Data Processing Addendum
Last updated: August 1, 2026 · Incorporated into the Terms of Service
Why this exists: when Holina answers your phone, we handle personal data about your callers — their phone numbers, what they said, what they ordered or booked. In data-protection terms, you decide what happens to that data and we act on your instructions. This document sets out that relationship in the form your own compliance team, or your customers', will ask for.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and EpochCore LLC ("Provider") for the Holina service. It applies to Provider's processing of Personal Data on Customer's behalf. Where this DPA conflicts with the Terms of Service, this DPA controls for data-protection matters.
1. Roles
- Customer is the controller (or "business" under U.S. state privacy law) of Caller Data — the personal data of people who call, text, or book with Customer's business.
- Provider is the processor (or "service provider") of that data and processes it only on Customer's documented instructions.
- Provider is an independent controller of its own business-contact data about Customer (billing contact, account administrator), governed by the Privacy Policy.
2. Scope of processing
| Subject matter | Operating an automated phone receptionist and related messaging, booking, and reporting on Customer's behalf |
|---|---|
| Duration | The term of the agreement, plus the retention periods in section 8 |
| Nature and purpose | Receiving and answering calls; converting speech to text and text to speech; generating responses from Customer-approved information; sending confirmations and links; recording bookings, orders and messages; producing call reports for Customer |
| Categories of data subject | Customer's callers and customers; Customer's own staff who use the dashboard |
| Categories of personal data | Phone numbers; names supplied by callers; call transcripts and, where enabled, call audio; message content; appointment and order details; email addresses where given; call metadata (times, duration, outcome) |
| Special-category data | Not contemplated. The service is not configured or contracted for health data subject to HIPAA, payment card data, government identifiers, or biometric data. Customer must not configure the service to collect them. |
3. Provider's obligations
- Process Personal Data only on Customer's documented instructions, which include the agreement, Customer's configuration of the service, and Customer's use of its features. Provider will tell Customer if an instruction appears to violate applicable law.
- Never sell or share Personal Data, and never use it for cross-context behavioral advertising.
- Never use Caller Data to train models for any other customer or third party. Provider's speech and language processing runs on Provider-operated hardware; Caller Data is not sent to a third-party AI provider — see Subprocessors.
- Ensure personnel with access are bound by confidentiality and are granted access on a least-privilege basis.
- Assist Customer, taking into account the nature of processing, with data subject requests, security, breach notification, and data protection impact assessments.
4. Security measures
Provider maintains technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) for all traffic, and encryption at rest for stored data.
- Tenant isolation. Every record is scoped to a tenant identifier and every query is filtered by the tenant resolved from the requester's authenticated session — never from a value the client supplies. This isolation is verified by an automated test suite that attempts cross-tenant access against every endpoint on each change.
- Authentication. Dashboard access requires one-time-code verification of a registered phone number; session tokens are stored only as hashes and expire.
- Post-quantum-ready cryptographic sealing of call evidence records, so an artifact's integrity can be proven independently.
- Least-privilege credentials, secret rotation, structured audit logging of administrative actions, and automated monitoring with alerting.
- Rate limiting, bot protection, and spend controls on abuse-prone endpoints.
5. Subprocessors
- Customer gives general authorization for Provider to engage the subprocessors listed at holina.io/legal/subprocessors.
- Provider imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable for their performance.
- Provider gives at least 30 days' notice before adding a subprocessor that will process Caller Data. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected service without penalty and receive a prorated refund of prepaid unused fees.
6. Personal data breach
- Provider will notify Customer without undue delay and in any case within 48 hours of becoming aware of a Personal Data Breach affecting Customer's data.
- The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent known, with updates as the investigation proceeds. Provider will not delay an initial notice in order to complete an investigation.
- Provider will reasonably assist Customer with Customer's own notification obligations to regulators and data subjects.
7. Data subject requests
The service gives Customer the ability to access, export, correct, and delete Caller Data directly. If a data subject contacts Provider instead, Provider will not respond substantively (except to direct them to Customer) and will forward the request to Customer without undue delay. Provider will assist Customer in responding, at no additional charge for a reasonable volume of requests.
8. Retention, return, and deletion
- Retention periods per data class are set out in the Privacy Policy. Call transcripts are retained for 13 months; call audio is not captured by default and, where enabled, is retained for 90 days; message logs for 90 days.
- On termination, Customer may export its data for 30 days. After that, Provider deletes it, and instructs subprocessors to do the same, within 30 days.
- Provider will certify deletion in writing on request.
- Exception: records evidencing an opt-out or do-not-contact request are retained indefinitely, because deleting them would allow the person to be contacted again. This is a suppression list, not a marketing list.
- Backups are overwritten on their normal cycle; a backup will not outlive the primary copy by more than 30 days.
9. Audits
On reasonable written request, no more than once per twelve months (or after a Personal Data Breach affecting Customer), Provider will make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to a reasonable security questionnaire. On-site audits, where a supervisory authority requires them, will be scheduled with reasonable notice, during business hours, subject to confidentiality, and without disrupting the service or other customers' data.
10. International transfers
Provider processes data in the United States. Where Customer transfers personal data subject to the GDPR or UK GDPR, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and, for UK transfers, the UK International Data Transfer Addendum, with: Clause 7 (docking) included; Clause 9 option 2 (general written authorization, 30 days' notice); Clause 11 optional redress body omitted; Clause 17 governed by the law of Ireland; Clause 18(b) courts of Ireland. Annexes I, II, and III are populated by sections 2, 4, and 5 of this DPA and the Subprocessors page respectively.
11. Signing this DPA
This DPA applies automatically to every customer. If your organization requires a countersigned copy, email john@holina.io and we will execute one — including a version incorporating your own paper where reasonable.
Contact
- Data protection contact: john@holina.io
- Mail: EpochCore LLC, 8315 Camberly Rd, Huntersville, NC 28078