Data Processing Agreement (DPA)

Appendix to Skipcall General Terms and Conditions

Last updated: September 12, 2026

This agreement (hereinafter the "Agreement") is intended to define the conditions under which SKIPCALL, acting as a "processor" within the meaning of European data protection regulations, undertakes to perform, on behalf of the Client, acting as the controller, personal data processing operations in connection with the performance of the services covered by the Contract as described in the SKIPCALL General Terms of Service, of which this Agreement forms an appendix. The processing covered by this Agreement is described in Annex 1.

Within the framework of their contractual relationship, the Parties undertake to comply with applicable personal data protection regulations, in particular the GDPR or Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (applicable since May 25, 2018), as well as French Law No. 78-17 of January 6, 1978 on Data Processing, Files and Freedoms (hereinafter collectively referred to as the "Applicable Regulations").

The Parties adopt the definitions set out in the applicable regulations, in particular the GDPR, including "personal data", "processing", "controller" and "processor".

Article 1. General Obligations of SKIPCALL

SKIPCALL undertakes to:

  • Process Personal Data only on the Client's instructions and not use personal data for any purpose other than the strict performance of the Contract.
  • Process data in accordance with the Client's instructions. The Client understands it may configure processing parameters itself (type of data, processing operations, retention period where that setting is available, etc.). If SKIPCALL considers an instruction to be non-compliant with Applicable Regulations, it will inform the Client.
  • Ensure confidentiality of processed Personal Data and ensure authorised persons are bound by confidentiality obligations.
  • Apply data protection by design and by default principles in its tools and services.
  • Implement the technical and organisational measures described in Annex 2 and provide assistance to enable the Client to meet its legal obligations.
  • Implement security measures taking into account risks such as destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
  • Notify the Client of any personal data breach within a maximum of 72 hours after becoming aware of it, including via email to the Client's DPO, including:
    • Description of the breach
    • Contact point
    • Likely consequences
    • Measures taken or proposed

    If full information is not immediately available, additional details will be provided as soon as possible.

  • Provide all necessary information to demonstrate compliance and allow audits under reasonable conditions. The Client is limited to one audit per contract year (except emergency situations). If audits create workload, they may be billed unless required by GDPR Article 28.
  • Maintain a written record of processing activities including:
    • Client details
    • Sub-processors
    • Processing categories
    • International transfers
    • Security measures

Article 2. Sub-processors

2.1 The Client authorises SKIPCALL to engage the sub-processors listed on the list published and kept up to date at skipcall.io/en/subprocessors, which the Client declares having reviewed. For each sub-processor, this list states its identity, the purpose for which it is engaged, the country of processing and, where applicable, the safeguard governing transfers outside the European Union.

2.2 SKIPCALL informs the Client of any addition or replacement of a sub-processor at least 15 days before it is put into service, by email to the contact address provided by the Client and, where applicable, through the subscription to list update notifications.

2.3 The Client may object to such addition or replacement on legitimate grounds relating to data protection, within 15 days of being informed. Failing a solution acceptable to both Parties, the Client may terminate the Contract without penalty for the part of the Services concerned.

2.4 SKIPCALL contractually imposes on each sub-processor data protection and confidentiality obligations equivalent to those of this Agreement, and remains fully liable to the Client for the performance of that sub-processor's obligations.

Article 3. Rights of Data Subjects

3.1 The Client remains responsible for informing data subjects at the time of data collection, in accordance with Articles 13 and 14 of the GDPR.

3.2 SKIPCALL assists the Client, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling its obligation to respond to requests for exercising the rights laid down in Articles 15 to 22 of the GDPR: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability and right to object.

3.3 To this end, SKIPCALL makes the following functions available to the Client from the Services interface:

  • Search and review: search by name, phone number or email address to identify all data attached to a person: contact record, calls, recordings, SMS, associated tasks and notes.
  • Rectification: direct editing of a contact's identification and contact details from its record.
  • Erasure: deletion of a contact, a selection of contacts or the entire contact base.
  • Access and portability: CSV export of contacts and their tracking data from a sequence. The Client's administrator allows or restricts this function for the members of its workspace.
  • Review of communication content: playback of the audio recording, the summary and the full transcript of a call from the corresponding recording record, with copy of the summary and the transcript.
  • Restriction of processing: deactivation of call recording across the workspace by the Client's administrator.
  • User management: addition, role change, deactivation, reactivation and removal of a user from the workspace by the Client's administrator.
  • Control of data flows to third-party tools: connection and disconnection of the Client's CRM (Salesforce, HubSpot, Pipedrive, Attio) at any time.

3.4 Where a request cannot be fulfilled by the Client from the interface, SKIPCALL acts on it upon the Client's documented instruction within 7 business days of receipt of the instruction.

3.5 If a data subject addresses a request to exercise their rights directly to SKIPCALL, SKIPCALL refrains from responding on the merits and forwards the request to the Client within a maximum of 7 business days, informing the data subject of this forwarding.

Article 4. Personal Data Retention and Deletion

SKIPCALL will not retain data beyond the retention periods defined by the Client or, failing that, those set out in point 1.6 of Annex 1, except for compliance or contractual proof.

Data is deleted at the Client's request within 30 days. Absent any instruction, it is deleted automatically within 90 days of the end of the subscription. Backups expire automatically after 30 days, and erasure propagates to them at that point.

Upon Client instruction or contract termination, SKIPCALL will return or permanently delete data and provide destruction confirmation.

Article 5. Data Protection Officer

Each Party must communicate DPO contact details and notify changes.

Article 6. Data Transfers

SKIPCALL will host and process personal data within the EU or in countries with adequate protection recognised by the European Commission and CNIL.

Transfers outside the EU will only occur with appropriate safeguards such as certifications or standard contractual clauses (SCCs).

Article 7. Sensitive Data

Services do not process sensitive data under GDPR Articles 9 and 10.

If needed, processing will be governed by an amendment specifying additional safeguards.

Article 8. Client Obligations

The Client undertakes to:

  • Provide necessary data
  • Document instructions
  • Ensure compliance with regulations and perform data protection impact assessments if needed, with the assistance of SKIPCALL provided for in Article 10
  • Supervise processing and audits
  • Maintain processing records
  • Ensure lawful data processing
  • Obtain equivalent obligations if acting as processor itself

Article 9. Cooperation in Case of Non-Compliance

If a compliance breach occurs, Parties will collaborate to assess severity and determine whether processing should be suspended or the Contract terminated.

If SKIPCALL cannot comply, it will inform the Client. After 30 days of suspension, termination rights may apply.

The Client may terminate if SKIPCALL is in serious or repeated breach or fails to comply with regulatory decisions.

SKIPCALL may terminate if Client instructions violate applicable laws.

Article 10. Assistance of SKIPCALL under Articles 32 to 36 of the GDPR

10.1 Security of processing (Article 32). SKIPCALL implements and maintains the technical and organisational measures described in Annex 2. It informs the Client of any substantial change to these measures. These measures may not be degraded during the term of the Contract.

10.2 Notification of breaches (Article 33). SKIPCALL notifies the Client of any personal data breach within a maximum of 72 hours from the moment it becomes aware of it, by email to the privacy contact address provided by the Client. The notification contains the elements already provided for in Article 1: description of the breach, contact point, likely consequences, measures taken or proposed. Information not available at the time of the initial notification is communicated as it becomes available.

10.3 Communication to data subjects (Article 34). SKIPCALL provides the Client, on request, with the information and cooperation needed to enable it to communicate the breach to data subjects where such communication is required.

10.4 Data protection impact assessment and prior consultation (Articles 35 and 36). SKIPCALL assists the Client in carrying out its data protection impact assessments (DPIA) and, where applicable, in the prior consultation of the supervisory authority. This assistance consists of providing, upon written request: the description of the processing set out in Annex 1, the technical and organisational measures set out in Annex 2, the up-to-date list of sub-processors and the information relating to transfers outside the European Union.

10.5 Terms. This assistance is provided free of charge.

Annex 1. Description of the processing

1.1 Subject matter of the processing

The purpose of the processing is the performance of the business telephony and phone prospecting Services subscribed to by the Client, as described in the General Terms of Service.

1.2 Duration of the processing

The processing is carried out for the entire term of the Contract, plus the retention periods defined in Article 4 and in point 1.6 of this annex.

1.3 Nature and purpose of the processing

List of operations carried out:

  • creation and management of the Client's user accounts and workspaces (workspaces and sub-teams)
  • allocation, management and return of landline and mobile phone numbers
  • making and receiving phone calls from the browser and from the iOS and Android mobile application
  • automated dialling (power dialer and parallel dialer up to four lines) and automatic answering-machine detection, combining SKIPCALL logic with Twilio native detection
  • call recording
  • automatic call transcription, performed by Gladia (processing in France / EEA)
  • generation of call summaries by artificial intelligence, performed by Gladia (processing in France / EEA)
  • sending and receiving SMS, manual and automated
  • dropping pre-recorded voice messages on contacts' voicemail boxes
  • hosting of a contact base (pre-CRM) and of the history of exchanges, statuses and associated tasks
  • enrichment of contact details (phone numbers and email addresses)
  • two-way synchronisation with the Client's CRMs (HubSpot, Pipedrive, Salesforce, Attio) and provision of a REST API and webhooks
  • production of activity statistics and dashboards (volumes, answer rates, activity per team)
  • retention, archiving and deletion of data according to the settings chosen by the Client
  • provision of support and technical assistance

1.4 Categories of personal data

Category Data concerned
Contact identificationsurname, first name, job title, company
Contact detailslandline and mobile phone numbers, email addresses
Enriched dataphone numbers and email addresses obtained through the enrichment service
Content of communicationsaudio recordings of calls, transcripts, AI-generated summaries, content of SMS sent and received, pre-recorded voice messages dropped
Traffic and connection datadate, time and duration of calls, call direction, calling and called number, call status (answered, voicemail, no answer), line and user originating the call
Sales tracking datacontact status, notes, tasks, reasons, interaction history
Data of the Client's userssurname, first name, business email address, login credentials, role, membership of a team or workspace, connection logs
Data from the Client's CRMData exchanged with the Client's CRM within the scope of the permissions granted by the Client when connecting its account. Read: contact records and their properties, including custom ones; company records and their properties; custom objects; record owners; contact lists. Write: updating of contact records and custom objects, for the purpose of logging the phone activity carried out from the Services. The exact scope of fields depends on the configuration of the Client's CRM, which the Client retains control of.

Note: scope of access to the Client's CRM

SKIPCALL's access to the Client's CRM is strictly limited to the permissions the Client grants when connecting its account. By way of illustration, the HubSpot integration requires the following permissions:

Access type Permission Scope
Read crm.objects.contacts.read · crm.schemas.contacts.read Contact records and their properties, including custom ones
Read crm.objects.companies.read · crm.schemas.companies.read Company records and their properties
Read crm.objects.custom.read · crm.schemas.custom.read Custom objects
Read crm.objects.owners.read Record owners (HubSpot users)
Read crm.lists.read Contact lists
Write crm.objects.contacts.write Contact records
Write crm.objects.custom.write Custom objects

SKIPCALL does not access the Client's deals, tickets or emails. The Client may revoke this access at any time from its CRM. The Pipedrive, Salesforce and Attio integrations require permissions of equivalent scope: reading contact and company records and their properties, writing to contact records for the purpose of logging phone activity. The exact list of permissions requested is presented to the Client on the connection screen of each integration, before the Client grants them.

1.5 Categories of data subjects

  • The Client's users: employees of the Client holding a Skipcall licence.
  • The users of the Client's CRM: employees of the Client identified as record owners in the connected CRM, whether or not they hold a Skipcall licence.
  • The Client's contacts: prospects, customers, candidates and more generally any person called by the Client, calling the Client, or receiving an SMS or a voice message sent through the Services.
  • Third parties mentioned during a communication: persons whose data is stated during a call or in an SMS and is thereby recorded in a recording, a transcript or a summary, without being a party to the communication.

1.6 Retention periods

Data Period
Audio recordings1 year. Client-configurable retention period available from the end of 2026.
Transcripts and AI summaries1 year. Client-configurable retention period available from the end of 2026.
SMS contentRetained until the conversation is deleted by the Client.
Contact data and historyRetained until the contact is deleted by the Client.
Call metadata in the application (date, time, duration, direction, status, user)term of the subscription
Infrastructure logs (Scaleway Cockpit)31 days
User accounts90 days after the end of the subscription
Return then permanent deletion after the end of the Contract90 days after the end of the subscription

1.7 Safeguards relating to artificial intelligence processing

The Client's data is not used to train any artificial intelligence model, including third-party or shared models.

Artificial intelligence processing relies solely on the audio content of the call concerned, to the exclusion of any knowledge base or external data source.

The Services perform no sentiment, mood or emotion analysis and include no autonomous conversational agent.

All artificial intelligence processing can be switched off: deactivating call recording at workspace level deactivates transcription and summaries, and no data is then transmitted to Gladia.

Annex 2. Technical and organisational measures

No. Area Measures
1Encryption in transitTLS 1.2 minimum on all flows. Certificates managed through cert-manager.
2Encryption at restAES-256. Application secrets encrypted with AES-256-GCM through Scaleway Secret Manager. API keys stored as cryptographic hashes.
3Key and secret rotationHalf-yearly rotation of keys and credentials. No secret stored in code or configuration.
4Physical access controlData centres of the hosting provider Scaleway (Paris region fr-par: PAR-1/PAR-2; backups replicated to Amsterdam nl-ams), ISO 27001 certified. Physical access control, video surveillance and security guarding provided by the hosting provider under its certification. SKIPCALL operates no physical hardware of its own.
5Logical access controlAuthentication delegated to WorkOS (AuthKit). MFA available, enforceable at organisation level on request. SSO / SAML / OIDC configurable on request. Password policy and session management (expiry, lockout) handled by WorkOS. Administrator access to the infrastructure only through a private VPN. Organisation-level roles: Member, Manager, Admin, with granular permissions. Access control enforced server-side.
6Internal authorisationsAccess of SKIPCALL staff to client data limited to what is strictly necessary (support, operations), according to the principle of least privilege.
7Logging and traceabilityApplication logging and error monitoring via Sentry and Cockpit. Logged events: application errors, infrastructure events, administrator access (VPN). Mutating API operations are logged. Centralised infrastructure logs (Scaleway Cockpit), 31-day retention. Client export of administrative audit logs is not available to date and is on the roadmap.
8Segregation of data between clientsShared architecture with logical multi-tenant isolation enforced by the SKIPCALL application: each request carries the organisation identifier (organizationId) issued by WorkOS, which restricts the scope of accessible data. Segregation is covered by code review and application tests. Dedicated, isolated environment available on request, subject to set-up fees and a specific plan.
9Secure developmentSeparate environments (development, staging, production). Systematic code review. Dependency and vulnerability management via npm and Dependabot, with monthly monitoring and support. CI/CD and infrastructure as code via Terraform, GitOps deployment (ArgoCD) on Kubernetes (Scaleway Kapsule). Regular OS and runtime updates on managed Kubernetes. Critical security patches applied upon disclosure. Security advisories communicated through the agreed support and escalation channel.
10Backups and restorationFrequency: every 6 hours. Retention: 30 days. Encryption: AES-256. Cross-region replication: Amsterdam (nl-ams). Restoration procedure tested.
11Availability and continuityPostgreSQL in high availability (automatic failover in about 10 seconds), Redis 7 in a TLS cluster, Kubernetes orchestration. RTO: about 10 minutes. RPO: about 6 hours. Internal availability target: 99.9%.
12Penetration tests and auditsIndependent penetration test carried out in April 2025 by RiskHunter. Report available on request under a non-disclosure agreement.
13Security incident managementDocumented incident management procedure, multi-channel monitoring and alerting (Sentry). Notification of personal data breaches to the Client within a maximum of 72 hours (see Article 10).
14StaffGDPR awareness training for staff. Offboarding procedure with revocation of access on departure.
15CertificationsHosting provider Scaleway: ISO 27001. SKIPCALL holds no certification of its own to date.