Processing of personal data on behalf of our business customers — Article 28 GDPR
Last updated: 29 July 2026
This annex supplements our Terms and Conditions and constitutes a data processing agreement within the meaning of Article 28 GDPR. It applies to every business customer using Léa Répond. No formality is required to benefit from it: it is binding from subscription onwards.
This annex governs the processing of personal data carried out by JLAIEL STUDIO AI ("the Provider") on behalf of its customer ("the Customer") as part of the Léa Répond service.
The Customer is the controller of the data of people who call their line: those callers are their own prospects, clients or patients, and it is the Customer who determines the purpose of the call and the instructions given to the agent.
The Provider is the processor: it processes such data only on the Customer's instructions, solely for the purposes set out in Article 2, and never for its own purposes.
The Provider remains the controller of the Customer's own data (subscriber identity, account, billing), which is governed by the Privacy Policy.
The Provider processes the data only on the Customer's documented instructions. The configuration carried out by the Customer in their dashboard — agent instructions, greeting, information to collect, caller categories, enabling appointments and call transfer — constitutes those instructions.
In accordance with the final paragraph of Article 28(3) GDPR, the Provider informs the Customer if, in its opinion, an instruction infringes the Regulation, and may decline to carry it out.
Persons authorised to access the data are bound by a duty of confidentiality. Access to production data is limited to what is strictly necessary to operate and support the service.
The Provider does not use any customer call data to train an artificial intelligence model.
The Customer authorises the Provider to use the sub-processors listed in section 5 of the Privacy Policy, which states each one's role and location.
The Provider will inform the Customer of any addition or replacement of a sub-processor with 30 days' notice. During that period the Customer may object in writing; failing agreement, the Customer may terminate without charge or penalty.
The Provider imposes on its sub-processors data protection obligations equivalent to those in this annex and remains responsible for their performance.
By default the active stack is entirely French: call content is transcribed, processed and synthesised by Mistral AI in France, on French OVH infrastructure. In that configuration, call content does not leave the European Union.
Where the Customer enables a non-European model or stack, or in the event of a technical fallback, the corresponding transfers are governed by the Standard Contractual Clauses approved by the European Commission (Article 46.2.c GDPR). The Customer is informed of this in the dashboard at the point of choice.
The Provider will, to a reasonable extent, assist the Customer in:
An erasure request concerning an identified caller is carried out within 30 days of being passed on by the Customer.
The Provider will notify the Customer without undue delay, and no later than 48 hours after becoming aware of it, of any personal data breach affecting data processed on the Customer's behalf. The notification will state the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken.
This enables the Customer, as controller, to make its own notification to the supervisory authority within the 72-hour period set out in Article 33 GDPR.
On expiry or termination of the contract, the Provider will delete the Customer's call data within 30 days, unless a written request for return is made before that date, or a legal retention obligation applies.
Billing data is retained for 10 years under statutory accounting obligations.
The Provider will make available to the Customer, on written request, the documentation needed to demonstrate compliance with Article 28 GDPR.
It will submit to reasonable audits by the Customer or an auditor appointed by them, limited to one audit per calendar year, subject to 30 days' notice and the signing of a confidentiality undertaking.
The Customer warrants that they:
The Provider is the provider of an artificial intelligence system within the meaning of Regulation (EU) 2024/1689. Pursuant to its Article 50, every call opens by informing the caller that they are speaking to a virtual assistant.
This disclosure is applied by the system and cannot be removed by the Customer: it is an obligation borne by the Provider as provider of the system, not a service setting.
The Customer shall not use any configuration or instruction intended to lead callers to believe they are speaking to a human being.
This annex applies for the whole term of the contract and for as long as the Provider processes data on behalf of the Customer.
In the event of any conflict with the Terms and Conditions, this annex prevails in all matters relating to the protection of personal data.
Contact for any question relating to data: contact@jlaielstudio.ai.