Data Processing Agreement (DPA)
Effective date: July 17, 2026 Last updated: July 17, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between TrueHuman LLC, 5830 E 2nd St, Ste 7000 #30633, Casper, WY 82609, USA ("TrueHuman", the "Processor") and the Customer ("Controller"). It applies whenever TrueHuman processes personal data contained in Customer Content on Customer's behalf in connection with the services at app.mytruehuman.com and dashboard.mytruehuman.com (the "Services").
"GDPR", "personal data", "processing", "data subject", "supervisory authority", and similar terms have the meanings given in Regulation (EU) 2016/679 and, where applicable, UK GDPR and equivalent laws ("Data Protection Laws").
1. Roles and scope
Customer is the controller (or a processor acting on behalf of another controller) of personal data in Customer Content; TrueHuman is its processor. For account, billing, and usage data, TrueHuman acts as an independent controller as described in its Privacy Policy, and that processing is outside the scope of this DPA.
2. Processing instructions
TrueHuman will process Customer Content only on Customer's documented instructions, including these: the Terms, this DPA, Customer's use and configuration of the Services (e.g., connecting a CRM, connecting an email account, enabling enrichment or lead discovery, uploading recordings), and any further written instructions agreed by the parties. TrueHuman will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, or if it is required by law to process otherwise (unless legally prohibited from informing).
3. Confidentiality
TrueHuman ensures that persons authorized to process Customer Content are bound by confidentiality obligations and process it only as needed to provide the Services.
4. Security
TrueHuman implements appropriate technical and organizational measures as described in Annex 2, taking into account the state of the art, costs, and the nature and risks of processing. TrueHuman may update these measures provided the overall level of protection is not reduced.
5. Subprocessors
Customer grants TrueHuman general written authorization to engage the subprocessors listed at Subprocessors. TrueHuman will: (a) impose data protection obligations on subprocessors materially equivalent to this DPA; (b) remain liable for their performance; and (c) give Customer at least 14 days' notice of new subprocessors (via the subprocessors page or email). Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.
6. Data subject requests
Taking into account the nature of processing, TrueHuman will assist Customer with appropriate technical and organizational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts TrueHuman directly about Customer Content, TrueHuman will refer the request to Customer without undue delay and will not respond except as required by law.
7. Assistance
TrueHuman will reasonably assist Customer with security, breach notification, data protection impact assessments, and consultations with supervisory authorities under Articles 32–36 GDPR, taking into account the information available to TrueHuman.
8. Personal data breach
TrueHuman will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and in any case in time to enable Customer to meet its 72-hour notification duty. The notification will describe, to the extent known, the nature of the breach, affected categories and approximate numbers, likely consequences, and measures taken or proposed.
9. Deletion and return
During the subscription, Customer can export Customer Content through the Services. Upon termination, TrueHuman will make Customer Content available for export for 30 days, then delete it within 60 days, except for copies it must retain by law and residual copies in backups, which are deleted on the backup rotation cycle and remain protected under this DPA until deleted.
10. Audits
TrueHuman will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits and certifications of its infrastructure providers. Where this is insufficient, Customer may conduct (at most annually, on 30 days' notice, at its own cost, under confidentiality, without disruption) an audit limited to TrueHuman's processing of Customer Content; TrueHuman may charge reasonable costs for extensive assistance.
11. International transfers
Customer Content is primarily hosted in the United States; certain realtime message-delivery infrastructure (Ably) is located in the United Kingdom. To the extent transfers of EEA/UK/Swiss personal data to TrueHuman or its subprocessors require a transfer mechanism, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller-to-processor) — or Module Three where Customer is itself a processor — with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 14 days); Clause 17 governed by Irish law; Clause 18 courts of Ireland; Annexes completed with the information in this DPA and the Subprocessors page. For UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the SCCs adapted as required by the FDPIC. Where a subprocessor is certified under the EU-U.S. Data Privacy Framework, that certification may serve as the transfer mechanism for that subprocessor.
12. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws do not permit such limitation. If there is a conflict, this DPA prevails over the Terms with respect to processing of personal data, and the SCCs prevail over this DPA.
Annex 1 — Details of processing
Subject matter and duration. Processing of Customer Content to provide the Services, for the duration of the subscription plus the export/deletion period in Section 9.
Nature and purpose. Hosting and storage; CRM synchronization; contact and deal management; AI-assisted analysis, chat, and message generation; connecting and recording in-app phone calls through a telephony provider; transcription and analysis of uploaded and in-app call recordings; contact enrichment and lead discovery/prospecting from third-party and public sources; sending outreach and follow-up emails from a User's connected email account (via Microsoft's Mail.ReadWrite permission) and reading inbox message headers and the content of replies and delivery-failure notices on conversations started through the Services; mirroring sent-email content into a connected CRM as notes; reporting and coaching insights; technical support.
Call recording retention. For each in-app call, the Controller's User selects whether to retain the audio recording. If retention is not selected, the audio is sent to the transcription subprocessor (AssemblyAI) to produce the transcript and then promptly deleted (best-effort) from TrueHuman's storage and from the telephony subprocessor; if selected, the audio is retained until the User deletes it. Transcripts and analyses are retained as Customer Content under Section 9.
Categories of data subjects. Customer's Users (sales representatives, managers); Customer's prospects, leads, customers, and other business contacts; individuals surfaced by lead-discovery/prospecting features who are not yet in Customer's CRM; participants in recorded calls.
Categories of personal data. Identification and contact data (names, business emails, phone numbers, job titles, employers, LinkedIn URLs); commercial data (deals, pipeline stages, notes, interactions); communications (chat content, generated messages, files; email content and metadata of tracked conversations — message and conversation identifiers, recipients, subjects, timestamps, delivery status); voice recordings and transcripts; derived data (scores, analyses, insights); CRM identifiers and connection metadata.
Special categories. None intended. Customer agrees not to submit special-category data (Art. 9 GDPR) or data of children; voice recordings are processed for transcription/analysis only and not for biometric identification.
Frequency. Continuous, as driven by Customer's use.
Annex 2 — Technical and organizational measures
- Encryption. TLS 1.2+ in transit; AES-256 encryption at rest for databases, file storage, and backups; application-level encryption for stored credentials (e.g., CRM OAuth tokens) and pre-registration secrets.
- Access control. Authentication via a managed identity provider (Okta/Auth0) with MFA support; role-based access; per-tenant data scoping enforced in the application layer (with row-level security as a backstop); least-privilege access for personnel, with privileged internal support/debugging tools restricted to authorized staff and subject to access logging; segregated production credentials.
- Infrastructure. Hosted on SOC 2 / ISO 27001-certified cloud providers (see Subprocessors); network controls, hardened HTTP security headers, rate limiting, webhook signature verification for payment events.
- Monitoring. Centralized logging, error monitoring, and alerting; audit trails for billing and credit events; idempotent processing of payment webhooks.
- Resilience. Automated backups with rotation; point-in-time recovery for the primary database; documented incident response.
- Organizational. Confidentiality undertakings for personnel; vendor due diligence and DPAs with all subprocessors; periodic review of security measures and access rights.
Annex 3 — Authorized subprocessors
See the current list at Subprocessors, incorporated by reference.