Data Processing Addendum

This Data Processing Addendum (“DPA”) is incorporated into our Terms of Service and applies whenever Lina processes Customer Personal Data for an organization that uses Lina. It is between that organization (the “Customer”) and Lina (Joseph Linares, sole proprietor, San Diego, California). If this DPA and the Terms conflict about personal data, this DPA controls.

1. Definitions

2. Roles

The Customer is the business (controller) for Customer Personal Data, and Lina is its service provider (processor). The Customer is responsible for the lawfulness, accuracy and minimization of Customer Personal Data and its instructions; having a lawful basis for every collection and communication; honoring data-subject rights; and giving the notices and getting and documenting the consents the law requires — including to record, transcribe or process a call with AI (Lina transcribes every call its AI agent answers and processes it with AI, even when recording is off), for all-party or two-party call recording, calls and texts, commercial email, bot disclosure and campaign communications. The Customer must not instruct us to process data in violation of Data Protection Laws.

3. Processing only on instructions

We process Customer Personal Data only on the Customer’s documented instructions: the Terms and this DPA, the Customer’s configuration and use of Lina, and any other written instructions we agree to. We will tell the Customer if we believe an instruction breaks Data Protection Laws.

4. Service-provider commitments (CCPA)

We will not sell or share Customer Personal Data. We will not retain, use or disclose it for any purpose other than providing Lina to the Customer (or as the CCPA otherwise allows a service provider), or outside our direct business relationship with the Customer, and we will not combine it with personal information we receive from others except as the CCPA permits. We will comply with the CCPA obligations that apply to us, give the data the level of protection the CCPA requires, and tell the Customer if we can no longer meet these obligations. The Customer may take reasonable steps to stop and fix any unauthorized use.

5. Confidentiality

Access to Customer Personal Data is limited to Lina personnel — today, the owner — who need it to run, support or secure the service and who are bound by confidentiality.

6. Security measures

We maintain these measures, described further on our security page:

7. Subprocessors

The Customer authorizes the subprocessors listed on our Subprocessors page. We use each under its data-protection terms and remain responsible for its processing of Customer Personal Data as this DPA requires. We will add a new subprocessor to that page at least 14 days before it starts processing Customer Personal Data, unless an urgent replacement is needed to keep Lina running (then we will update the page as soon as we can). The Customer may object on reasonable data-protection grounds by emailing legal@linasystems.org within that period. We will try to resolve the objection; if we cannot, the Customer may cancel the affected service and we will refund prepaid fees for the unused part of its term.

8. Requests from data subjects

Lina gives the Customer tools to find, export, correct and erase personal data: the Command Center, an export (Settings → Account → Export my data; it does not include call or voicemail audio or files over 50 MB), and per-person erasure of contact and call details, including from archived and deleted chats (it keeps the identifier the person was listed under as a record of the erasure, and does not rewrite chat transcripts; the Customer deletes those conversations separately). If a data subject contacts us about Customer Personal Data, we will pass the request to the Customer and not answer it ourselves, except to point the person to the Customer or where the law requires. We will reasonably help with requests the tools do not cover.

9. Security Incidents

We will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting its Customer Personal Data. The notice will describe what happened, the data and people affected as far as we know them, the likely consequences, and what we are doing about it, and we will update it as we learn more. We will take reasonable steps to contain the incident and help the Customer meet its own notification duties. Notice or cooperation is not an admission of fault or liability.

10. Deletion and return

During the term the Customer can export its data at any time (the export does not include call or voicemail audio or files over 50 MB). When the Customer’s account ends, its data is kept for 30 days so it can export it or come back. The account then becomes eligible for deletion, and we delete its data within 30 days; backup copies expire within 30 days after that. Lina copies each voicemail from Twilio into its call record and then deletes it at Twilio, and when a call record or the account is deleted, or a caller is erased, Lina asks Twilio to delete any copy it still holds; a deletion Twilio does not confirm is logged, and we remove that copy when the Customer asks at legal@linasystems.org. We keep data longer only where the law requires, and then protect it and use it only for that purpose.

11. Demonstrating compliance

We will make available the written information reasonably needed to show compliance with this DPA: this DPA, our Security and Subprocessors pages, and written answers to a reasonable security questionnaire once a year or after a Security Incident. If a regulator requires more, we will cooperate on reasonable notice, during normal business hours, without exposing another customer’s data or our confidential security information, and at the Customer’s cost.

12. Where data is processed

Lina is hosted in the United States. Some subprocessors may process data in other locations, as listed on the Subprocessors page.

The Customer’s instruction to use an external information source authorizes the lookup described on the Subprocessors and Privacy pages, including sending an address or ZIP-containing query and any surrounding message text to the U.S. Census Bureau’s public geocoder. External source sites and platforms are independent recipients governed by their own terms, not contracted subprocessors.

13. Liability and term

Each party’s liability under this DPA is subject to the limitation of liability in the Terms. This DPA lasts for as long as we process Customer Personal Data for the Customer.