
Dorazo shall notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of a Personal Data breach affecting the Customer's data. The notification will include, to the extent known:
- The nature and approximate scope of the breach
- Categories and approximate number of individuals and records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
The Customer is solely responsible for notifying affected data subjects and relevant supervisory authorities as required by Applicable Data Protection Law.
Data Subject Rights
Dorazo will assist the Customer in responding to data subject requests to exercise rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, and portability). The Customer is responsible for handling all such requests from its data subjects. Dorazo will provide reasonable technical assistance within 30 days of the Customer's documented request.
International Transfers
Personal Data is processed and stored in the United States. Where required by Applicable Data Protection Law for transfers from the EEA, UK, or Switzerland, the parties agree to execute Standard Contractual Clauses (SCCs) as adopted by the European Commission or equivalent transfer mechanisms. To obtain SCCs, contact legal@dorazoai.com.
Audit Rights
Upon 30 days' written notice and no more than once per year, Dorazo will cooperate with Customer audits of data processing practices relevant to this DPA by providing written responses to reasonable security questionnaires or, where applicable, sharing third-party audit reports (e.g., SOC 2) under confidentiality. On-site audits require mutual written agreement and are subject to reasonable time and access limitations.
Return and Deletion of Data
Upon termination of the Services, Dorazo will, at the Customer's election:
- Make Customer Personal Data available for export in a commercially reasonable format; or
- Securely delete Customer Personal Data within 90 days of termination
Dorazo may retain anonymized or aggregated data that cannot be linked to any individual or Customer.
Liability and Indemnification
Each party's liability under this DPA is subject to the limitations set out in the Master Service Agreement. Dorazo is liable for damages caused by Processing that fails to comply with this DPA or Applicable Data Protection Law where Dorazo is at fault. The Customer is liable for damages resulting from instructions that violate Applicable Data Protection Law.
Contact
For DPA execution, data processing questions, or to request Standard Contractual Clauses, contact legal@dorazoai.com.