last updated: 14 august 2026
Data Processing Agreement
This Data Processing Agreement (hereinafter referred to as “DPA") has been executed by and between Curvo Corporation, of 1111B S Governors Ave STE 7807, Dover, DE 19904, United States, contactable at support@curvo.ai ("Curvo", "we", "us", or "our"), and you.
In this DPA, Curvo and you shall each be referred to as a "Party" individually and as "Parties" jointly.
Regarding the processing activities undertaken by the Parties, you will act as a Controller, and we will act as a Processor.
1. REPS AND WARRANTIES
The Processor represents, warrants and covenants that:
- the privacy, security and data handling practices adopted and maintained by the Processor shall be in effect and consistently applied as long as the Processor provides the services in connection with, or otherwise retains, personal data for or on behalf of the Controller; and
- the Processor shall promptly notify the Controller in writing with at least fifteen (15) business days prior to any material change in the Processor’s privacy, security, or data handling practices.
2. ACTING UPON INSTRUCTIONS
The Processor, acting on behalf of the Controller regarding the processing of personal data, agrees to operate solely based on the Controller's instructions.
The Processor and any other person acting under its authority who has access to personal data, shall process those data solely according to the instructions received from the Controller, solely for the purpose of performing the Legal Terms, and not for any other purpose, or in any other manner, unless required to do so by the applicable laws. The Processor will implement all the necessary measures in this respect.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes GDPR or other internal or European Union data protection legal provisions.
This document reflects the instructions from the Controller. The Controller can also give subsequent instructions throughout the duration of the processing of personal data, but such instructions shall always be documented and kept in writing, including electronically.
The instructions should include at least the following details regarding the processing, which can be completed and adjusted on a case-by-case basis:
- subject-matter: Performance by the Processor of the services or delivery of the Services covered by the Legal Terms;
- duration of the processing: personal data will be stored only as long as necessary for the performance of the services under the Legal Terms and for as long as the Controller is subject to the Legal Terms, unless there are deletion or return instructions from the Controller;
- nature and purpose of processing: Carrying out the necessary processing operations with regard to personal data in order to achieve the purposes pursued by the execution of the services under the Legal Terms;
- type of personal data: The personal data processed on the content of the recordings that are captured via the Services or uploaded by the Controller. The content of the recording is linked to the purpose of the meeting/dialogue, which is in complete control of the Controller, Controller staff or affiliates using the Services provided by the Processor. Email addresses and calendar schedules may be processed if the Controller chooses to integrate the Services with calendar apps.
- categories of data subjects: Individuals attending calls/meetings, or individuals whose data may be included in the recordings uploaded by the Controller.
When the Processor must process personal data to which it has access in its role as Controller’s data processor, due to a legal obligation imposed on the Processor, it shall promptly inform the Controller of that legal requirement before processing, unless such disclosure is prohibited by law for significant reasons of public interest.
3. ACCESS RIGHTS OF PERSONNEL
The Processor shall designate the persons who will process the personal data in the context of these Legal Terms, as well as the persons specialized in information security in order to ensure the processing of personal data, including the accurate functioning of used information systems.
Such persons (i) shall act under the Processor’s authority, (ii) must have committed themselves to confidentiality obligation or must be under an appropriate statutory obligation of confidentiality and (iii) shall access or otherwise process the personal data in the context of these Legal Terms only on a need to know basis. The Processor is required to update at the occurence of every change and keep under periodic review the list of persons to whom the access has been granted. On the basis of such review, such access to personal data can be withdrawn, if access is no longer necessary, and personal data shall consequently not be accessible anymore to those persons.
The Processor shall at the request of the Controller demonstrate that the said persons under the Processor’s authority (i) are subject to the aforementioned confidentiality obligation and (ii) have been adequately and timely subjected to training sessions regarding processing of data.
4. SECURITY MEASURES
The Processor applies and keeps constantly updated appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as well as against any other form of illegal processing.
The Processor represents and warrants that it shall implement and maintain reasonable administrative, technical and physical safeguards, and other security measures proportionate with the type of personal data being processed by the Processor for or on behalf of the Controller and the risk of a personal data breach.
5. DATA BREACH
In case of a personal data breach affecting personal data processed for or on behalf of Controller, the Processor shall take all necessary and appropriate corrective actions and shall cooperate with the Controller.
The Processor shall provide to the Controller a prompt written notice of any personal data breach affecting personal data processed by the Processor for or on behalf of the Controller, no later than 48 hours following the occurrence of such personal data breach.
Such notice shall summarize in reasonable detail (i) the nature of the data security breach, (ii) the impact of such data security breach upon the Controller and the persons whose personal data is affected by data security breach and (iii) the measures taken or proposed to be taken to address the data security breach.
The Processor shall assist the Controller in notifying the personal data breach with the supervisory authority, obtaining the information listed above, necessary to fill in the notification, and in communicating with the data subjects, as the case may be.
The Processor will not make any public announcements relating to personal data breach without the Controller’s prior written approval.
6. ASSISTING THE CONTROLLER
The Processor assists the Controller in respect of the management of the data subjects rights requests, the security of personal data, respectively the data protection impact assessment and prior consultation, the management of the requests received from public authorities, including supervisory authority, taking into account the nature of processing and the information available to the Processor.
7. RECORDS OF PROCESSING
The Processor will maintain a record of the Processing operations carried out on the Controller's behalf in the format to be communicated from time to time to the Controller.
8. RETURNING OR DELETING DATA AT TERMINATION
At the end of the provision of services related to processing, at the choice of the Controller, the Processor (i) shall return all original documents or (ii) shall delete or destroy all materials in any medium, containing personal data, including all copies, and any materials derived from or incorporating such personal data and shall certify to the Controller that it has done so, unless the law requires the Processor to retain such personal data.
The Processor shall delete all personal data processed on behalf of the Controller within thirty (30) days after the end of the provision of services relating to processing or the termination of the Legal Terms, whichever occurs first.
9. AUDIT AND INSPECTION
The Processor shall provide to the Controller with all necessary materials, documents and other information to enable the Controller to confirm that the Processor has complied with its obligations under this document.
The Controller or another auditor mandated by the Controller shall have the right to inspect the Processor’s business processes and practices that involve the Processing of personal data in relation to the services being provided for or on behalf of the Controller. The Processor shall allow and contribute to such audits, including inspections conducted by the Controller or another auditor mandated by the Controller.
Such audits shall be conducted during the Processor’s normal business hours, with prior written notice of at least thirty (30) days, and shall be carried out in a manner that causes minimum disruption to the Processor’s operations.
10. SUBCONTRACTING
The Controller grants the Processor a general authorization to engage sub-processors. The list of sub-processors, as well as any subsequent changes to the list, shall be communicated by the Processor to the Controller. The Controller shall have the right to object to the amendment of the list within thirty (30) days of the communication by the Processor, stating its reasonable data protection grounds for the objection.
If the Controller objects on reasonable grounds and the Parties are unable to resolve the objection within a further thirty (30) days, the Controller's sole and exclusive remedy shall be to terminate, without penalty, the specific services affected by the proposed sub-processor. The Processor shall have no obligation to withdraw or decline to engage the proposed sub-processor other than as necessary to give effect to such termination.
The list of subcontractors already authorised by the Controller is included in Appendix A to this DPA.
Processor shall, prior to any such disclosure to any sub-processor, enter into a written, valid and enforceable agreement with such subcontractor that includes terms that: (i) are substantially the same as the obligations applicable to personal data as contained in this DPA, (ii) otherwise require such subcontractors to comply with the terms and conditions of this DPA regarding the process of personal data.
11. TRANSFERS OUTSIDE UK/EEA
The Processor shall not disclose or transfer any personal data processed by the Processor for or on behalf of the Controller outside UK/European Economic Area, to third countries or international organisations without informing the Controller or on the documented instructions from the Controller.
In case transfers to third countries or international organizations, which the Processor has not been instructed to perform by the Controller are required under local laws to which the Processor is subject, the latter shall inform the Controller without undue delay of that legal requirement prior to processing unless that law prohibits such information on important grounds of public interest.
Any transfer outside European Economic Area to third countries or international organizations shall always take place in compliance with the requirements provided by GDPR/UK GDPR and internal law and the Processor shall comply with applicable law governing the transfer of personal data into such third country or international organization.
In case of a transfer of the personal data from Controller to Processor or access by the Processor from locations outside EU/EEA, the Parties will comply with and ensure the applicability of the European Commission's Standard Contractual Clauses (SCCs) for transfers to processors and, where the Controller is located in the United Kingdom, the UK International Data Transfer Addendum to the SCCs issued by the ICO (together, the "Transfer Clauses"), copies of which are available from the Processor upon request. The Processor undertakes that the sub-processor shall sign the Transfer Clauses defined by the European Commission or, where applicable, the ICO, in force at the time of acceptance of these Legal Terms and shall communicate them to the Processor. In the event that the Processor will transfer personal data to the United States of America it undertakes and will ensure that the entity receiving the personal data holds the certifications required and recognised by applicable law and European regulations, recommendations, such as but not limited to the Data Privacy Framework (DPF).
12. OTHER CLAUSES
Insofar the Processor discloses its collaborators’, employees’ and any other individual's personal data to the Controller for the purpose or in connection with the Legal Terms, the Processor has the obligation to inform all such individuals with regard to such disclosure and to the processing of their personal data by the Controller, including in connection with the Controller's audit rights set out in this DPA. The Processor shall take all the appropriate measures (including obtaining the consent from such individuals, if the case) so that the Controller may process such personal data for purposes provided by the Legal Terms, without any formalities.
Appendix A
Authorised Sub-processors
| Sub-processor | Activity | Location | DPA | International Transfer |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Primary persistent storage and processing of customer data, including recordings, transcripts, and derived analysis. We use ECS, SES, S3, RDS, S3 Vectors, Translate, and Route 53. | AWS eu-west-2 (London) for primary persistent storage and processing. Route 53 is global. | https://aws.amazon.com/compliance/ | Not applicable for London-hosted services; Route 53 is global. |
| Apollo.io (ZenLeads Inc.) | Business, organisation, and stakeholder enrichment, including business contact data. | United States, with US-hosted infrastructure. | https://www.apollo.io/dpa | EU-US Data Privacy Framework and UK Extension; EU SCCs and UK Addendum as fallback. |
| Anthropic, PBC | AI processing as a downstream model provider through OpenRouter. | US storage; processing may occur in the US, Europe, Asia, and Australia. | Anthropic Data Processing Addendum | Via OpenRouter; EU SCCs and UK Addendum. |
| OpenAI | Remaining direct AI processing for semantic analysis, feedback, and actionable steps before and during sales calls. | US / EU | https://openai.com/policies/data-processing-addendum/ | EU SCCs and UK Addendum. |
| AssemblyAI | Configurable transcription of meeting audio into text. | EEA or United States, depending on the configured provider and service route. | https://www.assemblyai.com/legal/data-processing-addendum | EU SCCs and UK Addendum where required. |
| Deepgram | Configurable transcription of meeting audio into text. | EEA or United States, depending on the configured provider and service route. | Deepgram Data Privacy Compliance | EU SCCs and UK Addendum where required. |
| Eleven Labs Inc. | Voice role-play, including scenario material, audio, transcripts, and scorecards. | United States by default; optional Enterprise residency in the EU, India, or Singapore. | https://elevenlabs.io/dpa | EU-US Data Privacy Framework and UK Extension; SCCs and UK Addendum. |
| Gladia | Configurable transcription of meeting audio into text. | EEA or United States, depending on the configured provider and service route. | https://www.gladia.io/data-process-agreement | EU SCCs and UK Addendum where required. |
| Google LLC | AI processing as a downstream Gemini model provider through OpenRouter. | Global, depending on provider routing; data may be processed wherever Google or its agents maintain facilities. | Google Data Processing Addendum | Via OpenRouter; Data Privacy Framework and SCCs where the framework or adequacy does not apply. |
| Logo.dev (Logodev, Inc.) | Retrieval and serving of company logos using company domains. | United States. | https://www.logo.dev/legal/dpa | EU SCCs and UK Addendum. |
| Nango Inc. | User-initiated connector authorisation, encrypted OAuth and API credential storage, and API proxying. | United States for Nango Cloud, hosted on AWS. | https://nango.dev/terms/ | EU SCCs and UK Addendum. |
| OpenRouter, Inc. | AI inference gateway and routing of prompts and responses to selected model providers. | United States, using Google Cloud US regions. | https://openrouter.ai/data-processing-agreement | EU SCCs and UK Addendum. |
| Plain (Not Just Tickets Ltd) | In-app customer support chat, customer identity, and support communications. | United Kingdom and EEA, with some US onward processing. | https://www.plain.com/legal/dpa | SCCs or UK IDTA for restricted onward transfers. |
| Recall.ai | Calendar integration and botless or visible-bot meeting capture, including authorisation tokens, meeting URLs and times, meeting and participant metadata, recordings, and transcripts. | Frankfurt, Germany (Recall.ai eu-central-1). | https://security.recall.ai/ | UK adequacy regulations; SCCs where required. |
| Stripe Payments Europe, Limited | Payment processing, hosted checkout, subscriptions, billing portal, and invoicing. | Ireland contracting entity; global processing by Stripe affiliates and service providers. | https://stripe.com/legal/dpa | Data Privacy Framework takes precedence; EU SCCs and UK Addendum as fallback. |
| Perplexity | Pre-call data generation. | US / EU | https://www.perplexity.ai/hub/security | Data Privacy Framework. |
| HubSpot | Optional CRM integration, we synchronise data to / from on our platform. | US/EU | https://legal.hubspot.com/dpa | Data Privacy Framework. |
| Salesforce | Optional CRM integration, we synchronise data to / from on our platform. | US/EU | https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/Agreements/data-processing-addendum.pdf | Data Privacy Framework; SCCs and UK Addendum as fallback. |
| Merge.dev | Unified API for alternative CRMs. We synchronise data to various CRMs via this platform. | US/EU | https://www.merge.dev/legal/data-processing-agreement | EU SCCs and UK Addendum. |
| Pusher | Live browser updates via WebSockets from our APIs | US/EU | https://pusher.com/legal-archived/terms-of-service/ | Data Privacy Framework. |
| Temporal | In house deployment. Utilised for long running tasks / data processing. | Internal AWS VPC | https://temporal.io/images/temporal-data-processing-agreement-10-10-24.pdf | Not applicable. |
