This Data Processing Addendum ("DPA") is part of the agreement between Virtual
Guardians, LLC ("Virtual Guardians," the "Processor") and the Customer identified in the
applicable order or subscription (the "Customer," the "Controller") for the Herald service
(the "Service"), and applies where Virtual Guardians processes Personal Data on the
Customer's behalf. It is incorporated into the Herald Terms of
Service or the parties' signed agreement (the "Agreement").
1. Definitions
"Personal Data," "processing," "controller," "processor," "data subject," and "personal
data breach" have the meanings given by applicable data protection law, including — where
applicable — the EU/UK General Data Protection Regulation ("GDPR") and the California
Consumer Privacy Act ("CCPA"). "Customer Data" means Personal Data that Virtual Guardians
processes on the Customer's behalf in providing the Service, as described in Annex A.
2. Roles and scope
The Customer is the controller (or a processor acting for another controller) of
Customer Data; Virtual Guardians is the Customer's processor (and, under the CCPA, a
"service provider").
Virtual Guardians will process Customer Data only to provide and support the Service
and only on the Customer's documented instructions — which are: the Agreement, this DPA,
and the Customer's configuration of the Service (which integrations are connected, which
users are licensed, which features are enabled) — unless processing is required by law, in
which case Virtual Guardians will notify the Customer unless prohibited.
Virtual Guardians will not sell Customer Data, share it for cross-context behavioral
advertising, retain, use, or disclose it for any purpose other than providing the Service
(including not combining it with other data except as permitted for service providers), and
will notify the Customer if it determines it can no longer meet these obligations.
Virtual Guardians may temporarily suspend processing where reasonably necessary to
protect the security, integrity, or availability of the Service or to comply with law,
with notice to the Customer where practicable.
3. Customer responsibilities
As the controller, the Customer is solely responsible for:
the legality of its collection and use of Personal Data processed through the
Service;
providing all required notices to, and obtaining all required consents from, data
subjects (including any notices or consents required for call monitoring, call recording,
or transcription);
ensuring it has the authority to connect the third-party services it connects to
Herald (its Webex organization, its CRM, and any other connected system);
determining which CRM fields, call transcripts, AI-generated notes, and other content
are processed through the Service, via its own configuration of those connected
systems;
complying with the privacy, employment, telecommunications, healthcare, and other laws
that apply to the Customer's business and its use of the Service.
Accuracy of displayed information. The Service identifies callers using telephone
numbers and data returned by the systems the Customer connects. Virtual Guardians does not
independently verify the accuracy, completeness, or currency of CRM records, caller
identification data, or AI-generated content. The Customer is responsible for verifying
displayed information before acting on it, and for reviewing AI-generated summaries and
notes before relying on them.
4. Third-party platforms and AI-generated content
Herald does not generate call transcripts or AI summaries. Such content is
created by Cisco Webex or other platforms the Customer has configured, under the
Customer's own settings and agreements with those providers. Herald processes that content
solely to transfer it to the Customer's designated CRM; it does not use it to train,
tune, or analyze any AI or machine-learning model.
Virtual Guardians is not responsible for, and this DPA does not make it liable for:
the Customer's CRM configuration or permissions; outages, errors, or API changes of Cisco
Webex, HubSpot or other CRM providers, Google Cloud, or any other third-party platform;
inaccurate, incomplete, or deleted data in the Customer's connected systems; or the
Customer's configuration of recording, transcription, or AI features in those systems.
5. Health information (HIPAA)
The Service is not intended to receive, store, or process Protected Health Information
("PHI") as defined by HIPAA, except where the Customer independently chooses to expose
such information through the systems it connects (for example, PHI the Customer keeps in
its own CRM fields or that appears in its own call transcripts).
Virtual Guardians is not a Covered Entity under HIPAA.
Where the Customer is a Covered Entity or Business Associate and its use of the
Service requires it, the parties will execute a separate Business Associate Agreement
(BAA) before the Customer exposes PHI to the Service. Contact
info@virtual-guardians.com to request one.
6. Confidentiality and vendor access
Virtual Guardians ensures that persons it authorizes to process Customer Data are bound by
confidentiality obligations and access Customer Data only as needed to provide the Service.
Administrative access is granted only to personnel with a legitimate business need, is
restricted and protected by multi-factor authentication, and every administrative action is
audit-logged.
7. Security
Virtual Guardians implements and maintains appropriate technical and organizational
measures to protect Customer Data, as described in Annex B. Virtual Guardians may update
these measures from time to time, provided the overall level of protection is not reduced.
The Service requests only the minimum third-party permissions (OAuth scopes) necessary to
perform its functions, and Herald never stores customer passwords — authentication to
connected platforms uses those platforms' own OAuth sign-in.
8. Subprocessors
The Customer authorizes the subprocessors listed in Annex C.
Virtual Guardians will notify Customer administrators at least 30 days before adding or
replacing a subprocessor. If the Customer reasonably objects on data-protection grounds and
the parties cannot resolve the objection, the Customer may terminate the affected
subscription with a pro-rated refund of prepaid fees.
Virtual Guardians remains responsible for its subprocessors' performance and will
impose data-protection obligations on them no less protective than this DPA.
For clarity, Cisco Webex and the Customer's CRM provider (e.g., HubSpot) are the
Customer's own service providers, contracted and configured by the Customer — they are data
sources/destinations the Customer connects to the Service, not Virtual Guardians
subprocessors.
9. Assistance and audits
Data subject requests. If Virtual Guardians receives a request from a data
subject relating to Customer Data, it will forward the request to the Customer and, taking
into account the nature of the processing, provide reasonable assistance so the Customer
can respond. Given Herald's short retention windows (Annex A), most personal data relating
to individual calls expires automatically within hours to days.
Compliance assistance. Virtual Guardians will provide reasonable assistance with
the Customer's security, breach-notification, and data-protection-impact obligations, and
will make available information reasonably necessary to demonstrate compliance with this
DPA.
Audits. Virtual Guardians may satisfy audit and information requests by
providing documentation, independent certifications and audit reports of its hosting
providers, completed security questionnaires, penetration-test summaries, or other
reasonable evidence. An on-site audit is available only where required by applicable law
or a supervisory authority, and then no more than once in any 12-month period, on at least
30 days' written notice, during normal business hours, at the Customer's expense, subject
to confidentiality obligations, and conducted so as not to disrupt the Service or expose
other customers' data.
10. Personal data breach
Virtual Guardians will notify the Customer without undue delay, and in any event within 72
hours, after confirming that a security incident constitutes a personal data breach affecting
Customer Data, and will provide information reasonably available to help the Customer meet
its notification obligations, and take reasonable steps to contain and remediate the breach.
Breach notices are sent to the Customer's administrator email addresses on file; the Customer
may designate a different security contact by writing to
info@virtual-guardians.com.
11. Government and legal requests
If Virtual Guardians receives a subpoena, court order, or other governmental demand for
Customer Data, it will notify the Customer before disclosure unless legally prohibited from
doing so, and will disclose only what it is legally required to disclose.
12. Return and deletion
Upon termination or expiration of the Agreement, Virtual Guardians will delete Customer
Data within 30 days, except for minimal records retained as required by law (which remain
protected by this DPA until deleted). Because call-level data expires automatically (Annex
A), deletion primarily covers tenant configuration, tokens, user records, and audit data.
Data the Service wrote into the Customer's own CRM remains in the Customer's CRM and is
unaffected by this section.
13. International transfers and data residency
The Service currently operates only within United States infrastructure: it is hosted and
operated in the United States (Google Cloud region us-east1). The Customer instructs Virtual
Guardians to process Customer Data in the United States. If applicable law requires a
transfer mechanism for Customer Data originating elsewhere, the parties will cooperate to put
an appropriate mechanism in place (e.g., standard contractual clauses).
14. Order of precedence; liability
If this DPA conflicts with the Agreement, this DPA controls for data-protection matters.
Each party's liability under this DPA is subject to the limitations and exclusions of
liability in the Agreement, and nothing in this DPA makes Virtual Guardians liable for the
third-party and Customer-controlled matters described in Sections 3 and 4.
Annex A — Details of processing
Subject matter
Providing the Herald screen-pop and CRM-integration service for the Customer's Webex Calling users.
Duration
The term of the Agreement, plus the deletion period in Section 12.
Nature and purpose
Receiving inbound-call notifications; matching callers against the Customer's CRM; displaying results to the answering user; (Pro tier) logging calls, outcomes, and Webex-generated transcripts/AI notes to the Customer's CRM; administering users, licenses, and integrations.
Categories of data subjects
The Customer's users (agents, administrators) and the individuals who call them or appear in the Customer's CRM (customers, prospects, other contacts).
Categories of Personal Data
Caller phone numbers and network-provided names; call metadata (identifiers, timestamps, durations, outcome); CRM records selected by the Customer via its CRM configuration (e.g., contact name, title, company, lifecycle stage, record owner, and related records the Customer's CRM returns); Webex-generated call transcript/AI-note text (created by the Customer's connected platforms, processed transiently in transit, stored only in the Customer's CRM); user identifiers (name, work email, Webex IDs); OAuth tokens (encrypted); diagnostic and audit logs.
Special categories
None intended. The Service does not request special-category data; incidental content within CRM fields or call transcripts is controlled by the Customer's own configuration and data. See Section 5 for health information.
Retention
Pop delivery events expire 10 minutes after the call; per-call records ≈24 hours (automated deletion completes within ~24 hours of expiry); operational logs ≈30 days; tokens until revoked/offboarded; tenant configuration, license, and audit records for the subscription term. Details in the Privacy Policy.
Annex B — Technical and organizational measures
Encryption in transit (HTTPS/TLS) for all interfaces; webhook authenticity verified via HMAC signatures.
OAuth tokens encrypted at rest (AES-256-GCM); encryption keys and secrets held in Google Secret Manager, not in code or configuration files. Tokens are revoked and deleted upon customer disconnect, user deprovisioning, or authorization revocation. No customer passwords are stored by Herald.
Least-privilege OAuth scopes requested from connected platforms; per-tenant isolation of CRM credentials and configuration.
Vendor administrative console protected by identity-pinned sign-in plus multi-factor authentication; administrative access limited to personnel with a legitimate business need; all administrative and vendor actions audit-logged.
Automatic expiry (TTL) of call-level data; no storage of call audio.
Operational logs are minimized: they contain tenant and call identifiers, timestamps, and processing/API status, with caller numbers redacted to their last four digits — never call transcripts, CRM notes or contact details, or full phone numbers.
Hosting on Google Cloud Platform (SOC 2 / ISO 27001 audited infrastructure), single region us-east1; infrastructure access restricted to authorized personnel. Operating-system and runtime patching, physical security, and infrastructure resilience are provided by the managed platform (serverless containers, managed database).
Vulnerability management: automated dependency scanning on the source repository; dependencies and base images updated as part of the release process.
Backups and disaster recovery: durable configuration and license data is stored in Google Cloud Firestore with the platform's built-in replication and point-in-time recovery; the Service is redeployable from source control to restore operations.
Source control, code review, automated tests, and CI checks for changes to the Service.
Annex C — Authorized subprocessors
Subprocessor
Purpose
Location
Google LLC (Google Cloud Platform)
Cloud hosting, data storage, secret management, logging (currently Cloud Run, Firestore, Secret Manager, and Cloud Logging, including successor products)
United States (us-east1)
Contact
Virtual Guardians, LLC
1608 Queen Street #21, Wilmington, NC 28401, USA info@virtual-guardians.com ·
(910) 530-1600