Data Processing Addendum
A few terms are still being finalised. They are marked Not settled yet below. Where a decision has not been made we say so, rather than state a number we would not stand behind. If one of them matters to you, email johnsontechstudio@gmail.com and we will tell you where it stands, in writing, before you rely on it.
This document has not been reviewed by a lawyer yet. It is a first publication, drafted from an attorney-review package, and several of its sections depend on facts about our providers that we have not finished verifying — those are marked below rather than asserted. If a section matters to a decision you are making, email johnsontechstudio@gmail.com and we will tell you where it stands, in writing, before you rely on it.
This Addendum is part of your Terms of Service with Johnson Tech Studio LLC dba gig33 (“Johnson Tech Studio,” “we,” “us”). It covers the personal information of your own customers — the people who ring your phone, chat on your website, or fill in your form — which passes through our system because you asked us to answer your phone and capture your leads.
Those people never signed up with us. They rang you. That is what this document is about, and if it disagrees with the Terms of Service on anything to do with their information, this document wins.
1. Who decides what, and who does what
- You decide. You determine what your customers’ information is collected for and how it is used. In privacy-law language you are the controller or business.
- We carry it out. We process that information on your behalf and on your instructions — the processor or service provider. Your instructions are this agreement, the settings you choose in the product, the workflows you configure, and support requests you send us.
- We will not go outside that. We will not sell your customers’ information, share it for cross-context behavioural advertising, use it for unrelated advertising, or use it for anything outside providing your service, except where the law requires it.
- We will not train models on it. Not our own, and not by handing it to someone else to train theirs, unless you separately and specifically tell us in writing that we may and it is lawful for us to.
- Our people. Only staff who need access to build and support your service have it, and they are under confidentiality obligations.
2. What we process, for whom, and for how long
- What it covers: hosting and running the services you bought — your website and forms, the AI receptionist and chat, lead capture and follow-up, reviews when that is switched on, integrations, support, and security.
- Whose information: your staff; the people who call, chat, or fill in a form; your customers and prospects; the people you nominate for call transfers; and reviewers.
- What information: names, phone numbers, email addresses, what service someone asked about, how urgent it is, notes summarising what they need, an address where the job needs one, appointment or job details, call transcripts and summaries, chat message logs, call metadata, do-not-contact records, and review content.
- What we do not take: we do not store call audio, and we do not store the caller’s number from caller ID. Our telephone provider hears the audio in order to produce the transcript we keep.
- Sensitive information is out of scope. This service is not built for card numbers, credentials, Social Security numbers, health records, or biometric data. Do not configure it to collect them unless we have approved that use case in writing.
- How long: for as long as you are a customer, plus the period described in section 7.
3. What you are responsible for
- Giving us lawful instructions, and not asking us to do something with this information that breaks the law.
- The accuracy of the information you supply and how it was collected — including having given your own customers whatever notice and choice the law requires.
- Telling your customers, in your own privacy notice, that an AI answers your phone and writes down what is said. If your notice does not cover that today, it needs to.
- Choosing settings that suit your industry and your state — what the assistant collects, what it must never say, and who can see it inside your business. The recording announcement is not among them: it always plays and cannot be switched off.
- Not putting regulated or highly sensitive information into the ordinary service.
4. Security
We maintain safeguards appropriate to this kind of information. These are the ones we can point at:
- Separation between businesses. Our database enforces per-business access rules, so one customer cannot read another customer’s leads, transcripts, or chats.
- Encryption in transit, and at rest with our providers.
- Passwordless sign-in. The links we email work once and expire after an hour.
- Connected-account tokens are encrypted before storage, and the database refuses to store one that is not.
- Incoming webhooks are signature-checked before they are acted on.
- Outbound messaging runs through a single gate that refuses to send without a complete, readable consent record — a missing or unreadable record is a refusal, not a pass.
- Activity records store references and reasons rather than names, phone numbers, or message contents.
- Secrets stay on the server and are separated between our development and production environments.
Not settled yet — we have not had an outside security assessment, we hold no security certification, and we are not claiming one. Ask about a specific control and we will tell you honestly whether it exists.
No system is completely secure, and we will not tell you otherwise.
5. The companies we use to do this
We use other companies to run parts of the service. Our Privacy Policy names every one of them and says what each receives — the database and file storage, the telephone and voice provider, the AI providers, the host, the email delivery service, the registrar, and the payment processor.
- We require the ones handling your customers’ information to be under appropriate data-protection obligations.
- If we add or change one in a way that materially affects your customers’ information, we will update the Privacy Policy, and we will tell you before it takes effect where the change is significant.
Not settled yet — we have not finished verifying, for each provider, its exact legal entity, the region it stores data in, its own data-processing terms, its retention periods, and who it passes data to in turn. We are not going to present those as verified facts before we have checked them. Ask about a specific provider and we will tell you what we know and what we do not.
Not final — how you can object to a new provider, and what happens if you do, has not been settled with our lawyer. Until it is, tell us your objection and we will work it out with you rather than point at a clause.
6. Requests from the people whose information it is
If one of your customers asks to see, correct, delete, or get a copy of their information, or asks to be left alone:
- Tell us and we will act on our copy — removing their lead record and the transcript of their conversation from your account.
- If they come to us first and the record belongs to your account, we will point them to you, because you are the one who decides — and we will tell you it happened.
- We may need to check who is asking before we act.
- Do-not-contact records survive deletion, deliberately. If someone opts out of messages, we keep the minimum needed to keep honouring that, because deleting an opt-out would mean they could be messaged again.
Not settled yet — we have not committed to a response deadline, and we have not built a formal appeal route. If a law that applies to you gives your customers a deadline or an appeal, it applies whether or not it is written here.
7. Deleting and getting your data back
- While you are a customer, ask us and we will give you a copy of your business content and your lead records.
- After you leave, ask us and we will delete your customers’ information, keeping only what we genuinely have to — billing and tax records, do-not-contact records, evidence for a live dispute or security investigation, and copies that age out of backups on their own.
- We will not keep your customers’ information active forever just because you stopped being a customer.
What is actually true about deletion today. There is a routine that runs every night to remove the contents of old transcripts. It deletes nothing: it is set to rehearse, counting what it would remove and stopping. Two separate deliberate acts by a person are needed to arm it, and neither has been done. Not settled yet — so there is no automatic deletion schedule in force, and this document is not going to promise one. Deletion happens because you ask for it, which you can do at any time and which we do act on. The periods that routine is aimed at are listed in our Privacy Policy, described as targets rather than commitments.
If you connect a Google Business Profile, Google’s own rules may require us to hold content from it for a shorter time than anything above. Where they do, Google’s rules win for that content.
8. If there is a security incident
If we confirm a security incident affecting your customers’ personal information, we will tell you without undue delay, and we will keep telling you as we learn more — early information is usually incomplete, and waiting until the picture is whole is worse than telling you what we know. We will work with you on containing it, fixing it, and any notice that has to go out.
Not settled yet — we have not fixed a notification deadline in hours or days, because the deadlines that actually apply differ by state and we would rather meet the real one than a number we invented. We also do not yet maintain a written incident-response plan, and we are telling you that rather than implying one exists.
9. Helping you with your own obligations
If you have to carry out a privacy assessment or demonstrate that you are meeting your obligations, ask us and we will give you the information we reasonably have about how the service handles data. Whether what you are doing with the service is lawful in the first place — your marketing, your calling, your recording, your industry’s rules — remains yours to judge.
Once a year, on reasonable written notice, you can ask us for the information reasonably needed to show we are meeting this Addendum. If a law that applies to you requires an actual audit and that information is not enough, we will agree a narrow one that does not expose other customers’ data. You cover your own costs unless the audit finds a material failure on our side.
10. State privacy laws
This Addendum is written to support the processor and service-provider obligations that United States state privacy laws impose — including in Texas, Virginia, Colorado, and California — where they apply to us.
Not final — which of those laws actually applies to us, and the specific wording each one requires, has not been confirmed by our lawyer. Several turn on revenue and volume thresholds we have not measured. This document states no certification and claims no determination; if a law applies, it applies, and nothing here reduces what it gives your customers.
11. Outside the United States
This is written for United States operations. We do not have the transfer arrangements that European, United Kingdom, or Swiss data-protection law requires, and we are not going to pretend we do. If your business needs them, ask us before you send us data that falls under those rules — the honest answer today is that this is not the right product for it.
12. How this fits with the rest
The liability limits, third-party claim provisions, disputes wording, and governing law in the Terms of Service apply here too, except where a privacy law says they cannot. Where this Addendum and the Terms disagree about your customers’ personal information, this Addendum wins.
13. Contact
Anything about this Addendum, including a request about a specific person’s information: johnsontechstudio@gmail.com, or by post at Johnson Tech Studio LLC, 4319 Country Brook Dr, Dallas, TX 75287, United States.
Data protection questions: johnsontechstudio@gmail.com