Skip to main content
Sagecom — Smarter Conversations. Better Business.

Data Processing Addendum

Effective / last updated: July 29, 2026

Introduction

Sagecom Inc. Data Processing Addendum (DPA) Enterprise Data Processing Addendum Version: 1.0 Effective Date: July 29, 2026 Last Updated: July 29, 2026

1. Purpose

This Data Processing Addendum (“DPA”) forms part of the Master Terms of Service, Master Services Agreement (“MSA”), Enterprise Agreement, Subscription Agreement, Order Form, or other written agreement (the “Agreement”) between Sagecom Inc. (“Sagecom”, “Processor”, “Service Provider”, “we”, “our”, or “us”) and the Customer (“Controller”, “Business”, “Customer”, “you”, or “your”). This DPA governs Sagecom’s Processing of Personal Data on behalf of the Customer in connection with the provision of Cloud PBX, UCaaS, Hosted Voice, Virtual Office, AI Services, Communications APIs, Customer Portal, Professional Services, and related cloud communications services. Where this DPA conflicts with the Agreement regarding the Processing of Personal Data, this DPA shall prevail to the extent of that conflict.

2. Definitions

For purposes of this DPA: Applicable Privacy Laws means all privacy, data protection, telecommunications, cybersecurity, and AI-related laws applicable to the Processing of Personal Data, including, where applicable: EU GDPR UK GDPR UK Data Protection Act 2018 Swiss Federal Act on Data Protection

California Consumer Privacy Act (CCPA), as amended by the CPRA U.S. state comprehensive privacy laws Applicable telecommunications privacy laws Other applicable international privacy legislation. Controller means the entity determining the purposes and means of Processing Personal Data. Processor means Sagecom when Processing Personal Data on behalf of the Customer. Personal Data has the meaning assigned under Applicable Privacy Laws. Customer Content includes Personal Data, business information, AI prompts, AI responses, call recordings, transcripts, uploaded documents, knowledge bases, CRM data, communications, and other information submitted through the Services. Processing includes collection, storage, organisation, transmission, use, disclosure, deletion, destruction, analysis, recording, retrieval, and any other operation performed on Personal Data. Subprocessor means a third party engaged by Sagecom to Process Personal Data on Sagecom’s behalf.

3. Scope

This DPA applies whenever Sagecom Processes Personal Data on behalf of a Customer using: Cloud PBX Unified Communications as a Service (UCaaS) Hosted Voice Virtual Office AI Receptionists AI Voice Agents AI Customer Service AI Workflow Automation AI APIs Communications APIs Customer Portal Websites Mobile Applications

Professional Services Technical Support

4. Roles of the Parties

Except where otherwise agreed in writing: the Customer acts as the Controller (or Business under applicable U.S. privacy laws); and Sagecom acts as the Processor (or Service Provider/Processor, as applicable). Nothing in this DPA transfers ownership of Personal Data to Sagecom.

5. Customer Instructions

Sagecom shall Process Personal Data only: to provide the Services; in accordance with documented Customer instructions; as required to comply with Applicable Law; or as otherwise expressly authorised in the Agreement. If Sagecom believes an instruction violates Applicable Law, Sagecom may notify the Customer before carrying out the instruction, unless prohibited by law.

6. Categories of Personal Data

Depending on the Services used, Sagecom may Process: names; business contact details; email addresses; telephone numbers; billing information; account credentials; IP addresses; device identifiers;

call detail records (CDRs); call recordings; voicemail; AI prompts; AI responses; AI-generated summaries; transcripts; uploaded documents; knowledge bases; CRM records; support communications; authentication logs; API activity; usage analytics.

7. Categories of Data Subjects

Personal Data may relate to: Customer personnel; authorised users; employees; contractors; prospective customers; customers of the Customer; suppliers; website visitors; callers; messaging recipients; support contacts; business partners.

8. Confidentiality

Sagecom shall ensure that personnel authorised to Process Personal Data: are subject to confidentiality obligations;

receive appropriate privacy and security training; access Personal Data only where necessary to perform their duties.

9. Security Measures

Sagecom maintains administrative, technical, and organisational safeguards designed to protect Personal Data, including: encryption in transit using TLS; encryption at rest where supported; role-based access controls; multi-factor authentication for privileged access; audit logging; vulnerability management; secure software development practices; network monitoring; intrusion detection; secure backup procedures; disaster recovery capabilities; periodic security assessments. Security measures may evolve to reflect changes in technology, threats, and industry standards.

10. AI Services

Where AI Services are used: Customer Content remains the property of the Customer. Sagecom does not intentionally use Customer Content to train public or shared AI foundation models unless the Customer has expressly opted in through a separate written agreement. AI prompts, responses, transcripts, and knowledge bases are processed solely to provide the requested Services. Customers remain responsible for the legality of information submitted to AI Services.

11. Subprocessors

The Customer authorises Sagecom to engage Subprocessors to support the provision of the Services. Sagecom shall: conduct reasonable due diligence before engaging Subprocessors; require Subprocessors to protect Personal Data through written contractual obligations; remain responsible for the performance of Subprocessors to the extent required by Applicable Law. A current list or categories of Subprocessors will be made available upon reasonable request or through Sagecom’s designated customer resources, subject to confidentiality and security considerations.

12. International Data Transfers

Where Personal Data is transferred outside the country in which it was collected, Sagecom shall implement appropriate safeguards, including, where applicable: Standard Contractual Clauses (SCCs); UK International Data Transfer Agreement (IDTA) or UK Addendum; adequacy decisions; contractual safeguards; technical and organisational measures designed to protect Personal Data.

13. Assistance to the Customer

Taking into account the nature of the Processing and the information available, Sagecom shall provide reasonable assistance to enable the Customer to: respond to data subject requests; conduct data protection impact assessments (where applicable); consult with supervisory authorities where legally required; demonstrate compliance with Applicable Privacy Laws.

14. Security Incidents & Personal Data Breaches

If Sagecom becomes aware of a confirmed Personal Data Breach affecting Personal Data Processed on behalf of the Customer, Sagecom shall: investigate the incident; take reasonable measures to contain and remediate the incident; notify the Customer without undue delay, taking into account applicable contractual and legal obligations; provide available information reasonably necessary to assist the Customer in meeting its own legal notification obligations. Notification does not constitute an admission of fault or liability.

15. Data Subject Requests

Where Sagecom receives a request directly from a data subject relating to Personal Data Processed on behalf of the Customer, Sagecom will: promptly notify the Customer where legally permitted; not respond directly except where required by law or authorised by the Customer; provide reasonable assistance in responding to the request.

16. Retention & Deletion

Upon termination or expiration of the Services, and subject to Applicable Law and the Agreement, Sagecom shall: return Personal Data to the Customer upon request, where technically feasible; or securely delete or anonymise Personal Data after applicable retention periods. Information may be retained where required by law, for fraud prevention, security, dispute resolution, enforcement of legal rights, or legitimate business continuity purposes.

17. Audits

Where required by Applicable Privacy Laws or an executed Enterprise Agreement, Sagecom will make available reasonable information demonstrating compliance with this DPA. To protect confidential information and the security of Sagecom’s systems and other customers, audit obligations may be satisfied through: independent third-party audit reports; recognised security certifications; compliance attestations; responses to reasonable security questionnaires. On-site audits will be subject to reasonable notice, confidentiality obligations, security requirements, and mutually agreed scope.

18. Customer Responsibilities

The Customer is responsible for: establishing a lawful basis for Processing; providing required privacy notices; obtaining legally required consents; ensuring uploaded information is lawfully obtained; configuring retention settings where available; maintaining appropriate security controls for its own systems and users.

19. Liability

Liability arising under this DPA shall be subject to the limitations of liability set forth in the applicable Agreement, except where such limitations are prohibited by Applicable Law.

20. Term & Survival

This DPA remains in effect for as long as Sagecom Processes Personal Data on behalf of the Customer.

Provisions relating to confidentiality, security, international transfers, liability, dispute resolution, and deletion of Personal Data survive termination to the extent necessary to fulfil their purpose.

21. Governing Law

This DPA shall be governed by the governing law specified in the applicable Agreement unless Applicable Privacy Laws require otherwise.

22. Order of Precedence

For matters relating to Personal Data Processing, the following order of precedence applies:

23. Contact Information

Questions regarding this DPA should be directed to: Privacy Officer Sagecom Inc. Miami, Florida, USA Privacy: privacy@sagecominc.com Legal: legal@sagecominc.com Security: security@sagecominc.com General: info@sagecominc.com

Appendix A – Description of Processing Subject Matter: Provision of cloud communications, telecommunications, AI, and related services. Duration: For the term of the Agreement and any applicable retention period. Nature of Processing: Collection, storage, organisation, transmission, analysis, retrieval, hosting, support, AI processing, communications routing, authentication, billing, and secure deletion. Purpose: Service delivery, customer support, billing, fraud prevention, network operations, AI functionality, security, legal compliance, and business continuity. Categories of Data Subjects: Customers, users, employees, contractors, callers, website visitors, business contacts, support contacts, and authorised representatives. Categories of Personal Data: As described in Section 6 of this DPA. Special Categories of Data: Processed only where submitted by the Customer and permitted by Applicable Law.

Appendix B – Technical & Organisational Measures Sagecom maintains a risk-based Information Security Program that includes: Information security governance Encryption standards Identity and access management Multi-factor authentication Secure software development Vulnerability management Security monitoring Audit logging Backup and disaster recovery Incident response Vendor risk management Business continuity planning Employee security awareness training

Periodic security and compliance reviews Continuous improvement of security controls These measures may be updated periodically to reflect evolving threats, technologies, regulatory requirements, and industry best practices.