Legal
Frontbell Data Processing Addendum
Last updated: August 1, 2026
Effective Date: August 1, 2026 Last Updated: August 1, 2026
This Data Processing Addendum (this "DPA") is entered into between Vaxio, Inc., a Delaware corporation, doing business as Frontbell ("Frontbell," "we," "us," or "our"), and the Customer that has accepted the Frontbell Terms of Service (the "Terms"). This DPA is incorporated into the Terms by reference (see Terms Section 8.3) and governs Frontbell's processing of End-Customer Data on Customer's behalf. Capitalized terms not defined here have the meanings given in the Terms or the Privacy Policy.
This DPA applies whenever Frontbell processes personal information about Customer's own end-customers ("End-Customer Data," as defined in Terms Section 8.1) in the course of providing the Service. It does not change how Frontbell handles personal information about Customer's own account holders and Authorized Users, which is Frontbell's own controller-role processing described in the Privacy Policy.
1. Roles of the Parties
1.1. With respect to End-Customer Data, Customer is the business/controller — Customer determines the purposes and means of processing its own end-customers' personal information (for example, deciding which customers to contact, what services to offer them, and what data to collect about them through the Service). Under the CCPA, Customer is the "Business." Under the GDPR (to the extent applicable), Customer is the "Controller."
1.2. Frontbell is the processor/service provider — Frontbell processes End-Customer Data solely on Customer's behalf and documented instructions, in order to provide the technology infrastructure and AI features that make up the Service. Frontbell does not determine the purposes or means of processing End-Customer Data. Under the CCPA, Frontbell is the "Service Provider." Under the GDPR, Frontbell is the "Processor."
1.3. Customer is the party responsible for lawful basis, consent, and recording notices for its own communications with its end-customers (see Terms Sections 5.1 and 5.2); Frontbell provides the tooling that supports that responsibility but does not assume it.
2. Subject Matter, Duration, Nature, and Purpose of Processing
2.1. Subject matter. The processing of End-Customer Data by Frontbell on Customer's behalf in connection with Customer's use of the Service.
2.2. Duration. For the term of Customer's subscription and any post-termination period required to return or delete End-Customer Data under Section 10 below.
2.3. Nature of processing. Hosting, storage, transmission, transcription, AI inference (intent classification, summarization, drafting), text-to-speech synthesis, telephony origination and termination, SMS origination and termination, payment metadata exchange, analytics, customer support, and security operations.
2.4. Purpose of processing. To provide and operate the Service in accordance with Customer's documented instructions — meaning the Terms, this DPA, and Customer's own configuration of the Service (for example, which AI features are enabled, what data Customer chooses to submit, and what retention settings Customer selects where the Service exposes them).
3. Categories of Data Subjects and Personal Data
3.1. Categories of Data Subjects.
- Customer's own end-customers (typically homeowners and other individuals who contact Customer or are contacted by Customer through the Service).
- Customer's Authorized Users (employees and contractors) to the extent their information appears in records they create.
- Other individuals whose personal information Customer submits to, or generates within, the Service in the ordinary course of business.
3.2. Categories of Personal Data. Drawn from the categories described in the Privacy Policy, Section 1:
- Identifiers — name, email address, phone number, company name.
- Postal and service addresses.
- Call and message content processed by the AI Assistant, including call recordings, transcripts, and SMS/message content, where those features are used, subject to the recording disclosures built into the Service.
- Content submitted to the Service — customer records, photos, estimates, invoices, schedules, notes, and messages.
- Service and billing history — appointments, estimates, invoices, work orders, and payment metadata (Frontbell does not store full card numbers; those are held by Stripe).
- Authentication and access logs.
3.3. Sensitive categories. Frontbell does not knowingly request health, government-ID, or similarly sensitive information through the Service, and Customer agrees not to submit such data unless the Service is expressly designed to collect it. Call recordings are handled per the disclosure and retention practices described in the Privacy Policy and Section 9 below.
4. Frontbell's Obligations
Frontbell will:
(a) Process only on documented instructions. Process End-Customer Data only to provide the Service as described in the Terms and this DPA and in accordance with Customer's own configuration of the Service, and not for any other purpose — including not using End-Customer Data for Frontbell's own advertising purposes and not combining it with data from other Customers except where necessary to provide the Service (e.g., shared infrastructure, fraud and abuse detection) or as Customer separately directs.
(b) No sale or cross-context sharing. Not sell End-Customer Data, and not share it for cross-context behavioral advertising, consistent with the Privacy Policy.
(c) Confidentiality. Ensure that personnel authorized to process End-Customer Data are subject to confidentiality obligations, whether contractual or statutory.
(d) Notify on inability to comply. Promptly notify Customer if Frontbell determines it can no longer meet its obligations under this DPA or applicable data-protection law.
(e) Cooperate on remediation. Take reasonable and appropriate steps, on Customer's reasonable request, to remediate unauthorized use of End-Customer Data.
5. Security Measures
Frontbell will maintain administrative, technical, and physical safeguards designed to protect End-Customer Data, summarized in Annex B. Frontbell will not materially decrease the overall level of security of the Service during the term of Customer's subscription.
6. Sub-Processors
6.1. General authorization. Customer grants Frontbell a general authorization to engage sub-processors to help provide the Service, subject to this Section.
6.2. Current list. The sub-processors currently engaged are listed in Annex A.
6.3. Notice of changes. Frontbell will provide notice of a new sub-processor (by email or in-product notice) before that sub-processor begins processing End-Customer Data in production, except where the change is a like-for-like replacement of an existing sub-processor's infrastructure with no material change in the categories of data processed.
6.4. Flow-down. Frontbell imposes data-protection obligations on each sub-processor that are consistent with this DPA, appropriate to the nature of the service the sub-processor provides, and remains responsible to Customer for the performance of its sub-processors' obligations under this DPA.
7. Data Subject Request Assistance
7.1. Frontbell does not respond directly to a request from Customer's end-customer to exercise privacy rights (access, deletion, correction, or opt-out) except as required by law. Instead, consistent with the Privacy Policy, Frontbell routes such requests to Customer within a reasonable time.
7.2. On Customer's request, Frontbell will provide reasonable assistance to help Customer respond to its own end-customers' requests, including through self-service tools available in the Service where applicable, and by responding to Customer's own assistance requests in a reasonable time given the nature of the request.
7.3. Customer is responsible for verifying its end-customer's identity, evaluating the request, and determining the appropriate response; Frontbell is not in a position to make that determination on Customer's behalf.
8. Security Incident Notification
8.1. Frontbell will notify Customer of a confirmed security incident affecting End-Customer Data without undue delay, and in any event within seventy-two (72) hours of Frontbell confirming the incident.
8.2. The notice will include, to the extent then known: the nature of the incident, the categories and approximate number of data subjects and records affected, the measures taken or proposed to address it, and a point of contact for follow-up. Where full information is not yet available, Frontbell will provide updates as its investigation progresses.
8.3. Frontbell will reasonably cooperate with Customer's own investigation and any notifications Customer is required to make to regulators or affected individuals. A notification under this Section is not an admission of fault.
9. Deletion and Return on Termination
9.1. Following termination of Customer's subscription, Customer may export End-Customer Data for the period described in the Privacy Policy, Section 9 ("Active account and Customer content" — for as long as the account is active, plus a reasonable export/recovery window after termination).
9.2. After that window, Frontbell will delete End-Customer Data from production systems, subject to the same retention table in Privacy Policy Section 9 (for example, financial records retained per applicable tax law, and the backup-propagation window of approximately 100 days described there), except where retention is required by law.
9.3. On Customer's written request, Frontbell will confirm that deletion has occurred.
10. Audits
10.1. On reasonable request, no more than once per year except following a confirmed security incident, Frontbell will make available the security and compliance documentation reasonably necessary to demonstrate compliance with this DPA — for example, a completed security questionnaire, a summary of the measures in Annex B, and (once available) any third-party audit report Frontbell has commissioned.
10.2. Given Frontbell's current size and operating model, audits are conducted through documentation review and questionnaires rather than on-site inspection. If documentation is genuinely insufficient to address a specific, documented compliance concern, Frontbell will discuss a reasonable alternative (for example, a call with engineering leadership) in good faith. Frontbell does not currently commit to on-site audit rights; enterprise customers who require them should raise it before signing so it can be evaluated as a negotiated term.
11. CCPA Service-Provider Certifications
Frontbell certifies that it understands the restrictions in this Section and will comply with them with respect to End-Customer Data:
- Frontbell will not sell or share End-Customer Data, as those terms are defined under the CCPA.
- Frontbell will not retain, use, or disclose End-Customer Data for any purpose other than providing the Service under Customer's instructions, including not retaining, using, or disclosing it outside the direct business relationship between Frontbell and Customer.
- Frontbell will not combine End-Customer Data received from Customer with personal information received from another source, except to provide the Service, for security and fraud-prevention purposes, or as otherwise permitted under applicable law.
12. International Transfers
Frontbell processes personal information in the United States. Frontbell does not currently
operate outside the U.S. and does not direct the Service at the EU/EEA/UK. If that changes, or
if a specific Customer engagement requires an international-transfer mechanism, Frontbell will
address it in a supplemental agreement (for example, Standard Contractual Clauses) rather than
in this default DPA. See docs/legal/TENANT_DPA_TEMPLATE_2026.md for a dormant SCC framework
prepared in case this becomes necessary.
13. Liability and Term
13.1. The liability provisions of the Terms (Section 13) apply to claims arising under this DPA.
13.2. This DPA takes effect when Customer accepts the Terms and remains in effect for as long as Frontbell processes End-Customer Data on Customer's behalf.
13.3. In the event of a conflict between this DPA and the Terms regarding the processing of End-Customer Data, this DPA governs.
Annex A — Sub-Processors
The following sub-processors are currently engaged to help provide the Service. Frontbell will provide notice of changes per Section 6.3 above.
| # | Sub-processor | Role | Categories of Data |
|---|---|---|---|
| 1 | Amazon Web Services, Inc. | Cloud hosting (application servers), database (Amazon RDS for PostgreSQL), object storage (Amazon S3 — photos, call recordings), transactional email (Amazon SES), and AI inference (AWS Bedrock — Claude models, in the customer-facing voice/chat pipeline) | All categories at rest and in transit; call recordings and photos in object storage; transcripts and prompts for LLM inference; recipient email addresses and message metadata |
| 2 | Anthropic PBC | AI inference — Claude models, used both via AWS Bedrock (row 1) and, for a subset of internal and product workflows, Anthropic's direct API | Transcripts, prompts, and content submitted for AI-assisted drafting, summarization, and classification |
| 3 | Google LLC | (a) Cloud Text-to-Speech ("Chirp" voices) — primary voice synthesis for the AI Assistant on calls; (b) Gemini API — secondary/fallback AI inference in the voice pipeline; (c) OAuth-scoped Gmail and Calendar integration, used only when a Customer connects its own Google account | (a)/(b) AI-generated speech text and inference prompts, which can include names, addresses, or other details spoken back to a caller; (c) Customer-authorized email and calendar content, limited to the scopes Customer grants |
| 4 | Stripe, Inc. | Payment processing — Customer's own subscription and usage billing to Frontbell, and (separately, as Customer's own merchant-of-record account) payments Customer's end-customers make to Customer through the Service | Billing contact and payment metadata; Frontbell does not store full card numbers |
| 5 | Twilio Inc. | Telephony carrier — inbound/outbound call routing, call recording, and SMS delivery | Call metadata, call audio recordings, SMS message content and delivery metadata |
| 6 | Deepgram, Inc. | Speech-to-text transcription of call audio, and secondary/fallback text-to-speech voice synthesis | Call audio (processed to produce a transcript) and transcript text |
| 7 | Resend, Inc. | Legacy transactional email delivery path. Amazon SES (row 1) is the default and primary transactional email provider; Resend remains configured as a fallback path and is not used for new sending by default | Recipient email addresses and transactional email content, if and when the fallback path is invoked |
| 8 | Functional Software, Inc. (Sentry) | Error monitoring and application diagnostics | Stack traces and request metadata, which can incidentally include identifiers such as an IP address or account identifier captured at the time of an error |
How this list was verified. Each row reflects an active integration confirmed in the
production codebase as of this document's last_updated date — not a vendor account that
merely exists or a code path that is present but unconfigured. Cartesia, Inc. was Frontbell's
original text-to-speech vendor and is not included above: it was removed from the live
voice pipeline (no API key configured, chain head reassigned to Google) after a July 2026
review determined Cartesia's data-processing agreement and zero-retention terms were
Enterprise-tier only. OpenAI is similarly not included: earlier batch workflows that used
it were migrated off in June 2026 (summaries to AWS Bedrock, transcription to Deepgram), and
while an OpenAI fallback code path still exists in one internal service, it is not the
documented, provisioned configuration and is not represented here as active. If either
assumption changes, this Annex needs a corresponding update.
Annex B — Security Measures
Frontbell maintains the following measures, which it may update from time to time provided the overall level of security is not materially decreased.
Encryption. Data in transit is encrypted (TLS). Passwords are stored hashed, never in plain text. Data at rest in the production database and object storage is encrypted.
Access control. Access to the Service and to production data is role-based — Customer's own Authorized Users see only what their configured role permits within their organization, and Frontbell's production systems are logically separated by tenant so that one Customer's data is not accessible through another Customer's account.
Hosting. The Service runs on Amazon Web Services infrastructure (see Annex A), with the production environment segmented from Frontbell's corporate systems.
Logging and monitoring. Frontbell maintains centralized application logging and error monitoring (see Annex A, Sentry) to detect and respond to operational and security issues.
Incident response. Frontbell maintains an internal incident-response process and will notify Customer of a confirmed security incident per Section 8 above.
Vendor management. Sub-processors are selected based on whether they can meet Frontbell's data-handling requirements for the category of data involved, and the sub-processor list is reviewed periodically (see Annex A verification note above).
Compliance roadmap. Frontbell does not yet hold a third-party security certification (for example, SOC 2). This is on Frontbell's roadmap as the Customer base scales, but is not a present representation or a scheduled date.
Vaxio, Inc. — Product: Frontbell (frontbell.ai) Contact: legal@vaxio.ai (this DPA) or privacy@frontbell.ai (privacy/DSAR requests)
Related Documents
- Terms of Service:
docs/legal/TERMS_OF_SERVICE_DRAFT_2026-08.md(Section 8.3) - Privacy Policy:
docs/legal/PRIVACY_POLICY_DRAFT_2026-08.md - Detailed working draft with statutory annotations and SCC framework:
docs/legal/TENANT_DPA_TEMPLATE_2026.md - Operational retention schedule:
docs/legal/RETENTION_POLICY.md