Doorline

Legal

Data Processing Addendum

This DPA forms part of the Doorline Terms of Service and governs the processing of Personal Data by Doorline on behalf of Customer.

Effective date: 2026-05-23 · Last updated: 2026-05-23

1. Roles

Customer is the Controller. Doorline is the Processor. Doorline processes Personal Data only on documented instructions from Customer, except as required by applicable law.

2. Categories of data

Names, phone numbers (E.164), email addresses, property preferences, qualification fields (budget, timeline, area), call transcripts and recordings, calendar events, and lead-related CRM notes generated by Doorline.

3. Subprocessors

Doorline engages the subprocessors below. Customer authorizes Doorline to engage them and any successors. Doorline will give 30 days' prior written notice before engaging a new subprocessor; Customer may object in writing within that period.

SubprocessorPurposeDataRegion
Amazon Web Services (AWS)Primary compute + storage (Postgres, Redis, object storage)All customer dataUS (us-east-1, us-west-2)
NeonManaged PostgresTenants, leads, calls, transcripts (encrypted at rest)US (us-east-2)
CloudflareCDN, DDoS protection, R2 (recording storage)Marketing assets, call recordings (encrypted), edge cacheGlobal edge, US for R2
AnthropicLLM (Claude) — qualification and summarizationCall transcripts and lead context (zero-day retention configured)US
OpenAIEmbeddings for listing search (text-embedding-3-small)Listing descriptions only — no caller PIIUS
DeepgramSpeech-to-textLive call audio (not retained beyond transcription)US
CartesiaText-to-speechAgent response text only — no caller PIIUS
LiveKitWebRTC + SIP voice transportLive call audio (transient)US
TwilioPhone numbers + SIP terminationPhone numbers, call metadataUS
StripeBilling + payment processingCustomer billing contacts; no card data crosses DoorlineUS
ClerkCustomer authentication + user managementDashboard user accounts, sessionsUS
SentryError tracking + performance tracesStack traces, request metadata; PII scrubbedUS
DopplerSecrets managementEncrypted environment variables only — never customer dataUS

4. Security

Doorline implements and maintains the technical and organizational security measures described at /security, including Row-Level Security on every tenant table, column-level encryption for OAuth tokens, TLS 1.3 in transit, AES-256 at rest, and an immutable audit log of privileged actions.

5. International transfers

All Personal Data is stored and processed in the United States. For Customers in jurisdictions requiring Standard Contractual Clauses (SCCs), Doorline incorporates the EU SCCs by reference.

6. Data subject requests

Doorline will assist Customer with responding to data subject requests (access, deletion, portability) within 14 days. Customer may export or delete a lead's data via the dashboard or by emailing privacy@doorline.ai.

7. Retention

Call recordings are retained 30 days by default. Transcripts and outcome events are retained for 7 years for billing-audit purposes. Customer may request earlier deletion at any time.

8. Breach notification

Doorline will notify Customer of a confirmed Personal Data Breach within 72 hours of discovery, including the nature of the breach, categories and approximate number of records affected, and mitigation steps.

9. Audits

On reasonable notice and no more than once per year (except following a Personal Data Breach), Customer may inspect Doorline's SOC 2 Type II report and DPA-related controls.

10. Contact

For DPA questions or to request a counter-signed copy with Customer details: privacy@doorline.ai.