RONUS

Effective August 16, 2026

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") forms an integral part of the agreement between RUFUS TECH LLC ("RONUS") and the Client contracting the Service. It complies with Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and equivalent regulations when RONUS processes personal data on behalf of the Client. If the Client's end-customers have data subject to HIPAA in the U.S., in addition to this DPA the Business Associate Agreement (BAA) must be signed. The live list of sub-processors, with each one's purpose and location, is published at ronus.tech/subprocessors and forms part of this DPA.

1. Definitions

Capitalized terms not defined here have the meaning given to them in the GDPR. For purposes of this DPA:

  • "Controller" means the Client, who determines the purposes and means of the processing.
  • "Processor" means RONUS, who processes personal data on behalf of the Controller.
  • "Personal Data" means any personal data of the Client or its end-customers that RONUS processes while providing the Service.
  • "Processing" means any operation performed on Personal Data.
  • "Sub-processor" means any third party engaged by RONUS to process Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the European Commission's Standard Contractual Clauses for international transfers (Decision (EU) 2021/914).
  • "Data Breach" means a breach of security that leads to destruction, loss, alteration, or unauthorized access to Personal Data.

2. Roles of the parties

With respect to the Client's end-customers, the Client acts as the Controller and RONUS acts as the Processor.

With respect to its own users of the ronus.tech site (visitors who request a demo or contact us), RONUS acts as Controller, on the terms described in its public Privacy Policy. That sphere falls outside the scope of this DPA.

3. Subject-matter, duration, nature, and purpose

Subject-matter: the processing of Personal Data necessary for RONUS to provide the Client with the Service of AI assistants (voice and chat).

Duration: while the service agreement between the Client and RONUS is in force, plus the reasonable return/deletion period described in the Termination section.

Nature: collection, storage, organization, consultation, modification, transmission, and deletion of Personal Data, through the infrastructure of RONUS and its Sub-processors.

Purpose: to provide the contracted Service: handle calls and messages, schedule and confirm appointments, integrate with the Client's software, and produce the corresponding operational reports.

4. Categories of data subjects and Personal Data

Data subjects: the Client's end-customers and leads, as well as Client personnel who use the system.

  • Identifiers: name, phone, email.
  • Conversation content data: WhatsApp and SMS messages and, once the voice channel is active, call recordings and transcripts.
  • Appointment and booking data: date, time, service, modifications, confirmations, and reminders.
  • Service usage / operational data: timestamps, session identifiers, technical logs.
  • In dental and aesthetic sectors, data that may be health-related (special categories under Art. 9 GDPR). For U.S. clients, this information may constitute PHI under HIPAA and requires a separate BAA.

5. Documented instructions of the Controller

RONUS processes Personal Data only on the documented instructions of the Client. The initial instructions are the service agreement, the assistant configuration, this DPA, and, where applicable, the BAA.

The Client may issue additional written instructions (email to privacy@ronus.tech). RONUS will inform the Client without delay if it considers that an instruction infringes the GDPR or other applicable data protection law.

If mandatory EU or Member State law requires RONUS to process Personal Data beyond the instructions, RONUS will notify the Client before the processing, unless the law itself prohibits such notice on important public interest grounds.

6. Personnel confidentiality

RONUS will ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality. Access is granted on a need-to-know basis.

7. Security measures

RONUS implements appropriate technical and organizational measures, taking into account the state of the art, costs, the nature of the processing, and the risks. Minimum measures include:

  • Encryption in transit (TLS) and at rest of Personal Data.
  • Strict tenant isolation between clients.
  • Main database, authentication and storage on Supabase, European Union region (Ireland). The workflow orchestrator (n8n) and the business API run on a Hetzner virtual private server in Germany (Nuremberg), as reflected in the public sub-processor list.
  • Access controls: least-privilege principle, strong authentication, and revocation of access upon role/employment changes.
  • Activity logging: logs of access to Personal Data with reasonable retention for audit.
  • Regular backups and recovery procedures.
  • Regular testing and evaluation of the effectiveness of the measures.

8. Sub-processors

The Client provides general authorization for RONUS to engage Sub-processors to provide the Service. The complete, current list, with each one's purpose and location, is published at ronus.tech/subprocessors and forms part of this DPA. As of today they are: Supabase (database, authentication and files, EU), OpenAI (language models), Twilio (WhatsApp, SMS and verification), Stripe (payments), Vercel (web hosting), Cloudflare (CDN and access), Expo (app notifications and builds), Zoho (transactional email), Google and Apple (stores and notifications), OpenStreetMap/Nominatim, CARTO and unpkg (the app's map), Google Drive and Telegram (internal operations), GitHub (code and deployment) and Hetzner (the virtual private server, Germany). VAPI is announced for the future handling of voice calls and does not receive data yet.

RONUS will impose on each Sub-processor, by contract, data protection obligations equivalent to those set out in this DPA. RONUS remains liable to the Client for the Sub-processor's compliance with its data protection obligations.

RONUS will notify the Client of any intended changes to the list of Sub-processors at least 30 days in advance. The Client may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Client may terminate the service agreement without additional penalty.

9. International transfers

The main database resides in the European Union (Supabase, Ireland). Several Sub-processors are established in the U.S. (OpenAI, VAPI, Twilio, Stripe, Vercel, Cloudflare, Expo, Zoho, Google, Apple, GitHub), and not all of them have EU data residency enabled. In those cases, RONUS executes the applicable Standard Contractual Clauses or other valid transfer mechanisms under Chapter V of the GDPR with each Sub-processor, and implements such additional measures as may be necessary.

With language-model providers, RONUS contracts zero-retention and zero-training terms with respect to the Client's Personal Data.

10. Assistance with data subject rights

Taking into account the nature of the processing, RONUS will assist the Client, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Client's obligations to respond to requests from data subjects exercising their rights under Articles 15 to 22 of the GDPR (access, rectification, erasure, objection, restriction, portability, and rights related to automated decisions).

If a data subject contacts RONUS directly, RONUS will refer them to the Client as Controller and notify the Client without undue delay.

11. Assistance with security, breaches, and DPIAs

RONUS will assist the Client, taking into account the nature of the processing and the information available to RONUS, in complying with the Client's obligations under Articles 32 to 36 of the GDPR: security of processing, notification of Data Breaches to the supervisory authority and, where appropriate, to data subjects, Data Protection Impact Assessments (DPIAs), and prior consultations.

12. Data Breach notification

RONUS will notify the Client of any Data Breach without undue delay after becoming aware of it and, in any event, within 72 hours.

The notification will include, to the extent available: the nature of the Breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to mitigate it.

If not all information is available at the start, RONUS will provide it in phases as soon as it becomes known.

13. Return or deletion upon termination

Upon termination of the service agreement, RONUS will keep the Personal Data available for 30 days so the Client can retrieve it and, at the Client's choice, return it in a readable format or delete it. After that period it is deleted or anonymised. Excepted is whatever mandatory law requires to be kept (billing and audit records) and the residue surviving in backups, which are rotating and encrypted: data deleted in production disappears from them when the rotation reaches them, not at the same instant. The specific periods for each table are published in section 12 of the privacy policy (ronus.tech/privacy).

RONUS will make Personal Data available to the Client for export for a reasonable period, no less than 30 days from termination, in a structured and commonly used format.

After that period, RONUS will delete or anonymize the Personal Data within a reasonable time and, upon the Client's request, issue a certificate of destruction.

14. Audits and information

On the Client's reasonable request, RONUS will make available all information necessary to demonstrate compliance with the obligations of this DPA and will allow audits, including inspections, by the Client or an independent auditor designated by the Client, subject to reasonable confidentiality obligations.

Audits will be conducted no more than once per year, with at least 30 days' notice, during business hours, and in a way that does not unreasonably disrupt RONUS's operations. The costs of the audit will be borne by the Client, unless the audit reveals a material breach attributable to RONUS.

Security certifications of RONUS and its Sub-processors (where available) may substitute, in whole or in part, the need for an on-site audit.

15. Liability

Each party's liability under this DPA is governed by the limitations of liability agreed in the main service agreement between the Client and RONUS, except to the extent that mandatory data protection law does not permit such limitations.

16. Governing law and jurisdiction

This DPA is governed by the laws of the State of South Carolina (USA), without prejudice to the mandatory application of the GDPR and other data protection law applicable to the processing.

For any dispute arising from this DPA, the parties submit to the courts of Greenville County, South Carolina (USA), without prejudice to any mandatory consumer rights of EU residents.

17. Prevailing language and miscellaneous

This DPA is published in Spanish and English. In the event of discrepancy between versions, the English version shall prevail.

If any provision is held invalid, the rest will remain in full force. This DPA prevails over any conflicting provision in the main service agreement on data protection matters.

For any question about this DPA, contact privacy@ronus.tech.