Last updated: May 28, 2026 Effective date: May 28, 2026
This Data Processing Agreement ("Agreement" or "DPA") forms part of the Terms of Service or other written or electronic agreement ("Principal Agreement") between Softix, an Israeli business having its mailing contact address at P.O. Box 7575, 9850009, Israel (the "Processor", "Gaaba", "we", "us"), and the customer identified in the Principal Agreement (the "Controller", "Customer", "you"), together the "Parties".
In the event of a conflict between this Agreement and the Principal Agreement, the terms of this Agreement shall prevail with respect to the Processing of Personal Data.
WHEREAS
(A) Customer acts as a Controller of personal data relating to its end users (including callers, prospects, and customers who interact with Customer's business through the Gaaba Voice CRM platform).
(B) Customer engages Processor to provide the Gaaba Voice CRM Services ("Services"), which involve the Processing of Personal Data on Customer's behalf.
(C) The Parties wish to set out their respective rights and obligations in compliance with applicable Data Protection Laws.
IT IS AGREED AS FOLLOWS:
1. Definitions and Interpretation
1.1. Capitalized terms not defined herein have the meanings given in the Principal Agreement or in the GDPR/UK GDPR. The following terms have the meanings set out below:
- "Agreement" means this DPA and all Annexes.
- "Customer Personal Data" means any Personal Data relating to Customer's end users (including callers, leads, customers, and other individuals whose data is collected through Customer's use of the Services) that is Processed by Processor on behalf of Customer.
- "Data Protection Laws" means all applicable laws relating to the Processing of Personal Data and privacy in any relevant jurisdiction, including (i) the Israeli Protection of Privacy Law, 5741-1981, and its regulations; (ii) the GDPR; (iii) the UK GDPR; (iv) the CCPA/CPRA and other US Data Protection Laws; (v) the FADP (Switzerland); and any associated, additional, or replacement legislation in force from time to time.
- "GDPR" means EU Regulation 2016/679 (General Data Protection Regulation).
- "UK GDPR" means the GDPR as it forms part of UK domestic law by virtue of the European Union (Withdrawal) Act 2018.
- "US Data Protection Laws" means all data privacy, data protection, and cybersecurity laws, rules, and regulations of the United States applicable to the Processing of Personal Data under the Principal Agreement, including but not limited to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, the "CCPA"); the Colorado Privacy Act; the Connecticut Data Privacy Act; the Utah Consumer Privacy Act; the Virginia Consumer Data Protection Act; and any binding regulations promulgated thereunder, as amended from time to time.
- "FADP" means the Swiss Federal Act on Data Protection and its Ordinances, as amended.
- "EEA" means the European Economic Area.
- "Protected Area" means (i) for EU Personal Data, the EU Member States, the EEA, and any country covered by an adequacy decision under Article 45 GDPR; (ii) for UK Personal Data, the United Kingdom and any country covered by an adequacy regulation under UK law; (iii) for Swiss Personal Data, any country recognized as adequate by the Swiss Federal Data Protection and Information Commissioner ("FDPIC") or the Swiss Federal Council; and (iv) for Israeli Personal Data, jurisdictions recognized as providing an adequate level of protection under Israeli Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001.
- "Personal Data" means any information that is protected as "personal data", "personal information", "personally identifiable information", or similar terms under applicable Data Protection Laws.
- "Personal Data Breach" has the meaning given in the GDPR.
- "Processing" has the meaning given in the GDPR, and "Process" and "Processed" shall be construed accordingly.
- "Services" means the Gaaba Voice CRM platform and related services provided by Processor to Customer pursuant to the Principal Agreement, including AI-assisted call handling, lead capture and management, scheduling, notifications, call recording and transcription (where enabled), and reporting. For the avoidance of doubt, with respect to the Google Ads API integration, the scope of Services is strictly limited to read-only reporting, analytics, customer account selection, campaign performance review, geographic insights, and AI-assisted recommendation data processing. The Google Ads API integration does not currently include creating, editing, pausing, enabling, removing, deleting, or otherwise mutating campaigns, ads, keywords, bids, budgets, or Google Ads account settings.
- "Subprocessor" means any third party appointed by Processor to Process Customer Personal Data on Customer's behalf in connection with this Agreement.
- "Standard Contractual Clauses" or "SCCs" means:
- In respect of EU Personal Data: the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor), excluding optional clauses ("EU SCCs").
- In respect of UK Personal Data: the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner ("UK Addendum").
- In respect of Swiss Personal Data: the EU SCCs with adaptations as required by the FDPIC in its Statement of 27 August 2021.
1.2. Other capitalized terms ("Controller", "Data Subject", "Member State", "Supervisory Authority", etc.) shall have the meanings given in the GDPR and UK GDPR. Analogous terms under US Data Protection Laws (e.g., "Consumer", "Service Provider", "sale", "share") shall have the meanings given in the CCPA and other applicable US Data Protection Laws.
2. Roles and Scope
2.1. Roles. The Parties acknowledge that, with respect to Customer Personal Data, Customer is the Controller and Processor is the Processor (or, where applicable under US Data Protection Laws, Processor is a "Service Provider" acting on behalf of Customer as the "Business").
2.2. Scope. This Agreement applies to the Processing of Customer Personal Data by Processor in connection with the Services. The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.
3. Obligations of the Customer (Controller)
3.1. Customer shall:
3.1.1. ensure that all Customer Personal Data is collected, used, and disclosed in compliance with applicable Data Protection Laws, including having a valid legal basis for Processing and providing all required notices to Data Subjects;
3.1.2. be solely responsible for obtaining all required consents from Data Subjects, including (without limitation) consents required for call recording, call transcription, electronic marketing communications, and cookies. Customer acknowledges that laws regarding call recording vary significantly by jurisdiction (including all-party-consent requirements in several US states and notice requirements under the GDPR and Israeli law) and that compliance is Customer's sole responsibility;
3.1.3. provide documented instructions to Processor in accordance with this Agreement and the Principal Agreement; and
3.1.4. not provide to Processor any Special Categories of Personal Data (as defined in Article 9 GDPR) or sensitive personal information unless the Parties have agreed in writing on additional safeguards.
4. Obligations of the Processor
4.1. Processor shall:
4.1.1. Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Customer Personal Data outside the Protected Area, unless required to do so by laws to which Processor is subject. Where Processor is required by law to Process Customer Personal Data otherwise than on Customer's instructions, it shall inform Customer of that legal requirement before Processing, unless the relevant law prohibits such notification on important grounds of public interest. The Principal Agreement, this Agreement, and Customer's use of the Services together constitute Customer's documented instructions;
4.1.2. ensure that persons authorized to Process Customer Personal Data are bound by appropriate confidentiality undertakings;
4.1.3. implement and maintain appropriate technical and organizational measures as described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access;
4.1.4. notify Customer if, in Processor's reasonable opinion, an instruction from Customer infringes Data Protection Laws (it being acknowledged that Processor is not obliged to perform legal compliance reviews on Customer's behalf);
4.1.5. not Sell or Share (as those terms are defined in the CCPA) Customer Personal Data, and not retain, use, or disclose Customer Personal Data for any purpose other than the specific purpose of performing the Services or as otherwise permitted by Data Protection Laws; and
4.1.6. comply with applicable Data Protection Laws in its Processing of Customer Personal Data.
4.2. Processor certifies that it understands and will comply with the restrictions in this Section 4.
5. Personnel and Confidentiality
5.1. Processor shall take reasonable steps to ensure the reliability of any personnel with access to Customer Personal Data and ensure that all such personnel are bound by written confidentiality obligations or statutory duties of confidentiality with respect to Customer Personal Data.
6. Security
6.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of natural persons, Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, where appropriate, the measures referred to in Article 32(1) GDPR. These measures are described in Annex II.
7. Subprocessing
7.1. General Authorization. Customer provides Processor with general authorization to engage the Subprocessors listed in Annex III, and to engage additional Subprocessors in accordance with this Section 7.
7.2. Flow-down Obligations. Processor shall enter into a written contract with each Subprocessor imposing data protection obligations substantially equivalent to those imposed on Processor under this Agreement. Where a Subprocessor fails to fulfill its data protection obligations, Processor shall remain fully liable to Customer for the performance of that Subprocessor's obligations.
7.3. Changes to Subprocessors. Processor may engage additional or replacement Subprocessors. Processor shall provide Customer with notice of the addition or replacement of any Subprocessor at least fourteen (14) days in advance, by updating the list at [https://gaaba.ai/legal/subprocessors] or by other reasonable means.
7.4. Objection Right. If Customer reasonably objects to a new Subprocessor on data protection grounds, Customer shall notify Processor in writing within seven (7) days after receipt of the notice. The Parties shall work together in good faith to address the objection. If the objection cannot be addressed within thirty (30) days, Customer may terminate the affected Services with reasonable written notice as its sole and exclusive remedy.
8. Data Subject Rights
8.1. Processor shall, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, to enable Customer to fulfill its obligation to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.
8.2. If Processor receives a request from a Data Subject in respect of Customer Personal Data, Processor shall:
8.2.1. promptly notify Customer; and
8.2.2. not respond to the request except on Customer's documented instructions or as required by applicable law.
8.3. Processor may charge a reasonable fee for assistance under this Section 8 to the extent that such assistance falls outside the scope of the Services, except where the assistance is required as a direct result of Processor's own acts or omissions.
9. Personal Data Breach
9.1. Processor shall notify Customer without undue delay, and in any event no later than seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing Customer with the information then available that is reasonably necessary to enable Customer to meet its own notification obligations under Data Protection Laws. Because the 72-hour regulatory clock under the GDPR runs against Customer as Controller, Processor will use reasonable efforts to notify materially sooner where the circumstances of the incident allow, and the initial notification may be followed by updates as more information becomes available.
9.2. Processor shall cooperate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
10. Data Protection Impact Assessments
10.1. To the extent required by Data Protection Laws, Processor shall provide Customer with reasonable assistance, taking into account the nature of the Processing and the information available to Processor, with data protection impact assessments and prior consultations with supervisory authorities.
11. Audits
11.1. Processor shall make available to Customer, upon reasonable written request and subject to appropriate confidentiality obligations, the information reasonably necessary to demonstrate compliance with this Agreement.
11.2. Customer (or an independent auditor mandated by Customer and approved by Processor, such approval not to be unreasonably withheld) may, no more than once per calendar year and at Customer's expense, conduct an audit of Processor's compliance with this Agreement. Audits shall be conducted during regular business hours, with reasonable advance written notice, and in a manner that does not unreasonably disrupt Processor's business operations.
11.3. Processor may satisfy its obligations under this Section 11 by providing relevant third-party audit reports or certifications (e.g., SOC 2, ISO 27001), where available.
12. International Transfers
12.1. Customer acknowledges that Processor and its Subprocessors are located in various jurisdictions, including Israel, the United States, and others as identified in Annex III, and that Customer Personal Data may be Processed outside the Protected Area to provide the Services. Customer authorizes such transfers.
12.2. EU/UK/Swiss Transfers. Where the transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country outside the Protected Area is not covered by an adequacy decision, the Parties agree that such transfer shall be governed by the applicable Standard Contractual Clauses, which are hereby incorporated by reference and deemed executed by the Parties as of the effective date of this Agreement.
12.3. For purposes of the EU SCCs:
12.3.1. Module 2 (Controller to Processor) applies;
12.3.2. Clause 7 (Docking Clause) does not apply;
12.3.3. for Clause 9, Option 2 (general written authorization) applies, with the time period for notification of changes to Subprocessors as set out in Section 7.3 above;
12.3.4. for Clause 11, the optional language does not apply;
12.3.5. for Clause 17, the SCCs are governed by the law of Ireland;
12.3.6. for Clause 18(b), the courts of Ireland have jurisdiction;
12.3.7. for Annex I.A (List of Parties), Customer is the data exporter and Processor is the data importer, with contact details as set out in the Principal Agreement and Annex I of this Agreement;
12.3.8. Annex I.B (Description of Transfer), Annex II (Technical and Organizational Measures), and Annex III (List of Subprocessors) are as set out in this Agreement.
12.4. UK Personal Data. The UK Addendum is hereby incorporated by reference. Table 1 (parties), Table 2 (selected EU SCCs and modules), and Table 3 (Appendix information) are completed by reference to the relevant sections and Annexes of this Agreement. Table 4 (ending the Addendum): either party may end the Addendum as set out in Section 19 of the Addendum.
12.5. Swiss Personal Data. The EU SCCs apply with the following adaptations: (a) references to the GDPR are interpreted as references to the FADP; (b) references to EU Member States are interpreted to include Switzerland; (c) the competent supervisory authority is the FDPIC; and (d) data subjects in Switzerland may bring claims in their place of habitual residence.
12.6. Israeli Personal Data. Transfers of Personal Data subject to Israeli law shall be made in accordance with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, on the basis that recipient jurisdictions provide an adequate level of protection, the recipient is bound by data protection obligations substantially similar to those under Israeli law, or another lawful basis applies.
12.7. Conflict. In the event of any conflict between this Agreement and the SCCs, the SCCs shall prevail.
13. Return or Deletion of Customer Personal Data
13.1. Upon termination or expiry of the Services, Processor shall, at Customer's choice, either (a) return all Customer Personal Data to Customer or (b) delete all Customer Personal Data, in each case within a reasonable period and subject to Processor's standard data retention periods. Processor may retain Customer Personal Data to the extent required by applicable law, for the establishment, exercise, or defense of legal claims, or as part of routine backups (which shall be deleted in accordance with Processor's backup retention schedule).
13.2. Processor shall, upon request, certify in writing the deletion of Customer Personal Data carried out under this Section 13.
14. General
14.1. Term. This Agreement applies as long as Processor Processes Customer Personal Data on behalf of Customer.
14.2. Confidentiality. Each Party shall keep confidential the terms of this Agreement and any Confidential Information of the other Party, except (a) where disclosure is required by law, (b) where the information is in the public domain through no fault of the receiving Party, or (c) with the prior written consent of the other Party.
14.3. Notices. Notices under this Agreement shall be sent to the contact details set out in the Principal Agreement, or, for data protection matters, to privacy@gaaba.ai.
14.4. Governing Law and Jurisdiction. Except as required by the SCCs (Section 12), this Agreement is governed by, and shall be interpreted in accordance with, the laws and exclusive jurisdiction set out in the Principal Agreement.
14.5. Order of Precedence. In the event of a conflict between this Agreement and the Principal Agreement with respect to the Processing of Personal Data, this Agreement shall prevail. The SCCs prevail over this Agreement to the extent of any conflict.
14.6. Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
14.7. Counterparts and Electronic Signature. This Agreement may be executed in counterparts and by electronic signature, each of which shall be deemed an original and which together shall constitute one instrument.
SIGNATURES
The Processor
Softix
Signature: ____________________________
Name: Daniel Turgeman
Title: Founder
Date: ____________________________
The Customer (Controller)
[CUSTOMER LEGAL ENTITY NAME]
Signature: ____________________________
Name: [CUSTOMER REPRESENTATIVE NAME]
Title: [CUSTOMER REPRESENTATIVE TITLE]
Date: ____________________________
ANNEX I — Processing Activities and List of Parties
A. Processing Activities
Subject matter of the Processing
The Processing of Customer Personal Data relates to the provision of the Gaaba Voice CRM Services, an AI-assisted platform that converts inbound phone calls into structured CRM leads and supports lead management, scheduling, customer communications, and reporting for Customer's business.
Nature and purpose of the Processing
The Processing operations include: receiving and routing inbound voice calls; AI-assisted call handling and conversation; capture of caller details and lead information; storage and management of CRM records; scheduling of appointments and dispatching of technicians; sending of notifications via SMS, WhatsApp, email, and Telegram; optional recording and transcription of calls; reporting and analytics; read-only Google Ads reporting and recommendation features where enabled; billing and account management.
The purpose of the Processing is to enable Customer to operate its business using the Services.
Duration
For the term of the Principal Agreement, plus any retention periods set out herein, configured in the Services, or required by applicable law. Unless otherwise agreed, Customer Personal Data is retained while the account is active; call recordings and transcripts are retained by default for thirty (30) days; audit logs are retained for up to six (6) months; and backups are retained for up to thirty (30) days.
Categories of Data Subjects
- Customer's end users, including callers, prospects, leads, customers, and other individuals who interact with Customer's business through the Services.
- Customer's personnel (including business owners, administrators, and technicians) authorized to use the Services on Customer's behalf.
Categories of Personal Data Processed
As determined and provided by Customer (or generated through the use of the Services), including (without limitation):
- Identity and contact data: name, phone number, email address, postal address.
- Communication content: voice recordings (where enabled by Customer), call transcripts, SMS/WhatsApp/email message content, chat logs.
- Service-related data: lead details, job tickets, appointment data, service history, invoicing data, technician assignments.
- Technical data: IP address, device information, log data, timestamps.
- Authentication data: account credentials and session identifiers of Customer's personnel (hashed/encrypted).
Special Categories of Personal Data
None intended. Customer shall not submit Special Categories of Personal Data (Article 9 GDPR) or comparable sensitive personal information to the Services unless the Parties have agreed in writing on additional safeguards.
B. List of Parties
Data Exporter (Controller): the Customer identified in the Principal Agreement.
- Contact: as set out in the Principal Agreement or Customer's account.
- Role: Controller.
- Activities: as described in the Principal Agreement.
Data Importer (Processor): Softix.
- Address: P.O. Box 7575, 9850009, Israel.
- Contact: privacy@gaaba.ai.
- Role: Processor.
- Activities: provision of the Gaaba Voice CRM Services.
C. Description of Transfer
- Categories of Data Subjects: as described in Section A above.
- Categories of Personal Data: as described in Section A above.
- Sensitive Data: none intended; see Section A.
- Frequency of transfer: continuous, for the duration of the Principal Agreement.
- Nature of the Processing: as described in Section A above.
- Purpose(s) of the transfer and further Processing: as described in Section A above.
- Period of retention: for the term of the Principal Agreement, plus retention periods required by applicable law or set out in this Agreement, the Principal Agreement, or the Service configuration. Unless otherwise agreed, Customer Personal Data is retained while the account is active; call recordings and transcripts are retained by default for thirty (30) days; audit logs are retained for up to six (6) months; and backups are retained for up to thirty (30) days.
- Competent supervisory authority: to be determined in accordance with Clause 13 of the EU SCCs, based on the Customer's establishment or representative within the EEA.
ANNEX II — Technical and Organizational Security Measures
Processor implements and maintains the following technical and organizational measures to protect Customer Personal Data. These measures are reviewed periodically and may be updated to reflect industry practices, provided that no update materially reduces the level of protection.
1. Access Control. Role-based access control with least-privilege principles. Multi-factor authentication for administrative access. Strict separation of duties. Tenant isolation enforced at the database query level: each customer's data is segregated and accessible only via authenticated, authorized queries scoped to that customer's business identifier.
2. Encryption. Personal Data in transit is protected using TLS 1.2 or higher. Sensitive fields (including OAuth tokens, third-party API credentials, and designated personal data fields) are encrypted at rest using industry-standard symmetric encryption (e.g., AES-256). Authentication credentials are stored as one-way hashes (bcrypt) and never in plain text.
3. Pseudonymization and Minimization. Logs and diagnostic data are minimized; sensitive identifiers (e.g., full chat IDs, OAuth tokens, raw payment data) are not recorded in logs.
4. Backup and Recovery. Encrypted backups taken on a regular schedule and retained per Processor's standard backup retention policy. Documented disaster recovery procedures.
5. Network Security. Firewalls and network segregation between public-facing and internal systems. Production services are deployed behind a reverse proxy with TLS termination.
6. Software Security. Secrets and credentials are stored in environment configuration or encrypted database fields, never in source code. Source code is managed under version control with restricted access. Dependencies are reviewed and updated periodically. Automated typecheck and lint checks run in the CI pipeline before deployment.
7. Monitoring and Logging. Application and infrastructure logs are collected and retained for a defined period for security, audit, and troubleshooting purposes. Automated alerts notify Processor of service health issues and selected security events.
8. Personnel. Personnel with access to Personal Data are subject to written confidentiality obligations. Access is granted on a need-to-know basis and revoked promptly upon role change or termination.
9. Incident Response. Documented Personal Data Breach response procedures, including notification to affected Customers in accordance with Section 9 of this Agreement.
10. Subprocessor Oversight. Subprocessors are reviewed before engagement and bound by contractual obligations substantially equivalent to those set out in this Agreement. A current list is maintained per Section 7 and Annex III.
ANNEX III — List of Subprocessors
Processor engages the following Subprocessors to provide the Services. An updated list is maintained at [https://gaaba.ai/legal/subprocessors].
| Subprocessor | Service Provided | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure | United States |
| Twilio Inc. | Voice, SMS, and, where enabled, WhatsApp messaging | United States |
| Stripe, Inc. | Payment processing | United States |
| Anthropic, PBC | AI-assisted call handling (Claude) | United States |
| OpenAI, L.L.C. | AI-assisted processing (where enabled) | United States |
| Google LLC | Calendar integration; AI-assisted processing (Gemini, where enabled) | United States |
| WhatsApp LLC / Meta Platforms, Inc. | Underlying WhatsApp platform and related delivery services, where WhatsApp messaging is enabled | United States / Global |
| Telegram FZ-LLC | Notification delivery (where enabled) | United Arab Emirates / Global |
END OF AGREEMENT