Dorazo

Legal

Data Processing Agreement

Last updated: August 2, 2026

This DPA is incorporated by reference into Dorazo's Master Service Agreement and governs all processing of personal data by Dorazo on behalf of the Customer. Have your legal counsel review this document before signing.

01

Definitions

  • “Controller” means the Customer — the entity that determines the purposes and means of processing personal data.
  • “Processor” means Dorazo — the entity that processes personal data on behalf of the Controller.
  • “Personal Data” means any information relating to an identified or identifiable natural person processed in connection with the Services.
  • “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • “Sub-processor” means any third party engaged by Dorazo to process Personal Data on the Controller's behalf.
  • “Applicable Data Protection Law” means the GDPR, CCPA, and any other applicable privacy or data protection legislation.
02

Roles and Scope

The Customer is the Controller of Personal Data submitted to the Dorazo platform. Dorazo acts solely as a Processor, processing such data only as instructed by the Customer and as necessary to provide the Services.

This DPA applies to Personal Data that Dorazo processes on the Customer's behalf, including:

  • Business owner and staff contact information
  • Caller names, phone numbers, and call records
  • Call transcripts and appointment data containing personally identifiable information
  • Communications data (SMS, email, and voice call records)
03

Processing Instructions

Dorazo shall process Personal Data only on documented instructions from the Customer, including as set out in the Master Service Agreement and this DPA, unless otherwise required by applicable law. Dorazo will promptly inform the Customer if any instruction violates Applicable Data Protection Law.

Dorazo personnel authorized to process Personal Data are bound by confidentiality obligations.

04

Sub-processors

The Customer authorizes Dorazo to engage the following sub-processors to assist in delivering the Services. Dorazo shall impose data protection obligations on each sub-processor equivalent to those in this DPA.

Sub-processorPurposeLocation
Anthropic, PBCAI language model processing (chat, voice scripts)USA
Supabase, Inc.Database hosting and storageUSA
Twilio Inc.SMS and voice call deliveryUSA
Resend, Inc.Transactional email deliveryUSA
Stripe, Inc.Payment processingUSA
Railway Corp.Application hosting and computeUSA

Dorazo will notify the Customer with at least 30 days' notice before engaging a new sub-processor. If the Customer objects, Dorazo will use commercially reasonable efforts to accommodate the objection; if it cannot, the Customer may terminate the Services for cause.

05

Security Measures

Dorazo shall implement and maintain technical and organizational security measures appropriate to the risks presented by the Processing, including:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls limiting Personal Data access to authorized personnel on a need-to-know basis
  • Regular security assessments and vulnerability scanning
  • Logical separation of customer data environments
  • Incident response and breach notification procedures
06

Data Breach Notification

Dorazo shall notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of a Personal Data breach affecting the Customer's data. The notification will include, to the extent known:

  • The nature and approximate scope of the breach
  • Categories and approximate number of individuals and records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

The Customer is solely responsible for notifying affected data subjects and relevant supervisory authorities as required by Applicable Data Protection Law.

07

Data Subject Rights

Dorazo will assist the Customer in responding to data subject requests to exercise rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, and portability). The Customer is responsible for handling all such requests from its data subjects. Dorazo will provide reasonable technical assistance within 30 days of the Customer's documented request.

08

International Transfers

Personal Data is processed and stored in the United States. Where required by Applicable Data Protection Law for transfers from the EEA, UK, or Switzerland, the parties agree to execute Standard Contractual Clauses (SCCs) as adopted by the European Commission or equivalent transfer mechanisms. To obtain SCCs, contact legal@dorazoai.com.

09

Audit Rights

Upon 30 days' written notice and no more than once per year, Dorazo will cooperate with Customer audits of data processing practices relevant to this DPA by providing written responses to reasonable security questionnaires or, where applicable, sharing third-party audit reports (e.g., SOC 2) under confidentiality. On-site audits require mutual written agreement and are subject to reasonable time and access limitations.

10

Return and Deletion of Data

Upon termination of the Services, Dorazo will, at the Customer's election:

  • Make Customer Personal Data available for export in a commercially reasonable format; or
  • Securely delete Customer Personal Data within 90 days of termination

Dorazo may retain anonymized or aggregated data that cannot be linked to any individual or Customer.

11

Liability and Indemnification

Each party's liability under this DPA is subject to the limitations set out in the Master Service Agreement. Dorazo is liable for damages caused by Processing that fails to comply with this DPA or Applicable Data Protection Law where Dorazo is at fault. The Customer is liable for damages resulting from instructions that violate Applicable Data Protection Law.

12

Contact

For DPA execution, data processing questions, or to request Standard Contractual Clauses, contact legal@dorazoai.com.