Skip to content

Data Processing Addendum

The terms on which Wixzel processes personal data on your behalf — the people your agents call, and the contacts you upload.

Last updated 2026-09-07. Operated by Aqeel Shamsudheen, trading as Wixzel, India. Questions to aqeel@wixzel.com.

1. Scope and roles

This Data Processing Addendum (DPA) is part of the Terms of Service and applies whenever Customer Data you put into the Service contains personal data about other people — your callers, your contacts, the people whose appointments an agent books. For that data you are the controller (the data fiduciary in Indian law) and Wixzel is your processor. Words defined in the Terms mean the same here; “personal data”, “processing”, “controller” and “processor” have the meanings in the GDPR, read together with equivalent terms in the laws that apply to you.

For your own account data we are the controller, and the Privacy Policy applies instead of this DPA.

2. What we process, and why

ItemDetail
Subject matterProviding AI voice agents that make and receive calls on your behalf
DurationThe life of your account, plus the deletion period in section 8
Nature and purposeReceiving call audio; converting it to and from text; generating the agent’s replies with language models; storing transcripts, recordings, contacts and appointments; metering usage; making all of it available to you through the API and console
Categories of dataNames, phone numbers and any other fields you attach to leads; the content of calls, including whatever callers say; appointment details; identifiers of the calls themselves
Data subjectsPeople you call, people who call your numbers, and your contacts
Special categoriesNone intended. Callers may nevertheless say anything on a call; you must not design an agent to solicit health, financial, biometric or other sensitive data unless you have a lawful basis and have told us

3. Your instructions

We process Customer Data only on your documented instructions. Your instructions are: the Terms, this DPA, and what you configure and call through the API and console — which agent, which engine, which numbers, what to store and what to delete. Calls are recorded by default; recording is switched off for your account on request. We will tell you if we believe an instruction breaks the law, and we may stop processing under it until the point is resolved. We do not process Customer Data for our own purposes, do not use it to train models, and do not sell it.

4. Your obligations

  • You have a lawful basis to collect each contact, to call each person, and to record where you record, and you give callers the notices the law requires. See the Acceptable Use Policy.
  • You respond to the rights requests of the people you call. We will help you, as described in section 7.
  • You do not upload data you are not entitled to process, and you do not instruct us to process it in a way that breaks the law.

5. Sub-processors

You authorise us to use the sub-processors listed in the Privacy Policy. Each is bound by written terms at least as protective as this DPA. The model providers receive the audio and text of the calls that use them; the hosting providers store the rest. We will update the list at least 14 days before a new sub-processor handles Customer Data, by changing that page and, for a material change, by email. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected part of the Service; unused credit is handled under the Credits and Refunds policy. We remain responsible for our sub-processors’ performance.

6. Security

We maintain technical and organisational measures appropriate to the risk, including: TLS on every connection over the internet; bcrypt for passwords and a peppered hash for API keys; encryption at rest with a dedicated key for trunk passwords and third-party credentials; scoped and revocable API keys; per-account isolation of every resource; rate limiting and abuse controls; a request id on every request for traceability; production access limited to the operator; and dropping request logs after three months. Everyone who accesses Customer Data on our side is bound to confidentiality.

Breach notice. If we become aware of a personal-data breach affecting Customer Data we will notify you without undue delay, and in any case within 72 hours, with what we know: what happened, which data and how many people are affected, the likely consequences, and what we are doing about it. We will update you as we learn more and cooperate with your own notifications.

7. Helping you with rights, assessments and authorities

  • If a person contacts us directly about data you control, we will pass the request to you and not answer it ourselves unless the law requires us to.
  • The API lets you find, export and delete a caller’s records yourself — leads, appointments, and each call with its transcript and recording. Where you cannot, we will do it within 10 business days of your request.
  • We will give you the information reasonably needed for a data-protection impact assessment or a consultation with a supervisory authority, to the extent it concerns our processing.
  • If a court, regulator or law-enforcement body demands Customer Data from us, we will tell you before complying unless we are legally prohibited, and disclose only what is required.

8. Deletion and return

You can export Customer Data through the API at any time and delete individual records whenever you choose. Closing your account from the console deletes Customer Data at once, and copies at our sub-processors are deleted on their retention schedules, except where the law requires us to keep something — billing records, for instance, in a form that no longer contains call content.

9. Audit

Once a year, or after a breach affecting your data, you may ask for written evidence of our compliance with this DPA — a description of our measures, and any third-party reports we hold. If that is insufficient to meet a legal requirement you have, you may conduct or commission an audit on 30 days’ notice, at your cost, during business hours, without disrupting the Service, and under confidentiality terms. We are a small operation; we will be candid about what we can show.

10. International transfers

Customer Data is stored in Finland and processed by sub-processors in the United States and India as described in the Privacy Policy. Where the GDPR governs the transfer, the parties rely on the European Commission’s standard contractual clauses, which are incorporated into this DPA with us as data importer and you as data exporter, module two (controller to processor), and on the EU–US Data Privacy Framework for eligible US sub-processors. Where Indian law governs, transfers are to countries not restricted by the central government.

11. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Terms of Service, and the total liability of each party under the Terms and this DPA combined is a single cap, not two. Where this DPA conflicts with the Terms on a data-protection point, this DPA prevails. This DPA ends when the Terms end, and sections 8 and 11 survive.