Legal
Vendor Data Processing Agreements
Effective Date: May 19, 2026 · Version 1.0
This document sets out the data processing agreements in place with each third-party vendor Radiant Calls engages to deliver its service, what data each vendor processes, and the key terms that apply.
1. Purpose & Scope
Radiant Calls ("Radiant Calls") operates an AI-powered voice receptionist service. To deliver this service, Radiant Calls engages a number of third-party vendors who process personal data on its behalf. By using Radiant Calls, business clients and their callers acknowledge that personal data will be processed by the vendors listed below in accordance with each vendor's DPA. Radiant Calls requires all vendors to meet its data protection standards and has confirmed that a DPA or equivalent agreement is in place with each vendor listed herein.
2. Radiant Calls as Data Controller
For the purposes of data protection law, Radiant Calls acts as the data controller in respect of caller personal data. Each vendor listed below acts as a data processor on Radiant Calls's behalf, processing data only as instructed by Radiant Calls and only for the purposes required to deliver the service.
3. Vendor Agreements
- Vapi processes data solely to provide and improve the voice AI service
- Data use is limited to enhancing call features, latency, and AI performance
- Each sub-provider (transcription, LLM, voice generation) has its own contractual terms
- GDPR-compliant; HIPAA-capable accounts available
Note: Vapi does not monitor or guarantee sub-provider compliance on Radiant Calls's behalf. Radiant Calls reviews the terms of any sub-providers enabled within its Vapi configuration.
- Twilio processes customer data as a processor, except for Communications Usage Data where it acts as an independent controller for billing and fraud prevention
- Certified under the EU-US Data Privacy Framework and Swiss-US DPF
- Twilio may process data for AI model training to combat spam and fraud
- Radiant Calls is responsible for obtaining caller consent — call recording disclosure is included in the Radiant Calls opening greeting
- Supabase processes data solely for the purpose of providing hosted database services as instructed by Radiant Calls
- Data is hosted on AWS infrastructure in the United States
- Transfer mechanism for EU data: Standard Contractual Clauses (Module 2: Controller to Processor)
- Row Level Security (RLS) is Radiant Calls's responsibility to configure
Action required: Sign and return the Supabase DPA to privacy@supabase.io to formalise the processor relationship, particularly before onboarding any EU-based clients.
- Resend acts as a data processor for email delivery; Radiant Calls is the data controller
- Certified under the EU-US Data Privacy Framework and UK Extension
- Does not use customer data for advertising or sell personal data
- SOC 2 Type II and ISO 27001 certified infrastructure
- Sentry acts as a data processor; Radiant Calls is the data controller
- Does not retain, use, or disclose personal data beyond providing the error monitoring service
- Does not sell or share personal data under the CCPA
- Self-certified under the EU-US Data Privacy Framework, UK Extension, and Swiss-US Framework
Action required: Accept the Sentry DPA under Settings > Legal & Compliance. Ensure full call transcripts are not being sent to Sentry — only masked, limited metadata should be included in error context.
- Render acts as a data processor; Radiant Calls is the data controller
- Certified under the EU-US Data Privacy Framework as of January 6, 2025, including UK Extension and Swiss-US DPF
- Processes personal data only as required to provide the hosting service
- Application logs on free tier retained for 30 days
Note: Render free tier has limitations including shared infrastructure and shorter log retention. Consider upgrading to a paid plan for production deployments handling sensitive caller data.
4. Client Acknowledgement
By entering into an agreement with Radiant Calls, business clients acknowledge and agree to the following:
- Radiant Calls engages the vendors listed above as sub-processors to deliver the Radiant Calls service
- Each vendor processes data under a DPA that requires them to protect personal data to the standards described in this document
- Caller personal data will be transferred to and processed by these vendors in the United States in accordance with applicable data transfer mechanisms (SCCs, EU-US Data Privacy Framework)
- Radiant Calls remains the data controller and each vendor acts as a data processor
- Business clients are responsible for their own compliance obligations as data controllers in respect of their customers' data
- Clients may request a copy of any vendor DPA listed above for their own compliance records
5. Changes to Vendor Agreements
Radiant Calls will update this document when vendor DPAs change materially or when new vendors are added. Clients will be notified of material changes. This document should be reviewed annually as part of Radiant Calls's data protection compliance review.
6. Contact
Radiant Calls
Email: keshav@radiantcalls.com