1 · Purpose & scope of processing
This Data Processing Agreement (“DPA”) forms part of the agreement between Rozper, Inc. (“Rozper,” “we,” or “Processor”) and the business customer that has signed up for the Rozper platform (the “Customer” or “Controller”). It governs the processing of personal data that occurs when Customer uses Rozper's UCaaS, wholesale voice, SIP trunking, virtual number, and bulk messaging services (the “Services”) to communicate with its own end users, contacts, and employees.
The purpose of processing is narrow and functional: to route calls and messages, provision virtual numbers across our 150+ country footprint, generate billing records, and — where Customer has switched the feature on — record, transcribe, or analyze conversations for quality and compliance purposes. Rozper processes personal data only to deliver the Services Customer has configured, for the duration of the underlying commercial agreement, unless a longer period is required by law.
2 · Roles: Rozper as processor, Customer as controller
For the purposes of applicable data protection law (including the EU/UK GDPR and the California Consumer Privacy Act), the parties agree that Customer acts as the data controller(or “business,” under CCPA terminology) with respect to personal data of its end users, contacts, and employees that flows through the Services. Rozper acts as the data processor(or “service provider”), processing that data solely on Customer's documented instructions as set out in this DPA, the underlying agreement, and Customer's configuration of the platform.
Rozper does not determine the purposes for which personal data passing through Customer's tenant is processed, and does not sell, rent, or use that data for its own advertising purposes. Where Rozper processes account, billing, or marketing-site data about Customer's own personnel, it does so as an independent controller, as described in our Privacy Policy.
3 · Categories of personal data processed
The Services can touch several categories of personal data, depending on which products Customer has enabled:
- Call & message metadata. Calling and called numbers, timestamps, duration, routing legs, SMS delivery receipts, and carrier codes generated as calls and messages traverse our network.
- Recordings & transcripts. Audio recordings, AI-generated transcripts, and conversation summaries, but only where Customer has enabled call recording or transcription for a given number or queue.
- Contact & CRM data. Names, phone numbers, email addresses, and account identifiers that Customer syncs from its CRM or helpdesk into Rozper to power caller ID, routing rules, or click-to-call workflows.
- Billing & account data. Invoicing details, usage volumes, and payment references tied to Customer's own account, handled under the payment-processing terms described in our Privacy Policy.
- Agent/user identifiers. Names and login credentials of Customer's employees or contractors provisioned as seats on the platform.
Rozper does not require Customer to submit special categories of data (Article 9 GDPR) to use the Services, and asks Customer not to route such data through the platform unless a specific written arrangement is in place.
4 · Processing instructions & staff confidentiality
Rozper will process personal data only on documented instructions from Customer — including instructions embedded in Customer's configuration of routing rules, recording toggles, and integrations — unless required to do otherwise by law binding on Rozper, in which case Rozper will inform Customer of that legal requirement before processing, unless the law prohibits such notice.
Every Rozper employee and contractor with access to systems that may contain Customer personal data is bound by written confidentiality obligations that survive the end of their employment, and completes security and data-handling training before receiving access. Access to production systems carrying call content or recordings is restricted on a least-privilege basis and logged.
5 · Sub-processor use & right to object
Customer provides general authorization for Rozper to engage sub-processors to help deliver the Services — for example, cloud infrastructure hosting, carrier interconnect partners, and email or SMS delivery providers. Rozper imposes data-protection obligations on each sub-processor that are materially equivalent to those set out in this DPA, and remains liable for each sub-processor's performance.
The current, maintained list of sub-processors — including what each one does and where it is located — is published at /sub-processors. Rozper will give advance notice before adding a new sub-processor that will handle Customer personal data. If Customer reasonably objects to a new sub-processor on data-protection grounds within the notice period, the parties will work in good faith to find a resolution, which may include Rozper not routing Customer's data through that sub-processor or, if no resolution is reached, allowing Customer to terminate the affected Service without penalty.
6 · Security measures
Rozper maintains technical and organizational measures appropriate to the risk of processing telecommunications data at scale, including:
- Encryption of data in transit (TLS/SRTP) and at rest across production data stores.
- Role-based access controls, single sign-on, and mandatory multi-factor authentication for internal systems.
- Network segmentation, carrier-grade DDoS protection, and continuous monitoring across our global points-of-presence.
- Infrastructure engineered for 99.99% platform uptime, with redundant routing paths so that a regional failure does not interrupt Customer's traffic.
- Regular vulnerability scanning, penetration testing, and a documented incident-response process.
Further detail on our security architecture is available at /security.
7 · Assistance with data subject rights
Because Customer is the controller of end-user and contact data flowing through the platform, Rozper will forward to Customer any data-subject request (access, correction, deletion, restriction, portability, or objection) that Rozper receives directly regarding data Customer controls, without responding substantively itself unless instructed to do so.
Rozper provides Customer with self-service tools — including number, recording, and contact deletion controls in the admin console — and will otherwise provide reasonable technical assistance so Customer can respond to data-subject requests within the timelines required by applicable law.
8 · Breach notification commitments
If Rozper becomes aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer personal data processed on the Services (a “Security Incident”), Rozper will notify Customer without undue delay and, in any event, within 72 hours of confirming the incident.
The notification will describe, to the extent then known, the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed to address it. Rozper will cooperate with Customer's own investigation and regulatory notification obligations and will provide reasonable updates as the incident is further investigated.
9 · International transfer mechanisms
Rozper operates regional points-of-presence across the Americas, Europe, and Asia-Pacific, and Customer can pin a tenant to a specific region where that is offered. Where personal data is nonetheless transferred internationally — for example because Customer's end users are dialing across borders, or because global support requires it — Rozper relies on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by the technical and organizational measures described in Section 6.
A full breakdown of transfer mechanisms, regional hosting options, and supplementary safeguards is maintained in our GDPR Transfer Pack, which forms part of this DPA by reference.
10 · Audit rights
On reasonable prior written notice, and no more than once per calendar year (except where required by a regulator or following a confirmed Security Incident), Customer may request evidence of Rozper's compliance with this DPA, which Rozper will satisfy by providing its current third-party audit reports, security certifications, and completed due-diligence questionnaires. Where those materials do not reasonably address Customer's inquiry, the parties will agree on the scope, timing, and confidentiality terms of an on-site or remote audit, conducted at Customer's expense by a mutually agreed auditor.
11 · Data return & deletion on termination
On termination or expiry of the underlying agreement, and subject to any longer retention period required by law or agreed in writing, Rozper will — at Customer's election, made in writing within 30 days of termination — return Customer personal data in a standard export format, delete it, or both, and will delete any remaining copies within our standard backup-rotation cycle thereafter. Recordings, transcripts, and CRM-synced contact data are covered by the same commitment.
12 · Requesting a signed DPA
This page reflects Rozper's standard data processing terms. If your organization requires a signed, countersigned copy — for procurement, vendor-risk, or internal legal records — email legal@rozper.com or reach out through /contactus and our legal team will send an executable version, typically within two business days.