Nexis Studio
Data Processing Agreement
Parties and conclusion of the agreement
This Data Processing Agreement (the agreement) is concluded between the customer of the phone assistant service, as controller, and Nexis Studio, as processor, in line with Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679; the GDPR).
- Controller: the customer, that is the business or office that uses the service, with the name, OIB and registered address it entered and confirmed in the app
- Processor: NEXIS STUDIO, obrt za uredske i pomoćne uredske usluge, vl. Luka Djogaš, Buje, Juki 141, OIB 63105181019, support@nexistudio.dev
An obrt (sole trader business) has no separate legal personality, so the contracting party is its owner, Luka Djogaš. In this agreement we call the owner and the obrt together Nexis Studio or "we".
The customer accepts the agreement in the app at app.nexistudio.dev, together with the Terms of Service, before we create its assistant. We record the time of acceptance and the version. The agreement is concluded in electronic form.
The agreement is part of the Terms of Service. Terms not defined here have the meaning given in the GDPR and the Terms of Service. If this agreement and the Terms of Service differ on matters of personal data protection, this agreement prevails.
This version applies from 13 September 2026.
Subject matter, duration, nature and purpose
- Subject matter: processing of callers' personal data when our phone assistant takes the calls the customer forwards to our number.
- Duration: for as long as the customer's subscription runs, and after that until the data is deleted, as described in the section "Deletion and return of data".
- Nature of the processing: receiving calls, recording them, speech to text, composing replies with a language model from the office information, synthetic speech, creating the transcript and summary, extracting details from the conversation, checking free slots and booking into the calendar the customer connected or emailing the customer an invitation for the appointment, emailing call summaries, storage, display in the dashboard, and deletion.
- Purpose: answering calls on the customer's behalf when nobody at the office can pick up, passing callers' messages on to the customer, and booking appointments.
Data subjects and types of data
The data subjects are people who call the customer and whose call the assistant takes, and people the caller mentions during the call.
Types of personal data:
- The number the caller is calling from (if not withheld), the time and duration of the call, and technical call data.
- The recording and transcript of the call, and everything the caller says in it.
- The call summary and details extracted from the call, such as the caller's name, the reason for the call, the message, the callback number and whether it was confirmed, urgency and preferred time.
- Appointment data, such as the caller's name, the visit type, the callback number, the start and end of the appointment, and the ID of the calendar event.
- Technical logs, which may contain the caller's number, the number called, and call and appointment identifiers.
The assistant does not ask for special categories of data, such as health data: one sentence is enough for the reason for the call, and it records only a neutral visit type in the calendar. If a caller nevertheless gives such data on their own, it stays in the recording, transcript and summary until the periods in the section "Deletion and return of data" run out.
The controller's instructions
We process the data only on the customer's documented instructions. The instructions are this agreement, the Terms of Service, the settings the customer chooses in the app (for example the greeting, the voice, booking, the connected calendar and email summaries), and written instructions sent to support@nexistudio.dev.
Some parts of the service are the same for all customers and the customer cannot change them: at the start of every call the assistant says that it is an automated AI assistant and that the call is recorded, all calls are recorded, and we delete data within the periods in the section "Deletion and return of data". By accepting this agreement, the customer also gives these as its instructions.
We process the data outside the instructions only where the law of the European Union or the Republic of Croatia requires us to. In that case we will inform the customer before the processing, unless that law prohibits such information.
If we believe an instruction infringes the GDPR or other data protection law, we will inform the customer immediately.
We do not use callers' data for our own purposes and we do not sell it. We do not use calls to customers to check how the assistant works.
Confidentiality
Only people at Nexis Studio who need it to provide the service, to solve a problem the customer reported, or to meet a legal obligation have access to callers' data. These people are bound to confidentiality by contract or by law.
The duty of confidentiality continues after this agreement ends.
Security measures
We apply technical and organisational measures under Article 32 GDPR that are appropriate to the risk of the processing. No system is completely secure, and we do not claim ours is. The measures we currently use:
- The database is located in the EU (Supabase). Row level security is switched on for every table, with no rules that would allow public access, and the browser never reads the database directly: only the server side of the app accesses the data.
- Traffic between the browser and the app, and between the app and service providers, goes over encrypted connections (HTTPS).
- Access to the app requires a user account, sign-in attempts are rate limited, and each customer sees only its own office's data.
- We do not store passwords: Supabase Auth keeps them in a form from which the password cannot be read.
- Access keys for providers are kept as secret app settings, not in the code. Notices sent to us by Telnyx, Vapi and Stripe are checked with a signature or a secret key before we process them.
- The call recording link is signed with a secret key, so it cannot be guessed or altered to open a different call. Anyone the link is forwarded to can listen to the recording for as long as the recording exists; after the retention period the recording can no longer be opened.
- We access Google Calendar without a service account key, with a short-lived token limited to the calendar. We store the calendar link the customer enters in the app encrypted.
- We delete data automatically when the periods in the section "Deletion and return of data" run out, in our database and on the Vapi platform.
- The app sends security headers that, among other things, prevent it from being shown inside other websites.
We may change and improve the measures, but not in a way that lowers the level of protection.
Sub-processors
The customer gives us general authorisation to engage sub-processors. We have data processing agreements, or have accepted data processing terms, with our sub-processors that bind them to protect the data. We remain liable to the customer for their work in line with Article 28(4) GDPR.
Sub-processors that process callers' data:
- Telnyx LLC (USA): the Croatian phone number calls are forwarded to, and call control.
- Vapi Inc. (USA): phone assistant platform, recordings, transcripts and call summaries.
- Deepgram, Inc. (USA): speech to text, as Vapi's sub-processor.
- OpenAI (USA): language model, as Vapi's sub-processor.
- Eleven Labs Inc. (ElevenLabs, USA): synthetic voice, as Vapi's sub-processor.
- Vercel Inc. (USA): the application that handles calls, messages and bookings, the app at app.nexistudio.dev, and technical logs.
- Supabase (database in the EU; contracting party Supabase Pte. Ltd, Singapore): database.
- Plus Five Five, Inc. (Resend, USA): emailing call summaries and appointment invitations to the customer.
- Google (the office's Google Calendar and Google Cloud): busy periods and appointments in the calendar the customer connected; Google runs the calendar as the controller for the customer.
The language model Vapi uses to write call summaries also works within the Vapi platform.
An exception to the duty to process data only on our instructions: under its own privacy policy, Vapi may also use call recordings, transcripts and logs to improve its AI models, and under its own terms, Deepgram may keep audio to improve its models unless a setting switches this off. The customer takes this into account when assessing whether the service is suitable for it.
We will tell the customer by email at least 30 days in advance about any intended addition or replacement of a sub-processor that processes callers' data. Within that period the customer may object on reasonable grounds at support@nexistudio.dev. If we cannot accommodate the objection, the customer can cancel the subscription before the change takes effect.
The list of all our providers, including those that do not process callers' data, is in our Privacy Policy.
Transfers outside the EU
Most sub-processors are in the USA, so callers' data is also transferred to and processed there. The database is in the EU, but the data does not stay only in the EU. For these transfers we rely on the safeguards in Chapter V of the GDPR:
- Telnyx and Vercel: certified under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on adequacy). Their data processing agreements also contain standard contractual clauses, which apply if the certification stops being valid.
- Vapi: standard contractual clauses adopted by the European Commission, which Vapi relies on in its terms and data protection documents.
- Deepgram, OpenAI and ElevenLabs: they receive data as Vapi's sub-processors. ElevenLabs (Eleven Labs Inc.) states that it is certified under the EU-US Data Privacy Framework, and its data processing agreement also contains standard contractual clauses. Deepgram and OpenAI rely on standard contractual clauses.
- Supabase: the database is in the EU. If Supabase or its sub-processors access data from outside the EU, for example for support, standard contractual clauses apply.
- Resend: the EU-US Data Privacy Framework, which Resend states in its data processing agreement that it complies with, and the standard contractual clauses in that agreement.
- Google (the office's Google Calendar): Google runs the calendar under the office's terms with Google. Google LLC is certified under the EU-US Data Privacy Framework.
The customer can ask for a copy or summary of these safeguards at support@nexistudio.dev.
Assisting the controller
Taking into account the nature of the processing and the information available to us, we help the customer to:
- respond to callers' requests for access, rectification, erasure, restriction of processing, portability and objection. If a caller sends a request to us, we pass it on to the customer without delay. At the customer's request we find, export or delete a caller's data in the database and at our providers; for now we do this by hand, so the customer needs to give the caller's number and the date and time of the call;
- meet its obligations under Articles 32 to 36 GDPR, including a data protection impact assessment and prior consultation with the supervisory authority, by giving it, on request, information about the processing, our providers and the security measures.
Personal data breach
If we become aware of a breach of callers' personal data, we will notify the customer without undue delay, and at the latest within 48 hours of becoming aware of it. We send the notice by email to the customer's address entered in the app.
In the notice we give what we know at that point: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures we have taken or propose, and a contact for further information. What we do not yet know we provide later, without undue delay.
The customer, as controller, notifies the supervisory authority and the callers of the breach, and we help it do so.
Deletion and return of data
While the subscription runs, we delete data automatically:
- Call recordings and transcripts: 90 days from the call, in our database and on the Vapi platform.
- Summaries, details extracted from calls, messages, appointments and call records: 12 months.
- Event notices sent to us by providers: 30 days.
- Technical logs at Vercel: up to one day.
When the subscription ends, we delete the customer's calls, messages and appointments from our database 30 days later, and at that point we also delete its assistant on the Vapi platform. If the customer renews the subscription before that date, the data stays.
If the customer wants a copy of the data before it is deleted, it can ask for one at support@nexistudio.dev while the data still exists. We will provide the data from our database in a common, machine-readable format.
The customer can also ask for earlier deletion of a particular call at support@nexistudio.dev.
We do not keep the data longer, unless the law of the European Union or the Republic of Croatia requires it. Some providers keep part of the data under their own rules: Telnyx keeps call data for as long as it reasonably needs to provide its service, for billing and to meet legal obligations, and ElevenLabs may keep a history of synthesised speech, which may include a phone number the assistant read back.
Audits and information
At the customer's request we provide the information needed to demonstrate compliance with Article 28 GDPR: this agreement, the list of sub-processors, a description of the security measures, and the sub-processors' data processing agreements and certifications available to us.
If that information is not enough, the customer, or an auditor it authorises, may carry out an audit, including an on-site inspection. The audit must be announced at least 30 days in advance, takes place during business hours and in a way that does not put the confidentiality of other customers' data at risk, and its costs are borne by the customer. The auditor must be bound to confidentiality.
Audits of sub-processors are possible within the rights their terms give us.
We allow the supervisory authority to carry out inspections as the law provides.
The controller's obligations
The customer, as controller, is responsible for the lawfulness of processing callers' data. In particular, it:
- ensures there is a legal basis for processing callers' data and that callers are informed about it, for example in its own privacy notice;
- gives instructions that comply with the GDPR and other law;
- does not put personal data that is not needed to answer callers into the office information and documents it adds in the app;
- responds to callers' requests and notifies the supervisory authority and the callers where the GDPR requires it.
Liability, term and changes
For damage caused by an infringement of the GDPR, the parties are liable in line with Article 82 GDPR. Otherwise, the liability provisions of the Terms of Service apply, unless the GDPR provides otherwise.
This agreement applies for as long as the subscription runs and we process the customer's callers' data, including the period until that data is deleted. Obligations that by their nature should continue after that, such as confidentiality, continue to apply.
We may change this agreement in the same way as the Terms of Service, with notice by email at least 30 days in advance. This agreement is governed by the law of the Republic of Croatia.