Effective date: August 5, 2026 · Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Genez LLC ("TalkOmni", "Processor") and the business that uses TalkOmni ("Customer", "Controller"). It applies whenever TalkOmni processes personal data on the Customer's behalf. No signature is required: it takes effect when the Customer accepts the Terms of Service. A countersigned copy is available on request at support@talkomni.com.
Terms such as personal data, processing, controller, processor, data subject and personal data breach have the meaning given in the EU General Data Protection Regulation (GDPR) and, for Turkey, the corresponding terms of the Personal Data Protection Law No. 6698 (KVKK).
1. Roles
The Customer is the controller (in KVKK terms, the veri sorumlusu) of the personal data it brings into or generates through its workspace: conversations, voice calls, form submissions, leads, contacts and uploaded documents. TalkOmni is the processor (veri işleyen) of that data.
TalkOmni is a controller in its own right for data about the Customer itself: account, billing, support, security and usage data. That processing is described in the Privacy Policy and is outside this DPA.
2. Scope and instructions
TalkOmni processes Customer personal data only:
- to provide, secure, maintain and support the service under the Terms of Service;
- in accordance with the Customer's documented instructions, which are given through the configuration of the workspace, the use of the dashboard and API, and any written instruction sent to support@talkomni.com;
- as required by applicable law, in which case TalkOmni informs the Customer beforehand unless the law prohibits it.
TalkOmni does not sell Customer personal data, does not use it for advertising, and does not use it to train AI models. If TalkOmni believes an instruction infringes data protection law, it will inform the Customer and may suspend performance of that instruction.
The details required by Article 28(3) of the GDPR (subject matter, duration, nature and purpose of processing, types of personal data and categories of data subjects) are in Annex I.
3. Confidentiality
TalkOmni grants access to Customer personal data only to personnel who need it to perform the service, who are bound by confidentiality obligations and who are trained on their data protection duties. Administrative access is restricted and logged.
4. Security
TalkOmni implements and maintains the technical and organizational measures described in Annex II, appropriate to the risk. Those measures may evolve, but the overall level of protection will not be reduced during the term.
5. Personal data breach
TalkOmni notifies the Customer of a personal data breach affecting Customer personal data without undue delay and, wherever feasible, within 48 hours of becoming aware of it. The notification describes the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. TalkOmni provides reasonable assistance so the Customer can meet its own notification duties to authorities and data subjects. Notification is not an admission of fault.
6. Sub-processors
The Customer gives general authorization for TalkOmni to engage the sub-processors listed in Annex III. TalkOmni:
- imposes data protection obligations on each sub-processor that are no less protective than this DPA;
- remains fully liable to the Customer for its sub-processors' performance;
- publishes the current list in section 9 of the Privacy Policy and announces any new or replacement sub-processor at least 30 days before it starts processing, by email to the workspace owner or a notice in the dashboard.
The Customer may object to a new sub-processor on reasonable data protection grounds within that 30-day period. The parties will discuss the objection in good faith; if no solution is found, the Customer may terminate the affected part of the service and receive a refund of prepaid fees for the unused period.
7. Assistance to the Customer
Taking into account the nature of the processing and the information available, TalkOmni assists the Customer with:
- responding to data subject requests for access, correction, deletion, restriction, objection and portability. The dashboard and API let the Customer fulfil most requests directly; where it cannot, TalkOmni helps within a reasonable time. If a request reaches TalkOmni directly, it is forwarded to the Customer without undue delay and TalkOmni does not respond on the merits unless instructed;
- data protection impact assessments and prior consultations with a supervisory authority;
- demonstrating compliance with Article 28 of the GDPR and the corresponding KVKK obligations.
8. Deletion and return
On termination of the service, workspace data stays available for export for 30 days. After that period TalkOmni deletes or anonymizes Customer personal data within 90 days, including in routine backups as they expire on their normal cycle, unless a longer retention is required by law. TalkOmni confirms deletion in writing on request. Retention periods for specific data types are set out in section 7 of the Privacy Policy.
9. Audit
TalkOmni makes available the information necessary to demonstrate compliance with this DPA and provides, on request and no more than once a year, responses to a reasonable written security questionnaire and copies of any current certifications or reports. Where an on-site or in-depth audit is required by law or by a supervisory authority, the parties agree the scope, timing and cost in advance, and the audit is conducted during business hours, subject to confidentiality, and in a way that does not disrupt the service or affect other customers.
10. International transfers
TalkOmni's primary infrastructure is in the European Union (Google Cloud, Belgium region). TalkOmni is established in the United States and certain sub-processors listed in Annex III process data outside the European Economic Area and outside Turkey.
For transfers from the EEA, the United Kingdom or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) where the Customer is a controller and Module Three (processor to processor) where the Customer acts as a processor for another controller, together with the UK International Data Transfer Addendum where the UK GDPR applies. In those clauses: the Customer is the data exporter and TalkOmni the data importer; Annexes I, II and III of this DPA supply the corresponding annex content; the optional docking clause applies; the supervisory authority is that of the Customer's establishment; and the governing law and forum are those set out in the Standard Contractual Clauses.
For transfers of personal data of individuals in Turkey, the parties rely on the transfer conditions of Article 9 of the KVKK, including the standard contract and undertaking mechanisms recognized by the Turkish Personal Data Protection Board and, where applicable, the explicit consent of the data subject, which the Customer is responsible for obtaining. TalkOmni signs the applicable Board-approved standard contract on request and provides the information needed to notify or register it.
11. Customer responsibilities
The Customer warrants that it has a lawful basis for the personal data it processes through the service, that it has provided the required privacy notice to its own end users (including the aydınlatma metni under the KVKK), that it has obtained any consent required for marketing messages, outbound calls and call recording, and that it does not send TalkOmni special categories of personal data without a lawful basis. The Customer configures retention, access and channel settings appropriately for its own risk.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
13. Term, changes and contact
This DPA applies for as long as TalkOmni processes Customer personal data. TalkOmni may update it to reflect legal or service changes, with at least seven days' notice before the effective date; the version and date above are updated accordingly.
Genez LLC · 1209 Mountain Road Pl NE #8028, Albuquerque, NM 87110, USA · support@talkomni.com
Annex I — Details of processing
Subject matter: provision of the TalkOmni omnichannel AI customer assistant.
Duration: the term of the Customer's subscription, plus the deletion periods in section 8.
Nature and purpose: receiving, storing, analyzing and answering end-user messages and calls; retrieving answers from Customer documents; executing Customer-approved actions against Customer systems; capturing leads and form submissions; routing conversations to human agents; producing transcripts, summaries and analytics.
Categories of data subjects: the Customer's end users and customers; the Customer's own personnel who use the dashboard; contacts submitted through forms and landing pages.
Types of personal data: identifiers provided by the channel (phone number, username, email address, name); message content and any files or images sent in a conversation; voice call metadata, audio, transcripts, summaries and analysis; form field values, consent flags and marketing attribution parameters; appointment and lead records; IP address and technical logs; content of documents the Customer uploads, which may itself contain personal data.
Special categories: not requested by TalkOmni and not required by the service. Where a Customer's sector means an end user may volunteer such data, it is processed only as part of the conversation content under the Customer's instructions and lawful basis.
Frequency of transfer: continuous, for as long as the service is used.
Annex II — Technical and organizational measures
- Tenant isolation: every query is scoped to the organization and project; ownership is verified in the service layer, not only at the route.
- Encryption: TLS for all data in transit; managed encryption at rest for the database and object storage; channel tokens, API keys and gateway credentials encrypted at rest and never displayed back in full.
- Access control: role-based access in the dashboard (owner, admin, representative), invite-only membership, administrative access restricted to named personnel and recorded in an audit log with actor and IP.
- Authentication: password hashing with bcrypt at a cost above the OWASP baseline, short-lived access tokens with rotating refresh tokens, bot protection on sign-up, login and recovery.
- Action safety: actions the assistant performs against Customer systems are whitelisted, parameter-validated on the server and audit-logged; write actions are never inferred from model output alone.
- Webhook and API integrity: signature verification with constant-time comparison, idempotency enforced by database constraints, rate limiting on authentication and inbound webhooks, trusted client IP resolution.
- Network and infrastructure: managed hosting on Google Cloud (EU) and Vercel, hardened HTTP timeouts, outbound requests through clients with enforced timeouts and SSRF protection.
- Logging and monitoring: application, error and audit logs with defined retention; alerting on abuse and anomaly signals; secrets excluded from logs by a redaction helper.
- Data lifecycle: automated retention jobs for visitor uploads and request logs; documented export and deletion process on termination.
- Organizational: confidentiality obligations for all personnel with access, least-privilege credential issuance, environment separation, and review of security-relevant changes before release.
Annex III — Sub-processors
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Google Cloud | API hosting, managed database, file storage | EU (Belgium) |
| Vercel | Website and dashboard hosting | EU / global edge |
| Anthropic | AI language model powering assistant replies | US |
| Voyage AI | Text embeddings for document search | US |
| VAPI | Voice call orchestration and call recordings | EU / US |
| Deepgram | Speech-to-text for voice calls | US |
| ElevenLabs | Text-to-speech for voice calls and avatars | US |
| fal.ai | Avatar image editing and lip-sync video rendering | US |
| Stripe | Payments and subscription billing | US / EU |
| Meta Platforms | WhatsApp, Instagram and Messenger message delivery | US / EU |
| Telegram | Telegram message delivery | Global |
| Cloudflare | DNS, security and bot protection | Global |
| Google (reCAPTCHA) | Abuse prevention on authentication flows | US |
| Google (Gmail SMTP) | Transactional email delivery | US / EU |