On this page
This Data Processing Addendum (“DPA”) forms part of the tealsi Terms of Service or other written agreement between Constellation X, LLC and Customer governing Customer’s use of tealsi. It applies when tealsi processes Personal Data on behalf of Customer in connection with the Platform.
THIS DPA ALLOCATES DATA-PROTECTION RESPONSIBILITIES BETWEEN CUSTOMER AND TEALSI. CUSTOMER REMAINS RESPONSIBLE FOR THE LAWFULNESS OF ITS DATA, ITS INSTRUCTIONS, ITS COMMUNICATIONS, AND ITS RELATIONSHIP WITH ITS OWN CONTACTS, CLIENTS AND END USERS.
1. Scope and Incorporation
This DPA governs the Processing of Personal Data by Constellation X, LLC, through its tealsi software platform (“tealsi,” “Company,” “we,” “us,” or “our”), on behalf of a Customer in connection with the Services.
This DPA is incorporated into and forms part of the applicable tealsi Terms of Service, Order Form, subscription agreement, master services agreement, or other written agreement between Customer and Constellation X, LLC (collectively, the “Agreement”). Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
If there is a conflict between this DPA and the Agreement regarding Processing of Personal Data on Customer’s behalf, this DPA controls to the extent of that conflict.
2. Definitions
For purposes of this DPA:
- “Applicable Data Protection Law” means privacy, data protection and data security laws applicable to the Processing covered by this DPA.
- “Controller” includes a “business” or equivalent entity that determines the purposes and means of Processing Personal Data.
- “Customer Data” means data, content, records, contacts, messages, files, prompts, call data, recordings, transcripts, credentials, configuration information and other information submitted to, connected to, generated through or otherwise Processed within Customer’s tenant, excluding data for which tealsi independently determines the purposes and means of Processing.
- “Personal Data” means information relating to an identified or identifiable individual, or equivalent term under Applicable Data Protection Law.
- “Process” or “Processing” means any operation performed on Personal Data, including collection, access, storage, use, transmission, disclosure, deletion or destruction.
- “Processor” includes a “service provider,” “contractor” or equivalent entity that Processes Personal Data on behalf of a Controller.
- “Security Incident” means unauthorized access to, acquisition of, disclosure of, alteration of, loss of or destruction of Customer Personal Data in tealsi’s control that constitutes a reportable personal data breach under Applicable Data Protection Law. Unsuccessful attempts that do not compromise Customer Personal Data are not Security Incidents.
- “Subprocessor” means a third party engaged by tealsi to Process Customer Personal Data on tealsi’s behalf in providing the Services.
3. Roles of the Parties
For Customer Data Processed through the Platform on Customer’s behalf, Customer is generally the Controller and tealsi is generally the Processor. If Customer itself acts as a Processor for another Controller, tealsi acts as Customer’s Subprocessor for the relevant Processing.
Customer determines the purposes for which it uses the Platform, the categories of individuals it contacts or stores, the content it uploads, the communications it initiates, the automations and AI agents it configures, and the third-party services it connects.
Nothing in this DPA prevents tealsi from Processing information as an independent Controller where tealsi independently determines the purposes and means of such Processing, including for account administration, billing, fraud prevention, security, legal compliance and certain product analytics as described in the Privacy Policy.
4. Customer Instructions
Customer instructs tealsi to Process Customer Personal Data as reasonably necessary to provide, secure, support and maintain the Services, to enable features selected or configured by Customer, to perform Customer-requested support, and as otherwise documented in the Agreement or Customer’s lawful use of the Platform.
Customer’s configuration and use of the Platform, including connecting third-party accounts, configuring automations, initiating communications, enabling AI or voice features, importing contacts, creating workflows and enabling integrations, constitute documented instructions to tealsi.
tealsi will not Process Customer Personal Data for materially different purposes except as required by applicable law, necessary to protect the Platform or users, necessary to investigate abuse or security threats, or otherwise permitted by the Agreement and Applicable Data Protection Law.
5. Customer Responsibilities
Customer is responsible for the lawfulness, fairness and transparency of its Processing and instructions. Without limiting the Agreement, Customer represents and warrants that it:
- has a valid legal basis for collecting, using, disclosing and otherwise Processing Customer Personal Data;
- has provided all notices and obtained all permissions and consents required by law;
- will not instruct tealsi to Process Personal Data in violation of applicable law;
- is responsible for responding to its own customers, contacts, clients, employees and End Users concerning Customer’s privacy practices;
- is responsible for the legality of communications, call recordings, AI interactions, contact lists, uploaded content, imported data and connected services;
- will use reasonable access controls and protect account credentials; and
- will promptly notify tealsi if Customer believes an instruction would violate Applicable Data Protection Law.
6. Confidentiality and Personnel
tealsi will take reasonable steps to ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary for their role.
Personnel access to Customer tenants is restricted according to operational need, permissions and applicable internal controls. Routine support access is not intended to be unrestricted or discretionary.
7. Security Measures
Taking into account the nature of the Processing, the state of the art, implementation costs and risks presented by the Processing, tealsi will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss or destruction.
Such measures may include, as appropriate, authentication controls, access restrictions, rate limiting, progressive account lockouts, logging, monitoring, network protections, encrypted transport, infrastructure controls, backup practices, least-privilege principles, incident-response processes and vendor-management practices.
Customer acknowledges that no software, cloud environment, telecommunications network, internet connection, AI system or security control can be guaranteed to be completely secure or error-free.
8. Administrative and Support Access
tealsi personnel generally will not access a Customer tenant through administrative support access for ordinary support purposes without Customer authorization.
Notwithstanding the foregoing, tealsi may access systems, logs, tenant information or Customer Data to the limited extent reasonably necessary to investigate or respond to a Security Incident, fraud, abuse, suspected unlawful activity, a threat to the Platform or other users, essential infrastructure operations, system restoration, preservation of evidence, or valid legal process.
Any such access is subject to applicable confidentiality, security and access-control requirements.
9. Subprocessors
Customer provides general authorization for tealsi to engage Subprocessors to support the Services. Subprocessors may provide hosting, telecommunications, AI, voice, infrastructure, security, support or other functionality.
tealsi will maintain a public Subprocessors notice identifying material Subprocessors where appropriate. tealsi will impose data-protection obligations on Subprocessors that are designed to provide a level of protection appropriate to the Processing they perform.
Where required by Applicable Data Protection Law, tealsi will provide reasonable notice of material additions or replacements of Subprocessors. If Customer has a legally supportable objection based on data-protection grounds, the parties will work in good faith to address the objection. If no reasonable solution is available, tealsi may permit Customer to discontinue the affected feature or Service, subject to the Agreement.
10. Customer-Connected Third-Party Services
The Platform may allow Customer to connect or authorize services such as Meta, WhatsApp, Google, TikTok, Stripe, PayPal and other third-party platforms. When Customer directly connects, authorizes or instructs a third-party service, that third party may Process Personal Data under its own terms, privacy notice and independent legal role.
Not every third-party service accessible through tealsi is a Subprocessor of tealsi. A service directly selected, contracted, authorized or controlled by Customer may act independently or as Customer’s own processor. Customer is responsible for reviewing and complying with the terms applicable to those services.
11. International Data Transfers
Customer Personal Data may be Processed in the United States and other jurisdictions where tealsi or its Subprocessors operate. Customer authorizes such Processing subject to this DPA.
If Applicable Data Protection Law requires a specific transfer mechanism for a restricted international transfer, the parties will use an applicable lawful transfer mechanism, which may include standard contractual clauses, an approved addendum or another legally recognized safeguard.
To the extent legally required, the relevant transfer terms are incorporated into this DPA by reference and will apply only to the extent necessary for the applicable transfer.
12. Data Subject Requests
Customer is responsible for responding to requests from individuals concerning Customer Personal Data. Taking into account the nature of the Processing, tealsi will provide commercially reasonable assistance through available Platform functionality or other reasonable measures to help Customer respond to requests for access, correction, deletion, portability or other rights required by Applicable Data Protection Law.
If tealsi receives a request directly from an individual concerning Customer Personal Data for which Customer is the Controller, tealsi may redirect the individual to Customer unless applicable law requires tealsi to respond directly.
13. Personal Data Breaches and Security Incidents
tealsi will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data where notice is required by Applicable Data Protection Law.
Notification may be provided in phases as information becomes available and may include, where reasonably available, the nature of the incident, categories of affected data, known or reasonably anticipated consequences, mitigation steps and a contact for additional information.
tealsi’s notification or response to a Security Incident is not an admission of fault, liability or legal responsibility.
Customer remains responsible for determining whether Customer must notify individuals, regulators, contractual counterparties or others, except to the extent Applicable Data Protection Law assigns that obligation directly to tealsi.
14. Compliance Assistance
Taking into account the nature of Processing and information reasonably available to tealsi, tealsi will provide commercially reasonable assistance to Customer with obligations that may apply to Customer concerning data security, breach response, data protection impact assessments and regulator consultations.
Assistance that is materially beyond standard Platform functionality or ordinary support may be subject to reasonable fees if permitted by the Agreement and applicable law.
15. Audits and Compliance Information
Upon reasonable written request, tealsi may make available information reasonably necessary to demonstrate compliance with this DPA, which may include relevant policies, security information, questionnaires, summaries, third-party reports or certifications that tealsi elects to provide.
If Applicable Data Protection Law requires an audit beyond the information reasonably made available by tealsi, Customer may request an audit no more than once annually unless a Security Incident or regulator requires otherwise. Any audit must be conducted during normal business hours, on reasonable advance notice, without unreasonably disrupting operations, subject to confidentiality obligations, and without exposing information concerning other customers or compromising Platform security.
Customer bears its audit costs and will reimburse tealsi for reasonable costs of extraordinary audit assistance to the extent permitted by law.
16. Return, Deletion and Retention
During an active subscription, Customer may use available Platform features to access or export Customer Data where supported.
Following cancellation or termination, Customer Data will generally be scheduled for deletion or anonymization from active production systems within approximately thirty (30) days, subject to the Agreement and technical feasibility.
Limited information may remain for longer in backups, security logs, billing and accounting records, fraud-prevention records, legal holds, records required by law, or systems where immediate deletion is technically impracticable. Such retained information remains subject to applicable security and confidentiality protections and will not be restored to active use except as necessary for recovery, security, legal compliance or other permitted purposes.
17. Government and Legal Requests
tealsi may disclose or preserve Customer Personal Data when reasonably necessary to comply with a valid subpoena, court order, warrant, regulatory request, law-enforcement request or other legal obligation.
Where legally permitted and reasonably practicable, tealsi may notify Customer of a legally compelled disclosure relating specifically to Customer Data. tealsi may challenge or narrow a request when it reasonably determines that doing so is appropriate, but is not obligated to pursue litigation on Customer’s behalf.
18. Sensitive and Regulated Data
Customer will not use tealsi to Process regulated or highly sensitive information unless the applicable feature, plan and written terms expressly support that category of data.
Unless expressly agreed in writing, Customer must not assume that tealsi is designed for or compliant with specialized regimes applicable to protected health information, financial account credentials, government-classified information, biometric templates, children’s data subject to specialized parental-consent regimes, or other specially regulated data.
Customer is responsible for determining whether a particular category of information may lawfully and appropriately be Processed through the Platform.
19. AI and Voice Processing
When Customer enables AI, voice, transcription, calling, agent or related functionality, Customer instructs tealsi to transmit and Process relevant Customer Data using the infrastructure reasonably necessary to provide that functionality, which may include AI, voice and telecommunications Subprocessors.
Customer is responsible for the legality of prompts, recordings, voice inputs, contact data, call content, consent, notices and instructions submitted through such features.
Customer must not submit sensitive, confidential or regulated information to AI or voice features unless Customer has determined that the applicable feature, agreement and provider configuration are appropriate for that information.
20. Liability and Relationship to the Terms
Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement to the maximum extent permitted by applicable law.
Nothing in this DPA expands tealsi’s responsibility for Customer’s independent legal obligations, Customer’s communications, Customer’s content, Customer’s End Users, Customer’s clients, or Customer’s use of third-party services.
21. Term and Changes
This DPA remains in effect for as long as tealsi Processes Customer Personal Data on Customer’s behalf, including any limited post-termination retention period required or permitted by this DPA.
tealsi may update this DPA to reflect changes in law, regulation, Platform functionality, Subprocessors, security practices or operational requirements. Material changes will be communicated as required by the Agreement or applicable law.
22. Contact
Questions concerning this DPA or Customer’s data-processing relationship with tealsi may be sent to support@tealsi.com until a dedicated privacy or legal contact is published.
Exhibit A
Processing Details
| Item | Description |
|---|---|
| Subject matter | Provision, operation, security, support and maintenance of the tealsi SaaS platform and Customer-selected functionality. |
| Duration | For the term of the Agreement plus any limited retention period described in the Agreement or this DPA. |
| Nature of Processing | Collection, receipt, hosting, organization, storage, retrieval, consultation, transmission, communication, analysis, generation, alteration, deletion and other Processing necessary to provide Customer-selected features. |
| Purposes | CRM, automations, messaging, calling, AI agents, voice functionality, websites/funnels, calendars, integrations, analytics, support, security and related Platform functionality configured by Customer. |
| Categories of Data Subjects | Customer personnel, Authorized Users, Customer clients, Customer Clients, leads, prospects, consumers, contacts, vendors and other individuals whose Personal Data Customer submits or causes to be Processed through the Platform. |
| Categories of Personal Data | Identifiers and contact details; business information; CRM records; communications content and metadata; appointment information; call information; recordings and transcripts when enabled; AI prompts and outputs; website/form submissions; transaction-related information; device and technical information; and other data Customer elects to Process. |
| Sensitive Data | Only to the extent Customer lawfully submits such information and the applicable feature and Agreement support it. Customer must not assume that specialized regulated data is supported without written confirmation. |
| Frequency | Continuous or as initiated/configured by Customer during use of the Services. |
Exhibit B
Technical and Organizational Measures
The measures below describe the general categories of safeguards tealsi may use. Specific implementation details may change as the Platform evolves and are not intended to disclose security-sensitive configuration thresholds.
| Control Area | General Measures |
|---|---|
| Access control | Role-based or permission-based access, account authentication, least-privilege concepts and restricted administrative access. |
| Authentication protection | Automated protections designed to detect repeated unauthorized access attempts, rate limiting and progressive lockout/blocking controls. |
| Transport security | Encrypted connections where reasonably supported for data transmitted between users, the Platform and infrastructure providers. |
| Infrastructure | VPS/cloud infrastructure, network controls, operating-system and application controls, updates and other measures appropriate to the service architecture. |
| Logging and monitoring | Operational and security logs, monitoring, suspicious-activity review and records supporting incident response and abuse prevention. |
| Tenant access | Ordinary support access requires Customer authorization; limited exceptions exist for security, fraud, abuse, essential operations, restoration and valid legal process. |
| Availability and recovery | Reasonable backup, recovery and operational continuity practices appropriate to the Services, without guaranteeing uninterrupted availability or zero data loss. |
| Vendor management | Use of providers subject to contractual, security, privacy or operational requirements appropriate to their function. |
| Incident response | Processes designed to investigate, contain, mitigate, document and communicate material Security Incidents as required by applicable law. |
| Confidentiality | Confidentiality obligations and access limitations for personnel authorized to Process Customer Personal Data. |
Exhibit C
Subprocessor Framework
Depending on Customer configuration and the functionality used, tealsi may rely on the following categories of infrastructure. The current public Subprocessors page should be treated as the authoritative operational list and may be updated over time.
| Provider | Purpose | General Role |
|---|---|---|
| Hostinger | VPS / hosting infrastructure | Infrastructure provider |
| Twilio | Telecommunications, messaging, phone-number and related communications infrastructure | Subprocessor/infrastructure provider when used by tealsi to provide Customer functionality |
| Vapi | AI voice and calling infrastructure | Subprocessor/infrastructure provider when relevant features are enabled |
| ElevenLabs | Voice synthesis, speech and related processing | Subprocessor/infrastructure provider when relevant features are enabled |
| OpenAI | AI model processing and related AI functionality | Subprocessor/infrastructure provider when relevant features are enabled |
Customer-connected services are different. Platforms such as Meta, WhatsApp, Google, TikTok, Stripe and PayPal may be directly connected or authorized by Customer and may operate under their own legal role. They are not automatically treated as tealsi Subprocessors merely because the Platform integrates with them.
Questions about data processing?
Contact support@tealsi.com or return to the Legal Center. tealsi is a software product provided by Constellation X, LLC.