Skip to content

Legal

Data processing agreement

Last updated: September 2026

Related: Privacy · Terms · Subprocessors · Security

This page is an unsigned processor DPA template in the style of GDPR Article 28. It is not an executed contract, not a signature, and not a claim that MinuteOne is GDPR-certified.

01Status of this document

This is a public template of processor terms we are willing to discuss. It does not bind either party until a signed DPA (or order form that incorporates one) is executed. Publishing it here is not electronic signature, click-wrap, or deemed acceptance.

02Parties and roles

  • Controller: the customer organization that determines why lead and call data are processed.
  • Processor: MinuteOne AI, which processes that data to provide the managed first-response service.

Account, billing, and security data for the SaaS itself are typically processed by MinuteOne as controller — see Privacy.

03Processing instructions

MinuteOne processes lead identity, consent artefacts, call metadata, transcripts, and recordings (when enabled) only to provide the service the controller configured: contact, qualification, booking, and related workspace operations. No secondary use: we do not sell lead lists or use customer lead or call data to train foundation models across tenants.

04Security

  • Recordings are private to the workspace when enabled — not a public object store.
  • Encryption at rest for recordings when that configuration is enabled.
  • Access control scoped to the customer organization.
  • Operational and audit logs as described in-product.

Controls as shipped are summarized on Security. This template does not invent SOC 2 or ISO 27001.

05Subprocessors

MinuteOne may use the processors listed at /subprocessors. Material changes are notified by updating that page. Which vendors apply depends on workspace configuration (voice region, CRM connectors, optional analytics).

06International transfers

Subprocessors may process data in the United States, including Stripe, Deepgram, OpenRouter, Twilio, Sentry, and tenant-chosen CRMs. Transfer tools (standard contractual clauses / EU–US Data Privacy Framework) are not executed in this template. Do not treat this page as an SCC, DPF certification, or transfer impact assessment. See International transfers.

07Personal-data incidents

If we become aware of a personal-data incident affecting controller data, we notify the controller without undue delay. We do not auto-file with a supervisory authority on the controller’s behalf. Operational steps live in our internal incident policy; see also Security.

08How to execute

To request a signed DPA, use the contact form (subject “DPA”) or the privacy contact noted during onboarding. This page is not a signature and does not form a contract by visiting or linking it.