Data Processing Agreement

How we handle your callers' data.

Version 2026-10-05 · in force from the date you accept it

1. Parties, scope and order of precedence

  1. This Data Processing Agreement (“DPA”) is concluded between the business that uses Kesru (“Customer”) and Umbolement UG (haftungsbeschränkt), Ulmenweg 10, 85221 Dachau, Germany (“Kesru”, “we”).
  2. It applies whenever Kesru processes personal data on the Customer's behalf while providing the service described in the Terms of Service, in particular data of people who call the Customer's business. It meets Article 28 of the EU General Data Protection Regulation (“GDPR”) and, where they apply, U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”).
  3. The Customer accepts this DPA when creating an account or starting a subscription. We store the version, the time and the account that accepted it.
  4. If this DPA and the Terms of Service conflict on the protection of personal data, this DPA prevails.

2. Subject, nature, purpose and duration

Kesru answers phone calls forwarded to a number it provides, talks with callers using AI, and sends the Customer summaries, transcripts and requested actions such as appointment bookings. The processing lasts for the term of the Customer's subscription and ends with the deletion described in section 11. Categories of data and of data subjects are listed in Annex 1.

3. Instructions

  1. We process personal data only on the Customer's documented instructions. The Terms of Service, this DPA, the settings in the Customer's account and messages from the Customer's account holder are the complete instructions at the time of acceptance. Further instructions must be given in writing, including by email.
  2. We may process data without an instruction only where Union or Member State law requires it; we then inform the Customer before processing unless that law forbids it.
  3. We tell the Customer without undue delay if we believe an instruction infringes data protection law, and may pause that instruction until it is confirmed or changed.

4. Confidentiality

Everyone at Kesru who can access personal data is bound to confidentiality by contract or by law and only accesses data as far as needed for the service.

5. Security

We implement the technical and organizational measures in Annex 2, taking into account the state of the art, the cost of implementation and the risks for data subjects (Article 32 GDPR). We may improve these measures over time, but we will not lower the overall level of protection.

6. Sub-processors

  1. The Customer authorizes us generally to engage sub-processors. The current sub-processors, what they do, where they process data and the safeguard used are listed in Annex 3 and on kesru.com/subprocessors.
  2. We inform the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may end the subscription with effect before the change; fees already paid for the remaining period are refunded pro rata.
  3. We impose on every sub-processor by contract data protection obligations that are at least as protective as this DPA, and we remain responsible to the Customer for their performance.

7. International transfers

  1. Personal data may be processed outside the European Economic Area, including in the United States where the Customer's business and its phone numbers are located. We only transfer data under a valid safeguard: an adequacy decision (including the EU-U.S. Data Privacy Framework for certified recipients) or the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914).
  2. Where Kesru, as a processor established in Germany, returns personal data to a Customer outside the EEA, Module 4 (processor to controller) of the Standard Contractual Clauses is incorporated into this DPA by reference. For sub-processors outside the EEA without an adequacy decision we conclude Module 3 (processor to processor).

8. Rights of data subjects

Taking into account the nature of the processing, we help the Customer to answer requests from data subjects, such as access, correction, deletion or objection. If a data subject contacts us directly about data we process for the Customer, we forward the request to the Customer without undue delay and do not answer it ourselves unless the Customer instructs us to.

9. Assistance and personal data breaches

  1. We help the Customer, as far as the information available to us allows, with security, data protection impact assessments and prior consultation of supervisory authorities (Articles 32 to 36 GDPR).
  2. We notify the Customer without undue delay, and in any case within 48 hours after becoming aware of it, of any personal data breach affecting the Customer's data. The notice describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences and the measures taken or proposed. We add information as it becomes available.

10. Proof and audits

We make available all information necessary to demonstrate compliance with this DPA. The Customer may audit our compliance, also through an independent auditor bound to confidentiality, once per calendar year and additionally after a personal data breach, with at least 30 days' notice, during business hours and without disrupting our operations. Each party bears its own costs. Where possible we first answer audit questions in writing.

11. Deletion and return at the end

  1. Before the end of the subscription the Customer can export its data in the dashboard or ask us for a copy.
  2. After the subscription has ended and the phone line has been released, we delete or anonymize the Customer's personal data within 30 days, including data held by sub-processors on our behalf. Backups are overwritten within their retention cycle of at most 30 days; if a backup is restored, completed deletions are applied again before the data is used.
  3. We keep only what the law requires us to keep, such as invoices and payment references under German commercial and tax law, limited to the data and period required. On request we confirm the deletion in writing.

12. U.S. state privacy laws

Where the CCPA or a comparable U.S. state privacy law applies, Kesru acts as the Customer's service provider or processor. We process personal information only for the business purpose of providing the service under this DPA. We do not sell or share it, do not retain, use or disclose it for any other purpose or outside our direct business relationship with the Customer, and do not combine it with personal information we receive from others, except as those laws permit. We comply with the obligations that apply to us under those laws, give the same level of privacy protection they require, notify the Customer if we can no longer meet them, and allow the Customer to take reasonable steps to stop and remedy unauthorized use. We certify that we understand and will comply with these restrictions.

13. Liability and term

Liability under this DPA follows the liability rules of the Terms of Service, except where mandatory data protection law provides otherwise. This DPA remains in force as long as we process personal data for the Customer. German law applies; venue is Munich, Germany, to the extent permitted by law.

Annex 1 · Data subjects and categories of data

Data subjectsCategories of personal data
People who call the Customer's businessPhone number, time and length of the call, what the caller says (processed as text), name, contact details and requests they give, appointment details
The Customer's staff and account usersName, email address, phone number for forwarding, login and session data, settings
People named in content the Customer providesInformation contained in the knowledge, documents and instructions the Customer adds

We do not keep audio recordings of calls. Call transcripts are deleted after 90 days. The service is not designed for special categories of personal data (Article 9 GDPR); the Customer does not instruct the receptionist to collect them.

Annex 2 · Technical and organizational measures

Annex 3 · Sub-processors

The current list of sub-processors with their purpose, processing location and transfer safeguard is maintained at kesru.com/subprocessors and forms part of this Annex.

Contact for data protection

privacy@kesru.com · Umbolement UG (haftungsbeschränkt), Ulmenweg 10, 85221 Dachau, Germany