Data Processing Agreement (DPA)
Last updated: July 14, 2026
This Data Processing Agreement ("DPA") is entered into under Art. 28 of Regulation (EU) 2016/679 ("GDPR") and forms an integral part of the Terms and Conditions of Use of the Linia Directă platform. By accepting the Terms and Conditions, the Customer also accepts this DPA.
1. Definitions
- Controller: the Customer, the legal entity or authorised natural person who has contracted the Linia Directă Service and who determines the purposes and means of processing the personal data of data subjects (callers, end customers).
- Processor: Digital Leadership SRL, with registered office at Strada Viorelelor 17A, Dezmir, Cluj County, 407039, Romania, Tax ID 38585123, J2017006715126, which operates the Linia Directă platform (liniadirecta.ro) and processes personal data on behalf of and in accordance with the Controller's instructions.
- Data subjects: the natural persons whose data are processed through the Service: the Controller's callers or end customers.
- Personal data: any information relating to an identified or identifiable natural person, processed through the Service.
- The Service: the Linia Directă platform, including the AI virtual reception assistant, appointment-management features, dashboard, and all related components.
- Sub-processor: any third party engaged by the Processor to carry out processing activities on behalf of the Controller.
- Security breach: a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
2. Subject matter and duration of processing
The Processor processes personal data exclusively for the purpose of providing the Linia Directă Service, in accordance with the Controller's documented instructions.
The processing duration corresponds to the contract term, from the activation of the Controller's account until termination/expiry of the subscription or a request to delete the data. Upon termination, the Processor applies the procedure described in Section 11 (Return and deletion of data).
3. Nature and purpose of processing
Processing is carried out within the following activities:
- AI phone reception: automatic answering of incoming calls on the Controller's dedicated number, transcription, and understanding of conversation content
- Appointment management: creating, modifying, and cancelling appointments based on callers' requests
- Call recording(only if the Controller enables the recording feature): storing audio recordings and transcripts in the Controller's dashboard
- Summary generation: automatic production of call summaries to inform the Controller
- Transfer to human operator: redirecting the call to the Controller's staff at the caller's request or in exceptional situations
- Notifications: sending email notifications to the Controller about new calls, appointments, and daily summaries
4. Types of personal data processed
| Category | Specific data |
|---|---|
| Identification data | The data subject's name (when communicated during the call) |
| Contact data | The caller's phone number |
| Audio data | Audio recordings of phone calls (only if the recording feature is enabled) |
| Text data | Conversation transcripts, automatically generated summaries |
| Appointment data | Date, time, requested service, appointment status |
| Technical data | Call duration, date and time, call ID |
| Potentially sensitive data | Special-category data, to the extent it implicitly appears in call content (e.g.: health information), processed exclusively under Art. 9(2)(h) GDPR |
5. Categories of data subjects
- Callers or end customers of the Controller who call the dedicated number
- Persons who interact with the virtual assistant via the chat widget (if enabled)
6. Processor obligations
6.1 Processing solely on instructions
The Processor processes personal data exclusively on the basis of the Controller's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. If the Processor considers that an instruction infringes GDPR or other applicable data protection legislation, it shall immediately inform the Controller.
6.2 Confidentiality
The Processor ensures that persons authorised to process the personal data have undertaken to respect confidentiality or are subject to an appropriate legal confidentiality obligation. Access to processed data is strictly restricted to personnel who require access to provide the Service ("need to know" principle).
6.3 Security measures
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) for all communications
- Encryption at rest (AES-256) for the database
- Row Level Security (RLS): each Controller accesses only its own data
- Two-factor authentication for internal staff access to systems
- Rate limiting on all public endpoints
- Structured access logs with trace ID
- Automated database backups
- Infrastructure exclusively on servers located in the European Union
- Periodic vulnerability audits (Dependabot + npm audit)
6.4 Assistance with data subject rights
The Processor supports the Controller, through appropriate technical and organisational measures, in fulfilling the obligation to respond to requests regarding the exercise of data subjects' rights: access, rectification, erasure, portability, objection, and restriction of processing. Requests received directly by the Processor regarding the exercise of rights will be forwarded to the Controller within 5 business days.
6.5 Assistance with Controller obligations
Taking into account the nature of processing and the information available, the Processor assists the Controller in ensuring compliance with the obligations laid down in Art. 32-36 GDPR (security, breach notification, impact assessment, prior consultation).
6.6 Auditing
The Controller has the right to conduct audits or inspections regarding the Processor's compliance with this DPA, subject to prior written notice of at least 30 calendar days. Audits are carried out during normal business hours, without disrupting operations. The Controller bears the cost of the audit. Alternatively, the Processor may provide audit reports performed by independent qualified third parties.
7. Sub-processors
The Controller grants the Processor a general authorisation to engage sub-processors. The Processor will inform the Controller of any planned change regarding the addition or replacement of sub-processors, thereby giving the Controller the opportunity to raise reasoned objections within 15 calendar days of notification.
Current list of sub-processors, nature of processing, and geographic location:
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Cloud database provider | Database, authentication, data storage | EU | Art. 44+ GDPR (EU) |
| AI voice platform provider | AI call processing, STT/LLM/TTS orchestration | Frankfurt, EU | Art. 44+ GDPR (EU) |
| Telephony provider | Phone number provisioning, call routing | Dublin, EU (IE1) | Art. 44+ GDPR (EU) |
| Voice synthesis provider | Text-to-speech (TTS): text → voice | EU (processing): US entity | SCCs, Art. 46(2)(c) GDPR |
| Real-time communications infrastructure provider | Real-time audio transport (media routing, no content storage) | US entity | SCCs, Art. 46(2)(c) GDPR |
| Language model provider | Language model (LLM): text understanding and generation | Frankfurt, EU | Art. 44+ GDPR (EU) |
| Speech recognition provider | Speech-to-text (STT): voice → text | EU | Art. 44+ GDPR (EU) |
| Transactional email provider | Sending transactional emails | EU (processing): US entity | SCCs, Art. 46(2)(c) GDPR |
| Payment processor | Payment processing (Controller billing data) | EU | Art. 44+ GDPR (EU) |
| Application hosting provider | Web application hosting | Frankfurt, EU | Art. 44+ GDPR (EU) |
| Rate-limiting provider | Rate limiting | EU | Art. 44+ GDPR (EU) |
| Google Calendar | Appointment sync (optional, activated by the Controller) | EU | Art. 44+ GDPR (EU) |
The Processor imposes equivalent obligations on sub-processors through written contracts. The Processor remains fully responsible to the Controller for the fulfilment of obligations by sub-processors.
8. International data transfers
Personal data processed through the Service is processed on infrastructure located in the European Union / European Economic Area. Where a sub-processor is an entity established outside the EEA (the case for the transactional email provider, the voice synthesis provider and the real-time communications infrastructure provider, US entities), any potential data transfer is covered by the Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46(2)(c) GDPR, together with supplementary measures ensuring an equivalent level of protection.
The AI processing of conversations, meaning speech recognition (STT), language model (LLM) and voice synthesis (TTS), as well as the database, application hosting and telephony run on infrastructure located in the European Union.
If, in the future, the Processor intends to engage a sub-processor located outside the EEA, it will notify the Controller in accordance with Section 7 and implement the appropriate safeguards under Art. 44-49 GDPR before any such transfer.
9. Security breach notification
In the event of a security breach affecting personal data processed on behalf of the Controller, the Processor will notify the Controller without undue delay and, in any case, within a maximum of 72 hours of becoming aware of the breach.
The notification will include, to the extent information is available:
- Description of the nature of the breach, including the categories and approximate number of data subjects and records concerned
- Contact details of the responsible person from whom further information can be obtained
- Likely consequences of the breach
- Measures taken or proposed to address the breach, including, where appropriate, measures to mitigate any adverse effects
Notification is sent to the email address registered in the Controller's account. The Controller remains responsible for notifying the supervisory authority (ANSPDCP) and, where applicable, data subjects, in accordance with Art. 33-34 GDPR.
10. Controller obligations
The Controller undertakes to:
- Provide clear and documented instructions on data processing, including virtual assistant configurations
- Inform data subjects, prior to collecting data, about the processing carried out through the Service, in accordance with Art. 13-14 GDPR, including about the use of an AI virtual assistant and call recording
- Ensure, as Controller, that there is an adequate legal basis for processing data subjects' data
- Periodically verify that the virtual assistant configuration is correct and up to date
- Promptly notify the Processor if it identifies a potential security breach or an incident involving the processed data
- Maintain its own privacy policy that mentions Linia Directă (Digital Leadership SRL) as processor for the processing of caller/end-customer data through the virtual assistant
11. Return and deletion of data
Upon termination of the contract, by any means, the Processor will:
- Allow the Controller to export dashboard data (appointments, call logs, transcripts) within 30 days of the termination date
- Permanently delete all personal data of data subjects processed on behalf of the Controller after the 30-day export period expires
- Deletion also covers backups, within technical rotation cycles, but no later than 90 days from the date of the request
Exception: the Processor may retain data that it is legally required to keep (e.g.: billing data under tax legislation), with prior notice to the Controller.
At the Controller's request, the Processor will issue written confirmation of data deletion.
12. Liability
Each party is responsible for damages caused by non-compliance with its own GDPR obligations, in accordance with Art. 82 of the Regulation.
The Processor is liable to the Controller for direct damages caused by non-compliance with the obligations specifically set out in this DPA or by non-compliance with the Controller's lawful instructions. The Processor's total liability is limited to the amount of the subscription paid by the Controller in the previous 12 months preceding the damage-generating event.
The Processor is not liable for damages caused by the Controller's unlawful or incorrect instructions, by the Controller's failure to comply with its GDPR obligations as Controller, or by circumstances beyond the Processor's reasonable control.
13. Amendments to the DPA
The Processor may amend this DPA to reflect legislative, technical, or operational changes. Changes will be communicated to the Controller at least 30 calendar days before they take effect, by email to the address registered in the account and by updating the page liniadirecta.ro/dpa.
Continued use of the Service after the changes take effect constitutes acceptance of the new DPA. If the Controller does not accept the changes, it may terminate the contract in accordance with the Terms and Conditions.
14. Applicable law
This DPA is governed by Regulation (EU) 2016/679 (GDPR) and by the applicable Romanian legislation on personal data protection. Any dispute arising from the interpretation or performance of this DPA will be settled by the competent courts of Cluj-Napoca, Romania.
15. Contact and DPO
For any questions regarding this DPA or personal data processing:
- Data Protection Officer (DPO): dpo@liniadirecta.ro
- General email: contact@liniadirecta.ro
- Processor: Digital Leadership SRL, Tax ID 38585123, J2017006715126
- Registered office: Strada Viorelelor 17A, Dezmir, Cluj County, 407039, Romania
- Supervisory authority: ANSPDCP: www.dataprotection.ro