GlobalCanadaEuropeAsia-Pacific
Sign in

Data Processing Agreement

Available for signature

Distronode Corporation • Last Updated: September 10, 2026

01. What This Is

A Data Processing Agreement (DPA) is the contract that governs how we handle personal information on your behalf when you use District AI. This page is a plain-language summary of the DPA we offer to customers. It is written to be readable by a small-business owner, not only by a lawyer.

The signed DPA sits alongside our Terms of Service and Privacy Policy. Where the DPA and the Terms differ on the handling of personal information, the DPA governs.

02. Roles

You (the customer)

You decide why and how personal information is collected through your receptionist. Under privacy law you are the controller, and under PHIPA you may be the health information custodian. You are responsible for having a lawful basis and for giving your callers the notice and consent your situation requires.

Us (Distronode Corporation)

We act as your processor and service provider. We handle personal information on your instructions to deliver the service, and we do not decide the purposes of your processing. Distronode Corporation is a Canadian corporation, federally incorporated under the Canada Business Corporations Act, with our founder and CEO, Sean Dean, accountable for privacy.

03. Scope of Processing

03. Scope of Processing
ElementWhat it covers
Subject matterProviding the District AI voice receptionist and related messaging, CRM, and scheduling features.
DurationFor as long as your subscription is active, plus the limited period needed to delete or return data afterward.
Nature and purposeAnswering, routing, recording, transcribing, and summarizing calls; sending and receiving messages; enriching contacts where you enable it; and billing.
Types of personal dataCaller phone numbers, call audio and transcripts, contact and CRM records, message content, appointment details, and account and billing information. Where you register for a telephone number in a country whose regulator requires it, also the registration documents you provide: business registry extracts, proofs of address and, for registrations in an individual's name, government identity documents such as a passport or national identity card.
Categories of individualsYour callers and customers, your contacts, and your own team members who use the workspace.

04. Our Commitments as Processor

Process only on your instructions

We process personal information only to provide the service and to follow your documented instructions, including the settings you choose in your workspace. We do not use your content for our own purposes and we do not sell it. We may use statistics about use of the service that are aggregated and de-identified so that they identify neither you nor any individual.

Confidentiality

The people who handle your data are bound by confidentiality obligations, and access to production data is scoped and least-privilege.

Security

We keep appropriate technical and organizational safeguards. They are encryption in transit (TLS 1.2 or higher); database storage encrypted at rest by the provider hosting each region, with a second layer through Google Cloud KMS for stored third-party credentials; tenant isolation enforced by PostgreSQL row-level security; managed secrets; and rate limiting in front of authentication.

Sub-processors

We use vetted sub-processors to run the platform and remain responsible for their performance. We keep a current list and give at least 30 days' notice before adding or replacing one so you can object.

Assisting with individual requests

We help you respond to access, correction, deletion, and portability requests from the people whose information you process, using the export and deletion tools in the product and direct support where needed. Someone who contacts us directly about information you control is redirected to you, and we do not answer on your behalf unless you ask us to; help beyond the product tools may be charged at a reasonable rate where requests are excessive.

Breach notification

We maintain incident logs and will notify you without undue delay, and in any case within 48 hours of confirming a personal-data breach affecting your workspace, with the information you need to meet your own notification duties.

Deletion and return

On termination, or on your request, we delete or return your workspace data. Archived call recordings are also deleted on a retention schedule (90 days by default; a different default retention window can be arranged as part of an enterprise agreement). On request, we confirm deletion in writing.

Records and cooperation

We keep records of our processing and cooperate with your reasonable audit and information requests, and with supervisory authorities where the law requires it. Documentation, written answers and any third-party report we hold come first; an audit beyond that is limited to once in any twelve-month period, on at least 30 days' written notice, during business hours, at your cost, under confidentiality, in an agreed scope, and never touching another customer's data.

05. Your Commitments as Customer

06. International Transfers

Some processing happens outside the country where your workspace is stored. AI processing runs in the United States for workspaces outside Canada and Europe. For a European workspace, the language model powering live calls runs in the EU (europe-west4).

For a Canadian workspace, the language model runs in Montreal (northamerica-northeast1) on every voice engine but the realtime one. That engine listens and speaks with a single model Google does not serve from Montreal, so a Canadian workspace that chooses it is processed in the United States (us-east4) and the engine picker labels it that way. Since September 2026 a new Canadian workspace starts on an all-Canadian voice engine that runs speech recognition and speech synthesis in Montreal as well. A Canadian workspace on one of the other engines has those two speech legs processed in the United States.

Since September 2026 a telephone call for a Canadian workspace is handled in Montreal in both directions when we issued the number through Telnyx. A call arriving on a number issued through Twilio, Canadian or United States, still reaches us in the United States. The data residency map records where our claim stops, at the handoff to the carrier.

Support correspondence is a further exception, and we name it here rather than leaving you to find it. Requests you send our support desk are received on one site in Canada serving all four regions, so unless your workspace is Canadian they are held outside your region. Where personal information crosses borders, we rely on recognized transfer mechanisms, including standard contractual clauses and applicable adequacy decisions, together with the technical and organizational safeguards described in this DPA.

See the full data residency map for where each data type lives.

07. Sub-processors & How to Sign

Our current sub-processors, with their purpose, data category, and region, are listed on the sub-processor page. We give notice before changes so you can review them.

Download the executable DPA below, or contact us to have it countersigned (tell us your legal entity name):

Or email legal@distronode.com directly. The signed DPA incorporates the EU Standard Contractual Clauses (Module Two) and the UK Addendum by reference for EEA/UK transfers; where the Clauses or the Addendum conflict with the DPA, the Clauses or the Addendum prevail.