Legal
Data Processing Addendum
When we answer your phone or your website, we are handling your customers' personal information on your behalf. This is the document that governs how. It forms part of your Services Agreement.
Version 1.0 · 6 October 2026
Who this is for. This page is for clients. If you're a member of the public wondering how your information is handled, our Privacy Policy is the page you want.
1. Scope and roles
This Data Processing Addendum ("DPA") applies where Alera Digital ("Alera", "Processor") processes personal information on behalf of a client ("Client", "Controller") in providing the Services. It is incorporated into and governed by the Services Agreement between the parties.
Client is the controller. Client determines why personal information is collected and how long it is kept. Alera is the processor, acting on Client's documented instructions. Where a term is used that is defined in applicable privacy law, it carries that meaning.
Where this DPA and the Services Agreement conflict on the subject of data protection, this DPA controls.
2. What we process
Subject matter and purpose. Operating AI receptionists, chat agents, review requests, lead follow-up and related marketing services so that Client can respond to and serve its own customers.
Duration. For the term of the Services Agreement, plus the retention period in section 9.
Categories of individuals. Client's customers, prospective customers and enquirers; Client's own staff where they use the Services.
Categories of personal information:
- Identifiers — name, phone number, email address, postal or service address.
- Communications content — what a caller or visitor says or types, including details they volunteer about their enquiry.
- Call metadata — originating number, time, duration.
- Call recordings and transcripts.
- Appointment and job details — what was booked, when, and the reason.
- Message delivery data — sends, failures, opt-outs.
Special categories. The Services are not designed to collect health, financial-account, biometric, government-identifier or other sensitive information. Client must not configure the Services to solicit it, and must tell us in writing before the Services are used in a context where it is likely to be volunteered, so that retention and access can be set appropriately.
3. Our obligations
- We process personal information only on Client's documented instructions, including the configuration Client approves, except where law requires otherwise — in which case we will tell Client first unless the law prohibits it.
- We will tell Client if, in our opinion, an instruction appears to breach applicable privacy law.
- We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use it for our own purposes.
- We do not use one client's data to serve another client, and we do not use Client's customer data to train general-purpose AI models.
- Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to deliver the Services.
4. Security
We maintain technical and organisational measures appropriate to the risk, including: encrypted connections for data in transit; access limited to the people who need it; multi-factor authentication on accounts holding personal information; reputable infrastructure providers; and prompt removal of access when someone no longer needs it.
We review these measures as the Services change. No system is perfectly secure, and we do not represent otherwise — but the information we handle belongs to other people's customers and we treat it that way.
5. Sub-processors
Client authorises the sub-processors below. Each is engaged under terms requiring protections materially equivalent to this DPA, and we remain liable to Client for their performance.
- GoHighLevel — powers the AI receptionist and chat services; stores contact records, conversations and transcripts.
- Netlify — website hosting and server logs.
- Google Workspace — business email.
- Cal.com — booking calendar; stores the details given when booking a meeting.
- Stripe — payment processing. We do not see or store full card numbers.
- Telecommunications carriers and messaging aggregators necessary to originate, terminate and deliver calls and text messages.
Changes. We will give Client at least 30 days' notice before adding or replacing a sub-processor. If Client reasonably objects on data-protection grounds within that period, the parties will work in good faith to find an alternative; if none is workable, Client may terminate the affected Service without penalty for the unused portion of any prepaid fees.
6. Requests from individuals
Individuals exercise their rights against the Controller — that is, against Client. If a request reaches us directly, we will not respond substantively on Client's behalf; we will forward it to Client without undue delay and tell the individual who the responsible business is.
We will give Client reasonable assistance, at Client's cost where the effort is material, in responding to requests for access, correction, deletion, portability or restriction, and in carrying out any required data-protection assessment or consultation.
7. Breach notification
If we become aware of a personal data breach affecting Client's data, we will notify Client without undue delay and in any event within 72 hours of confirming it.
The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as the investigation progresses, and reasonable cooperation with Client's own notification obligations.
Notifying regulators and affected individuals is Client's responsibility as controller. We will not make such a notification naming Client without consulting Client first, unless law requires us to.
8. Call recording
Where the Services record calls, the AI states this at the start of each call before the caller has said anything substantive, and callers may end the call or ask to be transferred to a person.
Client is responsible for its own obligations regarding call recording in every jurisdiction where its callers are located, including states that require the consent of all parties. We provide the notice described above and will follow reasonable written instructions. We do not provide legal advice on recording consent.
9. Retention, return and deletion
Recordings and transcripts are retained for 90 days by default. Client may elect 30 days, or a longer period, in writing.
On termination, Client may request export of its data within 30 days. After that window we will delete or anonymise Client's personal information, except where retention is required by law or where it exists in routine backups — in which case it remains protected by this DPA and is deleted on the normal backup cycle.
10. Audit and information
On reasonable written request, and no more than once in any twelve months unless a regulator requires otherwise or a breach has occurred, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including a written description of our security measures and our sub-processor arrangements.
Any on-site inspection will be at Client's cost, during business hours, on at least 30 days' notice, subject to confidentiality, and conducted so as not to disrupt the Services or compromise the confidentiality of other clients' data.
11. International transfers
The Services are operated from, and personal information is stored in, the United States. We will not transfer Client's personal information outside the United States without first putting an appropriate transfer mechanism in place and informing Client.
12. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Services Agreement, and the limits apply in aggregate across the Services Agreement and this DPA combined — not separately to each.
13. Term, changes and governing law
This DPA takes effect when the Services Agreement does and continues for as long as we process personal information for Client. Sections 7, 9 and 12 survive termination.
We may update this DPA where required by law or to reflect a change in the Services, by giving Client reasonable notice. A change that materially reduces Client's protections requires Client's agreement.
This DPA is governed by the laws of the State of Hawaii, with venue in the state and federal courts located in Hawaii, consistent with the Services Agreement.
14. Contact
Data-protection questions and requests: contact@aleradigital.com · Alera Digital, 1001 Bishop St. STE 2685A, Honolulu, HI 96813.