Effective date: August 14, 2026 Last updated: August 14, 2026
This Data Processing Agreement ("DPA") supplements the Nunclara Terms of Service between Nunclara ("Processor," "we," "us") and the Customer ("Controller," "you") and applies to the extent Nunclara processes personal data on your behalf in connection with the Service. If there is a conflict between this DPA and the Terms of Service with respect to data processing, this DPA controls.
This DPA is offered as a standard template. If your business requires a signed, mutually negotiated DPA (for example, because one of your own customers or partners requires it of you), contact us at [email protected] and we'll work through it directly.
For personal data relating to your Callers (their name, phone number, address, and the content of their calls), you are the Controller — you determine why the data is collected and what happens to it. Nunclara is the Processor — we process that data only to provide the Service to you, according to your instructions.
For your own account and business data as a Nunclara Customer, Nunclara is the Controller, and that processing is governed by our Privacy Policy rather than this DPA.
Nunclara will process Caller personal data only:
We will not process Caller data for any other purpose, including marketing to Callers or building cross-customer profiles, without your prior consent.
Nunclara uses the following subprocessors to deliver the Service:
| Subprocessor | Purpose |
|---|---|
| Bland AI | Voice AI processing — speech-to-text, call handling, text-to-speech |
| Stripe | Payment processing (Customer billing data only, not Caller data) |
| DigitalOcean | Infrastructure hosting and storage of call data |
We will notify you before adding a new subprocessor that will process Caller personal data, and you may object on reasonable data-protection grounds by contacting [email protected] within 15 days of notice.
Nunclara maintains reasonable administrative, technical, and physical safeguards designed to protect Caller personal data, including encryption of call recordings at rest, access restrictions limited to personnel and systems that need the data to operate the Service, and monitoring for unauthorized access.
If Nunclara receives a request directly from a Caller to access, correct, or delete their data, we will forward it to you promptly and will not respond directly except to acknowledge receipt, unless required by law. We will provide reasonable assistance to help you respond to verified Caller requests within the time required by applicable law.
If Nunclara becomes aware of a security incident affecting Caller personal data, we will notify you without undue delay, and in any case within the timeframe required by applicable law, with the information available to us at the time to help you meet your own notification obligations.
On termination of the Service, Nunclara will make Caller data available for export for a reasonable period, after which it will be deleted in accordance with the retention schedule in our Privacy Policy, unless a longer retention period is required by law or for an active dispute.
Nunclara processes and stores data in the United States. If you or your Callers are located outside the U.S., you acknowledge that data will be transferred to and processed in the U.S. as part of the Service.
On reasonable written request, no more than once per 12-month period, Nunclara will provide you with information reasonably necessary to demonstrate compliance with this DPA, such as a summary of security practices. On-site audits are not offered at this time but may be available for enterprise accounts by separate agreement.
Liability under this DPA is subject to the limitations of liability set out in the Nunclara Terms of Service.
Nunclara
67-41 Kissena Blvd
Flushing, NY 11367
[email protected]