1. Scope and Defined Terms
This Data Processing Addendum forms part of the Terms or other agreement between Ulyvero and the customer. It applies when Ulyvero processes personal data on the customer’s behalf. “Applicable Data Protection Law” includes the Delaware Personal Data Privacy Act and other US state privacy laws that apply to the processing, as well as the GDPR when contractually applicable.
2. Roles and Processing Details
The customer is controller or business and Ulyvero is processor or service provider for customer data. Processing covers voice, SMS, chat, contact, appointment, business-knowledge, support, and security data for the duration of the Service and applicable retention period. Data subjects may include customer personnel, callers, message recipients, website visitors, and contacts.
3. Documented Instructions
Ulyvero processes customer data only to provide, secure, support, and improve the Service under the agreement and the customer’s documented configuration and instructions, unless law requires otherwise. We will notify the customer if an instruction appears to violate applicable data-protection law unless prohibited.
4. US State Service-Provider Commitments
Ulyvero will not sell or share customer personal data for targeted advertising, retain, use, or disclose it outside the direct business relationship except as permitted by law and the agreement, or combine it with unrelated personal data except as legally permitted to provide the Service. The customer may take reasonable steps to verify compliance and require remediation.
5. Confidentiality
Personnel authorized to process customer data are bound by confidentiality and receive access only as needed for their role.
6. Subprocessors
The customer authorizes the subprocessors listed on the Subprocessors page. Ulyvero remains responsible for their performance to the extent required by law and imposes data-protection terms appropriate to the services. We will provide notice of a material new subprocessor and a reasonable opportunity to object on substantiated data-protection grounds.
7. Security
Ulyvero maintains safeguards appropriate to risk, including encryption in transit and at rest, logical tenant separation, least-privilege access, credential protection, logging, vulnerability management, backups, and incident response.
8. Security Incidents
Ulyvero will notify the customer without undue delay after confirming a breach of customer personal data and will provide available information reasonably needed for the customer’s legal obligations. Notice is not an admission of fault.
9. Return and Deletion
At termination or on documented request, Ulyvero will delete or return customer data within the periods in the Privacy Policy, unless law requires retention. Protected backups are isolated from routine use and expire on the ordinary backup cycle.
10. Assistance
Taking account of the processing and information available, Ulyvero will reasonably assist with data-subject requests, security assessments, breach notifications, and data-protection impact assessments. Additional work outside standard product functions may be charged at agreed rates.
11. Information and Audits
Ulyvero will provide information reasonably necessary to demonstrate compliance. Once per year, unless a regulator or confirmed incident requires more, a customer may request a remote audit on reasonable notice, subject to confidentiality, security, and non-disruption requirements. Third-party reports may satisfy the request.
12. International Transfers
Customer data is primarily processed in the United States. If a restricted international transfer is in scope, the parties will use an applicable transfer mechanism, including Standard Contractual Clauses where required.
13. General
If this DPA conflicts with the agreement on personal-data processing, this DPA controls. Delaware law and the dispute provisions in the Terms apply. Questions: admin@ulyvero.com.