Legal
This Data Processing Addendum ("DPA") forms part of the Master Services Agreement ("MSA") between KnoxCall Limited ("Processor", "KnoxCall") and Customer ("Controller"). It governs the processing of Personal Data by KnoxCall on behalf of the Customer in connection with the KnoxCall service.
If you have signed our MSA without explicitly excluding this DPA, this DPA applies. To execute a counter-signed version, email [email protected].
KnoxCall processes Personal Data only on Customer's documented instructions, namely:
Processing continues for the term of the MSA plus any retention period in the Privacy Policy.
| Category | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Customer account identifiers | Service operation | Contract |
| End-user data passed through proxied routes | Routing, logging, anomaly detection | Customer's lawful basis as Controller |
| Audit log metadata | Security, accountability | Legitimate interest (security) + legal obligation |
| Telemetry (counts, latencies) | Operational improvement | Legitimate interest |
We do not knowingly process special-category data unless Customer pushes it through the service; in that event Customer remains the Controller and warrants their lawful basis.
KnoxCall may engage sub-processors. The current list is published at /legal/sub-processors. Customer authorises the addition of sub-processors on 30 days' prior notice (by email or in-app notification) and may object in writing within 14 days. If the parties cannot agree on a substitute, Customer may terminate the affected portion of the service for cause.
All sub-processors are bound by data-protection terms no less protective than this DPA.
KnoxCall maintains the security measures described in:
These include encryption at rest (AES-256-GCM envelope, per-tenant master keys, BYOK option), encryption in transit (TLS 1.2+), tamper-evident audit logging, MFA on every admin-UI user, RBAC + RLS for tenant isolation, vulnerability management, and an annual independent penetration test.
KnoxCall personnel processing Personal Data are bound by confidentiality obligations surviving termination and complete security & privacy training annually. Access is on the principle of least privilege and is reviewed quarterly.
KnoxCall provides self-service endpoints for the Controller's data subjects (data subject access requests and right-to-be-forgotten). Where Customer requires KnoxCall's assistance with a specific request, KnoxCall will respond within 10 business days; the 30-day GDPR clock remains the Controller's responsibility to manage end-to-end.
KnoxCall will notify Customer within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, providing:
Customer may, no more than once per year and on 30 days' notice, audit KnoxCall's compliance with this DPA. KnoxCall may satisfy the audit obligation by providing:
On-site audits at KnoxCall infrastructure require mutual agreement and are at the auditing Customer's cost.
Where Personal Data is transferred from the EEA, UK, or Switzerland to a third country, the SCCs apply. The Module is selected based on the parties' roles; the EU SCCs Module 2 (Controller-to-Processor) is the default when KnoxCall is processing on Customer's behalf. The UK IDTA applies for UK transfers; the Swiss FDPIC requirements apply for Swiss transfers.
Region pinning: Customer selects a primary region (us / eu / nz) at signup; data is stored and processed in that region except for resilience replicas as documented in the Trust Center.
On termination of the service, KnoxCall will, at Customer's choice and subject to reasonable export charges:
Cryptographic erasure for BYOK key material is irreversible.
Liability under this DPA is governed by the limitations of liability in the MSA.
In the event of conflict: MSA → this DPA → Privacy Policy.
Material changes to this DPA require 30 days' notice. Editorial / non-material updates may be made on notice via email or the admin UI.
Privacy / DPA matters: [email protected]
Data Protection Officer: [email protected]
Legal: [email protected]
Mail: KnoxCall Limited, Auckland, New Zealand