This is an English convenience translation, provided for your information. The legally binding version is the German original; in the event of discrepancies, the German version prevails.
Data Processing Agreement (DPA)
Agreement pursuant to Art. 28 GDPR · Version: 24 August 2026
If you as a business use the Coolblack app to receive calls from your customers, patients or clients, you are the controller of the processing. Coolblack processes the callers' data on your behalf. This text is the corresponding data processing agreement.
1. Parties
Client (controller within the meaning of Art. 4 No. 7 GDPR): you as the user of the Coolblack app (hereinafter the "Client").
Contractor (processor within the meaning of Art. 4 No. 8 GDPR):
Coolblack GmbH
Südfeldwiese 14, 32107 Bad Salzuflen, Germany
Managing director: Dirk Nesner
info@coolblack.gmbh
(hereinafter the "Contractor" or "Coolblack")
This agreement is concluded through acceptance in the app's setup assistant (item "Accept data processing agreement"). A copy can be viewed at any time at coolblack.gmbh/en/auftragsverarbeitung.
2. Subject matter and duration
Subject matter: automated answering of incoming phone calls by an AI voice agent, optionally including the creation of appointments, contacts and reminders as well as transfers to human staff.
Duration: for the duration of use of the Coolblack app. The agreement ends automatically when the app is uninstalled.
3. Nature and purpose of the processing
- Speech processing of incoming calls (speech recognition, response generation, speech synthesis)
- Creation of calendar entries, contacts and reminders — where activated by the Client
- Provision of the telephony infrastructure (SIP push, VoIP wake-up)
- Optionally: storage of call logs on the Client's device
4. Types of personal data
- The caller's audio stream and transcribed text
- Phone number and time of the call
- Information communicated by the caller (name, request, appointments, contact details)
- Contacts or appointments created at the caller's request
5. Categories of data subjects
- Callers (customers, patients, clients, business partners of the Client)
- Persons whose data is mentioned in the conversation
6. Obligations of the Contractor (Coolblack)
- Processing exclusively on the documented instructions of the Client — these instructions result from the configuration in the app (agent profile, knowledge base, activated capabilities)
- Ensuring the confidentiality of the persons involved in the processing (Art. 28(3)(b) GDPR)
- Appropriate technical and organisational measures pursuant to Art. 32 GDPR — see section 10 of this agreement
- Supporting the Client with data-subject requests (Art. 12 et seq. GDPR)
- Support in complying with Art. 32 to 36 GDPR (security, notification duties, data protection impact assessment)
- Notification of personal data breaches without undue delay, at the latest within 24 hours of becoming aware
- Support regarding the Client's audit rights (Art. 28(3)(h) GDPR)
- Deletion or return of all personal data after the end of the agreement
7. Obligations of the Client
- Ensure the lawfulness of the data processing (legal basis vis-à-vis the caller)
- Inform callers at the start of the conversation about the use of the AI — the Coolblack app provides a default greeting for this, which the Client can adapt
- Supplement their own privacy policy to cover the use of Coolblack
- Accuracy of the knowledge base that has been set up — Coolblack is not liable for content provided by the Client
8. Sub-processors
The Client consents to the use of the following sub-processors:
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — AI response generation via Vertex AI and speech synthesis (text-to-speech) in cloud mode; place of processing exclusively the EU (LLM in europe-west1, Belgium; speech synthesis via the EU endpoint); retention at most 30 days per Google's standard, no training; contract: Cloud Data Processing Addendum pursuant to Art. 28 GDPR.
- Cartesia AI Inc. (San Francisco, USA) — speech synthesis for former premium voices, only active for existing agents that chose a Cartesia voice before the switch to the Live voices (being phased out in favour of the Live voices); place of processing: EU cluster (Frankfurt region), contractually guaranteed including failover; third-country safeguards through EU standard contractual clauses (Art. 46 GDPR) and the EU-US Data Privacy Framework; retention: none (zero data retention).
- Apple Inc. (Cupertino, USA) — push notifications (CallKit wake-up) and the Apple Speech framework (speech recognition; on-device depending on device model); third-country transfer to the USA, safeguarded by EU standard contractual clauses and Apple's certification under the EU-US Data Privacy Framework.
- Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — hosting of the Coolblack server infrastructure (app.coolblack.gmbh, push.coolblack.gmbh); place of processing exclusively Germany; contract: DPA pursuant to Art. 28 GDPR.
- easybell GmbH (Brückenstraße 5a, 10179 Berlin, Germany) — provision of the telephony infrastructure for optional Coolblack phone numbers (SIP/VoIP switching of incoming calls); in doing so processes connection data (caller's number, time, duration of the connection); place of processing exclusively Germany; only active if the Client uses a Coolblack phone number. Supervisory authority: Federal Network Agency (Bundesnetzagentur); contract: DPA pursuant to Art. 28 GDPR.
Coolblack informs the Client by in-app notice or email at least 30 days before adding or replacing a sub-processor. The Client may object; in the event of an objection, the agreement ends.
9. Transfers to third countries
Transfers to the USA (Cartesia, Apple) take place exclusively on the basis of EU standard contractual clauses (Art. 46 GDPR) and supplementary safeguards (encryption, zero-retention agreements). In the case of Cartesia, the actual processing takes place on the EU cluster (Frankfurt region).
10. Technical and organisational measures (Art. 32 GDPR)
- TLS encryption for all server communication
- Per-device authentication with a unique secret in the keychain
- Servers in Germany; hardened system (firewall, automatic security updates, fail2ban)
- Restrictive file and database permissions
- Daily backups with rotation
- Sub-processors' API keys exclusively server-side — never in the app
- Local storage of sensitive data (knowledge base, transcripts) exclusively on the Client's device
11. Deletion and return after the end of the agreement
After the end of the agreement, Coolblack deletes all device-specific data on the server within 30 days — except data relevant to accounting (purchases, invoices) in accordance with statutory retention obligations, and anonymised security logs (retained for at most 14 days). Local data on the Client's device is removed by the operating system when the app is uninstalled.
12. Liability
The statutory provisions of the GDPR and the German Civil Code (BGB) apply. Coolblack is liable to the Client only for damage caused by a demonstrably culpable breach of the obligations under this agreement.
13. Final provisions
Should individual provisions of this agreement be invalid, the validity of the remaining provisions remains unaffected. German law applies. The place of jurisdiction is the Contractor's registered office insofar as the Client is a merchant.