Data Processing Addendum

1. Roles

The partner or end customer generally acts as controller/business for the purposes and lawful basis of calls. Ring2 generally acts as processor/service provider for data handled on written instructions. Ring2 may act as an independent controller for its own account, security and billing records.

2. Processing instructions

Ring2 processes personal data only to provide the ordered service, secure it, support authorized users, comply with law and follow documented instructions. New purposes require written agreement.

3. Processing details

4. Confidentiality and security

Authorized personnel and subprocessors must be bound by confidentiality. The final security schedule should cover access control, encryption, logging, vulnerability management, backup, recovery, isolation and incident response.

5. Subprocessors

Ring2 will list production hosting, carrier, speech, model, support and other subprocessors before launch, provide the agreed notice mechanism for changes and remain responsible for required contractual protections.

6. Incidents

Ring2 will notify the partner without undue delay after confirming a personal-data breach affecting partner data and provide information reasonably available for legal assessment and response. A specific contractual notification target remains to be approved.

7. Rights and assistance

Taking into account the service, Ring2 will reasonably assist with data-subject requests, security assessments, impact assessments and regulator inquiries as required by contract and law.

8. Return, deletion and audit

At termination or valid instruction, Ring2 will return or delete data subject to agreed backup and legal retention. Audit evidence, questionnaires and on-site rights must be proportionate and defined in the final agreement.

9. Transfers

Cross-border transfer locations and safeguards, including contractual clauses where required, must be documented before production processing.

10. Required schedules