Legal · DPA

Data Processing Agreement

Last updated: May 1, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and Caliradi LLC, operator of Caliradi.ai (the "Processor"), and applies when we process personal data on your behalf in providing the Caliradi Service.

For most customers: By accepting our Terms of Service, you also accept this DPA. No separate signature is required for our standard tiers. Enterprise customers requiring a counter-signed DPA can request one at [email protected].

1. Definitions

Capitalized terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679):

2. Scope & subject matter

We process personal data only to provide the Caliradi Service to you and as instructed by you. The duration of processing is the term of your subscription, plus any retention period required by law.

3. Categories of personal data & data subjects

Category of dataData subjects
Contact details (name, email, phone)Your customers, prospects, leads
Communication content (chat, email)Your customers, prospects
Transaction recordsYour paying customers
Usage and behavioral dataYour website visitors

4. Processor obligations

We will:

5. Controller obligations

You will:

6. Security measures

We implement and maintain the following technical and organizational measures:

7. Sub-processors

You authorize us to engage the following sub-processors for the purposes described:

Sub-processorPurposeLocation
Cloud hosting & CDN providerHosting & CDNUSA
AI model providerAI inference (Kaira chatbot & agents)USA
Customer-record platformCRM databaseUSA
Stripe, Inc.Payment processingUSA, Ireland
Cloudflare, Inc.Network security & DNSGlobal
Email delivery providersTransactional emailUSA

We will notify you at least 14 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if no resolution is reached, you may terminate the affected portion of the Service.

8. Audits

Once per year, with at least 30 days' written notice, you may audit our compliance with this DPA. We may satisfy audit obligations by providing recent third-party audit reports (e.g., SOC-2). Audits must respect confidentiality and not disrupt operations.

9. International transfers

Where personal data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we rely on the EU Standard Contractual Clauses (SCCs, Module 2 — Controller to Processor) and the UK International Data Transfer Addendum, as applicable. These are incorporated by reference into this DPA.

10. Data subject requests

If a Data Subject contacts us directly with a request to exercise their rights, we will refer them to you and notify you. We will reasonably assist you in responding within the legal timeframes.

11. Liability

The liability cap and indemnification provisions of our Terms of Service apply to claims arising under this DPA, except where mandatory data-protection law requires otherwise.

12. Term & termination

This DPA continues for as long as we process personal data on your behalf. Provisions intended to survive (confidentiality, audit, liability, return/deletion of data) survive termination.

13. Contact

Caliradi LLC · Data Protection Office
Email: [email protected]
Legal: [email protected]