Vestibo
All legal documents

Legal

Data processing addendum

Data Processing Addendum (DPA)

Version: v1.0 β€” 2026-07-23 Effective date: the date of acceptance of the Vestibo Terms of Service, or such later date as the parties counter-sign this DPA.

This Data Processing Addendum ("DPA") forms part of the agreement between Vestibo ("Processor") and the customer entity identified in the relevant order form or account record ("Customer", "Controller") for the use of the Vestibo platform (the "Service") under the Vestibo Terms of Service (together with any order form, the "Principal Agreement"). This DPA reflects the parties' agreement on the processing of Personal Data by Vestibo on the Customer's behalf in accordance with the requirements of Data Protection Laws.

1. Definitions

The capitalised terms below have the meanings set out here. Other capitalised terms have the meanings given in the Terms of Service.

  • "Affiliate" β€” an entity that controls, is controlled by, or is under common control with a party.
  • "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" β€” have the meanings given in the GDPR.
  • "Data Protection Laws" β€” the EU GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA, and any other applicable data-protection or privacy law.
  • "EU SCCs" β€” the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914, with the relevant module(s) selected in Schedule 3.
  • "UK Addendum" β€” the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s. 119A of the Data Protection Act 2018.
  • "Restricted Transfer" β€” a transfer of Personal Data from the EEA, the UK, or Switzerland to a country that has not been deemed to provide an adequate level of protection.

2. Scope and roles

For the purposes of this DPA, the Customer is the Controller and Vestibo is the Processor of Personal Data submitted to the Service. Schedule 1 (Processing Details) describes the subject matter, duration, nature, purpose, categories of Data Subject, and categories of Personal Data.

This DPA does not apply to (a) account data Vestibo processes as a controller for its own account-management, billing, and security purposes (see the Privacy Policy); or (b) anonymous, aggregated statistics derived from the Service.

3. Customer instructions

3.1 Vestibo processes Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required by EU/UK/Member State law (in which case Vestibo will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest).

3.2 The Principal Agreement, this DPA, the Customer's configuration of the Service (including the channels enabled, the guardrails set, the integrations connected, and the retention settings chosen), and the Customer's documented use of the Service in accordance with the documentation constitute the Customer's complete and final instructions to Vestibo.

3.3 Additional instructions outside the scope of the documentation require prior written agreement.

3.4 Vestibo will notify the Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

Vestibo ensures that its personnel authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security

5.1 Vestibo implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the measures set out in Schedule 2 (Technical and Organisational Measures) and described in the public Security Overview.

5.2 Vestibo regularly tests and reviews these measures and updates them as needed to address evolving threats. Material changes that materially reduce protections require the Customer's prior written consent.

5.3 Vestibo restricts access to Personal Data to personnel who need access to perform the Service. Access is logged.

6. Sub-processors

6.1 Authorisation. The Customer authorises Vestibo to engage the Sub-processors listed at SUBPROCESSORS.md (the "Sub-processors List"), which the Customer acknowledges it has reviewed and accepted on signing.

6.2 New Sub-processors. Vestibo gives the Customer at least thirty (30) days' written notice (by email and in-product banner) before adding or replacing a Sub-processor. The Customer may object on reasonable data-protection grounds within fifteen (15) days of the notice. If the parties cannot resolve the objection, the Customer may terminate the affected portion of the Service for convenience on thirty (30) days' notice, with a pro-rated refund of pre-paid fees.

6.3 Sub-processor contracts. Vestibo enters into a written contract with each Sub-processor that imposes obligations substantially the same as those imposed on Vestibo in this DPA, including the obligations under Art. 28(3) GDPR.

6.4 Liability. Vestibo remains fully liable to the Customer for the performance of each Sub-processor's obligations under its sub-processor contract.

7. Cooperation with Data Subjects, authorities, and assessments

7.1 Data Subject requests. Vestibo provides reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under the Data Protection Laws, taking into account the nature of the processing. The Service exposes self-service export and deletion tools in the dashboard. Where a Data Subject contacts Vestibo directly, Vestibo forwards the request to the Customer without undue delay.

7.2 Authority cooperation. Vestibo provides reasonable cooperation, at the Customer's expense, with data-protection authorities in connection with Vestibo's processing.

7.3 DPIA / prior consultation. Vestibo provides reasonable information and assistance to the Customer for the Customer's data protection impact assessments and prior consultations with authorities.

7.4 Audits. Once per twelve (12) months, on at least thirty (30) days' prior written notice, the Customer may audit Vestibo's compliance with this DPA by reviewing Vestibo's then-current security reports and controls documentation β€” including its SOC 2 Type II report once attested and, for the HIPAA tier, its HIPAA controls documentation (subject to confidentiality). Where the Customer can demonstrate that this is insufficient, the Customer (or an independent third-party auditor mutually agreed by the parties and bound by confidentiality obligations no less protective than this DPA) may conduct an on-site audit during normal business hours, at the Customer's expense and without disrupting Vestibo's operations or compromising other customers' data.

8. Personal Data Breach

8.1 Vestibo notifies the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.

8.2 The notification will contain, to the extent then known: a description of the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and the contact point for further information.

8.3 Vestibo provides reasonable assistance to the Customer in meeting the Customer's notification obligations to supervisory authorities and Data Subjects under Arts. 33–34 GDPR.

9. Return and deletion

On termination or expiry of the Principal Agreement, and at the Customer's choice, Vestibo deletes or returns all Personal Data within thirty (30) days, except to the extent applicable law requires retention. Personal Data in rolling backups is deleted within ninety (90) days. Vestibo provides written certification of deletion on request.

10. International transfers

10.1 Where a Restricted Transfer occurs, the parties agree to the EU SCCs as set out in Schedule 3. For transfers from the UK, the UK Addendum applies. For transfers from Switzerland, the FDPIC addendum to the SCCs applies.

10.2 Vestibo has completed a Transfer Impact Assessment under the Schrems II framework for each onward transfer to a US-based Sub-processor. A summary is available to the Customer on request.

10.3 Where a Sub-processor is certified under the EU-US Data Privacy Framework, the UK extension, or the Swiss-US DPF, the parties may also rely on that certification.

11. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Principal Agreement. Nothing in this DPA limits either party's liability to a Data Subject under Art. 82 GDPR.

12. Order of precedence

In the event of conflict between this DPA and the Principal Agreement, this DPA prevails. In the event of conflict between this DPA and the EU SCCs, the EU SCCs prevail.

13. Term

This DPA continues for the duration of the Principal Agreement, plus any period during which Vestibo continues to hold Personal Data.


Schedule 1 β€” Processing details

ItemDetail
Subject matterProvision of the Vestibo platform: configurable AI agents that take voice calls, exchange SMS/WhatsApp messages, answer web chat, exchange email, ingest knowledge bases, and β€” where enabled β€” perform experimental Browser Agent tasks, together with the related dashboard and APIs.
DurationThe term of the Principal Agreement, plus the post-termination retention period in Β§ 9.
Nature & purposeHosting, transcription, generation of agent responses, audit logging, billing, abuse prevention, support, and product analytics derived from de-identified usage.
Categories of Data Subject(a) Customer's administrators and users of the dashboard; (b) end-users that interact with an agent built on Vestibo (the Customer's callers, texters, emailers); (c) third parties referenced in conversation content.
Categories of Personal DataContact identifiers (name, email, phone), account identifiers (user IDs), conversation content (transcripts, voicemail recordings where a caller leaves one, message bodies), schedule data (appointment times, slots), business data the Customer chooses to embed in agent knowledge, OAuth tokens for connected integrations.
Special categories (Art. 9 GDPR)None by default. PHI is processed only under the HIPAA tier with an executed BAA.
FrequencyContinuous for the duration of the Principal Agreement.
RetentionAs set out in the Principal Agreement and Β§ 9 above.

Schedule 2 β€” Technical and Organisational Measures (Art. 32 GDPR)

The full description is in the Security Overview. Summary:

  • Access control. Role-based access, hardware-token MFA for all privileged accounts, just-in-time access for production, quarterly access reviews.
  • Encryption. TLS 1.2+ in transit; AES-256 at the AWS storage layer (RDS, KMS-managed); an application-layer Fernet envelope (AES-128-CBC + HMAC-SHA-256) for Customer-supplied secrets and OAuth tokens.
  • Tenant isolation. Logical tenant isolation enforced at the ORM, repository, and route layers.
  • Audit logging. Security- and compliance-relevant actions emit a structured audit event with actor, target, before/after values, and timestamp on an append-only, keyed-HMAC (HMAC-SHA-256) hash-chained ledger; coverage is being extended toward every state-changing action.
  • Backups. Encrypted, point-in-time recovery for the primary database; restore drill at least every six (6) months.
  • Vulnerability management. Trivy, Bandit, Gitleaks, npm audit, pip-audit, Schemathesis on every CI run; high-severity findings fixed within fourteen (14) days.
  • Personnel. Background checks where permitted by law; confidentiality agreements; annual security and privacy training.
  • Incident response. 24Γ—7 on-call rotation, documented runbooks, forty-eight (48) hour breach notification SLO.
  • Sandbox (planned). The experimental Browser Agent (off by default, not yet available in production) is designed to run in a sandboxed environment with an allowlist of hosts the Customer has explicitly approved.
  • PHI handling. Where the HIPAA tier is enabled, additional controls apply per the BAA and the PHI redaction pipeline.

Schedule 3 β€” EU Standard Contractual Clauses

For transfers of Personal Data from the EEA to a country that does not have an adequacy decision, the parties incorporate by reference Module 2 (Controller to Processor) of the EU SCCs (Commission Implementing Decision (EU) 2021/914 of 4 June 2021).

SCC referenceSelection
Clause 7 (Docking clause)Not used.
Clause 9 (Sub-processors)Option 2 (general written authorisation). The list and notice period are set out in Β§ 6 of this DPA.
Clause 11 (Redress)Optional Para. (a) not used.
Clause 17 (Governing law)Law of the Republic of Ireland.
Clause 18 (Choice of forum)Courts of Ireland.
Annex I.A (List of parties)Data Exporter = Customer (per the order form); Data Importer = Vestibo.
Annex I.B (Description of transfer)As set out in Schedule 1 of this DPA.
Annex I.C (Competent supervisory authority)The supervisory authority in the EU Member State of the Customer's lead establishment, or, where the Customer has no EU establishment, the Irish Data Protection Commission.
Annex II (Technical and Organisational Measures)As set out in Schedule 2 of this DPA.
Annex III (List of Sub-processors)The current Sub-processors List at SUBPROCESSORS.md.

For transfers from the UK, the UK Addendum applies, with:

  • Table 1: parties as in Annex I.A above;
  • Table 2: SCCs Version: the version above, including Modules and selected options;
  • Table 3: appendix information as in Annexes I–III above;
  • Table 4: neither party may end the Addendum on a change to the approved Addendum.

For transfers from Switzerland, the SCCs apply with the adjustments published by the FDPIC, with references to "Member State" read as including Switzerland.


Signature block

PartySignatureNameTitleDate
Customer (Controller)
Vestibo (Processor)

Changelog

  • v1.0 (2026-07-23) β€” first published version; rebranded to Vestibo and reconciled to the current product.
  • v0.1 (2026-05-16) β€” initial internal draft.

Questions? Email legal@vestibo.com.