Terms & Policies
Data Processing Addendum
Updated:
This Data Processing Addendum (the “DPA”) forms part of and is incorporated into the Software as a Service Agreement (the “Agreement”) between Robin Voice, Inc. d/b/a Commons (“Company”) and the Customer identified in the applicable Order Form (“Customer”). Capitalized terms not defined herein have the meanings set forth in the Agreement.
This DPA applies only to the extent Company processes Personal Information on behalf of Customer in connection with the Services.
For the purposes of this DPA:
“Personal Information” means personal information, personal data, or similar term as defined under applicable U.S. state privacy laws, to the extent included in Customer Data. For clarity, Personal Information processed under this DPA is a subset of Customer Data.
“Security Incident” means unauthorized access to or acquisition of Personal Information processed by Company on behalf of Customer that compromises the security, confidentiality, or integrity of such Personal Information, excluding unsuccessful attempts or events that do not result in unauthorized access.
1. Role of the Parties
1.1 Customer as Controller or Business
Customer determines the purposes and means of processing Customer Data transmitted through the Services. Customer acts as a “controller” or “business” under applicable U.S. state privacy laws.
1.2 Company as Processor or Service Provider
Company processes Personal Information solely on behalf of Customer and in accordance with Customer’s documented instructions as set forth in the Agreement, applicable Order Form, and this DPA. Company acts as a “processor” or “service provider” under applicable U.S. state privacy laws.
1.3 No Independent Sale or Sharing
Company does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising.
Company shall not retain, use, disclose, or combine Personal Information with personal information obtained from other customers or third parties except:
(a) as necessary to provide the Services;
(b) to improve, support, and secure the Services in a manner consistent with the Agreement and applicable law;
(c) to detect or prevent fraud, abuse, or security threats;
(d) to comply with applicable law; or
(e) as otherwise expressly permitted by applicable law.
Nothing in this DPA restricts Company’s rights under Section 3.4 of the Agreement to use aggregated or de-identified data.
1.4 Customer Data Use Limitations
Company will not use Personal Information processed under this DPA to train general-purpose artificial intelligence models, create cross-customer benchmarking products, create customer-specific intelligence products for other customers, or make such Personal Information available to other customers, except as expressly authorized in the Agreement, an applicable Order Form, this DPA, or another written agreement signed by Customer. This Section does not restrict Company’s use of aggregated or de-identified data as permitted by the Agreement and applicable law, provided such data is not reasonably capable of identifying Customer, Customer’s recipients, or any individual.
1.5 Applicable State Privacy Law Obligations
To the extent required by applicable U.S. state privacy law, Company shall: (a) comply with obligations applicable to it as a processor or service provider and provide the same level of privacy protection required of Customer; (b) notify Customer if Company determines it can no longer meet those obligations; (c) permit Customer, upon reasonable notice, to take reasonable and appropriate steps to help ensure Company’s processing is consistent with Customer’s obligations; and (d) permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized processing.
2. Scope and Nature of Processing
2.1 Subject Matter
Company provides a civic messaging platform that enables Customer to send and receive SMS, MMS, and voice communications and to manage related messaging workflows.
2.2 Nature and Purpose of Processing
Processing may include collection, storage, organization, transmission, routing, analysis, transcription, classification, and deletion of Personal Information for the limited and specified purposes of enabling Customer to send and receive SMS, MMS, and voice communications; processing inbound interactions; generating requested transcripts, classifications, and structured records; administering Customer accounts; providing support; maintaining and improving the security, integrity, reliability, and quality of the Services provided to Customer; detecting and preventing fraud, abuse, and security threats; and complying with applicable law and Customer’s documented instructions consistent with the Agreement and this DPA.
2.3 Duration
Processing will continue for the duration of the applicable Order Form and any period during which Company retains Personal Information in accordance with the Agreement and Privacy Policy, unless earlier deleted upon Customer’s written request in accordance with Section 8 of this DPA.
2.4 Categories of Data Subjects
Data subjects may include:
(a) Constituents, voters, supporters, or audience members of Customer;
(b) Individuals who send inbound text messages or place inbound calls to Customer’s dedicated number;
(c) Customer personnel and authorized users, solely to the extent their information is included in Customer Data and processed on Customer’s behalf;
(d) Visitors to Customer-controlled forms or pages operated through the Services, solely to the extent their information is included in Customer Data and processed on Customer’s behalf.
2.5 Categories of Personal Information
Personal Information processed may include:
(a) Phone numbers;
(b) Contact and audience attributes supplied by Customer, including names, tags, segments, and custom fields;
(c) Message content;
(d) Delivery and routing metadata;
(e) Engagement data, including replies and opt-outs;
(f) Inbound message and call data;
(h) Transcriptions or structured representations of inbound voice communications;
(h) Account information for Customer users, solely to the extent such information is included in Customer Data and processed on Customer’s behalf;
(i) Technical information associated with message transmission.
Customer represents and warrants that it has obtained all rights, permissions, and consents required to provide such Personal Information to Company and to authorize Company’s processing under this DPA, the Agreement, and the Acceptable Use Policy.
2.6 Transcription and Structured Processing
Where the Services include transcription or structured processing of voice or message content, such outputs are treated as Personal Information to the extent they contain or reflect Customer Data. Company may generate and store transcripts or structured records of inbound voice communications to provide the Services, including routing, classification, recordkeeping, and auditability. Unless expressly stated in an applicable Order Form, Company does not store call audio as the system of record. Customer acknowledges that transcripts or structured records may serve as the primary record of communications within the Services.
3. Customer Instructions
Company shall process Personal Information only:
(a) in accordance with the Agreement, Order Form, and this DPA;
(b) as necessary to provide the Services;
(c) as required to comply with applicable law; or
(d) as otherwise documented in writing by Customer.
Customer is solely responsible for the legality of its messaging activity, including consent compliance, as set forth in the Agreement and Acceptable Use Policy.
4. Confidentiality
Company shall ensure that personnel authorized to process Personal Information are subject to confidentiality obligations consistent with Section 3 of the Agreement.
5. Security Measures
5.1 Administrative, Technical, and Physical Safeguards
Company shall implement reasonable administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction, consistent with the Agreement and Privacy Policy.
5.2 Controls
Such safeguards include, as appropriate:
(a) Encryption of data in transit;
(b) Logical access controls;
(c) Role-based access restrictions;
(d) Secure cloud infrastructure;
(e) Monitoring for unauthorized access.
Company may update its security measures from time to time, provided that such updates do not materially diminish the overall level of security.
6. Subprocessors
6.1 Authorization
Customer authorizes Company to engage subprocessors to support delivery of the Services.
6.2 Subprocessors
Company maintains a current list of subprocessors engaged to process Personal Information on behalf of Customer in connection with the Services. Customers and prospective customers may request the current list by emailing privacy@usecommons.com.
6.3 Subprocessor Obligations
Company shall enter into a written agreement with each subprocessor that requires the subprocessor to process Personal Information only to provide the subcontracted services and to meet the same data protection obligations applicable to Company under this DPA and applicable law.
6.4 Changes
Company may update its subprocessors from time to time. Company will provide notice of material additions or replacements. If Customer reasonably objects on documented data protection grounds, the parties will work in good faith to address the concern. Nothing in this Section expands Customer’s termination rights beyond those set forth in the Agreement. Company may proceed with the subprocessor engagement if the parties cannot reach resolution and Customer continues to use the Services after receiving notice.
7. Data Subject Requests
7.1 Responsibility
Customer is responsible for responding to data subject requests under applicable U.S. state privacy laws.
7.2 Assistance
Taking into account the nature of processing, Company shall provide reasonable assistance to Customer in responding to verified consumer rights requests, to the extent such requests relate to Personal Information processed by Company on Customer’s behalf. Company’s assistance shall be limited to functionality available within the Services and reasonable cooperation. Additional assistance beyond standard functionality may be subject to mutually agreed fees.
7.3 Direct Requests
If Company receives a request directly from a data subject relating to Customer Data, Company may redirect the request to Customer.
8. Return and Deletion of Data
8.1 During the Term
Subject to the Agreement and applicable law, Customer may request deletion of messaging data.
8.2 Upon Termination
Upon termination or expiration of the Services, at Customer’s written direction, Company shall return or delete all Personal Information within a reasonable period, except to the extent retention is required by applicable law.
8.3 Backup Systems
To the extent permitted by applicable law, Personal Information maintained in routine backup or archival systems may remain until deleted through standard retention cycles, provided that it remains protected under this DPA and is not actively processed except for security, continuity, restoration, or legal-compliance purposes.
8.4 De-identified Data
This Section does not require the return or deletion of Aggregated Data permitted under Section 3.4 of the Agreement or data that has been lawfully de-identified and is no longer Personal Information under applicable law.
9. Security Incident Notification
9.1 Notification
In the event Company becomes aware of a Security Incident, Company shall notify Customer without unreasonable delay.
9.2 Content of Notice
Notification shall include information reasonably available to Company concerning the nature of the Security Incident. Customer is responsible for determining whether notification to individuals, regulators, or others is required under applicable law and for providing any such required notifications.
9.3 No Expanded Liability
Security Incident obligations are subject to the limitations of liability and other provisions set forth in the Agreement.
10. Compliance, Assistance, and Assessments
Taking into account the nature of the processing and information available to Company, Company shall provide reasonable assistance to Customer in meeting applicable U.S. state privacy-law obligations concerning consumer requests, security of processing, Security Incident notification, cybersecurity audits, risk assessments, and automated decision-making, in each case solely with respect to processing under Company’s control.
Upon reasonable request, Company shall make available information in its possession reasonably necessary to demonstrate compliance with this DPA and applicable law. Where an assessment is required by applicable law, Company shall cooperate with a reasonable assessment by Customer or Customer’s designated assessor or, where permitted by applicable law, may arrange for a qualified independent assessor to conduct the assessment using an appropriate and accepted control standard and provide the resulting report to Customer upon request.
Assessments shall be subject to reasonable scope, timing, security, and confidentiality protections and shall not occur more than once annually except following a Security Incident, when required by a regulator, or when otherwise required by applicable law. Company need not disclose other customers’ data, source code, privileged materials, or information whose disclosure would materially compromise security, except to the extent required by applicable law and subject to appropriate safeguards. Assistance beyond standard functionality or applicable legal requirements may be subject to mutually agreed fees.
11. U.S.-Only Processing
Company operates in the United States and does not intentionally transfer Personal Information outside of the United States. This DPA does not incorporate international transfer mechanisms unless separately agreed in writing.
12. Order of Precedence
In the event of a conflict between this DPA and the Agreement, the Agreement shall control except to the extent this DPA expressly addresses data processing obligations required by applicable law. In all other respects, the Agreement governs.
13. Limitation of Liability
This DPA is subject to the limitations of liability, disclaimers, and indemnification provisions in the Agreement to the maximum extent permitted by applicable law. Nothing in this DPA or the Agreement relieves either party of any obligation or liability imposed on it by applicable law by virtue of its role in the processing relationship. Except for such nonwaivable obligations or liability, nothing in this DPA expands Company’s liability beyond the Agreement.