Skip to content

Data Processing Agreement

DPA. Ready to sign.

When you use Rinqo, we process personal data on your behalf. GDPR Art. 28 requires a Data Processing Agreement for that. We have it prepared, including EU Standard Contractual Clauses and a full list of sub-processors.

Download the DPA template

Template in preparation

The legally finalised version will be available before market launch. In the meantime we will send you the current draft by email, typical reply within one business day.

What's in the DPA. In plain language.

Subject matter and duration

Rinqo processes your customers' data, name, phone number, email, conversation content, appointment details, for the duration of your contract. After termination we delete all personal data within 30 days, unless a statutory retention obligation applies.

Categories of data + data subjects

Categories: contact data, content data (calls, emails, chats), usage data. Data subjects: your customers, prospects, employees interacting with Rinqo. Sensitive data (GDPR Art. 9, e.g. health) only if you explicitly configure that and have a legal basis for it.

Technical and organisational measures

AES-256-GCM encryption for content data at rest, TLS 1.3 in transit, role-based access control, audit log on every write, two-factor authentication for all Rinqo staff, annual penetration tests at minimum. Full TOMs attached to the DPA.

Sub-processors

We use providers with a DPA per GDPR Art. 28 and Standard Contractual Clauses, with processing located in the EU: Hetzner (hosting, DE), Twilio Ireland (telephony), Microsoft Ireland Operations Ltd. (Azure OpenAI Service as primary LLM provider — Sweden Central, Microsoft EU Data Boundary, no training on customer data), KugelAudio GmbH, Hannover, Germany (TTS, EU hosting), Deepgram (STT, EU region), Brevo (email, FR). OVHcloud Roubaix stands by as an opt-in Pure-EU failover provider and only becomes a sub-processor after activation. Note: Deepgram is a US corporation with its own EU region — processing stays in the EU. You receive 30 days' notice before a new sub-processor is added, with right of objection. The full list with legal entities and data types is available in the TIA documentation in the dashboard.

Data subject rights + deletion

We assist you with access, rectification, deletion and portability requests (GDPR Art. 15-20). Via dashboard self-service you can export or delete individual records. On email request we respond within 48 hours.

Incident notification

We notify you of any data protection incidents without undue delay, within 24 hours of becoming aware. Incident reports include: nature of the incident, affected data, actions taken, recommendations for your own Art. 33 GDPR notification to the supervisory authority.

Audit rights

You may audit us once a year, and at any time on concrete cause. On request we provide reports (ISO 27001 in preparation, SOC-2 equivalent). On-site audits with two weeks' notice.

Sub-processors. Transparently listed.

The complete, up-to-date list of our sub-processors, including purpose, location and DPA status, is on the security page. Every change is documented there and announced 30 days before it takes effect.

View sub-processor list

Questions about the DPA?

Our data protection team can help with individual clauses, industry-specific requirements, or when your data protection officer has follow-up questions.

datenschutz@rinqo.de