FastLajna Log in

Terms & Documents

FastLajna contractual documents and privacy information. Switch between the individual documents below.

Informative translation. The binding version is the Czech text; in case of any discrepancy, the Czech version prevails.

Terms & Conditions DPA Price List Privacy Cookies

Terms & Conditions

↑ Back to top

Effective from July 20, 2026 · version v1

Contents

  • 1. Definitions
  • 2. Subject Matter and Scope of the Service
  • 2a. Price and Payment Terms
  • 3. Client's Obligations
  • 3.1 Client's Obligations towards Users
  • 3.2 Customer Identity Verification and Regulatory Obligations for Telephone Numbers
  • 3.3 Knowledge Base — Sources and Consent
  • 3.4 Mandatory Opening Call Disclosure
  • 3.5 Acceptable Use Policy (AUP)
  • 3.6 Specific Parameters of the Service
  • 3a. Processing of the Client's Personal Data (GDPR Notice)
  • 4. Prohibited Uses
  • 5. Intellectual Property Rights to Outputs
  • 6. Limitation of Liability
  • 7. SLA and Availability
  • 8. Change of the Service and Subcontractors
  • 9. Term, Termination and Data Export
  • 10. Indemnification
  • 11. Confidentiality
  • 12. AI-Specific Risks (fabricated data, drift and bias in outputs)
  • 13. Telecommunications Regulation and the Czech Telecommunication Office
  • 13a. Integration with Microsoft 365 / Outlook.com Calendar
  • 13b. Outbound Transactional SMS (SMS Add-on Service)
  • 14. Governing Law and Choice of Court
  • 15. Mirroring of Subcontractor Terms
  • 16. Final Provisions
  • Annex No. 1 — Acceptable Use Policy (AUP)
  • 1. Relationship to the GTC
  • 2. Consolidated Prohibited Uses (Intersection of Subcontractors' Rules)
  • 3. Prohibitions Specific to the Scope of the Service
  • 4. ElevenLabs — Prohibited Use Policy (Third-Party Beneficiary)
  • 5. Dynamic Incorporation of Subcontractors' Policies
  • 6. Sanctions
  • Annex No. 2 — SLA Schedule
  • 1. Definition of Availability
  • 2. Calculation of Availability
  • 3. Exclusions from the Availability Calculation
  • 4. Price Discounts
  • 5. Claiming the Discount
  • 6. Pay-as-you-go Tariff
  • 7. Scope of the SLA
  • 8. Amendment of this Annex

General Terms and Conditions

For the AI voice assistant service provided by Fastlajna s.r.o., with its registered office at Školská 1736/12, Nové Město, 110 00 Praha 1, Company ID (IČO) 29543908, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 448213 (hereinafter the "Provider").

1. Definitions

In these general terms and conditions (hereinafter the "GTC") the following terms have the meaning set out below:

1.1 "Service" — the AI voice assistant service providing for the receipt of incoming telephone calls, automated speech synthesis and recognition, dialogue management of the call by a language model, retrieval of answers from the Client's Knowledge Base, and booking in its calendar. The Service is provided exclusively for incoming communication; outbound calling is not part of the Service.

1.2 "Provider" — Fastlajna s.r.o. as the provider of the Service.

1.3 "Client" — an entrepreneur within the meaning of § 420 and § 421 of Act No. 89/2012 Sb., the Civil Code, who has entered into an agreement with the Provider for the provision of the Service.

1.4 "User" — a third party who initiates an incoming call to a telephone number made available to the Client as part of the Service (the Client's customer).

1.5 "Subcontractor" — a third party whose services the Provider uses to provide the Service; the current list is set out in Annex No. 1 to the DPA (Sub-processors).

1.6 "Agreement" — the agreement for the provision of the Service concluded between the Provider and the Client, an integral part of which are these GTC, the Data Processing Agreement (DPA), the Acceptable Use Policy (Annex No. 1), the SLA Schedule (Annex No. 2), and the Price List (Annex No. 3).

1.7 "AI Act" — Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence.

1.8 "GDPR" — Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

1.9 "ZEK" — Act No. 127/2005 Sb., on Electronic Communications.

1.10 "Baseline AI Assistant Configuration" — the Provider's binding internal configuration standard for AI assistants. A change to the Baseline AI Assistant Configuration with a material impact on the configuration of the Service at the Client (in particular a change to the mandatory opening disclosure elements, the prohibition on biometric functions, or the processing of sensitive data) is subject to notification under Art. 8.4 GTC.

1.11 "Payment Service Provider" or "PSP" — the payment service provider through which the Provider ensures the processing of the Client's card payments (contracting entity Stripe Payments Europe, Limited, Ireland; the regulated payment service provider is Stripe Technology Europe, Limited).

1.12 "Payment Card" — the Client's payment card stored (tokenised) with the PSP upon payment of the first Subscription or later in the PSP interface.

1.13 "Payment Mandate" — the Client's consent to the recurring debiting of payments from the Payment Card through the PSP pursuant to Art. 2a.

1.14 "Knowledge Base" — the set of information from the Client's websites and documents from which the AI assistant draws answers to Users' queries (Art. 3.3).

1.15 "Assistant" — an individual instance of the AI voice assistant set up by the Client within the Service, with its own configuration, chosen tariff, and assigned telephone number. The Client may operate multiple Assistants under the Agreement.

1.16 "Subscription" — the paid contractual relationship relating to an individual Assistant. Each Assistant has a separate Subscription with its own tariff and its own Billing Period; the price and the volume of performance included under the Price List always relate to a single Assistant, not to the Client's account as a whole.

1.17 "Billing Period" — the recurring monthly billing period of a particular Subscription maintained with the PSP. It begins on the day the Subscription is set up and need not coincide with the calendar month; the decisive boundaries are those of the billing period stated on the relevant invoice.

2. Subject Matter and Scope of the Service

2.1 The Provider provides the Client with the Service through the services of the Subcontractors listed in Annex No. 1 to the DPA. The nature and functionality of the Service depend on the Subcontractors' services; the Provider is not liable for limitations arising from the technical nature of machine learning models, in particular as to the accuracy, completeness, and currency of outputs.

2.2 Telephone numbers made available under the Service serve exclusively to receive incoming calls initiated by a User. Outbound calling is not part of the Service.

2.3 The Service does not serve for emergency calls (the 112 line or other emergency lines under § 33 ZEK or Art. 109(2) of Directive (EU) 2018/1972). The Client is obliged to inform Users that emergency calls cannot be made to the telephone numbers made available under the Service.

2.4 The Service is operated with the following structural parameters, which the Client acknowledges by accepting the GTC:

a. the AI assistant is configured in accordance with the Baseline AI Assistant Configuration (Art. 1.10); each new assistant undergoes verification against this standard before being put into operation;

b. recording of every incoming call is permanently active at the orchestration-layer Subcontractor (Vapi Inc.) with no technical means of disabling it;

c. the first sentence of every call contains the mandatory opening disclosure under Art. 3.4 (AI transparency under Art. 50(1) of Regulation (EU) 2024/1689, information about recording, and the option to end the call);

d. the Service is not provided for purposes prohibited under Art. 4 of these GTC;

e. the Service is provided in the version and configuration documented as of the effective date of the Agreement; changes are governed by Art. 8;

f. the Provider does not perform backups of the Client's and Users' data beyond the ordinary operational recovery of infrastructure; the Client is responsible for its own backup by exporting data under Art. 9.4.

2.5 Onboarding. Onboarding of a new Client takes place in the Provider's application. In the application, the Client enters the data necessary for setting up and operating an Assistant, in particular identification and contact details, data for regulatory identification (KYC), the web address for the Knowledge Base (Art. 3.3), and the Assistant's configuration including the system prompt (Art. 2.6, Art. 12.3). The Client is responsible for the truthfulness, completeness and currency of the data entered in the application and for keeping them up to date.

2.6 Setting up an Assistant. The Client sets up an Assistant by placing an order in the Provider's application, in which it selects the Assistant's configuration, tariff, and requested telephone number. The Subscription arises upon completion of the order and payment of the first fixed monthly component of the tariff in the PSP's secure payment interface (Art. 2a.2). Only after the PSP confirms successful payment does the Provider acquire the telephone number and set up and make available the Assistant; the provisioning takes place automatically and asynchronously, typically within minutes of payment. The Client's mere return from the payment interface to the application is not confirmation of payment or of setup.

2.7 Unavailability of the selected number. If the telephone number selected by the Client is no longer available at the time of setup, the Provider will assign the Assistant a substitute telephone number of the same category (country and type). If no substitute number is available, the setup of the Assistant fails and Art. 2.8 applies.

2.8 Failure of setup. If the Assistant cannot be set up (in particular due to unavailability of a telephone number or an insurmountable technical obstacle), the Provider will cancel the Subscription and refund the Client the first payment in full, typically automatically through the PSP to the Payment Card, otherwise manually without undue delay. Other claims by the Client arising from the failure of setup are excluded; this is without prejudice to Art. 6.3.

2.9 Customer Account and Acceptance of the Contractual Documentation. Use of the Service is conditional upon the creation of a customer account by registration in the Provider's application. Completion of the registration is conditional upon the Client's express confirmation that it has read the GTC and the DPA, including their annexes, and agrees to their wording; the Client makes the confirmation by ticking the designated box in the registration form, in which the GTC and the DPA are made available by link. The Agreement is concluded at the moment of this confirmation.

2.10 Express Confirmation of Structural Specifics and Client's Representation. Before completing the order for the first Assistant, the Client, by ticking the designated box in the application, expressly confirms that it has read the structural parameters of the Service under Art. 2.4, the specifics under Art. 3.6 and the expressly non-implemented measures under Art. 6.3 of the DPA, and that it accepts them — in particular the permanently active recording of calls, the transfer of personal data to Sub-processors in the USA and other third countries, the 30-day retention of call transcripts with OpenAI without prior redaction of personal data, the absence of backups beyond operational recovery, and the absence of application-level encryption of individual data fields — and at the same time represents that it does not and will not operate the Service in any of the prohibited categories under Art. 4.1. The order cannot be completed without this confirmation. An untrue representation constitutes the Client's gross negligence under Art. 4.2.

2.11 Record of Acceptance. The Provider electronically records the moment of the confirmations under Art. 2.9 and 2.10, the version of the accepted documents, and the identification of the customer account from which the confirmations were made. The Provider retains the record for the duration of the Agreement and for the duration of the limitation periods arising from it; the record serves as evidence of the conclusion of the Agreement and of the confirmations made.

2a. Price and Payment Terms

2a.1 Price List. The prices for the Service are set out in the Provider's price list (Annex No. 3, the "Price List"), which forms an integral part of the Agreement and is published at https://fastlajna.cz/en/compliance#cenik. The Price List sets out the tariffs, their fixed monthly component, the volume of performance included in the tariff, and the variable component based on actual usage (in particular the price per call minute beyond the included volume). Prices, the included volume, and the variable component always relate to a single Assistant (a single Subscription); if the Client operates multiple Assistants, it pays the price for each of them separately. The fixed monthly component includes the use of one telephone number under Art. 2.6 and 2.7; the supported countries and number types are set out in the Price List.

2a.2 Arising of the payment obligation and the Payment Mandate. By completing the order for an Assistant and paying the first fixed monthly component in the PSP's payment interface, the Client (a) expresses its consent to these GTC, if it has not already done so (Art. 2.9), (b) undertakes to pay the price of the chosen tariff under the Price List for the relevant Subscription, and (c) grants the Provider a Payment Mandate; the Payment Mandate applies to each Subscription so established. The Payment Mandate covers the recurring debiting of: (i) the fixed monthly component of the tariff in advance at the start of each Billing Period of the relevant Subscription, and (ii) the variable component based on actual usage for the preceding Billing Period (Art. 2a.2a), calculated in the manner set out in the Price List. The Client acknowledges the frequency of debiting (monthly, separately for each Subscription according to its Billing Period) and the method of determining the variable amount (per the Price List). The Payment Mandate expires upon cancellation of all Assistants under Art. 2a.9 or upon termination of the Agreement under Art. 9; the Client may change the Payment Card details at any time in the PSP interface (Art. 2a.3b).

2a.2a Consumption measurement and billing of the variable component. The consumption of a Billing Period includes calls of the relevant Assistant initiated within that period. The billed duration of each individual call is rounded up to whole minutes (each commenced minute of a call is billed as a full minute); only thereafter are the rounded minutes of individual calls summed. The variable component for a Billing Period is invoiced as a separate line item on the invoice issued for the immediately following Billing Period; the first invoice issued upon setup of the Subscription does not include the variable component. The detailed method of calculation and rounding of amounts is set out in the Price List. The basis for any billing complaint is the record of individual calls (start time, duration) maintained by the Provider.

2a.3 Automatic payment and proof of payment. The price is paid by automatic debiting from the Payment Card through the PSP on the basis of the Payment Mandate; for the card regime, the due date under the fallback invoicing regime (Art. 2a.6) does not apply. For each debit the Provider will issue the Client an invoice, sent electronically to the Client's e-mail address given upon registration; the Client consents to the electronic form of the document. The invoice is proof of a payment already made, not a payment request. The Provider is not a value added tax payer; prices are final, value added tax is not added to them, and the invoice is issued without value added tax.

2a.3a Storage and security of the Payment Card. The Client enters the Payment Card details directly into the PSP's secure interface. The Provider does not have access to the full Payment Card number and does not store it; it processes only the Payment Card identifier (token) provided by the PSP.

2a.3b Self-service PSP interface. In the PSP's self-service interface, the Client may change the Payment Card and view or download invoices and payment history. A change of tariff and cancellation of an Assistant are carried out exclusively in the Provider's application (Art. 2a.8 and 2a.9); performing these actions by any other means has no effect vis-à-vis the Provider.

2a.4 Unsuccessful debit and default. If a payment cannot be debited from the Payment Card (in particular due to decline, expiry, or insufficient funds), the Provider is entitled to repeat the debit attempt through the PSP and, after prior notice, to suspend the provision of the Service or of the individual Assistant until the outstanding amount is paid. The Client undertakes to maintain a valid Payment Card with sufficient funds with the PSP. During the period of default, the Provider is entitled to demand default interest at the statutory rate under Government Regulation No. 351/2013 Sb.; this is without prejudice to the right to terminate the Agreement under Art. 9 in the event of default exceeding 30 days. The Assistant's consumption is measured and billed even during the period of default, until the Assistant is suspended or cancelled.

2a.4a Chargebacks and fraudulent conduct. Payments debited in accordance with the Payment Mandate are authorised. An unauthorised chargeback of an authorised payment does not extinguish the Provider's receivable; the receivable persists regardless of any chargeback made, and the Provider is entitled to suspend the Service under Art. 2a.4 and to demand default interest. The Client is liable to the Provider for the costs and fees incurred as a result of a chargeback or fraudulent use of the Payment Card attributable to the Client and shall indemnify the Provider for the resulting damage.

2a.5 Change of the Price List. The Provider will notify the Client of a change to the Price List (Annex No. 3) 90 days in advance; where it reflects a change in the Subcontractors' prices, 30 days in advance. An extraordinary change to the Price List is governed by Art. 8.6. If the Client does not agree with the change, it is entitled to terminate the Agreement without penalty by the effective date of the change; by continuing to use the Service after the change takes effect, the Client agrees to the change.

2a.6 Fallback invoicing regime. Where payment by Payment Card cannot be used, the Provider may apply the invoicing regime: payment on the basis of an invoice issued monthly in arrears with a 14-day due date from issuance. The other provisions of this article apply mutatis mutandis.

2a.7 Payment Service Provider. The processing of payments is ensured by the PSP on the basis of its own contractual relationship with the Provider. The Provider is not liable for interruption, delay, or restriction of payments caused by the PSP, in particular for the withholding of funds (reserve), suspension, or cancellation of the Provider's account with the PSP; the availability of the Service is not contingent on the immediate availability of funds from the PSP.

2a.8 Change of tariff. The Client changes the Assistant's tariff in the Provider's application. The change takes effect from the start of the immediately following Billing Period of the relevant Subscription; no additional payment or pro-rata credit arises for the running Billing Period (no pro-rata settlement). If the Client makes multiple changes within the same Billing Period, the last one applies.

2a.9 Cancellation of an Assistant. The Client may cancel an Assistant at any time in the Provider's application. Cancellation is final and irreversible and has the following effects: (a) the Subscription and the provision of the service through the Assistant end at the moment of cancellation, and the telephone number is released; (b) the variable component not yet invoiced for the running Billing Period is invoiced as a separate invoice and debited on the basis of the Payment Mandate; the full volume included in the tariff is used for this calculation, with no pro-rata reduction; (c) the fixed monthly component already paid for the running Billing Period is not refunded or pro-rata reduced. Art. 9.4 to 9.6 apply mutatis mutandis to the data of a cancelled Assistant, with the period under Art. 9.4 running from the cancellation of the Assistant. Upon termination of the Agreement under Art. 9, all Subscriptions terminate with the effects under this article as of the effective date of termination.

3. Client's Obligations

3.1 Client's Obligations towards Users

The Client represents and undertakes that:

a. as the controller of Users' personal data, it has ensured compliance with all obligations under the GDPR, in particular the existence of a proper legal basis for processing (Art. 6, or Art. 9 GDPR where applicable) and compliance with the information obligation under Art. 13 and 14 GDPR;

b. it will ensure that Users are informed that they are communicating with an automated artificial intelligence system, in accordance with Art. 50(1) of Regulation (EU) 2024/1689, in a manner that is clear, comprehensible, and provided at the moment of first contact; the Provider fulfils this obligation technically through the call's opening disclosure under Art. 3.4, and the Client is responsible for supplementing it in its own personal data processing notice and in its other communication channels;

c. it will ensure, in accordance with § 89 and § 88a ZEK, that the caller is informed about the recording of the call and the retention of traffic and location data and, where relevant to the chosen legal basis, obtains the caller's consent; the Client acknowledges that the call's opening disclosure (Art. 3.4) provides the technical aspect of the information at the moment the call is answered, but does not replace the Client's information obligation in its own personal data processing notice;

d. Users of the Service are not persons under 18 years of age, unless the Client ensures the demonstrable consent of a legal guardian; Users under 13 years of age are excluded from the Service without exception.

3.2 Customer Identity Verification and Regulatory Obligations for Telephone Numbers

a. The Client undertakes to provide the Provider with true, complete, and up-to-date data necessary for the registration of telephone numbers as part of mandatory customer identity verification (regulatory identification; KYC) with the telecommunications Subcontractor (Twilio Inc.). The Client is responsible for the accuracy and currency of this data and for its ongoing updating. Without a valid address and the data required under this article, a telephone number cannot be acquired and an Assistant cannot be set up (Art. 2.8).

b. The Client acknowledges that untrue data provided for customer identity verification or an unauthorised breach of regulatory rules may result in the immediate suspension (blocking) of telephone numbers or of the Service by the Subcontractor, without the Provider being liable for such suspension (blocking).

3.3 Knowledge Base — Sources and Consent

a. The Client is responsible for having all rights to the content that the Provider processes on the Client's instruction as the assistant's Knowledge Base (in particular the text of the Client's website, structured documents, frequently asked questions).

b. The Client expressly agrees that the Provider may automatically retrieve the content of the web addresses (URLs) entered by the Client in the application and use the structured output for the purposes of providing the Service. Upon deployment, the Provider automatically retrieves the content of the web address (URL) specified by the Client and uses it for the assistant's Knowledge Base; retrieving content from additional addresses requires a separate written order.

c. The Client shall fully indemnify the Provider for any third-party claims arising from the content of the assistant's Knowledge Base, in particular claims for infringement of copyright, intellectual property rights, database rights, and trademark rights.

3.4 Mandatory Opening Call Disclosure

The Client acknowledges and agrees that every call within the Service begins with a mandatory opening disclosure containing four elements (identification of the Client, information that the caller is communicating with an AI assistant, information about the recording of the call, instructions for ending the call). A sample wording is:

"Hello, [Client's company name]. You are speaking with a virtual AI assistant. This call is recorded for the purpose of processing your booking. If you do not agree, please end the call. How can I help you?"

The Client may not unilaterally suppress the opening disclosure, shorten it below the scope of the mandatory four elements, or replace it with wording that would not cover the mandatory elements.

3.5 Acceptable Use Policy (AUP)

The Client undertakes to comply with the Acceptable Use Policy (Annex No. 1), which mirrors the Subcontractors' acceptable use policies and constitutes a material condition of the Agreement. A breach of the AUP by the Client or a User entitles the Provider to immediately suspend the Service without compensation or to terminate the Agreement with immediate effect.

3.6 Specific Parameters of the Service

By the express confirmation under Art. 2.10, the Client accepts the following specifics of the Service, which are structurally inherent in the nature of providing the Service:

a. Transfer to the USA and to third countries outside the EEA: voice recordings, transcripts, and call metadata pass through Subcontractors established or processing data in the USA (Twilio Inc., VAPI Inc., OpenAI OpCo, LLC, ElevenLabs Inc.; for sub-subcontractors, in particular Anthropic, PBC, see Annex No. 1 to the DPA) on the basis of standard contractual clauses under Commission Implementing Decision (EU) 2021/914 and, where relevant, also the EU-U.S. Data Privacy Framework. In the event the EU-U.S. Data Privacy Framework is invalidated, the transfer will automatically rely exclusively on standard contractual clauses without the need for an amendment to the Agreement. Speech recognition (Speech-to-Text) is provided by the Subcontractor Soniox Inc.; audio is routed to its European processing region (see item e), but the orchestration layer of VAPI Inc., through which audio passes to Soniox Inc., continues to be operated in the USA (item c), and Soniox Inc.'s system/billing data may be processed outside the European Union.

b. 30-day retention of input data at OpenAI: the text transcript of the call (a transcript containing names, telephone numbers, and other personal data of Users, produced by the Subcontractor Soniox Inc.) remains with the Subcontractor OpenAI for up to 30 days for the purposes of abuse detection and related human review (TaskUs LLC, the Philippines). OpenAI has not processed raw call audio since the deployment of the Subcontractor Soniox Inc. The Provider does not implement a mechanism for the prior removal (redaction) of personal data, for operational reasons (system latency).

c. VAPI as the primary orchestration layer: call handling takes place in the cloud environment of the Subcontractor VAPI Inc. (USA) on the basis of standard contractual clauses without a separate data processing agreement. Voice biometric verification, speaker recognition, emotion detection, and gender or age detection are not active under the Baseline AI Assistant Configuration.

d. Speech recognition (Soniox Inc.): the primary transcription of speech from incoming call audio is provided by the Subcontractor Soniox Inc. Audio processing is configured for the European processing region (the Provider has verified the activation for its account); without it, audio processing would be governed by the default US region. Soniox Inc. does not store audio or text by default (ongoing in-memory processing without persistent storage in real time). Soniox Inc.'s system and billing data are excluded from the region selection and may be processed outside the European Union.

e. Fallback speech transcription (Google Gemini 2.0 Flash): if the primary transcription service (Soniox Inc.) fails, transcription automatically switches to the substitute service of Google (Gemini 2.0 Flash) operated by Google LLC (USA). This Subcontractor is therefore an active Subcontractor of the Service and may change depending on availability at the level of the Subcontractor VAPI Inc.; changes are governed by Art. 8 (10 days' prior notification). The Provider is further evaluating this fallback architecture (single fallback vs. multi-tier fallback) following the deployment of Soniox Inc.

f. Further onward transfers to countries without an adequacy decision: as part of abuse detection at the Subcontractor OpenAI, human review is carried out by TaskUs LLC (Philippines); sub-providers of the Subcontractor Google may process data in other third countries (in particular India, Mexico, and Israel). These onward transfers rely on standard contractual clauses (Module 3) in accordance with the relevant Subcontractors' documentation; details are set out in Art. 8.4 of the DPA.

3a. Processing of the Client's Personal Data (GDPR Notice)

3a.1 Processing of the Client's data. The Provider processes the personal data of the Client and of persons acting on behalf of the Client (in particular name, contact and identification data, Company ID/Tax ID, billing data and the Payment Card token, identifiers of the customer account, subscriptions, and invoices held with the PSP) as controller for the purposes of concluding and performing the Agreement, invoicing and payment processing, compliance with legal obligations, and the protection of legitimate interests (fraud prevention, debt recovery). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR), compliance with a legal obligation (item (c)), and legitimate interest (item (f)).

3a.2 The Payment Service Provider as recipient. The recipient of the Client's payment and identification data is the PSP (Art. 1.11), which acts in part as an independent controller in relation to this data, in particular for the purposes of fraud prevention, anti-money-laundering (AML) compliance, and the PSP's regulatory obligations. The processing terms on the PSP's side are governed by its own policies.

3a.3 Transfer to a third country. Data may be transferred to the United States of America (Stripe, Inc.). The transfer relies primarily on standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914; the PSP's certification under the EU-U.S. Data Privacy Framework is used as a supplementary safeguard.

3a.4 Rights and retention period. The retention period and the rights of the data subject (access, rectification, erasure, restriction of processing, objection, portability, and the right to lodge a complaint with the Office for Personal Data Protection) are set out at https://fastlajna.cz/en/compliance#privacy. The Provider retains data for invoicing and accounting purposes for the period required by law; for this reason, historical invoices and billing records are not deleted even after the cancellation of an Assistant or the termination of the Agreement.

4. Prohibited Uses

4.1 The Client may not use the Service, or permit its use, for:

a. conduct contrary to the laws of the Czech Republic and the EU; among other things, for fraudulent conduct, voice fraud (vishing), phishing, impersonation of another person, the spreading of malicious software, the generation of content sexualising minors or inciting violence, or discrimination based on protected characteristics;

b. operation in healthcare in the broadest sense, in particular the provision of health services, medical, nursing, psychological, or psychotherapeutic counselling; operation by a public authority or another public-law entity. The Service is intended exclusively for private-law entrepreneurs in unregulated sectors under this article;

c. providing personalised professional advice in the fields of healthcare, law, finance, tax advisory, or investment services without qualified human review of the output before its delivery to the User and without an express notice as to the nature and limitations of AI;

d. processing special categories of personal data under Art. 9 GDPR without meeting the statutory conditions;

e. the systematic extraction of the Service's outputs and their further provision to third parties beyond ordinary use of the Service, or the use of the Service's outputs as training data for machine learning models;

f. operation for minors under 13 years of age without exception; for persons aged 13–18 only with the demonstrable consent of a legal guardian;

g. circumventing the Acceptable Use Policy (Annex No. 1) or the Baseline AI Assistant Configuration (Art. 1.10).

4.2 A breach of any obligation under Art. 4.1 is qualified as gross negligence by the Client within the meaning of § 2898 of Act No. 89/2012 Sb., the Civil Code. A breach entitles the Provider to immediately suspend the Service and terminate the Agreement with immediate effect without compensation; at the same time, the limitation of the Client's liability under Art. 6 does not apply.

4.3 By the express confirmation under Art. 2.10, the Client represents that it does not operate the Service in any of the prohibited categories under Art. 4.1. An untrue representation constitutes its gross negligence under Art. 4.2.

4.4 Subcontractor ElevenLabs — third-party beneficiary. The Subcontractor ElevenLabs is a third-party beneficiary in relation to the Client's obligations under the ElevenLabs Prohibited Use Policy. The Client is bound by the ElevenLabs Prohibited Use Policy (Annex No. 1) and undertakes to cooperate with any audit required by ElevenLabs. The Client shall indemnify both the Provider and ElevenLabs for any claims arising from a breach of this policy.

5. Intellectual Property Rights to Outputs

5.1 All outputs generated by the Service on the basis of the Client's use (in particular transcripts, generated answers, synthesised audio data, bookings, outputs of the Knowledge Base) belong to the Client to the extent they can be made the subject of intellectual property rights.

5.2 The Client grants the Provider a non-exclusive, royalty-free, territorially unlimited licence to use the outputs of the Service exclusively for the purposes of (a) providing the Service to the Client, (b) ensuring its security, abuse prevention, and auditing, (c) compliance with the Provider's and Subcontractors' obligations under the law, and (d) improving the Service. The use of the Client's outputs for training machine learning models by the Provider is excluded; the purpose under item (d) does not include model training. The undertaking not to use customer data for model training also applies to the Subcontractor ElevenLabs (opt-out from training activated).

5.3 The Client acknowledges that the Provider may retain aggregated and anonymised statistics about the use of the Service (e.g., number of calls, duration, technical telemetry); such data is not personal data within the meaning of Art. 4(1) GDPR, and the Provider is entitled to use it without further restriction.

5.4 The Client acknowledges that, with certain Subcontractors (in particular VAPI Inc., ElevenLabs Inc.), the Subcontractor reserves in its own terms and conditions a licence for operational purposes corresponding to its terms and conditions as then in effect, and the Provider cannot unilaterally terminate it. The licence granted to the Provider expires upon termination of the Agreement and survives only to the extent necessary for the deletion and export of data.

6. Limitation of Liability

6.1 The Provider's total aggregate liability under and in connection with the Agreement is limited to an amount equal to the payments made by the Client to the Provider for the 12 months preceding the event giving rise to the claim for damages. For the avoidance of doubt, the aggregate amount of the Provider's liability shall not exceed 12 times the fixed amount of the most expensive tariff in the Price List.

6.2 The Provider is not liable for:

a. indirect damage, lost profit, loss of data, loss of business opportunities, loss of goodwill, non-material harm to reputation;

b. damage caused by the outage, restriction, or termination of a Subcontractor's service that the Provider could not influence and of which it informed the Client without undue delay; this limitation includes, in particular, a Subcontractor's decision to restrict or terminate the Service;

c. damage caused by the failure of a Subcontractor's technical equipment or infrastructure that the Provider did not cause and could not influence;

d. damage caused by the inaccuracy, incompleteness, or distortion of AI model outputs (Art. 12);

e. damage caused by a breach of the Client's obligations under the Agreement or the GTC, in particular a breach of Art. 3 (Client's obligations) or Art. 4 (prohibited uses);

f. interruption, delay, or restriction of payments caused by the Payment Service Provider (PSP) under Art. 2a.7, which the Provider could not influence.

6.3 Exceptions to the limitation of liability. The limitation of liability under Art. 6.1 and the exclusions under Art. 6.2 do not apply to:

a. damage caused by the Provider intentionally or through gross negligence (§ 2898 of Act No. 89/2012 Sb.);

b. damage arising from fraud on the part of the Provider;

c. claims for infringement of third parties' intellectual property rights by the Provider;

d. claims for breach of the Data Processing Agreement (DPA) by the Provider;

e. claims for breach of the confidentiality obligation under Art. 11.

6.4 Mirroring and floor of liability. The limitation of liability of individual Subcontractors vis-à-vis the Provider is independent of the limitation of the Provider's liability vis-à-vis the Client under Art. 6.1; the Provider bears the difference, up to the limit of liability under Art. 6.1. The provision of Art. 15.1 (mirroring of Subcontractor terms) does not apply to the extent it would relieve the Provider of liability for damage caused to the Client below the limitation of liability under Art. 6.1.

6.5 The Provider is not a contractual partner (customer) of Microsoft in relation to data processed in the Microsoft 365 or Outlook.com environment; it accesses this environment exclusively as a third party on the basis of delegated authorisation (OAuth) granted by the Client, or its user. The Provider is not liable for acts, omissions, outages, or breaches of obligations on the part of Microsoft. Any claims arising from Microsoft's conduct shall be asserted by the Client directly against Microsoft on the basis of the contractual relationship that the Client (or its user) has entered into with Microsoft:

a. for business accounts (Microsoft 365 work/school), on the basis of the Client's agreement with Microsoft (typically the Microsoft Customer Agreement or an Enterprise Agreement); the limitation of liability is governed by that agreement;

b. for personal accounts (Outlook.com), on the basis of the Microsoft Services Agreement; the limitation of liability amounts to direct damage up to the fee for the service for the month in which the damage occurred, but no more than USD 10 where the service is provided free of charge.

The limitation of the Provider's liability under Art. 6.1 remains unaffected and applies independently.

7. SLA and Availability

7.1 The Provider guarantees monthly availability of the Service of 95% in a calendar month, calculated according to the methodology set out in Annex No. 2 (SLA).

7.2 If the guaranteed availability is not achieved, the Client is entitled exclusively to a discount on the monthly payment for the relevant calendar month, in the amount and under the conditions set out in Annex No. 2. This discount constitutes the Provider's full and sole remedy for failure to achieve the guaranteed availability and excludes any further claim by the Client for damages (in particular actual damage, lost profit, loss of data, and non-material harm).

7.3 The following are not included in the calculation of availability:

a. planned outages announced at least 48 hours in advance;

b. outages of continuous duration shorter than 15 minutes;

c. outages caused by the Client, its equipment, or Users' connectivity;

d. outages caused by force majeure;

e. outages caused by the termination or restriction of a service by a Subcontractor due to a breach of these GTC by the Client or a User;

f. outages caused by a regulatory decision of the Czech Telecommunication Office, a telecommunications operator, or a body of the European Union.

7.4 For Clients using Variant B of the Microsoft integration (a personal Outlook.com account — see Art. 13a.1), Microsoft does not provide an SLA for personal Outlook.com accounts. For work/school Microsoft 365 accounts, Microsoft provides an SLA of 99.9% for Exchange Online with service credits as the full and sole remedy, i.e., without a claim for actual damages against Microsoft. The 95% SLA under Art. 7.1 remains in effect in both cases; the Client acknowledges that for personal Outlook.com accounts, no compensation mechanism exists between the Provider and Microsoft.

8. Change of the Service and Subcontractors

8.1 The Provider is entitled to change the Service and its technological architecture, in particular to change Subcontractors, their configuration, and the scope of their services, where necessary to continue providing the Service or to ensure its security, availability, and compliance with the law.

8.2 Notification of a change of Subcontractor. The Provider will notify the Client of a change of a Subcontractor processing personal data (addition, replacement) at least 10 days in advance by e-mail to the Client's contact address and by updating Annex No. 1 to the DPA. The Client is entitled, within 10 days of the notification, to raise a written objection on the grounds of justified doubts as to the new Subcontractor's compliance with the GDPR. If the objection cannot be resolved by agreement of the parties within a further 30 days, the Client is entitled to terminate the Agreement on this ground as of the effective date of the change, without any right to damages arising for the Client.

8.3 Notification of an unplanned change. By way of derogation from the preceding paragraph, in the case of an unplanned operational change forced by the unavailability of a Subcontractor, the Provider will notify the Client of the change without undue delay after its implementation, no later than within 5 business days. The Client has the right of objection under Art. 8.2 even ex post; if it is exercised, the Provider will, where technically possible, ensure a return to the original or an alternative configuration within a reasonable period.

8.4 The Provider is entitled to unilaterally amend the GTC, the DPA, Annex No. 1 (AUP), and Annex No. 2 (SLA), with effect no earlier than 30 days after notice is delivered to the Client at its contact e-mail address. The Client has the right to reject the change by terminating the Agreement without penalty within 30 days of delivery of the notice; until the expiry of that period, the previous wording applies. A change to Annex No. 3 (Price List) is governed by Art. 2a.5 and Art. 8.6.

8.5 Voice replacement. The Subcontractor providing the voice output (ElevenLabs) is entitled to replace the deployed voice, in particular where a voice model is withdrawn by the voice talent or as a result of content moderation. The Client acknowledges and accepts that the deployed voice may be replaced with a substitute voice of comparable quality; such replacement is not a defect in the Service nor a ground for the Provider's liability.

8.6 Extraordinary change to the Price List. The Provider is entitled to unilaterally adjust the Price List (Annex No. 3) even outside the standard cycle under Art. 2a.5, if it demonstrates a proportionate change in input costs (in particular a change in Subcontractors' prices). In such a case, the Client has the right to terminate the Agreement without penalty within 30 days of notice of the change.

8.7 Structural dependency on Google. The Client acknowledges that Google LLC reserves the right, in the Google API Terms of Service, to terminate or restrict access to the Google Calendar API at any time without compensation. In such a case, the Provider is entitled to:

a. suspend or adjust the part of the Service integrating with Google Calendar;

b. carry out a migration using reasonable efforts to an alternative integration (Outlook, CalDAV) within a reasonable technical period;

c. terminate the Agreement by giving 30 days' notice;

in each case without any right to damages arising for the Client.

9. Term, Termination and Data Export

9.1 The Agreement is concluded for an indefinite period, unless otherwise agreed in the written order.

9.2 The Agreement may be terminated by mutual agreement or by notice given by either party, with a 30-day notice period beginning on the first day of the calendar month following delivery of the notice. This is without prejudice to the Client's right to cancel an individual Assistant at any time with immediate effect under Art. 2a.9.

9.3 The Provider is entitled to terminate the Agreement with immediate effect in the event of:

a. a breach of Art. 4 (prohibited uses) by the Client or its User;

b. a breach of the AUP (Annex No. 1) by the Client or its User;

c. an untrue representation by the Client under Art. 2.10 or of the data entered by the Client in the application;

d. the Client's default in payment of the price of the Service for more than 30 days;

e. the Client's insolvency or the commencement of insolvency proceedings against the Client;

f. the suspension (blocking) of the Provider's account by any Subcontractor as a result of conduct by the Client or its Users.

9.4 Data export after termination. After termination of the Agreement, upon the Client's written request, the Provider will make available to the Client, for a period of 30 days, an export of its data (in particular call recordings, transcripts, assistant configurations, and the content of the Knowledge Base) in a commonly used format (JSON). After the expiry of this period, the Provider will delete the Client's data from its systems. Deletion is without prejudice to documents and records that the Provider is required to retain under the law (in particular invoices and accounting records — Art. 3a.4).

9.5 After termination of the Agreement, the Provider will request the Subcontractors to delete the Client's data to the extent of their contractual obligations. The Client acknowledges that the deletion periods of individual Subcontractors vary and may exceed the period under Art. 9.4. The detailed deletion periods of individual Subcontractors are set out in Art. 13.4 of the DPA.

9.6 Upon the Client's written request delivered no later than 60 days after termination of the Agreement, the Provider will issue a confirmation of the deletion of data from its systems.

10. Indemnification

10.1 The Client shall indemnify the Provider in full, and without limitation by the limitations of liability under Art. 6, against any third-party claims (in particular by Users, affected natural persons, supervisory authorities, and Subcontractors) asserted in connection with:

a. a breach of Art. 4 (prohibited uses) by the Client or a User;

b. the content of the Client's Knowledge Base (in particular claims for infringement of copyright, database rights, and trademarks — Art. 3.3);

c. content that a User submits to the Service (in particular third parties' personal data, sensitive data, data infringing third-party rights);

d. indirect claims by Subcontractors against the Provider arising from a breach of the Subcontractors' acceptable use policies by the Client or Users;

e. claims arising from the operation of the Service in healthcare or in other prohibited categories (Art. 4.1) contrary to the Client's representation under Art. 2.10.

10.2 Indemnification includes fines imposed (including administrative sanctions of the Office for Personal Data Protection, the Czech Telecommunication Office, and equivalent authorities of other EU Member States), damages awarded to injured parties, the costs of legal representation and expert opinions, as well as other reasonably incurred costs of the Provider.

10.3 The Client's indemnification obligation under Art. 10.1 is not limited.

10.4 The Provider is obliged to notify the Client without undue delay of any third-party claim to which the indemnification under Art. 10.1 is to relate, and to provide the Client with cooperation in its defence.

11. Confidentiality

11.1 The parties are obliged to maintain confidentiality regarding all information of the other party of which they become aware in connection with the Agreement and which has the nature of a trade secret or confidential information (in particular technical solutions, pricing under individual terms, configuration parameters, business strategy, data about Users).

11.2 The confidentiality obligation lasts for the term of the Agreement and for 5 years after its termination; for Users' personal data, the confidentiality obligation applies without a time limit, except as provided by law.

11.3 The confidentiality obligation does not apply to information that:

a. is publicly available without a breach of the confidentiality obligation;

b. was known to the party before the conclusion of the Agreement and is not subject to another confidentiality obligation;

c. must be disclosed pursuant to a legal provision or a decision of a court or public authority.

12. AI-Specific Risks (fabricated data, drift and bias in outputs)

12.1 The Client acknowledges that the Service uses generative language models, automatic speech recognition and synthesis models, and other machine learning systems whose outputs are not deterministic and may contain factual inaccuracies, incompleteness, fabricated data (so-called hallucinations), bias, or a gradual shift in quality over time (drift).

12.2 The Provider is not liable for damage arising from factual inaccuracies in AI outputs within the meaning of Art. 12.1, unless caused by the Provider's intent or gross negligence under Art. 6.3.

12.3 The Client is responsible for deploying the Service in such a way that this characteristic cannot cause harm to Users, in particular through:

a. appropriate instructions in the assistant's system prompt (the Client is responsible for defining them in the application);

b. validation of key outputs (in particular bookings) before their execution.

12.4 Within the meaning of Art. 26 of Regulation (EU) 2024/1689, the Client is the deployer of the AI system towards Users and is responsible for complying with the deployer's obligations under the AI Act, in particular the transparency obligations under Art. 50 of Regulation (EU) 2024/1689. The Provider provides the Client with the necessary technical information and a sample opening disclosure (Art. 3.4).

13. Telecommunications Regulation and the Czech Telecommunication Office

13.1 The Provider provides the Service as an information society service. The Provider does not provide the Service as an electronic communications undertaking. The electronic communications service itself (transmission of incoming voice) is provided by the Subcontractor Twilio and local telecommunications operators.

13.2 The Client is responsible for complying with the obligations of a personal data controller towards Users in connection with the recording of calls (§ 89 ZEK) and the retention of traffic and location data (§ 88a ZEK). The Provider ensures the technical aspect of informing at the moment the call is answered through the mandatory opening disclosure (Art. 3.4); the Client is responsible for complying with the information obligation in its own personal data processing notice.

13.3 The parties undertake to notify each other without undue delay of proceedings conducted against them by the Czech Telecommunication Office or other state supervisory authorities in the field of electronic communications, insofar as they relate to the Service, and to provide each other with cooperation during inspections.

13.4 Telephone numbers and portability. The telephone numbers made available to the Client are allocated from the numbering plan of the Czech Republic through the Subcontractor Twilio. A number remains assigned to the relevant Assistant for the duration of its Subscription; upon cancellation of the Assistant under Art. 2a.9, the number is released. Porting the number to another provider after termination of the Agreement or cancellation of the Assistant is possible to the extent supported by the Subcontractor Twilio and the receiving operator; the Provider will provide the Client with the necessary cooperation if requested by the Client before cancellation of the Assistant. The Client acknowledges that portability is not guaranteed by the Provider beyond the Subcontractor's terms.

13a. Integration with Microsoft 365 / Outlook.com Calendar

13a.1 Microsoft's dual status. The Client declares the type of Microsoft account in the application when connecting the calendar. Depending on the account type, Microsoft (Microsoft Corporation, or for the EU/EEA, Microsoft Ireland Operations Limited, One Microsoft Place, Dublin 18, hereinafter "Microsoft") has one of two statuses:

a. Variant A — a Microsoft 365 work/school account (Microsoft Entra ID tenant): Microsoft is a sub-processor within the meaning of Art. 28 GDPR; the Microsoft Products and Services Data Protection Addendum applies, together with the 2021 standard contractual clauses (modules 2 and 3) under Commission Implementing Decision (EU) 2021/914 and the Microsoft EU Data Boundary; the legal basis for processing Users' calendar data is Art. 6(1)(b) or (f) GDPR;

b. Variant B — a personal Outlook.com account (Microsoft Services Agreement): Microsoft is an independent controller; the Microsoft Services Agreement and the Microsoft Privacy Statement apply; without a data processing agreement under Art. 28 GDPR and without the EU Data Boundary, transfers rely solely on the EU-U.S. Data Privacy Framework; the Client bears full controller liability towards Users, in particular the information obligation under Art. 13 and 14 GDPR and ensuring a legal basis for processing.

13a.2 For business accounts (Microsoft 365 work/school), the transfer of personal data outside the EU/EEA relies on (i) the EU Data Boundary (storage and processing of customer data and pseudonymised personal data in the EU/EFTA, with a partial exception for Entra ID authentication data), (ii) standard contractual clauses under Commission Implementing Decision (EU) 2021/914 (modules 2 and 3) incorporated in Microsoft's DPA, and (iii) the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection, the validity of which was confirmed by the General Court in its judgment of 3 September 2025 in Case T-553/23). For personal accounts (Outlook.com), the EU Data Boundary does not apply and transfers rely on the Data Privacy Framework. The clauses for transfers from the United Kingdom (UK IDTA) apply only where the Client processes data of data subjects in the United Kingdom; otherwise they are immaterial to the provision of the Service.

13a.3 Limitations of Variant B (personal Outlook.com). The Client acknowledges that, for personal Outlook.com accounts:

a. the checking of free/busy times for personal accounts takes place via a simplified route (the calendarView interface, only data on the start, end, and status of an event) and is therefore less accurate;

b. Microsoft does not provide an SLA (Art. 7.4) for personal Outlook.com accounts and limits its liability towards the User to USD 10 (free service), or the fee for one month (paid service);

c. after 2 years of inactivity of a personal account, Microsoft closes the account and deletes the related data; this fact is relevant to the User's right to erasure under Art. 17 GDPR, and controller liability rests with the Client.

13a.4 Scope of authorisation and minimisation. The Service obtains authorisation only to read and write to the primary calendar of the connected account (Calendars.ReadWrite), not to shared calendars of other persons (not Calendars.ReadWrite.Shared). Write access is necessary to create a booking.

13a.5 Liability in relation to Microsoft is governed by Art. 6.5.

13a.6 In its DPA, Microsoft undertakes to notify the Provider of a security incident "without undue delay," but without a fixed numerical deadline. The Provider will notify the Client of a personal data breach concerning data processed in the Microsoft environment no later than 48 hours from the moment it becomes aware of such a breach with reasonable certainty, regardless of the source of the discovery (notification by Microsoft or the Provider's own discovery).

13a.7 Structural dependency on Microsoft and end of support. Microsoft provides a 24-month notice period for the discontinuation of support for production (generally available) Microsoft Graph interfaces. In the event of the termination or restriction of the Microsoft Graph Calendar API, the Provider is entitled to proceed analogously to Art. 8.7(a)–(c) (suspension or adjustment of the integration; migration using reasonable efforts to an alternative — Google Calendar, CalDAV; termination by giving 30 days' notice), in each case without any right to damages arising for the Client.

13a.8 Microsoft demonstrably maintains certifications and compliance reports, in particular SOC 2 Type 2 for Microsoft 365 Microservices; contractual assurance of compliance is provided by Microsoft's DPA, the Product Terms, and the ISO certifications referred to.

13a.9 M365 Certification. The Provider need not be certified under the Microsoft 365 Certification program. If the configuration of the Client's tenant requires this certification or approval by the tenant administrator, the integration with Microsoft 365 may not be available to the Client; this is without prejudice to the availability of the other parts of the Service.

13a.10 Management of tenant users (Variant A). For work/school accounts, the Client, as the tenant administrator, is responsible for managing all tenant users, including guest accounts and their permissions. The Provider accesses only the primary calendar of the accounts for which the Client has authorised the integration.

13a.11 Security interplay (division of controls). The security of the Microsoft 365 integration depends on the division of controls between the Client, as the tenant administrator, and the Provider. The Client is responsible in particular for the authorisation and periodic review of user access permissions in its Microsoft 365 tenant, for enforcing multi-factor authentication for its users, and for managing their authentication mechanisms. The Provider is responsible in particular for the security of the application registration in Microsoft Entra, for the management and rotation of access credentials (certificate / shared secret), for the security of its own infrastructure (Forpsi VPS, encryption of OAuth tokens using the Fernet algorithm), for multi-factor authentication of its own operational accounts, and for the prompt removal of access upon personnel changes. The detailed division is set out in Art. 6.6 of the DPA. The Client acknowledges that the management of the encryption key (Fernet) on the Provider's infrastructure constitutes a single point of failure.

13a.12 Consumer protection of Users (joint clause — EECC). The Client acknowledges that, to the extent it has, in relation to Microsoft (Variant A), agreed to waive certain provisions on end-user protection under the European Electronic Communications Code (Directive (EU) 2018/1972, in particular Art. 102, 105, and 107), it does so exclusively within its own relationship with Microsoft as an undertaking. This waiver does not affect the rights of Users who are consumers; they retain, vis-à-vis both the Client and the Provider, all consumer and end-user rights under Directive (EU) 2018/1972, Act No. 127/2005 Sb., and Act No. 89/2012 Sb. This clause applies mutatis mutandis also to outbound transactional SMS under Art. 13b, where the SMS Add-on Service is agreed.

13b. Outbound Transactional SMS (SMS Add-on Service)

13b.1 Scope and purpose. The provisions of this article apply only where the SMS Add-on Service is agreed. Its content is the sending of outbound automated transactional SMS messages (booking confirmation and reminder) exclusively to Czech numbers (+420). These SMS messages are not commercial communications within the meaning of § 7 of Act No. 480/2004 Sb.

13b.2 Status of the parties. The Client is the controller of Users' personal data and the sender of the message. The Provider is the processor and the provider of the technical platform and, within the meaning of Art. 13.1, does not provide an electronic communications service. Transmission of the message is provided by the Subcontractor (Twilio) as the electronic communications service provider.

13b.3 Identification of the Client. SMS messages are sent under an alphanumeric sender designation (Sender ID). The Client is identified in the body of the message. The Client agrees to this identification as the sender of the message.

13b.4 Registration. The Provider will initiate sender registration with the operators (T-Mobile CZ, O2 CZ) promptly after the SMS Add-on Service is agreed; SMS functionality is activated after successful registration, typically within 3 weeks. The Provider is not liable for the refusal or delay of registration by the operators or for non-delivery caused by an operator.

13b.5 Permitted content. Only pre-approved templates provided or agreed by the Provider are sent (booking confirmation, reminder, rescheduling, and cancellation), with variable fields. The Client is not entitled to change the wording of the templates or insert marketing content. Any marketing element converts the message into the regime of a commercial communication under § 7 of Act No. 480/2004 Sb. (consent and the possibility of opting out), and full liability rests with the Client.

13b.6 Informing Users. The legal basis for processing the telephone number for transactional SMS is Art. 6(1)(b) of Regulation (EU) 2016/679 (performance of the booking contract). The Client is responsible for having an appropriate relationship and legal basis vis-à-vis the User and for ensuring that the confirmation/reminder will be delivered by SMS.

13b.7 Opt-out. The telephone number for SMS is technically one-way. Opting out cannot be done by replying to the message. The option to decline transactional reminders is stated in the body of the message and administered by the Client. The Provider operates an opt-out mechanism for outbound SMS meeting the requirements of the Twilio Messaging Policy: recognition of standardised opt-out keywords (in particular STOP and its Czech equivalents), automatic cessation of further messages to the relevant number, confirmation of opt-out, and retention of opt-out records. The Provider provides outbound transactional SMS only for as long as this mechanism is active. This is without prejudice to the Client's obligations under Art. 13b.5 and 13b.6.

13b.8 Czech numbers only. SMS messages are sent exclusively to +420 numbers, unless the Client agrees a supplementary service for specifically defined foreign numbers. Without the supplementary service, messages to foreign numbers are not within the scope of the Service; the system performs a check before sending and will not send SMS to unsupported numbers.

13b.9 Deliverability. The Provider does not guarantee the delivery of SMS messages; delivery depends on mobile operators and on sender registration. The Provider's 95% SLA under Art. 7.1 does not apply to non-delivery caused by an operator or a Subcontractor.

13b.10 Indemnification. The Client shall indemnify the Provider against any claims arising from the content of messages, the absence of a legal basis, a marketing element, a breach of opt-out obligations, or incorrect identification of Users.

13b.11 Billing of SMS. The price for transactional SMS sent applies only from the activation of the SMS Add-on Service and to the extent set out in the Price List. If no price is set for SMS in the Price List, SMS messages under the agreed SMS Add-on Service are included in the fixed monthly component of the tariff.

14. Governing Law and Choice of Court

14.1 The Agreement, these GTC, the DPA, and all of its Annexes are governed by the laws of the Czech Republic, in particular Act No. 89/2012 Sb., the Civil Code, Act No. 127/2005 Sb., on Electronic Communications, Act No. 110/2019 Sb., on the Processing of Personal Data, and the provisions of European Union law directly applicable in the Czech Republic (in particular the GDPR and the AI Act).

14.2 For the resolution of disputes arising from the Agreement, the general court having local jurisdiction over the Provider within the meaning of § 84 and § 85 of Act No. 99/1963 Sb., the Code of Civil Procedure, has jurisdiction.

14.3 The Client acknowledges that the terms and conditions of individual Subcontractors are, in the relationship between the Subcontractor and the Provider, governed by foreign law (in particular the law of the State of California, English law, or the law of the State of New York, or Irish law for parts governing data protection); disputes with Subcontractors are resolved in a foreign jurisdiction of the Subcontractors' choosing. This does not affect the governing law of the relationship between the Provider and the Client under Art. 14.1.

14.4 The binding version of the GTC, the DPA, and all Annexes is the Czech-language version. Any translation into another language is for information purposes only. In the event of a discrepancy between the Czech version and a translation, the Czech version shall prevail.

15. Mirroring of Subcontractor Terms

15.1 The Provider's rights and obligations under the Agreement and the DPA are set so as to reflect the Subcontractors' obligations towards the Provider. If a particular Subcontractor provides performance, supporting guarantees, or deadlines to a narrower extent than set out in the Agreement or the GTC, the Provider is obliged to act with professional diligence but is not liable for non-performance to the extent that the non-performance results from a Subcontractor's limitation that the Provider could not influence and of which it informed the Client without undue delay.

15.2 In the event of the termination or material restriction of a Subcontractor's services, the Provider is entitled to replace it with an alternative Subcontractor of a comparable category (with notification under Art. 8.2). For the period necessary for the replacement, the availability and functionality of the Service may be limited, without this giving rise to any claim by the Client under the SLA provisions (Art. 7).

16. Final Provisions

16.1 Severability clause. The invalidity, ineffectiveness, or unenforceability of any provision of the GTC does not affect the validity, effectiveness, and enforceability of the other provisions. In such a case, the parties undertake to replace the invalid, ineffective, or unenforceable provision with a valid, effective, and enforceable provision whose content most closely approximates the original intent.

16.2 Assignment. The Client may not assign the Agreement, or individual rights and obligations arising from it, to a third party without the Provider's prior written consent. The Provider is entitled to assign the Agreement to its legal successor or within a corporate transformation, as well as to assign receivables against the Client to a third party.

16.3 Delivery. Legal acts between the parties shall be delivered in writing, by e-mail, in the case of the Client to the address stated in its customer account and in the case of the Provider to the contact address stated in the application or on the Provider's website. The parties are obliged to notify each other of changes to contact details without undue delay. Deemed delivery: a message sent by the Provider to the Client's e-mail address stated in the customer account is deemed delivered on the third business day after demonstrable sending.

16.4 Waiver. The failure to exercise, or delay in exercising, a right under the Agreement by a party does not constitute a waiver of that right, nor its time-barring beyond the statutory rules.

16.5 Annexes. The following annexes form an integral part of the Agreement and the GTC:

  • Annex No. 1 — Acceptable Use Policy (AUP) — part of this document

  • Annex No. 2 — SLA — part of this document

  • Annex No. 3 — Price List — a separate document, published at https://fastlajna.cz/en/compliance#cenik

  • Baseline AI Assistant Configuration — as part of the Service's operational framework

Note: the list of Subcontractors (Sub-processors) forms Annex No. 1 to the DPA, not an annex to the GTC.

16.6 These GTC take effect on 20 July 2026 and supersede all previous versions.

Annex No. 1 — Acceptable Use Policy (AUP)

1. Relationship to the GTC

This Annex mirrors and specifies the prohibited uses under Art. 4.1 GTC (including the prohibition on operation in healthcare) and the prohibition on circumventing the Acceptable Use Policy or the Baseline AI Assistant Configuration under Art. 4.2(g) GTC. The Client undertakes to comply with these rules as a material condition of the Agreement (Art. 3.5 GTC).

2. Consolidated Prohibited Uses (Intersection of Subcontractors' Rules)

Beyond Art. 4.1 GTC, the Client may not use the Service, or allow it to be used, for:

a. unlawful content or conduct under the law of the Czech Republic, the European Union, and international conventions, including content falling under Regulation (EU) 2022/2065 (Digital Services Act);

b. sending spam or other unsolicited bulk communications;

c. harassment, threats, stalking, or other conduct endangering the safety of others;

d. infringement of third-party rights (copyright, trademarks, database rights, privacy and personality rights);

e. security attacks, circumvention of security measures or Service limits, unauthorized access to systems, vulnerability testing without consent, or reverse engineering;

f. automated scraping, bulk downloading, or creating permanent copies of Subcontractors' content beyond the Service's own mechanism for retrieving the Client's Knowledge Base (Art. 3.3(b) GTC);

g. deceptive impersonation of persons or entities, misrepresenting identity, or generating content intended to mislead as to whether it is AI, or as to the speaker's identity;

h. voice cloning or creating a synthetic voice imitating a specific real person without their consent — the Service uses exclusively preset (stock) voices from the ElevenLabs Voice Library (Art. 8.5 GTC);

i. high-risk use where failure of the Service could result in death, serious injury, or significant property or environmental damage (e.g., control of critical infrastructure, medical devices, or air traffic).

3. Prohibitions Specific to the Scope of the Service

The Client may further not use the Service for:

a. making outbound voice calls — the Service is intended exclusively for incoming communication (Art. 1.1 GTC); outbound voice calls are not part of the Service;

b. collecting payments from Users on the Client's behalf through the Service or the Payment Service Provider — the Payment Service Provider (Stripe, Art. 1.11 GTC) processes exclusively the Client's payments to the Provider (Art. 2a GTC), not payments between the Client and its Users;

c. facilitating emergency calls (112 and equivalent) — the Service does not provide this functionality and must not be presented to Users as doing so.

4. ElevenLabs — Prohibited Use Policy (Third-Party Beneficiary)

The Client is bound by the current version of the Prohibited Use Policy of the Subcontractor ElevenLabs, available at https://elevenlabs.io/use-policy, in particular as regards the prohibition on unauthorized voice cloning and impersonation, unauthorized robocalling and unsolicited communication ("call bombing"), and the other categories set out therein. The Subcontractor ElevenLabs is a third-party beneficiary in relation to the Client's obligations under this Prohibited Use Policy, and the Client undertakes to cooperate with any audit required by ElevenLabs. The Client shall indemnify both the Provider and ElevenLabs for any claims arising from a breach of this policy (Art. 4.4 GTC). This provision does not represent that the Provider is expressly authorized or licensed by ElevenLabs to make ElevenLabs' outputs available to the Client's Users.

5. Dynamic Incorporation of Subcontractors' Policies

The acceptable-use policies of individual Subcontractors may change over time; the current version is available on the relevant Subcontractor's public website, in particular:

  • Twilio Acceptable Use Policy and Messaging Policy

  • OpenAI Usage Policies

  • ElevenLabs Prohibited Use Policy (see Art. 4)

  • Soniox Terms of Service, Art. 6–9 (Acceptable Use, No Model Training, Voice Cloning, High-Risk and Regulated Uses)

  • Google API Services User Data Policy and Google APIs Terms of Service

  • Microsoft Universal License Terms for Online Services — Acceptable Use Policy

  • General Terms and Conditions of INTERNET CZ, a.s. (Forpsi), Art. XII–XIII

Where a Subcontractor's rule diverges from this Annex or from Art. 4.1 GTC, the stricter (more restrictive) rule applies.

6. Sanctions

A breach of this Annex by the Client or a User is assessed and sanctioned under Art. 3.5 and Art. 9 GTC (immediate suspension of the Service, termination of the Agreement with immediate effect and without compensation). This Annex does not introduce any sanctions beyond the GTC.

Annex No. 2 — SLA Schedule

1. Definition of Availability

Availability means the Service's ability to accept an incoming call on the telephone number assigned to an Assistant (Art. 2.6 GTC) and to begin processing it. Availability is measured per calendar month and per individual Assistant by the Provider's automated monitoring; the Provider's availability records serve as the basis for the calculation under this Annex and for any billing dispute (Art. 2a.2a GTC).

2. Calculation of Availability

Availability (%) = ((Mm − Mn) / Mm) × 100

where Mm = the number of minutes in the calendar month and Mn = the number of minutes of Service unavailability in that month for the relevant Assistant, excluding minutes excluded under Art. 3 of this Annex. The calculated value is rounded to two decimal places.

3. Exclusions from the Availability Calculation

The reasons under Art. 7.3 GTC are not included in the calculation of availability; the planned outage under Art. 7.3(a) GTC is limited to an aggregate scope of no more than 4 hours per calendar month.

The following are further not included in the calculation of availability:

a. a limitation of availability or functionality of the Service during a suspension under Art. 3.5 or Art. 9 GTC;

b. a limitation of availability during the period necessary to replace a Subcontractor under Art. 15.2 GTC;

c. non-delivery of outbound transactional SMS — this Annex does not apply to the SMS Add-on Service (Art. 13b.9 GTC).

A blanket exclusion of outages caused by Subcontractors beyond Art. 7.3 GTC and items a)–c) above is not introduced; such an exclusion would effectively empty out the availability guarantee under Art. 7.1 GTC.

4. Price Discounts

If the guaranteed availability (95% in a calendar month, Art. 7.1 GTC) is not achieved for a given Assistant, the Client is entitled, exclusively for that Assistant, to a discount on the Fixed Monthly Component of that Assistant's tariff for the relevant calendar month (Art. 7.2 GTC), in the following amount:

Availability in the calendar monthDiscount on the fixed monthly component of the tariff
less than 95% but at least 90%5%
less than 90% but at least 70%10%
less than 70%50%

The discount under this Annex constitutes the Provider's full and sole remedy for failure to achieve the guaranteed availability and excludes any further claim by the Client under Art. 7.2 GTC.

5. Claiming the Discount

The Client must claim the discount in writing (by e-mail to the Provider's contact address) no later than 30 days after the end of the calendar month to which the discount relates; the claim lapses upon the fruitless expiry of this period. The Provider will apply the awarded discount as a deduction from the Fixed Monthly Component on the invoice for the immediately following Billing Period of the relevant Subscription (Art. 3 of the Price List).

6. Pay-as-you-go Tariff

6.1 The discount under this Annex does not apply to Subscriptions on the Pay-as-you-go tariff; a Client on this tariff has no claims arising from a failure to achieve the guaranteed availability.

7. Scope of the SLA

This Annex does not guarantee any level of data backup, RPO, or RTO; the Provider does not perform backups beyond ordinary operational recovery of the infrastructure (Art. 9.4 GTC, Art. 6.3(c) DPA). For Clients using a Microsoft 365 integration (Variant A) or Outlook.com (Variant B), Art. 7.4 GTC applies additionally (Microsoft's SLA for Exchange Online, or the absence of an SLA for personal Outlook.com accounts, respectively). Deliverability of outbound transactional SMS is governed by Art. 13b.9 GTC and is not affected by this Annex (Art. 3(c)).

8. Amendment of this Annex

An amendment of this Annex No. 2 is governed by Art. 8.4 GTC.

DPA

↑ Back to top

Effective from July 20, 2026 · version v1

Contents

  • 1. Definitions
  • 2. Subject Matter of Processing
  • 2.1 Nature, Purpose, and Subject Matter of Processing
  • 2.2 Duration of Processing
  • 2.3 Categories of Data Subjects
  • 2.4 Categories of Personal Data
  • 2.5 Purposes of Processing
  • 3. Controller's Instructions
  • 4. Processor's Obligations under Art. 28(3) GDPR
  • 5. Confidentiality
  • 6. Security of Processing (Art. 32 GDPR) — Technical and Organisational Measures
  • 6.1 General Principle
  • 6.2 Measures Implemented at the Processor's Level
  • 6.3 Expressly Non-Implemented Measures and Conscious Acceptance
  • 6.4 Measures at the Level of the Sub-processors
  • 6.5 Call Recording and § 88a/§ 89 ZEK
  • 6.6 Complementary User Entity Controls (CUEC) as TOMs
  • 7. Sub-processors
  • 7.1 Controller's Generic Consent
  • 7.2 Controller's Objection
  • 7.3 Contractual Binding of Sub-processors
  • 7.4 Specifics of Sub-processors (Transparent Disclosure)
  • 7.5 Controller's Right to the List of Sub-processors
  • 7.6 Telecommunications Operators (Local Carriers)
  • 8. International Transfers
  • 8.1 Transfer Mechanism
  • 8.2 Data Privacy Framework and Fallback Mechanism
  • 8.3 Transfer Impact Assessment (TIA)
  • 8.4 Transfer outside a Country with an Adequate Level of Protection
  • 8.5 SCC Governing Law
  • 8.6 Microsoft — Transfers to Third Countries
  • 9. Data Subjects' Rights — Processor's Cooperation
  • 10. Notification of Personal Data Breach
  • 11. DPIA and Prior Consultation — Cooperation
  • 12. Audit
  • 13. Erasure or Return of Data after Termination
  • 14. Liability and Sanctions
  • 15. Final Provisions
  • Annex No. 1 (DPA) — List of Sub-processors
  • Annex No. 2 (DPA) — Technical and Organisational Measures (TOM)
  • A. TOM of the Processor
  • B. TOM of the Sub-processors (Summary)
  • Annex No. 3 (DPA) — Description of Processing under Art. 28(3) GDPR

Data Processing Agreement (DPA)

concluded pursuant to Art. 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) between:

the Controller: the Client, i.e. the entrepreneur identified in Section 1 of the Onboarding Form (Annex No. 4 to the GTC), which has accepted the GTC in accordance with Art. 2a.2 of the GTC (hereinafter the "Controller")

and

the Processor: Fastlajna s.r.o., with its registered office at Školská 1736/12, Nové Město, 110 00 Praha 1, Company ID (IČO) 29543908, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 448213 (hereinafter the "Processor")

(the Controller and the Processor together hereinafter the "Parties").

This Data Processing Agreement (hereinafter the "DPA") forms an integral part of the General Terms and Conditions (hereinafter the "GTC") and of the overall contractual documentation between the Parties.

Version effective as of 20 July 2026.

Informative translation. The binding version is the Czech text. In case of any discrepancy, the Czech version prevails (GTC Art. 14.4).

1. Definitions

For the purposes of this DPA, the terms defined in Art. 4 GDPR are used (in particular controller, processor, personal data, processing, data subject, sub-processor, supervisory authority, personal data breach).

The terms "Service," "Provider," "Client," "Subcontractor," "User," "Baseline AI Assistant Configuration," "AI Act," "GDPR," and "ZEK" have the meaning given to them in the GTC.

The term "Sub-processor" corresponds to the term "another processor" under Art. 28(2) and (4) GDPR; in this DPA it is used interchangeably with the term "Subcontractor" as introduced in the GTC.

2. Subject Matter of Processing

2.1 Nature, Purpose, and Subject Matter of Processing

The Processor processes the personal data of Users in the course of providing the Service, i.e., the AI voice assistant providing for the receipt of incoming telephone calls, automated speech synthesis and recognition, dialogue orchestration with a language model, retrieval of answers from the Controller's knowledge base, and booking in its calendar, for the duration of the Agreement.

2.2 Duration of Processing

For the duration of the Agreement and thereafter for the period necessary to fulfil Art. 13 of this DPA (return or erasure of personal data).

2.3 Categories of Data Subjects

a. Users — natural persons calling the telephone number made available to the Controller as part of the Service (in particular consumers — the Controller's customers);

b. the Controller's contact persons — employees, statutory body, contact persons of the Controller (operational administration, invoicing).

2.4 Categories of Personal Data

The Processor processes the following categories of Users' personal data:

a. identification data — first name, surname (given by the User during the call), the caller's telephone number, e-mail address (given by the User);

b. content of communication — the audio recording of the call, the transcript of the call (incl. structured JSON with Users' personal data), structured response configuration;

c. traffic and location data — date and time of the call, duration, call identifier (Twilio call SID, VAPI call ID), the caller's country, technical metadata (operator, codec);

d. booking data — date, time, place, name of the person making the booking (passed to the Controller's calendar via the Google Calendar API);

e. logs and audit — records of events in the Processor's system (authentication logs, OAuth tokens in encrypted form).

The processing of special categories of personal data under Art. 9 GDPR is excluded in accordance with the prohibited uses under Art. 4 of the GTC and in accordance with the Subcontractors' prohibitions (OpenAI DPA Schedule 1.5, ElevenLabs ElevenAgents Terms § 2.E). If a User spontaneously discloses such data during a call, neither the Processor nor the Sub-processors process it separately beyond the ordinary content of the call.

2.5 Purposes of Processing

The purpose of the processing is exclusively the provision of the Service to the Controller to the extent agreed in the Agreement and the GTC, in particular:

a. ensuring telecommunications connectivity of the incoming call;

b. automatic speech recognition (Speech-to-Text);

c. dialogue orchestration with a language model (LLM);

d. speech synthesis (Text-to-Speech) for responses to the User;

e. recording the call for the Controller's purposes in accordance with § 89 ZEK;

f. booking in the Controller's calendar;

g. retrieval of answers from the Controller's knowledge base;

h. compliance with the legal obligations of the Processor and the Sub-processors (in particular obligations under the ZEK).

3. Controller's Instructions

3.1 The Processor processes personal data exclusively on the basis of the Controller's documented instructions. The Controller's instructions are given by this DPA, the GTC, and the specific configuration of the Service in the Processor's management interface (dashboard).

3.2 Extraordinary instructions beyond the scope of the agreed configuration of the Service must be given in writing (by e-mail from the Controller's registered contact address).

3.3 The Processor will inform the Controller without undue delay if, in its opinion, a given instruction infringes the GDPR or other data protection legislation. The Processor is not obliged to carry out such an instruction.

3.4 The Processor processes Users' personal data falling within the scope of abuse prevention operated by Sub-processors (in particular OpenAI) under the Sub-processors' own instructions, not on the Controller's instruction. This part of the processing takes place within the independent controller role of the relevant Sub-processor; this fact is accepted by the Controller as the conscious acceptance of a specific risk (Art. 3.6(b) of the GTC; express confirmation under Art. 2.10 GTC).

4. Processor's Obligations under Art. 28(3) GDPR

The Processor undertakes:

4.1 (a) to process personal data only on the Controller's instructions (Art. 3);

4.2 (b) to ensure that persons authorised to process personal data are bound by confidentiality or are subject to a statutory duty of confidentiality (see Art. 5);

4.3 (c) to take all measures required by Art. 32 GDPR (see Art. 6);

4.4 (d) to comply with the conditions for engaging further processors under Art. 28(2) and (4) GDPR (see Art. 7);

4.5 (e) taking into account the nature of the processing, to assist the Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to requests from data subjects (see Art. 9);

4.6 (f) to assist the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (in particular data protection impact assessments, prior consultation with the supervisory authority) — see Art. 11;

4.7 (g) in accordance with the Controller's decision, to delete or return all personal data to the Controller after the end of the provision of the Service, and to delete existing copies, unless European Union or Member State law requires otherwise (see Art. 13);

4.8 (h) to provide the Controller with all information necessary to demonstrate compliance with its obligations and to allow for audits (see Art. 12).

5. Confidentiality

5.1 The Processor undertakes that the persons who process Users' personal data on its behalf are bound by a contractual duty of confidentiality that survives the termination of their employment or similar relationship.

5.2 The Processor will similarly bind all Sub-processors to confidentiality and will require the Sub-processors to extend this obligation to their employees and suppliers.

5.3 The specific confidentiality obligation of the hosting Subcontractor (Forpsi — INTERNET CZ, a.s.) is set out in Art. XVIII.1 of its general terms and conditions; the Processor has not required Forpsi to provide extended contractual confidentiality beyond the clause referred to, and the Controller acknowledges this fact.

6. Security of Processing (Art. 32 GDPR) — Technical and Organisational Measures

6.1 General Principle

The Processor takes appropriate technical and organisational measures corresponding to the risks associated with the processing of Users' personal data, the state of the art, and the costs of implementation, always having regard to the nature, scope, and purposes of processing (Art. 32(1) GDPR).

6.2 Measures Implemented at the Processor's Level

a. Encryption in transit: TLS 1.3+ by default for all communication between components of the Service (client ↔ Twilio, Twilio ↔ VAPI, VAPI ↔ OpenAI/ElevenLabs/Google, the receiving interface ↔ the VPS); TLS 1.2 as a fallback protocol exclusively for legacy clients where TLS 1.3 is not available; TLS 1.3+ for access to the Processor's console and API.

b. Encryption at rest at the operating-system level: LUKS (block-level encryption) on the Forpsi VPS disk.

c. Encryption of Google Calendar OAuth tokens: application-level encryption using the Fernet algorithm (AES-128-CBC + HMAC-SHA256) for the access_token_enc and refresh_token_enc fields; the key is stored in the application environment.

d. SSH authentication: key-based only (no password), a non-standard port (2242), the fail2ban tool against brute-force attacks.

e. Network isolation: the VPS has no publicly accessible services other than the HTTPS endpoint and SSH.

f. Logging of access and operations at the application layer.

g. HMAC SHA-256 signing of webhooks between VAPI and the Processor's receiving interface with timing-safe validation (per the Baseline AI Assistant Configuration).

h. Isolation of individual customers' data in the database via an identifier (UUID).

i. Management of API keys at the Subcontractor Vapi: the Subcontractor Vapi processes the Processor's API keys to further Subcontractors (OpenAI, ElevenLabs). The Processor applies measures to limit exposure and to periodically rotate these keys; it treats any compromise of a key as a security incident under Art. 10.

6.3 Expressly Non-Implemented Measures and Conscious Acceptance

The Controller acknowledges and accepts that, for operational, cost, and technical reasons (system latency), the Processor consciously does not implement the following measures; their absence is taken into account in the overall assessment of appropriateness under Art. 6.1, and the Controller expressly confirms this under Art. 2.10 GTC:

a. field-level application encryption (call transcripts, telephone numbers, the audit log) — data is stored in the Processor's database in plaintext; encryption is provided only at the disk level (LUKS) and in transit (TLS);

b. prior removal (redaction) of personal data from the call transcript before it is passed to the Subcontractor OpenAI (LLM) — not implemented, for reasons of system latency; the consequence is 30-day retention of the unredacted text input (transcript) at OpenAI (Art. 7.4.4). Call audio is not passed to the Subcontractor OpenAI; transcription is provided by the Subcontractor Soniox without retention (Art. 7.4.3);

c. backups beyond ordinary operational recovery of infrastructure — not performed; the Controller is responsible for its own backup by exporting data (Art. 9.4 of the GTC);

d. row-level access control in the database (Row-Level Security) and key management in a separate system (KMS/HSM) — placed on the development backlog, not currently implemented; data isolation is provided at the application level (UUID), and the Fernet encryption key is stored in the application environment, constituting a single point of failure.

6.4 Measures at the Level of the Sub-processors

The Processor's Sub-processors adopt their own technical and organisational measures corresponding to Art. 32 GDPR, evidenced typically by SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, or equivalent certification (scope depending on the relevant Sub-processor):

a. Twilio Inc. — SOC 2 Type II, ISO 27001/27017/27018, Binding Corporate Rules (BCR);

b. OpenAI Ireland Ltd. / OpenAI OpCo, LLC — Annex II TOM under DPA v.010126 (AES-256, TLS 1.2+, SOC 2 Type II summary available on request);

c. ElevenLabs Inc. / Eleven Labs Poland sp. z o.o. — SOC 2 Type II (per DPA § 10.1);

d. VAPI Inc. — SOC 2 Type II, PCI DSS v4.0.1, HIPAA compliance (non-public documents accessible via SafeBase under NDA);

e. Google LLC — ISO/IEC 27001, SOC 2, SOC 3;

f. INTERNET CZ, a.s. (Forpsi) — measures appropriate to the type of IaaS hosting;

g. Microsoft: SOC 2 Type 2, ISO/IEC 27001, 27018, and 27701.

Current details of the Sub-processors' technical and organisational measures (TOM) are the subject of Annex No. 2 to this DPA.

6.5 Call Recording and § 88a/§ 89 ZEK

The Controller acknowledges that:

a. call recording is permanently active at the Subcontractor VAPI Inc. with no technical means of disabling it; the Processor fulfils the information obligation towards the User through the mandatory opening disclosure under Art. 3.4 of the GTC;

b. the retention of traffic and location data (§ 88a ZEK) is ensured by the telecommunications Subcontractor Twilio Inc. and the local carrier; Twilio also processes CDR data as an independent controller (Twilio DPA § 3.3); local carriers act as independent controllers (Art. 14 GDPR).

6.6 Complementary User Entity Controls (CUEC) as TOMs

Microsoft's SOC 2 report presupposes Complementary User Entity Controls on the part of the user of the service. These are divided as follows:

a) On the Controller's side (as administrator of its own Microsoft 365 tenant): authorisation and periodic review of access permissions of its own administrator and user accounts in the tenant; enforcement of multi-factor authentication for these accounts; reporting identified security incidents to the Processor. (Corresponds to CUEC-01, CUEC-03, and CUEC-08 in the part relating to tenant administration.)

b) On the Processor's side (as operator of the application with delegated access):

  • security of the application registration in Microsoft Entra: a certificate instead of a shared secret, its rotation and storage in Key Vault; management of its own operational and developer accounts;

  • strong authentication and multi-factor authentication of these accounts;

  • encryption of network sessions (TLS);

  • security of the infrastructure used for access (Forpsi VPS, patch management, restricted access), including the conscious acceptance of a single master encryption key (Fernet) as a single point of failure under Art. 32 of Regulation (EU) 2016/679 and the associated risk;

  • internal training of personnel in the secure handling of tokens and data;

  • compliance with Microsoft's contractual terms;

  • controls over the completeness and accuracy of inputs, processing, storage, and output of calendar data (validation of data passed to and from Microsoft Graph and reconciliation with the Processor's database).

(Corresponds to CUEC-01 in the part relating to application registration and operational accounts, CUEC-02, CUEC-03 in the part relating to the Processor's accounts, CUEC-04, CUEC-06, CUEC-07, CUEC-08 in the part relating to reporting to Microsoft, and CUEC-10 to CUEC-14.)

The Processor will further implement an internal procedure for revoking access upon personnel changes within 24 hours of notice of termination (SSH keys to Forpsi, administrator roles in Microsoft Entra, the secrets manager).

7. Sub-processors

7.1 Controller's Generic Consent

The Controller grants the Processor general authorisation to engage the Sub-processors listed in Annex No. 1 to this DPA (List of Sub-processors). The Processor will notify the Controller of a change to the list of Sub-processors (addition or replacement) at least 10 days in advance by e-mail to the Controller's contact address and by updating Annex No. 1. For the Microsoft Sub-processors, for whom a longer notification period applies on the Sub-processor's side (6 months for customer data, 30 days for the AI sub-processor), the Processor forwards the notification to the Controller within 5 business days of receiving it (3 business days for the AI sub-processor); the general 10-day period under the first sentence does not apply in that case. The period runs from the moment the Processor receives the notification from Microsoft. A change of Sub-processor also includes the transfer of its activities or data to a successor entity as part of a merger, acquisition, or similar transaction; the notification and objection regime under this article applies.

7.2 Controller's Objection

The Controller is entitled, within 10 days of the notification, to raise a written objection on the grounds of justified doubts as to the new Sub-processor's compliance with the GDPR. The Parties undertake to resolve the objection by agreement within 30 days. If agreement cannot be reached, the Controller is entitled to terminate the Agreement on this ground as of the effective date of the change, without any right to damages arising for the Controller.

7.3 Contractual Binding of Sub-processors

The Processor will impose on each Sub-processor the same data protection obligations as are set out in this DPA, in particular the provision of sufficient guarantees under Art. 28(4) GDPR. If a Sub-processor fails to fulfil its obligations, the Processor is liable to the Controller for the performance of the Sub-processor's obligations to the extent set out in Art. 28(4) GDPR.

7.4 Specifics of Sub-processors (Transparent Disclosure)

7.4.1 Twilio Inc.

a. Role: telecommunications Subcontractor for incoming CZ numbers, PSTN connectivity.

b. Location of processing: USA (default storage); for Regional Twilio, Ireland (IE1) is available — the Processor selects Regional Twilio Ireland for Customer Content where available. Customer Account Data (incl. KYC subscriber records) remains in the USA.

c. Transfer mechanism: EU-U.S. Data Privacy Framework + Twilio BCR + EU SCC (cascading regime under Twilio DPA Schedule 3 § 2.1).

d. Dual role: Twilio is an independent controller of Communications Usage Data (CDR metadata) under Twilio DPA § 3.3 and, under Twilio DPA § 3.4, reserves a partial controller role over Customer Content for the purposes of product development, business analytics, and training AI/ML models for fraud detection and security. The telecommunications providers (local carriers) used by Twilio are independent controllers for call metadata.

e. Recording on Twilio's side: disabled (the Twilio-side recording feature is OFF); recording takes place at the level of the Subcontractor VAPI.

f. Subscriber Records (KYC): retained for the period of the statutory obligation.

SMS scope (outbound transactional SMS):

g. Extension of the Subcontractor's role: Twilio now provides, in addition to incoming voice, the transmission of outbound transactional SMS. Twilio acts as an electronic communications service provider and as a Sub-processor under Art. 28 of Regulation (EU) 2016/679.

h. Status of the parties for SMS: the Controller (Client) = the controller and sender of the message (in the legal sense); the Processor (Provider) = the processor; Twilio = the Sub-processor. Notwithstanding that Twilio's terms and conditions regard the account holder (the Processor) as the "Customer," the sender of the message (in the legal sense) is the Controller; this role is evidenced by the Sender ID bearing the name of the Controller's place of business, identification of the Controller in the body of the message, and the registration record held by Twilio.

i. Retention of SMS data: Twilio's Message Logs have a default retention period of 400 days (13 months); the Processor sets a shorter retention period. Minimum retention period for PII (Minimum Time Limit): the body of the message for at least 30 days, the telephone number for at least 120 days. The Processor will consider and apply Message Redaction (not storing the telephone number and the body of the message) as a minimisation measure under Art. 25 and Art. 5(1)(c) of Regulation (EU) 2016/679. After account termination, Twilio deletes Customer Content within 30 days and Customer Account Data within approximately 60 days; Twilio reserves a longer retention period for legal, security, and anti-fraud purposes.

j. Transfers to third countries (SMS): SMS data may by default be processed by Twilio in the USA; the transfer is secured by Twilio's DPA, standard contractual clauses under Commission Implementing Decision (EU) 2021/914, and the EU-U.S. Data Privacy Framework. The Processor may select Regional Twilio (Ireland) for data residency in the EU.

k. Incident notification (SMS): Twilio notifies a security incident "without undue delay" without a fixed numerical deadline; the Processor will notify the Controller of a breach within 48 hours from the moment it becomes aware of it with reasonable certainty, regardless of the source of the discovery (aligned with Art. 33(2) of Regulation (EU) 2016/679 and with the anchor used for the other Sub-processors — Art. 13a.6 of the GTC).

7.4.2 VAPI Inc.

a. Role: orchestration layer — manages the dialogue in real time (speech recognition, language model via BYOK, speech synthesis), call recording, transcript, and structured logs.

b. Location of processing: USA (AWS); within the Pay-as-you-go tier, without an account-wide choice of EU region. VAPI's documented BYOK STT list (Deepgram, Gladia, AssemblyAI, Speechmatics, Google, Azure) does not explicitly name either the previous OpenAI gpt-4o-transcribe or the new primary Sub-processor Soniox Inc. (Art. 7.4.3); the Processor therefore treats the integration regime (a BYOK direct sub-processor relationship vs. a VAPI-managed sub-processor) as an internally unresolved matter and applies a conservative approach to its disclosure, analogous to item i. (Anthropic, PBC) — it lists Soniox as its direct Sub-processor until VAPI expressly confirms otherwise.

c. Transfer mechanism: Standard Contractual Clauses (modules 2/3) with the choice of Irish law, the EU-U.S. Data Privacy Framework, a documented transfer impact assessment (TIA) (available on request after concluding an NDA via SafeBase).

d. DPA: VAPI provides a separate DPA under Art. 28 GDPR only to enterprise customers; the Processor does not have one. The contractual framework relies on VAPI's general Terms of Service. The Controller acknowledges this fact (Art. 2.10 GTC) and undertakes to inform Users in accordance with Art. 13/14 GDPR.

e. Call recording: permanently active in the VAPI cloud, with no client-side means of disabling it (the parameters recordingEnabled, loggingEnabled, pcapEnabled, transcriptPlan.enabled are ON by default).

f. AI model training: VAPI expressly excludes model training only for data from the Google Workspace API; for voice recordings and transcripts, the Processor relies on VAPI's general terms of service (ToS Art. 4.2). The Processor acknowledges, and discloses to the Controller, that VAPI may, under its terms, use data to train its orchestration models; the Processor has applied the available opt-out options.

g. Retention: 14 days for calls, 30 days for chats (Pay-as-you-go); system logs and usage metrics remain on VAPI's infrastructure with no option to redirect them to custom storage.

h. Fallback speech transcription: see Art. 7.4.7 (Google LLC).

i. Sub-sub-processor Anthropic, PBC: VAPI names Anthropic, PBC (USA) as a sub-sub-processor in its PCI AOC documentation. The specific data flow through Anthropic cannot be unambiguously verified in the Pay-as-you-go regime; the Processor therefore lists Anthropic in the list of Sub-processors out of caution. Transfer mechanism: SCC module 3 + the EU-U.S. Data Privacy Framework (Anthropic holds an active certification).

7.4.3 Soniox Inc. — Primary Speech-to-Text

a. Role: Speech-to-Text (recognition of speech from incoming call audio) via API access from the VAPI configuration; replaces the previous STT function of the Subcontractor OpenAI (see Art. 7.4.4(a)). The integration regime (a direct Sub-processor of the Processor in the BYOK regime, analogous to OpenAI/ElevenLabs, vs. a VAPI-managed sub-processor) is not unambiguously confirmed by VAPI Inc. (see Art. 7.4.2(b)); the Processor conservatively lists Soniox as its direct Sub-processor.

b. Contracting party: Soniox Inc., 1045 Helm Lane, Foster City, CA 94404, USA. In its documentation (SOC 2 report), Soniox also lists a place of business in Ljubljana, Slovenia; this fact does not establish a separate EU contracting entity, nor is it mentioned as such in the self-served DPA of Soniox.

c. Location of processing: EU region (endpoint api.eu.soniox.com) — the Processor has internally verified the activation for its account and VAPI's routing to this endpoint. Without active EU activation, the default location of audio processing is the USA (endpoint api.soniox.com); the Processor undertakes to periodically re-verify this state. System data (account, usage statistics, and billing data) is expressly excluded from the region selection and may be processed outside the EU region (self-served DPA § 6/7).

d. Transfer mechanism: Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, incorporated into the self-served DPA by reference. The self-served DPA is structured in terms of Module 2 (Controller-to-Processor) and does not expressly name Module 3 (Processor-to-Processor), although the relationship between the Processor (as processor towards the Controller) and Soniox (as its Sub-processor) factually corresponds to Module 3; the Processor records this inconsistency and the Controller acknowledges it. The EU-U.S. Data Privacy Framework is not mentioned in Soniox's self-served DPA; transfers of system/billing data outside the EU region rely exclusively on the SCC. The governing law of the self-served DPA (derived from the Terms of Service) is the law of the State of California, USA, with the exclusive jurisdiction of the courts of San Francisco, California — this choice relates exclusively to the relationship between the Processor and Soniox, not to the Agreement between the Parties (Art. 14 of the GTC, Art. 15.2 of this DPA).

e. Retention: no retention of audio or the text transcript by default ("does not store audio or text by default unless explicitly configured"); this is ongoing in-memory processing without persistent storage for the duration of transcription. The self-served DPA does not state an express exception for abuse prevention or security review; the Processor records this fact as open and does not base any claim of absolute zero retention on it. The Processor configures the Service exclusively in real-time streaming mode without enabling asynchronous/batch storage on Soniox's side.

f. Sub-processors of Soniox: AWS, Google Cloud Platform, Oracle Cloud Infrastructure, and Cloudflare (infrastructure); Stripe, Google Workspace, and Vanta (operational). Soniox's list states the location in summary form ("United States, European Union, Japan, other AWS/GCP/OCI regions"; Cloudflare "Global") without an exhaustive list of countries; the exact scope of the physical processing route (in particular for the Cloudflare edge network) cannot be verified from the available documentation. The self-served DPA contains no mechanism for prior notification of a change of sub-processor nor a right of objection; the current list is available only in the Soniox Console.

g. Model training: contractually excluded without an opt-in exception ("Soniox does not use Customer Content to train, fine-tune, evaluate, benchmark, or improve Soniox models or services") across the Terms of Service, Privacy Policy, and self-served DPA; only content-free, aggregated, and de-identified operational telemetry may be processed.

h. Limitation of Soniox's liability: the greater of an amount equal to the Processor's fees for 12 months, or USD 100 (Terms of Service Art. 29); with no uncapped exception for a personal data breach.

i. Security incident notification: the self-served DPA provides for notification "without undue delay" without a numerical deadline; see Art. 10.3 of this DPA.

j. Certification: SOC 2 Type II (unqualified opinion, period 21 January 2025 – 10 February 2026, scope exclusively the Security TSC, auditor Prescient Assurance LLC) and ISO/IEC 27001:2022 (valid until 22 February 2029, certifying body Prescient Security LLC), both covering AWS/GCP/OCI infrastructure.

k. Healthcare: Soniox offers separate HIPAA compliance documentation; given the exclusion of healthcare from the Service (Art. 4 of the GTC), this documentation is not relevant to the Processor and no claim towards the Controller is based on it.

7.4.4 OpenAI Ireland Ltd. / OpenAI OpCo, LLC (Large Language Model)

a. Role: Large Language Model (the GPT-5.1 model) for dialogue orchestration via API access from the VAPI BYOK configuration. Since the deployment of the Sub-processor Soniox (Art. 7.4.3), OpenAI no longer performs Speech-to-Text or processes the audio recording of the call; the input to OpenAI is exclusively the text transcript produced by the Sub-processor Soniox, containing Users' personal data (in particular names and telephone numbers disclosed during the call).

b. Contracting party: OpenAI Ireland Ltd. (EU contracting party); the data importer under the SCC is OpenAI OpCo, LLC (USA).

c. Location of processing: USA (default); the EU region for the Pay-as-you-go tier is not guaranteed without an Enterprise upgrade (see Art. 3.6(c) of the GTC).

d. Transfer mechanism: Standard Contractual Clauses (modules 2/3) with the choice of English law (Clause 17 Option 1), supervisory authority the ICO (Information Commissioner's Office, UK).

e. Dual role: OpenAI is a processor under DPA v.010126, but within the scope of abuse prevention (Business TOS Art. 4.2 and Art. 11.3) reserves an independent controller role for flagged content (Customer Content) (currently: flagged text content of the transcript); this role is disclosed to the Controller.

f. Retention: by default 30 days for API logs (Chat Completions API — the text input/output of the transcript and the model's response; the Audio API is no longer used since the deployment of Soniox); the Zero Data Retention (ZDR) Addendum is not agreed (it requires an Enterprise upgrade, which the Processor has not chosen). The Controller acknowledges this fact (Art. 2.10 GTC).

g. Sub-processor TaskUs, LLC (Philippines): content moderation of flagged text content; transfer on the basis of SCC module 3. The Philippines is neither a country with an adequate level of protection under Art. 45 GDPR nor a DPF member. The Controller acknowledges this fact (Art. 2.10 GTC) and undertakes to inform Users.

h. Model training: default exclusion from training (opt-out) (Business TOS Art. 4.2 — "OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use").

i. Prohibition on sensitive data: OpenAI DPA Schedule 1.5 and OpenAI Business TOS Art. 5.4 expressly prohibit the processing of sensitive personal data, including Protected Health Information, without a separate agreement; the Controller undertakes (in accordance with the prohibited uses under Art. 4 of the GTC) not to send such content.

j. Residual exposure: the transition of the Speech-to-Text function to the Sub-processor Soniox (Art. 7.4.3) does not affect OpenAI's obligations described in this article; the text transcript containing Users' personal data remains subject to OpenAI's 30-day retention and to transfer to the USA without an agreed zero data retention regime.

7.4.5 ElevenLabs Inc. (United States) / Eleven Labs Poland sp. z o.o. (EEA controller for Voice Data)

a. Role: Text-to-Speech (TTS); stock voices from the ElevenLabs Voice Library on the Processor's Starter plan, integrated in BYOK mode (the Processor's API key managed within the environment of the Subcontractor VAPI); ElevenLabs is a direct Sub-processor of the Processor, not a sub-processor of VAPI.

b. Voice cloning: the Processor does not use voice cloning (its own User Voice Models, custom voice training) or other biometric functionality; it uses exclusively voices from the Voice Library. The particular voice used is technically "cloned" from the Voice Library, but the commercial use of stock voices relies on ElevenLabs' general terms of service (ToS) and Acceptable Use Policy (the Voice Library Agreement does not contain a separate per-voice commercial licence), and consent from the voice talent is handled by ElevenLabs. For Users, this constitutes synthetic speech, not biometric data.

c. Location of processing: USA + Netherlands + Singapore (storage); the EEA controller for Voice Data, to the extent it arises, is Eleven Labs Poland sp. z o.o.

d. Transfer mechanism: the EU-U.S. Data Privacy Framework (only for the Eleven Labs Inc. entity in the USA), SCC 2021/914 (DPA § 11.1 and § 11.2 — Irish law + Courts of Ireland), the UK Addendum.

e. OEM Terms / B2B2C: the Processor operates in a B2B2C configuration (Making-Available of the Service's outputs to the Controller's Users). Making the outputs of ElevenLabs available to third parties (B2B2C Making-Available) is not licensed under the Starter or Business plan and would require a separate OEM/Enterprise Order Form. This residual licensing risk is borne by the Processor; its potential impact is the suspension or cancellation of the Processor's account with ElevenLabs and the loss of prepaid credit, not a sanction against the Controller. This risk has no effect on the processing of Users' personal data or on the Processor's obligations under this DPA.

f. Model training: the Processor has activated and maintains an opt-out from training on customer data with the Subcontractor ElevenLabs; ElevenLabs does not use customer data to train its models.

g. Retention of Voice Data / biometric data: up to 3 years (Privacy Policy § 6 and § 12); of no practical impact for the Processor, since voice cloning is OUT.

h. Moderation team outside Data Residency: ElevenLabs reserves the right to access Customer Content from various locations for content moderation purposes (DPA § 13.1.3); the Controller acknowledges this.

7.4.6 INTERNET CZ, a.s. (Forpsi) — Hosting Sub-processor

a. Role: VPS hosting (VPS Optimal) + PostgreSQL database, self-managed by the Processor.

b. Location of processing: European Union (the Privacy Policy states "EU"; the specific data centre for VPS Optimal has not been confirmed to the Processor; for housing within the Forpsi group, the Ktiš data centre in the Czech Republic is documented).

c. DPA under Art. 28 GDPR: within its terms and conditions and Privacy Policy, Forpsi does not provide a separate DPA under Art. 28 GDPR; it acts as an independent controller in relation to the personal data of the Processor as its customer. Within its contractual documentation towards the Controller, the Processor designates it as a Sub-processor and discloses to the Controller the technical measures that Forpsi in fact provides (LUKS, network isolation, contractual confidentiality under Art. XVIII.1 of Forpsi's terms and conditions).

d. Forpsi's subprocessor list: the Privacy Policy contains only a general mention of the "Aruba S.p.A. group" and external network providers; a specific list is not publicly available.

e. Deletion period after termination: Forpsi's terms and conditions for VPS Optimal do not state a specific period; for DNS hosting it is 30 days (DNS Art. III.2). After termination of the Agreement, the Processor performs its own deletion of data from its application layer.

f. Security incident notification: Forpsi's parsed documents do not state a deadline, channel, or scope of information for notification. The Processor relies on its own monitoring and, in the event of an incident, complies with the notification obligation under Art. 10 of this DPA.

g. Cap on Forpsi's liability: CZK 30,000 under Forpsi's terms and conditions Art. XVI.2, exclusion of liability for data loss under Art. X.15 and X.17.

h. Backup: for VPS Optimal, Forpsi expressly excludes liability for backups (terms and conditions Art. XI.1; server hosting Art. III.2–4); the Processor does not operate backups beyond the default operational behaviour (Art. 2.10 GTC).

i. Confidentiality and data analysis: under its terms and conditions (Art. X.4), Forpsi is entitled to analyse hosting service data even without the customer's consent for the purposes of ensuring the proper provision of the service; the confidentiality of Forpsi's employees under Art. XVIII.1 remains preserved.

7.4.7 Google LLC — DUAL ROLE Sub-processor

Google LLC acts in the Service in two separate roles:

(a) Google Calendar API (OAuth integration for calendar functions):

  • Purpose: reading free/busy times (availability queries on the Client's primary calendar) and writing appointments;

  • OAuth scope: https://www.googleapis.com/auth/calendar (full read and write — a sensitive scope) + openid + email;

  • Status depending on the type of the Client's account:

  • Workspace client (paid business Google subscription): Google acts as a direct Sub-processor of the Client under a separate Google Cloud DPA concluded between the Client and Google; the Processor is not a party to this relationship and Google does not constitute a Sub-processor of the Processor. The Processor accesses the Google Calendar API only through the Client's OAuth delegation as its technical agent. The Google Cloud DPA + SCC modules 2/3 + the EU-U.S. Data Privacy Framework apply between the Client and Google;

  • Gmail client (personal free account): Google acts as an independent controller towards both Users and the Client; the Client bears responsibility for informing Users and ensuring the legal basis for their consent within the meaning of Art. 13/14 GDPR;

  • The Controller declares the account type in the application when connecting the calendar (Art. 13a.1 GTC); a change of account type is made by a new declaration in the application;

  • Storage of tokens: the Processor stores OAuth tokens in encrypted form (the Fernet algorithm, AES-128-CBC + HMAC-SHA256); the Google refresh token structurally does not rotate, only the access token is renewed;

  • Revocation: when the integration is disconnected by the Client, the Processor immediately and irreversibly deletes the tokens and metadata from its database; revocation of the token with Google is carried out using reasonable efforts. If revocation with Google fails (e.g., the token has expired), the Processor deletes the record from its database and logs the failure; the token may formally survive at Google until its technical expiry (the Controller acknowledges this fact);

  • Assistant ↔ calendar mapping: the assignment of an assistant to a calendar is verified from the assistant identifier in the data from VAPI and is protected by tamper-resistant verification; its security depends on the confidentiality of the receiving interface's secret key (webhook secret) (Art. 2.10 GTC);

  • Retention of data at Google after termination of the Agreement: up to 30 days of recovery + 180 days for deletion = up to 210 days in total (Google Cloud DPA § 6.1 and § 6.2); Google's encrypted backups may retain data for up to 6 months after the Client deletes its Google account.

(b) Google Gemini 2.0 Flash (Czech) — fallback Speech-to-Text:

  • Purpose: fallback transcription at the moment of unavailability of the primary speech recognition Sub-processor, now Soniox Inc. (Art. 7.4.3, formerly OpenAI gpt-4o-transcribe); activation is controlled at the level of the Subcontractor VAPI Inc.;

  • Location of processing: USA;

  • Transfer mechanism: SCC, or DPF where applicable (scope per the Google API ToS);

  • Model training: for the Google Gemini API, no equivalent written opt-out is agreed such as the Processor guarantees for Soniox and OpenAI BYOK; the Controller acknowledges this fact (Art. 2.10 GTC);

  • Open question of fallback architecture: following the deployment of Soniox as the primary STT, the Processor is internally reassessing whether Google Gemini 2.0 Flash will remain the sole fallback element, whether the previous OpenAI STT will also be engaged as a secondary fallback, or whether Soniox will offer its own internal fallback. Pending this decision, the configuration described (Google Gemini 2.0 Flash as the sole fallback) remains unchanged;

  • Change of fallback Sub-processor: any future change of the default fallback speech recognition Sub-processor (e.g., replacing Google Gemini with another Sub-processor available in the VAPI orchestration layer, or adding a further fallback Sub-processor) is covered by the standard subprocessor change notification clause under Art. 7.1 of this DPA.

7.4.8 Microsoft — DUAL ROLE Sub-processor / Independent Controller

a) Business accounts (Microsoft 365 work/school) — Microsoft as Sub-processor: contracting entity Microsoft Ireland Operations Limited (Dublin); standard contractual clauses under Commission Implementing Decision (EU) 2021/914 (modules 2 and 3), the UK IDTA for any transfers from the United Kingdom; the EU Data Boundary (with an exception for Entra ID authentication data); a retention period of 180 days after the end of processing; an undertaking not to use customer data to train generative models; a 6-month (customer data) / 30-day (other personal data) notice period for a change of sub-processor, which the Processor forwards to the Controller within 5/3 days. For business accounts too, Microsoft processes a limited scope of operational data (invoicing, account management, internal and financial reporting) as an independent controller, with express minimisation and without profiling or advertising; this role is separate from the sub-processor role for customer data.

b) Personal accounts (Outlook.com) — Microsoft as an independent controller: on the basis of the Microsoft Services Agreement; the availability of free/busy data is provided via the calendarView method (Art. 13a.3 of the GTC), without the EU Data Boundary, relying only on the Data Privacy Framework; the governing law of the relationship is Irish law.

Revocation of access authorisation is carried out using reasonable efforts; failures are logged. The refresh token is replaced with a new one upon each use, and Microsoft does not revoke the previous token; the Processor securely removes the previous token. The Processor is not liable for any persistence of the token on Microsoft's side until the end of its validity.

7.5 Controller's Right to the List of Sub-processors

The current list of Sub-processors is available in Annex No. 1 to this DPA. The Processor updates it upon every change and notifies the Controller of the change in accordance with Art. 7.1.

7.6 Telecommunications Operators (Local Carriers)

Local telecommunications operators that provide the technical connectivity of the incoming call up to the Subcontractor Twilio Inc. are not Sub-processors within the meaning of the Twilio DPA (Twilio DPA § 1 and the Subprocessor List); in relation to traffic and location data (CDR), they act as independent controllers. The Controller communicates this fact to Users in accordance with Art. 14 GDPR.

8. International Transfers

8.1 Transfer Mechanism

The Controller acknowledges that the provision of the Service requires the transfer of personal data to third countries, in particular to the USA, and potentially to the United Kingdom, the Philippines, Singapore, India, Mexico, Israel, and other countries within the chain of Sub-processors. The transfer is secured on the basis of:

a. Standard contractual clauses under Commission Implementing Decision (EU) 2021/914, modules 2 (Controller-to-Processor) and 3 (Processor-to-Processor / Processor-to-Sub-processor) — for each relevant transfer between the Processor and a Sub-processor, or between a Sub-processor and its further sub-processors;

b. the EU-U.S. Data Privacy Framework for Sub-processors holding a valid certification (Twilio Inc., OpenAI OpCo LLC, ElevenLabs Inc. — for the US entity, Google LLC, VAPI Inc.);

c. the UK Addendum for the transfer of personal data of data subjects from the United Kingdom;

d. Twilio BCR (Binding Corporate Rules) as a secondary mechanism for the Twilio chain (Twilio DPA Schedule 3 § 2.1 cascading regime DPF → BCR → SCC);

e. supplementary technical and organisational measures corresponding to the recommendations of the European Data Protection Board (EDPB Recommendations 01/2020).

8.2 Data Privacy Framework and Fallback Mechanism

Where relevant, the transfer to third countries (the USA) relies on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection). In the event the EU-U.S. Data Privacy Framework is invalidated by a decision of the Court of Justice of the European Union, the transfer will automatically rely exclusively on Standard Contractual Clauses under Art. 8.1(a), without the need to conclude an amendment to this DPA. The Processor will publish an update of the subprocessor documentation on its website and will notify the Controller in accordance with Art. 7.1.

8.3 Transfer Impact Assessment (TIA)

For relevant transfers, the Processor performs (or adopts from the Sub-processors) a transfer impact assessment (TIA). The Sub-processors' TIAs are made available to the Controller on request through the relevant Sub-processors' Trust Center / Trust Portal (typically after concluding an NDA).

8.4 Transfer outside a Country with an Adequate Level of Protection

For transfers to countries without an adequate level of protection (in particular the Philippines — TaskUs LLC for OpenAI content moderation; India, Mexico, Israel — Google's sub-providers), SCC module 3 (onward transfer) applies in accordance with the Sub-processors' documentation. The Controller acknowledges this fact (Art. 3.6(f) of the GTC; express confirmation under Art. 2.10 GTC) and undertakes to inform Users.

8.5 SCC Governing Law

Within the meaning of Clause 17 of the SCC, the Parties choose the law of Ireland as the governing law of the SCC between the Controller and the Processor; disputes will be resolved before the courts of Ireland (Clause 18(b)) — this provision relates exclusively to the SCC framework. The principal contractual relationship between the Parties is governed by Czech law (Art. 14 of the GTC).

8.6 Microsoft — Transfers to Third Countries

For business accounts, the transfer relies on the EU Data Boundary and standard contractual clauses under Commission Implementing Decision (EU) 2021/914 (module 3 for onward transfers to sub-processors); for personal accounts, on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795, the validity of which was confirmed by the General Court in Case T-553/23). Microsoft's list of sub-processors includes entities in countries without an adequacy decision; these transfers rely on standard contractual clauses (module 3).

9. Data Subjects' Rights — Processor's Cooperation

9.1 The Processor assists the Controller, by appropriate technical and organisational measures, so that the Controller can fulfil its obligation to respond to requests from data subjects exercising rights under Art. 15 to 22 GDPR (the right of access, rectification, erasure, restriction of processing, portability, objection, and the right not to be subject to automated decision-making).

9.2 If the Processor receives a request directly from a data subject, it will forward the request to the Controller without undue delay and will not itself respond to it, unless obliged to do so by law.

9.3 The Processor provides the Controller with cooperation in particular by:

a. locating a particular User's records within its application database by telephone number or call identifier;

b. exporting the User's data in a commonly used structured format (JSON);

c. deleting the User's data from its application database and requesting deletion from the relevant Sub-processors to the extent of their contractual obligations.

9.4 The Controller acknowledges that the deletion of data across Sub-processors has practical limitations arising from the architecture of the Service:

a. recordings and transcripts at the level of VAPI Inc. are subject to the retention under Art. 7.4.2;

b. audio processed by the Sub-processor Soniox is not retained by default (Art. 7.4.3(e)), subject to the open question of an exception for abuse prevention;

c. the unredacted text transcript at OpenAI is subject to 30-day retention (Art. 7.4.4);

d. metadata at the level of Twilio Inc. may be retained for the period of a statutory obligation (Subscriber Records, CDR);

e. local telecommunications operators are independent controllers and the Processor has no contractual leverage over them.

9.5 The Processor is obliged to fulfil a data subject's request to the extent reasonably technically possible and to the extent it has technical access to the User's data. For actions requiring extraordinary effort beyond ordinary operational activity, the Processor is entitled to charge the Controller reasonable reimbursement of costs.

10. Notification of Personal Data Breach

10.1 The Processor will notify the Controller of a personal data breach (Security Incident) without undue delay, and in any event no later than within 48 hours from the moment it demonstrably became aware of the breach, whether through its own discovery or on the basis of a Sub-processor's notification.

10.2 The notification contains information to the extent necessary for the Controller to fulfil its obligation under Art. 33(3) GDPR towards the supervisory authority, in particular:

a. a description of the nature of the breach;

b. the categories and approximate number of data subjects and records concerned;

c. the likely consequences of the breach;

d. the measures taken or proposed to address the breach and mitigate its effects;

e. a contact point for further information.

If the Processor obtains the information referred to progressively, it will provide it to the Controller in successive notifications.

10.3 Dependency on Sub-processors.

a) The Parties acknowledge that the Processor's ability to meet the deadline under Art. 10.1 depends on the speed of notification by the Sub-processors, who typically undertake in their contractual documents only to notify "without undue delay" without a specific hourly deadline (e.g., Twilio DPA § 10.3(a), Soniox's self-served DPA (no numerical deadline), OpenAI DPA § 2.7, Google Cloud DPA § 7.2.1, ElevenLabs DPA § 8.1, VAPI SafeBase Schedule 2 (a fixed cap of 72 hours from confirmation of the incident), Microsoft DPA "Security Incident Notification" — "promptly and without undue delay" without a numerical hourly deadline; the 72-hour period is exclusively the controller's obligation towards the supervisory authority under Art. 33 GDPR, not an undertaking by Microsoft; Forpsi's terms and conditions contain no clause).

b) In relation to data processed in the Microsoft environment: Microsoft notifies an incident "without undue delay" without a fixed numerical deadline; the Processor will notify the Controller of a breach within 48 hours from the moment it becomes aware of it with reasonable certainty, regardless of the source of the discovery (Art. 13a.6 of the GTC).

c) The Controller undertakes to forward to the Processor, promptly and no later than within 12 hours of receipt, any incident notification received from Microsoft.

d) The Processor is not liable for a delay in notification caused by a Sub-processor's delay, provided it acted in good faith and passed the information to the Controller without undue delay after receiving it.

10.4 The notification is sent to the Controller's e-mail address stated in the customer account (Art. 16.3 GTC).

10.5 The Processor maintains its own operational monitoring (tracking Sub-processors' incident pages and security notices) and, on a reasonable periodic basis, verifies that the notification channels are functional.

11. DPIA and Prior Consultation — Cooperation

11.1 The Processor assists the Controller in carrying out a data protection impact assessment (DPIA) under Art. 35 GDPR, where such an assessment is required.

11.2 The Processor will provide the Controller with the information necessary to carry out the DPIA, in particular:

a. a description of the nature, scope, context, and purposes of the processing carried out by the Processor and the Sub-processors;

b. a description of the technical and organisational measures adopted to secure the processing (Art. 6);

c. available information on transfers to third countries (Art. 8);

d. available information on the risks arising from processing by an AI system;

e. a sample DPIA structure for an AI voice assistant within the agreed use case (booking), which the Controller will adapt to its specific situation.

11.3 The Processor further assists the Controller in a prior consultation with the supervisory authority (Art. 36 GDPR), where required.

11.4 If the Service is classified under the AI Act as a high-risk artificial intelligence system, the Processor will assist the Controller in carrying out a fundamental rights impact assessment (FRIA) under Art. 27 of the AI Act.

12. Audit

12.1 The Processor will demonstrate compliance with its obligations under this DPA primarily by submitting:

a. valid certificates and audit reports of the Sub-processors (in particular SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018);

b. completed standardised security questionnaires;

c. its own technical and organisational documentation corresponding to Art. 6 of this DPA.

12.2 The Controller is entitled to carry out an on-site audit at the level of the Processor:

a. no more than once per calendar year;

b. with at least 30 days' advance notice;

c. at its own expense (except for an audit that reveals a material breach of this DPA by the Processor);

d. during the Processor's normal business hours;

e. after concluding a separate non-disclosure agreement (NDA).

12.3 An extraordinary audit beyond Art. 12.2 is possible following a confirmed security incident affecting the Controller's personal data.

12.4 The Controller agrees that the audit of Sub-processors is carried out through:

a. certifications and audit reports of the Sub-processors, which the Processor makes available to it (typically under NDA);

b. publicly available Trust Center / Compliance Resource Center information;

c. not through physical audits by the Controller at the level of the Sub-processor (Twilio DPA § 11.2(d)(e), OpenAI DPA, Google Cloud DPA § 7.5).

12.5 A right of audit may be exercised against the Processor by the Sub-processors (in particular ElevenLabs OEM Terms § 3.C), at most once a year with 10 business days' advance notice, and for the duration of the agreement and 3 years after its termination. The Controller will provide the Processor with cooperation in facilitating such an audit to the extent it may concern the personal data of the Controller's Users.

13. Erasure or Return of Data after Termination

13.1 After termination of the Agreement, the Processor will, on the Controller's instruction, delete or return the Controller's Users' personal data to the Controller in the format under Art. 9.3(b). The Controller will give its instruction no later than within 30 days after the end of the Agreement.

13.2 Period for data export at the Controller's request: 30 days from the termination of the Agreement (Art. 9.4 of the GTC).

13.3 After the expiry of 30 days (or after prior deletion on the Controller's instruction), the Processor will delete the Controller's data from its active systems and request the Sub-processors to delete data to the extent of their contractual obligations.

13.4 The actual deletion periods across Sub-processors, which the Controller acknowledges:

a) Twilio: 30 days for export and 60 days' retention of backups, up to 90 days in total;

b) OpenAI: 30 days from termination, with exceptions for mandatory retention for legal proceedings and abuse detection purposes;

c) Google Calendar: up to 30 days of recovery and 180 days for deletion, up to 210 days in total (Google Cloud DPA § 6.1 and § 6.2); encrypted backups may retain data for up to 6 months after termination of the Google account;

d) ElevenLabs (Self-Serve plan): no contractual deletion obligation; the Processor performs ongoing deletion via the API;

e) VAPI: 14 days (calls under the Pay-as-you-go regime) / 30 days (chats); system logs remain on VAPI's infrastructure;

f) Forpsi: no specific contractual period for the VPS; the Processor requests deletion after termination;

g) Google and Microsoft OAuth tokens: revocation is carried out using reasonable efforts; a token may formally survive at the provider until its technical expiry;

h) Microsoft 365 (work/school account): up to 180 days (90 days of an account with limited functionality for extraction and 90 days for deletion);

i) Microsoft (personal Outlook.com account): data is managed by Microsoft as an independent controller under the Microsoft Privacy Statement; after 2 years of account inactivity, Microsoft closes the account and deletes the data.

13.5 The Processor may retain part of the personal data after the end of the Agreement, where required by European Union or Member State law (in particular § 88a ZEK, tax legislation, Act No. 563/1991 Sb., on Accounting). In such a case, the Processor will restrict access to this data and use it exclusively for the purpose for which the law permits its retention.

13.6 Upon the Controller's written request delivered no later than 60 days after the end of the Agreement, the Processor will issue a confirmation of the deletion of data from its systems.

14. Liability and Sanctions

14.1 The Parties' contractual liability under this DPA is limited in accordance with Art. 6 of the GTC. The limitation of liability does not apply to the exceptions under Art. 6.3 of the GTC (intent, gross negligence, fraud, infringement of intellectual property rights, breach of the DPA, breach of confidentiality).

14.2 This is without prejudice to claims by data subjects against the controller and the processor arising directly from Art. 82 GDPR. The Processor and the Controller are each liable to the other for damage caused to a data subject by a breach of obligations under this DPA to the extent set out in Art. 82 GDPR.

14.3 The Controller (Client) shall fully indemnify the Processor, in accordance with Art. 10 of the GTC (indemnification), against third-party claims arising from a breach of its obligations as controller, in particular the obligation to inform Users and to ensure the legal basis for processing.

15. Final Provisions

15.1 Relationship to the GTC and the Agreement. This DPA forms an integral part of the Agreement and the GTC. In the event of a conflict between the DPA and another part of the contractual documentation, this DPA prevails on matters of personal data protection.

15.2 Governing law and jurisdiction. This DPA is governed by Czech law; for disputes, the general court having local jurisdiction over the Processor under Art. 14 of the GTC has jurisdiction. For the Standard Contractual Clauses, the choice of governing law and forum under Art. 8.5 applies.

15.3 Term. This DPA is concluded together with the Agreement (Art. 2a.2 of the GTC) and takes effect together with it (Art. 2.5 of the GTC). It lasts for the duration of the Agreement, extended by the period necessary to fulfil the obligations under Art. 13. This version of the DPA is effective as of 20 July 2026 and supersedes previous versions; for Agreements concluded before that date it applies in accordance with Art. 15.4.

15.4 Amendment of the DPA. This DPA may be amended in accordance with the rules of Art. 8.4 of the GTC. The reflection of changes in the Sub-processors' contractual terms (in particular changes to the SCC under Commission Implementing Decision (EU) 2021/914 or its successor) is considered a change compelled by law.

15.5 Annexes. The following form an integral part of this DPA:

  • Annex No. 1 (DPA) — List of Sub-processors (with location, role, transfer mechanism)

  • Annex No. 2 (DPA) — Technical and Organisational Measures (TOM) — details of the Processor's TOM and a summary of the Sub-processors' TOM

  • Annex No. 3 (DPA) — Description of processing under Art. 28(3) GDPR (recap of Art. 2 of this DPA + onboarding data)

Annex No. 1 (DPA) — List of Sub-processors

Sub-processorRoleLocation of ProcessingTransfer MechanismStatus
Twilio Inc. (US) / Twilio Ireland Limited (IE — EU contracting party)Telecommunications connectivity, PSTN inbound, CZ numbers; outbound transactional SMS (+420)USA (default) / Ireland (if Regional Twilio); local operators as independent controllersEU SCC modules 2/3 + Twilio BCR + DPF cascading regime (Twilio DPA Schedule 3 § 2.1)active
VAPI Inc.Call orchestration, recording, transcript, BYOK callsUSA (AWS) — no account-wide EU region on PAYGSCC modules 2/3 + DPF + Irish law + TIA (via SafeBase NDA)active; DPA only for Enterprise (conscious acceptance per Art. 2.10 GTC)
Anthropic, PBC (USA) — sub-sub-processor via the VAPI chainPossible sub-sub-processor identified in VAPI's PCI AOC declaration; the specific data flow in the Pay-as-you-go regime cannot be verifiedUSASCC module 3 (onward transfer) + DPFactive; listed out of caution
Soniox Inc. (USA)Speech-to-Text (primary) via the VAPI configuration; the BYOK vs. VAPI-managed integration regime not confirmed by VAPI (listed out of caution)EU region (activation for the account internally verified); system/billing data outside the region selectionSCC under Commission Implementing Decision (EU) 2021/914, the self-served DPA structured as Module 2 (inconsistency with the factual Module 3 recorded); DPF not mentionedactive; no retention of audio/text by default; replaces OpenAI's STT function
OpenAI Ireland Ltd. (EU contracting party) / OpenAI OpCo, LLC (US — data importer)Large Language Model (GPT-5.1) via BYOK from VAPI; since the deployment of Soniox, text input only (transcript), not audioUSA (default); EU region not guaranteed on Pay-as-you-goEU SCC modules 2/3 (Clause 17 Option 1 — English law) + DPFactive; 30-day retention of the unredacted text transcript; zero data retention regime not agreed
TaskUs, LLC (Philippines)Content moderation for OpenAI flagged content (text transcript)PhilippinesSCC module 3 (onward transfer)sub-subprocessor of OpenAI; conscious acceptance per Art. 2.10 GTC
ElevenLabs Inc. (US) / Eleven Labs Poland sp. z o.o. (PL — EEA controller for Voice Data)Text-to-Speech (Voice Library voice, Starter plan / BYOK)USA + Netherlands + SingaporeSCC 2021/914 + DPF (US entity) + UK Addendum; DPA § 11.2 — Irish lawactive; voice cloning OUT
INTERNET CZ, a.s. (Forpsi)VPS hosting (VPS Optimal) + PostgreSQL DBEU (Privacy Policy states "EU"; the specific data centre for VPS Optimal not stated)EU/EEAactive; no separate DPA under Art. 28 GDPR (conscious acceptance)
Google LLC — DUAL ROLE: (a) Google Calendar API (OAuth) + (b) Google Gemini 2.0 Flash (Czech) as fallback STT(a) Calendar integration (availability queries + write); (b) fallback transcription during an outage of the primary STT (Soniox, formerly OpenAI)USA + sub-providers in India, the Philippines, Mexico, Israel, Sri Lanka (current list: the Google Cloud Sub-processors page — https://cloud.google.com/terms/subprocessors; SCC module 3 for countries without adequacy)(a) Workspace: Google Cloud DPA + SCC modules 2/3 + DPF; Gmail: Privacy Policy + DPF (independent controller); (b) SCC + DPF per the Google API ToS; SCC module 3 for sub-providers in countries without adequacyactive; the fallback STT architecture is being internally reassessed following the deployment of Soniox (see Art. 7.4.7); may change depending on availability at VAPI (an operational change per Art. 7.1)
Microsoft (Microsoft Ireland Operations Limited — EU contracting; Microsoft Corporation) — DUAL STATUS depending on account typeMicrosoft 365 / Outlook.com calendar integration (free/busy availability + write); the 2nd calendar provider, at parity with GoogleEU/EEA under the Microsoft EU Data Boundary (Variant A work/school); globally (Variant B consumer); Microsoft's sub-processors include, among others, the USA, India, Israel, Cyprus, ChinaVariant A (work/school): Microsoft DPA (Art. 28) + 2021 SCC modules 2/3 + UK IDTA + EU Data Boundary + DPF; Microsoft = Sub-processor. Variant B (Outlook.com consumer): Microsoft Services Agreement + Privacy Statement + DPF; Microsoft = independent controller (no DPA/EUDB)active; see Art. 7.4.8; Microsoft's subprocessor notice 6 months / 30 days (AI), forwarded to the Controller within 5 / 3 business days

Standard subprocessor change notification clause: 10 days in advance (Art. 7.1 of this DPA); right of objection 10 days (Art. 7.2).

Publicly available data protection documentation of the Sub-processors may not reflect the current state of their processing; the Controller therefore fulfils the transparency obligation towards Users under Art. 13 and 14 of Regulation (EU) 2016/679 through its own information notice, not by reference to a Sub-processor's documentation.

Annex No. 2 (DPA) — Technical and Organisational Measures (TOM)

A. TOM of the Processor

(Detail per Art. 6 of this DPA — expressly disclosed non-implementations per Art. 6.3.)

AreaMeasure
Encryption in transitTLS 1.3+ by default; TLS 1.2 fallback protocol only for legacy clients
Encryption at rest (OS)LUKS (block-level encryption) on the Forpsi VPS
Application-level encryption (selective)Fernet (AES-128-CBC + HMAC-SHA256) for Google Calendar OAuth tokens
Application-level encryption (transcripts, telephone numbers, audit log)OUT — conscious acceptance under Art. 6.3(a)
Redaction (removal) of personal data before OpenAIOUT — conscious acceptance under Art. 6.3(b)
Backup beyond operational recoveryOUT — conscious acceptance under Art. 6.3(c)
Row-Level Security (PostgreSQL)OUT — backlog; application-level isolation via UUID
KMS / HSM key managementOUT — backlog (internal operational trigger)
SSH authenticationkey-based only, port 2242, fail2ban
Network isolationVPS with no publicly accessible services other than HTTPS + SSH
Security of receiving interfacesHMAC SHA-256 + timing-safe validation
Loggingapplication-level records of operations
Assistant onboardingverification against the Baseline AI Assistant Configuration
STT configuration (Soniox)exclusively real-time streaming; asynchronous/batch storage on the side of the Subcontractor Soniox not enabled (Art. 7.4.3(e))

B. TOM of the Sub-processors (Summary)

Details of the Sub-processors' TOM are the subject of their respective DPAs / Trust Center documentation. Main sources:

Sub-processorCertification / DocumentationAccess for the Controller
Twilio Inc.SOC 2 Type II, ISO 27001/27017/27018, BCR; Twilio DPA Schedule 2NDA via Twilio account
Soniox Inc.SOC 2 Type II (exclusively the Security TSC, unqualified, 21.1.2025–10.2.2026, auditor Prescient Assurance LLC); ISO/IEC 27001:2022 (valid until 22.2.2029, certifying body Prescient Security LLC)Soniox Console (trust portal)
OpenAIAnnex II TOM (DPA v.010126), SOC 2 Type II summaryTrust portal trust.openai.com
ElevenLabsSOC 2 Type II (DPA § 10.1)compliance.elevenlabs.io under NDA
VAPI Inc.SOC 2 Type II, PCI DSS v4.0.1, HIPAA compliance (non-public)SafeBase under NDA
Google LLCISO/IEC 27001, SOC 2, SOC 3Cloud Compliance Resource Center; SOC 3 publicly available
MicrosoftSOC 2 Type 2 (M365 Microservices, Deloitte, unqualified, categories Security/Availability/Processing Integrity/Confidentiality); ISO 27001/27017/27018/27701/42001; M365 Central Services SOC 2 for Exchange Online + Graph (pre-launch request)Microsoft Service Trust Portal under NDA + tenant login
ForpsiNo publicly documented certification (gap)n/a

Annex No. 3 (DPA) — Description of Processing under Art. 28(3) GDPR

ItemContent
Subject matter of processingAI voice assistant for incoming calls (bookings + Knowledge Base)
Duration of processingFor the duration of the Agreement + per Art. 13
Nature of processingCollection, storage, analysis of call content, response synthesis, calendar operation
Speech-to-Text providerSoniox Inc. (primary, Art. 7.4.3); Google LLC — Gemini 2.0 Flash (fallback, Art. 7.4.7(b))
Large Language Model providerOpenAI Ireland Ltd. / OpenAI OpCo, LLC — GPT-5.1 (Art. 7.4.4)
Purposes of processingSee Art. 2.5 of this DPA
Type of personal dataSee Art. 2.4 of this DPA
Categories of data subjectsSee Art. 2.3 of this DPA
Controller's obligations and rightsPer Art. 4 GDPR + the GTC + this DPA

Price List

↑ Back to top

Effective from July 20, 2026 · version v1

Contents

  • Price List for the Service (Annex No. 3)
  • 1. Tariffs (per Assistant and Billing Period)
  • 2. Variable Component (based on actual usage)
  • 3. Invoicing and method of payment
  • 4. Tariff change and cancellation of an Assistant
  • 5. Pilot / demo operation
  • 6. One-off / setup fees
  • 7. Effectiveness and changes

Price List for the Service (Annex No. 3)

This Price List forms an integral part of the Agreement (Art. 1.6 GTC), is published at https://fastlajna.cz/en/compliance#cenik and sets out the prices of the Service pursuant to Art. 2a GTC.

Prices, the included volume, and the Variable Component always relate to a single Assistant (a single Subscription, Art. 1.15 and 1.16 GTC); each additional Assistant is paid for separately.

The Provider is not a value added tax payer; prices are final and the invoice is issued without value added tax (Art. 2a.3 GTC).

1. Tariffs (per Assistant and Billing Period)

TariffFixed Monthly ComponentIncludedPrice per billed minute over the limit
StarterCZK 990/month100 billed call minutesCZK 10 / minute
StandardCZK 3,490/month300 billed call minutesCZK 9 / minute
ProCZK 5,990/month600 billed call minutesCZK 8 / minute
Pay-as-you-goCZK 0/monthno included minutesCZK 11 / minute

Each Subscription, including the Pay-as-you-go tariff, includes the use of one Czech telephone number (+420) of a geographic or mobile type per the offering in the application, assigned to the Assistant (Art. 2.6 and 2a.1 GTC), regardless of the amount of the fixed monthly component. Other countries and number types are not supported.

For the Pay-as-you-go tariff, no fixed monthly component is charged; only the Variable Component based on actual usage under Art. 2 is paid. Upon setting up an Assistant on the Pay-as-you-go tariff, the Payment Card is verified and stored in the PSP's payment interface for the purposes of recurring payments (Art. 2a.2 GTC).

2. Variable Component (based on actual usage)

The Variable Component consists of billed minutes of incoming calls beyond the volume included in the tariff, priced at the "price per billed minute over the limit" of the relevant tariff under Art. 1. For the Pay-as-you-go tariff, which includes no minutes, all billed minutes of incoming calls are billed minutes.

Method of calculating the Variable Component (Art. 2a.2 and 2a.2a GTC):

  • calls of the Assistant initiated within the Billing Period are included in that Billing Period's consumption;

  • the billed duration of each individual call is rounded up to whole minutes (each commenced minute of a call = one full billed minute); only thereafter are the billed minutes of individual calls summed. Example: three calls of 45 seconds each = 3 billed minutes; a call of 61 seconds = 2 billed minutes;

  • minutes beyond the volume included in the tariff = max(0; sum of billed minutes − included minutes); for the Pay-as-you-go tariff the included volume is zero, so all billed minutes are charged;

  • Variable Component = minutes beyond the volume × the price per billed minute over the limit of the relevant tariff;

  • the monetary amount is rounded to two decimal places (hellers) arithmetically, rounding half up (from 0.005 upward).

SMS Add-on Service

The sending of outbound transactional SMS (Art. 13b GTC) is not currently provided. Until this add-on service is put into operation, outbound transactional SMS are not charged; the price for SMS and any related one-off fees (in particular sender registration) will be set out in this Price List upon activation of the service (Art. 13b.11 GTC).

3. Invoicing and method of payment

The Fixed Monthly Component is debited from the Payment Card in advance at the start of each Billing Period of the Subscription; the first fixed component is paid upon setting up the Assistant in the PSP's payment interface (Art. 2.6 GTC). For the Pay-as-you-go tariff, the first and subsequent fixed components are zero and only the Variable Component is paid. The Variable Component for an ended Billing Period is invoiced as a separate line item on the invoice for the immediately following Billing Period; the first invoice issued upon setup does not include the Variable Component. Both are paid automatically on the basis of the Payment Mandate pursuant to Art. 2a.2 GTC through the Payment Service Provider (Stripe, Art. 1.11 GTC). The Billing Period begins on the day the Subscription is set up and need not coincide with the calendar month; the boundaries of the billing period stated on the relevant invoice are decisive (Art. 1.17 GTC). The Client receives an electronic invoice for each debit (Art. 2a.3 GTC). Where payment by card cannot be used, the fallback invoicing regime with a 14-day payment term applies (Art. 2a.6 GTC).

4. Tariff change and cancellation of an Assistant

A tariff change takes effect from the start of the following Billing Period, with no additional payment and no pro-rata credit for the running period (Art. 2a.8 GTC). Upon cancellation of an Assistant, the Variable Component not yet invoiced for the running period is invoiced separately as a stand-alone invoice; the full volume of minutes included in the tariff is used for this calculation, with no pro-rata reduction; the Fixed Component already paid is not refunded (Art. 2a.9 GTC).

5. Pilot / demo operation

Pilot or demo operation is provided only on the basis of an individual written arrangement between the Provider and the Client. Unless pilot operation is expressly agreed to be free of charge, the Service is charged in accordance with this Price List from the setup of the Assistant.

6. One-off / setup fees

Setting up an Assistant (onboarding) is not charged; the setup fee is CZK 0. Any one-off fees associated with the SMS Add-on Service will be set out under Art. 2 upon activation of that service.

7. Effectiveness and changes

Effective from 20 July 2026. Changes to the Price List are governed by Art. 2a.5 and Art. 8.6 GTC (90-day advance notice; 30-day notice where reflecting a change in Subcontractors' prices; an extraordinary change where a change in input costs is demonstrated). If the Client does not agree with a change, the Client may terminate the Agreement without penalty within the period set out in the provisions referred to above.

Privacy

↑ Back to top

Effective from July 20, 2026 · version v1

Contents

  • 1. Controller and contact
  • 2. Personal data we process
  • 3. Purposes and legal bases
  • 4. Recipients and transfers
  • 5. Retention
  • 6. Individual rights
  • 7. Requirement to provide data
  • 8. Automated decision-making
  • 9. Changes to this document

Privacy information

This document explains how Fastlajna s.r.o. processes personal data of website visitors, prospective customers and customers in its role as a data controller.

1. Controller and contact

The controller is Fastlajna s.r.o., registered office at Školská 1736/12, Nové Město, 110 00 Prague 1, Czech Republic, Company ID 29543908, registered with the Municipal Court in Prague under file C 448213. Questions and requests can be sent to hello@fastlajna.cz.

2. Personal data we process

Depending on how the service is used, we may process:

  • identification and contact data, including name, email address and telephone number;

  • company and registration data, including Company ID, Tax ID and business address;

  • customer account data, sign-in method and session identifiers;

  • order, subscription and invoice data and the payment token provided by Stripe; we do not store complete payment card details;

  • communications with customer support and our sales team;

  • technical and security data, including IP address, request time, browser type, request identifier and security events;

  • browser choices described in the Cookie and local storage information.

We primarily process callers' personal data as a processor on behalf of the Client under the DPA. That role and its conditions are described separately in the Data Processing Agreement.

3. Purposes and legal bases

We process personal data to:

  • respond to enquiries and take steps before entering into a contract;

  • create and manage accounts, provide the service, deliver customer support and perform the contract;

  • issue invoices, maintain accounting records and comply with other legal obligations;

  • secure the service, prevent misuse, protect legal claims and perform operational diagnostics on the basis of our legitimate interests;

  • send marketing communications only where an appropriate legal basis exists and an easy opt-out is available.

Where processing is based on consent, it can be withdrawn at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

4. Recipients and transfers

We disclose data only to the extent necessary to provide the service, particularly to infrastructure and email providers, Stripe payment services, Google authentication and calendar integrations, and other suppliers listed in the DPA. Data may be transferred outside the European Economic Area under the conditions described in the GTC and DPA, in particular on the basis of an adequacy decision or Standard Contractual Clauses.

5. Retention

We retain data only for as long as necessary for its purpose:

  • enquiry data for the handling of the commercial relationship and subsequently for as long as needed to evidence communications and protect legal claims;

  • account and service data for the duration of the contractual relationship and subsequently for applicable limitation periods;

  • tax and accounting records for the periods required by law;

  • an authentication session for no more than 7 days after the latest refresh token was issued, unless revoked earlier;

  • technical and security logs for a period proportionate to their purpose and the severity of the recorded event.

Specific data may be retained longer where necessary for legal proceedings, a public authority inspection or compliance with a legal obligation.

6. Individual rights

Subject to the conditions of the GDPR, you have the right of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests and withdrawal of consent. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz.

Send requests to hello@fastlajna.cz. We may reasonably verify the requester's identity before responding.

7. Requirement to provide data

We need data marked as required to handle an enquiry, enter into a contract or provide the relevant feature. Without it, we may be unable to process the request. Other data is optional.

8. Automated decision-making

We do not use automated individual decision-making with legal or similarly significant effects when managing visitors, prospective customers or customer accounts.

9. Changes to this document

The current version is always available on this page. We will notify existing customers of material changes in an appropriate manner.

Cookies

↑ Back to top

Effective from July 20, 2026 · version v1

Contents

  • 1. Operator
  • 2. Technologies we use
  • 3. Storage inventory
  • 4. Consent and essential storage
  • 5. Sign-in cookie security
  • 6. External services
  • 7. Managing and deleting storage
  • 8. Changes to this document

Cookie and local storage information

This document describes technologies that store information on the devices of visitors to the FastLajna website and users of the FastLajna application.

1. Operator

The website and application are operated by Fastlajna s.r.o., registered office at Školská 1736/12, Nové Město, 110 00 Prague 1, Czech Republic, Company ID 29543908, registered with the Municipal Court in Prague under file C 448213. Contact: hello@fastlajna.cz.

2. Technologies we use

We use only technologies that are technically necessary or explicitly requested by the user. We currently do not use analytics, advertising or profiling cookies, and we do not deploy tools that track visitors across websites.

The rules in this document also apply to similar technologies, including browser localStorage and sessionStorage.

3. Storage inventory

NameTechnologyWhere usedPurposeRetention
refresh_tokenHttpOnly cookieFastLajna application after sign-inSecurely maintain the signed-in session and issue a short-lived access tokenup to 7 days; the value is rotated on refresh
app_localelocalStorageFastLajna applicationRemember the language selected by the useruntil changed or browser data is removed
assistant_wizard_calendar_pendingsessionStorageassistant creation wizardReturn to the correct step after connecting Google Calendaruntil the return is completed or the tab is closed
fastlajna_cookie_consentlocalStoragepublic website and applicationStore the current banner choice so the banner is not repeatedly displayeduntil the information version changes or browser data is removed

The short-lived application access token is held only in the open page's memory. It is not persisted in cookies or local storage after the page is closed.

4. Consent and essential storage

We use technically essential storage without consent because it is necessary for security and for features explicitly requested by the user. Selecting “I agree” or “I do not agree” in the current banner does not change the technologies used because we currently use no optional cookies. Only the choice itself is stored.

If we introduce analytics, marketing or other optional technologies later, they will not be activated without prior consent. We will update the version of this document and ask the user to choose again.

5. Sign-in cookie security

The refresh_token cookie is not available to JavaScript (HttpOnly), is transmitted only over HTTPS in production (Secure) and uses SameSite=Lax. It contains a random session identifier, not a password. The server stores only its cryptographic digest and rotates the token when the session is refreshed.

6. External services

Social media links are ordinary links, so their providers cannot place cookies through FastLajna pages before a click. Google OAuth, Google Calendar and the Stripe payment interface are opened only after an explicit user action and may use technologies on their own domains under their own policies.

7. Managing and deleting storage

Cookies and local storage can be removed in browser settings. Removing refresh_token signs the user out. Removing the language preference restores the browser language. Removing the stored banner choice causes the banner to be displayed again.

8. Changes to this document

The current version is always available on this page. If we introduce a new purpose, a new optional technology category or a material change to recipients, we will request a new user choice.

Want to try FastLajna?

Get started
FastLajna

AI phone assistant for Czech small businesses and local operations.

Terms & Documents

  • Terms & Conditions
  • DPA
  • Price List
  • Privacy
  • Cookies

Contact

  • hello@fastlajna.cz
  • +420 728 436 188

© 2026 Fastlajna s.r.o. · Školská 1736/12, Nové Město, 110 00 Praha 1, Czech Republic · Company ID 29543908 · File No. C 448213, Municipal Court in Prague

Your privacy

We use essential technologies for sign-in, security and language settings. We do not currently use optional cookies. If their purpose changes, we will ask you to choose again.

Cookie information