1. Roles
Customer is the Controller. Doorline is the Processor. Doorline processes Personal Data only on documented instructions from Customer, except as required by applicable law.
2. Categories of data
Names, phone numbers (E.164), email addresses, property preferences, qualification fields (budget, timeline, area), call transcripts and recordings, calendar events, and lead-related CRM notes generated by Doorline.
3. Subprocessors
Doorline engages the subprocessors below. Customer authorizes Doorline to engage them and any successors. Doorline will give 30 days' prior written notice before engaging a new subprocessor; Customer may object in writing within that period.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary compute + storage (Postgres, Redis, object storage) | All customer data | US (us-east-1, us-west-2) |
| Neon | Managed Postgres | Tenants, leads, calls, transcripts (encrypted at rest) | US (us-east-2) |
| Cloudflare | CDN, DDoS protection, R2 (recording storage) | Marketing assets, call recordings (encrypted), edge cache | Global edge, US for R2 |
| Anthropic | LLM (Claude) — qualification and summarization | Call transcripts and lead context (zero-day retention configured) | US |
| OpenAI | Embeddings for listing search (text-embedding-3-small) | Listing descriptions only — no caller PII | US |
| Deepgram | Speech-to-text | Live call audio (not retained beyond transcription) | US |
| Cartesia | Text-to-speech | Agent response text only — no caller PII | US |
| LiveKit | WebRTC + SIP voice transport | Live call audio (transient) | US |
| Twilio | Phone numbers + SIP termination | Phone numbers, call metadata | US |
| Stripe | Billing + payment processing | Customer billing contacts; no card data crosses Doorline | US |
| Clerk | Customer authentication + user management | Dashboard user accounts, sessions | US |
| Sentry | Error tracking + performance traces | Stack traces, request metadata; PII scrubbed | US |
| Doppler | Secrets management | Encrypted environment variables only — never customer data | US |
4. Security
Doorline implements and maintains the technical and organizational security measures described at /security, including Row-Level Security on every tenant table, column-level encryption for OAuth tokens, TLS 1.3 in transit, AES-256 at rest, and an immutable audit log of privileged actions.
5. International transfers
All Personal Data is stored and processed in the United States. For Customers in jurisdictions requiring Standard Contractual Clauses (SCCs), Doorline incorporates the EU SCCs by reference.
6. Data subject requests
Doorline will assist Customer with responding to data subject requests (access, deletion, portability) within 14 days. Customer may export or delete a lead's data via the dashboard or by emailing privacy@doorline.ai.
7. Retention
Call recordings are retained 30 days by default. Transcripts and outcome events are retained for 7 years for billing-audit purposes. Customer may request earlier deletion at any time.
8. Breach notification
Doorline will notify Customer of a confirmed Personal Data Breach within 72 hours of discovery, including the nature of the breach, categories and approximate number of records affected, and mitigation steps.
9. Audits
On reasonable notice and no more than once per year (except following a Personal Data Breach), Customer may inspect Doorline's SOC 2 Type II report and DPA-related controls.
10. Contact
For DPA questions or to request a counter-signed copy with Customer details: privacy@doorline.ai.