Roles
The customer is the controller and Operon is the processor. Where the customer is itself a processor for another controller, Operon acts as a subprocessor and the same obligations apply.
Scope of processing
Operon processes personal data only on documented instructions from the customer, which the agreement and the customer's platform configuration constitute. We tell the customer if we believe an instruction violates applicable data protection law.
- Subject matter: provision of AI communication agents and supporting services
- Duration: the term of the agreement, plus the export window
- Categories of data subjects: the customer's customers, prospects, patients, clients, and staff
- Categories of personal data: contact details, call audio and transcripts, message content, appointment and transaction records, and where applicable health information
Confidentiality and personnel
Access to personal data is limited to personnel who need it to deliver the service, all of whom are bound by written confidentiality obligations and receive annual data protection training.
Security measures
Operon maintains technical and organizational measures appropriate to the risk, including:
- Encryption in transit using TLS 1.3 and at rest using AES-256
- Least-privilege access control with SSO, SCIM, and immutable audit logging
- Logical tenant isolation and regional data residency
- Field-level redaction for PHI and payment data before storage
- Quarterly penetration testing and continuous vulnerability management
- Documented incident response with 24-hour customer notification after confirmation
Subprocessors
The customer authorizes the use of the subprocessors listed on our subprocessors page. We impose data protection obligations on each subprocessor no less protective than those in this DPA, and we remain liable for their performance.
We give 30 days notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds, and if we cannot resolve the objection the customer may terminate the affected service without penalty.
Model providers and training
Personal data is not used to train any model, whether operated by Operon or by a third-party provider. On Enterprise plans, inference can be routed through a zero-retention path where no provider persists any prompt or completion.
Data subject requests
Operon provides the customer with the tools to access, correct, export, and delete personal data directly. Where a data subject contacts us instead of the customer, we route the request to the customer and assist in responding, without additional charge.
International transfers
Where personal data is transferred out of the EEA, UK, or Switzerland, the parties rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum, each incorporated into this DPA by reference.
Audit
Operon makes available its SOC 2 Type II report and penetration test summaries on request. Where the customer requires further assurance, the parties will agree on the scope and timing of an audit, no more than once per year absent a security incident.
Deletion and return
On termination, the customer may export personal data for 60 days. After that window Operon deletes it from primary storage, backups, and analytics within 30 days, except where retention is required by law.
