Legal · Last updated 1 October 2026
Slovio Data Processing Addendum (DPA)
This Data Processing Addendum (“DPA”) forms part of the Slovio Terms of Use between Crunchy Media Pvt Ltd (“Slovio”) and the customer (“you”). It applies to personal data that Slovio processes on your behalf when providing the service.
1.Roles of the parties
- 1.1
For personal data of your contacts, customers and team that you process through the service, you are the Data Fiduciary and we are your Data Processor under the Digital Personal Data Protection Act, 2023.
- 1.2
You are responsible for having a lawful basis, including consent where required, and for giving the notices the law requires to the people whose data you process.
2.Scope of processing
- 2.1
We process contact details, messages, call recordings, transcripts, AI summaries, files, CRM records and usage data only to provide, secure and support the service, for as long as your account is open and as described below.
3.Processing instructions
- 3.1
We process personal data only on your documented instructions, which include the Terms of Use, your configuration of the service and your use of its features. If we believe an instruction breaks the law we will tell you.
- 3.2
Our staff and contractors who access personal data are bound by confidentiality.
4.Sub-processors
- 4.1
You authorise us to use sub-processors for: cloud hosting and storage; messaging and telecom delivery (Meta, mobile operators, DLT platforms and voice carriers); AI model providers for AI features; email delivery; and payment processing. The current list is available on request from hello@slovio.ai.
- 4.2
We impose data protection obligations on each sub-processor at least as protective as this DPA and remain responsible for their performance. We will tell you before adding a new category of sub-processor, and you may object on reasonable data protection grounds.
- 4.3
Where you connect your own AI provider key or integration, that provider processes the data under your own agreement with it and is not our sub-processor.
5.Security measures
- 5.1
Slovio is ISO/IEC 27001 certified and holds a SOC 2 audit report. Measures include role-based access control, workspace separation, encryption in transit, audit logs, monitoring and staff security training.
6.Personal data breaches
- 6.1
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and give you the information we have so you can meet your own obligations to notify the Data Protection Board of India and affected people.
7.Transfers outside India
- 7.1
Some sub-processors process data outside India. We transfer personal data only to countries the Government of India has not restricted and subject to the protections in this DPA.
8.Assistance and audits
- 8.1
We will help you, through the features of the service and on request, to respond to requests from people exercising their rights and to meet your security and breach obligations.
- 8.2
On request, and under confidentiality, we will provide our ISO/IEC 27001 certificate and SOC 2 report so you can check our controls.
9.Return and deletion
- 9.1
You can export your data while your account is open. After your account closes we delete personal data we process for you within a reasonable period, unless the law requires us to keep it, in which case we keep it only for that purpose.
10.Contact
- 10.1
Questions about this DPA or a request for the sub-processor list: hello@slovio.ai.