Legal

Data Processing Agreement

How JELLYBYTE LTD processes personal data on behalf of Kollup customers, under Article 28 GDPR.
Version 1.1 · Effective 26 August 2026

You do not need to sign this to be covered by it. This Data Processing Agreement (“DPA“) is incorporated into the Kollup Terms of Service and applies automatically to every customer from the moment they start using the Service.

If your procurement process requires a countersigned copy, or you need it on your own paper, email hello@kollup.com and we will send one. We are also happy to sign a customer’s own DPA where its terms are compatible with this one.

1. Parties and scope

  • 1.1This DPA is between JELLYBYTE LTD, registered in Cyprus under number HE 495017, of Spyrou Kyprianou & Agias Fylaxeos 182, Kofteros Business Centre, 2nd floor, Office 201, 3083 Limassol, Cyprus (“Processor“, “we“, “us“), and the organisation subscribing to Kollup (“Controller“, “you“).
  • 1.2It applies where we process personal data on your behalf in connection with the Service, and forms part of the Terms of Service. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
  • 1.3It takes effect when you first use the Service and continues for as long as we process personal data on your behalf.

2. Definitions

“Data Protection Law” means Regulation (EU) 2016/679 (GDPR), Cyprus Law 125(I)/2018, and any other data protection law applicable to the processing. “Controller“, “processor“, “personal data“, “processing“, “data subject“, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in Customer Data. “Sub-processor” means any third party we engage to process Customer Personal Data. Other capitalised terms have the meanings given in the Terms of Service.

3. Roles of the parties

  • 3.1You are the controller and we are the processor in respect of Customer Personal Data. You determine the purposes and means of the processing; we act on your behalf.
  • 3.2Where you are yourself acting as a processor for another controller, you warrant that you have the authority to appoint us as a sub-processor on the terms of this DPA, and references to “controller” apply accordingly.
  • 3.3We act as an independent controller in respect of our own account, billing and website data, and in respect of aggregated and anonymised statistics under clause 11.5 of the Terms of Service. Our Privacy Policy covers that processing. This DPA does not apply to it.

4. Our instructions

  • 4.1We will process Customer Personal Data only on your documented instructions, including in relation to international transfers, unless required to do otherwise by law to which we are subject. Where a law requires us to process without your instruction, we will inform you before doing so unless that law prohibits it on important grounds of public interest.
  • 4.2Your instructions are: the Terms of Service, this DPA, your configuration and use of the Service through its normal functionality, and any further written instruction you give us that we agree to.
  • 4.3We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may suspend performance of that instruction until it is withdrawn, amended or confirmed.
  • 4.4We will not sell Customer Personal Data, and we will not use it to train, fine-tune or improve any artificial intelligence model — whether ours or a third party’s — beyond what is strictly necessary to deliver the Service to you.
  • 4.5We will not process Customer Personal Data for any purpose of our own, including our own marketing or product analytics, except as anonymised statistics that cannot identify you, your Users or any individual.

5. Your obligations as controller

  • 5.1You are responsible for the lawfulness of the personal data you submit and of your instructions to us. In particular you will: establish and maintain a lawful basis for the processing; provide any privacy notice required to your Users and to any third party whose speech is transcribed; and obtain any consent required by law.
  • 5.2You will comply with clause 8 of the Terms of Service concerning the recording and transcription of conversations, including obtaining consent or giving notice where the law requires it.
  • 5.3You will not submit special category personal data within the meaning of Article 9 GDPR, data relating to criminal convictions, or the personal data of children, to the Service. The Service is not designed for such data and Annex 2 does not describe measures appropriate to it.
  • 5.4You are responsible for the accuracy of Customer Personal Data and for configuring access within your own organisation appropriately, including removing Users who no longer need access.

6. Confidentiality of our personnel

We ensure that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, is subject to that obligation after they stop working with us, and has access only to the data necessary for their role. Access to production systems containing Customer Personal Data is limited to personnel who require it to operate, secure or support the Service.

7. Security

  • 7.1We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR. Those measures are described in Annex 2.
  • 7.2We may update those measures over time. We will not make a change that materially reduces the overall level of security of the Service.

8. Sub-processors

  • 8.1You give us general written authorisation to engage Sub-processors to process Customer Personal Data, subject to this clause.
  • 8.2The categories of Sub-processor we currently engage are set out in Annex 3. The complete named list — including what each processes, where it is located, and the transfer safeguards that apply — is available to you on written request to hello@kollup.com, whatever plan you are on, subject to a written confidentiality undertaking (clause 13 of the Terms of Service is sufficient where it applies to you). We will respond within a reasonable period, normally within 10 business days.
  • 8.3What the list covers. It identifies each Sub-processor, the personal data it processes, its location and the applicable transfer safeguard — the information necessary to demonstrate compliance with Article 28 GDPR. It does not extend to information that is not necessary for that purpose, including how the Service is built and operated, the internal routing of data between providers, model names, versions or prompts, our scoring logic or configuration, or our commercial terms with any Sub-processor. Where we provide a copy of a Sub-processor contract, we may redact commercially sensitive terms.
  • 8.4Information provided under clause 8.2 is our confidential information and is given so that you can meet your own obligations as controller. It may not be used for any other purpose, and clause 7 of the Terms of Service continues to apply to it. We may decline a request that is manifestly excessive or repetitive, on the basis set out in clause 10.4.
  • 8.5We impose on every Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each Sub-processor’s obligations.
  • 8.6Notice and objection. We will give you at least 30 days’ written notice before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period. If you do, we will work with you in good faith to find a solution — which may include making the relevant functionality available without that Sub-processor. If we cannot resolve it within 30 days of your objection, you may terminate the affected part of the Service without penalty and we will refund fees paid for any period after termination.
  • 8.7To receive notices under clause 8.6, tell us the email address to use. Otherwise we will use your Administrator’s address.

9. International transfers

  • 9.1Some Sub-processors are established outside the European Economic Area. Where Customer Personal Data is transferred outside the EEA, we ensure an appropriate safeguard under Chapter V GDPR applies — ordinarily the European Commission’s Standard Contractual Clauses under Article 46(2)(c), or an adequacy decision where one covers the recipient.
  • 9.2Where Standard Contractual Clauses apply, we enter into them with the relevant Sub-processor and, where required, on your behalf as controller. We will provide details of the safeguard applying to any particular Sub-processor on request.
  • 9.3We conduct a transfer risk assessment where required and apply supplementary technical measures including encryption in transit and at rest.

10. Assisting you

  • 10.1Data subject requests. The Service allows you to access, correct and delete Customer Personal Data yourself — accounts, scenarios, knowledge base content and reports — which will usually be enough to answer a request. The Service does not currently include a self-service bulk export; where you need one, or where self-service is not enough, we will provide reasonable assistance by appropriate technical and organisational measures.
  • 10.2If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will tell them to contact you, and inform you promptly.
  • 10.3Assessments and consultations. Taking into account the nature of the processing and the information available to us, we will assist you with data protection impact assessments and prior consultations with a supervisory authority under Articles 35 and 36 GDPR.
  • 10.4Assistance under this clause is provided at no charge where the effort involved is reasonable. Where a request is manifestly excessive or repetitive, we may charge our reasonable costs, having told you first.

11. Retention, deletion and return of data

  • 11.1During your subscription you may ask us at any time for an export of Customer Personal Data, and we will provide it in a commonly used machine-readable format. Individual reports can also be printed or shared from within the Service.
  • 11.2Report history. Coaching reports and their transcripts remain visible for a period determined by your plan, shown on the Billing page in the Service. Once a report passes that window it is hidden from view; after a further grace period it is permanently deleted, together with its transcript and any record of the tips shown during the call. Moving to a plan with a longer window restores reports that have not yet been deleted.
  • 11.3When a report is deleted under clause 11.2 we retain the underlying call record — its date, duration, mode and the User it belonged to — with no conversation content, because we need it to meter minutes and to invoice you correctly.
  • 11.4On termination, you may request an export within 30 days, and we will provide it in a commonly used machine-readable format.
  • 11.5After that period we will delete Customer Personal Data from our production systems within 90 days, and from backups in accordance with our backup cycle, unless we are required by law to retain it — in which case we will keep it only for as long as that law requires and continue to protect it under this DPA.
  • 11.6Where you delete data within the Service — for example by removing a User, which deletes that individual’s account and their reports — deletion happens immediately and we cannot reverse it. At your written request we can also delete your entire company account, which permanently removes every User, scenario, knowledge base entry, call, transcript and report belonging to it.
  • 11.7We do not store call recordings. Live Assist audio is streamed to the speech-to-text provider as it is spoken and discarded — it is never written to disk on our systems. For voice practice calls the audio is handled in transit by our real-time voice provider; we receive only the transcript, and no audio recording is stored in Kollup. There is therefore no recording for us to return or delete.

12. Audits and information

  • 12.1We will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
  • 12.2In practice, we expect most requests to be satisfied by the information in this DPA, our written responses to security questionnaires, and any certifications or reports we hold. Please start there.
  • 12.3Where that is not sufficient, you may conduct an audit on 30 days’ written notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach affecting you. Audits must take place during business hours, must not unreasonably disrupt our operations, must respect the confidentiality of other customers’ data, and must be conducted by an auditor who is not our competitor and who is bound by confidentiality.
  • 12.4You bear your own costs of an audit. Where an audit reveals a material breach by us, we bear our own costs of remediation.

13. Personal data breaches

  • 13.1We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
  • 13.2The notification will describe, so far as we know at the time: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; and the measures we have taken or propose to take. Where we cannot provide everything at once, we will provide it in phases without further undue delay.
  • 13.3We will assist you in meeting your own obligations under Articles 33 and 34 GDPR, including notifying a supervisory authority or affected data subjects.
  • 13.4We will not notify a supervisory authority or any data subject about a breach affecting Customer Personal Data on your behalf unless you ask us to, or unless we are independently required to do so by law.
  • 13.5Notifying you of a breach is not an admission of fault or liability.

14. Liability

  • 14.1Each party’s liability under this DPA is subject to the limitations and exclusions in clause 15 of the Terms of Service, and the caps there apply to the parties’ combined liability under the Terms of Service and this DPA together — not separately to each.
  • 14.2Nothing in this DPA limits any liability that cannot be limited under Data Protection Law, including a data subject’s rights under Article 82 GDPR.

15. Term, changes and governing law

  • 15.1This DPA remains in force for as long as we process Customer Personal Data on your behalf, and clauses that by their nature should survive, do.
  • 15.2We may update this DPA where necessary to reflect a change in law, guidance from a supervisory authority, or a change to the Service. Where a change materially reduces your rights, we will give at least 30 days’ notice and you may terminate before it takes effect.
  • 15.3This DPA is governed by the laws of the Republic of Cyprus, and the courts of the Republic of Cyprus have exclusive jurisdiction, save that nothing prevents a supervisory authority or a data subject from exercising rights available to them elsewhere.

Annex 1 — Details of processing

Required by Article 28(3) GDPR.

Subject matterProvision of the Kollup AI sales training and live assistance service.
DurationFor the term of the subscription, subject to the plan-based report retention in clause 11.2, plus the deletion periods in clause 11.
Nature and purposeHosting, storage, transmission, transcription of speech to text, synthesis of speech, generation of simulated dialogue, generation of real-time coaching tips, and automated generation of scores and coaching assessments — all for the purpose of delivering the Service to the Controller.
Categories of data subjectThe Controller’s personnel — administrators, managers and sales agents. Incidentally: any third party whose speech is transcribed during a Live Assist session; any individual the Controller names in a customer label, a scenario or its company knowledge base; and any recipient of a shared report link.
Types of personal dataName; work email address; job title; role within the account; authentication data (password hashes, session identifiers, invitation and password-reset tokens); IP address and technical log data; content of practice call transcripts; content of Live Assist transcripts, together with the coaching tips shown during the call and the utterance each was prompted by; any customer label entered for a live call; any personal data the Controller chooses to place in a scenario or in its company knowledge base; scores, assessments and coaching text relating to an identified individual; usage data such as minutes consumed and number of calls.
Special category dataNone. The Controller must not submit it (clause 5.3). Note that free-text speech is inherently unpredictable; the Controller is responsible for instructing its personnel accordingly.
FrequencyContinuous, for the duration of the subscription.

Annex 2 — Technical and organisational security measures

Required by Articles 28(3)(c) and 32 GDPR. This is the annex a security reviewer will read most closely.

Access control

  • Individual named accounts; shared logins are prohibited by the Terms of Service.
  • Passwords stored only as salted cryptographic hashes; plaintext passwords are never stored or logged and are not recoverable by us.
  • Session management via secure, HTTP-only cookies with server-side session records that can be revoked.
  • No self-service password reset: reset links are issued from within the account by an Administrator or Manager, are single-use and time-limited.
  • Role-based access within each customer account: Administrator, Manager and Agent, each with a distinct permission set.
  • Access to production systems restricted to personnel who require it, and removed promptly when no longer required.
  • Our own platform administration view is limited to a single named account and shows operational and billing information — company, plan, minutes used, call dates, durations and modes. It does not display transcripts, coaching reports or knowledge base content.
  • A coaching report is only reachable outside the account if a User of that account creates a share link. Links use an unguessable token, are excluded from search engine indexing, expire with the plan’s report retention window, and can be revoked at any time.

Separation of customer data

  • Every record is bound to a single customer account at the database level.
  • Every query is scoped to the requesting customer, enforced in application code rather than relying on interface controls.
  • Isolation is enforced in application code on every query rather than by interface controls alone, and is reviewed whenever data access code changes.

Encryption

  • All data in transit encrypted using TLS.
  • Data at rest encrypted by our infrastructure providers.
  • Credentials and API keys held in a secrets store, never in source code.

Minimisation by design

  • Kollup does not store call recordings. Live Assist audio streams to the speech-to-text provider as it is spoken and is discarded; it is never written to disk on our systems. For voice practice calls, audio is handled in transit by our real-time voice provider and we receive only the transcript. Only transcripts are retained.
  • We do not collect personal data beyond what the Service requires to function.
  • We do not use Customer Personal Data to train or fine-tune AI models.
  • Report data is purged on a schedule: transcripts and coaching content are permanently deleted once a report passes the plan’s retention window and its grace period, leaving only content-free call records used for metering.

Availability and resilience

  • Managed hosting with automated backups of the production database.
  • Ability to restore from backup in the event of loss or corruption.
  • Monitoring of service availability and error rates.

Organisational measures

  • Confidentiality obligations binding on all personnel with access to Customer Personal Data.
  • Written data processing agreements with every Sub-processor.
  • A documented process for identifying, assessing and notifying personal data breaches within the timescale in clause 13.
  • Review of these measures at least annually, and after any material change to the Service.

Annex 3 — Sub-processors

Categories of Sub-processor engaged as at the effective date. The complete named list is available to customers on written request, under the conditions in clauses 8.2 to 8.4.

CategoryProcessing carried outLocation
Website hostingHosting of kollup.com and associated server logsEU
Cloud application hosting and databaseHosting and storage of all service data — accounts, scenarios, transcripts and reportsOutside the EEA
Large language model providerGeneration of simulated client dialogue and coaching reports from scenario text and transcriptsOutside the EEA
Speech-to-text providerConversion of call audio to text, in transit onlyOutside the EEA
Real-time voice infrastructureDelivery of voice practice calls, including audio and transcripts in transitOutside the EEA
Speech synthesis providerGeneration of the simulated client’s voice from text, engaged through our voice infrastructure providerOutside the EEA
Transactional emailDelivery of invitations, password reset links and service notifications — name and work email address onlyOutside the EEA
SchedulingDemo bookings made through our website (not Customer Personal Data under this DPA)Outside the EEA
Website analyticsConsent-based statistics about visitors to kollup.com (not Customer Personal Data under this DPA — the Service itself carries no analytics)EEA, with transfers outside it

We engage no payment processor: fees are invoiced directly and the Service neither collects nor stores card or bank details.

Contact

JELLYBYTE LTD
Registration No. HE 495017
Spyrou Kyprianou & Agias Fylaxeos 182,
Kofteros Business Centre, 2nd floor, Office 201,
3083 Limassol, Cyprus

Data protection enquiries: hello@kollup.com

Version 1.1 · Effective 26 August 2026 · Replaces Version 1.0 of 19 August 2026

Cookies preferences

✕

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

Necessary

Necessary
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.