1. Parties and scope
This agreement is between the business that accepts it (“you”, the controller) and ListenFox (“we”, the processor). It forms part of the Terms of Service and applies whenever we process personal data in the calls, recordings, transcripts and contact details you connect. Where it conflicts with the Terms on personal data, this agreement wins.
2. Your instructions
We process personal data only on your documented instructions: the Terms, this agreement and the settings you choose in the product (sources, redaction, retention, alerts and sharing). We tell you if we think an instruction breaks the law. The subject matter, nature, purpose and duration of the processing are in Annex I.
3. No use for our own purposes
- We do not sell or share your data, and we do not use it for advertising.
- We do not use it to train or improve AI models, ours or anyone else’s.
- We do not combine it with data from other customers or use it to serve another customer.
- We do not keep or use it for any purpose other than providing the service to you.
4. Confidentiality
Everyone at ListenFox who can reach your data is bound by confidentiality and reaches it only when the work needs it, such as answering a support request you made.
5. Security
We keep the technical and organisational measures in Annex II in place, and we only change them in ways that keep the overall level of protection the same or better.
6. Subprocessors
You authorise the subprocessors on our subprocessor list (Annex III). Each is bound by data-protection terms at least as protective as these. We email account owners and DPA signatories at least 30 days before we add or replace one. You may object by replying; if we can’t resolve the objection, you may close your account before the change takes effect. We remain responsible for our subprocessors.
7. Helping you meet your obligations
We help you, as far as we reasonably can, to answer requests from the people in your calls (access, correction, deletion and objection), and with data-protection impact assessments, risk assessments and consultations with regulators. Much of this you can do in the product, for example deleting a call or a source. For the rest, email us. If someone contacts us directly about your data, we pass the request to you and do not answer it ourselves unless you ask us to.
8. Personal data breaches
We tell you without undue delay, and within 48 hours of becoming aware, of a breach that affects your data. We tell you what happened, what data and people are involved, what we are doing about it and who to contact, and we keep you updated as we learn more. That gives you time to meet a 72-hour deadline to notify a regulator.
9. Deletion at the end
When the agreement ends, we delete your personal data within 30 days, unless the law requires us to keep part of it (such as billing records). Before that, you can ask us for a copy.
10. Audits and information
We give you the information you reasonably need to show that this agreement is being kept, including a written report on our measures once a year if you ask. You, or an independent auditor bound by confidentiality, may audit us on 30 days’ notice, at your own cost, no more than once a year unless a regulator requires it or a breach has occurred.
11. If we can’t comply
If we can no longer meet our obligations under this agreement or the law, we tell you, and you may stop the processing and end the agreement.
12. International transfers
We operate from India, host in the EU and use subprocessors in the US. Where the law of your country restricts a transfer, the regional annex for it applies (Annex IV).
13. Liability
The limits of liability in the Terms apply to this agreement, except where the law does not allow them.
Annex I: Details of the processing
- Subject matter and purpose: transcribing and analysing your business calls and showing you the results, as the service describes.
- Duration: for as long as you use the service, then section 9.
- Nature: collection from your connected sources, storage, transcription, AI analysis, search, display, alerts, sharing on your instruction, and deletion.
- People: your callers, your staff and agents on the calls, and the users of your account.
- Data: phone numbers, names and anything else said on a call; voice recordings; transcripts; call details such as time, duration and agent; and user account details.
- Special categories: callers may mention health or other sensitive matters. You decide what to connect, and you may switch on redaction. Do not connect calls containing protected health information of a US HIPAA covered entity: we do not sign business associate agreements.
- Frequency: continuous, as calls arrive.
Annex II: Technical and organisational measures
- Encryption in transit (HTTPS) everywhere; source credentials encrypted at rest. Recordings and the database are not encrypted at rest by us today.
- Passwords hashed with argon2id; sessions are random tokens in httpOnly cookies; changes carry a CSRF token.
- Every request for workspace data passes through one tested membership check; roles limit what each user sees.
- Optional redaction of card numbers, ID numbers, bank account numbers and spoken passwords before a transcript is stored.
- An audit log of sensitive actions; public share links that expire and stop working when revoked.
- No security certification (such as SOC 2 or ISO 27001) today. More on the security page.
Annex III: Subprocessors
The subprocessor list, as changed under section 6.
Annex IV: Regional terms
- EU and EEA: the Standard Contractual Clauses (Module 2 between you and us, Module 3 between us and our subprocessors) apply to transfers out of the EEA, with a transfer impact assessment. Our EU representative will be named here.
- United Kingdom: the UK International Data Transfer Addendum to those clauses applies.
- United States: we act as your service provider under the CCPA. We do not sell or share your personal information, or keep, use or disclose it outside our business relationship with you, and we tell you if we can no longer meet these obligations.
- India: we act as your data processor under the Digital Personal Data Protection Act, 2023 and its Rules, apply the safeguards in section 5, and keep relevant logs for at least one year.
- UAE: we help you meet your obligations under the UAE data-protection law that applies to you.
Questions about this agreement: [email protected].