Data Processing Agreement

Last updated: May 2, 2026

This Data Processing Agreement ("DPA") supplements the LeadGuard AI Terms of Service and applies when we process personal data on your behalf.

1. Definitions

"Controller" means you, the customer. "Processor" means HyperKits Industries (LeadGuard AI). "Personal Data" means any data relating to an identified or identifiable individual, including caller information captured by your AI agents.

2. Scope of Processing

We process personal data only as necessary to provide the LeadGuard AI service: answering calls, capturing caller information, generating transcripts, booking appointments, and sending notifications as configured by you.

3. Data Categories

Caller name, phone number, email address, reason for call, appointment preferences, urgency level, and call audio (processed in real-time, not stored long-term).

4. Sub-Processors

We use the following sub-processors: Retell AI (voice processing), Supabase (database), Stripe (billing), Resend (email), and Netlify (hosting). We will notify you before adding new sub-processors.

5. Security Measures

We implement measures described in our Security Overview, including encryption, access controls, and monitoring.

6. Data Subject Rights

We will assist you in responding to data subject requests (access, deletion, portability) within 30 days.

7. Data Breach Notification

We will notify you of any personal data breach within 72 hours of becoming aware of it.

8. Duration & Deletion

This DPA remains in effect while you use LeadGuard AI. Upon account termination, we delete your data within 30 days unless legal retention is required.

9. Contact

DPA inquiries: privacy@leadguardai.app

HyperKits Industries, New York, NY