This Data Processing Agreement (this "DPA") forms part of, and is incorporated by reference into, the OverFlow Terms of Service (the "ToS") between Better Flow Ai, LLC, a New York limited liability company ("Better Flow Ai, LLC", "we", "us", or "our"), and the customer that subscribes to the Services (the "Customer", "you"). This DPA governs our processing of Personal Information in connection with the OverFlow AI voice-agent service ("OverFlow" or the "Services"). Capitalized terms not defined here have the meanings given in the ToS.
1. Definitions
For purposes of this DPA, the following terms apply. They are intended to align with CCPA/CPRA. Where a term is defined in the CCPA/CPRA, that statutory definition controls.
1.1 "Business" means the Customer, in its capacity as the entity that determines the purposes and means of the Processing of Personal Information collected about Callers and its own staff through the Services. The Customer is the "Business" with respect to such Personal Information.
1.2 "Service Provider" means Better Flow Ai, LLC, in its capacity as the entity that Processes Personal Information on behalf of the Business pursuant to the written contract formed by this DPA and the ToS.
1.3 "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Caller, Customer staff member, or other natural person or household, as further described in Appendix A. It includes the Caller data categories listed in Appendix A.
1.4 "Caller" means a homeowner or other third party who telephones the Customer's forwarded line and whose call is answered by the OverFlow AI voice agent.
1.5 "Consumer", "Sell", "Share", "Process"/"Processing", "Service Provider", "Contractor", "Third Party", "Business Purpose", and "Commercial Purpose" have the meanings given in the CCPA/CPRA. "Sensitive Personal Information" has the meaning given in the CCPA/CPRA.
1.6 "Subprocessor" means any third party engaged by us to Process Personal Information on the Business's behalf in connection with the Services, as listed in Appendix B.
1.7 "Permitted Purpose" means the limited and specified purpose of providing, operating, supporting, securing, and improving the Services for the Customer as described in this DPA, Appendix A, and the ToS, and performing the Business Purposes set out in Section 3.2.
1.8 "Privacy Law" means the CCPA/CPRA and any other U.S. state or federal data-protection or privacy law applicable to the Processing under this DPA.
2. Roles and Scope
2.1 Roles. As between the parties, the Customer is the Business and we are the Service Provider with respect to all Personal Information Processed through the Services. We Process Personal Information solely as a Service Provider and not as a Third Party.
2.2 Customer as Business. The Customer is responsible, as the Business, for (a) establishing a lawful basis and providing legally required notices to Callers and staff, (b) the accuracy of any Processing instructions it gives, and (c) compliance with Privacy Law applicable to its own collection and use of Personal Information. The Customer represents that it has the right to provide, and to direct our Processing of, the Personal Information it routes to or generates through the Services.
2.3 Scope of our Processing. We will Process Personal Information only:
(a) to provide, operate, maintain, secure, support, and (subject to §3) improve the Services; (b) on the Customer's documented instructions, which are given by (i) this DPA and the ToS, (ii) the Customer's configuration choices in the Services (e.g., alert recipients, SMS settings, service radius), and (iii) any further written instructions the Customer gives that we agree to in writing; and (c) as otherwise required by applicable law, in which case we will, where legally permitted, inform the Customer of that legal requirement before Processing.
2.4 Conflicting instructions / unlawful instructions. If we believe an instruction violates Privacy Law, we will inform the Customer (and are not obligated to follow it). If we cannot provide at least the same level of protection as required of a Service Provider under Privacy Law, we will notify the Customer and the Customer may take reasonable steps under §13.
2.5 What this DPA does and does not cover. This DPA covers Personal Information we Process as a Service Provider on the Customer's behalf (Caller data and Customer-staff data within the Services). It does not cover (a) Personal Information we Process as a Business for our own account — e.g., the Customer's own account-administrator contact details, billing data, and usage analytics used to run our business — which is governed by our Privacy Policy; or (b) tokenized payment-card data, which is handled by our payment processor (Stripe) as described in §8 and the ToS.
3. CCPA/CPRA Service-Provider Commitments
We make the following commitments with respect to Personal Information Processed under this DPA, as required of a Service Provider under the CCPA/CPRA (Cal. Civ. Code § 1798.140(ag) and § 1798.100(d)):
3.1 No sale; no sharing. We will not Sell and will not Share (as "Share" is defined for cross-context behavioral advertising) any Personal Information. We receive no monetary or other valuable consideration for Personal Information beyond the fees the Customer pays us for the Services.
3.2 Purpose limitation — Permitted Purpose only. We will not retain, use, or disclose Personal Information for any purpose other than the Permitted Purpose, including the following Business Purposes: answering and recording missed/after-hours calls; transcribing calls; capturing and triaging lead information; sending the Customer's staff alert texts and emails and a daily digest; sending the Caller a confirmation text only where the Caller gave verbal consent on the call; geocoding the property address; referring a Caller, with the Caller's consent given on the call, to another OverFlow business designated by the Customer or participating in the Emergency Assist Network the Customer has opted in to; where the Customer has opted in to the Emergency Assist Network, displaying the approximate (ZIP-code-level) location, problem type, urgency and hour of overflow calls to other opted-in businesses in the same trade nearby while a declared emergency is active; securing and debugging the Services; and detecting and preventing fraud or abuse. We will not retain, use, or disclose Personal Information for any Commercial Purpose other than providing the Services, or outside the direct business relationship with the Customer.
3.3 No combining across customers. We will not combine the Personal Information we receive from, or on behalf of, the Customer with Personal Information we receive from, or on behalf of, any other person or Customer, or that we collect from our own interaction with the Consumer, except (a) as the Customer instructs through a consented referral or the Emergency Assist Network opt-in described in the ToS, and (b) as permitted by the CCPA/CPRA to perform a Business Purpose (e.g., to detect security incidents or prevent fraud). OverFlow's multi-tenant database is logically segregated per Customer using row-level tenant isolation (see Appendix C).
3.4 No use outside the direct business relationship. We will not retain, use, or disclose Personal Information outside of the direct business relationship between us and the Customer, except as the Customer instructs through a consented referral or the Emergency Assist Network opt-in, or where permitted by the CCPA/CPRA.
3.5 No independent AI training on Caller data. We will not use Personal Information to train, fine-tune, or develop generative or other AI/ML models for our own benefit or for any third party's benefit, and we will contractually require our voice-AI and LLM Subprocessors not to do so (see Appendix B).
3.6 Certification. We certify that we understand the restrictions and obligations set out in this §3 and will comply with them.
3.7 Notice of inability to comply. We will notify the Customer if we determine we can no longer meet our obligations under Privacy Law as a Service Provider.
3.8 Onward disclosures. We will disclose Personal Information to Subprocessors only under a written contract that binds them to Service-Provider/Contractor-equivalent restrictions consistent with this §3.
4. Appendix A — Details of Processing
A.1 Subject matter. Our Processing of Personal Information about Callers and Customer staff to provide the OverFlow AI voice-agent Services to the Customer.
A.2 Duration. For the term of the ToS, plus the retention/deletion periods in §10.
A.3 Nature and purpose of Processing. Receiving forwarded missed/after-hours calls; AI-voice answering with a locked disclosure that the call is recorded and the agent is AI; audio recording; transcription; triage (emergency detection, problem, property address + ZIP, callback number, derived urgency/emergency flag); storage in a multi-tenant Postgres database; sending staff alert texts/emails, mobile push notifications to staff devices running the OverFlow companion app, and daily digests; sending Caller confirmation texts where consent was given; geocoding; and securing, supporting, and debugging the Services. The Permitted Purposes are as set out in §3.2.
A.4 Categories of Personal Information (Caller data).
- Voice recording (audio of the call)
- Transcript of the call
- Caller name
- Callback / phone number
- Property address and ZIP code
- Approximate location derived from the ZIP code (ZIP-centroid; never the street address)
- Problem / damage description (free text, as spoken)
- Derived urgency / emergency flag
- Call metadata (date, time, duration, the OverFlow number called)
A.5 Categories of Consumers / data subjects.
- Callers — homeowners and other third parties who phone the Customer's forwarded line.
- Customer staff — the Customer's owners, technicians, dispatchers, and other personnel who receive alerts/digests or use the dashboard or companion app (names, business contact details, alert-recipient phone numbers/emails, and mobile push tokens with device platform for staff who install the app).
A.6 Frequency. Continuous / on an ongoing basis, triggered by inbound calls and Customer use.
5. Subprocessors
5.1 General authorization. The Customer provides a general authorization for us to engage Subprocessors to Process Personal Information for the Permitted Purpose, subject to this §5.
5.2 Subprocessor obligations. Before a Subprocessor Processes Personal Information, we will impose on it, by written contract, data-protection obligations no less protective than those in this DPA and as required of a Subprocessor/Contractor under the CCPA/CPRA, including the purpose-limitation, no-sale/no-share, and no-independent-AI-training restrictions. We remain responsible to the Customer for each Subprocessor's performance.
5.3 Current Subprocessors. As of the Effective Date, our Subprocessors are:
| Subprocessor | Function | Personal Information involved |
|---|---|---|
| Supabase | Database hosting, authentication (multi-tenant Postgres) | All stored Caller and staff data |
| Vercel | Application hosting / infrastructure | Data in transit; logs |
| Twilio | Inbound voice, call recording transport, SMS (A2P 10DLC) | Phone numbers, recordings, SMS content |
| Retell | Voice-AI agent orchestration | Audio, transcript (real-time) |
| Retell's LLM provider | Large-language-model inference used by the voice agent | Transcript / call content sent for inference |
| Stripe | Payment processing (tokenized cards) | Customer billing data (not Caller data) |
| Resend | Transactional email (alerts, daily digest) | Staff email addresses; lead summaries |
| Expo (Expo Application Services) | Mobile push relay for the companion app | Device push tokens; alert content for lead, voicemail, inbound-referral and emergency notifications (caller name, callback number, problem/message summary) |
| Apple Push Notification service | OS-level push delivery to iOS devices | Device push tokens; alert content as above |
| Google Firebase Cloud Messaging | OS-level push delivery to Android devices | Device push tokens; alert content as above |
| OpenStreetMap Nominatim | Geocoding property address → coordinates | Property address / ZIP |
| Google Maps Platform (Geocoding API) | Geocoding property address → coordinates (primary when configured) | Property address / ZIP |
5.4 Change notice. We will notify the Customer of any intended addition or replacement of a Subprocessor at least 30 days before that Subprocessor begins Processing Personal Information, by email to the Customer's account-admin contact and/or by updating our published subprocessor page (with notification subscription available). If the Customer reasonably objects on data-protection grounds within 30 days, the parties will work in good faith to address the concern; if it cannot be resolved, the Customer's sole remedy is to terminate the affected Services under the ToS and obtain a pro-rata refund of any prepaid, unused fees.
6. Security Measures
6.1 We will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Information against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure, appropriate to the nature of the data and the risks of a small SaaS handling Caller lead data. These measures are described in Appendix C.
6.2 We will take reasonable steps to ensure that personnel authorized to Process Personal Information are subject to confidentiality obligations and access it only as needed for the Permitted Purpose.
7. Appendix C — Technical and Organizational Security Measures
The following measures apply as of the Effective Date and may be updated to equivalent or stronger measures over time:
- Tenant isolation: Multi-tenant Postgres (Supabase) with row-level security (RLS) enforcing per-Customer logical segregation so one Customer cannot access another's Caller data.
- Encryption in transit: TLS/HTTPS for data in transit between Callers' carriers, our application, and Subprocessors; SMS/voice transport secured per carrier/Twilio standards.
- Encryption at rest: Our production database — including call transcripts, lead records, and message content — is encrypted at rest with AES-256 via Supabase's managed encryption. Call audio recordings are not stored in our database or on our infrastructure: they are hosted by our voice Subprocessor (Retell) and are subject to that Subprocessor's storage and encryption controls; we retain only a reference to each recording. Recordings are deleted at the Subprocessor on the schedule published in our Privacy Notice.
- Access controls: Authentication on the Customer dashboard; role-based and least-privilege access to production systems; administrative access limited to authorized personnel.
- Tokenized card data: Payment cards are tokenized by Stripe; we never store full card numbers.
- Logging & monitoring: Application and access logging via the hosting platform; reasonable monitoring for security events.
- Secrets management: API keys and credentials for Subprocessors stored as protected environment secrets, not in source code.
- Backups: Automated daily database backups with a 7-day retention window (Supabase Pro).
- Change/access review: Periodic review of access and Subprocessor configurations as the team scales.
8. Tokenized Payment Data
Payment-card data is collected and tokenized by our payment processor, Stripe, in connection with the 14-day free trial that auto-renews at the monthly price of the plan tier selected at signup (and any setup fee) under the ToS. We never store full card numbers. Stripe Processes cardholder data under its own role and PCI-DSS obligations; this is Customer billing data and is not Caller Personal Information Processed on the Business's behalf under §2–§3.
9. Personal-Data Breach Notification
9.1 Notice. If we become aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information Processed under this DPA (a "Security Incident"), we will notify the affected Customer without undue delay, and in any event we will use commercially reasonable efforts to notify within 72 hours of confirming the incident.
9.2 Contents. The notice will, to the extent known, describe the nature of the incident, the categories and approximate number of Consumers and records affected, the likely consequences, and the measures taken or proposed to address it. We will provide updates as more information becomes available.
9.3 Cooperation. We will reasonably cooperate with the Customer's investigation and the Customer's own breach-notification obligations to Consumers and regulators. The Customer, as the Business, is responsible for determining whether and how to notify affected Callers, staff, or regulators under applicable law.
9.4 No admission. Our notice or cooperation is not an acknowledgment of fault or liability.
10. Assistance; Data-Subject Requests; Deletion and Return
10.1 Consumer rights requests. Taking into account the nature of our Processing, we will provide reasonable assistance, by appropriate technical and organizational measures, to help the Customer respond to verifiable Consumer requests to know, access, correct, delete, or opt out under Privacy Law, to the extent the Customer cannot fulfill the request itself through the Services (e.g., via the dashboard). If a Caller or other Consumer contacts us directly with such a request, we will, unless legally required to act, promptly forward it to the relevant Customer and not respond substantively except to direct the Consumer to the Customer.
10.2 Compliance assistance. Taking into account the information available to us, we will provide the Customer reasonable assistance with the Customer's data-protection impact assessments, security obligations, and Security Incident handling related to the Services. We may charge a reasonable fee for assistance that is unusually burdensome or repetitive.
10.3 Deletion / return on termination. On expiry or termination of the ToS, or earlier on the Customer's written request, we will, within 30 days and at the Customer's choice, delete or return the Personal Information we Process on the Customer's behalf, and delete existing copies, except to the extent retention is required by law or for a permitted Business Purpose (e.g., short-term backups, fraud prevention, or dispute defense), in which case the data remains protected under this DPA until deleted.
10.4 Propagation to Subprocessors. We will instruct our Subprocessors to delete or return the relevant Personal Information consistent with §10.3, and will use commercially reasonable efforts to confirm deletion within their respective retention cycles (including backup expiry).
10.5 Deletion on Consumer request. Where the Customer directs us to delete a specific Consumer's Personal Information to satisfy a deletion request, we will delete it from active systems and notify Subprocessors to do the same, subject to the legal-retention and backup-expiry exceptions above.
11. International Transfers
11.1 U.S.-only today. As of the Effective Date, Personal Information under this DPA is Processed and stored in the United States, and the Services are offered to U.S. Customers serving U.S. Callers only. Subprocessors are engaged on a U.S.-processing basis where reasonably available.
12. Audit Rights
12.1 Information. On the Customer's reasonable written request (no more than once per 12 months, unless required by a regulator or following a Security Incident affecting the Customer), we will make available information reasonably necessary to demonstrate our compliance with this DPA — including a summary of our security measures (Appendix C), our subprocessor list, and any third-party reports, certifications, or questionnaires we maintain.
12.2 On-site / further audit. Where the information in §12.1 is insufficient and an audit is required by Privacy Law or a regulator, the parties will agree in advance on reasonable scope, timing, notice (at least 30 days), confidentiality, and cost. Any audit will be conducted during business hours, will not unreasonably disrupt our operations or compromise other customers' data or confidentiality, and will be at the Customer's expense unless it reveals our material non-compliance.
13. Liability and Precedence
13.1 Precedence. This DPA is incorporated into and forms part of the ToS. If there is a conflict between this DPA and the ToS on the subject matter of data protection and the Processing of Personal Information, this DPA controls. On all other matters, the ToS controls.
13.2 Liability cap. Each party's liability arising out of or related to this DPA is subject to, and counts toward, the limitations and exclusions of liability (including any aggregate liability cap) set out in the ToS, except where applicable law does not permit such limitation.
13.3 Governing law. This DPA is governed by the laws of New York, consistent with the ToS, without regard to conflict-of-laws rules, and subject to the dispute-resolution provisions of the ToS.
14. Term; Order of the Parties
This DPA takes effect on the Effective Date and remains in effect for as long as we Process Personal Information on the Customer's behalf under the ToS. Provisions that by their nature should survive termination (including §3, §9, §10, §12, and §13) survive.
15. Signatures
This DPA is entered into by the parties' authorized representatives and is effective as of the Effective Date. Acceptance of the ToS constitutes acceptance of this DPA; a separately signed copy may be executed on request.
SERVICE PROVIDER — Better Flow Ai, LLC
Registered address: 36 Sunset Trail, Fairport, New York 14450 Privacy contact: admin@overflowvoice.com (Privacy Administrator, Better Flow Ai, LLC)
BUSINESS — CUSTOMER