← Back to home

Data Processing Annex

Processing of personal data on behalf of our business customers — Article 28 GDPR

Last updated: 29 July 2026

This annex supplements our Terms and Conditions and constitutes a data processing agreement within the meaning of Article 28 GDPR. It applies to every business customer using Léa Répond. No formality is required to benefit from it: it is binding from subscription onwards.

1. Purpose and roles of the parties

This annex governs the processing of personal data carried out by JLAIEL STUDIO AI ("the Provider") on behalf of its customer ("the Customer") as part of the Léa Répond service.

The Customer is the controller of the data of people who call their line: those callers are their own prospects, clients or patients, and it is the Customer who determines the purpose of the call and the instructions given to the agent.

The Provider is the processor: it processes such data only on the Customer's instructions, solely for the purposes set out in Article 2, and never for its own purposes.

The Provider remains the controller of the Customer's own data (subscriber identity, account, billing), which is governed by the Privacy Policy.

2. Description of the processing

  • Nature: answering inbound calls, speech transcription, generation of spoken replies, drafting a call summary, sending notifications to the Customer, and where applicable booking appointments and transferring calls.
  • Purpose: handling the Customer's inbound calls, in their absence or alongside their own reception.
  • Categories of data: caller's phone number; first and last name where provided; content of the conversation (transcript and summary); date, time and duration of the call; reason for the call; call-back details and appointment details where provided.
  • Categories of data subjects: any person calling the Customer's line.
  • Duration: the term of the subscription, with automatic deletion of call data after 12 months.

3. The Customer's instructions

The Provider processes the data only on the Customer's documented instructions. The configuration carried out by the Customer in their dashboard — agent instructions, greeting, information to collect, caller categories, enabling appointments and call transfer — constitutes those instructions.

In accordance with the final paragraph of Article 28(3) GDPR, the Provider informs the Customer if, in its opinion, an instruction infringes the Regulation, and may decline to carry it out.

4. Confidentiality and personnel

Persons authorised to access the data are bound by a duty of confidentiality. Access to production data is limited to what is strictly necessary to operate and support the service.

The Provider does not use any customer call data to train an artificial intelligence model.

5. Security (Article 32 GDPR)

  • Database encryption of phone numbers, summaries and transcripts (AES-256-GCM).
  • Hosting in France (OVH); database and mail server self-hosted on the Provider's own servers.
  • Encryption of data in transit (TLS) and of telephony secrets at rest.
  • Per-account isolation: each Customer can access only their own calls.
  • Automated daily database backups.
  • A daily purge automatically enforcing the published retention periods.

6. Sub-processors

The Customer authorises the Provider to use the sub-processors listed in section 5 of the Privacy Policy, which states each one's role and location.

The Provider will inform the Customer of any addition or replacement of a sub-processor with 30 days' notice. During that period the Customer may object in writing; failing agreement, the Customer may terminate without charge or penalty.

The Provider imposes on its sub-processors data protection obligations equivalent to those in this annex and remains responsible for their performance.

7. Transfers outside the European Union

By default the active stack is entirely French: call content is transcribed, processed and synthesised by Mistral AI in France, on French OVH infrastructure. In that configuration, call content does not leave the European Union.

Where the Customer enables a non-European model or stack, or in the event of a technical fallback, the corresponding transfers are governed by the Standard Contractual Clauses approved by the European Commission (Article 46.2.c GDPR). The Customer is informed of this in the dashboard at the point of choice.

8. Assistance provided to the Customer

The Provider will, to a reasonable extent, assist the Customer in:

  • responding to callers' requests to exercise their rights (access, rectification, erasure, objection);
  • documenting the security measures implemented;
  • carrying out a data protection impact assessment where one is required.

An erasure request concerning an identified caller is carried out within 30 days of being passed on by the Customer.

9. Personal data breach

The Provider will notify the Customer without undue delay, and no later than 48 hours after becoming aware of it, of any personal data breach affecting data processed on the Customer's behalf. The notification will state the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken.

This enables the Customer, as controller, to make its own notification to the supervisory authority within the 72-hour period set out in Article 33 GDPR.

10. Data at the end of the contract

On expiry or termination of the contract, the Provider will delete the Customer's call data within 30 days, unless a written request for return is made before that date, or a legal retention obligation applies.

Billing data is retained for 10 years under statutory accounting obligations.

11. Documentation and audit

The Provider will make available to the Customer, on written request, the documentation needed to demonstrate compliance with Article 28 GDPR.

It will submit to reasonable audits by the Customer or an auditor appointed by them, limited to one audit per calendar year, subject to 30 days' notice and the signing of a confidentiality undertaking.

12. The Customer's obligations

The Customer warrants that they:

  • have a legal basis for the processing of the calls entrusted to the Provider;
  • inform their own callers about the processing of their data, in accordance with Article 13 GDPR (a statement in their privacy policy, information at the point of contact, or any other appropriate means);
  • will not configure the agent to collect special category data within the meaning of Article 9 GDPR, in particular health data: the service is not hosted on infrastructure certified for French health data hosting (HDS). A healthcare professional may use the service to book appointments and route calls, provided the agent is not made to collect medical reasons for the call;
  • handle, as controller, the requests to exercise rights addressed to them, with the assistance set out in Article 8.

13. Disclosure that the agent is artificial (AI Act)

The Provider is the provider of an artificial intelligence system within the meaning of Regulation (EU) 2024/1689. Pursuant to its Article 50, every call opens by informing the caller that they are speaking to a virtual assistant.

This disclosure is applied by the system and cannot be removed by the Customer: it is an obligation borne by the Provider as provider of the system, not a service setting.

The Customer shall not use any configuration or instruction intended to lead callers to believe they are speaking to a human being.

14. Term, order of precedence and contact

This annex applies for the whole term of the contract and for as long as the Provider processes data on behalf of the Customer.

In the event of any conflict with the Terms and Conditions, this annex prevails in all matters relating to the protection of personal data.

Contact for any question relating to data: contact@jlaielstudio.ai.