This Data Processing Agreement ("DPA") forms part of the agreement between Jyoram LLC d/b/a Harlo, 8228 Oakwood, Plano, TX 75024, USA ("Harlo" or "Processor") and the customer that has entered into the Terms and Conditions or another written services agreement with Harlo (the "Customer" or "Controller"; together, the "Parties"). It governs the Processing of Personal Data by Harlo on the Customer's behalf in connection with the Harlo platform and services (the "Services"). Where there is a conflict between this DPA and the main agreement on data protection matters, this DPA prevails.
Capitalized terms not defined here have the meaning given in the main agreement. "Data Protection Laws" means all applicable laws relating to data protection and privacy, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and U.S. state privacy laws such as the CCPA/CPRA. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given under applicable Data Protection Laws. "Customer Personal Data" means Personal Data contained in Customer Data that Harlo Processes on the Customer's behalf under the Services.
For Customer Personal Data, the Customer is the Controller (or a processor acting on behalf of a third-party controller) and Harlo is the Processor. Where Harlo engages other entities to Process such data, those entities act as Harlo's subprocessors. Harlo Processes Customer Personal Data only to provide the Services and as described in this DPA and Annex A. For data Harlo processes for its own business purposes (e.g., account administration, billing, security), Harlo acts as an independent Controller as described in its Privacy Policy.
Harlo will Process Customer Personal Data only on documented instructions from the Customer, including with respect to international transfers, unless required by applicable law (in which case Harlo will inform the Customer of that legal requirement before Processing, unless the law prohibits such notice). The main agreement, this DPA, and the Customer's configuration and use of the Services constitute the Customer's complete and documented instructions. Harlo will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
The Customer warrants that it has a lawful basis and all necessary consents and notices in place to enable lawful Processing by Harlo, including for the recording, transcription, and AI analysis of communications and for any special-category data the Customer chooses to submit.
Harlo will not use Customer Personal Data to train, retrain, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, whether Harlo's own or a third party's, and will not permit its subprocessors to do so. Harlo engages its large-language-model, speech-to-text, and text-to-speech subprocessors only through commercial/API offerings whose terms prohibit the use of customer content for model training. Customer Personal Data is submitted to such subprocessors solely to generate real-time inference output (transcripts, responses, synthesized speech, summaries) needed to deliver the Services.
Any use of Customer Personal Data for model training or improvement would require the Customer's prior, express, written opt-in on separately agreed terms; absent such agreement, no such use occurs. This section does not restrict Harlo's use of aggregated or de-identified usage and performance data that is no longer Personal Data (e.g., latency and error metrics) to operate, secure, and improve the Services, provided such data is never used to train generalized AI models on the content of the Customer's communications and is not re-identified.
Harlo will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and are made aware of the confidential nature of the data, and that access is limited to those who need it to provide the Services.
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, Harlo will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. A description of these measures is set out in Annex B. Harlo may update its measures provided the level of protection is not materially reduced.
The Customer provides general authorization for Harlo to engage subprocessors to Process Customer Personal Data, subject to this section. Harlo will: (a) maintain a current list of subprocessors, including entity names, purposes, and locations, in Annex C, published at https://askharlo.ai/data-processing-agreement.html#annex-c; (b) impose data protection obligations on each subprocessor that are no less protective than this DPA (including the no-training commitment in Section 4 for AI subprocessors); and (c) remain responsible for its subprocessors' performance.
Changes. Harlo will give the Customer at least 30 days' prior written notice before adding or replacing a subprocessor, by email to the Customer's account administrator or designated contact and by updating the published list. The Customer may subscribe to subprocessor-change notifications by emailing privacy@askharlo.ai with the subject "Subscribe: subprocessor updates". The Customer may object on reasonable data-protection grounds within 30 days of the notice; the Parties will then work in good faith to resolve the objection (e.g., by a configuration that avoids the new subprocessor). If no resolution is reached within 30 days of the objection, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the terminated portion. Emergency replacements (e.g., for security or continuity) may take effect sooner, in which case Harlo will notify the Customer without undue delay and the same objection right applies.
Taking into account the nature of the Processing, Harlo will provide reasonable assistance, including by appropriate technical and organizational measures and the functionality of the Services, to help the Customer respond to requests from Data Subjects to exercise their rights. If Harlo receives such a request directly, it will, unless legally prohibited, promptly forward it to the Customer and not respond except on the Customer's instructions.
Harlo will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its breach-notification obligations. Harlo will take reasonable steps to mitigate and, where possible, remediate the breach. Harlo's notification is not an acknowledgment of fault or liability.
If Harlo receives a request, demand, or order from a government authority, law-enforcement agency, or court to disclose or provide access to Customer Personal Data, Harlo will: (a) promptly notify the Customer before disclosure, unless legally prohibited from doing so, and where prohibited use reasonable efforts to obtain a waiver of the prohibition or to have the requestor contact the Customer directly; (b) review the legality of the demand and challenge it, including seeking interim relief, where it is overbroad, lacks a valid legal basis, or exceeds the requestor's authority; (c) attempt to redirect the requestor to obtain the data from the Customer; (d) disclose only the minimum Customer Personal Data legally required to comply; and (e) document each demand and, where permitted, provide the Customer with relevant details. Harlo does not provide any government with voluntary, direct, standing, or bulk access to Customer Personal Data, and has not built any back door or similar means of access into the Services. As of the "last updated" date above, Harlo has not received any such demand concerning Customer Personal Data.
Taking into account the nature of Processing and the information available to it, Harlo will provide reasonable assistance to the Customer with data protection impact assessments and any prior consultations with supervisory authorities that the Customer is required to carry out under Data Protection Laws.
Customer Personal Data is hosted and Processed in the United States on Amazon Web Services infrastructure, and the subprocessors listed in Annex C Process Customer Personal Data from the locations stated there (see also the processing-locations entry in Annex A). Harlo will notify the Customer through the Section 7 subprocessor-change process before Processing Customer Personal Data from a country not already disclosed.
Where Harlo Processes Customer Personal Data subject to the GDPR or UK GDPR in a country that has not received an adequacy decision, the Parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum, which are incorporated by reference and completed using the details in the Annexes. Harlo will provide the Customer with information reasonably necessary to conduct transfer impact assessments, and the commitments in Section 10 (government access) apply as supplementary measures to any such transfer.
Upon termination or expiry of the Services (or earlier, upon the Customer's written request), Harlo will, at the Customer's choice, return Customer Personal Data in a commonly used, machine-readable format and/or delete it, and will complete deletion from active systems within 30 days of the termination date or request, unless applicable law requires continued storage (in which case Harlo will inform the Customer of the requirement, isolate the retained data, and continue to protect it under this DPA). Customer Personal Data in routine, encrypted backups is deleted as those backups expire on their normal rotation, and in any event within 90 days of the active-system deletion; backup copies are not restored to active use except for disaster recovery, and remain protected under this DPA until expiry. Upon written request, Harlo will provide the Customer with written certification that deletion has been completed. The Customer may export Customer Data through the Services during the applicable post-termination window.
Harlo will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable confidentiality, frequency, scope, and notice limitations. Where available, Harlo may satisfy audit requests by providing relevant third-party certifications or reports (e.g., SOC 2, ISO 27001).
To the extent the CCPA/CPRA or similar U.S. state laws apply, Harlo acts as a "service provider"/"processor" and will: Process Customer Personal Data only to perform the Services or as permitted by law; not "sell" or "share" such data; not retain, use, or disclose it outside the direct business relationship or for any purpose other than the Services; and not combine it with other data except as permitted. Harlo certifies it understands and will comply with these restrictions.
In addition, as required by Cal. Civ. Code §1798.100(d): (a) Harlo will notify the Customer without undue delay if it determines that it can no longer meet its obligations under the CCPA/CPRA or this DPA; and (b) upon such notice, or where the Customer reasonably believes Harlo is using Customer Personal Data in an unauthorized manner, the Customer may take reasonable and appropriate steps to stop and remediate that unauthorized use, and Harlo will cooperate, including by suspending the affected Processing. The Customer may also take reasonable and appropriate steps (including the audit rights in Section 14) to ensure that Harlo uses Customer Personal Data consistently with the Customer's obligations under those laws.
Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement. This DPA takes effect on the effective date above and continues for as long as Harlo Processes Customer Personal Data, after which the surviving obligations (e.g., confidentiality, deletion) continue to apply.
| Subject matter | Provision of the Harlo AI voice and chat agent Services. |
|---|---|
| Duration | For the term of the main agreement plus any applicable retention/backup window. |
| Nature & purpose | Receiving and conducting telephone, chat, and audio conversations on the Customer's behalf; speech-to-text transcription; large-language-model processing; text-to-speech synthesis; tool/integration execution; recording (where enabled); summarization; and persistence of records, all to deliver the Services. |
| Categories of Data Subjects | The Customer's end users, callers, chat participants, and the Customer's personnel/administrators. |
| Categories of Personal Data | Contact identifiers (e.g., name, phone number), communications content (call audio, chat messages, transcripts, summaries), interaction metadata (timestamps, channel, disposition), and any other data the Customer chooses to submit through the Services. |
| Special-category data | Not requested by Harlo. The Customer is responsible for any special-category data it chooses to submit and for ensuring a lawful basis. |
| AI training | None. Customer Personal Data is used for real-time inference only and is not used to train or improve AI/ML models by Harlo or its subprocessors (Section 4). |
| Processing locations | United States. The Services are hosted on Amazon Web Services infrastructure in the United States; subprocessors Process Customer Personal Data from the locations listed in Annex C (United States unless otherwise noted there). |
| Frequency | Continuous, on an ongoing basis, for the duration of the Services. |
Harlo engages the subprocessors listed below to provide the Services. This list is the current, published subprocessor list referenced in Section 7; changes are notified as described there. Entries marked with an asterisk (*) are engaged only where the relevant provider or feature is enabled for the Customer's configuration.
| Entity | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure; storage of records, transcripts, and call recordings; text-to-speech (Amazon Polly)*. | United States |
| Twilio Inc. | Telephony — inbound/outbound call media and signaling. | United States |
| RingCentral, Inc.* | Telephony — call media and signaling for RingCentral-connected numbers. | United States |
| Deepgram, Inc. | Speech-to-text transcription of call and audio content. | United States |
| OpenAI, L.L.C.* | Large-language-model processing — AI reasoning, response, and summary generation (inference only; no training, per Section 4). | United States |
| Anthropic, PBC* | Large-language-model processing — AI reasoning, response, and summary generation (inference only; no training, per Section 4). | United States |
| ElevenLabs, Inc.* | Text-to-speech synthesis of agent voice output. | United States |
| Cartesia AI, Inc.* | Text-to-speech synthesis of agent voice output. | United States |
| Microsoft Corporation* | Text-to-speech synthesis (Azure Speech). | United States |
| Google LLC* | Text-to-speech synthesis, address geocoding, and Customer-enabled Google integrations (e.g., Calendar, Drive). | United States |
| Pinecone Systems, Inc.* | Vector database for knowledge-base retrieval. | United States |
| Stripe, Inc. | Payment processing and billing. | United States |
Questions about this list, and subscription to change notifications, via privacy@askharlo.ai.