Data Processing Addendum
This addendum describes how Tig.ai may process customer content on behalf of a workspace or organization.
1. Scope and roles
This addendum applies when Tig.ai processes personal information or customer content on behalf of a workspace administrator or organization. The customer determines the purposes and means of that processing, and Tig.ai acts as a processor, service provider, or equivalent role where required by applicable law.
For account administration, billing, security, product analytics, and legal compliance, Tig.ai may act as an independent controller. The Terms of Service and Privacy Policy apply to those activities.
2. Processing details
The subject matter, duration, nature, and purpose of processing are to provide, secure, support, and maintain voice AI agents, workflows, telephony, WebRTC sessions, integrations, and related features requested by the customer.
Depending on the configuration, categories of data may include account and contact details, phone numbers, call metadata, audio, recordings, transcripts, messages, knowledge sources, files, workflow events, technical identifiers, and information contained in conversations.
The people whose information may be processed can include the customer's users, employees, callers, leads, customers, suppliers, and other people who interact with an agent or workflow.
3. Customer instructions and responsibilities
Tig.ai will process customer content only on documented instructions from the customer, including configuration and use of the service, unless applicable law requires another form of processing. The customer is responsible for ensuring that its instructions are lawful and complete.
- Provide notices and obtain permissions or consent required for calls, recordings, messages, AI disclosures, and personal data.
- Use data minimization, retention, access, suppression, and deletion settings appropriate to the use case.
- Do not send regulated or sensitive information unless the applicable agreement, feature, and safeguards permit it.
- Respond to requests from people whose information the customer controls and configure human escalation where automated processing is not appropriate.
4. Confidentiality and security
Tig.ai will require people authorized to process customer content to maintain confidentiality. Tig.ai will maintain reasonable technical and organizational measures designed to protect customer content against unauthorized access, use, alteration, or disclosure.
Measures may include access controls, authentication, encryption in transit where supported, logging, backups, incident response, vulnerability management, and vendor security reviews. The controls applicable to a workspace may depend on the plan, product configuration, and written agreement.
The customer is responsible for its own credentials, devices, integrations, instructions, permissions, and decisions about which data to send to the service.
5. Subprocessors and third parties
The customer authorizes Tig.ai to use subprocessors that support infrastructure, storage, communications, payments, analytics, speech processing, language models, security, support, and other service operations. Tig.ai remains responsible for the subprocessors it appoints to the extent required by applicable law or the agreement.
Customer-managed providers, integrations, carriers, and services connected with the customer's own credentials are not Tig.ai subprocessors. The customer is responsible for reviewing and configuring those providers and for their processing activities.
The applicable provider list, trust materials, order form, or notice may describe the subprocessors used for a particular service. Tig.ai may update that list and will provide notice or an objection process when required by the applicable agreement.
6. Rights requests and incidents
Taking into account the nature of the processing, Tig.ai will provide reasonable assistance to help the customer respond to requests to access, correct, export, restrict, or delete personal information. The customer remains responsible for verifying the requester's authority and responding to the individual unless the law assigns that duty to Tig.ai.
Tig.ai will notify the customer of a confirmed security incident involving customer content without undue delay where required by the applicable agreement or law. The notice will include information reasonably available to help the customer assess and meet its own notification obligations.
7. Transfers, return, and deletion
Customer content may be processed in countries where Tig.ai, its affiliates, or its subprocessors operate. The parties will use the transfer mechanism and safeguards required by applicable data-protection law or the applicable agreement.
At the customer's request or when the service ends, Tig.ai will delete or return customer content according to the workspace controls and applicable agreement, except where retention is required by law or content remains in routine backups for a limited period before secure deletion.
8. Regulated data, audits, and precedence
The customer must not use the service for regulated health, payment-card, biometric, government-identification, or other sensitive data unless Tig.ai has expressly agreed in writing to the required safeguards, certifications, or sector-specific terms. A separate business associate agreement or security addendum may be required.
Tig.ai will make available information reasonably necessary to demonstrate compliance with applicable processor obligations, subject to confidentiality, security, and reasonable limitations. Audits must not compromise other customers or the security of the service.
If this addendum conflicts with the Privacy Policy or Terms of Service about customer-content processing, this addendum controls for that processing. A signed order form or negotiated data-processing agreement controls where it expressly says so.
Questions about this addendum?
Contact legal@tig.ai and include the workspace, processing activity, and agreement that your request relates to.
