Data Processing Agreement
This is an English translation provided for convenience. In case of any discrepancy, the Hebrew version prevails.
Last updated: October 5, 2026
This agreement is part of the Terms of Use between the customer (the "Customer" or the "Controller") and Yehonatan Shamam, licensed dealer no. 302910187, of 94 Yigal Alon Street, Tel Aviv-Yafo ("TalkWiz" or the "Holder"). It governs the processing of Customer Data by TalkWiz for the Customer, and is intended to meet the requirements of the Privacy Protection Law and the Data Security Regulations regarding outsourcing. On the processing of personal information on behalf of the Customer, this agreement prevails over the other documents of the agreement.
1. Definitions
- "The Law": the Privacy Protection Law, 5741-1981, as amended from time to time, including Amendment No. 13.
- "Data Security Regulations": the Privacy Protection (Data Security) Regulations, 5777-2017.
- "Customer Data": as defined in the Terms of Use, to the extent it includes personal information.
- "Security Incident": an incident in which there is a real concern of harm to the integrity of Customer Data, its use without authorization or beyond authorization.
- "Sub-processor": a party that is not an employee of TalkWiz and that processes Customer Data for TalkWiz.
- Other terms are interpreted under the Law and the Terms of Use.
2. Roles of the parties
2.1. The Customer is the controller of the database that the Customer Data is part of. It determines the purposes of the processing and its main means, through its use of the Service and its settings.
2.2. TalkWiz is a holder of the database, and processes the Customer Data for the Customer only.
2.3. The Customer is solely responsible for the lawfulness of the collection and processing, the legal basis, the duty to inform, obtaining every required consent (including from end customers and employees), registering the database or giving notice of it where required, appointing a privacy protection officer where required, and the accuracy of the Customer Data. The instructions the Customer gives TalkWiz will comply with the law.
2.4. If the Customer itself processes the information for another party (for example a call center working for its own clients), the Customer represents that it is authorized to engage TalkWiz as a sub-holder and has obtained every required approval for this, and TalkWiz will take instructions from the Customer only. The Customer is responsible toward that party for fulfilling its obligations.
3. Details of the processing
- Purposes: transcribing calls; analyzing sales and service calls; agent scoring and coaching; extracting fields the Customer defined; producing summaries, insights, reports, alerts and message drafts; answering the Customer's users' questions about the calls; sending data back to destinations the Customer defined; security and support.
- Categories of data subjects: the Customer's end customers; the Customer's employees and agents; users of the Service on behalf of the Customer.
- Types of information: names, phone numbers, email, voice (in recordings), the content of the call and any information given in it, call metadata, statuses, notes, tags and analysis outputs. Payment details and identifiers are hidden automatically in the transcript and kept only partially.
- Systems the Holder may access: the Service's systems only, and the Customer's systems only through the connections the Customer defined and to the extent it defined.
- Type of processing: receiving, transcribing, hiding, encrypting, storing, automatic analysis, display, export, sending and deletion.
- Duration of processing: as long as the engagement is in force, subject to the retention periods in section 9.
- Location: the database and code execution in the European Union (Frankfurt). Transcription and analysis with the sub-processors in section 7. A change of the main storage region will be given to the Customer by notice in advance.
4. TalkWiz's obligations
4.1. To process Customer Data only on the Customer's instructions. The agreement, the organization's settings in the Service and the actions the Customer's users take in the Service are the Customer's documented instructions. If in TalkWiz's view an instruction violates the law, it will notify the Customer and may refrain from carrying it out.
4.2. Not to use Customer Data for any other purpose, including model training, advertising, sale or transfer to a third party not in accordance with the agreement.
4.3. To limit access to Customer Data to employees and providers who need it to provide the Service, support, security or legal compliance, and to have everyone with access on its behalf sign a confidentiality undertaking.
4.4. To implement the security measures set out in the Information Security and Information Management Policy, and the obligations that apply to a holder under the Data Security Regulations.
4.5. To assist the Customer, to a reasonable extent and taking into account the nature of the processing, in handling requests of data subjects, meeting security obligations and investigating security incidents. Assistance beyond the existing functions of the Service may involve a reasonable fee.
4.6. If TalkWiz receives a direct request from a data subject about Customer Data, it will pass it to the Customer and will not answer it on the merits without the Customer's instruction, unless the law requires.
4.7. If TalkWiz receives a demand from an authority to disclose Customer Data, it will notify the Customer, unless the law forbids it, and will disclose only what it must disclose.
4.8. To report to the Customer, at least once a year and on its request, on how it meets its obligations under this agreement and the Data Security Regulations, in the manner set out in section 10.
5. The Customer's obligations
5.1. To enter into the Service only data it is permitted to enter, and only to the extent needed for the purposes of the processing.
5.2. To inform data subjects as required by law, including about the recording, the transcription and analysis using artificial intelligence, the sub-processors and the transfer of information abroad.
5.3. To set permissions, retention periods and transfer destinations in accordance with the law and need, and to manage the users on its behalf.
5.4. To keep its access details, keys and connection addresses confidential.
5.5. To report to TalkWiz promptly any suspected security incident it learns of in connection with the Service.
6. Security incidents
6.1. TalkWiz will notify the Customer of a severe security incident affecting Customer Data without undue delay after learning of it, and where possible within 72 hours, to allow the Customer to meet its reporting obligations as controller.
6.2. The notice will include what is known at that stage, and will be supplemented later: the nature of the incident, the types of information and its estimated scope, the possible consequences, and the steps taken or to be taken.
6.3. TalkWiz will take reasonable steps to contain the incident and reduce the damage, and will cooperate with the Customer in investigating it. To the extent the law requires TalkWiz itself to report to the authority, it will do so.
6.4. A notice of a security incident is not an admission of liability.
7. Sub-processors
7.1. The Customer gives general approval to the use of the sub-processors listed in the Privacy Policy (section 6).
7.2. TalkWiz will update the list and notify the Customer at least 14 days in advance of adding or replacing a sub-processor that will process call data, by email or in the Service. The Customer may object in writing, within that period, on reasonable data protection grounds. If no reasonable alternative is found, the Customer's sole remedy is to cancel the subscription, and TalkWiz will refund the pro rata part of subscription fees paid in advance for the unused period. In an urgent case (for example a provider discontinuing its service or a security need) the notice may be given close to the replacement.
7.3. TalkWiz will engage sub-processors on terms that require them to protect the information at a reasonable level and according to their role. Global infrastructure providers provide their services on standard terms, and TalkWiz relies on their data protection undertakings.
8. Transfer outside Israel
The Customer approves the transfer of Customer Data to the sub-processors in the European Union and the USA, as set out in the Privacy Policy. The transfer is made under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, including on the basis of the provider's undertaking to protect the information.
9. Retention, return and deletion
9.1. Voice recordings are deleted right after transcription. A recording that was not transcribed (failure, expiry or getting stuck) is deleted within a few hours.
9.2. Transcripts and raw content are deleted at the end of the retention period the Customer set in the organization settings. Analysis outputs are kept as long as the organization is active, unless the Customer deleted them.
9.3. Before the end of the engagement the Customer can export the call data and analysis outputs from the Service as a CSV file. This is the way Customer Data is returned, and TalkWiz is not obliged to keep it or provide it in another way after the end of the engagement.
9.4. 30 days after a request to delete the organization or after the end of the engagement, TalkWiz will delete the Customer Data, except information it must keep by law. Copies in backups are deleted in the infrastructure provider's regular backup cycle, and until then they are protected and not used.
10. Control and audit
10.1. At the Customer's request, and not more than once a year (or after a severe security incident), TalkWiz will provide reasonable information to allow checking its compliance with this agreement, such as the security policy, answers to a security questionnaire and a description of the controls.
10.2. An on-site audit, if required by law, will be coordinated 30 days in advance, carried out during business hours, at the Customer's expense, by an auditor who has undertaken confidentiality and who is not a competitor of TalkWiz, and without exposing other customers' information or trade secrets.
11. Liability
11.1. The limitations of liability, waiver and indemnity in the Terms of Use (sections 15 to 17) also apply to this agreement and to any claim in connection with the processing of Customer Data, and TalkWiz's liability under this agreement and under the Terms of Use is subject to one shared cap.
11.2. Each party is liable toward data subjects and authorities under the law that applies to it. The Customer will indemnify TalkWiz for any claim arising from an instruction it gave, data it entered or a breach of its obligations under section 5 or the law.
12. Contact
Requests about this agreement, security incidents and requests of data subjects: the privacy protection officer, Adv. Yehonatan Shamam, info@talkwiz.app.
13. Term
This agreement takes effect on acceptance of the Terms of Use, and remains in force as long as TalkWiz processes Customer Data for the Customer.