SvaraCall — Data Processing Addendum
Sarwagyna Private Limited
Effective Date: 12 September 2026
Version 1.0
This Data Processing Addendum ("DPA") forms part of the SvaraCall Terms of Service between Sarwagyna Private Limited ("Sarwagyna", "Processor") and the Customer ("you", "Data Fiduciary"). It applies where we process personal data on your behalf.
1. Roles
1.1 You are the Data Fiduciary (and, where applicable, the controller) in respect of personal data you upload to the Services and personal data generated in calls placed or received by your AI Agents. You determine the purposes and means of that processing.
1.2 We are the Data Processor. We process that data only on your documented instructions.
1.3 Your instructions are: (a) these Terms and this DPA; (b) the configuration you set in the dashboard and through the APIs; and (c) any additional written instruction we accept. We will tell you if we believe an instruction breaches the DPDP Act or other applicable law.
1.4 We act as Data Fiduciary in our own right for account, billing, KYC, security, and platform-operation data. That processing is governed by our Privacy Policy, not by this DPA.
2. Scope of Processing
Subject matter: provision of the SvaraCall AI voice agent platform.
Duration: for the term of your subscription plus the deletion window in Section 9.
Nature and purpose: placing and receiving calls; speech-to-text transcription; language model inference to determine agent responses; text-to-speech synthesis; knowledge base retrieval; extraction of structured fields; storage of recordings, transcripts, and metadata; analytics and reporting; integration with your CRM; billing.
Categories of Data Principal: your End Users (the people your agents call or who call your agents); your employees and authorised users.
Categories of personal data:
- contact identifiers — phone number, name, and other fields you upload;
- voice — call audio, in real time and where recording is enabled, at rest;
- conversation content — transcripts, agent responses, extracted fields;
- call metadata — time, duration, direction, disposition, carrier response;
- any additional data you choose to include in contact lists, knowledge bases, or prompts.
Sensitive categories: you must not submit the restricted categories listed in Section 4 of the Acceptable Use Policy without our prior written agreement.
3. Our Obligations
We will:
3.1 process personal data only on your documented instructions, and not for our own purposes, except where required by law — in which case we will inform you unless the law prohibits it;
3.2 not use your call audio, transcripts, or contact data to train general-purpose AI models, and will contract with Subprocessors on terms that prohibit them from doing so where we control that setting;
3.3 ensure personnel with access are bound by confidentiality obligations and are granted access on a least-privilege, need-to-know basis;
3.4 implement and maintain the security measures in Annexure 1 to this DPA;
3.5 assist you, taking into account the nature of the processing and the information available to us, in meeting your obligations regarding Data Principal rights, security, breach notification, and any impact assessment;
3.6 make available information reasonably necessary to demonstrate our compliance with this DPA;
3.7 on your instruction, delete or return personal data as set out in Section 9.
4. Your Obligations
You will:
4.1 ensure you have a valid lawful basis for the processing you instruct, including for calling, recording, and transcription;
4.2 provide the notice required by Section 5 of the DPDP Act to your Data Principals, in the form and language required, before processing their data;
4.3 respond to Data Principal requests relating to your calling programme — we will forward to you any request we receive directly;
4.4 configure the Services in a way that meets your obligations, including retention periods, redaction settings, and access controls;
4.5 not instruct us to process data in a way that would breach applicable law;
4.6 comply with Annexure A (Telephony and AI Voice Compliance Addendum).
5. Subprocessors
5.1 Authorisation. You give general authorisation for us to engage Subprocessors. Our current list is available on request from privacy@svaracall.com.
5.2 Terms. We impose on each Subprocessor data protection obligations no less protective than those in this DPA. We remain liable to you for their performance.
5.3 Changes. We will give you at least thirty (30) days' notice before adding or replacing a Subprocessor that processes call content or contact data. Subscribe to notifications by emailing privacy@svaracall.com.
5.4 Objection. You may object on reasonable data protection grounds within the notice period. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Services without penalty and receive a pro-rata refund of prepaid fees.
5.5 Categories of Subprocessor currently engaged:
| Function | Purpose |
|---|---|
| Cloud hosting — application and workers | Running the platform |
| Cloud hosting — frontend and edge | Serving the dashboard |
| Managed database and cache | Storing account, campaign, call and configuration data |
| Telephony carriage and number provisioning | Placing and receiving calls |
| Speech-to-text | Transcribing call audio |
| Text-to-speech | Synthesising agent speech |
| Large language model inference | Generating agent responses |
| Real-time media orchestration | Managing the live audio session |
| Payment gateway | Processing payments |
| Transactional email | Account and service notifications |
| Error monitoring and observability | Diagnosing faults |
Named entities and processing locations are in the Subprocessor List, which is available on request.
6. International Transfers
6.1 Some Subprocessors process personal data outside India. The current position by component is set out in the Subprocessor List, which is available on request.
6.2 Where we transfer personal data outside India, we do so on contractual terms requiring the recipient to maintain protection substantially equivalent to that required under this DPA, and we transfer only what is necessary.
6.3 We will not transfer personal data to any country restricted by the Central Government under Section 16 of the DPDP Act.
6.4 Where you are subject to the GDPR or UK data protection law in respect of the data you send us, the Standard Contractual Clauses or UK International Data Transfer Agreement will apply as set out in Annexure 2, once executed between the parties. Annexure 2 is not yet in force and must be signed separately.
7. Security
7.1 We will implement and maintain the technical and organisational measures in Annexure 1.
7.2 We may update those measures provided the overall level of protection is not reduced.
7.3 You are responsible for the security of your own systems, credentials, API keys, and integrations, and for the access you grant to your users.
8. Personal Data Breach
8.1 We will notify you without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting personal data we process for you.
8.2 The notification will describe, so far as known: the nature of the breach, the categories and approximate volume of data and Data Principals affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases.
8.3 We will take reasonable steps to contain and remediate, preserve evidence, and assist you with your own notification obligations to the Data Protection Board of India, to CERT-In, and to affected Data Principals.
8.4 We will not make a public statement identifying you in connection with a breach without your prior consent, except where required by law.
8.5 You are responsible for determining whether the breach requires notification by you, and for making it.
9. Deletion and Return
9.1 You may export Customer Data at any time during the subscription through the dashboard or API.
9.2 On termination, we will make Customer Data available for export for thirty (30) days.
9.3 After that window we will delete or irreversibly anonymise Customer Data within sixty (60) days, except where retention is required by law, is necessary for the establishment or defence of a legal claim, or the data sits in routine backups — which are overwritten on their ordinary cycle and are not accessed in the interim.
9.4 We will confirm deletion in writing on request.
10. Audit
10.1 We will provide, on request and no more than once in any twelve (12) month period, reasonable documentation evidencing our compliance with this DPA, including our security measures, subprocessor list, and any third-party assessment reports we hold.
10.2 Where that documentation does not reasonably satisfy you, or where a regulator requires it, you may conduct an audit on at least thirty (30) days' written notice, during business hours, subject to confidentiality, at your cost, and in a manner that does not disrupt our operations or compromise other customers' data. We may require the auditor to be independent and not a competitor.
11. Data Principal Requests
11.1 Where a Data Principal contacts us directly about data we process on your behalf, we will not respond substantively. We will refer them to you and inform you within five (5) business days.
11.2 We will provide reasonable assistance, taking account of the nature of the processing, to help you respond — including retrieving, correcting, exporting, or deleting specific records where the platform supports it. Assistance beyond routine platform functionality may be chargeable at our then-current professional services rates.
12. Liability and General
12.1 Liability under this DPA is subject to the limitations in Section 13 of the Terms of Service.
12.2 This DPA prevails over the Terms of Service to the extent of any conflict on data protection matters.
12.3 This DPA is governed by Indian law, with dispute resolution as set out in Section 15 of the Terms of Service.
Annexure 1 — Technical and Organisational Measures
Access control
- Role-based access control in the application; least-privilege access to production infrastructure
- Multi-factor authentication required for administrative and production access
- Access reviewed on a defined cadence and revoked on personnel change
- Audit logging of administrative actions
Encryption
- TLS for all data in transit, including to Subprocessors
- Encryption at rest for databases and object storage
- Sub-account authentication tokens and third-party API credentials encrypted at rest under a managed secret store
Network and application security
- Environment separation between development, staging, and production
- HMAC signature verification on inbound webhooks
- Rate limiting and abuse controls on public endpoints
- Dependency scanning and a defined patching cadence
- Secrets excluded from source control
Operational
- Documented incident response procedure with defined escalation
- Backups taken on a defined schedule with documented restore testing
- Change management through version control and CI/CD with review before production deploy
- Personnel bound by written confidentiality obligations; security awareness briefing on joining
Data handling
- Customer-configurable retention for recordings and transcripts
- Customer-configurable redaction and PII exclusion controls where available
- Logical separation of customer data by workspace
- Deletion procedure as described in Section 9
Current certification status
We do not currently hold ISO 27001 certification or a SOC 2 attestation. Our roadmap toward independent assessment is available on request under NDA. We do not represent that we hold certifications we have not obtained.
Annexure 2 — Standard Contractual Clauses
This Annexure is reserved. Standard Contractual Clauses or a UK International Data Transfer Agreement will be executed separately if and when the Customer is subject to the GDPR or UK data protection law. They are not in force until signed.
Sarwagyna Private Limited | privacy@svaracall.com | +91 6305036991