Legal

Data Processing Addendum

Effective Date: September 8, 2026  ·  MF Automations LLC

This Addendum forms part of the Terms of Service between MF Automations LLC ("Processor") and the customer ("Controller") and governs Processor's handling of personal information contained in Customer Data.

1. Roles

Controller determines the purposes and means of processing personal information collected by its AI Operator. Processor processes that information only on Controller's documented instructions, which consist of the Terms, this Addendum, Controller's account configuration, and any written instruction Controller gives. Processor will notify Controller if an instruction appears to violate applicable law.

For purposes of the CCPA and similar state laws, Processor acts as a service provider. Processor does not sell or share personal information, does not retain, use, or disclose it for any purpose other than performing the Services, does not combine it with information from other sources except as permitted, and certifies that it understands and will comply with these restrictions.

2. Scope of processing

ItemDetail
Subject matterProvision of AI operator, telephony, messaging, and automation services.
DurationThe term of the Terms, plus the deletion window in section 8.
Nature and purposeReceiving, transcribing, storing, analyzing, and responding to communications; executing configured workflows.
Categories of data subjectController's customers, prospects, callers, message recipients, and personnel.
Categories of personal informationName, phone number, email, postal address, voice recording, transcript, message content, appointment and service details, and any other information a data subject volunteers during a communication.
Sensitive informationNot requested or required. Controller must not configure an AI Operator to solicit sensitive categories without a separate written agreement.

3. Confidentiality

Processor ensures that personnel authorized to process personal information are bound by confidentiality obligations and receive appropriate training. Access is granted on a least-privilege, need-to-know basis.

4. Security measures

Processor implements and maintains appropriate technical and organizational measures, including: encryption in transit (TLS 1.2 or higher); encryption at rest for credentials and sensitive stores; role-based access control with individual accounts; multi-factor authentication on administrative access; network segmentation of production systems; logging and monitoring of access to production data; regular patching; and periodic review of access rights. See our Security Overview for the current description.

5. Subprocessors

Controller authorizes Processor to engage the subprocessors listed at Subprocessors. Processor will impose data protection obligations on each subprocessor no less protective than this Addendum and remains liable for their performance. Processor will give Controller at least 30 days' notice before adding or replacing a subprocessor. Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Controller may terminate the affected Services without penalty.

6. Data subject requests

Taking into account the nature of the processing, Processor will assist Controller by appropriate technical and organizational measures in responding to requests to access, correct, delete, or port personal information, and will make available the tools needed to do so. If Processor receives a request directly, it will not respond substantively and will forward it to Controller without undue delay.

7. Personal data breach

Processor will notify Controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Controller's personal information. The notice will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. Processor will assist Controller with its own notification obligations.

8. Deletion and return

On termination, and at Controller's election, Processor will delete or return Customer Data. Absent an election, Processor will delete it within 30 days of termination, except copies required to be retained by law and copies held in routine backups, which are overwritten on the normal backup rotation and remain subject to this Addendum until then.

9. Audit

Processor will make available information reasonably necessary to demonstrate compliance with this Addendum, and will respond to a security questionnaire no more than once per year. Controller may conduct an on-site audit on 30 days' notice, no more than once per year, at Controller's expense, during business hours, subject to confidentiality and to not disrupting operations — or more often if required by a supervisory authority or following a breach.

10. International transfers

Processor stores and processes Customer Data in the United States. Where personal information is transferred from a jurisdiction requiring a transfer mechanism, the parties will enter into the applicable standard contractual clauses, which are incorporated by reference on execution.

11. Precedence

Where this Addendum conflicts with the Terms of Service regarding the processing of personal information, this Addendum controls. Otherwise the Terms control. Liability under this Addendum is subject to the limitations in Section 14 of the Terms.

12. Signature

This Addendum is accepted by using the Services. A countersigned copy for procurement purposes is available on request from [email protected].

MF Automations LLC · 233 NE 27th St, Miami, FL 33137 · [email protected] · (305) 965-9624