Legal
Data Processing Addendum
Last updated: July 28, 2026
This Data Processing Addendum ("DPA") is part of the Roddy HQ Terms of Service (the "Agreement") between Dakar Projects LLC, a Texas limited liability company doing business as Roddy HQ ("Roddy HQ", "we", "us"), and the business that subscribes to the Service ("Customer", "you"). It applies whenever we handle personal information on your behalf.
Contents
- The short version
- Words we use
- Who does what
- What we process, precisely
- Your instructions, and our CCPA commitments
- No AI training on your data
- Subprocessors
- Security
- If there is a breach
- Caller and consumer requests
- Verification (what we can realistically offer)
- Where your data is processed
- Keeping, exporting and deleting data
- Term, liability and precedence
- Accepting this DPA, and changes to it
- Contact
The short version
- Your callers' data is yours. We handle it only to run the receptionist service you signed up for.
- We do not sell it or share it for advertising, and we do not use it for our own purposes.
- We do not use your call content to train AI models — see section 5.
- For AI-answered calls we keep the transcript, not the audio. Audio is streamed live to be turned into text and is not stored by us. The one exception is voicemail: if a caller leaves a message, that recording is stored by our telephony provider, Twilio.
- We have no SOC 2 audit and no ISO certification, and we do not pretend otherwise (section 7).
- Telling callers that the line is answered by an AI and transcribed is your job, not ours (section 2.3).
- This summary is for readability. The numbered sections are what actually bind us.
1. Words we use
- Customer Data — personal information we process on your behalf: call metadata, transcripts, AI-derived call data, appointment details, voicemail recordings and their transcriptions, and your account and staff data.
- Business / Controller — the party that decides why and how the data is processed. That is you.
- Service Provider / Processor — the party that processes it on the other party's instructions. That is us.
- Subprocessor — a vendor we use to deliver the Service that handles Customer Data in doing so.
- Applicable Privacy Law — US federal and state privacy laws that apply, including the California Consumer Privacy Act as amended by the CPRA ("CCPA").
2. Who does what
2.1 You are the business/controller. You decide what the receptionist says, what it asks for, which calendar it writes to, who gets notified, and what you keep in your dashboard.
2.2 Roddy HQ is the service provider/processor. We process Customer Data only to provide the Service to you.
2.3 Recording and disclosure notices are your responsibility. Some US states require all-party consent to record or transcribe a call. Deciding whether your receptionist announces that the call is answered by an AI and transcribed, and getting any consent your state requires, is your call and your obligation. We give you the prompt controls to do it.
2.4 Prohibited data. The Agreement prohibits using the Service for protected health information subject to HIPAA. We are not a HIPAA business associate and will not sign a business associate agreement. You also must not configure the receptionist to ask for payment card numbers, Social Security numbers, government ID numbers, or account credentials. Callers speak freely and may volunteer sensitive things on their own — that is inherent to a phone line. Your obligation is not to design your prompts or workflows to collect these categories.
3. What we process, precisely
3.1 Why. To operate an AI phone receptionist and website chat widget for you: answering inbound calls your staff does not pick up, holding a conversation, answering questions about your business, booking, rescheduling and canceling appointments on your connected calendar, taking messages, transferring or escalating to a human, recording voicemail where you enable it, and producing call logs, summaries, notifications and reports in your dashboard and by email. Those are the limited and specified business purposes for which you disclose personal information to us.
3.2 Whose data. People who call your business number; people who use your website chat widget; your staff (operators who get ring-throughs, transfers, notification emails, and dashboard users); and anyone a caller happens to mention.
3.3 What data.
| Category | What it includes |
|---|---|
| Call metadata | Caller phone number, the business number dialed, start and end time, duration, call status and outcome. |
| Conversation transcript | Real-time transcription of what the caller and the receptionist said. |
| Call audio (AI-handled calls) | Not recorded or retained by Roddy HQ. Audio is streamed through our telephony and voice subprocessors to be turned into text in real time. We store the text, not the audio. |
| Voicemail audio — the exception | When a call goes to the voicemail fallback, the message is recorded using Twilio's recording feature. That audio file is stored by Twilio; a transcription is returned to us and shown to you. |
| AI-derived call data | Call summary, sentiment label, detected intent, action items, escalation flags. |
| Appointment details | What the caller gives for a booking — name, phone, email, service address, reason for the visit — written to your connected calendar and, where you enable it, used for confirmation and reminder emails. |
| Free text a caller volunteers | Anything else a caller chooses to say. In a clinic, vet or similar setting this can include health-related detail. Use of the Service for HIPAA-regulated PHI is prohibited under section 2.4. |
| Account and staff data | Dashboard user emails and authentication data, operator phone numbers, notification recipients, and billing or payout identifiers handled by Stripe. |
4. Your instructions, and our CCPA commitments
4.1 Your documented instructions are: the Agreement and this DPA; your dashboard configuration (business info, hours, service area, receptionist name and prompt, ring and escalation rules, calendar connection, notification recipients, voicemail behavior); your ordinary use of the Service's features; and any further written instruction you send to admin@dakarprojects.com that we accept. We process Customer Data only on those instructions, unless a law we are subject to requires otherwise — in which case we will tell you first unless the law forbids it. If we think an instruction breaks Applicable Privacy Law, we will tell you and may pause the affected processing.
4.2 Roddy HQ will not:
- sell or share Customer Data, as "sell" and "share" are defined in the CCPA — we receive no consideration for it and it is not disclosed for cross-context behavioral advertising;
- retain, use, or disclose Customer Data for any purpose other than the business purposes in section 3.1, including outside the direct business relationship between you and us;
- combine Customer Data with personal information we receive from anyone else or collect from our own interactions with consumers, except as the CCPA permits to perform the Service or to detect security incidents or fraud.
4.3 We further commit that we will:
- comply with the obligations that apply to us as a service provider under the CCPA, and provide Customer Data the same level of privacy protection the CCPA requires of you;
- tell you promptly if we determine we can no longer meet those obligations;
- engage subcontractors only under a written contract imposing these same obligations (section 6), and remain responsible for them;
- assist you in responding to consumer requests (section 9) and with security and breach obligations (sections 7 and 8).
4.4 We certify that we understand these restrictions and will comply with them. You have the right to take reasonable and appropriate steps under section 10 to confirm we use Customer Data consistently with your CCPA obligations, and, on notice to us, to take reasonable and appropriate steps to stop and remediate any unauthorized use.
4.5 We keep Customer Data confidential. Access is limited to personnel who need it to run or support the Service, under confidentiality obligations that survive the end of their engagement. If we receive a government or law enforcement demand for Customer Data, we will tell you unless legally prohibited, and will not hand it over unless legally compelled.
5. No AI training on your data
5.1 Roddy HQ does not use Customer call content — audio streams, transcripts, voicemail recordings or transcriptions, AI-derived summaries, or appointment details — to train, fine-tune, or otherwise improve any AI or machine learning model, ours or anyone else's.
5.2 We use our AI subprocessors under their commercial API terms, which provide that data submitted through the API is not used to train their models by default. We do not opt in to any data-sharing or model-improvement program, and we do not consent to human review of your call content beyond what those providers do for abuse and safety monitoring under their own terms.
5.3 We may use aggregated, de-identified operational metrics — call volume, average duration, error rates, latency, cost per call — to monitor, debug and improve the Service. This does not identify you, your callers, or the content of any conversation, and we will not try to re-identify it.
6. Subprocessors
6.1 You authorize the subprocessors below. Each is engaged under a written contract with data protection obligations at least as protective as this DPA, and we remain responsible to you for their performance.
| Subprocessor | What it does |
|---|---|
| Twilio | Telephony — inbound and outbound calls, SIP routing, voicemail recording and transcription. |
| LiveKit | Real-time call media transport between the caller and the voice agent. |
| OpenAI | The realtime speech model that conducts the conversation, and the post-call model that produces summaries, sentiment and action items. |
| Google Calendar API and OAuth for tenants who connect a Google calendar; Google's AI model behind the website chat widget where you use it. | |
| Microsoft | Outlook / Microsoft Graph Calendar for tenants who connect an Outlook calendar. |
| Supabase | PostgreSQL database and authentication. |
| Stripe | Payments and payouts. |
| Resend | Transactional email — confirmations, reminders, escalation and message notifications. |
| Vercel | Hosting for the web app, dashboard and serverless API functions. |
| DigitalOcean | Hosting for the backend server and voice agent. |
6.2 Changes. We will email your account admin at least thirty (30) days before a new or replacement subprocessor starts handling Customer Data. If a vendor fails or has to be replaced urgently for security or service continuity, we may act first and notify you as soon as practicable.
6.3 Objection. Within thirty (30) days of that notice you may object on reasonable data protection grounds by emailing admin@dakarprojects.com. We will try in good faith to find an alternative; if we cannot, you may terminate the affected part of the Service without penalty and get a pro-rated refund of prepaid fees for the unused remainder of the term.
7. Security
7.1 We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) between carriers, our infrastructure, our subprocessors and your browser.
- Managed, access-controlled infrastructure — the Service runs on Supabase, Vercel and DigitalOcean.
- Row-level security on all database tables, enforced at the database layer.
- Per-tenant scoping by phone number — settings, call logs, transcripts and calendar tokens are isolated to the tenant that owns the number.
- JWT authentication for dashboard access and token authentication between the voice agent and the backend.
- Administrative access limited to Roddy HQ operator personnel, gated on a designated admin identity.
- Enforced webhook signature validation on inbound telephony webhooks, so forged requests are rejected.
- Rate limiting and abuse controls on public API endpoints and on inbound call handling.
- Automated dependency and secret scanning in our build pipeline, with regular patching of the backend server.
7.2 No certifications. Roddy HQ has not completed a SOC 2 audit and holds no ISO certification. We do not claim either, and you should not represent to anyone that we hold them. Some of our subprocessors hold their own certifications; those are theirs, not ours.
7.3 We may change these measures over time as long as the overall level of security is not reduced.
8. If there is a breach
8.1 If we become aware of a breach of security leading to unauthorized access to or disclosure of Customer Data, we will notify you without undue delay after we confirm it, and in any event within seventy-two (72) hours of that confirmation, by email to your account admin.
8.2 The notice will cover, as far as we know at the time: what happened and when we learned of it; the categories of data and the approximate number of records and people affected; the likely consequences; what we have done to contain and fix it and what we suggest you do; and a contact for follow-up.
8.3 We will send an initial notice with what we have rather than delay it to be complete, and follow up as the investigation develops. An initial notice is not an admission of liability or fault.
8.4 Notifying regulators and affected individuals is your decision as the business, and your responsibility. We will give you the information you reasonably need to make it. We will not publicly identify you in connection with a breach without your prior written agreement, unless legally required.
9. Caller and consumer requests
9.1 If a caller or other individual contacts us directly to access, correct, delete, or limit use of their data, we will not answer substantively. We will point them to you and, where we can identify your account, forward the request to you without undue delay.
9.2 We will help you respond. You can view, export and delete call logs, transcripts and appointment records yourself in the dashboard. For anything the dashboard does not reach — including voicemail recordings held by Twilio — email admin@dakarprojects.com and we will locate or delete them.
9.3 That assistance is free. If a request needs substantial engineering work beyond ordinary support, we will tell you before starting and agree on cost with you first.
10. Verification (what we can realistically offer)
10.1 We are a small company serving small businesses, so verification is proportionate. On reasonable written request, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, we will: describe our technical and organizational measures in writing; complete a reasonable security or privacy questionnaire; answer reasonable written follow-up questions about how the Service handles Customer Data; and pass along relevant compliance documentation our subprocessors publish.
10.2 On-site inspections and penetration testing of our infrastructure are not available. Most of that infrastructure belongs to our hosting subprocessors and we cannot grant access to it. The documentation route in 10.1 is how you verify our compliance, and it satisfies your CCPA right to take reasonable and appropriate steps to confirm our use of Customer Data.
10.3 What we give you under this section is confidential and may be used only to assess our compliance with this DPA.
11. Where your data is processed
11.1 The Service is offered to US-based customers only, and Customer Data is processed in the United States.
11.2 We do not sell to customers established in the EEA, the UK or Switzerland, so this DPA deliberately contains no GDPR transfer machinery — no Standard Contractual Clauses, no EU/UK representative, no Article 27 appointment. If and when we serve customers in those regions, we will put an appropriate transfer mechanism and GDPR terms in place first and notify you under section 6.2.
11.3 Some subprocessors run global infrastructure and may provide support or routing from outside the US. Where that happens they do so under their own contractual data protection commitments, and we remain responsible to you under section 6.1.
12. Keeping, exporting and deleting data
12.1 During the term you can export and delete your call logs and records in the dashboard at any time.
12.2 When the Agreement ends, we delete Customer Data within ninety (90) days, except where law requires us to keep it. If you want a copy or faster deletion, email admin@dakarprojects.com within thirty (30) days of termination and we will provide a machine-readable export or delete on request.
12.3 We will instruct subprocessors to delete Customer Data they hold on the same basis, subject to their own retention and backup cycles.
12.4 Backups and system logs are overwritten on a rolling schedule. Data sitting in a backup stays covered by this DPA until it is overwritten.
12.5 Aggregated, de-identified metrics under section 5.3 may be kept.
13. Term, liability and precedence
13.1 This DPA applies for as long as we process Customer Data, and survives the Agreement until deletion is complete. Sections 4, 5, 6, 8 and 12 keep applying to any Customer Data we still hold.
13.2 Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA does not create a separate or additional cap. Nothing here limits liability that cannot be limited by law.
13.3 This DPA supplements the Agreement and forms part of it. On matters of data protection this DPA controls; otherwise the Agreement controls. Everything else in the Agreement stays in force.
14. Accepting this DPA, and changes to it
14.1 You accept this DPA by accepting the Agreement and using the Service. No signature or countersigned copy is needed. It takes effect when your subscription begins.
14.2 If your procurement process needs a signed copy, email admin@dakarprojects.com and we will execute one with these same terms.
14.3 If we make a material change, we will email account administrators before it takes effect. If a change materially reduces your protections and you do not agree, you may terminate the affected part of the Service without penalty and receive a pro-rated refund of prepaid fees for the unused remainder of the term.
15. Contact
Privacy questions, instructions, subprocessor objections, deletion requests, security questionnaires and breach follow-up:
- Dakar Projects LLC (d/b/a Roddy HQ), a Texas limited liability company
- Email: admin@dakarprojects.com
- Phone: (844) 318-9207