Holina

Data Processing Addendum

Last updated: August 1, 2026 · Incorporated into the Terms of Service

Why this exists: when Holina answers your phone, we handle personal data about your callers — their phone numbers, what they said, what they ordered or booked. In data-protection terms, you decide what happens to that data and we act on your instructions. This document sets out that relationship in the form your own compliance team, or your customers', will ask for.

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and EpochCore LLC ("Provider") for the Holina service. It applies to Provider's processing of Personal Data on Customer's behalf. Where this DPA conflicts with the Terms of Service, this DPA controls for data-protection matters.

1. Roles

2. Scope of processing

Subject matterOperating an automated phone receptionist and related messaging, booking, and reporting on Customer's behalf
DurationThe term of the agreement, plus the retention periods in section 8
Nature and purposeReceiving and answering calls; converting speech to text and text to speech; generating responses from Customer-approved information; sending confirmations and links; recording bookings, orders and messages; producing call reports for Customer
Categories of data subjectCustomer's callers and customers; Customer's own staff who use the dashboard
Categories of personal dataPhone numbers; names supplied by callers; call transcripts and, where enabled, call audio; message content; appointment and order details; email addresses where given; call metadata (times, duration, outcome)
Special-category dataNot contemplated. The service is not configured or contracted for health data subject to HIPAA, payment card data, government identifiers, or biometric data. Customer must not configure the service to collect them.

3. Provider's obligations

4. Security measures

Provider maintains technical and organizational measures appropriate to the risk, including:

5. Subprocessors

6. Personal data breach

7. Data subject requests

The service gives Customer the ability to access, export, correct, and delete Caller Data directly. If a data subject contacts Provider instead, Provider will not respond substantively (except to direct them to Customer) and will forward the request to Customer without undue delay. Provider will assist Customer in responding, at no additional charge for a reasonable volume of requests.

8. Retention, return, and deletion

9. Audits

On reasonable written request, no more than once per twelve months (or after a Personal Data Breach affecting Customer), Provider will make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to a reasonable security questionnaire. On-site audits, where a supervisory authority requires them, will be scheduled with reasonable notice, during business hours, subject to confidentiality, and without disrupting the service or other customers' data.

10. International transfers

Provider processes data in the United States. Where Customer transfers personal data subject to the GDPR or UK GDPR, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and, for UK transfers, the UK International Data Transfer Addendum, with: Clause 7 (docking) included; Clause 9 option 2 (general written authorization, 30 days' notice); Clause 11 optional redress body omitted; Clause 17 governed by the law of Ireland; Clause 18(b) courts of Ireland. Annexes I, II, and III are populated by sections 2, 4, and 5 of this DPA and the Subprocessors page respectively.

11. Signing this DPA

This DPA applies automatically to every customer. If your organization requires a countersigned copy, email john@holina.io and we will execute one — including a version incorporating your own paper where reasonable.

Contact