Data Processing Agreement

How Octanist processes customer personal data, including security, subprocessors, transfers and deletion.

Last updated: 29 September 2026.

1. Parties, roles and precedence

This DPA forms part of the agreement between Octanist B.V., KvK 42100062, Turnhoutseweg 22, 5541 NX Reusel, Netherlands, and the Customer identified in its order or authorised account acceptance.

It applies to personal data Octanist processes on the Customer's behalf in providing the Services. The Customer may be a controller or a processor authorised by its controller. Octanist acts as processor or further processor respectively. The Customer must ensure that it has the authority and instructions needed to engage Octanist, including any required authorisation for further processors.

For processing where Octanist independently determines purposes and means, including its own business administration, the Privacy Policy and applicable controller obligations apply. Merely labelling an activity in an agreement does not determine its legal role.

This DPA prevails over inconsistent general terms concerning processing personal data. Mandatory law and applicable standard contractual clauses for transfers prevail over conflicting contractual provisions. Defined data-protection terms have their meaning under applicable law, including the GDPR where applicable.

2. Instructions and purpose limitation

Octanist will process the covered data only on documented instructions, including instructions regarding transfers, unless applicable law requires otherwise. Instructions include the agreement, the enabled features, configured integrations and authorised actions through the platform, API and MCP. Additional instructions must be documented and agreed where they change the service scope or require new measures.

Where processing is required by law, Octanist will inform the Customer before processing unless that law prohibits notice. Octanist will inform the Customer if it considers an instruction to infringe applicable data-protection law and may pause the affected activity while the issue is resolved. It will not use covered customer data for its own advertising or sale, or for unrelated model training under its own instructions.

The Customer determines its purposes, legal bases, required notices and permissions. It must limit submissions and configurations to data and activities for which the Services and agreed safeguards are suitable. The Customer's obligations do not remove Octanist's own statutory responsibilities.

3. Personnel and security

Octanist will ensure that authorised personnel are bound by confidentiality and receive access appropriate to their duties. It will implement and maintain technical and organisational measures appropriate to the processing risks, as described in Schedule B, considering the nature of the data, state of the art and relevant context.

Measures may evolve, but changes must not materially reduce the agreed overall protection.

4. Subprocessors

Upon valid acceptance of this DPA and its current register, the Customer grants general written authorisation for the subprocessors identified there. Octanist will bind each subprocessor by written obligations providing the protections required for its processing and will remain responsible for performance of those obligations as required by applicable law.

For intended additions or replacements, Octanist will give at least 30 days' direct advance notice identifying the provider, purpose and relevant locations/safeguards, giving the Customer an opportunity to object on reasonable data-protection grounds.

The parties will work in good faith on a reasonable alternative or safeguards. Octanist will not process the objecting Customer's data through the disputed provider while the objection is unresolved; where that makes continued delivery impossible, the affected Services may end, with unused prepaid recurring fees refunded where the Customer is not in breach. Shorter notice may be necessary for an urgent protective replacement, but does not remove applicable authorisation, information and objection requirements; affected processing may need to pause until those can be met.

The notice and authorisation mechanism applies when this DPA becomes part of the agreement. It does not override individually agreed requirements unless validly amended.

5. Locations and international processing

Primary application and database hosting are described in the register. Other services, remote access, routing, logs and backups must be assessed separately.

Octanist will undertake a restricted international transfer only with a lawful transfer mechanism and necessary safeguards, documented for the relevant recipient and role. Where standard contractual clauses are used, the appropriate module, parties and annexes must be completed and any necessary supplementary measures applied.

Customer instructions to send data to a chosen external recipient do not authorise Octanist to ignore its own transfer obligations. The Customer is responsible for the lawfulness of its selection and the independent recipient arrangements it controls.

6. Assistance and personal-data breaches

Taking account of the nature of processing and available information, Octanist will provide reasonable assistance with data-subject requests, security obligations, impact assessments and required prior consultations. Requests concerning customer-controlled data received directly by Octanist will be referred without undue delay, unless law requires a direct response.

Octanist will notify the Customer without undue delay after becoming aware of a personal-data breach affecting covered data. The initial notification will provide available information about the incident, affected data/individuals, likely consequences, measures taken or proposed and a contact. Further information may follow in stages as the investigation progresses. Notification must not be delayed solely to complete all particulars.

Octanist will take reasonable steps to contain and remediate a breach, preserve relevant evidence and assist the Customer's response. The Customer determines its own notification obligations to regulators and individuals; it does not need Octanist's permission to meet a legal deadline.

Incident and privacy contact: support@octanist.com. Octanist support coordinates security incidents and escalates them to the responsible personnel.

Standard assistance needed to meet Octanist's own obligations will not be conditioned on a new fee. Any reasonable incremental charges for exceptional customer-requested work must be agreed in advance and must not impede mandatory rights or urgent breach assistance. Octanist bears costs attributable to its own failure to comply with agreed obligations.

7. Evidence and audits

Octanist will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or an appropriately qualified auditor mandated by it.

The parties will use proportionate arrangements, including relevant independent reports or documentary evidence where sufficient, reasonable notice and appropriate confidentiality/security safeguards. Additional investigation remains possible where warranted by an incident, credible non-compliance concern or competent authority requirement. The process must protect other customers' data and the security of the platform without defeating the Customer's mandatory audit rights.

Each party ordinarily bears its own audit costs unless otherwise agreed or the audit establishes material non-compliance attributable to Octanist, in which case reasonable attributable remediation costs are borne by Octanist. Findings and corrective actions will be documented.

8. Return, deletion and duration

This DPA applies for as long as Octanist processes the covered personal data, including retained account history and continued lead collection after a paid subscription ends. Ending the paid subscription does not itself instruct deletion. Continued processing is limited to the Customer's lawful instructions and necessary purposes as described in Schedule C. At the end of processing, Octanist will return or delete the data at the Customer's choice unless law requires retention.

After the agreed retrieval process or valid deletion instruction, Octanist will delete covered personal data and existing copies unless law requires retention. Legally retained data will be isolated as appropriate, protected and used only for the permitted purpose. Provider and backup handling will be included in the response to a deletion instruction. Any retained backup copies must remain protected and restricted to permitted recovery or legal purposes until removed; where a backup is restored, relevant deletion instructions must be reapplied before ordinary processing resumes.

Ending a subscription, deleting a database row and deleting a provider recording are not interchangeable. Octanist will apply documented instructions throughout the relevant processor chain. Confirmation of completion must reflect actual deletion and any specified lawful exceptions.

Confidentiality and necessary data-protection duties continue while data is retained. Applicable switching and retrieval rights prevail over an inconsistent deadline or fee provision.

9. Liability and governing arrangements

The agreement's valid liability provisions apply between the parties, subject to mandatory law and applicable transfer clauses. They do not limit data-subject rights, supervisory-authority powers or non-excludable statutory responsibility.

Dutch law and the agreement's valid dispute provisions apply, subject to mandatory rules. Acceptance must identify the Customer, authorised acceptor, date and document version through the agreed electronic process or a signed agreement.

Schedule A: processing description

Subject and duration

Description: Provision of Octanist features during the service relationship and retained-account, continued-collection and exit processing described in Schedule C

Purposes

Description: Customer-directed lead capture and management, attribution, campaign reporting, conversion exports, call routing/recording, enabled transcription/summaries, integrations and authorised access

Operations

Description: Collection, transmission, organisation, storage, matching, enrichment, retrieval, display, analysis, export and deletion as required by enabled features

Individuals

Description: Website visitors, prospective and existing customers, callers/call participants, customer and agency personnel, and other individuals lawfully included in customer data

Data

Description: Contact details; form/custom-field contents; lead statuses, notes and values; visitor/session IDs; IP/browser/context data; click IDs/campaign information; consent signals; integration credentials/metadata; call details, audio, transcripts, speaker information, raw transcription responses and summaries

Sensitive data

Description: Not inherently required for the standard purposes; customer submissions and conversations may nevertheless contain it. Assess the actual use case and safeguards before processing.

Frequency

Description: Ongoing as customers and participants use configured features; no call transcription or summary processing for features not enabled

Agency chain

Description: Where the Customer is a processor, it warrants authority to instruct Octanist for its client controller and will communicate relevant controller instructions

Schedule B: security measures

Octanist will maintain the following measures in support of its obligations under this DPA:

  • Limit production customer-data access within Octanist to authorised owners and management whose duties require it, with multi-factor authentication required for that access.
  • Use organisation-scoped access controls for customer accounts and server-side data operations, and protect account credentials and integration permissions against unauthorised use.
  • Use HTTPS for application and provider communications, including retrieval of call recordings, and authenticate supported provider webhooks using signature verification.
  • Bind authorised personnel to confidentiality, keep access appropriate to their duties and remove access when it is no longer authorised.
  • Use Vercel for the primary application and PlanetScale on AWS for the primary database, with the primary hosting locations in Frankfurt. Provider infrastructure, access and additional processing are governed by the applicable provider arrangements.
  • Coordinate security reports and incident response through Octanist support at support@octanist.com, investigate relevant reports and notify affected customers without undue delay as required by this DPA.
  • Protect retained data and coordinate valid access, return and deletion instructions across the relevant systems and provider-held copies. Account cancellation alone is not treated as a deletion instruction.

These measures do not constitute a certification or a guarantee that security incidents cannot occur. Appropriate measures must be maintained throughout processing, including after the paid subscription ends.

Schedule C: retention, continued collection and exit

The Customer retains paid access until the end of its paid period unless a lawful restriction or other agreed termination arrangement applies. Octanist currently retains account history after subscription cancellation without a fixed automatic expiry so that the Customer can reactivate with its history. Octanist does not currently run a routine inactivity review or automatic deletion process for abandoned accounts. Incoming leads continue to be accepted from tracking and submission sources that remain enabled. This does not continue a cancelled Call Tracking add-on or preserve released telephone numbers.

This retained-account arrangement is part of the processing instructions only for as long as it is lawful and necessary for the Customer's stated purposes. The Customer must review its retention needs, keep applicable notices and permissions in place, and give an instruction when processing should stop. A prospect of possible future reactivation does not override applicable storage-limitation duties or a valid deletion request. Octanist will inform the Customer if it considers an instruction unlawful under Section 2.

To stop collection from its website, the Customer must remove the Octanist pixel and disable any other source, including API, form or integration submissions, that continues sending leads. The organisation owner can delete the organisation through the dashboard. That action removes linked live workspace records and ends collection into that organisation; it does not necessarily delete the owner's personal login or other organisations. For return, assistance or deletion of additional records, an authorised contact should email support@octanist.com, identify the organisation and explain the requested scope. Dashboard deletion is followed by a management-run manual cleanup process for remaining customer-specific provider recordings and operational call-event records. Management will identify the relevant records, coordinate deletion with providers where necessary, verify the outcome and record any lawful exception. This cleanup must take place without undue delay and remains Octanist's responsibility; it is not conditional on the Customer buying another subscription. Stripe billing history retained for accounting and backup copies are handled separately. Octanist's return and deletion obligations continue for covered data remaining in those systems. Octanist will verify authority for additional requests, coordinate cessation of collection and explain the applicable retrieval and deletion process, including provider copies, backups and legal exceptions. Mandatory response and deletion duties are not conditional on buying a new subscription.

Leads, submitted forms, sessions, page views and call metadata

Handling: Stored as account history under the retained-account arrangement until valid deletion instructions are carried out or removal is otherwise required by law.

Transcripts, speaker information, summaries and stored raw processing responses

Handling: Stored in Octanist's database and subject to the same account-history instructions. Deleting a recording alone does not delete these separate records.

Integration details and credentials

Handling: Used only for authorised connections and retained-account functions. Revocation or disconnection limits further access but does not itself erase previously collected history. Closure and deletion instructions must address remaining credentials and records.

Handling: Hosted by Telnyx under the applicable configuration. Availability and retention are separate from Octanist account history; management includes these provider-held copies in the manual cleanup after organisation deletion and coordinates any separate return or deletion request.

ElevenLabs processing copies and logs

Handling: Governed by the applicable provider settings and processing terms. The transcription path is not represented as zero retention; management will coordinate applicable deletion instructions for covered provider copies as part of the manual cleanup process.

AI Gateway and OpenAI

Handling: The OpenAI model route requests zero retention for the covered model processing. Octanist retains its input transcripts and output summaries under the account-history rule. This is not a universal zero-retention promise for gateway metadata or other providers.

Operational logs and backups

Handling: May have separate provider-controlled retention and expiry. Octanist will establish the relevant handling when responding to instructions; remaining copies must stay protected, purpose-limited and subject to applicable deletion duties. No single immediate-erasure deadline is promised for every system.

Customers can export selected lead fields in CSV or XLSX through the platform while the relevant access is available. Those files do not necessarily include recordings, full session history, raw forms or all other stored data. Support will coordinate requests for additional covered data and a secure retrieval route where ordinary account access is unavailable. Retrieval and switching rights required by applicable law remain available.

Telephone numbers are cancelled when Call Tracking ends. Transfer assistance must be requested before cancellation or release and depends on carrier rules and availability. Any permissible transfer or assistance charge must be disclosed and agreed in advance. A released number can be reassigned and may not be recoverable.

Confidentiality, access protection and this DPA remain applicable while any covered personal data is processed. Octanist will not confirm complete erasure until that accurately reflects the relevant systems and any disclosed lawful exceptions.

See the Subprocessor Register and Privacy Policy.