Presence
Solutions ▾
  • Sales teamsEvery call logged, every rep coached
  • StartupsA US number before you have a US office
  • AgenciesA number your clients can always reach
  • Home servicesPlumbers, electricians, repairs
  • Manufacturing and suppliersQuotes and specs captured from the call
  • E-commerceA real number on your store
PricingSign inGet a number

Data processing addendum

Last updated 7 October 2026

In short. When your business’s calls, texts and contacts pass through Presence, we process them only to provide the service and only on your instructions. This addendum sets out our promises about that, including security, sub-processors, breach notice and transfers out of Europe, and it applies automatically; nobody needs to sign it.

1. Scope and how this addendum applies

1.1 This Data Processing Addendum (“DPA”) forms part of the Terms of service (the “Agreement”) between Redstone Castle LLC, a New York limited liability company (“Presence”, “we”), and the customer (“Customer”, “you”). It applies whenever we process Customer Personal Data in providing the Service and a Data Protection Law applies to that processing. It takes effect without signature when you accept the Agreement.

1.2 If this DPA conflicts with the Agreement, this DPA governs on the processing of personal data. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses govern.

2. Definitions

  • “Data Protection Law” means, to the extent it applies to the processing: the EU General Data Protection Regulation 2016/679 (“GDPR”); the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended by the California Privacy Rights Act, and its regulations (“CCPA”); and other US state consumer privacy laws.
  • “Customer Personal Data” means personal data in Customer Content that we process on your behalf.
  • “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in our or our sub-processors’ systems.
  • “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
  • “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
  • “Controller”, “processor”, “data subject”, “personal data”, “processing”, “business”, “service provider”, “sell”, “share” and “consumer” have the meanings given in the applicable Data Protection Law. Other capitalized words have the meanings in the Agreement.

3. Roles

3.1 For Customer Personal Data, you are the controller (or a processor acting for your own controller) and we are your processor (or sub-processor). Under the CCPA, you are the business and we are your service provider.

3.2 For account, billing and website information about you and your Users, we are an independent controller, and our Privacy Policy applies, not this DPA.

3.3 You are responsible for the lawfulness of the Customer Personal Data and of your instructions, including having a legal basis for the processing and giving the notices and obtaining the consents Data Protection Law and recording and telecommunications laws require.

4. Processing only on your instructions

4.1 We process Customer Personal Data only on your documented instructions, unless the law requires otherwise, in which case we will tell you first unless the law forbids it. Your instructions are: the Agreement and this DPA; your use and configuration of the Service, including turning on recording, transcription, AI notes, texting and integrations; and any other reasonable written instructions you give us that are consistent with the Agreement.

4.2 We will tell you if, in our opinion, an instruction breaks Data Protection Law. We are not required to follow such an instruction.

4.3 The subject matter, nature, purpose and duration of the processing, and the types of personal data and data subjects, are described in Annex 1.

5. Confidentiality

We ensure that everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality. Today, only the two people who run Presence have access to production systems.

6. Security

We implement and maintain the technical and organizational measures in Annex 2, which are designed to protect Customer Personal Data against Security Incidents, taking into account the state of the art, the cost of implementation and the risks of the processing. We may update those measures, but will not materially reduce the overall protection they give.

7. Sub-processors

7.1 You give us general authorization to use sub-processors. Our current sub-processors are listed on our sub-processor page.

7.2 We bind each sub-processor by written contract to data-protection obligations that are no less protective than this DPA, to the extent relevant to its service, and we remain responsible to you for its performance of them.

7.3 We will email account owners at least 14 days before a new sub-processor starts processing Customer Personal Data. You may object on reasonable data-protection grounds by emailing support@redstonecastles.com within that period. We will then discuss your concerns in good faith. If we cannot resolve them, you may end the Agreement for the affected Service by notice, and we will refund the prepaid Fees for the period after it ends.

7.4 Third-Party Services that you connect, such as HubSpot or Apollo, are not our sub-processors. Data you send to them is processed under your own agreements with them.

8. Helping you with data subject requests

Taking into account the nature of the processing, we will help you by appropriate technical and organizational measures, as far as reasonably possible, to answer requests from data subjects to exercise their rights. If we receive a request directly that relates to Customer Personal Data, we will pass it to you without undue delay and will not answer it ourselves except to direct the requester to you, unless the law requires otherwise. Admins can export contacts and calls with their notes and transcripts from Settings; for anything else, email support@redstonecastles.com.

9. Security Incidents

9.1 We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data.

9.2 The notice will describe, as far as we then know, the nature of the incident, the categories and approximate number of data subjects and records affected, its likely consequences, and the measures taken or proposed. Where we cannot give all of this at once, we will give it in stages as it becomes available.

9.3 We will take reasonable steps to contain and investigate the incident and reduce its effects, and will reasonably help you meet your own obligations to notify authorities and data subjects. Our notice is not an admission of fault.

10. Other assistance

Taking into account the nature of the processing and the information available to us, we will give you reasonable help with data protection impact assessments and prior consultations with authorities that the law requires of you in relation to the Service, mainly by giving you the information in this DPA and its annexes.

11. Deletion and return

11.1 Before the Agreement ends, you can export Customer Personal Data as described in Section 8, and ask us for copies of recordings and voicemails.

11.2 When your account closes, we delete Customer Personal Data from our live systems within 30 days. Copies in backups are deleted within 14 days after that, and technical logs within 90 days. We may keep Customer Personal Data where the law requires it, and will keep protecting it under this DPA and process it only for the purpose for which the law requires us to keep it.

12. Information and audits

12.1 We will make available to you the information reasonably necessary to show that we meet this DPA. We will start by answering your reasonable written questions and providing our security documentation.

12.2 If that is not enough to show compliance, or an authority requires it, you may audit our compliance, through yourself or an independent auditor bound by confidentiality, no more than once a year (unless a Security Incident or an authority requires it), on at least 30 days’ written notice, during business hours, without disrupting the Service or accessing other customers’ data. You bear the cost of the audit. We are not required to give access to our sub-processors’ facilities; instead we will share what they make available to us.

13. International transfers

13.1 We process Customer Personal Data in the United States. You authorize that transfer and onward transfers to our sub-processors, provided they meet this Section.

13.2 Transfers from the European Economic Area. To the extent that GDPR applies and the transfer is not covered by an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows: Module 2 (controller to processor) where you are a controller, and Module 3 (processor to processor) where you are a processor. You are the data exporter and we are the data importer. Clause 7 (docking clause) applies. Under Clause 9, option 2 (general written authorization) applies, with the notice period in Section 7.3. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one determined by that clause. Under Clauses 17 and 18, the SCCs are governed by the law of Ireland, and disputes go to the courts of Ireland. Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA, and Annex III by our sub-processor page.

13.3 Transfers from the United Kingdom. To the extent UK GDPR applies, the UK Addendum is incorporated into this DPA by reference and completed with the information in Section 13.2 and the annexes. Neither party may end the UK Addendum under its Section 19 except as it allows.

13.4 Transfers from Switzerland. To the extent the Swiss Federal Act on Data Protection applies, the SCCs apply as in Section 13.2, with references to the GDPR read as references to that Act, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and data subjects in Switzerland able to bring claims in Switzerland.

13.5 If a transfer mechanism we rely on is invalidated, we will work with you in good faith to put another lawful mechanism in place.

14. CCPA and US state privacy laws

14.1 You disclose Customer Personal Data to us only for the limited and specified business purposes of providing the Service as set out in the Agreement. We will not:

  • sell or share Customer Personal Data;
  • retain, use or disclose it for any purpose, including any commercial purpose, other than those business purposes, or as otherwise permitted to a service provider by the CCPA;
  • retain, use or disclose it outside the direct business relationship between you and us; or
  • combine it with personal information we receive from or on behalf of anyone else, or collect from our own interactions with consumers, except as the CCPA permits a service provider to do.

14.2 We will comply with the obligations that apply to us under the CCPA and give the same level of privacy protection it requires. We will tell you if we can no longer meet those obligations. You may take reasonable and appropriate steps to make sure we use Customer Personal Data consistently with your obligations under the CCPA, and, on notice, to stop and remediate any unauthorized use.

14.3 Where another US state privacy law applies, we will process Customer Personal Data as a processor under that law: following your instructions, keeping it confidential, binding sub-processors to the same obligations, deleting or returning it as Section 11 provides, making the information in Section 12 available, and helping you meet your obligations as Sections 8 to 10 provide.

14.4 We certify that we understand and will comply with the restrictions in this Section 14.

15. General

15.1 Each party’s liability under this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Law or the SCCs do not allow that.

15.2 This DPA lasts as long as we process Customer Personal Data. We may update it to reflect changes in Data Protection Law, new transfer mechanisms or changes to the Service, with notice under the Agreement, provided the update does not materially reduce your protection.

Annex 1. Description of the processing

  • Data exporter: the Customer, contactable through the account owner’s email address. Activities: using a business phone service.
  • Data importer: Redstone Castle LLC, New York, United States; contact support@redstonecastles.com. Activities: providing the Presence business phone service. Role: processor.
  • Data subjects: the Customer’s Users; people who call, are called by, text with or leave voicemails for the Customer; people in the Customer’s contacts and imported call lists.
  • Categories of personal data: names and phone numbers; call records (numbers, times, durations, who answered, outcomes); call recordings, voicemails and transcripts; AI notes, including summaries and caller profiles (such as industry, role and intent); text messages, delivery status and consent records; contact details, notes and tasks; and any other personal data callers and Users choose to say or write.
  • Sensitive data: none is intended. Callers and Users may disclose sensitive data during calls, voicemails or texts. The measures in Annex 2 apply to all Customer Personal Data, recordings are made only when the Customer turns recording on, and access is limited to the Customer’s Users and our two founders.
  • Frequency: continuous, for as long as the Customer uses the Service.
  • Nature and purpose: connecting, recording and storing calls and voicemails; sending and receiving texts; transcription and AI notes after calls; storing and displaying call history, contacts and notes; synchronizing devices; sending call records to integrations the Customer connects; security and fraud prevention; support.
  • Duration and retention: for the term of the Agreement, then as Section 11 describes. Recordings, voicemails, transcripts and notes are kept until the Customer asks for their deletion or the account closes.
  • Sub-processors: as listed on our sub-processor page, for the purposes, data and locations stated there.

Annex 2. Technical and organizational measures

  • Encryption in transit: HTTPS only for the website and apps; the apps pin our certificate chain and refuse unencrypted connections; call audio between browsers or apps and our voice server is encrypted. Calls and texts between our servers and the public phone network travel over carrier networks, as any phone call does.
  • Encryption of secrets: CRM credentials and two-step sign-in secrets are encrypted with keys kept outside the database; session tokens are stored only as hashes; push notifications are encrypted with a separate key for each phone, so Apple and Google cannot read them.
  • Authentication: passwords hashed with scrypt; optional two-step sign-in with an authenticator app and one-time backup codes; throttling of repeated failed sign-ins; customers can see and sign out signed-in devices.
  • Access control: each customer’s data is scoped to its organization in the application; recordings are served only to members of the organization they belong to; roles of owner, admin and member; production access limited to the two founders; a firewall on the server.
  • Audit: significant account actions are written to an audit log.
  • Telephony fraud controls: caller ID set by the server, never by the browser or app; outgoing calls limited to permitted US destinations; spending, call-length and simultaneous-call limits for each account; a switch that stops all outgoing calls.
  • Mobile apps: sign-in tokens kept in the iOS Keychain or Android Keystore-protected storage; no advertising, analytics or tracking code.
  • Availability and backups: nightly backups, kept for 14 days and checked after each run; off-site copies encrypted before upload with a key the storage provider does not hold; a public status page fed by checks every minute.
  • Data minimization: recording off by default; AI processing only after a call, from a recording or voicemail; technical logs kept for 90 days.
  • Sub-processors: chosen for the job, bound by written terms, listed publicly.

© 2026 Presence, a product of Redstone Castle LLC. Status · Reliability · Support

Terms · Privacy · Acceptable use · 911 · SMS terms · Sub-processors · DPA