Data Processing Addendum

Last Updated: July 2026

This Data Processing Addendum ("DPA") forms part of the Myra Terms of Service between HeyMyra Inc. ("Processor," "Myra") and the Customer ("Controller"). It applies to the processing by Myra of personal data on behalf of the Controller in connection with the Service, to the extent that the GDPR, UK GDPR, CCPA/CPRA or a materially similar privacy law applies to that processing.

1. Roles

Customer is the Controller (or a Processor acting on behalf of its own controllers, e.g. a business). Myra is the Processor (or Sub-Processor) and processes personal data only on documented instructions from the Controller as set out in the Terms, in this DPA, and as configured by the Controller through the Service.

2. Scope of Processing

  • Subject matter: provision of the Service.
  • Duration: for the term of the Terms plus applicable retention periods.
  • Nature & purpose: hosting, transmitting, routing, storing, analysing, transcribing and displaying Customer Content to operate the Service.
  • Data subjects: Customer's staff, customers, leads, contacts and other end-users of the workspaces controlled by Customer.
  • Categories of data: contact identifiers, account data, communications content (voice, SMS, email, chat), CRM records, usage and technical data, availability, device and authentication metadata relating to Customer's own users, and any special-category data Customer chooses to submit.

3. Myra Obligations

  • Process personal data only on the Controller's documented instructions.
  • Ensure personnel authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see Section 6).
  • Assist the Controller, taking into account the nature of processing, in responding to data-subject requests, and with security, breach notification, DPIAs and prior consultations, at Controller's cost.
  • Notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Content.
  • On termination or expiry, delete or return personal data as set out in the Privacy Policy, unless retention is required by law.
  • Make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits as set out in Section 7.

4. Controller Obligations

  • Ensure a valid lawful basis for the processing and for the transfer of personal data to Myra.
  • Provide all required notices to and obtain all required consents from data subjects (including for SMS, calls, recordings and AI processing).
  • Configure the Service appropriately and not submit personal data outside the scope described above without our prior written agreement.
  • Not submit to the Service any personal data of children below the applicable age of consent, or highly regulated data (e.g. HIPAA PHI, PCI cardholder data outside Stripe, government-classified data) unless expressly agreed in writing.

5. Sub-Processors

Customer provides general authorisation for Myra to engage sub-processors, including cloud infrastructure providers, telephony providers (voice/SMS), Stripe (payments), email delivery providers, AI model providers and Meta (for connected channels). A current list is available on request from contact@heymyra.ai. Myra imposes data-protection obligations on sub-processors that are materially equivalent to those in this DPA and remains liable for their performance. We will notify Controller of intended additions or replacements of sub-processors and give Controller a reasonable opportunity to object on reasonable data-protection grounds; if agreement cannot be reached, Controller's exclusive remedy is to terminate the affected part of the Service.

6. Security

Myra implements and maintains commercially reasonable technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These include encryption in transit, access controls, database row-level security, audit logging, signed webhooks, MFA support, least-privilege credentials and regular review of these measures.

7. Audits

Myra will make available on written request the information necessary to demonstrate compliance with this DPA, primarily through then-current certifications, third-party audit reports and written responses to a reasonable security questionnaire. On-site audits are permitted only where required by mandatory law, no more than once per 12 months, on at least 30 days' prior written notice, during business hours, subject to confidentiality, and at Controller's cost.

8. International Transfers

Where personal data originating in the EEA, UK or Switzerland is transferred to a country not deemed adequate, the parties agree that the applicable Standard Contractual Clauses (as adopted by the European Commission and, for the UK, the UK IDTA / UK Addendum) are incorporated by reference and apply, with Controller as data exporter and Myra as data importer.

9. CCPA / CPRA

Where CCPA/CPRA applies, Myra acts as a "Service Provider" (not a "Third Party") and will process personal information only for the business purposes set out in the Terms. Myra will not: (a) sell or share personal information; (b) retain, use or disclose personal information outside the direct business relationship with Customer or as otherwise permitted by CCPA/CPRA; or (c) combine personal information received from Customer with personal information received from other sources, except as permitted by CCPA/CPRA.

10. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms. Where a Controller obligation under this DPA (including obtaining consent) is breached and results in liability to Myra, the Controller will indemnify Myra in accordance with the Terms.

11. Conflict & Precedence

In the event of conflict, this DPA prevails over the Terms with respect to the processing of personal data, and the SCCs (where applicable) prevail over this DPA to the extent required by law.

12. Contact

Data-protection queries: contact@heymyra.ai.