Skip to content
Linevio
How it worksPricingLive demoFAQContact
Get startedLog in
Menu
How it worksPricingLive demoFAQContactLog in
Legal center

Data Processing Addendum

Instructions, confidentiality, subprocessors, security incidents, rights requests, and deletion of customer data.

Download documentsVersion link

Effective September 18, 2026. Keep a copy with your order.

Updated September 18, 2026
Version 2026-09-18

In this document

  • Scope and roles
  • Processing instructions and description
  • Use restrictions
  • Confidentiality and safeguards
  • Subprocessors and customer destinations
  • Security incidents
  • Rights requests, assessments, and audit
  • Return, retention, and deletion
  • Location, international transfers, and liability

1. Scope and roles

This Addendum forms part of the business service agreement when Linevio processes personal information on Customer’s behalf. Customer is the business or controller and Linevio is its service provider or processor, to the extent those roles apply under relevant law. Personal information means information about an identified or reasonably identifiable person under applicable data-protection law. Our separate handling of account administration, billing, and our own legal records is described in the Privacy Notice.

Customer must have authority and a lawful basis for its instructions, provide necessary notices, and respect individuals’ rights. We remain responsible for obligations applicable to our processing role. Neither party may use this Addendum to waive a person’s rights or transfer responsibility for its own unlawful conduct.

2. Processing instructions and description

The subject is the provision of the approved managed inbound phone service. Processing includes collection, transmission, real-time audio processing, transcription, summarization, storage, retrieval, approved appointment actions, delivery of call outcomes, support, protection, export, and deletion. It continues for the subscription and any lawful, limited return, deletion, or retention period afterward.

Data subjects may include callers, customer personnel, authorized account users, and people named in approved business documents or appointments. Data may include names, business contact details, caller and routing numbers, call audio in transit, transcripts, summaries, appointment details, configuration materials, and technical call metadata. Stored recordings require separate approval. Prohibited sensitive information and child-directed or regulated intake are outside the authorized scope.

Documented instructions consist of the accepted agreement, approved setup and changes, and lawful authenticated support instructions consistent with the service. We will process customer personal information only on those instructions or as legally required. If law requires otherwise, we will notify Customer before processing unless prohibited. We will inform Customer if an instruction appears to violate applicable data-protection law and may pause that instruction pending resolution.

3. Use restrictions

We will not sell customer personal information, share it for cross-context behavioral advertising, use it for unrelated advertising, or use it to train general-purpose AI models. We will not retain, use, or disclose it outside the direct business relationship or for purposes other than the specified service purposes, except as applicable law permits. We will not combine it with personal information from other customers or our own interactions except as expressly permitted by applicable service-provider law for the specified business purposes.

Where California service-provider or contractor rules apply, these restrictions have the meanings required by that law. We certify that we understand and will comply with the applicable restrictions, provide the legally required level of privacy protection, and notify Customer if we determine we can no longer meet those obligations. Customer may take reasonable and appropriate steps to verify compliance and stop and remediate unauthorized use, consistent with the audit process below.

4. Confidentiality and safeguards

We will limit access to people who need it for the service and are bound to confidentiality. Safeguards will be appropriate to the nature, scope, context, and risks of processing and will include access authorization, customer data separation, secure transmission, protection of stored credentials and sensitive content, change controls, relevant audit records, incident handling, and reasonable retention controls. We will not materially reduce the overall protection during the service term.

Customer must protect its own accounts, carrier settings, authorized recipients, and connected-system access. Customer must not submit prohibited data or demand unapproved security or residency guarantees. This Addendum does not represent a completed SOC 2 audit, HIPAA business associate agreement, or zero-risk system.

5. Subprocessors and customer destinations

Customer authorizes the service providers identified in the Provider & Subprocessor Register to perform the listed processing to the extent used for Customer’s service. We will bind subprocessors to written obligations appropriate to their work that protect customer personal information consistently with this Addendum and remain responsible for their performance of the processing obligations we delegate.

Before adding or replacing a subprocessor that will access customer personal information, we will give at least 15 days’ advance notice through the account contact and register. Customer may object within that period on reasonable, documented data-protection grounds. We will work toward a reasonable alternative; if none is available, either party may terminate the affected service and we will refund prepaid fees for its unused period. An urgent change needed for security or continuity may use shorter notice with an explanation and the same objection and termination remedy.

A customer-selected calendar, CRM destination, carrier, or other service may be controlled by Customer under its own agreement rather than be our subprocessor. We will distinguish those roles in the register and limit the information sent to the approved action. Customer is responsible for its instructions and recipient permissions; we remain responsible for transmitting within those instructions.

6. Security incidents

A security incident means confirmed unauthorized access to, acquisition, alteration, loss, destruction, or disclosure of customer personal information in our custody or control. Unsuccessful attempts that do not compromise such information are not by themselves a reportable incident under this Addendum.

We will notify Customer without undue delay after becoming aware of a security incident affecting its personal information and within any shorter period required by applicable law. We will provide available details about the nature, affected data, likely consequences, response measures, and a contact for follow-up, supplementing information as the investigation proceeds. Notification is not an admission of liability. We will reasonably cooperate in containment, remediation, and legally required notifications. Neither party’s obligations are postponed until a complete forensic report is available.

7. Rights requests, assessments, and audit

Taking account of the processing and available information, we will reasonably assist Customer with access, correction, deletion, portability, objections, regulator inquiries, security duties, and legally required risk assessments. We will promptly forward requests concerning Customer-controlled data to Customer unless legally prohibited and will not respond on Customer’s behalf without instruction unless law requires it. Customer determines the lawful response to its requests.

We will make information reasonably necessary to demonstrate compliance available under confidentiality, normally through written responses and relevant existing records. If those materials are insufficient to verify a material concern, Customer or a qualified independent auditor may conduct a reasonably scoped assessment on reasonable notice, during business hours, without accessing other customers’ data or compromising security. Routine audits are limited to once annually; that limit does not restrict a regulator, a legal requirement, or a reasonable investigation of an incident or material noncompliance.

Each party bears ordinary compliance costs. Material assistance outside ordinary service may require an agreed reasonable fee disclosed in advance, except where law requires assistance without charge or our breach caused the need. We will not delay a legally required response merely because a fee is disputed.

8. Return, retention, and deletion

Before production activation, the parties must document the applicable retention and deletion schedule and confirm that the selected providers and operational processes support it. The schedule must distinguish transcripts, any audio, summaries and call metadata, uploaded sources, support records, and audit or billing records. Automatic deletion applies only where specified in the agreed schedule.

At the end of processing, at Customer’s choice we will return available customer personal information in a reasonably usable form or delete it, and delete remaining copies under the agreed schedule unless applicable law requires retention. Customer should request export before service access ends. Any legally retained information remains protected and may be used only for the permitted retention purpose. Backups are isolated from ordinary use and expire on their documented lifecycle; deletion instructions must be reapplied if a backup is restored.

Customer-controlled copies in an inbox, calendar, CRM, or carrier account are managed by Customer and that recipient. We will give reasonable assistance identifying what our deletion can and cannot reach.

9. Location, international transfers, and liability

The initial service is intended for U.S. business customers. U.S. customers can still receive calls involving people elsewhere; Customer must identify any applicable additional requirements before using an affected workflow. We do not represent that a U.S. business address alone removes international data-protection duties.

A requirement for GDPR or UK GDPR transfer clauses, a transfer assessment, a particular hosting region, or another jurisdiction-specific instrument must be reviewed and expressly agreed before that processing begins. This Addendum does not incorporate Standard Contractual Clauses; any required transfer instrument must be separately agreed. The Terms govern contractual liability except where mandatory law or an expressly agreed transfer instrument requires otherwise.

All documents

Terms of ServiceService AgreementBilling & Cancellation PolicyAI & Call Data DisclosurePrivacy NoticeAcceptable Use PolicyData Processing AddendumProvider & Subprocessor Register

Linevio LLC

Registered in Wyoming

3857 Birch Street 3133, Newport Beach, CA 92660, United States

Legal & privacy

legal@linevio.com

Questions about these documents or your information can be sent here.

Jurisdiction

State of Wyoming, subject to applicable federal law and mandatory protections.

State and federal courts located in Wyoming.

Linevio

Your phone, in good hands.

Let’s talk

Explore

How it worksPlans & pricingTry the demoBlog

Here to help

Contact usCommon questionsCustomer portal

The details

Terms of servicePrivacyAll policies
© 2026 LinevioEnglish & Spanish. Around the clock.