1. Status and execution
This public document is not a self-executing DPA. It is a review framework for customer contracting. A binding DPA requires the parties’ exact legal names, signatures or valid incorporation, service scope, data-processing details, security exhibit, subprocessor list, transfer mechanism, and notice information.
2. Definitions and law
Controller, processor, business, service provider, personal data, personal information, processing, data subject, consumer, and supervisory authority have the meanings assigned by the privacy law applicable to the processing. Customer and LumiTalk may have different roles for different data sets.
3. Roles and instructions
For Customer Data processed solely to provide configured Services, Customer determines the permitted purposes and means and instructs LumiTalk through the agreement, Order Form, configuration, and documented directions. LumiTalk will process that data only on documented instructions, to provide and secure the Services, or as required by law.
4. Processing details
| Required annex field | Must be completed in the signed DPA |
|---|---|
| Subject and duration | Subscribed Services, term, transition, backup, and deletion periods |
| Nature and purpose | Channels, workflows, support, security, and authorized improvement uses |
| Data subjects | Customer personnel, prospects, clients, callers, message participants, or other defined groups |
| Data categories | Contact, conversation, recording, transcript, integration, account, audit, or other defined data |
| Sensitive data | Expressly identify permitted regulated or sensitive categories—or state none |
| Frequency and locations | Continuous, occasional, or event-driven processing and approved regions |
5. Customer obligations
- Provide lawful instructions and a valid basis for processing.
- Deliver required notices and obtain communications, recording, and integration permissions.
- Limit data and access to what the workflow needs.
- Configure retention, escalation, and human review appropriate to the risk.
- Do not submit prohibited regulated data without written authorization.
6. Confidentiality and personnel
LumiTalk will limit Customer Data access to personnel and contractors who need it for authorized duties and are bound by confidentiality obligations appropriate to their role. Customer is responsible for its authorized users and connected-system permissions.
7. Security measures
The executed DPA must incorporate a security exhibit describing applicable access controls, credential protection, encryption, logging, change management, vulnerability handling, backup, resilience, personnel safeguards, and incident response. This framework does not claim a certification or control that has not been verified.
8. Subprocessors
The executed DPA must authorize identified subprocessors, provide an update and objection process appropriate to applicable law, and require materially equivalent data-protection duties. If a reasonable objection cannot be resolved, the signed DPA should state the available service-change or termination remedy.
9. Individual-rights assistance
Taking into account the nature of processing, LumiTalk will provide reasonable assistance enabling Customer to respond to verified rights requests when Customer cannot fulfill the request through available tools. LumiTalk may direct a requester to Customer when Customer controls the data.
10. Security incidents
LumiTalk will notify Customer without undue delay after confirming a breach of Customer Personal Data where notice is required by the executed DPA, provide reasonably available information, take containment and remediation steps, and cooperate with legally required notifications. A specific deadline must be negotiated and written before reliance.
11. Assessments and consultations
LumiTalk will provide reasonable information about its processing needed for Customer’s legally required data-protection assessment or regulatory consultation, subject to confidentiality, security, proportionality, and protection of other customers.
12. International transfers
Restricted transfers require an applicable adequacy decision, certification, approved contractual clauses, or other lawful mechanism identified in the executed DPA. Required modules, annexes, supplementary measures, importer/exporter roles, and transfer locations must be completed; they are not supplied by assumption.
13. Information and audit
The executed DPA should prioritize current independent reports and questionnaires, then permit a proportionate audit when legally required or when those materials are insufficient. Audit scope, frequency, confidentiality, notice, cost, and security protections must be stated.
14. Return and deletion
At termination or Customer’s lawful instruction, LumiTalk will return or delete Customer Personal Data as stated in the executed DPA, subject to active-service needs, secure backup cycles, legal holds, security records, and mandatory retention. The signed annex must state usable export and deletion timelines.
15. Order of precedence
For personal-data processing, the executed DPA controls over conflicting general service terms. The Order Form controls service-specific commercial scope, while mandatory law controls to the extent it cannot be varied by contract.





