Legal

Data Processing Agreement

The client is the controller; AthonBound processes on their instructions. This is where that split is written down.

Smartbound – Athon L.L.C-FZ, Dubai, UAE

  1. 1. Who is who

    This agreement applies whenever AthonBound (Smartbound – Athon L.L.C-FZ, Dubai) processes personal data on behalf of a client, and forms part of the terms of service.

    The client is the data controller. AthonBound is the processor. The client decides which people are contacted, on what legal basis, and what the assistant is allowed to say. We process on documented instructions and for no other purpose.

    For AthonBound’s own website, marketing and account administration, AthonBound is the controller; that processing is not covered here.

  2. 2. What is processed, for whom, and for how long

    Subject matter and purpose: providing the outbound and market-intelligence services, AthonBound Studio, the Client Portal and the voice assistant.

    Data subjects:the client’s prospects, clients and contacts, and the client’s own users of the platform.

    Categories of data: identification and contact details (name, company, role, telephone number, email address); engagement history; call metadata (time, duration, outcome, number); call transcripts and, where the client has enabled it, call recordings; content the client writes into the knowledge base.

    Special categories are not requested and must not be supplied. The service is not designed for them.

    Duration: for as long as the contract is in force, plus the retention periods below.

  3. 3. Our instructions come from you

    We process only on the client’s documented instructions, including the configuration made in the platform, and for the purposes above. If we believe an instruction breaches data protection law we will say so before acting on it. We do not use the client’s data for our own purposes, and we do not use it to train models.

  4. 4. Confidentiality

    Everyone we authorise to process the data is bound by confidentiality and has access only to what their work requires. Access is removable for one person without affecting the rest of the team.

  5. 5. Security

    We take appropriate technical and organisational measures: encryption in transit, encryption at rest for credentials, hashed passwords and access codes, per-tenant isolation enforced in the database query, role-based access and revocation, and secrets kept out of the database. The current measures are described on our security page, which forms Annex 2.

  6. 6. Sub-processors

    The client gives general authorisation for AthonBound to engage sub-processors: among them providers of hosting, telephony, speech recognition, speech synthesis, language models, calendars and email delivery.

    The current list, with each provider’s role, location and transfer basis, is given to every client as Annex 3 and is available on request at any time. We impose on each sub-processor the same obligations set out here.

    We remain fully liable to the client for their performance.We give at least 30 days’ notice before adding or replacing one, and the client may object on reasonable data-protection grounds; if the objection cannot be resolved, either party may terminate the affected service.

  7. 7. Helping you answer your obligations

    Requests from individuals.If someone contacts us directly about data we process for a client, we do not answer on the client’s behalf: we pass the request on without undue delay and help them respond, including by locating, exporting or deleting the data.

    A request not to be contacted is different and is acted on immediately, including during a call, because acting later would mean calling that person again in the meantime.

    We also assist, taking into account what we know and the means at our disposal, with impact assessments, prior consultation and the client’s own security obligations.

  8. 8. If there is a breach

    If we become aware of a personal data breach affecting the client’s data we notify the client without undue delay and in any case within 48 hours, with what we know at that moment rather than waiting for a complete picture, and we keep them informed as we learn more. We do not notify the supervisory authority or the individuals on the client’s behalf: that is the controller’s decision.

  9. 9. Retention, deletion and return

    Call transcripts and recordings are kept for 90 days and then deleted, unless a longer period is agreed in writing or required by law. Discarded lead data is stripped after 30 days.

    Records of requests not to be contacted are kept indefinitely, by necessity: they exist to prevent a future call, and deleting one would defeat its only purpose. They are kept in a form that holds the number and the request, and nothing more than is needed for that.

    At the end of the contract we delete or return the client’s personal data at their choice, within 30 days, except what we are required to keep by law and the opt-out records above.

  10. 10. Information and audit

    We make available the information needed to demonstrate compliance with this agreement and answer security questionnaires. The client may audit, at its own cost, no more than once a year and on 30 days’ notice, or more often if required by a supervisory authority or after a breach. Where an audit would affect other clients’ data, we provide the information in a way that does not.

  11. 11. International transfers

    Some processing takes place outside the European Economic Area, including in the United States and the United Arab Emirates. Those transfers are covered by Standard Contractual Clauses or another mechanism recognised under Chapter V of the GDPR, with supplementary measures where required. The location of each sub-processor is stated in Annex 3.

  12. 12. What the client warrants

    The client warrants that it has a lawful basis for every person whose data it puts into the services, that it has provided them with the information the law requires, and that any consent it relies on was validly obtained.

    Where the services place calls, the client further warrants that the consent it holds covers calls made with an artificial or AI-generated voice, and that it screens its lists against the applicable do-not-call registers before a campaign and at least every 31 days while it runs. The full obligations are in section 5 of the terms of service.

  13. 13. Liability, precedence and law

    The limitation of liability in the terms of service applies to this agreement, except where the law does not allow it.

    Where this agreement and the terms of service conflict on the processing of personal data, this agreement prevails. It is governed by the same law and forum as the terms of service, without prejudice to the mandatory rules of the client’s own jurisdiction.

  14. 14. Annexes and contact

    Annex 1: details of the processing: sections 2 and 3 above. Annex 2: security measures: our security page. Annex 3: sub-processors: given to each client and available on request.

    To request Annex 3, or a signed copy of this agreement, write to us from the contact page.

    Last updated: 14 September 2026.