Lina · Legal
Data Processing Addendum
Last updated: · Revision 1
Effective for an account from the moment it accepts this version at signup. For an account that accepted an earlier version, or none: effective , or 30 days after we email notice to that account’s admin if later (Terms of Service, section 18).
This Data Processing Addendum (“DPA”) is incorporated into our Terms of Service and applies whenever Lina processes Customer Personal Data for an organization that uses Lina. It is between that organization (the “Customer”) and Lina (Joseph Linares, sole proprietor, San Diego, California). If this DPA and the Terms conflict about personal data, this DPA controls.
1. Definitions
- Customer Personal Data means personal information in content the Customer puts into Lina or collects through it — for example its visitors’ chats, callers’ details and transcripts, contacts and members, forwarded email and knowledge content.
- Data Protection Laws means the privacy laws that apply to that processing, including the California Consumer Privacy Act as amended (“CCPA”).
- Security Incident means a breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Customer Personal Data.
2. Roles
The Customer is the business (controller) for Customer Personal Data, and Lina is its service provider (processor). The Customer is responsible for the lawfulness, accuracy and minimization of Customer Personal Data and its instructions; having a lawful basis for every collection and communication; honoring data-subject rights; and giving the notices and getting and documenting the consents the law requires — including to record, transcribe or process a call with AI (Lina transcribes every call its AI agent answers and processes it with AI, even when recording is off), for all-party or two-party call recording, calls and texts, commercial email, bot disclosure and campaign communications. The Customer must not instruct us to process data in violation of Data Protection Laws.
3. Processing only on instructions
We process Customer Personal Data only on the Customer’s documented instructions: the Terms and this DPA, the Customer’s configuration and use of Lina, and any other written instructions we agree to. We will tell the Customer if we believe an instruction breaks Data Protection Laws.
- Subject matter and purpose: providing Lina — hosting, AI answering, call handling, email ingest and AI-drafted replies, email and text delivery, knowledge and website tools, storage, backups and support.
- Duration: the term of the Customer’s account, plus the retention window in section 10.
- Data subjects: the Customer’s website visitors, callers, email and text correspondents, contacts, donors, volunteers, members and staff.
- Categories of data: names and contact details; chat, email and text content; AI drafts and summaries; call transcripts; call audio when the Customer enables recording; voicemail; notes; knowledge, uploaded files and website content; campaign information and political content; donation, pledge or charge-issue details; and session identifiers and interaction/disclosure logs. The Customer must not send children-under-13 data. Lina is not designed for health, financial-account or government-ID data, and the Customer must not send such data without a separate written agreement.
4. Service-provider commitments (CCPA)
We will not sell or share Customer Personal Data. We will not retain, use or disclose it for any purpose other than providing Lina to the Customer (or as the CCPA otherwise allows a service provider), or outside our direct business relationship with the Customer, and we will not combine it with personal information we receive from others except as the CCPA permits. We will comply with the CCPA obligations that apply to us, give the data the level of protection the CCPA requires, and tell the Customer if we can no longer meet these obligations. The Customer may take reasonable steps to stop and fix any unauthorized use.
5. Confidentiality
Access to Customer Personal Data is limited to Lina personnel — today, the owner — who need it to run, support or secure the service and who are bound by confidentiality.
6. Security measures
We maintain these measures, described further on our security page:
- Encryption in transit: TLS on every hosted domain, managed by our hosting provider.
- Isolation between organizations: each request is resolved to one organization and reads and writes only that organization’s data; sign-in sessions are bound to their organization; automated tests run two organizations side by side to check that nothing crosses over.
- Access control: admin, editor and viewer roles, enforced by the server on every Command Center API; per-organization credentials for inbound webhooks.
- Authentication: passwords stored as salted PBKDF2 hashes; single-use password-reset links bound to the organization; a changed password ends that account’s existing sessions.
- Verified integrations: payment, phone and inbound-email webhooks are signature-checked, and unverified calls are rejected.
- Secrets: kept as environment variables on our hosting provider — never in source code, never shown in the Command Center; logs mask secret-shaped values.
- Backups: nightly backups, kept 30 days, with an automated restore rehearsal after each one.
- Change control: every change passes the automated test suite and secret scanning in CI before it is deployed.
- Monitoring and audit: an external uptime monitor, alerts to the owner for errors, billing events and failed backups, and an audit log of privileged admin actions.
7. Subprocessors
The Customer authorizes the subprocessors listed on our Subprocessors page. We use each under its data-protection terms and remain responsible for its processing of Customer Personal Data as this DPA requires. We will add a new subprocessor to that page at least 14 days before it starts processing Customer Personal Data, unless an urgent replacement is needed to keep Lina running (then we will update the page as soon as we can). The Customer may object on reasonable data-protection grounds by emailing legal@linasystems.org within that period. We will try to resolve the objection; if we cannot, the Customer may cancel the affected service and we will refund prepaid fees for the unused part of its term.
8. Requests from data subjects
Lina gives the Customer tools to find, export, correct and erase personal data: the Command Center, an export (Settings → Account → Export my data; it does not include call or voicemail audio or files over 50 MB), and per-person erasure of contact and call details, including from archived and deleted chats (it keeps the identifier the person was listed under as a record of the erasure, and does not rewrite chat transcripts; the Customer deletes those conversations separately). If a data subject contacts us about Customer Personal Data, we will pass the request to the Customer and not answer it ourselves, except to point the person to the Customer or where the law requires. We will reasonably help with requests the tools do not cover.
9. Security Incidents
We will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting its Customer Personal Data. The notice will describe what happened, the data and people affected as far as we know them, the likely consequences, and what we are doing about it, and we will update it as we learn more. We will take reasonable steps to contain the incident and help the Customer meet its own notification duties. Notice or cooperation is not an admission of fault or liability.
10. Deletion and return
During the term the Customer can export its data at any time (the export does not include call or voicemail audio or files over 50 MB). When the Customer’s account ends, its data is kept for 30 days so it can export it or come back. The account then becomes eligible for deletion, and we delete its data within 30 days; backup copies expire within 30 days after that. Lina copies each voicemail from Twilio into its call record and then deletes it at Twilio, and when a call record or the account is deleted, or a caller is erased, Lina asks Twilio to delete any copy it still holds; a deletion Twilio does not confirm is logged, and we remove that copy when the Customer asks at legal@linasystems.org. We keep data longer only where the law requires, and then protect it and use it only for that purpose.
11. Demonstrating compliance
We will make available the written information reasonably needed to show compliance with this DPA: this DPA, our Security and Subprocessors pages, and written answers to a reasonable security questionnaire once a year or after a Security Incident. If a regulator requires more, we will cooperate on reasonable notice, during normal business hours, without exposing another customer’s data or our confidential security information, and at the Customer’s cost.
12. Where data is processed
Lina is hosted in the United States. Some subprocessors may process data in other locations, as listed on the Subprocessors page.
The Customer’s instruction to use an external information source authorizes the lookup described on the Subprocessors and Privacy pages, including sending an address or ZIP-containing query and any surrounding message text to the U.S. Census Bureau’s public geocoder. External source sites and platforms are independent recipients governed by their own terms, not contracted subprocessors.
13. Liability and term
Each party’s liability under this DPA is subject to the limitation of liability in the Terms. This DPA lasts for as long as we process Customer Personal Data for the Customer.