Legal
Data processing addendum
The controller-processor terms for customers whose own privacy obligations require them, including the CCPA service-provider terms.
Last updated August 30, 2026.
Draft: not yet in force. Ringfully does not yet have an incorporated legal entity, so the party, address and governing law below read [TBD]. This document is published for review and does not bind anyone until those are filled in and it has been through a lawyer.
This applies automatically as part of the terms; nothing needs signing. Clauses 5, 6 and 9 name the places where Ringfully is currently weaker than a mature vendor (no certification, no case file behind a data-subject request, no independent report) because finding that out during procurement is better than finding it out during an audit.
1Roles
You are the controller of the personal information you put into Ringfully and of the information the service generates about your calls. [TBD] is your processor, and acts on your documented instructions.
Under the California Consumer Privacy Act, we are a service provider. We do not sell or share personal information, do not retain it for any purpose other than providing the service, and do not combine it with information from anyone else.
This addendum forms part of the terms of service and applies automatically. You do not need to sign anything separately, though we will countersign a copy if your process requires one.
2Subject matter, duration and categories
- Subject matter and duration
- Provision of a cloud telephone service, for as long as your subscription lasts, plus the thirty-day window after it ends.
- Nature and purpose
- Connecting, routing, recording and metering telephone calls and text messages, and keeping a record of them for you.
- Categories of data subject
- Your employees and contractors who use the service, and the members of the public who call you or whom you call.
- Categories of personal information
- Names, work email addresses, telephone numbers, call metadata, call recordings, voicemail audio and transcripts, text-message content, contact records, agent availability history, and session records including IP addresses. Set out in full in the privacy policy.
- Special categories
- None intended. A caller may nevertheless say something sensitive on a recorded call, which is a reason to think carefully about recording rather than a category we process on purpose.
3Our obligations
We will:
- process personal information only on your instructions, and tell you if we believe an instruction breaks the law;
- keep everyone with access under a duty of confidence;
- apply the security measures in clause 5;
- use sub-processors only under clause 4;
- help you respond to a data-subject request, under clause 6;
- tell you about a personal-data breach without undue delay, under clause 7; and
- delete or return the data at the end, under clause 8.
4Sub-processors and international transfer
You give general authorisation for the sub-processors listed on the sub-processors page. We will update that page and tell you before a new one starts handling your data, and you may object.
Everything is processed in the United States: our servers and database in AWS US East (Northern Virginia), and call audio at Twilio with no region pinned. There is no Canadian and no European hosting option.
If you are a Quebec business, Law 25 requires you to assess this transfer before making it. This addendum, the sub-processors page and the security page are the material for that assessment, and we will answer specific questions in writing.
5Security measures
Passwords hashed with bcrypt; encryption in transit; per-organization data isolation enforced on an identifier read from the verified session token, with a test suite that attempts cross-organization access and asserts it fails; short-lived access tokens with rotating refresh tokens and replay detection; account lockout; rate limiting at the application and at the edge; a default-deny egress firewall on outbound requests made by call flows; secrets in a managed secret store. The security page describes each.
Administrative actions are written to an append-only log. It records account, role and permission changes; sign-ins, failed sign-ins, lockouts and password resets; changes to telephone numbers, call flows, the recording policy and the retention policy; exports and erasures carried out for a data subject; and every time someone plays or downloads a recording, voicemail or transcript. Nothing in the product edits or removes an entry. A user holding the audit permission can read the log in the admin portal and export the same filtered view as a CSV file.
Stated equally plainly, because an addendum that omitted them would be misleading:
- We hold no SOC 2 report, no ISO 27001 certificate and no HIPAA or PCI attestation. Agents can turn on two-factor sign-in; organizations cannot yet require it for every agent. Multi-factor is mandatory on our own operator console only.
- That log is best-effort. A write that fails is dropped rather than reversing the action it describes, so it evidences the accesses it recorded and proves nothing about any it missed. It is not tamper-evident, and it is not fit to be the sole evidence for an attestation that requires provable completeness. One export returns at most 10,000 entries, newest first; a longer history is exported a date range at a time.
6Data-subject requests
If a data subject comes to us directly we will not respond substantively; we will pass the request to you, tell you we have, and help you answer it.
Most of it you can answer yourself. The admin portal has a privacy-requests screen: identify the person by phone number, by their contact record or by their user account, confirm it is the right person before anything is read, export everything held about them as one JSON file or a section at a time as CSV, and erase them. Erasure runs as a rehearsal by default and reports what it would remove; a real run requires the identifier to be typed back before it will proceed.
Erasure is not total, and the report names what was kept. Usage and billing records stay, because tax law requires the books an invoice was computed from to be kept for six years. The log entry recording the erasure stays, because it is the evidence the request was honoured, which also means an erased employee’s name and email survive in the entries describing what they did. Call records stay with the person’s identifiers replaced rather than the row deleted. Recording and voicemail audio is deleted at our telephony processor before the row pointing at it; if the processor will not confirm, nothing is marked deleted, the run reports itself partial, and the request is not finished.
What is still manual is the request itself. Nothing records that a request arrived, who made it, or how their identity was checked, and nothing tracks the thirty-day clock. Our commitment is the same thirty days. If your obligations require you to respond faster than that as a matter of course, tell us before you buy.
7Breach notification
We will tell you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing. We will keep you updated as we learn more rather than waiting for a complete picture. We keep a record of incidents whether or not they meet a notification threshold.
8Deletion and return
During the term, data is deleted on a schedule. Your organization has a retention window for each kind of record it holds: call recordings, voicemail, call records, text messages, the administrative log, notification records and agent availability history among them. Where you have set nothing, the platform defaults apply: thirty days for recordings, ninety days for voicemail, one year for text messages, notification records and availability history, and seven years for call records and the administrative log. A user holding the policy permission can change any of them in the admin portal, and a nightly job deletes what has passed the window in force.
Shortening a window deletes on the next run and cannot be undone: there is no archive and no separate copy of call audio to restore from. One exception to the schedule is stated rather than hidden, because it lets a record outlive its window: a call record that had a recording is left in place, since the row evidencing that the audio was deleted still points at it.
On termination we will, at your request made within thirty days, provide a copy of your data in a commonly-used format and then delete it, including from backups on their ordinary cycle. After that window we may delete it without further notice. We will confirm deletion in writing if you ask.
9Audit
We will make available the information needed to show we are meeting this addendum, and answer a security questionnaire. We do not currently offer on-site audit, and there is no third-party report to substitute for one. Where that is not enough for your process, say so early. The answer may be that Ringfully does not yet meet your bar, and that is better established before a contract than after.
10Contact
[email protected], addressed to [TBD]. For a countersigned copy, send yours and we will return it.