> For the complete documentation index, see [llms.txt](https://docs.salescaling.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.salescaling.com/en/compliance-and-legal/procesamiento-datos.md).

# Data Processing Agreement

### Data Processing Agreement

SALESCALING, in its capacity as Data Processor (hereinafter the “PROCESSOR”) shall process the personal data it receives from the CLIENT, as Data Controller (hereinafter the “CONTROLLER”), in connection with the performance of the Agreement for the provision of the Services, following the instructions and purposes determined by the CONTROLLER.

For the purposes of this Agreement, “CLIENT” refers to any natural or legal person or affiliated entity of the Client that has entered into a service agreement with SALESCALING and processes personal data for which it is responsible to ensure the provision of the services under the agreement between both parties.

Both parties, in the exercise of their respective powers, agree to enter into this Personal Data Processing Agreement (hereinafter, the “Agreement”), in compliance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, hereinafter “GDPR”) and Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (“LOPDGDD”), in accordance with the following,

### Provisions

#### 1. Purpose

1.1. The PROCESSOR, within the framework of this Agreement, shall process personal data on behalf of the CONTROLLER in accordance with the terms and conditions set out in this document.

1.2. The purpose of the processing is the provision of the Services specified in the service agreement covered by this Agreement.

1.3. The term of the assignment shall last as long as the contractual relationship between the parties remains in force and until the personal data are deleted in accordance with the provisions of this Agreement.

1.4. In relation to the Agreement, the CONTROLLER is the person who determines the purposes and means by which the CONTROLLER’s Data are processed by the processor (as defined below).

1.5. The personal data provided by the CONTROLLER to the PROCESSOR relate to the categories of data and data subjects indicated in Appendix I.

#### 2. Obligations of the Data Processor

The PROCESSOR and all its staff undertake the following obligations:

2.1. Use the personal data subject to processing, or those collected for inclusion, only for the purpose of this assignment. Under no circumstances may the data be used for its own purposes. 2.2. Process the data in accordance with the documented instructions of the CONTROLLER. 2.3. If the PROCESSOR considers that any of the instructions infringes the GDPR, LOPDGDD or any other provision on data protection of the European Union or the Member States, the PROCESSOR shall immediately inform the CONTROLLER. 2.4. Not disclose the data to third parties, unless it has the prior express written authorization of the CONTROLLER, in legally established and permissible cases. 2.5. The PROCESSOR may disclose the data to other processors of the same controller, in accordance with the CONTROLLER’s instructions. In this case, the CONTROLLER shall identify, in advance and in writing, the entity to which the data are to be disclosed, the data to be disclosed, and the security measures to be applied in order to make the disclosure. 2.6. The PROCESSOR shall carry out transfers of personal data to a third country or organization only under the documented instructions of the CONTROLLER. If the PROCESSOR must transfer such personal data to a third country or international organization, under the European Union or Member State law applicable to it, it shall inform the CONTROLLER of that legal requirement in advance, unless such law prohibits it on important grounds of public interest. 2.7. Likewise, the PROCESSOR undertakes to return to the CONTROLLER the medium or media containing the personal data, or to destroy them, at the request of the latter, once the provision of services has ended, without retaining any copy thereof, unless otherwise established by the CONTROLLER.

2.8. **Subprocessing.**

a. The PROCESSOR may subcontract with third parties the performance of personal data processing activities for the proper provision of the services covered by this Agreement, including certain necessary technical and IT services and necessary ancillary services.

b. Pursuant to the GDPR and LOPDGDD, any subcontracting of the service that is carried out for the performance of the contract and that the PROCESSOR wishes to carry out must be communicated to the CONTROLLER at the email address indicated in the Specific Terms, indicating the processing activities that it intends to subcontract and clearly and unambiguously identifying the subcontracting company and its contact details. The subcontracting may take place if the CONTROLLER does not object within 5 days from the communication.

c. The list of Sub-processors or authorized providers is set out in Appendix I.

d. The subcontractor, who will also have the status of data processor, is likewise obliged to comply with the obligations set out in this document for the PROCESSOR and with the instructions issued by the CONTROLLER.

e. It is the responsibility of the PROCESSOR to enter into a new contract with the new processor so that it is subject to the same conditions and the same formal requirements as it, with regard to the proper processing of personal data and the guarantee of the rights of the affected persons. In the event of non-compliance by the sub-processor, the PROCESSOR shall remain fully liable to the CONTROLLER with regard to compliance with the obligations.

2.9. The PROCESSOR may share the CONTROLLER’s personal data with those service providers or third-party companies, including artificial intelligence services, upon instruction of the CONTROLLER. In such case, since the PROCESSOR acts following the CONTROLLER’s instructions, it shall not need to give prior notice to the CONTROLLER, and it shall be the CONTROLLER who ensures that such provider complies with the guarantees regarding the protection of personal data and its compliance with the applicable regulations.

2.10. Maintain the duty of confidentiality regarding the personal data to which the PROCESSOR has had access by virtue of the services provided to the CONTROLLER, even after the relationship between them has ended.

2.11. Ensure that the persons authorized to process personal data expressly and in writing undertake to respect confidentiality and to comply with the corresponding security measures, of which they must be duly informed.

2.12. Keep available to the CONTROLLER the supporting documentation proving compliance with the obligation set out in the previous paragraph.

2.13. Ensure the necessary training in personal data protection of the persons authorized to process such data.

2.14. Assist the CONTROLLER, taking into account the nature of the processing, through appropriate technical and organizational measures, whenever possible, so that it can comply with its obligation to respond to requests aimed at exercising data subject rights.

2.15. When the affected persons exercise the rights of access, rectification, erasure and objection, restriction of processing, data portability, and the right not to be subject to automated individual decisions, before the PROCESSOR, the latter must communicate this by email to the address indicated by the CONTROLLER. The communication must be made as soon as possible, making its best efforts for it to occur within 3 working days from receipt of the request, and shall include, where appropriate, other information that may be relevant to resolve the request.

2.16. Right to information. It is the CONTROLLER’s responsibility to provide the right to information at the time the data are collected.

2.17. **Notification of data security breaches**

a. The PROCESSOR shall notify the CONTROLLER, without undue delay and in any case within a maximum period of 36 hours, and through a simple communication, of any security breaches of which it becomes aware concerning the data under its control, together with all relevant information and documentation regarding the incident.

b. Notification shall not be required where such breach is unlikely to constitute a risk to the rights and freedoms of natural persons.

c. The notification shall include at least the following information:

```
  i. A description of the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects affected, and the categories and approximate number of personal data records affected.

  ii. The name and contact details of the data protection officer or other contact point where more information may be obtained.

  iii. A description of the possible consequences of the personal data breach.

  iv. A description of the measures taken or proposed to remedy the personal data breach, including, where appropriate, measures taken to mitigate any possible adverse effects. If it is not possible to provide the information simultaneously, and to the extent that it is not possible, the information shall be provided progressively without undue delay.
```

2.18. Assist the CONTROLLER in carrying out data protection impact assessments, where appropriate.

2.19. Assist the CONTROLLER in carrying out prior consultations with the supervisory authority, where appropriate.

2.20. Make available to the CONTROLLER all the information necessary to demonstrate compliance with its obligations, as well as for the performance of audits or inspections carried out by the controller or another auditor authorized by it, when required.

2.21. **Security Measures.** The PROCESSOR undertakes to apply to personal data the security measures necessary to prevent alteration, loss, unauthorized processing or access, taking into account the state of the art, the nature of the data stored and the risks to which they are exposed, whether arising from human action or from the physical or natural environment. In this regard, in accordance with the provisions of Articles 24 and 32 of the GDPR, the PROCESSOR is obliged to have appropriate technical and organizational security measures implemented.

2.22. Specifically, the PROCESSOR shall adopt the security measures set out in Appendix I.

2.23. **Data destination.** The PROCESSOR undertakes to destroy the data once the service has been completed. However, the PROCESSOR may keep a copy, with the data duly blocked, while liabilities may arise from the performance of the service.

***

### 3. Obligations of the Data Controller

The CONTROLLER undertakes to:

3.1. Be responsible for the personal data subject to processing.

3.2. Carry out an assessment of the impact on the protection of personal data of the processing operations to be carried out by the processor, where appropriate.

3.3. Ensure the duty to inform data subjects in accordance with Articles 13 and 14 of the GDPR.

3.4. Carry out the relevant prior consultations.

3.5. Ensure, in advance and throughout the processing, compliance with the GDPR and LOPDGDD by the PROCESSOR.

3.6. Communicate changes to the basic structure of the data that imply or may imply a change in the application of security measures.

3.7. Grant the PROCESSOR access only to those data that are appropriate, relevant and not excessive, in view of the purpose of the contracted service.

3.8. The CONTROLLER shall ensure, for the data subject, depending on the nature, scope, context and purposes of the processing, on the basis of Article 24 of the GDPR, that it has adopted appropriate technical and organizational measures to maintain the security of the personal data provided.

3.9. It is the CONTROLLER’s responsibility to communicate data security breaches to the data subjects as soon as possible, when the breach is likely to pose a high risk to the rights and freedoms of natural persons.

The communication must be made in clear and simple language and shall, at a minimum:

a. Explain the nature of the data breach.

b. Indicate the name and contact details of the data protection officer or other contact point where more information may be obtained.

c. Describe the possible consequences of the personal data security breach.

d. Describe the measures taken or proposed by the controller to remedy the personal data security breach, including, where appropriate, measures taken to mitigate any possible adverse effects.

3.10. The CONTROLLER shall ensure that the service providers or third-party companies to which the PROCESSOR discloses personal data under the CONTROLLER’s instruction comply with the guarantees regarding data protection and the rest of the current regulations and shall be liable to the PROCESSOR.

***

### Appendix I to the Data Processing Agreement on processing details

#### 1. Purpose(s) of the processing:

To ensure the provision of the service(s) contracted by the CONTROLLER, in accordance with the Service Agreement. Such processing may include different technological services, such as the recording and transcription of calls and meetings, as well as the use of SDRs through AI Agents between the CONTROLLER and its employees or end customers.

#### 2. Types of personal data provided by the CONTROLLER to the PROCESSOR:

1. Identification data (e.g., first and last name, telephone number, email address, etc.)
2. Professional and company data (e.g., position, company, industry, professional contact details, user identifier in internal systems)
3. System access and usage data (e.g., user identifiers, access logs, IP addresses, cookies, logs)
4. Technical and operational data.
5. Audio and video recordings of calls.
6. The Parties will not collect or intentionally process any special category of data. The PROCESSOR will immediately inform of any unintentional receipt of special categories of data.

#### 3. Categories of personal data processed by the PROCESSOR:

1. Employees of the CONTROLLER.
2. Clients, potential clients, their employees, contacts, or end users of the CONTROLLER.

#### 4. Type of processing carried out

The Assignment will involve the following processing of personal data:

1. Storage and retention of data, recording, retrieval and input of data.
2. Access to and consultation of information
3. Voice recording.
4. Information processing through AI.
5. Audio transcription through AI.
6. Semantic analysis of text.
7. Analysis and processing of data
8. Integration with AI platforms or third-party systems
9. Anonymization or pseudonymization of data.
10. Deletion or destruction of data.
11. Updating of data, including its correction, adaptation, alteration, alignment and combination.

#### 5. Security measures

**Category | Security measure implemented**

**Organizational measures**

* Periodic security assessments.
* Secure and automated processes (CI/CD).

**Technical measures**

* Data encryption at rest and in transit.
* Session tokens.
* Antivirus scanning.
* Protection against attacks (injection, XSS, SSRF).

**Access control measures**

* Authentication via trusted providers and OTP.
* Role-based authorization (OpenFGA).
* 2FA on administrative interfaces.

**Continuity and recovery measures**

* Automated deployments with recovery <10 min.
* Monitoring and verification of configurations.
* Periodic backups.

***

#### 6. Authorized sub-processors

| Provider/Sub-processor | Service provided                     | Location | International transfers |
| ---------------------- | ------------------------------------ | -------- | ----------------------- |
| Bunny.net              | CDN and video storage                | EU       | N/A                     |
| Google Cloud           | Cloud infrastructure / AI            | EU       | N/A                     |
| Vercel                 | Hosting and deployment               | EU       | N/A                     |
| Hyperdoc               | Meeting recording                    | EU       | N/A                     |
| Crisp                  | Live chat                            | EU       | N/A                     |
| Nylas                  | Email and calendar API               | EU       | N/A                     |
| Hookdeck               | Webhook management                   | EU       | N/A                     |
| Supabase               | Database                             | EU       | N/A                     |
| AWS                    | Backup and additional infrastructure | EU       | N/A                     |
| Auth0                  | Authentication and authorization     | EU       | N/A                     |
| Stripe                 | Payment processing                   | EU       | N/A                     |
| Resend                 | Email sending                        | EU       | N/A                     |
| DigitalOcean           | Cloud infrastructure                 | EU       | N/A                     |
| Posthog                | Usage analytics                      | EU       | N/A                     |
| Datadog                | Monitoring and logs                  | EU       | N/A                     |
| Assembly AI            | Audio transcription through AI       | EU       | N/A                     |
| Elevenlabs             | Conversational AI models             | EU       | N/A                     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.salescaling.com/en/compliance-and-legal/procesamiento-datos.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
