Data-processing agreement
The standard agreement between a customer (the controller) and AIMERICA LLC (the processor). Version of 24 September 2026.
This is our standard template. To put it in force, email sales@a1merica.ai from the owner's address with your company name and the date; we countersign and both parties keep a copy. Where a signed agreement differs from this page, the signed one governs.
1. Parties and scope
This agreement is between the customer named in the AIMERICA account ("Customer", the controller) and AIMERICA LLC, 6037 Winthrop Commerce Ave, Riverview, FL 33578, United States ("AIMERICA", the processor). It forms part of the Terms of Service and applies to all personal data AIMERICA processes for Customer through the Service.
2. What is processed
| Subject | Detail |
|---|---|
| Nature and purpose | Providing the business phone service: calls, voicemail, texts, faxes, call recordings and transcripts, the AI receptionist, contacts, meetings, and the billing of the Service. |
| Categories of data | Names, phone numbers, email addresses, call and message records and content, voicemail and call recordings, transcripts and AI summaries, contact records, emergency addresses, account and billing details. |
| Data subjects | Customer's staff, customers, callers, texters and contacts. |
| Duration | For as long as Customer has an account, then the deletion period in section 8. |
3. AIMERICA's obligations
- Process personal data only on Customer's documented instructions, which are the Terms, this agreement and the settings Customer chooses in the Service, unless the law requires otherwise, in which case AIMERICA tells Customer first where it may.
- Ensure that staff with access are bound to confidentiality and have access only as needed.
- Keep the security measures described on the Security page, and never lower them for Customer's data without notice.
- Help Customer answer data-subject requests (access, correction, deletion, a copy of the data) within ten business days of a request, and help with the assessments the law asks of Customer, using the information AIMERICA has.
- Make available the information needed to show these obligations are met, and allow audits by Customer or an auditor Customer appoints, on 30 days' notice, at most once a year unless a regulator or a breach requires more.
4. Subprocessors
Customer authorises the subprocessors below. AIMERICA tells Customer by email at least 30 days before adding or replacing one; Customer may object within that time, in which case the parties discuss, and Customer may end the Service without penalty if no solution is found. AIMERICA remains responsible for its subprocessors' work.
| Provider | Where | What for |
|---|---|---|
| Telnyx | United States | Phone numbers, calls, texts, faxes and 911 routing (the carrier) |
| Deepgram | United States | Speech to text: transcripts and the AI receptionist's hearing |
| Cartesia | United States | Text to speech: the AI receptionist's voices |
| OpenAI | United States | Language models behind the AI receptionist and summaries |
| Anthropic | United States | Language models behind AI assistance and summaries |
| Finix | United States | Card payments: the platform's own invoices and AIMERICA Payments |
| ReliableSite | United States (Miami, Florida) | The servers everything runs on and the encrypted offsite backup store |
5. International transfers
All processing takes place in the United States. For Customers in Canada and Quebec, AIMERICA provides on request the information needed for the transfer assessment Quebec's Law 25 requires, and applies protection equivalent to that law's requirements to the data transferred.
6. Personal-data breach
AIMERICA tells Customer of a personal-data breach affecting Customer's data without undue delay and within 72 hours of becoming aware of it, by email to the account owner, with what is known: what happened, which data and roughly how many people, the likely consequences, and what has been done. AIMERICA keeps a register of security incidents and updates Customer as facts are established.
7. Customer's obligations
Customer has the legal basis for the personal data it brings to the Service, gives the notices the law requires (including recording notices where AIMERICA's spoken notice is not enough for Customer's situation, and texting consent), and keeps its own account access, roles and emergency addresses current.
8. Deletion at the end of the contract
When the account is closed, AIMERICA deletes Customer's personal data within 30 days, and the encrypted offsite backups that still contain it expire within a further 30 days. Before closing, Customer may export its data through the Service or by asking AIMERICA. AIMERICA keeps only what the law requires it to keep, for example billing records, for as long as the law requires.
9. Liability and law
Each party's liability under this agreement is subject to the limitation of liability in the Terms. This agreement is governed by the law named in the Terms. Where a data-protection law that applies to Customer requires terms this agreement does not contain, the parties add them in writing.
