AlefOS Legal Center
Data Processing Agreement
The public data processing terms that apply when AlefOS processes business data on behalf of a customer.
1. What this agreement covers
This DPA defines how AlefOS handles personal data on your behalf. It supplements the Terms of Service and overrides them on data protection matters.
This Data Processing Agreement ('DPA') sets out the conditions under which AlefOS processes personal data on behalf of the Customer in connection with services provided through the AlefOS product.
This DPA applies to all processing of personal data carried out by AlefOS as Processor where the Customer determines the purposes and essential means of the processing in the course of its professional activity.
This DPA forms an integral part of the Terms of Service and any contractual relationship entered into between:
MyBot Ltd
Israeli company registration number 516373891
Ashkelon, Israel
Email: support@alefos.ai
Data Protection Contact: MyBot Ltd
(hereinafter 'AlefOS' or the 'Processor')
and the business customer using AlefOS in the course of its activity, including any artisan, professional tenant, company, operator, or contracting entity (hereinafter the 'Customer' or the 'Controller').
2. Where this fits in the contract stack
The DPA sits above the Terms of Service on data matters. If there's a conflict, the DPA wins.
This DPA supplements the Terms of Service and Privacy Policy applicable to the AlefOS service.
In the event of conflict between this DPA and the Terms of Service, this DPA shall prevail for any matter relating to the processing of personal data carried out on behalf of the Customer.
3. Key definitions
Plain language versions of the GDPR terms used throughout this document.
For the purposes of this DPA:
a) 'Personal Data' means any information relating to an identified or identifiable natural person;
b) 'Processing' means any operation or set of operations performed on personal data, whether or not by automated means;
c) 'Controller' means the entity that determines the purposes and means of processing;
d) 'Processor' means the entity that processes personal data on behalf of the Controller;
e) 'Data Subject' means the natural person to whom the personal data relates;
f) 'Personal Data Breach' means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;
g) 'Applicable Law' means any applicable rule relating to data protection, including where relevant Regulation (EU) 2016/679, Israeli privacy law, and any other mandatory applicable rule.
4. Who does what
You determine the purposes. We execute. You alone decide what's lawful and what your contacts are told.
4.1 The Customer acts as Controller for all personal data processed in connection with its professional use of AlefOS.
4.2 AlefOS, operated by MyBot Ltd, acts exclusively as Processor and provides technical infrastructure for intake, processing, transcription, structuring, delivery, and management of operational flows.
4.3 The parties acknowledge that the Customer alone determines:
a) the purposes of its activities;
b) the nature of the data collected in the context of its professional relationships;
c) the lawfulness of call recording, transcription, follow-up, and communications;
d) the categories of data subjects;
e) the legal basis applicable to each processing activity initiated in its operations.
5. What we actually do with your data
We receive calls, transcribe them, generate signals, manage messages, and create contact profiles — on your behalf, for the service you activated.
5.1 AlefOS processes personal data solely for the purpose of providing the service to the Customer.
5.2 Processing operations may include, in particular:
a) intake and routing of call flows and signals;
b) temporary recording of audio content where enabled;
c) automated transcription of conversations;
d) transformation of operational flows into signals, missions, relationship statuses, PION elements, or other outputs;
e) management of inbox messages and group messages;
f) creation and maintenance of relationship profiles, including Ghost or Phantom profiles where the Customer uses that mechanism;
g) hosting, security, technical logging, maintenance, support, and operations strictly necessary for performing the service.
5.3 AlefOS does not process the Customer's data for the Customer's own business purposes, except where strictly necessary for AlefOS's own distinct purposes of security, billing, compliance, defense of rights, technical improvement, or contractual performance, in which case AlefOS acts as controller for those separate purposes.
6. Duration
We process your data for as long as your contract is active — and as required by law after it ends.
Processing is carried out for the duration of the contractual relationship between the Customer and AlefOS, subject to the technical and operational retention periods applicable to the service and to any legal obligations relating to retention, security, evidence, or defense of rights.
7. What data is processed
Identity, calls, messages, transcripts, signals, logs — whatever the service needs to function based on how you use it.
Depending on the Customer's use, processed categories of personal data may include:
a) identification data, including name, surname, phone number, company name, role, and contact identifier;
b) communication data, including inbound and outbound calls, communication metadata, inbox messages, group messages, timestamps, duration, and call direction;
c) call audio content, where recording is enabled;
d) transcripts derived from audio content;
e) relationship and tracking data, including operational signals, PION signals, missions, statuses, relationship histories, and Ghost or Phantom profiles;
f) technical, access, and security data, including logs, IP addresses, session identifiers, browser or device environment data;
g) any other data entered, imported, generated, or transmitted by the Customer in the course of using the service.
8. Who the data is about
Your clients, your callers, your team, your Ghost contacts — anyone whose data flows through your use of AlefOS.
Data subjects may include, in particular:
a) the Customer's customers, prospects, business contacts, and interlocutors;
b) callers, recipients, inbound or outbound contacts;
c) the Customer's collaborators, employees, representatives, agents, or contractors;
d) authorized users of the service;
e) Ghost, Phantom, or silent contacts resulting from relevant phone interactions;
f) any other person whose data is introduced by the Customer into the service.
9. We only do what you tell us
AlefOS processes data only based on documented instructions — your configuration, the Terms, this DPA. We'll flag it if something seems illegal.
9.1 AlefOS shall process personal data only on documented instructions from the Customer, as resulting from:
a) this DPA;
b) the Terms of Service;
c) the features activated and configured by the Customer in the service;
d) any additional written instruction agreed between the parties.
9.2 If AlefOS considers that an instruction infringes Applicable Law, AlefOS may inform the Customer and suspend execution of the relevant instruction to the extent reasonably necessary.
10. Your obligations as controller
You must have the legal right to submit this data, inform people when required, and handle requests from your contacts yourself.
The Customer represents, warrants, and undertakes that it shall:
a) have all rights, authority, permissions, and legal bases necessary to entrust personal data to AlefOS;
b) provide notice to data subjects in accordance with Applicable Law;
c) ensure the lawfulness of recording, transcription, analysis, and relationship communications;
d) respond to requests from data subjects where it acts as Controller;
e) not use the service in any unlawful manner or contrary to applicable regulation;
f) not provide AlefOS with instructions that are manifestly contrary to Applicable Law.
11. Confidentiality within our team
Everyone at AlefOS with access to your data is bound by a confidentiality obligation — contractual or statutory.
AlefOS shall ensure that persons authorized to process personal data are subject to an appropriate duty of confidentiality or a suitable statutory confidentiality obligation.
12. How we secure your data
Access controls, authentication, logging, encryption, rate limiting, tenant isolation. We act on risks, not just policies.
12.1 AlefOS shall implement appropriate technical and organizational measures taking into account the nature of the processing and reasonably identified risks.
12.2 Such measures may include, as appropriate:
a) logical access control;
b) authentication and permissions management;
c) technical logging;
d) retention limitation;
e) infrastructure, environment, and flow security;
f) monitoring, maintenance, patching, and resilience measures appropriate to the service;
g) access limitation on a need-to-know basis.
12.3 The Customer acknowledges that no security measure guarantees the complete absence of risk.
13. Sub-processors we use
By using AlefOS you authorize us to use these providers. We make sure they're bound by appropriate data protection obligations.
13.1 The Customer authorizes AlefOS to engage onward sub-processors and technical service providers required for operation of the service.
13.2 As of the date of this DPA, the identified sub-processors and technical providers include:
— AWS (Amazon Web Services): storage and infrastructure, regions Israel (il-central-1) and EU Paris (eu-west-3)
— Railway: application hosting and managed database
— Hetzner: infrastructure services
— Firebase (Google LLC): authentication and session management
— OpenAI / Whisper: AI transcription and signal processing
— DIDWW: telephony and SIP services
— Telnyx: telephony services and number portability
— RunPod: compute infrastructure for AI workloads
13.3 AlefOS shall ensure that its onward sub-processors are bound by appropriate contractual obligations regarding confidentiality, security, and data protection to a degree compatible with the nature of the services provided.
13.4 AlefOS may update this list and replace providers with reasonably comparable providers as operational needs require.
14. Cross-border transfers
Some providers are outside the EU. We use Standard Contractual Clauses or equivalent mechanisms to cover those transfers.
14.1 The Customer acknowledges that the service infrastructure may involve cross-border processing or access.
14.2 Where required by Applicable Law, AlefOS shall implement an appropriate transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, or any other recognized safeguard.
15. We help you meet your obligations
If you need our help handling a rights request, a breach notification, or a DPIA — we'll assist. Complex or time-intensive requests may be charged separately.
Taking into account the nature of the processing and to the extent reasonably possible, AlefOS shall assist the Customer by appropriate technical and organizational means in enabling the Customer to comply with obligations relating to:
a) data subject rights requests;
b) security of processing;
c) notification and management of personal data breaches;
d) data protection impact assessments, where required;
e) prior consultation with a supervisory authority, where applicable.
Such assistance may be provided on reasonable terms and may, where applicable, be separately charged if the request exceeds standard support.
16. If someone contacts us about their data
If someone asks AlefOS directly about data you control, we'll forward the request to you. We don't answer on your behalf unless you authorize us to.
16.1 Where AlefOS directly receives a request from a data subject concerning processing carried out on behalf of the Customer, AlefOS may, to the extent permitted by Applicable Law:
a) forward the request to the Customer;
b) invite the data subject to contact the Customer directly;
c) assist the Customer in handling the request.
16.2 AlefOS shall not respond substantively to such request except on the Customer's instruction or where otherwise required by law.
17. If there's a data breach
We'll notify you without undue delay — with enough detail for you to assess your own obligations and decide what to report to regulators.
17.1 AlefOS shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting personal data processed on behalf of the Customer, to the extent such breach is likely to require action by the Customer under Applicable Law.
17.2 Such notification shall include, to the extent available and reasonably possible, relevant information enabling the Customer to assess the breach and its obligations.
18. What happens to your data when the contract ends
We delete it — subject to the service's retention timelines and any legal obligation to keep it longer.
18.1 Upon termination of the contractual relationship, AlefOS shall delete or render inaccessible personal data processed on behalf of the Customer, unless retention is required by law, security necessity, evidentiary need, or another legitimate basis requiring limited retention.
18.2 The service's operational retention rules remain applicable during contract performance, including:
a) raw audio can be processed from a transmitted file, URL, provider flow or call feature where enabled, and retention depends on the source and configuration;
b) raw transcripts may be neutralized or deleted according to configured retention rules, while summaries, signals, missions and operational metadata may be retained as business memory where needed;
c) inbox message bodies: according to configured body TTL;
d) group messages: according to configured group retention rules;
e) PION signals: for the duration of the active relationship;
f) Ghost or Phantom contacts: while the relevant relationship signal remains active.
19. Audit rights
You can ask us to demonstrate compliance. We'll provide documentation, written responses, or certifications. On-site audits require reasonable notice and justification.
19.1 Upon reasonable request from the Customer, and subject to confidentiality, security, trade secret protection, and proportionality, AlefOS may provide information reasonably necessary to demonstrate compliance with this DPA.
19.2 Any on-site or intrusive audit request must be reasonable, strictly necessary, compatible with service security, subject to sufficient prior notice, and, unless otherwise required by law, limited to a reasonable frequency.
19.3 AlefOS may satisfy this obligation by providing documents, written responses, available certifications, technical summaries, or other appropriate evidence.
20. Ghost and Phantom contacts — your responsibility
We build and maintain the Ghost profiles on your instructions. You remain the controller — and the one responsible for verifying it's lawful where you operate.
20.1 The Customer acknowledges that the service may create silent, Ghost, or Phantom profiles before a person formally registers, based on an inbound call or other interaction relevant to the professional relationship.
20.2 In connection with this mechanism:
a) the purpose pursued by the Customer is relationship continuity and maintenance of useful operational follow-up;
b) AlefOS acts as processing infrastructure;
c) such profiles do not constitute active user accounts;
d) notice under Article 14 GDPR may be provided through an automatic SMS footer linking to alefos.ai/privacy;
e) relationship maintenance SMS messages may be issued at 14, 28, and 84 days, without marketing purpose under the standard service configuration.
20.3 The Customer remains solely responsible for verifying that this mechanism, its legal basis, its messages, and its use are lawful in the relevant jurisdictions.
21. Liability split
Each party is liable for its own breaches. Your communications, your legal bases, your content — your responsibility. Our infrastructure security — our responsibility.
21.1 Each party shall be responsible for its own failures to comply with obligations incumbent on it under Applicable Law.
21.2 The Customer remains solely responsible for the purposes, legal bases, content, communications, messages, calls, and decisions it initiates or operates using the service.
21.3 AlefOS's liability under this DPA is subject to the liability limitations set out in the Terms of Service, except where prohibited by mandatory Applicable Law.
22. Governing law
Same as the Terms of Service: Israeli law, courts of Israel, unless your local mandatory rules say otherwise.
This DPA shall be governed by the law specified in the Terms of Service, unless mandatory data protection law requires otherwise.
Any dispute relating to this DPA shall be subject to the jurisdiction specified in the Terms of Service, subject to any mandatory applicable forum.
23. Final provisions
One bad clause doesn't invalidate the rest. This DPA is active for as long as we process data on your behalf.
23.1 If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in effect.
23.2 This DPA enters into force on the effective date of the contractual relationship between the Customer and AlefOS.
23.3 This DPA remains applicable for as long as AlefOS processes personal data on behalf of the Customer.