Data Processing Addendum

This addendum is part of the Terms of Service between your business ("the business") and Kavara Inc. ("CommLocker"). It covers the personal information in the business's records that CommLocker processes on the business's behalf.

1. Roles

  • The business decides what is captured, who on its team can see it, how long it is kept, and when it is deleted.
  • CommLocker is the business's service provider. It processes the business's records only on the business's behalf, as this addendum and the Terms of Service set out.

For the personal information CommLocker collects about its own users (their accounts, sign-in and usage), see the Privacy Policy.

2. What is processed

Records Calls and their recordings, live and after-call transcripts and summaries; texts with photos and files; voicemail; email; meeting recordings and transcripts; WhatsApp, Instagram and Facebook messages; imported documents
Beside the records People and the numbers, emails and handles matched to them; Files and their parties; notes; Ask questions and answers; exports; the audit log
Whose information The business's team, and the people they talk to: customers, callers, and anyone else in the business's conversations
What for Capturing, storing, fingerprinting, searching, organising, exporting and answering questions over the business's records, and placing and receiving its calls and texts: providing CommLocker to the business
How long While the business has a plan, and for 90 read-only days after it ends, unless the business deletes sooner

3. What CommLocker commits to

CommLocker:

  1. processes the business's records only to provide CommLocker to the business, following the business's settings and instructions in the app;
  2. never sells or shares them, and never uses them for advertising;
  3. never keeps, uses or discloses them for any other purpose, or outside its direct relationship with the business;
  4. never combines them with personal information from other sources, except as the law allows a service provider to;
  5. never uses them, or lets anyone else use them, to train AI models;
  6. follows the California Consumer Privacy Act and gives the records the protection it requires;
  7. tells the business if it can no longer meet these commitments;
  8. lets the business take reasonable steps to make sure CommLocker uses the records as this addendum says, and to stop and fix any use that isn't allowed;
  9. requires the same commitments from every company that processes the records for it (section 5).

4. Requests from the people in the records

If someone asks CommLocker to see, correct or delete what a business holds about them (for example a caller), CommLocker passes the request to the business. The business has the tools in CommLocker to act on it: search and export by person, and delete a record or all data.

5. Companies that process records for CommLocker

Company What for Records it processes
Amazon Web Services Hosting, storage and databases in the United States All
Telnyx Numbers, calls, texts, voicemail, 911, number porting, texting registration, live and voicemail transcripts Calls, texts, voicemail. CommLocker deletes Telnyx's copy of a recording once it has stored it
OpenRouter, and Anthropic, OpenAI and Google models Ask and summaries, only when the business turns AI on Only the parts of records a question or summary needs, and only what the person asking may see. Every provider used keeps nothing and trains on nothing
Sentry Crash reports None: crash reports carry no record content, names or numbers

When the business connects Google, Microsoft, Zoom or Meta accounts, CommLocker receives records from those services at the business's request; they are the business's own providers.

6. Security

  • Records are encrypted in transit and at rest, each business's with its own key.
  • Every record is stored in write-once storage when it is captured and fingerprinted (SHA-256). No one, CommLocker included, can change it or delete it before its lock ends.
  • Each system has only the access it needs, and every person at CommLocker with access uses two-step sign-in.
  • Every change a person makes in the business is kept in its audit log.
  • Logs never contain message content, recordings or sign-in tokens.

If CommLocker learns that the business's records were accessed by someone not allowed to, it tells the Owner without undue delay, with what happened and what was done.

7. Deletion and return

  • The business can export its records at any time, and during the 90 read-only days after its plan ends.
  • Deleting the account or all data switches off the business's key: within minutes no one, CommLocker included, can open the records. The locked copies are erased when their lock ends, on the date the app shows.
  • After the 90 read-only days, CommLocker deletes all of the business's data the same way.
  • Database backups keep deleted data for up to 35 days, then it is gone from them too.

8. Contact

Kavara Inc., <address>. Email <support email>.