Data Processing Addendum
Last updated: April 2026
This page summarizes the terms under which Calling Bees processes personal data on behalf of its customers. The full executable version of our Data Processing Addendum (DPA) is available on request — contact legal@callingbees.io and we'll send you a countersignable PDF.
Roles
When you use Calling Bees, you are the data controller and Calling Bees is the data processor. We process personal data only on your documented instructions and only as needed to provide the service.
Data we process
- Contact records you upload (name, phone, email, fields)
- Call audio recordings and transcripts
- Call metadata (duration, outcome, timestamps)
- Account and authentication data for your team members
Sub-processors
We use a small set of vetted sub-processors to deliver the service — including telephony providers (Twilio, Telnyx), real-time voice infrastructure (LiveKit), large language model providers (OpenAI, Google, Groq), speech recognition (Deepgram), text-to-speech (ElevenLabs, Cartesia, Rime), and cloud hosting (AWS). The complete current list, with the regions in which each sub-processor operates, is available on request.
International transfers
For customers in the EU, UK, or Switzerland we rely on the Standard Contractual Clauses (and the UK Addendum or Swiss equivalent where applicable) to legitimize transfers of personal data outside those regions.
Security
We maintain technical and organizational measures appropriate to the risk of processing — including encryption in transit and at rest, access controls, and continuous monitoring. See our Security page for the operational details.
Data subject requests
If a data subject contacts Calling Bees directly with a request relating to their personal data, we will redirect them to you and assist you in responding. We honor deletion requests from customers within 30 days.
Contact
Questions or to request the executable DPA, email legal@callingbees.io.