Defuse Legal
Data Processing Addendum
Controller-processor terms for Customer Personal Data handled through Defuse.
Effective August 29, 2026 | Version 1.0
1. Parties, scope, and effect
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between CarterPeak LLC d/b/a Defuse ("Defuse") and the customer identified in the Defuse account or applicable order form ("Customer"). It applies to Defuse's Processing of Customer Personal Data on Customer's behalf in providing the Service.
This DPA is effective when Customer accepts the Agreement or begins using the Service, whichever occurs first. If there is a conflict concerning Processing of Customer Personal Data, this DPA controls over the Agreement, except that an expressly negotiated and signed data-processing term controls over this DPA.
2. Definitions
"Applicable Data Protection Law" means a U.S. federal or state law applicable to the Processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act as amended, the New Hampshire Expectation of Privacy Act, and other applicable comprehensive state privacy laws.
"Controller," "Business," "Consumer," "Personal Data," "Personal Information," "Process," "Processor," "Security Incident," "Sell," "Service Provider," "Share," and "Subprocessor" have the meanings assigned by Applicable Data Protection Law. "Customer Personal Data" means Personal Data that Defuse Processes on Customer's behalf through the Service. "Call Data" means caller numbers, audio, transcripts, summaries, call metadata, and related content.
3. Roles and instructions
Customer is the Controller or Business and Defuse is the Processor or Service Provider for Customer Personal Data. Each party is independently responsible for obligations imposed on it by law. The Agreement, this DPA, Customer's permitted account settings, and documented support instructions constitute Customer's instructions to Defuse.
Defuse will Process Customer Personal Data only to provide, secure, maintain, support, and improve the Service; comply with documented lawful instructions; prevent fraud or abuse; and comply with law. Defuse will promptly inform Customer if, in Defuse's reasonable opinion, an instruction violates Applicable Data Protection Law, unless prohibited from doing so.
The details of Processing are in Annex 1. Customer remains responsible for the lawfulness, accuracy, quality, and content of Customer Personal Data and for whether its instructions and use comply with law.
4. Defuse obligations
- Limit access to personnel and providers who need access for the permitted purposes and who are subject to confidentiality obligations.
- Maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of the Processing, as summarized in Annex 2.
- Assist Customer, taking into account the nature of Processing and information available to Defuse, with Consumer requests, security obligations, incident notices, and legally required data-protection assessments.
- On Customer's request or at termination, return or delete Customer Personal Data as described in the Agreement, subject to legal requirements and limited backup, fraud-prevention, or security retention.
- Make information reasonably necessary to demonstrate compliance with this DPA available as described in Section 9.
- Notify Customer if Defuse determines it can no longer meet material obligations applicable to its role and cooperate in reasonable remediation.
5. U.S. service-provider and processor restrictions
To the extent U.S. state privacy law applies, Defuse will not: (a) Sell Customer Personal Data; (b) Share Customer Personal Data for cross-context behavioral advertising; (c) use Customer Personal Data for targeted advertising; (d) retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by law; (e) retain, use, or disclose Customer Personal Data for a purpose other than the limited and specified purposes in the Agreement and this DPA; or (f) combine Customer Personal Data with personal data received from another person or from Defuse's own consumer interactions except as permitted by law.
Defuse will provide the same level of privacy protection required of a Processor or Service Provider by Applicable Data Protection Law. Customer may take reasonable and appropriate steps to help ensure Defuse uses Customer Personal Data consistently with Customer's applicable obligations and, after reasonable notice, may require Defuse to stop and remediate unauthorized use.
6. Consumer and end-caller requests
Customer is primarily responsible for receiving, verifying, and responding to requests from its callers and other Consumers. Defuse will not respond substantively to a request concerning Customer Personal Data without Customer's instruction unless required by law.
If Defuse receives a request relating to Customer Personal Data, Defuse may direct the requester to Customer and will notify Customer where reasonably possible. On Customer's documented request, Defuse will use commercially reasonable measures to help locate, access, correct, export, restrict, or delete relevant data in time for Customer to meet applicable deadlines.
Customer will provide sufficient verified information to identify the applicable call, such as customer account, call date and approximate time, and caller number. Defuse may refuse a request that would compromise security, disclose another person's data, exceed Customer's lawful instructions, or be technically infeasible after reasonable efforts, and will explain the basis to Customer.
7. Security Incidents
Defuse will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include information reasonably available to Defuse about the nature of the incident, affected data, likely consequences, mitigation, and a contact for follow-up. Defuse may provide information in phases and may withhold information when legally required or necessary to preserve security or an investigation.
Defuse's notice is not an admission of fault or liability. Customer is responsible for determining whether notice to Consumers, regulators, or others is required, and Defuse will provide reasonable assistance based on the nature of Processing and information available to it.
8. Subprocessors
Customer grants Defuse general authorization to use the Subprocessors listed in Annex 3. Defuse will require each Subprocessor that Processes Customer Personal Data to provide data-protection obligations materially appropriate to the services it performs. Defuse remains responsible for its obligations under this DPA notwithstanding its use of Subprocessors.
Defuse may add or replace a Subprocessor. Defuse will provide reasonable advance notice of a material new Subprocessor by email, in-product notice, or an updated Subprocessor list. Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate the affected Service, and Customer's exclusive remedy is a prorated refund of prepaid unused fees for that affected Service, if any.
9. Assessments and information
No more than once annually, Customer may request information reasonably necessary to demonstrate Defuse's compliance with this DPA. Defuse may respond through security documentation, policies, questionnaires, third-party reports, certifications, or summaries. Customer must protect non-public materials as Defuse Confidential Information.
If Applicable Data Protection Law requires an additional assessment and available materials are insufficient, Customer may request a reasonable assessment by an independent qualified assessor, subject to confidentiality, security, scope, timing, and cost arrangements designed to avoid unreasonable disruption. Defuse may satisfy an assessment request by providing a relevant independent report where legally permitted.
10. Customer obligations
- Provide all notices, obtain all consents, and maintain all lawful bases required for collection, recording, transcription, disclosure, transfer, and Processing of Customer Personal Data.
- Issue only lawful instructions and use the Service consistently with the Agreement, Acceptable Use Policy, Customer's own privacy notices, and Applicable Data Protection Law.
- Avoid submitting prohibited regulated data and take reasonable steps to minimize unrequested sensitive information during calls.
- Implement reasonable security for Customer systems, accounts, exports, recipients, and credentials.
- Respond to Consumers and regulators and notify Defuse promptly when assistance is needed.
Customer acknowledges that Defuse cannot determine a caller's location or which law applies to a particular call. Customer is responsible for its transfer procedure and any pre-transfer notice or consent required by law.
11. Return, deletion, and termination
During the subscription, Customer may use available controls to delete individual calls and select a retention period. After cancellation, Defuse will make call data available for export for 30 days and then delete Customer Personal Data from active systems, subject to limited legal, security, fraud-prevention, and backup retention.
Defuse will not actively Process retained backup data except for security, disaster recovery, or legal compliance and will delete or overwrite it according to ordinary schedules. Sections that by their nature should survive, including restrictions on retained data, confidentiality, and liability allocation, will survive.
12. International data
The Service is offered for U.S. business use and is not designed for Customer Personal Data subject to the laws of the European Economic Area, United Kingdom, Canada, or other non-U.S. jurisdictions. Customer will not intentionally use the Service for such data without Defuse's prior written agreement. If an international transfer mechanism becomes legally required, the parties will cooperate in good faith to execute appropriate terms before the Processing begins.
13. Liability and general terms
The liability limitations, exclusions, indemnities, governing law, venue, and other general provisions in the Agreement apply to this DPA. This DPA terminates with the Agreement except for obligations concerning retained Customer Personal Data.
Annex 1 - Details of Processing
| Item | Processing details |
|---|---|
| Subject matter | AI-assisted handling and documentation of customer-service calls transferred by Customer. |
| Duration | The subscription term, the customer-selected call-retention period, the 30-day post-cancellation export period, and limited periods required for deletion, backups, security, or law. |
| Nature and purpose | Receive calls; process voice; record and transcribe; generate summaries; display authenticated call records; send dashboard notifications; support, secure, troubleshoot, meter, and delete the Service. |
| Data subjects | Customer personnel, authorized users, notification recipients, and end-callers who are customers or contacts of Customer. |
| Personal Data | Business contact and account data; caller number; audio; transcript; issue and sentiment descriptions; resolution, outcome, and follow-up fields; timestamps; duration; configuration; device, access, and security logs. |
| Sensitive data | Not intended. Unstructured call content may incidentally include sensitive data. Prohibited regulated categories are restricted by the Agreement and AUP. |
| Frequency | Continuous, depending on Customer's configuration and transferred call volume. |
| Customer instructions | The Agreement, DPA, account configuration, selected retention, deletion actions, and documented support requests. |
Annex 2 - Technical and organizational measures
| Control area | Measures |
|---|---|
| Access control | Authenticated customer access; Supabase row-level security; tenant-scoped authorization; least-privilege support access; access limited to personnel with a need to know. |
| Transmission and storage | TLS for data in transit; provider encryption at rest where supported; payment-card data handled by Stripe; no routine direct audio playback in the customer dashboard. |
| Application security | Environment and secret management; input validation; dependency and platform updates; logging and monitoring appropriate to a cloud SaaS product. |
| Availability and recovery | Use of established cloud providers, provider recovery capabilities, monitoring, and operational response procedures. No contractual service-level commitment unless stated in an order form. |
| Data minimization | Detailed call content kept behind authenticated access; customer-selectable notification detail, so a Customer may choose that transactional emails contain only a link to the dashboard rather than call content; customer-selectable retention with a 90-day default; single-call deletion. |
| Personnel and support | Confidentiality obligations; access for support or incident investigation only when reasonably necessary; no routine review of customer call content. |
| Incident response | Investigation, containment, remediation, documentation, and Customer notice without undue delay after confirmation of a Security Incident. |
| Vendor management | Use of established providers; contractual data-protection terms where applicable; Subprocessor list and change process. |
Annex 3 - Subprocessors
| Provider | Purpose and data | Location |
|---|---|---|
| Vercel | Application hosting and traffic; may process account, application, and call-related request data. | United States |
| Supabase | Database and authentication; account data, configuration, transcripts, summaries, caller numbers, call metadata, and access data. | United States; configured in AWS us-east-1 |
| Retell AI | Voice agent, telephony coordination, call audio, recording, transcription, caller number, and call metadata. May use underlying telecommunications providers including Twilio. | United States |
| OpenAI | Business/API processing of call transcripts to generate structured summaries. | United States |
| Resend | Transactional email delivery; notification recipient addresses and notification content, which by default includes the call summary and may be reduced by the Customer to a link to the authenticated dashboard. | United States |
Questions about this DPA or the Subprocessor list may be sent to support@usedefuse.com.
© 2026 CarterPeak LLC d/b/a Defuse · 221 Main Street, Suite N, Nashua, NH 03060 · support@usedefuse.com