Data Processing Addendum
Version 1.1 · Effective August 19, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Servicebetween DIGITAL WARRIORS LLC, a Florida limited liability company with its registered address at 180 NE 29th St, Apt 330, Miami, FL 33137 ("Operator Base," "we," "us"), and the customer that has accepted those Terms ("Customer," "you").
It sets out the terms on which we process personal data on your behalf and is intended to satisfy Article 28(3) of Regulation (EU) 2016/679 (the "GDPR") and, where applicable, the UK GDPR. It applies automatically wherever your use of the Service involves personal data protected by those laws. If you need a countersigned copy for your records, email support@operatorbase.app.
Changes in this version
Version 1.1 supersedes version 1.0 of August 19, 2026. It adds commitments and does not withdraw any protection given in version 1.0. Six changes:
- Section 8 now states the sub-processor notice period as 30 days, which was previously only on the Sub-processor page, and states what happens when you object.
- Section 9 now states a 10 business day turnaround for the assistance we give you on a data subject request, and describes the self-service erasure control that went live in the AI agent platform on August 19, 2026, together with what erasure does not reach.
- Section 11now states an outer limit of 48 hours for breach notification, replacing an unqualified "without undue delay."
- Section 15 is new: how we handle a government or law enforcement request for your data, and our assessment of the laws we are subject to.
- Section 16 is new: our commitments as a service provider under the California Consumer Privacy Act and as a processor under the other United States state privacy laws.
- Section 14 now names the version and date of the Sub-processor page that Annex III incorporates, and prior versions of that page are archived at dated addresses.
Sections 15 and 16 are insertions, so what were sections 15 to 18 in version 1.0 are now sections 17 to 20. No text in those sections changed.
1. Definitions
- "Controller," "processor," "data subject," "personal data," "processing," and "supervisory authority" have the meanings given to them in the GDPR.
- "Customer Personal Data" means personal data contained in the Customer Data (as defined in the Terms) that we process on your behalf in providing the Service.
- "End Contact" means an individual your AI agents communicate with or hold a record about, such as a lead, prospect, or customer of your business.
- "Sub-processor" means a third party engaged by us to process Customer Personal Data.
- "Data Protection Law" means the GDPR, the UK GDPR, and any other data protection or privacy law applicable to our processing of Customer Personal Data under this DPA.
- "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
2. Roles of the parties
You are the controller. We are the processor. You determine the purposes and means of processing Customer Personal Data. We process it only to provide the Service to you and on your instructions.
This allocation applies in particular to data about your End Contacts. You decide which contacts enter the Service, what your agents say to them, which integrations receive their data, and how long you keep it. We hold that data on your behalf and have no independent relationship with your End Contacts.
We act as a controller, not a processor, for a narrow and separate set of data, which we process to operate our own business:
- Account data of the individuals who sign in to Operator Base on your behalf.
- Billing data.
- User Content in the operator app. The community posts, comments, direct messages, files, voice notes, and live call participation your people create inside the operator app are User Content as defined in section 4 of the Terms of Service. That content is created by your people for their own purposes inside a shared community we operate, not processed by us on your documented instructions, so we are the controller for it. It is a distinct category from both the account data above and the Customer Personal Data governed by this DPA, and it is not Customer Personal Data.
Processing of all three categories is governed by our Privacy Policy and not by this DPA.
You are responsible for establishing a lawful basis for the processing you instruct, for providing any notices your End Contacts are entitled to, and for ensuring you are permitted to transfer their data to us.
3. Subject matter, duration, nature, and purpose
- Subject matter. Our provision of the Service, an AI agent platform for building, deploying, and operating chat and voice agents and the contact records and conversations they generate.
- Duration. For as long as your subscription is active, plus the period described in section 12 for deletion or return.
- Nature of processing. Collection, recording, organization, structuring, storage, retrieval, use, transmission to the integrations you connect, generation of automated responses, transcription of voice calls, creation of text embeddings and summaries, and erasure or pseudonymization.
- Purpose. Providing, maintaining, and securing the Service as described in the Terms, and no other purpose.
4. Categories of data subjects and personal data
Categories of data subjects
- Your End Contacts: the leads, prospects, and customers your agents communicate with.
- Individuals whose details appear in content you upload, such as imported contact lists or knowledge base documents.
- Your personnel who use the Service, to the extent their data appears within Customer Personal Data rather than in the account data described in section 2.
Categories of personal data
- Identifiers and contact details: name, email address, telephone number, messaging handles, and external CRM identifiers.
- Communications content: the text of chat, SMS, email, and messaging conversations, voice call audio recordings, and call transcripts.
- Derived and inferred data: agent memory, conversation summaries, intent classifications, text embeddings, and appointment or opportunity records.
- Technical and metadata: timestamps, channel of origin, message delivery status, and session identifiers.
- Any other personal data you choose to place in the Service, including in custom fields, uploaded files, and agent instructions.
Special category data. The Service is not designed for special categories of personal data under Article 9, nor for personal data relating to criminal convictions under Article 10, nor for protected health information. You must not use the Service to process such data unless we have agreed to it in writing in advance.
5. Processing only on documented instructions
We process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which we are subject. Where a law requires us to process beyond your instructions, we will inform you of that legal requirement before processing, unless the law prohibits that notification on important grounds of public interest.
Your documented instructions comprise:
- the Terms of Service and this DPA;
- your configuration and use of the Service, including the agents you build, the instructions you give them, the model and voice providers you select, and the integrations you connect;
- any further written instruction you give us that we accept in writing.
We will notify you if, in our opinion, an instruction infringes Data Protection Law. We do not sell Customer Personal Data, and we do not use it to train generalized artificial intelligence or machine learning models of our own.
6. Confidentiality of personnel
We ensure that persons authorized to process Customer Personal Data are bound by an obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. We limit access to Customer Personal Data to those personnel who need it to provide, maintain, or secure the Service, and we remove that access when it is no longer required.
7. Security measures
We implement appropriate technical and organizational measures under Article 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
Those measures are described in detail on our Security page, which is incorporated into this DPA by reference and forms the technical and organizational measures annex required by Article 28(3)(c) and by the SCCs. It covers tenant isolation, encryption in transit and at rest, application-level encryption of the credentials you connect, log and error redaction, the append-only audit trail, access controls, and data residency. It also states plainly which certifications and controls we do not hold. We do not restate those measures here so that there is one source of truth that stays current.
We may update the measures over time, provided the updates do not materially reduce the overall level of security.
8. Sub-processing
General authorization. You give us general written authorization to engage sub-processors to process Customer Personal Data, subject to this section.
Current sub-processors. Our sub-processors are listed on the Sub-processor page. That page carries a version number, an effective date, and a changelog, and every prior version stays retrievable at its own dated address, so you can produce the exact list that was in force when you signed. This DPA incorporates version 1.0 of August 19, 2026 as Annex III. The current version of that page, together with its archive of prior versions, is the authoritative record of who processes Customer Personal Data on our behalf and when each one was added. The page also identifies the third-party integrations that receive data only when you connect them with your own credentials. Those integrations are not our sub-processors: you select them, you hold the contract with them, and we transmit data to them on your instruction.
Our obligations toward sub-processors.We impose on each sub-processor data protection obligations that are, in substance, no less protective than those in this DPA, by written contract. We remain fully liable to you for the performance of each sub-processor's obligations.
Notice of changes: 30 days. We give you at least 30 days advance written notice, at the email address on your account, before a new sub-processor begins processing Customer Personal Data. We update the Sub-processor page at the same time. The same 30 day notice applies where we replace a sub-processor with another performing the same function. Removing a sub-processor requires no notice, because it reduces the number of parties that reach your data.
The one exception is a sub-processor engaged to address an emergency affecting the security or availability of the Service, where we will give notice as soon as we reasonably can rather than in advance, and your objection right below applies from the date of that notice.
Objection. You may object to a new sub-processor on reasonable grounds relating to data protection by writing to support@operatorbase.app within the 30 day notice period. We will discuss the objection with you in good faith, which may include making a reasonable alternative arrangement available or offering a configuration that avoids the sub-processor. If we cannot resolve the objection by the end of that period, you may terminate the affected part of the Service without penalty and without any early termination charge for the remainder of the term, on written notice to us, and we will refund any prepaid fees covering the terminated portion after the termination date.
9. Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise rights under Articles 15 to 22 of the GDPR.
Our turnaround: 10 business days. Where you forward a data subject request to us and need our help to answer it, we will provide that assistance within 10 business days of receiving the request at support@operatorbase.app, or tell you within that period what we need from you and when we will complete it. This is our internal service level for assisting you. It is not the deadline you owe the data subject: as controller, Article 12(3) of the GDPR requires you to respond to the data subject without undue delay and in any event within one month of receiving their request. Our 10 business days sits inside your month so that you have time left to review what we produce and to reply.
What the Service lets you do yourself.A tenant administrator can export an account's data from the dashboard in a machine-readable format. That export covers the whole account, including the data of any individual data subject within it. Contact records can be viewed and corrected in the dashboard, which addresses rectification under Article 16. Since August 19, 2026, a tenant administrator holding the contact deletion permission can also erase an individual contact from the dashboard under Article 17. That control shows a preview of the records the erasure will affect before anything is destroyed, and then schedules the erasure with a cancellation window, seven days by default, during which nothing has been destroyed and the request can be withdrawn. You may set that window to zero if a request needs to be honored immediately.
What our team does on request. An export narrowed to a single data subject, for access requests under Article 15 and portability requests under Article 20, is produced by the Operator Base team rather than through a self-service control. Send the request to support@operatorbase.app and we will action it and confirm back to you. We will also run an erasure on your behalf if you would rather we did.
What erasure does not reach. These limits are stated in the contract rather than discovered later, and you should account for them when you answer a data subject:
- Erasure pseudonymizes the contact record and removes the identifiers attached to it, rather than deleting every underlying row.
- It does not reach copies held in the third-party systems you have connected, such as your CRM, telephony, or messaging providers. You remain responsible for erasure in those systems. If a contact is re-synchronized into the Service from a connected system after erasure, the record, and identifying details on it, can reappear.
- It is keyed to the contact record. A voice call record that is no longer linked to a contact cannot be matched to that contact and is not erased.
- Our audit trail is append-only and retained for six years as evidence of what happened to a record, including evidence of the erasure itself. Erasure removes the contact's name from the audit entries that are keyed to that contact. Audit entries keyed to something else, such as a conversation, can still contain the name, and those are not reached today. If you are asked whether every trace of a name is gone from our records, the accurate answer is that it is not.
We will tell you which of these apply to a specific request if you ask before you respond to the data subject.
Requests that come to us directly. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to confirm receipt and to direct them to you. We will notify you promptly and provide reasonable assistance in responding.
10. Assistance with Articles 32 to 36
Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR. This includes providing the information in this DPA and on our Security and Sub-processor pages for your data protection impact assessments and any prior consultation with a supervisory authority, and responding to reasonable security questionnaires.
11. Personal data breach
We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. We commit to 48 hours because Article 33 gives you, as controller, 72 hours to notify your supervisory authority, and that clock starts when you become aware. Notifying you inside 48 hours leaves you a full day to assess what we send and to make your own notification.
Our notification will describe, to the extent known at the time and updated as we learn more:
- the nature of the personal data breach;
- the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned;
- the likely consequences of the breach;
- the measures we have taken or propose to take to address the breach, including, where appropriate, measures to mitigate its possible adverse effects; and
- a contact point for further information.
Where we cannot provide all of that information within 48 hours, we notify you within 48 hours with what we know at that point and provide the rest in phases as it becomes available, rather than delaying the notification until the picture is complete.
We will assist you in meeting your own notification obligations to a supervisory authority under Article 33 and to affected data subjects under Article 34. Our notification to you is not an acknowledgement of fault or liability.
12. Deletion or return of data
On termination or expiry of the Service, you may export Customer Personal Data using the export function in the dashboard, as described in the Service Continuity and Data Portability section of our Terms of Service.
At your choice, we will delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies, unless applicable law requires us to retain it. Send a deletion or return instruction to support@operatorbase.app. Until you instruct us otherwise, Customer Personal Data remains in the Service so that your export tools continue to work.
Residual copies in routine backups are deleted on the ordinary backup rotation of our infrastructure provider and remain subject to this DPA for as long as they exist. Deletion under this section does not reach copies held in the third-party systems you connected; those are erased under your agreements with those vendors.
13. Audits and information rights
We make available to you the information necessary to demonstrate compliance with the obligations in Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice, we satisfy this in the first instance through this DPA, our Security page, our Sub-processor page, and by responding to reasonable written security questionnaires. We do not currently hold a third-party audit report such as SOC 2 or ISO 27001, and we do not represent that we do.
Where that documentation is not sufficient for your compliance obligations, you may conduct an audit on reasonable prior written notice, during business hours, no more than once in any twelve-month period, subject to confidentiality obligations, and in a manner that does not disrupt the Service or compromise the data of other customers. You bear your own costs and ours where an audit requires more than a reasonable amount of our time. A supervisory authority may exercise this right without the once-a-year limit where the law requires.
14. International transfers
Where processing happens.We process Customer Personal Data in the United States. The AI agent platform's application services and primary database run in the AWS us-east-1region. The operator app's backend, which also holds the sign-in accounts used across the Service, runs in a separate project in the us-west-2 region. Our sub-processors are listed with their processing locations on the Sub-processor page. We have not configured a European or other non-US region for any part of the Service. Our hosting and content delivery providers serve files and run edge code from the network location nearest the requesting device, which can be outside the United States; the systems that store Customer Personal Data remain in the regions named here. If you transfer personal data protected by the GDPR or UK GDPR to us, that data will be transferred to and processed in the United States.
Transfer mechanism. Where your use of the Service involves a transfer of personal data from the European Economic Area, Switzerland, or the United Kingdom to us in the United States, and that transfer is not otherwise covered by an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference and apply to that transfer, as follows:
- Module Two (controller to processor) applies, with you as data exporter and us as data importer.
- Clause 7, the docking clause, applies.
- Clause 9, sub-processors: Option 2, general written authorization, applies, with the notice and objection process set out in section 8 of this DPA.
- Clause 11: the optional independent dispute resolution wording does not apply.
- Clause 17, governing law, and Clause 18, choice of forum: the law and courts of the EU Member State of your establishment, or of Ireland where you are not established in the EU.
- Annex I (parties, description of transfer) is populated by sections 2, 3, and 4 of this DPA and by the contact details in section 20. Annex II (technical and organizational measures) is populated by our Security page as it stood on August 19, 2026. Annex III (sub-processors) is populated by version 1.0 of our Sub-processor page, effective August 19, 2026, archived at /subprocessors/2026-08-19.
- For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs applies to the SCCs as incorporated above. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
Where there is a conflict between the SCCs and this DPA in relation to a transfer covered by the SCCs, the SCCs prevail.
15. Government and law enforcement access requests
This section applies where a court, law enforcement agency, regulator, or other public authority makes a binding request for Customer Personal Data, whether by subpoena, warrant, court order, or any other legal process.
We tell you. We notify you of the request without undue delay, and before disclosing anything where that is possible, so that you can seek protective relief. We give you the information you need to respond, including what was requested and by whom, unless we are legally prohibited from providing it.
If we are prohibited from telling you. Where a legal prohibition prevents us from notifying you, we will use reasonable efforts to obtain a waiver of that prohibition, in order to communicate as much information to you as we can and as soon as possible. We will document our efforts so that we are able to demonstrate them to you and, on request, to a supervisory authority.
We challenge requests that are not lawful. We will review the legality of each request and will challenge it where we conclude, after an assessment of the circumstances, that the request is unlawful, overbroad, or inconsistent with the law of the European Union, the United Kingdom, or another applicable data protection law, including where a conflict of laws arises. We will pursue available avenues of appeal where there is a reasonable prospect of success. Where we are required to disclose while a challenge is pending, we will seek interim measures to suspend the effect of the request.
We disclose the minimum. Where we are ultimately compelled to disclose, we will provide only the minimum amount of Customer Personal Data necessary to respond, based on a reasonable interpretation of the request.
No direct or unfettered access. We do not give any public authority direct, blanket, or unrestricted access to Customer Personal Data or to the systems that hold it, and we have not built, and will not build, any mechanism into the Service for that purpose.
Our assessment of the laws we are subject to, for your transfer impact assessment. We have assessed the laws and practices of the United States that apply to us, taking into account the nature of the Service, the categories of Customer Personal Data described in section 4, and the safeguards described on our Security page. As at the effective date of this version, we have no reason to believe that those laws or practices prevent us from fulfilling our obligations under this DPA or under the SCCs, and we have received no order that would require us to act inconsistently with them. If at any point we have reason to believe that this has changed, including where we become subject to a law or measure that would prevent us from meeting those obligations, we will notify you without undue delay so that you can take steps to protect the data, up to and including suspending the transfer or terminating the affected part of the Service.
Nothing in this section requires either party to act unlawfully. This section supplements, and does not limit, Clauses 14 and 15 of the SCCs where the SCCs apply to a transfer under section 14.
16. United States state privacy laws
This section applies where your use of the Service involves personal information protected by a United States state privacy law. It sits alongside the GDPR terms above rather than replacing them, and where both apply to the same data, the stricter obligation governs. Terms used in this section that are defined in the applicable state law, such as "business," "service provider," "sell," "share," and "personal information," carry the meaning given in that law.
Which laws. We contract on these terms so that customers who are subject to a state privacy law have the service provider or processor terms that law requires them to put in place. We offer them under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under the comprehensive privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and Montana (MCDPA). Other states have passed comprehensive privacy laws with substantially similar controller and processor terms, and further states continue to do so. These commitments apply to any such law that applies to your use of the Service, whether or not that state is named here, so that this list going out of date cannot leave you without terms.
Roles. For Customer Personal Data, you are the business or controller and we are your service provider under the California Consumer Privacy Act and your processor under the other state laws named above. The categories of personal information we process, and the business purposes for which we process them, are those described in sections 3 and 4 of this DPA.
Our restrictions. With respect to Customer Personal Data, we:
- do not sell it and do not share it,as "sell" and "share" are defined in the applicable state law, and we receive no monetary or other valuable consideration for it. We do not use it for cross-context behavioral advertising or for targeted advertising;
- process it only for the limited and specified business purposes set out in this DPA and the Terms of Service, which is the provision of the Service to you, and for no other purpose;
- do not retain, use, or disclose it for our own commercial purposes, including our own product development or marketing, and do not use it to train generalized artificial intelligence or machine learning models of our own;
- do not retain, use, or disclose it outside the direct business relationship between you and us, except where the applicable state law expressly permits it;
- do not combine it with personal information we receive from, or on behalf of, another person, or that we collect from our own interactions with a consumer, except where the applicable state law permits a service provider to do so, such as to perform a business purpose you have authorized;
- engage sub-processors only under a written contract imposing these same restrictions, as described in section 8; and
- apply the security measures described on our Security page, which state plainly which certifications we do and do not hold.
Our certification. We understand the restrictions above and we will comply with them. This paragraph is the certification required by the California Consumer Privacy Act and its implementing regulations.
Notice if we can no longer comply. We will notify you without undue delay if we determine that we can no longer meet our obligations under the applicable state law. On receiving that notice, you may direct us to stop processing, and to remediate any unauthorized use of, the affected personal information.
Your right to monitor and to remediate. You may take reasonable and appropriate steps to confirm that we use Customer Personal Data consistently with your obligations under the applicable state law, and reasonable and appropriate steps to stop and remediate any unauthorized use of it. The mechanism for this is section 13, and the same practical means described there, our documentation, our responses to your security questionnaires, and where those are not sufficient, an audit, apply here.
Consumer rights requests. We assist you in responding to verified consumer requests to know, access, correct, delete, opt out, or limit, on the terms and within the turnaround stated in section 9. Where a consumer contacts us directly about Customer Personal Data, we handle it as described in that section.
What this section does not cover. It applies to Customer Personal Data only. Personal information for which we are the business or controller in our own right, being the account, billing, and operator app User Content described in section 2, and personal information collected through our website, is covered by our Privacy Policy instead of by this section.
17. Liability and order of precedence
Liability.Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law, and nothing in it limits a data subject's rights under Article 82 of the GDPR or under the SCCs.
Order of precedence. In the event of a conflict, the following order applies, from highest to lowest:
- the SCCs, in relation to any transfer to which they apply under section 14;
- this DPA;
- the pages incorporated by reference into this DPA, being the Security page and the Sub-processor page;
- the Terms of Service and any other agreement between the parties relating to the Service.
Where an individually negotiated enterprise agreement is signed by both parties and expressly states that it overrides this DPA, that agreement takes precedence over items 2 to 4 above, but never over the SCCs.
18. Governing law
Except where section 14 applies a different law to a transfer covered by the SCCs, this DPA is governed by the laws of the State of Florida, and the dispute resolution and forum provisions of the Terms of Service apply.
19. Changes to this DPA
We may update this DPA where required by a change in Data Protection Law, by a change to the SCCs or another approved transfer mechanism, or to reflect a change in the Service. We will notify you of material changes in accordance with the notice provisions of the Terms of Service. Changes will not reduce the level of protection for Customer Personal Data.
20. Contact
For any matter under this DPA, including data subject request assistance, sub-processor objections, breach notifications, and audit requests:
DIGITAL WARRIORS LLC
180 NE 29th St, Apt 330
Miami, FL 33137
United States
support@operatorbase.app