Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service between Polca LLC ("Processor") and the Agency ("Controller"), applies to both editions of the platform (Polca and LifePros), and governs Polca's processing of Agency Personal Data: personal information the Agency submits to or generates through the Service, including lead and client records, call recordings and transcripts, the Agency's Opt-Out Ledger, and application related materials that may contain health related answers and banking details. If this DPA conflicts with the Terms on personal data processing, this DPA controls.
1. Roles and instructions
The Agency is the controller/business; Polca is the processor/service provider. Polca will process Agency Personal Data only: (a) to provide, secure, and support the Service as described in the Terms and Annex 1; (b) per the Agency's documented instructions given through the Service's configuration; and (c) as required by law. For governmental or legal demands concerning Agency Personal Data, Polca will review the demand for legal validity, seek to narrow demands it reasonably considers overbroad, disclose only the information legally required, and notify the Agency before disclosure unless prohibited by law. Polca will promptly inform the Agency if, in its opinion, an instruction violates applicable data protection law.
Agency responsibilities. The Agency is responsible for the lawfulness, accuracy, and quality of Agency Personal Data and of its processing instructions; providing legally required privacy notices; obtaining required consents or other lawful bases, including for sensitive data and call recording; responding to Consumers as controller; securing its own credentials, integrations, and user access; and configuring and using the Service lawfully, including not submitting data the Service is not designed and authorized to process.
2. Service provider certifications
Polca will not: sell or share Agency Personal Data; retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes in Annex 1 (including not for advertising or training generalized AI models); or combine it with data from other sources except to perform the Service. Polca certifies it understands and will comply with these restrictions under the CCPA/CPRA and similar state laws.
3. Confidentiality, personnel and the firewall
Access to Agency Personal Data is limited to personnel and contractors who need it to perform the Service and who are bound by written confidentiality obligations. Access is least privilege, support only, and audit logged. Consistent with Section 15 of the Terms, information learned from Agency Personal Data is never used by any agency affiliated with Polca's owner to compete with the Agency, solicit its Consumers, or recruit its personnel; the only cross agency use is the de-identified, aggregated benchmark use described in the Terms, which is always disclosed as such and never identifies an Agency or Consumer.
4. Sensitive data; HIPAA
Agency workflows may include health related and financial information collected by the Agency from its clients. Polca applies Annex 2 safeguards to all Agency Personal Data uniformly. This DPA is not a Business Associate Agreement and does not authorize submission of PHI subject to HIPAA. An Agency that believes its use requires a BAA must contact legal@polca.ai and may not submit such PHI unless and until the parties execute one. To the extent applicable to the Agency or Agency Personal Data, Polca acts as a service provider supporting the Agency's obligations under GLBA related safeguards requirements and applicable state insurance data security laws.
5. Sub-processors
The Agency authorizes the sub-processor categories in Annex 3. Polca will: maintain a current named list (available at privacy@polca.ai); bind each sub-processor by written contract to obligations materially equivalent to this DPA, including the service provider restrictions applicable under state privacy laws (such as the CCPA/CPRA); remain responsible for their performance; and give at least 15 days' notice of additions or replacements, during which the Agency may object on reasonable data protection grounds. If an objection is unresolved, the Agency may terminate the affected portion of the Service prorated.
6. Security
Polca implements and maintains the technical and organizational measures in Annex 2, appropriate to the nature of the data, and will not materially decrease the overall protection during a subscription term.
7. Personal data breach
"Personal Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Agency Personal Data; it excludes unsuccessful attempts and incidents that do not compromise the confidentiality, integrity, or availability of Agency Personal Data (such as blocked attacks, failed login attempts, or port scans).
Polca will notify the Agency without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Agency Personal Data, providing: the nature and categories affected, approximate volumes, likely consequences, measures taken or proposed, and a contact point, supplemented as information becomes available. Polca will reasonably cooperate with the Agency's own notification obligations. Notification is not an admission of fault.
8. Assistance
Taking into account the nature of processing, Polca will reasonably assist the Agency with: (a) responding to Consumer requests (access, deletion, correction, opt-out); the Service provides export and deletion tooling, automated opt-out enforcement, and the downloadable Opt-Out Ledger; (b) security and impact assessments relating to the Service; and (c) regulator inquiries concerning Agency Personal Data processed by Polca. Assistance beyond built-in tooling may be billed at reasonable rates with advance notice, except that Polca will not charge for assistance reasonably required because of Polca's breach of this DPA, its violation of applicable data protection law, or a Personal Data Breach caused by Polca or its sub-processors.
9. Retention, deletion and return
9.1 During the term, the Agency may export Agency Personal Data at any time, including a one-click full export of leads, appointments, notes, call logs, and the Opt-Out Ledger.
9.2 Call recordings are retained for 90 days from creation and then permanently deleted, platform wide; the Agency may export recordings before deletion.
9.3 On termination or cancellation, Agency Personal Data is frozen and available for export for 60 days, after which Polca deletes it from production systems; encrypted backups are deleted or overwritten within 35 days thereafter. Exceptions: (a) retention required by law, valid legal process, or a documented legal hold, in which case the retained data remains protected under this DPA and is deleted when the retention basis ends; and (b) the Opt-Out Ledger, which Polca may retain after account closure solely to honor do-not-call and opt-out obligations. On written request, Polca will confirm deletion in writing.
10. Audits
No more than once annually (and after a confirmed breach affecting the Agency), Polca will, on written request: provide a written description of its security program and this DPA's implementation, complete a reasonable security questionnaire, and make available existing third party assessments when they exist. If these are insufficient to meet a legal obligation, the parties will agree on a reasonable, scoped remote audit at the Agency's expense, under confidentiality, no more than once annually, except following a material Personal Data Breach, a material security control change, or where required by a regulator or applicable law.
11. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (Section 21). This DPA is effective for as long as Polca processes Agency Personal Data.
Annex 1: Processing details
- Subject matter and purpose: operating the appointment setting platform: placing and answering calls, transcription, summarization, disposition, CRM synchronization, calendaring, reporting, storage, support, security, and opt-out suppression.
- Duration: the subscription term plus the 60 day export and freeze period and the deletion schedule in Section 9.
- Data subjects: the Agency's leads, clients, and policyholders; Agency users.
- Categories: identifiers and contact details; call audio, transcripts, and summaries; appointment and disposition records; opt-out and suppression records; documents the Agency uploads, which may include health related application answers and banking details; Agency user account data.
Annex 2: Security measures
- Tenant isolation enforced at the database layer via forced row level security on every tenant table; a non-privileged application role that cannot bypass it; automated isolation tests in the deployment pipeline.
- Encryption in transit (TLS); hashed credentials (memory hard algorithm); secrets stored outside source control with restricted permissions.
- Least privilege, individually attributed, audit logged administrative access limited to support, maintenance, security, billing, and compliance purposes.
- Network controls: firewalled databases (application only access), carrier restricted SIP ingress, hardened public endpoints.
- Recording lifecycle management: automatic suppression of recording on calls to numbers associated with designated all-party consent states, and scheduled deletion of recordings no later than 90 days after creation, except where preservation is required by law or legal hold.
- Platform enforced dialing rails: calling hour and Sunday restrictions, timezone cross-checks, opt-out suppression at dial time, kill switch, and cadence caps, none of which can be loosened by configuration.
- Vulnerability remediation prioritized by severity; periodic security review against a maintained internal audit.
- Personnel confidentiality obligations; contractor IP and confidentiality agreements; offboarding access revocation.
- Encrypted backups are access restricted and deleted or overwritten within 35 days after deletion from production systems, except where preservation is legally required.
Annex 3: Authorized sub-processor categories
- Cloud infrastructure hosting: application hosting, databases, encrypted storage, backups, and related infrastructure in the United States
- Payment processing (currently Stripe): Agency billing data only
- Telephony carriers and caller identity/branding registrars: call delivery, number provisioning, attestation
- AI speech and language providers: transcription, speech synthesis, and conversation processing in live call handling