GDPR compliance
DialPhone processes customer personal data as a Processor under GDPR Article 28. EU data residency, SCCs, and a published DPA make compliance straightforward for EU-based customers and US customers with EU data subjects.
Technical & organizational measures
- EU data residency option (Frankfurt, Dublin) with no cross-region replication unless customer-enabled
- Standard Contractual Clauses (SCCs) for transfers outside the EEA
- UK International Data Transfer Addendum (IDTA) for UK transfers
- Swiss FADP addendum for Swiss transfers
- Data Processing Agreement (DPA) executed with every paid plan — auto-incorporated into Terms
- Appointed EU Representative per GDPR Article 27
- Data Protection Officer (DPO) for privacy inquiries
- 72-hour breach notification to Controllers
- Subprocessor registry with 30-day advance change notices
Data Subject Rights supported
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Rights related to automated decision-making (Art. 22)
Documents
- → Data Processing Agreement (DPA)
- → Privacy Policy
- → Subprocessor registry
- → Standard Contractual Clauses (incorporated by reference in the DPA)