Data Processing Addendum
Template — version January 1, 2026
This Data Processing Addendum ("DPA") is entered into between [Customer legal name] ("Customer," the Controller) and MORnet Communications, LLC, operating Hosted Voice ("Processor," "we"), effective [date]. Where Customer processes personal data on behalf of its own customers, Customer is a processor and we are a sub-processor, and this DPA applies accordingly.
1. Definitions
"Data Protection Laws" means all applicable privacy and data-protection laws, including the EU/UK GDPR and the California Consumer Privacy Act as amended (CCPA/CPRA). "Personal Data," "Controller," "Processor," "Process," "Data Subject," and "Personal Data Breach" have the meanings given under Data Protection Laws. "Customer Personal Data" means personal data we process on Customer's behalf under the Agreement, described in Annex A.
2. Roles and scope
Customer is the Controller (or a processor acting for a third-party controller) and we act as Processor. We Process Customer Personal Data only to provide the services and only on Customer's documented instructions (including as set out in the Agreement and this DPA), unless required by law, in which case we will notify Customer unless legally prohibited. Details of Processing are in Annex A.
3. Our obligations as Processor
- Instructions: Process only on Customer's documented instructions.
- Confidentiality: ensure personnel authorized to Process are bound by confidentiality.
- Security: implement appropriate technical and organizational measures (Annex B).
- Assistance: assist Customer, taking into account the nature of Processing, with (a) responding to Data Subject requests, (b) security, breach notification, and data-protection impact assessments, and (c) consultation with authorities.
- Deletion/return: on termination, delete or return Customer Personal Data as set out in Section 8.
- Audits: make available information necessary to demonstrate compliance and allow for audits as set out in Section 9.
4. Sub-processors
Customer provides general authorization for us to engage sub-processors (including messaging carriers/aggregators and infrastructure providers) to deliver the services. Current sub-processors are listed in Annex C. We impose data-protection obligations on sub-processors that are substantially the same as those in this DPA and remain responsible for their performance. We will give Customer reasonable notice of intended changes to sub-processors and an opportunity to object on reasonable data-protection grounds.
5. International transfers
Where Customer Personal Data is transferred out of the EEA, UK, or other restricted regions, such transfers are made under an approved transfer mechanism (for example, the EU Standard Contractual Clauses and the UK Addendum), which the parties agree to incorporate by reference where applicable.
6. Data subject requests
Taking into account the nature of the Processing, we will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data Subject rights. If we receive such a request directly, we will (unless legally required to act) direct the Data Subject to Customer.
7. Personal data breaches
We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.
8. Deletion or return
On expiry or termination of the services, we will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law (for example, call-detail and messaging records required for regulatory or billing purposes), in which case we protect it and Process it only as required.
9. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (or after a material breach or where required by a supervisory authority), allow Customer or its mandated auditor to conduct an audit, subject to confidentiality and to reasonable limits protecting other customers' data and our operations.
10. CCPA/CPRA terms
To the extent the CCPA/CPRA applies, we act as a service provider. We will not sell or share Customer Personal Data, will not retain, use, or disclose it except to perform the services (or as permitted by the CCPA), and will not combine it with other data except as permitted. We certify we understand and will comply with these restrictions.
11. General
If there is a conflict between this DPA and the Agreement on data protection, this DPA controls. Liability is subject to the limitations in the Agreement. This DPA is governed by the law stated in the Agreement.
Annex A — Details of Processing
| Subject matter | Provision of hosted voice and messaging services under the Agreement. |
|---|---|
| Duration | The term of the Agreement, plus any legally required retention. |
| Nature & purpose | Transmitting, routing, storing, and supporting voice calls and SMS/MMS messages, and related billing and abuse prevention. |
| Types of personal data | Phone numbers; caller/recipient identifiers; call-detail and message metadata (time, duration, status); message content in transit; account and contact details; [other, if any]. |
| Categories of data subjects | Customer's staff, callers, message recipients, and end users. |
Annex B — Security Measures
- Access controls and least-privilege for systems processing Customer Personal Data; MFA for administrative access.
- Encryption in transit for supported protocols; encryption at rest for stored credentials/records where applicable.
- Network security, monitoring, and abuse/fraud detection.
- Confidentiality obligations for personnel; onboarding/offboarding controls.
- Logging, backup, and recovery appropriate to the services.
- Vendor/sub-processor due diligence and contractual data-protection terms.
Annex C — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [Messaging carrier/aggregator, e.g. Bandwidth / Telnyx / Commio] | SMS/MMS transmission & 10DLC registration | USA |
| Microsoft (Microsoft 365 / Azure) | Email, hosting/infrastructure | USA |
| Cloudflare, Inc. | Network, security, edge delivery | USA |
| [Add others as applicable] |
Signatures
Name: [ ]
Title: [ ]
Date: [ ]
Name: [ ]
Title: [ ]
Date: [ ]