Automatically incorporated. This Data Processing Addendum applies when WrenchRelay processes personal data on behalf of a Customer under the WrenchRelay Terms of Service or another written agreement that incorporates it.
1. Parties and scope
This Data Processing Addendum (“DPA”) is entered into between the Customer identified in the applicable subscription, order, or account and AzVa Enterprises LLC, doing business as WrenchRelay(“WrenchRelay”). It supplements the WrenchRelay Terms of Service or other agreement governing the Service (the “Agreement”).
This DPA applies only to Customer Personal Data that WrenchRelay processes on Customer’s behalf in providing automated call intake, call routing, recording, transcription, structured extraction, summaries, notifications, dashboard access, support, and related services.
If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls. Capitalized terms not defined here have the meanings given in the Agreement.
2. Definitions
- “Applicable Data Protection Law” means privacy, data protection, and data security laws that apply to WrenchRelay’s processing of Customer Personal Data under the Agreement.
- “Customer Personal Data” means personal data, personal information, or a similar protected category contained in Customer Data and processed by WrenchRelay on Customer’s behalf.
- “Controller,” “processor,” “business,” “service provider,” “contractor,” “consumer,” “data subject,” “process,” and “personal data” have the meanings given by Applicable Data Protection Law.
- “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in WrenchRelay’s possession or control. It excludes unsuccessful attempts that do not compromise Customer Personal Data.
- “Subprocessor” means a third party engaged by WrenchRelay to process Customer Personal Data on Customer’s behalf.
3. Roles and instructions
Customer is the controller or business and WrenchRelay is the processor, service provider, or contractor for Customer Personal Data, except where Applicable Data Protection Law assigns a different role. Customer determines the purposes of processing and is responsible for its legal basis, notices, consents, instructions, retention choices, and responses to individuals.
WrenchRelay will process Customer Personal Data only:
- to provide and support the Service under the Agreement;
- on Customer’s documented instructions, including account configuration and user actions;
- to protect the security and integrity of the Service;
- as needed to comply with applicable law; or
- as otherwise permitted by Applicable Data Protection Law.
The Agreement, this DPA, Customer’s configuration, and authorized use of the Service constitute Customer’s documented instructions. If WrenchRelay believes an instruction violates Applicable Data Protection Law, it may suspend the affected processing and notify Customer unless legally prohibited.
4. Customer obligations
Customer represents and warrants that:
- it has the right and legal basis to provide Customer Personal Data to WrenchRelay;
- its notices and consents adequately cover automated interaction, recording, transcription, analysis, storage, and disclosure to WrenchRelay and its Subprocessors;
- its instructions comply with Applicable Data Protection Law;
- it will not use the Service to collect highly sensitive information that the Service is not designed to handle; and
- it will limit account access to authorized personnel and use reasonable safeguards for credentials, devices, exports, and notifications.
Customer is responsible for determining whether the Service is appropriate for its intended processing and for configuring retention, access, disclosures, and workflows accordingly.
5. Confidentiality and personnel
WrenchRelay will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary to perform their duties. WrenchRelay will maintain appropriate access controls and take reasonable steps to ensure personnel follow this DPA.
6. Security measures
WrenchRelay will maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of Customer Personal Data and the risks of processing. Measures may include:
- encryption in transit using industry-standard protocols;
- managed hosting and database security controls;
- authentication, role-based authorization, and least-privilege access;
- separation of customer records through application and database controls;
- logging, monitoring, backups, and availability safeguards;
- secret and credential management;
- change control, dependency maintenance, and vulnerability response;
- provider due diligence and contractual data-protection requirements; and
- incident response and recovery procedures.
Security is a shared responsibility. Customer must secure its own telephone systems, forwarding configuration, credentials, devices, email accounts, exports, and authorized-user access.
7. Subprocessors
Customer generally authorizes WrenchRelay to engage Subprocessors needed to provide the Service. WrenchRelay will require each Subprocessor to protect Customer Personal Data under obligations that are materially consistent with this DPA for the services it performs.
Current core Subprocessors and service categories are listed in Schedule 2 below. WrenchRelay may add or replace Subprocessors as the Service evolves. We will update the published list and, where required by Applicable Data Protection Law or a separate written agreement, provide advance notice of a material new Subprocessor.
Customer may object to a new Subprocessor on reasonable data-protection grounds by contacting support@wrenchrelay.com within 15 days after notice. The parties will work in good faith on a commercially reasonable solution. If no solution is available, WrenchRelay may allow Customer to discontinue the affected Service without penalty for the unused prepaid portion.
8. Individual rights requests
Taking into account the nature of processing, WrenchRelay will provide reasonable assistance to Customer in responding to verified requests to access, correct, delete, obtain a copy of, or exercise other applicable rights concerning Customer Personal Data.
If WrenchRelay receives a request directly from an individual concerning Customer Personal Data, WrenchRelay may refer the individual to Customer and will not independently fulfill the request unless required by law or authorized by Customer. Customer is responsible for deciding whether a request is valid and for communicating with the individual.
WrenchRelay may charge reasonable fees for assistance that is unusually burdensome, repetitive, or outside standard Service functionality, after notifying Customer in advance.
9. Compliance assistance
Taking into account the nature of processing and information available to WrenchRelay, we will provide reasonable assistance with Customer’s obligations concerning security, breach notifications, data-protection assessments, and consultations with regulators where required by Applicable Data Protection Law.
Customer remains responsible for its legal compliance and for determining whether a data protection assessment, consent mechanism, or regulator consultation is required.
10. Security Incidents
WrenchRelay will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice may be provided to the account owner or another designated contact and will include information reasonably available to WrenchRelay about the nature of the incident, affected data, likely consequences, and mitigation steps.
WrenchRelay will take reasonable steps to contain, investigate, and remediate the Security Incident and will provide reasonable cooperation. Notification is not an admission of fault or liability. Customer is responsible for determining whether notice to individuals, regulators, insurers, or others is legally required.
11. Government and legal requests
If WrenchRelay receives a legally binding request for Customer Personal Data, we will disclose only information we reasonably believe is required. Where lawful, we will notify Customer and provide an opportunity to seek protection. WrenchRelay may challenge a request that it reasonably believes is unlawful or overbroad but is not obligated to litigate at its own expense.
12. Return and deletion
During the subscription, Customer may access or export Customer Personal Data through available Service features. Upon termination or Customer’s documented request, WrenchRelay will delete or return Customer Personal Data within a commercially reasonable period, unless retention is required by law or reasonably necessary for security, fraud prevention, billing, dispute resolution, or enforcement of the Agreement.
Customer Personal Data may remain in encrypted or access-restricted backups until overwritten under normal backup cycles. During that period, WrenchRelay will not use the data except for restoration, security, legal compliance, or disaster recovery.
13. Information and audits
Upon reasonable written request, WrenchRelay will provide information reasonably necessary to demonstrate compliance with this DPA, such as summaries of relevant policies, safeguards, provider controls, or independent reports that become available.
If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request one no more than once per year, unless a confirmed Security Incident or regulator requires otherwise. Audits must occur during normal business hours, avoid disruption, protect other customers and confidential systems, use an independent qualified auditor, and be subject to confidentiality. Customer bears audit costs unless the audit identifies a material breach by WrenchRelay.
14. Processing locations and international transfers
The Service is operated primarily for United States customers. Customer Personal Data may be processed in the United States and other locations where WrenchRelay or its Subprocessors operate. Customer authorizes those transfers subject to this DPA and Applicable Data Protection Law.
If the parties later require a specific international transfer mechanism, they will cooperate in good faith to implement an appropriate addendum or standard contractual terms before the affected transfer.
15. United States state privacy terms
To the extent a United States state privacy law applies and WrenchRelay processes Customer Personal Data as a service provider, contractor, or processor, WrenchRelay will:
- process the data only for the limited and specified purposes in the Agreement and this DPA;
- not sell Customer Personal Data or share it for cross-context behavioral advertising;
- not retain, use, or disclose it outside the direct business relationship except as permitted by law;
- not combine it with personal information from unrelated sources except as permitted by law;
- provide the same level of privacy protection required by the applicable law;
- notify Customer if WrenchRelay can no longer meet an applicable legal obligation; and
- permit Customer to take reasonable steps to stop and remediate unauthorized processing.
16. Liability and termination
The liability limitations, exclusions, indemnities, governing law, and dispute terms in the Agreement apply to this DPA. A material breach of this DPA is a material breach of the Agreement.
This DPA remains effective while WrenchRelay processes Customer Personal Data and survives termination of the Agreement for as long as WrenchRelay retains that data.
Schedule 1 — Processing details
Subject matter
Automated intake and organization of telephone calls forwarded by Customer, including routing, voice interaction, recording, transcription, extraction, classification, summarization, notification, dashboard presentation, support, and security.
Duration
The subscription term and any limited retention period described in the Agreement, Privacy Policy, Customer configuration, or documented instructions.
Nature and purpose
Receiving calls, collecting caller-provided information, preparing an actionable message for Customer, facilitating shop follow-up, maintaining service records, securing the Service, and providing support.
Categories of individuals
- callers and prospective or existing repair-shop customers;
- vehicle owners, drivers, family members, fleet contacts, vendors, and other message subjects;
- Customer’s owners, employees, contractors, and authorized account users; and
- people who contact WrenchRelay for support or account administration.
Categories of personal data
- names, telephone numbers, email addresses, and business contact details;
- call audio, transcripts, timestamps, duration, routing, and caller-ID information;
- vehicle year, make, model, and caller-provided vehicle details;
- service requests, symptoms, timing preferences, status questions, and messages;
- record-associated names and relationship information voluntarily provided;
- automated summaries, classifications, extracted fields, and workflow records;
- account identifiers, permissions, audit records, and support communications; and
- device, IP, browser, security, diagnostic, and email-delivery information.
Sensitive data
The Service is not designed to intentionally process government identifiers, complete payment credentials, account passwords, medical records, biometric identification templates, or other highly sensitive data. Callers may nevertheless volunteer information, and Customer is responsible for minimizing and appropriately handling such disclosures.
Schedule 2 — Core providers and Subprocessors
- Twilio — telephony, call routing, telephone numbers, and communications infrastructure.
- ElevenLabs — automated voice interaction, speech processing, transcription, and call analysis.
- Supabase — hosted database, authentication, storage, and related backend services.
- Vercel — application hosting, serverless execution, delivery, logs, and web infrastructure.
- Resend — transactional email delivery and delivery-status processing.
- Stripe — subscription billing and payment processing; Stripe may act independently for certain payment data.
- Telecommunications carriers — network interconnection, forwarding, and call transport.
Provider names, functions, and processing locations may change. This published schedule is the current general authorization list and will be updated when core providers materially change.
17. Data protection contact
Questions about this DPA, Subprocessors, or data-protection assistance may be sent to support@wrenchrelay.com.