GrayWorks
Start Setup

Legal · Updated July 17, 2026

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Gray-Works Technologies & Solutions LLC (“GrayWorks”, the “Processor”) and the subscribing customer (the “Customer”, the “Controller”) and governs GrayWorks' processing of personal data on the Customer's behalf.

1. Definitions

“Personal Data” means information relating to an identified or identifiable person that GrayWorks processes on the Customer's behalf — chiefly caller voice recordings, transcripts, phone numbers, messages, and booking details. “Processing,” “Controller,” and “Processor” have the meanings given by applicable data protection laws, including the CCPA and comparable state laws.

2. Term

This DPA applies for as long as GrayWorks processes Personal Data on the Customer's behalf under the Terms of Service.

3. Processing of Personal Data

The Customer is the Controller of caller and end-user Personal Data; GrayWorks is its Processor. GrayWorks processes Personal Data only to provide the Service as configured by the Customer and as documented in the Terms and this DPA, not for its own marketing purposes, and does not sell Personal Data.

4. Personnel

GrayWorks limits access to Personal Data to personnel who need it to operate the Service and binds them to confidentiality obligations.

5. Subprocessors

The Customer authorizes these subprocessors: Retell AI (voice AI and telephony), Stripe (payments), Twilio SendGrid (transactional email), Cal.com (scheduling, when connected), and GrayWorks' cloud infrastructure provider. GrayWorks binds each subprocessor to data protection obligations no less protective than this DPA, will give Customers at least 10 days' email notice before adding or replacing a subprocessor, and remains responsible for its subprocessors' performance. A Customer that objects on reasonable data-protection grounds may cancel under the Terms before the change takes effect.

6. Security

GrayWorks maintains technical and organizational measures appropriate to the risk, including encryption of data in transit, tenant-scoped data isolation, restricted production access, and secrets management.

7. Cross-Border Transfers

The Service is operated from the United States, and Personal Data is processed there. Customers subject to transfer-restriction laws should not use the Service for that data without contacting us first at support@grayworks.services.

8. Data Subject Requests

GrayWorks will promptly forward to the Customer any request it receives from a caller or end user about their Personal Data, and will reasonably assist the Customer in responding, given the nature of the processing.

9. Security Incidents

GrayWorks will notify affected Customers by email without undue delay, and in any event within 72 hours of confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Data, and will provide information reasonably needed for the Customer's own notifications.

10. Assessments

GrayWorks will provide reasonable cooperation with data protection impact assessments the Customer is legally required to perform concerning the Service.

11. Return or Deletion

On account closure, GrayWorks deletes or de-identifies Personal Data within a commercially reasonable period, except where the law requires retention. Before closure, Customers may export transcripts and business data from the dashboard or request an export at support@grayworks.services.

12. Audit and Compliance Information

On written request, no more than once per year, GrayWorks will provide information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and subprocessor list.

13. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.

14. Governing Law

This DPA is governed by the laws of the District of Columbia, consistent with the Terms of Service.

15. Severability and Order of Precedence

If any provision of this DPA is unenforceable, the remainder stays in effect. If this DPA conflicts with the Terms of Service regarding the processing of Personal Data, this DPA controls.