EntBox AI
HomeCost CalculatorCareersPrivacy PolicyDPA

EntBox Ai Inc.

Global Privacy Policy

Effective date: July 31st, 2026·Last updated: August 3rd, 2026

Privacy PolicyData Processing Addendum

1. Introduction and Scope

EntBox Ai Inc. (“EntBox,” “we,” “us” or “our”) provides the EntBox AI Platform and related websites and services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose and protect Personal Data, and the rights and choices available to individuals. This is our single, universal global Privacy Policy — it is not tailored to any individual customer, and it is the policy our Master Services Agreement (and any other customer agreement) references when we commit to handle Personal Data in accordance with our Privacy Policy and applicable law. Capitalized terms not defined here have the meanings given in the Agreement.

Controller vs. processor. This Policy describes our practices where we act as a Controller — for example, Personal Data we collect from website visitors, prospective customers, job applicants, and the administrators and users of Customer accounts. Where our Customers submit Personal Data into the Platform for processing (e.g., their own end-customer records, tickets, or billing data), we act as a Processor on that Customer’s behalf, and that processing is governed by our Data Processing Addendum and the Customer is the Controller pursuant to its own privacy policy, not this one.

2. Who We Are and How to Reach Us

Data controller: EntBox Ai Inc., 2560 Anthem Village Drive, Ste 130, Henderson, NV 89052. For privacy questions or to exercise your rights, contact us at privacy@entbox.ai or the addresses in Section 16. Where we process EEA/UK personal data on behalf of a customer (as a Processor), that processing is governed by our Data Processing Addendum.

3. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information — from you directly, automatically through your use of the Services, and from third parties such as our customers, recruiters and service providers:

CategoryExamplesTypical source
Identifiers & contact dataName, email, phone, employer, job title, account username.You; our customer (account admin).
Account & profile dataLogin credentials, roles/permissions, preferences, support history.You; the Services.
Billing & transaction dataBilling contact, plan, invoices. Fees are invoiced (ACH/wire/check); we do not process card data.You.
Usage & device dataIP address, device/browser, log data, pages viewed, feature usage.Automatic via the Services.
CommunicationsEmails, support tickets, chat, and call transcripts, voice content and AI-generated summaries where applicable.You; communications providers.
Marketing dataMarketing preferences, event/webinar registrations.You; marketing tools.
Recruitment & hiring dataFor job applicants and prospective/current employees and contractors: contact details, CV/résumé, employment and education history, skills, references, interview notes and assessments, and right-to-work / eligibility information.You (applicant); recruiters/agencies; references.

We collect recruitment & hiring data to evaluate applications and manage the recruitment, hiring and onboarding of employees and contractors, including future and prospective personnel. We do not intentionally collect special-category / sensitive personal information through our own Controller activities. We do not direct the Services to children (see Section 13). We do not collect or use biometric identifiers (such as voiceprints or faceprints) to identify individuals in providing the Services.

4. How We Use Personal Information

  • Provide, operate, maintain and secure the Services and customer accounts;
  • Authenticate users, manage access, and prevent fraud and abuse;
  • Process billing, invoicing and payments;
  • Provide customer support and respond to enquiries;
  • Recruit, evaluate and onboard employees and contractors, and manage applications and the hiring process;
  • Communicate about the Services, including service and security notices, and — where permitted — marketing;
  • Analyze and improve the Services, including aggregated and de-identified analytics;
  • Comply with legal obligations and enforce our agreements; and
  • Other purposes disclosed at the point of collection or with your consent.

5. Legal Bases for Processing (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing and operating the Services; account administration; billingPerformance of a contract (Art. 6(1)(b)).
Security, fraud prevention, service improvement, basic analyticsLegitimate interests (Art. 6(1)(f)).
Recruitment and hiring of employees and contractorsSteps prior to entering a contract and/or legitimate interests (Art. 6(1)(b)/(f)); legal obligation (Art. 6(1)(c)) where applicable, e.g., right-to-work checks.
Marketing communicationsConsent (Art. 6(1)(a)), where required.
Legal, tax and regulatory complianceLegal obligation (Art. 6(1)(c)).

6. AI Features and Automated Processing

The EntBox AI Platform uses artificial-intelligence and large-language-model technology to provide its features. The following describes our approach; for Personal Data processed inside the Platform on a Customer’s behalf, the DPA and the Model-Provider terms control.

  • AI Providers. The Services send inputs — which may include support queries and knowledge-base content — to our AI subprocessors to generate responses, including for knowledge-base retrieval (RAG), which is an active feature. Our AI subprocessors are identified in the subprocessor table in Section 8.
  • Training. As of the Last updated date of this Policy, we do not use your Personal Data to train AI models.
  • Accuracy. AI outputs are probabilistic and may be inaccurate or incomplete; they are intended to be reviewed by a human before reliance.
  • Automated decision-making. We do not use the Services to make decisions producing legal or similarly significant effects about individuals based solely on automated processing without human involvement. Where AI features assist a decision, a human reviews the output before any action is taken. Individuals in the EEA/UK have the right not to be subject to solely automated decisions with legal or similarly significant effect, and, where applicable state law provides, you may have the right to opt out of certain profiling; to exercise these rights, contact us as described in Section 16.

7. Cookies and Similar Technologies

Our website uses cookies and similar technologies (such as local storage) only as necessary to operate the site, maintain security and session integrity, and keep you signed in where you have an account. Cookies are small text files placed on your device; similar technologies perform comparable functions.

We do not use cookies or similar technologies for advertising, cross-site tracking, or behavioral profiling. We do not use cookies to sell Personal Data or to "share" it for cross-context behavioral advertising.

Because we set only strictly necessary cookies, we do not display a consent banner. You can block or delete cookies through your browser settings; doing so may affect how the site functions. If we introduce analytics, functional or other non-essential cookies in future, we will update this Policy and, where required by law, obtain your consent before those cookies are set.

8. How We Disclose Personal Data

We disclose Personal Data to service providers and subprocessors that perform functions on our behalf, to corporate affiliates, in connection with a corporate transaction, to comply with law, and with your consent. We do not sell Personal Data.

Key service providers and subprocessors include:

SubprocessorFunction
Google Cloud Platform (Google LLC)Cloud hosting and infrastructure (US regions); each customer tenant is provisioned in its own Google Cloud project.
AnthropicAI model inference (Claude): support, agent-search, and knowledge-base retrieval responses.
OpenAIAI embeddings for knowledge-base retrieval (RAG); ingested knowledge-base and support content, and end-user search queries.
DeepgramSpeech-to-text and text-to-speech for the voice/IVR product, where enabled.
TwilioTelephony/voice (IVR), SMS and click-to-call, where enabled.
ResendOutbound customer email, where enabled.
Google (Gmail API)Outbound customer email for tenants configured to send via Gmail, where enabled.
GoHighLevelCRM synchronization (contact records, opportunity/pipeline stage, tags), where enabled.
Google Maps PlatformAddress geocoding, where enabled; full customer service addresses.
SlackDelivery of notification content to a customer or Entbox workspace, where enabled.
US Census Geographic CoderAddress geocoding fallback where no Maps key is configured; customer service addresses.

9. International Data Transfers

We are based in the United States and process Personal Data in the U.S. (our cloud regions are in the United States). Where we process Personal Data on behalf of a Customer that includes EEA, UK or Swiss Personal Data, that processing is governed by our Data Processing Addendum, and transfers rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.

10. Data Retention

We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy. As general guidance: Customer account and Services data is retained for the term of the Customer Agreement and for a limited period afterwards, in accordance with the Customer Agreement; database backups cycle out on an approximately 7-day schedule; website, prospect and marketing data is retained until no longer needed or until you opt out; and data of unsuccessful job applicants is retained for approximately 12 months. We may retain information longer where required by law or to resolve disputes or enforce our agreements.

11. Security and Data Breach Notification

We maintain an information-security program with administrative, technical and physical safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration and destruction. Our Services are hosted on Google Cloud Platform. These safeguards include encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+ at the public edge, with enforced SSL on all customer production database connections), role-based access controls, and the technical and organizational measures described in our Data Processing Addendum, overseen by our security lead. As of the date of this Policy we are working toward SOC 2 and ISO/IEC 27001 certification but have not completed a SOC 2 audit or an ISO/IEC 27001 certification; we do not represent certification until obtained. No method of transmission or storage is completely secure.

If we become aware of a Personal Data breach affecting your Personal Data, we will investigate, take steps to mitigate it, and notify affected individuals, applicable authorities and affected customers without undue delay and as required by applicable law. Where we act as a Processor on a Customer’s behalf, we will notify that Customer without undue delay in accordance with the DPA so they can meet their own notification obligations.

12. Your Privacy Rights and Choices

Subject to applicable law and verification of your identity, you may have rights to access, correct, delete, port, restrict or object to the processing of your Personal Data, and to withdraw consent. To exercise rights, contact us as described in Section 16. We will not discriminate against you for exercising your rights.

12(a). EEA, UK and Switzerland

If you are in the EEA, UK or Switzerland, you have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your supervisory authority. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

12(b). California (CCPA / CPRA)

California residents have the right to know the categories and specific pieces of Personal Data we collect, the right to delete and to correct, and the right to opt out of the “sale” or “sharing” of Personal Data and to limit use of sensitive Personal Data. We do not sell Personal Data and do not “share” it for cross-context behavioral advertising. The categories we collect and disclose are described in Sections 3 and 8. You may use an authorized agent to submit requests.

12(c). Other U.S. states and jurisdictions

Residents of other U.S. states with comprehensive privacy laws, and individuals in other jurisdictions, may have similar rights, including rights to access, correct, delete and opt out of certain processing. We honor these rights as applicable law requires.

13. Children’s Privacy

The Services are not directed to children and are intended for business use only. We do not knowingly collect Personal Data from children under 18. If you believe a child has provided us Personal Data, contact us and we will take appropriate steps to delete it.

14. Third-Party Links and Services

The Services may link to third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.

15. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Prior versions of this Policy are available on request at privacy@entbox.ai. Your continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

16. How to Contact Us

  • Privacy enquiries and rights requests: privacy@entbox.ai
  • Postal: EntBox Ai Inc., 2560 Anthem Village Drive, Ste 130, Henderson, NV 89052

Privacy Policy

  • 1.Introduction and Scope
  • 2.Who We Are and How to Reach Us
  • 3.Personal Information We Collect
  • 4.How We Use Personal Information
  • 5.Legal Bases for Processing (EEA / UK)
  • 6.AI Features and Automated Processing
  • 7.Cookies and Similar Technologies
  • 8.How We Disclose Personal Data
  • 9.International Data Transfers
  • 10.Data Retention
  • 11.Security and Data Breach Notification
  • 12.Your Privacy Rights and Choices
  • 13.Children’s Privacy
  • 14.Third-Party Links and Services
  • 15.Changes to This Policy
  • 16.How to Contact Us
Data Processing Addendum ↓

EntBox Ai Inc.

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Master Services Agreement (the “Agreement”) between EntBox Ai Inc. (“EntBox,” “Provider” or “Processor”), a Nevada corporation with its principal place of business at 2560 Anthem Village Drive, Ste 130, Henderson, NV 89052, and the customer identified in the Agreement (“Customer” or “Controller”). It applies to the extent Provider Processes Personal Data on Customer’s behalf in connection with the EntBox AI Platform and Services. Privacy inquiries may be directed to privacy@entbox.ai. Capitalized terms not defined here have the meanings given in the Agreement.

1. Definitions

“Applicable Data Protection Laws” means all privacy, data protection, cybersecurity and data-breach-notification laws applicable to the Processing of Personal Data under the Agreement, including (as applicable), but not limited to the EU GDPR, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and other U.S. state privacy laws.

“Personal Data” means any Customer Data (as defined in the Agreement) that relates to an identified or identifiable natural person and that Provider Processes on Customer’s behalf under the Agreement.

“Processing” (and “Process”) has the meaning given under Applicable Data Protection Laws and includes any operation performed on Personal Data.

“Controller,” “Processor,” “Data Subject” have the meanings given under Applicable Data Protection Laws; “Business” and “Service Provider” under U.S. state laws map to Controller and Processor respectively.

“Subprocessor” means any third party engaged by Provider to Process Personal Data on Customer’s behalf.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Provider.

“Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission for the transfer of personal data to third countries (Module Two: Controller-to-Processor), and the UK International Data Transfer Addendum where UK data is transferred.

2. Roles of the Parties

2.1 Processor. For Personal Data that Customer or its Authorized Users submit into the Platform, Customer is the Controller (or Business) and Provider is the Processor (or Service Provider). Provider shall Process such Personal Data only on Customer’s documented instructions, which are given pursuant to the Agreement, the applicable Order Form(s), Customer’s configuration of the Services, and Annex 1, unless required to Process by law (in which case Provider will inform Customer unless legally prohibited).

2.2 Controller. Provider acts as an independent Controller for the limited Personal Data for which it determines the purposes, namely: (a) account administration and billing; (b) security, fraud prevention and abuse detection; and (c) operating, maintaining and securing the Services (including service reliability and, on an aggregated and de-identified basis, analytics). Provider’s Controller processing is described in its Privacy Policy.

2.3 Restrictions. Provider shall not: (a) sell Personal Data or “share” it for cross-context behavioral advertising; (b) retain, use or disclose Personal Data outside the direct business relationship or for any purpose other than providing the Services; or (c) combine Personal Data with data from other sources except as permitted by Applicable Data Protection Laws. Provider certifies it understands and will comply with these restrictions. The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subjects are set out in Annex 1.

2.4 Sensitive and special-category data. Customer shall not submit to the Services any special-category or sensitive personal data — including health or “consumer health” data, biometric identifiers, precise geolocation, or children’s data — except where expressly agreed in the applicable Order Form with any additional safeguards specified there. Customer is responsible for providing all notices and obtaining all consents required for the Personal Data it submits. Provider does not intentionally collect or process special-category or sensitive personal data in providing the Services and does not use Customer Data to create biometric identifiers.

3. Provider (Processor) Obligations

Provider shall:

  • process Personal Data only on Customer’s documented instructions, and promptly inform Customer if, in Provider’s opinion, an instruction infringes Applicable Data Protection Laws;
  • ensure persons authorized to Process Personal Data are bound by confidentiality obligations and, as a formal security-awareness training program is established, will receive appropriate privacy and security training, and access Personal Data only on a need-to-know basis;
  • implement and maintain the technical and organizational security measures in Annex 2, consistent with the security measures required under the Agreement;
  • taking into account the nature of the Processing, assist Customer by appropriate measures to respond to Data Subject requests (Section 7) and to meet Customer’s obligations regarding security, breach notification, data protection impact assessments and prior consultation (Sections 6 and 8);
  • make available to Customer information reasonably necessary to demonstrate compliance with this DPA (Section 11); and
  • at Customer’s choice, return or delete Personal Data on termination (Section 10).

4. Security Measures

Provider shall implement and maintain the technical and organizational security measures described in Annex 2 to ensure a level of security appropriate to the risk. In determining what is appropriate, Provider takes into account the current state of technology, the cost of implementation, the nature, scope, context and purposes of the Processing, and the level of risk to affected individuals. Provider regularly tests and evaluates the effectiveness of these measures and may update them from time to time, provided any change does not materially reduce the overall level of security. The measures in Annex 2 are the same measures referenced in the Agreement and summarized in the Privacy Policy.

Switzerland. Where Personal Data originating from Switzerland is transferred, the EU SCCs apply with the following adaptations: (a) the Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for Swiss transfers; (b) references to the GDPR are read as references to the Swiss Federal Act on Data Protection (FADP) where the FADP applies; and (c) the term “Member State” does not prevent Swiss-resident data subjects from enforcing their rights in their place of habitual residence.

5. Subprocessors

Customer provides general authorization for Provider to engage Subprocessors to Process Personal Data, provided that Provider: (a) maintains an up-to-date list of its Subprocessors in Annex 3 (or at a location Provider makes available) and updates that list before a new or replacement Subprocessor begins Processing Personal Data; (b) makes the then-current list available to Customer, including, where offered, a means for Customer to subscribe to updates — it is Customer’s responsibility to review the then-current list, and Customer may object to a new or replacement Subprocessor on reasonable data-protection grounds within a reasonable period after the list is updated; (c) imposes data-protection obligations on each Subprocessor that are no less protective than those in this DPA; and (d) remains fully liable to Customer for each Subprocessor’s acts and omissions.

6. Breach Notification

Provider shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of (a) a confirmed Personal Data Breach affecting Customer’s Personal Data, or (b) any other confirmed security breach affecting Customer Data, whether or not the affected data constitutes Personal Data. The notification shall describe, to the extent known: the nature of the breach and categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it and mitigate harm; and a contact point. Provider shall cooperate with Customer and take reasonable steps to mitigate and remediate. Provider’s notification is not an acknowledgement of fault or liability.

7. Data Subject Requests

Provider shall, taking into account the nature of the Processing, provide reasonable assistance to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws. Such assistance may include locating and exporting relevant Customer Data by reasonable means available to Provider. Where responding to a request requires action that Provider’s standard functionality does not support, Provider will assist Customer on a commercially reasonable, good-faith basis. If Provider receives such a request directly, it shall not respond except on Customer’s documented instructions or as required by law, and shall promptly forward the request to Customer.

8. Data Protection Impact Assessments (“PIAs”) and Consultation

Provider shall provide reasonable assistance to Customer with any PIAs and prior consultations with supervisory authorities that Customer reasonably considers required, in each case solely in relation to the Processing of Personal Data by Provider and taking into account the information available to Provider.

9. International Transfers

Where Provider Processes Personal Data originating from the EEA, UK or Switzerland in a country that has not received an adequacy decision, the Parties agree that the Standard Contractual Clauses (Module Two: Controller-to-Processor) and, for UK data, the UK International Data Transfer Addendum, are incorporated into this DPA and completed as set out in Annex 4. In the event of conflict, the SCCs prevail with respect to the transfers they govern. Processing occurs in the United States; EU data residency is not offered.

10. Return or Deletion of Personal Data

On expiry or termination of the Agreement, Provider shall, at Customer’s written request and using commercially reasonable, good-faith efforts, return and/or delete all Personal Data Processed on Customer’s behalf, and delete existing copies unless retention is required by law. This obligation is consistent with, and additional to, the transition and export assistance provided under the Agreement.

11. Audits and Information

Provider shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, on reasonable prior notice, no more than once per year (except where required by a supervisory authority or following a Personal Data Breach), subject to confidentiality and to reasonable limits protecting other customers’ data. Where available, Provider may satisfy audit requests by providing its then-current third-party audit reports or certifications once obtained.

12. AI Subprocessor Processing

The Services use third-party AI subprocessors, identified in Annex 3, to deliver AI features. In providing the Services, Provider transmits Customer inputs — which may include support queries and knowledge-base content — to the applicable AI subprocessor to generate responses, including for knowledge-base retrieval (RAG). A truncated search-query string (up to approximately 80 characters) may be retained in operational logs for approximately 30 days.

From the effective date of the Agreement, Provider does not use Customer Data that identifies, or could reasonably identify, the Customer or any individual to train Provider’s or any third party’s AI models, and does not permit any AI subprocessor to use such Customer Data transmitted through the Services to train that subprocessor’s models. Provider may use aggregated and de-identified data to operate, secure and improve the Services. Customer Data is otherwise processed by the applicable AI subprocessor at inference time only.

Provider does not use the Services to carry out solely automated decision-making producing legal or similarly significant effects on Data Subjects on Customer’s behalf. Any profiling is limited to what Customer configures and instructs.

13. Liability; Order of Precedence

This DPA is subject to the limitations and exclusions of liability set out in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls; in all other respects the Agreement controls. The SCCs prevail over both with respect to the transfers they govern.

14. Term and General

This DPA takes effect on the Effective Date of the Agreement and remains in effect for as long as Provider Processes Personal Data on Customer’s behalf; provisions that by their nature should survive (including Sections 10 and 11) survive termination. This DPA may be executed as part of, or as an addendum to, the Agreement.

Annex 1 — Details of the Processing

Subject matterProvision of the EntBox AI Platform and Services to Customer under the Agreement.
DurationThe term of the Agreement, plus any period during which Provider retains Personal Data.
Nature and purposeHosting, storage, support/ticketing, CRM, scheduling, billing, voice/IVR, AI triage/routing and related processing as deployed for Customer (varies by instance).
Types of Personal DataIdentifiers and contact data; account/profile data; billing and transaction data; usage/device/log data; communications (email, tickets, chat, voice content, call transcripts and AI-generated summaries); and records migrated from Customer’s legacy systems. If any special-category data is in scope, it is listed in the Order Form with additional safeguards.
Categories of Data SubjectsCustomer’s employees and contractors; Customer’s own customers and end-users; prospective customers; and vendors, as reflected in the data Customer submits to the Platform.
Data location / residencyProcessing in the United States. Where Personal Data includes EU/UK-origin data, transfers rely on the SCCs / UK IDTA (Annex 4). EU data residency is not offered.
SubprocessorsSee Annex 3.
FrequencyContinuous, for the duration of the Agreement.

Annex 2 — Technical and Organizational Security Measures

Hosting & tenant isolation. Google Cloud Platform; each customer tenant is provisioned in its own Google Cloud project. Certain shared operational services — attachment storage, the shared task/MCP service and its database, and a database-backup bucket — are currently hosted in a shared project and are being migrated to per-tenant isolation.

Access control & authentication. Application-level role-based access control (RBAC); GCP IAM governs infrastructure; authentication via Google Identity Platform (OAuth/OIDC), with passwords stored as salted scrypt hashes (Provider stores no raw passwords). Enterprise SSO (OIDC) is available and can be enabled per customer on request.

Encryption. At rest: AES-256 (Google-managed keys; customer-managed keys not configured). In transit: TLS 1.2+ at the public edge, with enforced SSL on all customer production database connections (server-side enforcement, TLS 1.2+); the customer production databases accept only TLS-encrypted connections.

Application security. Changes are made via pull requests and peer-reviewed as a matter of practice (not gated or separately recorded); automated secret detection and dependency/software-composition scanning across git history; continuous cloud-posture scanning; application-level rate limiting; HMAC-signed tokens with timestamp validation on administrative endpoints. Formal SAST/DAST in CI and a secure-SDLC policy are being established.

Vulnerability & patch management. Continuous internal scanning with severity-classified findings; no independent third-party penetration test to date; formal remediation SLAs are being established.

Logging & monitoring. Cloud Audit Logs (Admin Activity) always-on and retained approximately 400 days; operational logs retained approximately 30 days; automated log-based security alerting in the customer production environments (internal and non-production projects are not uniformly covered); SIEM export supported via log sinks.

Personnel security. Personnel are bound by written non-disclosure / confidentiality obligations and access Customer data on a need-to-know basis. Background checks are not performed. A formal security-awareness training program is being established.

Endpoint & device security. No centrally managed MDM / endpoint-protection program is currently in place; device posture is not centrally managed.

Backup & recovery. Automated daily encrypted backups with recent daily backups retained; point-in-time recovery and deletion protection enabled on the customer production databases. Recovery-point/recovery-time capabilities align with the underlying Google Cloud Platform service terms; Provider has not separately committed a numeric RPO/RTO and restore procedures are not yet tested on a documented cadence.

Disaster recovery & continuity. Single-region deployment; no multi-region failover today. Formal DR and business-continuity plans are being established.

Incident response. Incident-response procedures are being formalized; automated alerting is in place for the customer production environments; the 72-hour customer breach-notification obligation in Section 6 applies.

Certifications / attestations. Provider has not completed a SOC 2 audit or an ISO/IEC 27001 certification and is not itself the subject of an audit engagement. Provider is the vendor/subprocessor (not the entity being certified) and provides subprocessor evidence to support Customer’s own audits and assessments.

Annex 3 — Approved Subprocessors

SubprocessorPurposeLocation
Google Cloud Platform (Google LLC)Cloud hosting and infrastructure; per-tenant GCP projects. Core.US
AnthropicAI model inference (Claude): support, agent-search, and knowledge-base retrieval responses. Core.US
OpenAIAI embeddings for knowledge-base retrieval (RAG): ingested knowledge-base and support content, and end-user search queries (free-text customer content). Core.US
DeepgramSpeech-to-text and text-to-speech for the voice/IVR product; raw caller audio and agent speech, where voice is enabled.US
TwilioTelephony/voice (IVR), SMS and click-to-call, where enabled.US
ResendOutbound customer email, where enabled.US
Google (Gmail API)Outbound customer email for tenants configured to send via Gmail, where enabled.US
GoHighLevelCRM synchronization (contact records, opportunity/pipeline stage, tags), where enabled.US
Google Maps PlatformAddress geocoding, where enabled; full customer service addresses. Distinct from the Google Cloud hosting relationship.US
SlackDelivery of notification content to a customer or Provider workspace, where enabled.US
US Census Geographic CoderAddress geocoding fallback where no Maps key is configured; customer service addresses.US

Core Subprocessors (Google Cloud Platform, Anthropic and OpenAI) apply to all deployments. The remaining Subprocessors apply only where the corresponding feature is enabled for the Customer, so not all Subprocessors listed above are engaged for every Customer. The Subprocessors active for a given Customer are identified in that Customer’s Order Form.

Annex 4 — International Transfer Mechanisms

Where EEA / UK / Swiss personal data is in scope, the Parties complete and incorporate the SCCs (Module Two: Controller-to-Processor) and, for UK data, the UK IDTA — including the module options, docking clause, Clause 7; Clause 9 (subprocessor authorization and notice period); Clause 11 (optional independent dispute resolution); Clause 17 (governing law); Clause 18 (forum); the UK IDTA tables; and the technical-measures reference to Annex 2.

Data Processing Addendum

  • 1.Definitions
  • 2.Roles of the Parties
  • 3.Provider (Processor) Obligations
  • 4.Security Measures
  • 5.Subprocessors
  • 6.Breach Notification
  • 7.Data Subject Requests
  • 8.Data Protection Impact Assessments (“PIAs”) and Consultation
  • 9.International Transfers
  • 10.Return or Deletion of Personal Data
  • 11.Audits and Information
  • 12.AI Subprocessor Processing
  • 13.Liability; Order of Precedence
  • 14.Term and General
  • Annex 1 —Details of the Processing
  • Annex 2 —Technical and Organizational Security Measures
  • Annex 3 —Approved Subprocessors
  • Annex 4 —International Transfer Mechanisms
Global Privacy Policy ↑
EntBox AI

The Institutional Intelligence Layer. A synthesis layer that connects every ticket, call, document, and decision your organization has ever made.

Built by EntBox AI

Platform
ServicesAI CapabilitiesArchitectureCompare
Company
AboutCareersBlogContact
Resources
DocumentationCase StudiesAPI ReferenceSupport
© 2026 EntBox AI. All rights reserved.
PrivacyDPATermsSecurity