Harlo

Data Processing Agreement

Last updated: 5 August 2026 · Effective date: 21 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Jyoram LLC d/b/a Harlo, 8228 Oakwood, Plano, TX 75024, USA ("Harlo" or "Processor") and the customer that has entered into the Terms and Conditions or another written services agreement with Harlo (the "Customer" or "Controller"; together, the "Parties"). It governs the Processing of Personal Data by Harlo on the Customer's behalf in connection with the Harlo platform and services (the "Services"). Where there is a conflict between this DPA and the main agreement on data protection matters, this DPA prevails.

Contents

  1. Definitions
  2. Roles & Scope
  3. Processing Instructions
  4. No AI Training
  5. Confidentiality
  6. Security Measures
  7. Subprocessors
  8. Data Subject Requests
  9. Personal Data Breaches
  10. Government Access Requests
  11. Assistance & DPIAs
  12. Transfers & Locations
  13. Return & Deletion
  14. Audits
  15. U.S. State Laws
  16. Liability & Term
  17. Annex A — Details of Processing
  18. Annex B — Security Measures
  19. Annex C — Subprocessors

1. Definitions

Capitalized terms not defined here have the meaning given in the main agreement. "Data Protection Laws" means all applicable laws relating to data protection and privacy, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and U.S. state privacy laws such as the CCPA/CPRA. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given under applicable Data Protection Laws. "Customer Personal Data" means Personal Data contained in Customer Data that Harlo Processes on the Customer's behalf under the Services.

2. Roles & Scope

For Customer Personal Data, the Customer is the Controller (or a processor acting on behalf of a third-party controller) and Harlo is the Processor. Where Harlo engages other entities to Process such data, those entities act as Harlo's subprocessors. Harlo Processes Customer Personal Data only to provide the Services and as described in this DPA and Annex A. For data Harlo processes for its own business purposes (e.g., account administration, billing, security), Harlo acts as an independent Controller as described in its Privacy Policy.

3. Processing Instructions

Harlo will Process Customer Personal Data only on documented instructions from the Customer, including with respect to international transfers, unless required by applicable law (in which case Harlo will inform the Customer of that legal requirement before Processing, unless the law prohibits such notice). The main agreement, this DPA, and the Customer's configuration and use of the Services constitute the Customer's complete and documented instructions. Harlo will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.

The Customer warrants that it has a lawful basis and all necessary consents and notices in place to enable lawful Processing by Harlo, including for the recording, transcription, and AI analysis of communications and for any special-category data the Customer chooses to submit.

4. No Training on Customer Personal Data

Harlo will not use Customer Personal Data to train, retrain, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, whether Harlo's own or a third party's, and will not permit its subprocessors to do so. Harlo engages its large-language-model, speech-to-text, and text-to-speech subprocessors only through commercial/API offerings whose terms prohibit the use of customer content for model training. Customer Personal Data is submitted to such subprocessors solely to generate real-time inference output (transcripts, responses, synthesized speech, summaries) needed to deliver the Services.

Any use of Customer Personal Data for model training or improvement would require the Customer's prior, express, written opt-in on separately agreed terms; absent such agreement, no such use occurs. This section does not restrict Harlo's use of aggregated or de-identified usage and performance data that is no longer Personal Data (e.g., latency and error metrics) to operate, secure, and improve the Services, provided such data is never used to train generalized AI models on the content of the Customer's communications and is not re-identified.

5. Confidentiality

Harlo will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and are made aware of the confidential nature of the data, and that access is limited to those who need it to provide the Services.

6. Security Measures

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, Harlo will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. A description of these measures is set out in Annex B. Harlo may update its measures provided the level of protection is not materially reduced.

7. Subprocessors

The Customer provides general authorization for Harlo to engage subprocessors to Process Customer Personal Data, subject to this section. Harlo will: (a) maintain a current list of subprocessors, including entity names, purposes, and locations, in Annex C, published at https://askharlo.ai/data-processing-agreement.html#annex-c; (b) impose data protection obligations on each subprocessor that are no less protective than this DPA (including the no-training commitment in Section 4 for AI subprocessors); and (c) remain responsible for its subprocessors' performance.

Changes. Harlo will give the Customer at least 30 days' prior written notice before adding or replacing a subprocessor, by email to the Customer's account administrator or designated contact and by updating the published list. The Customer may subscribe to subprocessor-change notifications by emailing privacy@askharlo.ai with the subject "Subscribe: subprocessor updates". The Customer may object on reasonable data-protection grounds within 30 days of the notice; the Parties will then work in good faith to resolve the objection (e.g., by a configuration that avoids the new subprocessor). If no resolution is reached within 30 days of the objection, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the terminated portion. Emergency replacements (e.g., for security or continuity) may take effect sooner, in which case Harlo will notify the Customer without undue delay and the same objection right applies.

8. Data Subject Requests

Taking into account the nature of the Processing, Harlo will provide reasonable assistance, including by appropriate technical and organizational measures and the functionality of the Services, to help the Customer respond to requests from Data Subjects to exercise their rights. If Harlo receives such a request directly, it will, unless legally prohibited, promptly forward it to the Customer and not respond except on the Customer's instructions.

9. Personal Data Breaches

Harlo will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its breach-notification obligations. Harlo will take reasonable steps to mitigate and, where possible, remediate the breach. Harlo's notification is not an acknowledgment of fault or liability.

10. Government & Law-Enforcement Access Requests

If Harlo receives a request, demand, or order from a government authority, law-enforcement agency, or court to disclose or provide access to Customer Personal Data, Harlo will: (a) promptly notify the Customer before disclosure, unless legally prohibited from doing so, and where prohibited use reasonable efforts to obtain a waiver of the prohibition or to have the requestor contact the Customer directly; (b) review the legality of the demand and challenge it, including seeking interim relief, where it is overbroad, lacks a valid legal basis, or exceeds the requestor's authority; (c) attempt to redirect the requestor to obtain the data from the Customer; (d) disclose only the minimum Customer Personal Data legally required to comply; and (e) document each demand and, where permitted, provide the Customer with relevant details. Harlo does not provide any government with voluntary, direct, standing, or bulk access to Customer Personal Data, and has not built any back door or similar means of access into the Services. As of the "last updated" date above, Harlo has not received any such demand concerning Customer Personal Data.

11. Assistance & Data Protection Impact Assessments

Taking into account the nature of Processing and the information available to it, Harlo will provide reasonable assistance to the Customer with data protection impact assessments and any prior consultations with supervisory authorities that the Customer is required to carry out under Data Protection Laws.

12. International Transfers & Processing Locations

Customer Personal Data is hosted and Processed in the United States on Amazon Web Services infrastructure, and the subprocessors listed in Annex C Process Customer Personal Data from the locations stated there (see also the processing-locations entry in Annex A). Harlo will notify the Customer through the Section 7 subprocessor-change process before Processing Customer Personal Data from a country not already disclosed.

Where Harlo Processes Customer Personal Data subject to the GDPR or UK GDPR in a country that has not received an adequacy decision, the Parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum, which are incorporated by reference and completed using the details in the Annexes. Harlo will provide the Customer with information reasonably necessary to conduct transfer impact assessments, and the commitments in Section 10 (government access) apply as supplementary measures to any such transfer.

13. Return & Deletion

Upon termination or expiry of the Services (or earlier, upon the Customer's written request), Harlo will, at the Customer's choice, return Customer Personal Data in a commonly used, machine-readable format and/or delete it, and will complete deletion from active systems within 30 days of the termination date or request, unless applicable law requires continued storage (in which case Harlo will inform the Customer of the requirement, isolate the retained data, and continue to protect it under this DPA). Customer Personal Data in routine, encrypted backups is deleted as those backups expire on their normal rotation, and in any event within 90 days of the active-system deletion; backup copies are not restored to active use except for disaster recovery, and remain protected under this DPA until expiry. Upon written request, Harlo will provide the Customer with written certification that deletion has been completed. The Customer may export Customer Data through the Services during the applicable post-termination window.

14. Audits

Harlo will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable confidentiality, frequency, scope, and notice limitations. Where available, Harlo may satisfy audit requests by providing relevant third-party certifications or reports (e.g., SOC 2, ISO 27001).

15. U.S. State Privacy Laws

To the extent the CCPA/CPRA or similar U.S. state laws apply, Harlo acts as a "service provider"/"processor" and will: Process Customer Personal Data only to perform the Services or as permitted by law; not "sell" or "share" such data; not retain, use, or disclose it outside the direct business relationship or for any purpose other than the Services; and not combine it with other data except as permitted. Harlo certifies it understands and will comply with these restrictions.

In addition, as required by Cal. Civ. Code §1798.100(d): (a) Harlo will notify the Customer without undue delay if it determines that it can no longer meet its obligations under the CCPA/CPRA or this DPA; and (b) upon such notice, or where the Customer reasonably believes Harlo is using Customer Personal Data in an unauthorized manner, the Customer may take reasonable and appropriate steps to stop and remediate that unauthorized use, and Harlo will cooperate, including by suspending the affected Processing. The Customer may also take reasonable and appropriate steps (including the audit rights in Section 14) to ensure that Harlo uses Customer Personal Data consistently with the Customer's obligations under those laws.

16. Liability & Term

Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement. This DPA takes effect on the effective date above and continues for as long as Harlo Processes Customer Personal Data, after which the surviving obligations (e.g., confidentiality, deletion) continue to apply.

Annex A — Details of Processing

Subject matterProvision of the Harlo AI voice and chat agent Services.
DurationFor the term of the main agreement plus any applicable retention/backup window.
Nature & purposeReceiving and conducting telephone, chat, and audio conversations on the Customer's behalf; speech-to-text transcription; large-language-model processing; text-to-speech synthesis; tool/integration execution; recording (where enabled); summarization; and persistence of records, all to deliver the Services.
Categories of Data SubjectsThe Customer's end users, callers, chat participants, and the Customer's personnel/administrators.
Categories of Personal DataContact identifiers (e.g., name, phone number), communications content (call audio, chat messages, transcripts, summaries), interaction metadata (timestamps, channel, disposition), and any other data the Customer chooses to submit through the Services.
Special-category dataNot requested by Harlo. The Customer is responsible for any special-category data it chooses to submit and for ensuring a lawful basis.
AI trainingNone. Customer Personal Data is used for real-time inference only and is not used to train or improve AI/ML models by Harlo or its subprocessors (Section 4).
Processing locationsUnited States. The Services are hosted on Amazon Web Services infrastructure in the United States; subprocessors Process Customer Personal Data from the locations listed in Annex C (United States unless otherwise noted there).
FrequencyContinuous, on an ongoing basis, for the duration of the Services.

Annex B — Technical & Organizational Security Measures

Annex C — Subprocessors

Harlo engages the subprocessors listed below to provide the Services. This list is the current, published subprocessor list referenced in Section 7; changes are notified as described there. Entries marked with an asterisk (*) are engaged only where the relevant provider or feature is enabled for the Customer's configuration.

EntityPurposeLocation
Amazon Web Services, Inc.Cloud hosting and infrastructure; storage of records, transcripts, and call recordings; text-to-speech (Amazon Polly)*.United States
Twilio Inc.Telephony — inbound/outbound call media and signaling.United States
RingCentral, Inc.*Telephony — call media and signaling for RingCentral-connected numbers.United States
Deepgram, Inc.Speech-to-text transcription of call and audio content.United States
OpenAI, L.L.C.*Large-language-model processing — AI reasoning, response, and summary generation (inference only; no training, per Section 4).United States
Anthropic, PBC*Large-language-model processing — AI reasoning, response, and summary generation (inference only; no training, per Section 4).United States
ElevenLabs, Inc.*Text-to-speech synthesis of agent voice output.United States
Cartesia AI, Inc.*Text-to-speech synthesis of agent voice output.United States
Microsoft Corporation*Text-to-speech synthesis (Azure Speech).United States
Google LLC*Text-to-speech synthesis, address geocoding, and Customer-enabled Google integrations (e.g., Calendar, Drive).United States
Pinecone Systems, Inc.*Vector database for knowledge-base retrieval.United States
Stripe, Inc.Payment processing and billing.United States

Questions about this list, and subscription to change notifications, via privacy@askharlo.ai.