Data processing agreement
Standard terms for Riot Tool ApS' processing of personal data on behalf of your organization. Last updated 1 July 2026.
1. Parties and roles
This data processing agreement (DPA) is entered into between the customer (the data controller) and Riot Tool ApS, provider of CloudDialer (the data processor). It forms an integral part of the terms of service and applies to all processing of personal data the customer enters into CloudDialer.
2. Nature and purpose of the processing
The processor processes the data solely to deliver the service: storing and displaying CRM data, placing and documenting calls and SMS, transcription and AI summaries of calls (where enabled), automation, and synchronization with the integrations the customer has activated.
3. Categories of data subjects and data
Data subjects are typically the customer's leads, customers, contact persons and own employees. The data covers ordinary personal data such as name, job title, company, email, phone number, order and billing history, notes, and call recordings and transcriptions. The customer must not enter special categories of data (GDPR art. 9) into the service.
4. Instructions
The processor processes the data only on documented instructions from the customer — by default the configuration the customer makes in the product — unless required otherwise by EU or Danish law. The processor informs the customer if, in our assessment, an instruction infringes the GDPR.
5. Confidentiality and security
All staff with access to customer data are bound by confidentiality. The processor implements appropriate technical and organizational measures per GDPR art. 32: encryption in transit and at rest, role-based access control, logging, per-organization separation of customer data, and continuous backups.
6. Sub-processors
The customer grants a general authorization for the use of sub-processors for hosting, payment processing, SMS delivery and transcription. A current list is available on request at hello@clouddialer.net. Changes are announced so the customer can object. Sub-processors are bound by the same obligations as in this agreement, and third-country transfers are safeguarded by a valid transfer mechanism, e.g. the EU standard contractual clauses.
7. Assistance and data breaches
The processor assists the customer in responding to data subject requests and with the customer's obligations under GDPR art. 32-36. Personal data breaches are notified to the customer without undue delay after the processor becomes aware of them, with the information the customer needs for its notification to the supervisory authority.
8. Deletion, audit and term
On termination the processor deletes or returns, at the customer's choice, all personal data, unless legislation requires retention. The processor makes available the information necessary to demonstrate compliance with GDPR art. 28 and allows audits on reasonable notice. The agreement applies for as long as the processor processes personal data on the customer's behalf.