Data Processing Agreement
Last updated 2026-08-19. This page is written to reflect the system's actual current behavior — not aspirations.
This Data Processing Agreement (DPA) forms part of the Terms of Service and reflects the obligations of Anchor AI LLC as a data processor under GDPR Article 28 and the UK Data Protection Act 2018. It applies to any customer whose personal data is processed within the European Union, the European Economic Area, or the United Kingdom.
01Scope and roles
Anchor AI LLC, dba Growth Agent System ("Processor") processes personal data on behalf of the customer ("Controller") for the purpose of providing the Growth Agent System voice agent platform. The Controller determines the purposes and means of processing; the Processor processes data only on documented instructions from the Controller.
This DPA applies to all processing of personal data carried out by the Processor on behalf of the Controller, including data collected through lead forms, call recordings, appointment bookings, and account information.
02Categories of data
The Processor processes the following categories of personal data on behalf of the Controller:
- Lead contact data: name, phone number, business name, business location, and the prospect's stated problem.
- Call interaction data: call transcripts, call outcomes, appointment details, and calendar events.
- Account data: email address, authentication identifiers, and subscription status.
- Attribution data: referral source, campaign identifiers, and UTM parameters.
The Processor does not process special categories of personal data (Article 9) unless explicitly agreed in writing for the Clinical Front Desk product, which operates under HIPAA-scoped controls.
03Purpose and duration
Processing is limited to providing the contracted service: calling web leads back, qualifying them, booking appointments, and reporting outcomes. The Processor does not use the data for any other purpose, including its own marketing or product development, without separate consent.
Data is retained for the duration of the Controller's subscription plus 30 days, after which it is automatically deleted unless the Controller requests earlier deletion through the self-service account deletion endpoint.
04Sub-processors
The Processor engages the following sub-processors to deliver the service:
- Google Cloud Platform — infrastructure hosting (Cloud Run, Cloud SQL, Cloud Armor). GCP is certified under ISO 27001, SOC 2, and ISO 27017.
- Google Firebase — authentication and identity management.
- Vapi, Inc. — voice agent infrastructure (call orchestration, speech-to-text, text-to-speech). Each Controller is provisioned a distinct, dedicated Vapi sub-processor account instance.
- Stripe, Inc. — payment processing. Stripe is PCI DSS Level 1 certified.
- Google Calendar API — appointment synchronization, when the Controller has connected their calendar.
- Resend, Inc. — transactional and lifecycle email delivery.
The Controller is notified of any new sub-processor at least 30 days in advance. The Controller may object to a new sub-processor by notifying legal@growthagentsystem.com, in which case the Processor will either provide an alternative or the Controller may terminate the service with a pro-rata refund.
05Security measures
The Processor implements the following technical and organizational security measures:
- Encryption in transit: TLS 1.2+ for all connections.
- Encryption at rest: Cloud SQL and Cloud Storage encrypt all stored data using AES-256. Sensitive call data (transcripts, caller name, caller phone, call summaries) receives additional application-level Fernet encryption (AES-128-CBC + HMAC-SHA256).
- Row-level security: PostgreSQL RLS enforces tenant isolation at the database engine level.
- Access control: Firebase Admin SDK with custom claims; admin access requires multi-factor authentication.
- PII redaction: all application logs pass through a PII scrubbing layer before persistence.
- Network security: Cloud Armor WAF; origin firewall restricts access to known networks.
- Vulnerability scanning: automated security scanner runs on every commit (Sentinel).
06International transfers
The Processor is based in the United States and processes data on Google Cloud Platform infrastructure in the United States. Transfers from the EU/UK to the US are made under the EU-US Data Privacy Framework (where the Processor is certified or relies on a certified sub-processor) or, where the DPF does not apply, under the Standard Contractual Clauses (SCCs Module 2: Controller-to-Processor) as adopted by the European Commission, incorporated herein by reference as the default fallback mechanism for all EU/UK Controllers.
Vapi also processes data in the United States. The Processor has executed or relies on sub-processor SCCs for these transfers.
07Data subject rights
The Processor assists the Controller in fulfilling data subject requests, including:
- Access (Article 15): the Controller may export all tenant data via
GET /api/v1/account/export. - Erasure (Article 17): the Controller may erase tenant data via
DELETE /api/v1/account. Erasure applies three categories: (a) Erased — personal data in tenant tables is hard-deleted; (b) Anonymized — financial and audit records (commission ledger, conversion events, dispute logs, fraud warnings) are retained with identifying columns removed under Article 17(3)(b) and (e); (c) Retained — contract and policy acceptance records and the webhook idempotency ledger are retained under Article 17(3)(b) and (e). Retained and anonymized records remain disclosable under Article 20. - Portability (Article 20): the export endpoint returns data in machine-readable JSON.
- Rectification (Article 16): the Controller may update lead and account data through the dashboard.
The Processor forwards any data subject request received directly to the Controller within 5 business days and does not respond to the data subject directly.
08Breach notification
The Processor notifies the Controller of any personal data breach within 72 hours of becoming aware of it, providing: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. Notification is sent to legal@growthagentsystem.com or the Controller's designated contact email.
09Audit and records
The Processor maintains records of processing activities under Article 30 and makes them available to the Controller on request. The Controller may audit the Processor's compliance with this DPA upon 30 days' written notice, subject to confidentiality obligations and the Processor's security requirements.
The Processor undergoes independent security assessments and shares relevant certifications (SOC 2, ISO 27001) with sub-processor coverage on request.
10Termination and deletion
On termination of the service, the Processor erases personal data processed on behalf of the Controller within 30 days, applying the three categories described in Section 07 (Erased, Anonymized, Retained). Records retained under GDPR Article 17(3)(b) or (e) — financial records for tax reporting, contract and policy acceptance records for legal claims defense, and the webhook idempotency ledger for service integrity — are kept only for as long as the legal obligation requires and are then deleted. The Controller may initiate immediate erasure through the self-service endpoint at any time during the subscription term.
A deletion confirmation is logged and provided to the Controller on request.