Data Processing Addendum

Telnyx Data Processing Addendum (DPA)
Version 3.0

This Data Processing Addendum (“DPA”) is incorporated into the Telnyx Terms and Conditions of Service (the “Agreement”) between Telnyx LLC (and/or any of its subsidiaries or other affiliates, “Telnyx”) and the customer that is party to the Agreement (“Customer”) with respect to the “Services” as defined in the Agreement. This DPA is binding on Customer upon Customer's acceptance of the Agreement, without further execution.


1. Definitions

All capitalized terms used but not otherwise defined in this DPA shall have the meaning ascribed to such terms in the Agreement. The following definitions and rules of interpretation below apply to this DPA:

“Adequate” in relation to the level of protection given to Personal Data in countries outside the European Economic Area (“EEA”), the United Kingdom or Switzerland, means a decision made by the European Commission under Article 45 of Regulation (EU) 2016/679 (the “GDPR”) or a finding under section 17A of the UK Data Protection Act 2018, or an adequacy decision of the Swiss Federal Council under the Swiss Federal Act on Data Protection, each as amended or replaced from time to time, in each case finding that the relevant third country provides an adequate level of protection by reason of its domestic law or of the international commitments it has entered into.
“AI Addendum” means the Telnyx AI-Enabled Services Addendum available at www.telnyx.com/legal/ai-services-addendum, as updated from time to time.
“AI Services” means the AI Features (as defined in the AI Addendum).
“AI Usage Data” means technical metadata generated by the AI Services about a request, such as request timestamps, token counts, model and voice identifiers, latency and error codes. AI Usage Data does not include Input Data, Output or any other Customer Content, including any sentiment analysis, summaries, insights, embeddings or other data derived from Customer Content.
“Applicable Data Protection Law(s)” refers to all laws and regulations applicable in relation to the processing of Personal Data under the Agreement.
“Cloud Storage” means the Telnyx cloud object storage and file storage Services.
“Communications Usage Data” means Personal Data processed by Telnyx to transmit, route, store or exchange Customer Content, and otherwise to provide, maintain, secure and bill for the Services, including (a) data used to trace and identify the source and destination of a communication, such as individual data subjects’ telephone numbers, sender and recipient identifiers, call detail records and message logs, and the date, time, duration, status and type of communication; (b) data on the location of a device generated in the context of providing the Services, including network and SIM-based location and session data for wireless and IoT connectivity Services; and (c) technical data generated through Customer’s use of Telnyx application programming interfaces, such as IP addresses, device and browser details, request timestamps and error codes. Communications Usage Data does not include Customer Content or AI Usage Data.
“Controller”, “Processor”, “Data Subject” and “Processing” (and “Process”) have the meanings given in accordance with Applicable Data Protection Law.
“Customer Account Data” means Personal Data that relates to Customer’s relationship with Telnyx, including the names, phone numbers and/or contact information of individuals authorized by Customer to access Customer’s Telnyx account and/or use the Services, billing information and shipping addresses.
“Customer Content” means Personal Data exchanged by use of the Services, such as text, call recording, message bodies, conversation transcriptions, voicemail recordings, voicemail transcription, video recording, video files, images and sound, as well as Personal Data contained in (i) Input Data submitted to, and Output generated by, the AI Services, including prompts, audio, transcripts, conversation history, summaries and other insights, embeddings and fine-tuning data, and (ii) files, objects and other content that Customer stores in the Services (including Cloud Storage). Notwithstanding Section 17.1 of the Agreement, this DPA applies to Personal Data contained in Storage Content (as defined in the Agreement).
“Documentation” means the technical and support documentation for the Services that Telnyx makes generally available at developers.telnyx.com and support.telnyx.com, as updated by Telnyx from time to time.
“Employees” with respect to any entity refers to such entity’s employees and contractors.
“Input Data” and “Output” have the meanings given in the AI Addendum.
“Personal Data” or “personal data” means any information relating to an identified or identifiable natural person where an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Security Incident” means a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to, Personal Data transmitted, stored or otherwise processed.
“Sensitive Personal Data” means Personal Data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, data concerning a natural person's sex life or sexual orientation, or any other data that falls within the definition of “special categories of data” under Applicable Data Protection Law.
“Standard Contractual Clauses” or “SCC” means
(a) for the transfer of data from the EEA outside the EEA to a non-adequate country, the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in the decision (EU) 2021/914 of 4 June 2021 (“EEA SCCs”)
(b) for the transfer of data from the United Kingdom to a non-adequate country, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022 ("UK International Data Transfer Addendum").
“Sub-processor” means any processor engaged by Telnyx for the purposes of the provision of the Services under the Agreement.


2. Relationship of the Parties

2.1 Customer Content.

The parties acknowledge and agree that with regard to the processing of Customer Content, Customer may act either as a controller or processor and Telnyx acts as a processor (where Customer is a controller) or sub-processor (where Customer is a processor); and an independent data controller (and the Customer is a controller) for the purpose of improving and enhancing the Services, subject to Sections 3.1 and 3.5.

2.2 Customer Account Data and Communications Usage Data.

The parties acknowledge that, with regard to the processing of Customer Account Data, Communications Usage Data and AI Usage Data, Customer is a controller and Telnyx is an independent controller, not a joint controller with Customer.


3. Processing of Personal Data

3.1 Purpose Limitation.

Telnyx shall process Customer Content as a data processor (a) for the performance of the Services in accordance with Customer’s instructions as set forth in the Agreement and this DPA and in accordance with Applicable Data Protection Law, (b) as otherwise necessary to provide the Services (which may include responding to support requests and prevention and resolution of security, fraud and technical issues, the latter may include engaging and providing access to Customer Content to telecommunication carriers to diagnose and solve the issue), (c) as initiated through the use of the Service and (d) as further instructed by the Customer in writing. Telnyx shall process Customer Content as a data controller to improve and enhance the Services, subject to Section 3.5 and the remainder of this Section 3.1. Telnyx will not use Customer Content (including Input Data and Output) to train or fine-tune artificial intelligence or machine learning models made available to anyone other than Customer, except (a) with Customer’s prior opt-in in writing, or (b) using data de-identified in accordance with Section 3.5. Nothing in this Section limits Telnyx’s use of Communications Usage Data and AI Usage Data for the purposes in Schedule 1 (including improving the Services), or its processing of Customer Content as a processor, including to customize a model made available solely to Customer. Telnyx will process Customer Account Data, Communications Usage Data and AI Usage Data as a data controller in accordance with Applicable Data Protection Law, the Privacy Policy and the Agreement for the purposes detailed in Schedule 1 of this DPA.

3.2 Customer Instructions.

Customer will ensure that its instructions comply with Applicable Data Protection Laws and that Telnyx’s processing of the Customer Content in accordance with Customer’s instructions will not cause Telnyx to violate Applicable Data Protection Laws. Telnyx will notify Customer to the extent permitted by law if it becomes aware or reasonably believes that Customer’s data processing instructions would violate Applicable Data Protection Law.

3.3 Customer Compliance.

Customer shall ensure that (a) it has and will continue to comply with Applicable Data Protection Law in its use of the Services; (b) its customers and end users are provided adequate notice of Telnyx’s processing activities for which Telnyx acts as a controller, to fulfill the requirements of Applicable Data Protection Laws (c) it has, and will continue to have, the right to transfer, or provide access to, its customers’ and end users’ Personal Data (including, as applicable, Sensitive Personal Data) to Telnyx for processing in accordance with the terms of the Agreement and this DPA; (d) appropriate technical and organizational measures and suitable safeguards are in place before transmitting or processing Sensitive Personal Data, and/or before permitting Customer’s end users to transmit or process any Sensitive Personal Data via the Services; (e) it has provided all notices and obtained all consents and authorizations required under applicable law (including call recording, wiretap and biometric privacy laws) before using the Services to record, transcribe, analyze, generate or synthesize the voice or other communications of its customers, end users, and other participants in communications, including through conversational AI, transcription, speech synthesis, voice design and synthetic-media detection features, and including the consent of any individual whose voice is used to create or customize a synthetic voice (whether or not that individual participates in any communication); and (f) where Customer uses identity, verification or lookup Services, it has a lawful basis to request and receive information relating to the individuals concerned and provides any transparency information required by Applicable Data Protection Law. Telnyx does not use voice or other biometric data to uniquely identify natural persons, except where Customer configures a feature that does so, and Customer is responsible for maintaining any publicly available retention and destruction schedule required by applicable biometric privacy law.

3.4 Processing Information.

Schedule 1 of this DPA details the duration of processing, the nature and purpose of processing, the type of Personal Data and the categories of data subjects processed by Telnyx.

3.5 Data Minimization; Anonymized Data.

Where Telnyx processes Customer Content for its own purposes under Section 2.1, Telnyx will first apply appropriate measures to de-identify, pseudonymize or aggregate such Personal Data so that it does not identify Customer, Customer’s customers or end users, or any data subject. Personal Data that has been anonymized, de-identified or aggregated so that it no longer constitutes Personal Data under Applicable Data Protection Law is not subject to this DPA, provided that Telnyx (i) will not re-identify, or attempt to re-identify, such data, (ii) publicly commits to maintain and use such data only in de-identified form, and (iii) contractually obligates any recipient of such data to comply with the foregoing.

3.6 AI Services; Retention Controls.

This Section 3.6, Section 4.8, the definition of AI Usage Data and Section 5.5 (insofar as it relates to the AI Services) apply only to the extent Customer enables or uses AI Services. Customer acknowledges that certain AI Services store Customer Content on Customer’s behalf, including conversation history, transcripts, recordings, summaries and other insights, memory, embeddings and fine-tuning data. Telnyx processes such stored Customer Content as a data processor in accordance with Section 3.1. Customer controls whether and for how long such Customer Content is retained through the configuration options described in the Documentation, and Customer is responsible for configuring those options (including any separate recording, logging and storage settings at the number, application or account level) in accordance with its obligations under Applicable Data Protection Law. Disabling a retention or logging option applies prospectively and does not affect Customer Content already stored, which Customer may delete in accordance with Section 11.1.

3.7 Additional Instructions.

Processing of Personal Data outside the scope of the Agreement and this DPA requires prior written agreement between the parties, including agreement on any additional fees payable by Customer to Telnyx for carrying out such additional instructions.


4. Sub-processors

4.1 Sub-processors list and engagement.

Customer acknowledges that Telnyx engages Sub-processors in connection with the provision of the Services and Customer provides general consent for Telnyx to appoint sub-processors, subject to this clause 4. The engagement by Telnyx of any such Sub-processor shall be on written terms which impose upon the Sub-processor data protection obligations to the standard required by Applicable Data Protection Law, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, including providing sufficient guarantees to implement appropriate technical and organizational measures. Telnyx’s up-to-date sub-processors list is set forth at www.telnyx.com/legal/subprocessors (the “Sub-processors List”). The Sub-processors List may designate certain Sub-processors as engaged solely in connection with the AI Services; such Sub-processors process Customer Content only to the extent Customer enables or uses the relevant AI Services.

Customer grants a general authorization to Telnyx to appoint other entities of Telnyx as Sub-processors, conditional on the requirements detailed in Section 4.1

4.3 Notification Mechanism.

When a Sub-processor is replaced or a new one appointed, the Sub-processors List may be modified pursuant to a notification mechanism (“Notification Mechanism”). In the event Customer subscribes, Telnyx will provide notification of any new or replacement Sub-processor.

4.4 Objection to new Sub-processors.

If Customer objects to Telnyx’s appointment or replacement of a Sub-processor based on reasonable grounds relating to data protection, it shall notify Telnyx in writing within 10 days of receipt of notice. In such event, Telnyx will use reasonable efforts to provide the Services to Customer in accordance with the Agreement without using the Sub-processor.

4.5 Sub-Processor liability.

Telnyx shall be liable for its Sub-processors’ processing of Customer Content to the same extent that Telnyx would be liable if performing the processing activities of each Sub-processor directly under the terms of this DPA.

4.6 Communications sent through the Services and payment gateways.

Customer acknowledges that Telnyx may use telecommunication providers in the provision of the Services. Customer further acknowledges that in order to send communications for the provision of the Services, Telnyx may need to transmit Customer’s communications through existing telecommunications networks and suppliers and through over-the-top and rich messaging platforms (such as WhatsApp and RCS Business Messaging), via companies bound to comply with applicable telecommunications and privacy laws but who may not all have direct contracts with Telnyx and/or Customer. Customer further acknowledges that Telnyx may use payment gateways in the provision of Services via companies bound to comply with data protection laws but who may not have direct contracts with Telnyx. Customer hereby instructs Telnyx to transmit the communications through existing telecommunications networks and to use payment gateways as necessary to provide the Services and acknowledges and agrees that telecommunications networks and payment gateway suppliers are not considered Sub-processors under either the DPA or the Agreement.

4.7 Call quality.

When Customer reports potential issues with the quality of the Services, the Customer instructs Telnyx to engage its relevant telecommunication suppliers for assistance including by providing them with access to communications data (for example, CDRs or call recordings) which may contain personal data for the purpose of diagnosing and resolving the reported issues.

4.8 Third-Party AI Technology.

Customer acknowledges that certain AI Services may be powered in whole or in part by Third-Party Technology (as defined in the AI Addendum). Where such Third-Party Technology providers process Personal Data on Telnyx’s behalf, they are Sub-processors subject to this Section 4 and are identified on the Sub-processors List. Where Customer selects a specific Third-Party Technology provider, model or voice within the Services, Customer instructs Telnyx to transmit the relevant Input Data to, and receive Output from, that provider. Where Customer configures the Services to use Customer’s own account or credentials with a Third-Party Technology provider, that provider processes Input Data and Output on Customer’s behalf under Customer’s agreement with that provider and is not a Sub-processor of Telnyx. Third-Party Technology providers process Input Data and Output in accordance with their own terms and privacy policies, which Telnyx identifies in the Documentation or on the Sub-processors List. Customer is responsible for reviewing those terms before enabling any AI Service that relies on Third-Party Technology, including any provisions concerning the retention of Input Data and Output and their use to train or improve the provider’s models, and Telnyx makes no representation on behalf of any Third-Party Technology provider regarding such practices. If Customer does not accept a Third-Party Technology provider’s terms, Customer may select a different provider or model where the Services permit, use Customer’s own credentials with a provider of its choice, or discontinue use of the affected AI Service.


5. Data Transfers

5.1 Telnyx data transfer.

To the extent that any Personal Data is transferred from the European Economic Area, the United Kingdom, and/or Switzerland (either directly or via onward transfer) to any country that, according to the European Commission or the competent authority for the UK and Switzerland, does not provide an adequate level of protection for personal data, the parties agree that the Standard Contractual Clauses, incorporated by reference to this DPA, will apply in respect of the processing of such Personal Data. The Standard Contractual Clauses and this Clause 5 will not apply to Personal Data that is not transferred, either directly or via onward transfer, outside the EEA, the United Kingdom and/or Switzerland. In relation to the Standard Contractual Clauses, Telnyx will comply with the obligations of the 'data importer' in the Standard Contractual Clauses and the Customer will comply with the obligations of the 'data exporter'. Appendices of the EEA SCCs shall be deemed completed as set forth in Schedule 2 of this DPA in relation to transfer of personal data outside the EEA. The UK International Data Transfer Addendum, applicable to transfer of personal data outside the United Kingdom, shall be deemed completed as set forth in Schedule 3.

5.2 In the event of any conflict or inconsistency between the EU Standard Contractual Clauses (Schedule 2) or UK International Data Transfer Addendum (Schedule 3), and the terms of this DPA, the EU Standard Contractual Clauses or UK International Data Transfer Addendum (Schedule 3), as applicable, shall prevail.

5.3 Request for Personal Data.

5.3.1 If Telnyx receives a civil or criminal subpoena, search warrant, or other official and written request that is legally binding (“Request”) by a public authority that is not from an EEA country, the UK, or a country considered Adequate (“Requesting Party”) for disclosure of Customer’s personal data, Telnyx may respond to such Requesting Party with respect to any Request that Telnyx reasonably deems to be valid and appropriate in scope. Otherwise, Telnyx may, insofar as legally permissible, redirect the Requesting Party to request that Personal Data directly from Customer instead.

5.3.2 In the event that the information is provided, Telnyx will (a) ensure that the disclosed Personal Data is the minimum required to satisfy the Request; and (b) take all commercially reasonable steps to ensure that such Customer information is afforded confidential treatment by the authorities.

5.4 Sub-processors data transfer.

If in the performance of the Services, Telnyx permits processing of any Personal Data by a Sub-processor outside the EEA, except if in an Adequate country, without prejudice to Section 4, Telnyx shall in advance of any such transfer ensure that a legal mechanism to achieve adequacy in respect of that processing is in place, such as:

5.4.1 Standard Contractual Clauses;

5.4.2 affirmative representation or covenant regarding compliance with applicable law; or

5.4.3 the existence of any other specifically approved safeguard for data transfers as recognized under Applicable Data Protection Law and/or a European Commission or Information Commissioner’s Office finding of adequacy.

5.5 Processing in the United States.

Customer acknowledges that, as of the date hereof, Telnyx’s primary processing facilities are in the United States of America. Certain Services, including certain AI Services and Cloud Storage, allow Customer to select a processing region as described in the Documentation. Where Customer selects a processing region, Telnyx will use commercially reasonable efforts to process Customer Content submitted to that Service within the selected region, except (a) as Customer otherwise directs or configures, including by selecting Third-Party Technology or endpoints located outside that region; (b) for failover, resilience or capacity reasons described in the documentation; (c) as necessary to provide support, security and abuse prevention; or (d) as required by law. Telnyx will notify Customer through the documentation of the regions available for each Service. Region selection determines where Customer Content is stored and, for AI Services that support it, where inference is performed, in each case as described in the Documentation. Remote access to Customer Content by Telnyx personnel for support purposes constitutes a transfer of Personal Data subject to the safeguards described in this Section 5.

5.6 Data Privacy Framework.

As of the effective date of this DPA, Telnyx has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework Principles (collectively, the “DPF”). To the extent Telnyx processes Personal Data received from the EEA, the United Kingdom or Switzerland in reliance on the DPF, Telnyx will provide at least the same level of protection to such Personal Data as is required by the DPF Principles. If Telnyx’s self-certification under the DPF is withdrawn, terminated, revoked, not renewed or otherwise invalidated, the Standard Contractual Clauses described in Section 5.1 will continue to apply to the relevant transfers.


6. Security of Personal Data

6.1 Security measures.

Telnyx has implemented and will maintain appropriate administrative, technical, and organizational measures (www.telnyx.com/legal/technical-organizational-security-practices) to protect Personal Data from a Security Incident, having regard to the state of technological development and the cost of implementing such measures, as well as the nature, scope, context and purposes of processing and the likelihood and severity of harm to the interests of data subjects that may be expected to result from any such Security Incident.

6.2 Employee Access.

Telnyx shall ensure that only such of its employees who may be required by it to provide the Services to Customer or assist Telnyx in meeting its obligations under this DPA shall have access to Personal Data. Telnyx will ensure that the employees accessing Customer Content are under confidentiality obligations to protect such personal information.


7. Security Incidents

7.1 Security Incident Involving personal data.

Upon confirming a Security Incident involving personal data for which Telnyx acts as data processor, Telnyx will:

7.1.1 to the extent permitted by applicable law, notify Customer without undue delay, such notice to be delivered in accordance with Section 13 of this DPA;

7.1.2 to the extent such Security Incident is caused by Telnyx’s violation of its obligations under this DPA, take such reasonable remedial steps to address such Security Incident and prevent any further incidents; and

7.1.3 promptly provide the Customer with all relevant information in its possession as reasonably required by Applicable Data Protection Law to comply with any reporting obligations of a relevant regulatory authority concerning such Security Incident. Telnyx’s notification of, or response to, a Security Incident shall not be construed as an acknowledgement by Telnyx of any fault or liability with respect to the Security Incident.

7.2 Notification to the supervisory authority:

If Customer determines that a Security Incident must be notified to any supervisory authority and/or data subjects and/or the public or portions of the public pursuant to the Applicable Data Protection Law, Customer will to the extent commercially feasible notify Telnyx before the communication is made (and where not commercially feasible, as soon as is commercially feasible after such communication) and supply Telnyx with copies of any written documentation to be filed with the supervisory authority and of any notification Customer proposes to make (whether to any supervisory authority, data subjects, the public or portions of the public) which directly or indirectly references Telnyx, its security measures and/or role in the Security Incident, whether or not by name. Subject to Customer’s compliance with any mandatory notification deadlines under Applicable Data Protection Law, Customer will consult with Telnyx in good faith and take account of any clarifications or corrections Telnyx reasonably requests to such notifications and which are consistent with Applicable Data Protection Law. In the event that impacted data subjects are required to be notified of the Security Incident, Customer will provide reasonable assistance to Telnyx to effectuate appropriate notice to such impacted data subjects.


8. Audits

8.1 Demonstrated Compliance.

Upon Customer’s written request, no more than once annually and subject to adequate confidentiality provisions, Telnyx shall, in accordance with Applicable Data Protection Laws, make available to Customer such reasonable information in Telnyx’s possession or control to demonstrate Telnyx’s compliance with its obligations as a data processor of Customer Content to satisfy Customer’s audit rights granted by Applicable Data Protection Law (including, where applicable, the Standard Contractual Clauses).


9. Personal Data on Expiry or Termination

9.1 Deletion of Personal Data.

In respect of the Customer Content that Telnyx processes as a data processor pursuant to the Agreement, Telnyx shall cease to process such personal data and will promptly arrange for its deletion on expiry or termination of the Agreement, unless otherwise agreed by the parties in writing, in which case Telnyx shall hold Customer Content in accordance with the data retention term agreed by the parties. Notwithstanding anything to the contrary in this Section 9, Telnyx may retain Customer Content or any portion of it if required by applicable law, in which case, Telnyx shall comply with Applicable Data Protection Law regarding the deletion and retention of Personal Data.


10. Data Protection Impact Assessment

10.1 Telnyx shall provide reasonable assistance to Customer (taking into account the nature of processing and the information available to Telnyx and at Customer's expense) with respect to data protection impact assessments or consultations with supervisory authorities that may be required in accordance with Applicable Data Protection Law.


11. Data Subject Requests

11.1 Self-service features.

As part of certain Services, Telnyx may, but is not obligated to, provide Customer with self-service features to delete, retrieve or restrict use of Customer Content, which the Customer may use to assist in its compliance with its obligations under Applicable Data Protection Law with respect to responding to requests from data subjects.

11.2 Additional assistance.

In addition, upon written request, Telnyx will provide reasonable additional and timely assistance in relation to Customer Content, at Customer’s expense, to assist Customer in complying with its data protection obligations to respond to requests for exercising the rights of data subject under Applicable Data Protection Law.

11.3 Inability to Identify Data Subjects.

Customer acknowledges that, given the nature of the Services, Telnyx may be unable to match Customer Content or Communications Usage Data (such as telephone numbers, call detail records or message logs) to an identified data subject. In such cases, Telnyx will inform Customer accordingly and, to the extent Telnyx cannot identify the data subject, Telnyx’s assistance under this Section 11 in respect of that request will be limited to acting on the identifiers (such as telephone numbers, call or message identifiers) that Customer supplies, without prejudice to Customer’s own obligations under Applicable Data Protection Law.


12. Liability

12.1 Liability; Conflicts and Order of Precedence.

This DPA is without prejudice to the rights and obligations of the parties under the Agreement which shall continue to have full force and effect, including any limitations on liability contained therein which shall apply to this DPA as if fully set forth herein. In the event of any conflict between the terms of this DPA and the terms of the Agreement, the terms of this DPA shall prevail so far as the subject matter concerns the processing of Personal Data. Without limiting Section 5.2, in the event of any conflict among the documents comprising the Agreement with respect to the processing of Personal Data, the order of precedence shall be: (a) the Standard Contractual Clauses and the UK International Data Transfer Addendum; (b) this DPA; (c) the AI Addendum; and (d) the remainder of the Agreement, including the Terms and Conditions.

12.2 Penalties.

Notwithstanding anything to the contrary in this DPA or in the Agreement, neither party will be responsible for any fines issued or levied under Article 83 of the GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the GDPR.


13. Notification

13.1 All notices given by Telnyx to Customer under or in connection with this DPA shall be validly served by email. Where Customer has subscribed to the Notification Mechanism, Customer shall receive notifications pursuant to Clause 4.3 of this DPA. All other notices given by Telnyx to Customer under or in connection with this DPA shall be sent to Customer’s email address associated to their Telnyx account; and any notice given by Customer to Telnyx shall be sent to [email protected] and [email protected].


14. Indemnification


15. Miscellaneous

15.1 Governing Law and Jurisdiction.

This DPA shall be governed by and construed in accordance with the law and the jurisdiction of the country or territory which governs the Agreement, except as otherwise specified in this DPA, including its Schedules, or required by Applicable Data Protection Law.

15.2 Jurisdiction Specific Terms.

To the extent Telnyx processes Personal Data protected by Applicable Data Protection Laws in a jurisdiction listed in Schedule 4, then the terms specified in Schedule 4 (“Jurisdiction Specific Terms”) apply and in case of any conflict between the Jurisdiction Specific Terms and any term of this DPA, the applicable Jurisdiction Specific Terms will take precedence.

15.3 Updates.

Telnyx may update the terms of this DPA from time to time where the changes (a) are required to comply with Applicable Data Protection Law, applicable regulation, a court order or guidance issued by a regulator or agency; (b) do not have a material adverse impact on Customer’s rights under the DPA; or (c) are required as a result of new products or services or material changes to any of the existing Services.


Schedule 1

Details of Processing


1. Nature and Purpose of Processing

1.1 Customer Content.

Telnyx will process Customer Content in accordance with Section 3.1 of this DPA. This includes Customer Content submitted to the AI Services or stored in the Services on Customer’s behalf, which Telnyx processes as a data processor in accordance with Section 3.6 of this DPA.

1.2 Customer Account Data, Communications Usage Data and AI Usage Data.

Telnyx will process Customer Account Data, Communications Usage Data and AI Usage Data as a controller to perform the functions as a communications service provider that may include, but are not limited to, (a) manage the relationship with the Customer; (b) carry out Telnyx’s business operations, such as accounting, tax, billing, audit and compliance; (c) to investigate security issues, fraud, unauthorized or unlawful use of the service and other misuses; (d) to improve the Services; (e) to prevent, detect and investigate abuse or misuse of the Services, including through the development and improvement of Telnyx’s internal tools and models used for such purposes, and to assist telecommunications providers, regulators and law enforcement in combating spam, fraud and illegal activity; (f) to comply with telecommunications regulatory obligations, including know-your-customer, subscriber record, number portability and emergency services requirements; and (g) as required by applicable law, rule or regulation, including but not limited to Applicable Data Protection Law. Telnyx processes AI Usage Data as a controller solely for the purposes in (b), (c), (d) and (e) above as they relate to the AI Services (billing, security, abuse prevention and improving the AI Services); the telecommunications regulatory purposes in (f) apply only to Communications Usage Data. Telnyx does not use Communications Usage Data or AI Usage Data relating to Customer’s customers or end users for Telnyx’s own marketing purposes.


2. Duration of Processing

2.1 Telnyx acting as processor for Customer Content.

Telnyx will process Customer Content for the duration outlined in Section 9 of this DPA.

2.2 Telnyx acting as controller.

Telnyx will process personal data as a controller for as long as needed to provide the Services. Upon termination of the Agreement, Telnyx may retain personal data (a) for the purposes outlined in Section 1.2 of this Schedule 1; or (b) as required by law. Telnyx will promptly delete or anonymize such personal data when Telnyx no longer requires it for the herein mentioned purposes.


3. Types of Personal Data

3.1 Telnyx processes personal data contained in Customer Content (including Input Data and Output), Customer Account Data, Communications Usage Data and AI Usage Data as defined in Section 1 of this DPA.


4. Categories of Data Subjects

4.1 Customer Content.

Customer Content may concern the following categories of data subjects:

  • Customer’s authorized users, who are those individuals that are authorized by the Customer to use the Services on behalf of the Customer.
  • Customer’s customers and end users.
  • Any other individuals whose Personal Data is contained in Customer Content, including in Input Data submitted to the AI Services or in content stored in the Services.

4.2 Customer Account Data, Communications Usage Data and AI Usage Data.

Customer Account Data, Communications Usage Data and AI Usage Data may concern the following categories of data subjects:

  • Customer’s employees and agents
  • Customer’s authorized users
  • Customer’s customers and end users

Schedule 2

Standard Contractual Clauses Decision (EU) 2021/914

Terms applicable to the EEA SCCs:
(i) Clause 7 - the optional docking clause will not apply;
(ii) Clause 9 - Option 2 will apply and the time period for prior notice of sub-processor changes will be as set forth in Section 4 (Sub-processors) of this DPA;
(iii) Clause 11 (a) - the optional language will not apply;
(iv) Clause 17 - Option 1 will apply and the Clauses will be governed by the law of Ireland;
(v) Clause 18 - disputes will be resolved before the courts of Ireland;
(vi) Module One (Controller to Controller) of the EEA SCCs apply where Customer is a controller and Telnyx is an independent controller
(vii) Module Two (Controller to Processor) of the EEA SCCs apply where Customer is a controller and Telnyx is a processor
(viii) Module Three (Processor to Processor) of the EEA SCCs apply where Customer is a processor and Telnyx is a processor


Annex I

A. List of Parties

Data exporter(s):

  • Name: The company defined as Customer who is party to the Agreement.
  • Address: The address of the Customer as provided in the Agreement.
  • Contact details: Customer’s email address associated to their Telnyx account.
  • Activities relevant to the data transferred under these Clauses: purchase of Telnyx Services.
  • Signature and date: By entering into the Agreement, Data Exporter is deemed to have signed these Standard Contractual Clauses, including their Annexes, as of the date the parties entered into the Agreement or this DPA, whichever is later.
  • Role: The Data Exporter’s role is as set forth in Section 2 (Relationship of the Parties) of this DPA.

Data importer(s):

  • Name: Telnyx LLC.
  • Address: Telnyx's address specified in the Agreement.
  • Contact details: [email protected] and [email protected]
  • Activities relevant to the data transferred under these Clauses: Provision of the Services, which includes, but is not limited to, communications services that enable communications features and capabilities to be embedded into web, desktop and mobile software applications, together with related identity and verification, networking and wireless connectivity, compute, storage and AI Services.
  • Signature and date: By entering into the Agreement, Data Importer is deemed to have signed the Standard Contractual Clauses, including their Annexes, as of the date the parties entered into the Agreement or this DPA, whichever is later.
  • Role: The Data Importer’s role is as set forth in Section 2 (Relationship of the Parties) of this DPA.

B. Description of Transfer

Categories of data subjects whose personal data is transferred: As described in Section 4 of Schedule 1 (Details of Processing) of this DPA.
Categories of personal data transferred: Telnyx processes personal data contained in Customer Content (including Input Data and Output), Customer Account Data, Communications Usage Data and AI Usage Data as defined in Section 1 (Definitions) of this DPA.
Sensitive data: Telnyx does not intentionally collect or process Sensitive Personal Data in providing the Services. Customer Content may, from time to time, include Sensitive Personal Data where Customer or its end users choose to include it in communications, Input Data or stored content, in which case Customer is responsible for the safeguards described in Section 3.3(d) of this DPA.
The frequency of the transfer: The data is transferred on a continuous basis.
Nature of the processing: is as set forth in Section 1 of Schedule 1 (Details of Processing) of this DPA.
Purpose(s) of the data transfer and further processing: Telnyx processes personal data for the purposes described in Section 1 of Schedule 1 (Details of Processing) of this DPA.
The period for which the personal data will be retained: Telnyx retains data for the duration described in Section 2 of Schedule 1 (Details of Processing) of this DPA.
For transfers to (sub-) processors, the subject matter, nature and duration of the processing is set forth in the Sub-processors List (refer to Section 4.1 of this DPA).


C. Competent Supervisory Authority

Identify the competent supervisory authority/ies: The Irish supervisory authority is the competent supervisory authority.


Annex II
Technical and Organizational Measures Including Technical and Organizational Measures to Ensure the Security of the Data
Description of the technical and organizational security measures implemented by the data importer are as set forth in Section 6.1 of this DPA. The data importer may update its security document from time to time provided that there is no material degradation to the security and/or privacy of the services.


Annex III – List of Sub-Processors
Module Two: Transfer controller to processor
As per the Sub-processors List (in Section 4.1 of this DPA).


Schedule 3

UK International Data Transfer Addendum
Standard Data Protection International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Commissioner under S119A(1) Data Protection Act 2018
VERSION B1.0, in force 21 March 2022


PART 1: Tables

Table 1: Parties

  • Start date: As set forth in the order or Agreement that incorporates these Standard Contractual Clauses by reference or as set forth in the DPA, whichever is later.
The PartiesExporter (who sends the Restricted Transfer)Importer (who receives the Restricted Transfer)
Parties' detailsFull legal name: The company defined as Customer who is party to the Agreement.
Trading name (if different):
Main address (if a company registered address): The address of the Customer as provided in the Agreement.
Official registration number (if any) (company number or similar identifier): As provided in the Agreement.
Full legal name: Telnyx LLC
Trading name (if different):
Main address (if a company registered address): The Telnyx address specified in the Agreement.
Official registration number (if any) (company number or similar identifier): 03125734
Key ContactFull Name (optional):
Job Title:
Contact details including email:
Customer’s email address associated to their Telnyx account
Full Name (optional):
Job Title:
Contact details including email:
[email protected] and [email protected]
Signature (if required for the purpose of Section 2)By entering into the Agreement, the parties are deemed to have signed this UK International Data Transfer AddendumBy entering into the Agreement, the parties are deemed to have signed this UK International Data Transfer Addendum

Table 2: Selected SCCs, Modules and Selected Clauses

  • Addendum EU SCCs: The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information:
    Date: as provided in Table 1 above
ModuleModule in operationClause 7 (Docking Clause)Clause 11 (Option)Clause 9a (Prior Authorization or General Authorization)Clause 9a (Time period)
1YesDoes not applyOptional language does not apply
2YesDoes not applyOptional language does not applyOption 2 applies - general authorizationAs set forth in Section 4 of the DPA
3YesDoes not applyOptional language does not applyOption 2 applies - general authorizationAs set forth in Section 4 of the DPA

Table 3: Appendix Information

“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

  • Annex 1A: List of Parties: as set forth in Annex I.A of Schedule 2 of this DPA.
  • Annex 1B: Description of Transfer: as set forth in Annex I.B of Schedule 2 of this DPA.
  • Annex II: Technical and organizational measures including technical and organizational measures to ensure the security of the data: as set forth in Annex II of Schedule 2 of this DPA.
  • Annex III: List of Sub processors (Modules 2 and 3 only): as set forth in Annex III of Schedule 2 of this DPA.

Table 4: Ending this Addendum when the Approved Addendum Changes

Which Parties may end this Addendum as set out in Section 19: Importer & Exporter


PART 2: Mandatory Clauses

Mandatory Clauses:
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.


Schedule 4

Jurisdiction Specific Terms

Australia:

  • The definition of “Applicable Data Protection Law” includes the Australian Privacy Principles (APPs) and the Australian Privacy Act (1988).
  • The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.
  • The definition of “sensitive data” includes “Sensitive Information” as defined under Applicable Data Protection Law.

Brazil:

  • The definition of “Applicable Data Protection Law” includes the Lei Geral de Proteção de Dados (LGPD).
  • The definition of “processor” includes “operator” as defined under Applicable Data Protection Law.
  • The definition of “Security Incident” includes a security incident that may result in any relevant risk or damage to the data subjects.

California:

  • The definition of “Applicable Data Protection Law” includes the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) (collectively the "CCPA").
  • The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.
  • The definition of “data subject” includes “Consumer” as defined under Applicable Data Protection Law.
  • The definition of “controller” includes “Business” as defined under Applicable Data Protection Law.
  • The definition of “processor” includes “Service Provider” as defined under Applicable Data Protection Law.
  • Data Subject Rights include Consumer rights as provided in the CCPA. Telnyx will provide reasonable additional and timely assistance to assist Customer in complying with its obligations with respect to consumer requests, as provided in Section 11 of the DPA.
  • Telnyx will process, retain, use, and disclose Personal Data only as necessary to provide the Services under the Agreement, which constitutes a business purpose. Telnyx agrees not to sell or share Customer’s Personal Data or Customer end users’ Personal Data; retain, use, or disclose Customer’s Personal Data for any commercial purpose other than providing the Services; or retain, use, or disclose Customer’s Personal Data outside of the scope of the Agreement. Telnyx understands its obligations under the Applicable Data Protection Law and will comply with them.
  • Telnyx certifies that its Sub-processors, as described in Section 4 of the DPA, are Service Providers under Applicable Data Protection Law, with whom Telnyx has entered into a written contract that includes terms substantially similar to this DPA. Telnyx conducts appropriate due diligence on its Sub-processors.
  • Telnyx will implement and maintain the reasonable security procedures and practices appropriate to the nature of the Personal Data it processes as set forth in Section 6 of the DPA.
  • Telnyx shall notify the Customer if it makes a determination that it can no longer meet its obligations as Service Provider under the CCPA.
  • Upon notice, including if Telnyx notifies the customer that it can no longer meet its obligations, Customer will have the right to take reasonable and appropriate steps in accordance with the Agreement to stop and remediate unauthorized use of personal information.
  • Telnyx shall not combine Customer Content that it receives from Customer, or on behalf of Customer, with personal information that it receives from, or on behalf of, another person or persons, or collects from its own interaction with the consumer, provided that Telnyx may combine personal information to perform any business purpose as defined in the regulations adopted pursuant to paragraph (10) of subdivision (a) of Section 1798.185, of the CPRA except as provided for in paragraph (6) of subdivision (e) of the CPRA and in regulations adopted by the California Privacy Protection Agency.
  • The engagement of Telnyx of a sub-processor/service provider to process personal data will be on written terms which impose upon the service provider data protection obligations to the standard required by Applicable Data Protection Law, as provided in Section 4.1 of this DPA.

Canada:

  • The definition of “Applicable Data Protection Law” includes the Federal Personal Information Protection and Electronic Documents Act (PIPEDA).
  • Telnyx’s Sub-processors, as described in Section 4 of the DPA, are third parties under Applicable Data Protection Law, with whom Telnyx has entered into a written contract that includes terms substantially similar to this DPA. Telnyx has conducted appropriate due diligence on its Sub-processors.
  • Telnyx will implement technical and organizational measures as set forth in Section 6 of the DPA.

European Union:

  • The definition of “Applicable Data Protection Law” includes the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”).

Germany:

  • The definition of “Applicable Data Protection Law” includes the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).

Israel:

  • The definition of “Applicable Data Protection Law” includes the Protection of Privacy Law (PPL).
  • The definition of “controller” includes “Database Owner” as defined under Applicable Data Protection Law.
  • The definition of “processor” includes “Holder” as defined under Applicable Data Protection Law.
  • Telnyx will require that any personnel authorized to process Customer Content comply with the principle of data secrecy and have been duly instructed about Applicable Data Protection Law. Such personnel sign confidentiality agreements with Telnyx in accordance with Section 6 of the DPA.
  • Telnyx must take sufficient steps to ensure the privacy of data subjects by implementing and maintaining the security measures as specified in Section 6 of the DPA and complying with the terms of the Agreement.
  • Telnyx must ensure that the Personal Data will not be transferred to a Sub-processor unless such Sub-processor has executed an agreement with Telnyx pursuant to Section 4.1 of this DPA.

Japan:

  • The definition of “Applicable Data Protection Law” includes the Act on the Protection of Personal Information (APPI).
  • The definition of “Personal Data” includes “Personal Information” as defined under Applicable Data Protection Law.
  • The definition of “controller” includes “Business Operator” as defined under Applicable Data Protection Law. As a Business Operator, Telnyx is responsible for the handling of Personal Data in its possession.

Singapore:

  • The definition of “Applicable Data Protection Law” includes the Personal Data Protection Act 2012 (PDPA).
  • Telnyx will process Personal Data to a standard of protection in accordance with the PDPA by implementing adequate technical and organizational measures as set forth in Section 6 of the DPA and complying with the terms of the Agreement.

United Kingdom:

  • The definition of “Applicable Data Protection Law” includes the Data Protection Act 2018.
  • References in this Addendum to GDPR will be deemed to be references to the corresponding laws of the United Kingdom, this is UK GDPR and Data Protection Act 2018.

Virginia:

  • The definition of “Applicable Data Protection Law” includes the Virginia Consumer Data Protection Act (“VCDPA”).
  • The definition of “data subject” includes “Consumer” as defined under the VCDPA.

United States – State Privacy Laws:

  • The definition of “Applicable Data Protection Law” includes the other comprehensive consumer privacy laws of the states of the United States that apply to the processing of Personal Data under the Agreement, including the Texas Data Privacy and Security Act and the laws of Colorado, Connecticut, Utah and Oregon, in each case as amended from time to time, and the definitions of “controller”, “processor” and “data subject” include the materially equivalent terms under such laws.
  • The terms set forth above for California apply, mutatis mutandis, to Telnyx’s processing of Personal Data as a processor or service provider under such laws.