Data Processing Agreement (DPA)
Last Updated: March 2026
This Data Processing Agreement ("DPA") is entered into between Ortuas LLC ("Processor") and the client ("Controller") and forms part of the Terms of Service between the parties. This DPA applies where Ortuas processes personal data on behalf of the client in connection with the Services.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal data, including collection, storage, use, transmission, and deletion.
- "Controller" means the client who determines the purposes and means of processing personal data.
- "Processor" means Ortuas, which processes personal data on behalf of the Controller.
- "Sub-processor" means any third party engaged by Ortuas to process personal data.
- "Data Subject" means the individual whose personal data is being processed.
2. Scope and Purpose
Ortuas processes personal data solely for the purpose of providing the Services described in the Terms of Service, including operating AI voice agents, managing appointment scheduling, and delivering SMS and call automation on behalf of the client. Ortuas will not process personal data for any other purpose without the client's prior written consent.
3. Client Obligations
As the Controller, the client agrees to:
- Ensure that all personal data provided to Ortuas has been collected lawfully and that all required consents are in place
- Provide Ortuas with all information necessary to fulfill data subject rights requests
- Notify Ortuas immediately of any data subject rights requests, complaints, or regulatory inquiries related to data processed through Ortuas
- Comply with all applicable data protection laws in connection with the client's use of the Services
4. Ortuas Obligations
As the Processor, Ortuas agrees to:
- Process personal data only on the documented instructions of the client
- Ensure that all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, or destruction
- Notify the client without undue delay (and no later than 72 hours) upon becoming aware of a personal data breach
- Assist the client in responding to data subject rights requests (access, correction, deletion, portability) to the extent technically feasible
- Delete or return all personal data to the client upon termination of the Services, unless retention is required by law
- Make available all information necessary to demonstrate compliance with this DPA upon reasonable request
5. Sub-processors
Ortuas currently uses the following categories of sub-processors to deliver the Services:
- CRM and Workflow Automation: GoHighLevel (GHL)
- Analytics: Google Analytics
- Advertising: Google Ads
- Communication Infrastructure: Twilio (SMS and voice)
- AI Voice Processing: Third-party AI voice providers integrated via GHL
Ortuas will notify the client of any material changes to its sub-processor list. The client may object to a new sub-processor within 14 days of notification. A full sub-processor list is available upon request at [email protected].
6. International Data Transfers
If personal data is transferred outside of the European Economic Area (EEA) or the United Kingdom, Ortuas will ensure that such transfers are made in compliance with applicable data protection laws, including through the use of Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
7. Data Subject Rights
Ortuas will assist the client in fulfilling data subject rights requests under GDPR, CCPA, and applicable state privacy laws, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to object to processing
- Right to opt out of sale or sharing of personal data
To submit a data subject rights request, data subjects should contact the client directly. The client may then contact Ortuas at [email protected] for assistance.
8. Security Measures
Ortuas implements the following technical and organizational security measures:
- Encryption of data in transit using TLS 1.2 or higher
- Access controls limiting data access to authorized personnel only
- Regular security assessments and vulnerability testing
- Incident response procedures including breach notification protocols
9. HIPAA
For clients in healthcare or medical industries, Ortuas is available to execute a separate Business Associate Agreement (BAA) as required under HIPAA. This DPA does not constitute a BAA. To request a BAA, contact [email protected] before transmitting any Protected Health Information (PHI) through the Services.
10. Term and Termination
This DPA remains in effect for the duration of the Terms of Service. Upon termination, Ortuas will delete or return all personal data within 30 days unless retention is required by applicable law.
11. Contact
For questions about this DPA or to request a signed copy, contact:
Ortuas LLC
13359 N Highway 183, Suite 406-171
Austin, TX 78750
Email: [email protected]