How We Process Your Customers' Data
The Article 28 agreement between RuleInside and every merchant — what we process, on whose instructions, with what safeguards, and what happens to the data when you leave.
GDPR Article 28 · Standard Contractual Clauses · 30-day sub-processor notice
Ruleinside LLC (trading as RuleInside)
Wyoming filing ID 2023-001209068 · 30 N Gould St, Ste 32376, Sheridan, WY 82801, United States of America
Contact: info (at) ruleinside.com
This Data Processing Agreement ("DPA") forms part of the RuleInside Terms of Service between Ruleinside LLC (trading as RuleInside), Wyoming filing ID 2023-001209068, 30 N Gould St, Ste 32376, Sheridan, WY 82801, United States ("RuleInside", "Processor") and the customer ("Merchant", "Controller"). It is accepted when the Terms of Service are accepted; no separate signature is required.
It governs RuleInside's processing of personal data relating to the Merchant's own customers and callers ("Shopper Data").
It does not govern the Merchant's own account data — name, email, billing identity, login. For that data RuleInside is an independent controller and the Privacy Policy applies.
1. Subject matter, duration, nature and purpose
| Subject matter | Operation of an AI voice and chat agent on the Merchant's behalf |
| Duration | The term of the Terms of Service, plus the deletion window in section 8 |
| Nature and purpose | Answering and placing calls and messages, order and shipping lookups, appointment booking, lead capture, and the reporting derived from them |
| Types of personal data | Voice recordings and transcripts; the content of WhatsApp messages sent to and received from a Shopper; name; telephone number; email address; order and shipping details; consent and contact-preference records; call and message metadata |
| Categories of data subject | The Merchant's customers, callers and website visitors |
| Special-category data | None. See section 11. |
2. Processing on documented instructions
2.1 RuleInside processes Shopper Data only on the Merchant's documented instructions, including as to transfers to a third country. The Terms of Service, this DPA, and the Merchant's configuration of the service in the RuleInside portal together constitute those instructions.
2.2 If RuleInside becomes subject to a legal requirement to process Shopper Data otherwise, it will inform the Merchant before processing, unless that law prohibits the notification on important grounds of public interest.
2.3 RuleInside will inform the Merchant if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected processing until the instruction is withdrawn or amended.
2.4 RuleInside does not use Shopper Data to train, fine-tune or improve any model, and does not sell or share it for advertising.
3. Confidentiality
3.1 RuleInside ensures that persons authorised to process Shopper Data are bound by confidentiality obligations, whether contractual or statutory, that survive the end of their engagement.
3.2 Access is limited to those who need it to provide or support the service, and administrative access is recorded in an append-only audit log.
4. Security
RuleInside implements the technical and organisational measures in Annex II, having regard to the state of the art, the costs of implementation, the nature and purposes of processing, and the risk to data subjects. RuleInside may update those measures provided the level of protection is not reduced.
5. Sub-processors
5.1 The Merchant grants general written authorisation for RuleInside to engage sub-processors. Those engaged at the date of this DPA are listed in Annex III and published at ruleinside.com/sub-processors.
5.2 RuleInside gives the Merchant at least 30 days' notice before appointing a new or replacement sub-processor, by updating that page and notifying the Merchant's registered contact address.
5.3 The Merchant may object on reasonable grounds relating to data protection within that period. The parties will work in good faith to resolve the objection. If they cannot, the Merchant may terminate the affected part of the service without penalty and receive a refund of fees pre-paid for the terminated portion.
5.4 RuleInside imposes on each sub-processor, by written contract, data protection obligations substantially equivalent to those in this DPA, and remains fully liable to the Merchant for their performance.
5.5 Some processors in the chain are engaged by ElevenLabs, not by RuleInside - telephony, the language models that generate agent replies, and WhatsApp delivery for a Client whose messaging runs through ElevenLabs. RuleInside's obligation as to those parties flows through its contract with ElevenLabs. They are named in Annex III so that the chain is visible.
5.6 Where a Client connects its own WhatsApp Business Account to RuleInside, Meta Platforms is a direct sub-processor of RuleInside and is listed as such in Annex III. In that configuration messages pass between Meta and RuleInside without ElevenLabs in the path, and RuleInside's obligations as to Meta arise directly under this Agreement rather than through the ElevenLabs contract.
5.7 Requests from public authorities. If RuleInside receives a legally binding request from a public authority for Personal Data processed under this Agreement, RuleInside shall: (a) review the request for legal validity before disclosing anything; (b) challenge the request where RuleInside considers it unlawful, and seek interim measures where available; (c) disclose only the minimum data necessary to comply; (d) record the request, the response, the legal reasoning and the parties involved; and (e) notify the Client unless legally prohibited from doing so, in which case RuleInside shall use reasonable efforts to obtain a waiver of that prohibition. RuleInside shall not grant any public authority direct or unfettered access to Personal Data.
6. Data subject rights
6.1 Taking into account the nature of the processing, RuleInside assists the Merchant by appropriate technical and organisational measures, insofar as possible, in fulfilling the Merchant's obligation to respond to requests under Chapter III GDPR.
6.2 The service provides subject access export and erasure, each scoped to a single data subject and covering both RuleInside's database and the conversation records held by ElevenLabs.
6.3 If RuleInside receives a request directly from a data subject relating to Shopper Data, it will not respond substantively and will refer the request to the Merchant without undue delay — save that it may confirm the request relates to the Merchant, or direct the individual to the Merchant.
6.4 Records retained after an erasure are identified in Annex II. Consent and opt-out records are retained under Article 17(3)(b) GDPR, because deleting them would destroy the evidence that the person opted out.
7. Breach, impact assessments and prior consultation
7.1 RuleInside notifies the Merchant without undue delay after becoming aware of a personal data breach affecting Shopper Data, and in any event in time to allow the Merchant to meet its 72-hour obligation under Article 33. The notification includes the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken.
7.2 The accountable contact is info (at) ruleinside.com.
7.3 RuleInside provides reasonable assistance with data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to it.
8. Deletion or return
8.1 On termination or expiry, the Merchant may export Shopper Data through the service for 30 days.
8.2 At the end of that period RuleInside permanently deletes all Shopper Data, including the associated conversation records held by ElevenLabs, unless retention is required by law. This is a deletion, not a deactivation.
8.3 At the Merchant's written election within the 30-day window, RuleInside will instead return the data in a structured, commonly used, machine-readable format and then delete it.
8.4 Deletion is confirmed in writing on request.
8.5 During the term, categories of Shopper Data expire automatically on the shorter periods in Annex II. Section 8 governs the end of the relationship; Annex II governs the life of the data within it.
9. Information and audits
9.1 RuleInside makes available to the Merchant all information necessary to demonstrate compliance with Article 28, including this DPA, Annex II and the sub-processor list.
9.2 RuleInside will respond to a written data protection questionnaire once in any twelve-month period, within 30 days.
9.3 Where the Merchant reasonably requires an audit, it may be conducted by the Merchant or an independent auditor it appoints who is not a competitor of RuleInside, on at least 30 days' written notice, during business hours, no more than once in any twelve-month period, subject to confidentiality, and at the Merchant's cost — except where the audit reveals material non-compliance, in which case RuleInside bears the reasonable cost. Additional audits may be conducted where required by a supervisory authority or following a personal data breach.
10. International transfers
10.1 Processing happens in two regions.
- The database is in the European Union (Ireland). It holds contact records, call metadata, the transcript copy, consent records and event history.
- The voice pipeline is processed in the United States. Call audio and the primary transcript are handled there.
10.2 RuleInside is a United States entity, so its access constitutes a transfer. Transfers rely on the Standard Contractual Clauses (Module Two, controller-to-processor) approved by Commission Implementing Decision (EU) 2021/914, and for UK transfers on the UK International Data Transfer Addendum (version B1.0), both incorporated into this DPA by reference and deemed executed on its taking effect.
10.3 Where a sub-processor holds a certification under the EU-U.S. Data Privacy Framework, that certification may be relied on in addition. ElevenLabs, who process the call audio, are certified under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Framework and the UK Extension.
10.4 EU-only processing of call audio is not available. A Merchant requiring it should raise this before entering into the agreement.
11. Special-category data
11.1 The service is not designed to process data within Article 9 GDPR, and the Merchant must not configure it to solicit such data.
11.2 RuleInside does not create a voiceprint or any other biometric identifier from caller audio. It stores recordings and transcripts of what was said; it does not derive a template that identifies a person by their voice.
11.3 Because a voice conversation is open-ended, a caller may volunteer special-category data unprompted. Such data is subject to the same retention, security and erasure provisions as all other Shopper Data.
12. Precedence
Where this DPA conflicts with the Terms of Service, this DPA prevails as to the processing of Shopper Data.
Annex I — Description of processing
As set out in section 1.
Annex II — Technical and organisational measures
- Tenant isolation
- Every query filters by store identifier. The service role bypasses row-level security, so the per-query filter — not row-level security — is the operative tenant boundary; row-level deny-all is defence in depth.
- Secrets management
- All credentials are held in a managed secrets vault and fetched per use. Merchant API keys are stored hashed, never in plaintext.
- Personal-data gating
- Every path returning personal data requires a server-verified signed identity token. Caller ID is treated as spoofable: the inbound personalisation path forces the identity token empty and returns no personal data, so a spoofed number reaches a guest experience.
- Audit logging
- The administrative audit log is append-only; update, delete and truncate are revoked from the service role, so the identity performing an action cannot rewrite the record of it. Consent events are protected the same way.
- Encryption
- Data is encrypted in transit and at rest.
- Fail-closed outbound
- Four independent gates — opt-out, do-not-call, consent, and calling window. Any error on any gate means the recipient is not contacted.
- Consent integrity
- Ingestion never grants consent; consent is written by exactly one module.
- Retention, as it runs
- Automatic expiry sweeps run every 15 minutes: verbatim message text 180 days; conversations, sentiment and contact events 365 days; delivery logs 30 days; request-idempotency records 24 hours. Conversation records at ElevenLabs are deleted on the same schedule; call audio at ElevenLabs is held for 90 days.
- Retained past erasure
- Consent and opt-out records survive an erasure request under Article 17(3)(b), because deleting them would destroy the proof that the person opted out.
Annex III — Sub-processors
Engaged directly by RuleInside
| Sub-processor | Purpose | Transfer safeguard |
|---|---|---|
| ElevenLabs | Voice agent: speech recognition, turn-taking, speech synthesis, conversation storage. Processed at their US endpoint. | EU-U.S. Data Privacy Framework, Swiss-U.S. Framework, UK Extension |
| Supabase | Database, secrets vault, file storage. Hosted in Ireland. | EU-hosted |
| OpenAI | Embeddings for product search | Standard Contractual Clauses |
| Stripe | Merchant billing identity. No Shopper Data. | Standard Contractual Clauses |
| Resend | Merchant-facing email. Merchant addresses only. | Standard Contractual Clauses |
| Better Stack | Operational alerting; alert context can carry a contact identifier | Standard Contractual Clauses |
| Vercel | Hosts the merchant portal; request metadata | Standard Contractual Clauses |
| Meta Platforms (WhatsApp Business Platform) | Delivery and receipt of WhatsApp messages where the Client connects its own WhatsApp Business Account (section 5.6). Shopper telephone numbers and message content. | Standard Contractual Clauses |
Engaged by ElevenLabs, disclosed for chain visibility (section 5.5)
| Party | Purpose |
|---|---|
| Twilio | Telephony for inbound and outbound calls |
| Meta (WhatsApp) | WhatsApp message delivery where the Client's messaging runs through ElevenLabs. Where the Client connects its own WhatsApp Business Account, Meta is a direct sub-processor instead - see the table above and section 5.6. |
| Language model generating agent replies, on some agents | |
| Anthropic | Language model generating agent replies, on other agents |
| OpenAI | Language model generating agent replies |
The current list is maintained at ruleinside.com/sub-processors.

