Legal · Last updated June 1, 2026

Data Processing Addendum

This Data Processing Addendum (“DPA”) supplements the Bobbuilt Terms of Service and forms part of the agreement between Bobbuilt, Inc. (“Processor,” “Bobbuilt”) and the customer entity identified in the applicable order form (“Controller,” “Customer”) for the processing of Personal Data in connection with the Services. Capitalized terms not defined here have the meaning given in the Terms of Service or in applicable Data Protection Laws.

1. Roles and scope

Customer is the Controller (or Processor on behalf of its own customers) of the Personal Data submitted to the Services. Bobbuilt acts as Processor (or Subprocessor) and processes Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by law.

2. Nature and purpose of processing

Bobbuilt processes Personal Data to provide and support the Services, including hosting and storing data, generating and routing leads, placing and recording calls (where enabled), running AI inference, sending transactional messages, and producing analytics. Processing continues for the duration of the Services and any post-termination retention period set out in the Terms.

3. Categories of data and data subjects

  • Data subjects: Customer’s end users, prospects, leads, employees, and contractors
  • Identification data: name, email address, phone number, postal address
  • Profile data: quiz responses, lead form answers, qualification status
  • Communications: call recordings (where enabled), transcripts, SMS, and email
  • Technical data: IP address, user agent, device identifiers, event timestamps

4. Customer responsibilities

Customer is responsible for the lawfulness of the Personal Data it submits, for obtaining all required notices and consents (including TCPA-compliant prior express written consent where applicable), and for honoring data subject requests directed to Customer. Customer must configure the Services and integrations consistent with Data Protection Laws.

5. Confidentiality and personnel

Bobbuilt ensures personnel authorized to process Personal Data are bound by written confidentiality obligations and have received appropriate training in data protection and information security. Access to Personal Data follows the principle of least privilege.

6. Security measures

Bobbuilt implements appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest
  • Logical separation of customer environments
  • Role-based access controls and mandatory MFA for production access
  • Centralized audit logging and continuous monitoring
  • Regular vulnerability scanning and annual third-party penetration testing
  • Documented incident response, business continuity, and disaster recovery plans
  • Background checks for personnel with production access, to the extent permitted by law

7. Subprocessors

Customer provides general authorization for Bobbuilt to engage subprocessors to process Personal Data. Bobbuilt maintains a current list of subprocessors and will provide at least 30 days’ notice before adding or replacing a subprocessor with material access to Personal Data. Customer may object on reasonable data protection grounds, in which case the parties will work in good faith to resolve, and absent resolution Customer may terminate the affected portion of the Services. Bobbuilt remains liable for the acts and omissions of its subprocessors.

8. International data transfers

Where Personal Data is transferred from the EEA, UK, or Switzerland to a country not deemed adequate, the parties incorporate the EU Standard Contractual Clauses (Module Two: Controller to Processor; Module Three: Processor to Processor as applicable), the UK International Data Transfer Addendum, and equivalent Swiss safeguards by reference. Bobbuilt will apply supplementary technical, contractual, and organizational measures as required.

9. Data subject requests

Taking into account the nature of the processing, Bobbuilt will provide reasonable assistance to enable Customer to respond to requests from data subjects exercising their rights under Data Protection Laws. Where a data subject contacts Bobbuilt directly, Bobbuilt will redirect them to Customer without undue delay.

10. Personal data breaches

Bobbuilt will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably necessary for Customer to meet its own breach notification obligations.

11. Audits

Bobbuilt will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including current SOC 2 Type II reports and security questionnaires under NDA. Where strictly required by Data Protection Laws, Customer may conduct an audit no more than once per year on at least 30 days’ written notice, during normal business hours, and at Customer’s expense.

12. Deletion and return

Upon termination or expiry of the Services, Bobbuilt will, at Customer’s election, delete or return Personal Data within 90 days, except where retention is required by law. Backups containing Personal Data are deleted in the ordinary course of backup rotation.

13. Liability and order of precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. In the event of any conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA prevails.

14. Request a signed DPA

To countersign this DPA or request a specific contractual variant (e.g. HIPAA BAA, sector-specific addendum), email the contact form at bobbuilt.io/contact with your legal entity name, jurisdiction, and the Services in scope.

Ready to build your book?

Talk with our team about how Bobbuilt fits your agency.

Book a 30-minute call