• Enterprise
  • Pricing
Login

Features

Product OverviewBuild, deploy and optimize AI Agents.ProceduresTrain your agent like a new teammate.HelpdeskHand off complex issues to humans.CopilotAsk your conversations what customers need.

Outreach

Email campaignsSend campaigns that start a conversation.Voice campaignsReach customers with a natural voice.

Industries

TechnologyTravel & HospitalityRetail & EcomFinancial ServicesEducationFitness & Wellness

Use cases

Customer Support AgentSales Agent

Learn

BlogIdeas, guides and product updates.LLM infoHow AI can learn about Guzli.Product overviewExplore the Guzli platform.

Latest from the blog

Connect Guzli to ClaudeConnect Guzli to Claude and ChatGPT via MCPSeptember 25, 2026Best AI Chatbot for WooCommerceBest AI Chatbot for WooCommerce Live Chat and Phone (2026)September 21, 2026Bland AIBland AI vs a Chat + Phone AI Agent (2026)September 21, 2026

Connect Guzli to Claude and ChatGPT via MCPNew

You can now hook Guzli straight into Claude or ChatGPT and just ask for things in plain English. No copying API keys, no engineering help needed.

Learn more →
  • Product

    Product OverviewProceduresHelpdeskCopilot

    Outreach

    Email campaignsVoice campaigns
  • Solutions

    TechnologyTravel & HospitalityRetail & EcomFinancial ServicesEducationFitness & WellnessCustomer Support AgentSales Agent
  • Resources

    Learn

    BlogLLM infoProduct overview
  • Enterprise
  • Pricing
Login
Home/ Legal/ Data Processing Addendum

Data Processing Addendum

How Guzli processes personal data on behalf of customers.

On this page

Parties and scopeDefinitionsRolesDetails of processingProcessor obligationsInternational transfersLiabilityTerm

Draft for legal review — not yet executed.

Parties and scope

This draft Data Processing Addendum (DPA) describes the processing of personal data by Guzli on behalf of a customer using Guzli’s services. It is intended to supplement an executed service agreement between Guzli and that customer. It has no effect until the parties agree to it.

Definitions

Customer personal data means personal data submitted to, collected through, or generated by the services on the customer’s behalf. Applicable data protection law means the privacy and data protection laws that apply to that processing. Sub-processor means a third party engaged by Guzli to process customer personal data for the services. Terms such as controller, processor, data subject, and personal data have the meanings given by applicable data protection law.

Roles

The customer determines the purposes and means of processing customer personal data and acts as controller. Guzli processes that data on the customer’s documented instructions and acts as processor. The customer is responsible for its instructions, notices, permissions, and lawful basis for using the services. If applicable law requires Guzli to process data outside those instructions, Guzli will inform the customer before doing so unless the law prohibits notice.

Details of processing

  • Subject matter: Customer personal data handled through Guzli’s chat, email, and voice agents, related helpdesk workflows, and service administration.
  • Duration: For the term of the customer’s service agreement, plus any period needed to complete return or deletion under this DPA or to meet legal retention duties.
  • Nature and purpose: Receiving, recording, storing, retrieving, analyzing, transmitting, and deleting data to configure agents, answer and route conversations, perform requested actions, provide human handoff, and operate and secure the services.
  • Data subjects: The customer’s end users, website visitors, callers, email correspondents, leads, and authorized team members.
  • Categories of data: Contact and account details, conversation and call content, voice recordings or transcripts when enabled, customer support details, knowledge content, and technical usage data. Actual categories depend on the customer’s configuration and use.

Processor obligations

Guzli will:

  1. Process customer personal data only on documented customer instructions, including instructions about transfers, unless applicable law requires otherwise.
  2. Ensure people authorized to process customer personal data are bound by confidentiality obligations.
  3. Maintain appropriate technical and organizational security measures for the risk, including access controls, protection of data in transit, and processes for identifying and responding to security incidents.
  4. Engage sub-processors only under written obligations that protect customer personal data to a comparable standard. Relevant service categories may include cloud hosting, large language model providers, and telephony providers. Guzli will give notice of proposed additions or replacements and a reasonable opportunity to object before they process customer personal data.
  5. Assist the customer, taking into account the nature of processing and information available to Guzli, with requests from data subjects and with the customer’s obligations concerning security, breach assessment, impact assessments, and regulator consultation.
  6. Notify the customer without undue delay, and within 72 hours after becoming aware, of a personal data breach affecting customer personal data. Guzli will provide available details and reasonable cooperation as the investigation develops.
  7. At the end of the services, at the customer’s choice, return or delete customer personal data, unless applicable law requires retention. Any retained data remains subject to this DPA’s protections.
  8. Make information reasonably necessary to demonstrate compliance available to the customer and permit reasonable audits or inspections, subject to appropriate confidentiality, security, and scheduling safeguards.

Guzli will promptly inform the customer if, in its opinion, an instruction infringes applicable data protection law.

International transfers

If customer personal data is transferred to a country requiring a transfer safeguard, the parties will use an appropriate lawful mechanism, such as the applicable Standard Contractual Clauses (SCCs), and any required supplementary measures. The parties will complete the relevant SCC modules and annexes before relying on them for a restricted transfer. Guzli will require appropriate transfer safeguards from relevant sub-processors.

Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in its executed service agreement, to the extent permitted by applicable law. Nothing in this draft limits a liability that cannot legally be limited.

Term

Once executed, this DPA takes effect with the service agreement and continues for as long as Guzli processes customer personal data on the customer’s behalf. Its confidentiality, security, return or deletion, and audit obligations survive as needed to complete that processing and meet applicable law.

Questions about this policy?

Our team can help you understand how these terms apply to Guzli.

Email our team
Guzli

Product

  • Product overview
  • Procedures
  • Helpdesk
  • Copilot

Outreach

  • Email campaigns
  • Voice campaigns

Solutions

  • Retail & Ecom
  • Technology
  • Travel & Hospitality
  • Financial Services
  • Education
  • Fitness & Wellness
  • Customer Support Agent
  • Sales Agent

Resources

  • Blog
  • Pricing
  • Enterprise
  • LLM info

Policy

  • Privacy Policy
  • Terms & conditions
  • DPA
  • Cookie Policy
Request AI summary

© 2026 Guzli Inc.

✧ Hey AI, learn about us
Guzli

  • Product overview
  • Procedures
  • Helpdesk
  • Copilot

  • Email campaigns
  • Voice campaigns

  • Retail & Ecom
  • Technology
  • Travel & Hospitality
  • Financial Services
  • Education
  • Fitness & Wellness
  • Customer Support Agent
  • Sales Agent

  • Blog
  • Pricing
  • Enterprise
  • LLM info

  • Privacy Policy
  • Terms & conditions
  • DPA
  • Cookie Policy
Request AI summaryHey AI, learn about us

© 2026 Guzli Inc.

HIPAASOC 2GDPR
HIPAASOC 2GDPR