Sylo Data Processing Agreement
Effective date: July 25, 2026
Version: 2026-07-25
In plain words: When your customers call, text, or chat with your Sylo receptionist, that conversation data belongs to you, and we handle it only to run the service for you. This agreement is our binding promise about how we do that: we follow your instructions, we protect the data with the security measures listed at the end, we use a small set of vetted service providers under contract, we tell you quickly if something goes wrong, we help you answer your customers' privacy requests, and when you leave we let you export everything and then delete it within 30 days. We never sell your data and we never use one business's data to help another.
1. Introduction and incorporation
1.1 This Data Processing Agreement (the "DPA") forms part of the Sylo Terms of Service (the "Agreement") between Wayhow Technology Solutions Inc. ("Wayhow", "we", "us"), the operator of the Sylo service ("Sylo" or the "Service"), and the business customer that accepts the Agreement (the "Tenant", "you").
1.2 This DPA applies whenever Wayhow processes Tenant Personal Data (defined in Section 2) on the Tenant's behalf in the course of providing the Service. It is incorporated into the Agreement by reference and takes effect when the Tenant accepts the Agreement.
1.3 If this DPA conflicts with the Agreement on a matter of data protection, this DPA prevails. If the Standard Contractual Clauses described in Section 12 apply and conflict with this DPA, the Standard Contractual Clauses prevail to the extent of the conflict.
2. Definitions
2.1 "Applicable Data Protection Law" means all laws that apply to the processing of Tenant Personal Data under this DPA, which may include: the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"); the Act respecting the protection of personal information in the private sector (Quebec) as amended by Law 25 ("Quebec Law 25"); the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into United Kingdom law ("UK GDPR"); the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"); and comparable US state privacy laws.
2.2 "Tenant Personal Data" means personal data or personal information (as defined by Applicable Data Protection Law) that Wayhow processes on the Tenant's behalf in providing the Service. It does not include data for which Wayhow is the controller under Section 3.3.
2.3 "End User" means an individual who interacts with the Tenant through the Service, such as a caller, text sender, or website chat visitor, and any individual mentioned in those interactions.
2.4 "Sub-processor" means a third party engaged by Wayhow to process Tenant Personal Data in providing the Service.
2.5 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Tenant Personal Data.
2.6 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, as amended or replaced.
2.7 "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner's Office under s.119A of the UK Data Protection Act 2018, as amended or replaced.
2.8 The terms "controller", "processor", "data subject", "processing", "personal data", "personal information", "business", "service provider", "sell", and "share" have the meanings given to them by Applicable Data Protection Law.
3. Roles of the parties
3.1 For Tenant Personal Data, the Tenant is the controller (or, where the CCPA applies, the business) and Wayhow is the processor (or, where the CCPA applies, the service provider). Where the Tenant itself acts as a processor for another controller, the Tenant warrants that it has the authorizations needed to appoint Wayhow as a further processor on these terms, and Wayhow acts as the Tenant's sub-processor.
3.2 The Tenant is responsible for the lawfulness of the processing it instructs, including: having a lawful basis for collecting End User data; giving End Users any legally required notices; its choice to enable or disable call recording and its recording consent obligations; the accuracy of its knowledge base, menus, prices, and business information; and honoring its own obligations to its customers.
3.3 Wayhow is an independent controller of data about the Tenant's own account and relationship with Wayhow, such as Tenant staff account details, billing records, subscription and usage records, support communications, and security logs. That processing is described in the Sylo Privacy Policy, not this DPA.
4. Scope and details of processing
4.1 The subject matter, duration, nature, and purposes of the processing, the categories of data subjects, and the categories of Tenant Personal Data are set out in Annex I.
4.2 In summary: Wayhow operates an AI receptionist that answers the Tenant's phone line, SMS, and website chat; transcribes and generates responses to conversations; captures bookings, orders, and messages; recognizes returning customers where enabled; sends related notifications; and makes conversation records available to the Tenant in its dashboard. Processing lasts for the term of the Tenant's subscription plus the 30 day deletion period in Section 15.
5. Instructions
5.1 Wayhow will process Tenant Personal Data only on the Tenant's documented instructions, including with respect to transfers of Tenant Personal Data to a third country, unless required to do otherwise by law that applies to Wayhow. In that case, Wayhow will inform the Tenant of the legal requirement before processing, unless the law prohibits it from doing so.
5.2 The Tenant's documented instructions are: (a) this DPA and the Agreement; (b) the Tenant's configuration of the Service, which is the primary instruction set, including the channels the Tenant activates, the knowledge base content the Tenant provides, the recording setting the Tenant chooses, the booking and ordering features the Tenant enables, and the customer memory and deletion actions the Tenant takes in the dashboard; and (c) other written instructions the Tenant gives, such as support requests, where Wayhow agrees to act on them.
5.3 Wayhow will inform the Tenant if, in Wayhow's opinion, an instruction infringes Applicable Data Protection Law. Wayhow may decline to carry out an instruction that it reasonably believes is unlawful, including instructions that would require unlawful recording, disclosure of another tenant's data, or processing of data described in Section 14.
6. Confidentiality
6.1 Wayhow will ensure that every person it authorizes to process Tenant Personal Data (including staff and contractors) is bound by a contractual or statutory duty of confidentiality and processes Tenant Personal Data only as needed to perform their role.
6.2 Wayhow limits staff access to Tenant Personal Data to what is needed to operate, secure, and support the Service, on a least privilege basis, with staff access protected by multi-factor authentication.
7. Security
7.1 Wayhow will implement and maintain appropriate technical and organizational measures to protect Tenant Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. The measures Wayhow maintains as of the version date of this DPA are described in Annex II.
7.2 Wayhow may update the Annex II measures from time to time, provided the updates do not materially reduce the overall level of protection of Tenant Personal Data during the subscription term.
7.3 The Tenant is responsible for its own use of the Service, including securing its staff account credentials, deciding whether to enable multi-factor authentication for its staff, assigning appropriate roles, and configuring the Service appropriately for the sensitivity of the data it handles.
8. Sub-processors
8.1 The Tenant gives Wayhow general written authorization to engage Sub-processors to provide the Service, subject to this Section 8.
8.2 Wayhow does not publish a named list of its Sub-processors, because the composition of the vendor stack is confidential business information. Instead: (a) Annex III lists the categories of Sub-processors currently engaged; and (b) where the Tenant's own legal or contractual obligations require named vendor disclosure, Wayhow will provide the current named Sub-processor list on request under a non-disclosure agreement. Requests go to info@wayhow.ai.
8.3 Wayhow will give the Tenant at least 30 days' advance notice (by email or dashboard notice) before a Sub-processor in a new category not listed in Annex III begins processing Tenant Personal Data. Tenants that have received the named list under Section 8.2(b) will also be given at least 30 days' advance notice of the addition or replacement of a named Sub-processor within an existing category.
8.4 The Tenant may object to a change notified under Section 8.3 on reasonable, documented data protection grounds within the notice period. The parties will work in good faith to resolve the objection, for example by adjusting the configuration of the Service. If no resolution is reasonably available, the Tenant may terminate the affected part of the Service, or the Agreement if the affected part is central to the Service, and will receive a pro rata refund of prepaid fees for the terminated portion after the termination date. This is the Tenant's sole remedy for a Sub-processor objection.
8.5 Wayhow will impose on each Sub-processor, by written contract, data protection obligations that are materially no less protective than those in this DPA, including appropriate security measures and, where relevant, transfer safeguards and restrictions on using Tenant Personal Data to train models for other customers. Wayhow remains responsible to the Tenant for the performance of its Sub-processors' data protection obligations.
9. Assistance with data subject requests
9.1 Taking into account the nature of the processing, Wayhow will assist the Tenant, by appropriate technical and organizational measures, in fulfilling the Tenant's obligation to respond to data subjects' requests to exercise their rights under Applicable Data Protection Law (such as access, correction, deletion, portability, restriction, objection, and opt-out rights).
9.2 The Service provides self-serve tools that satisfy most of this assistance directly: the Tenant can view and export conversation records, delete an individual customer's transcripts, learned details, and messages through the per-customer erasure control, export all business data as a file, and delete the account entirely. Where a request cannot be completed through those tools, Wayhow will provide reasonable additional assistance on request.
9.3 If Wayhow receives a request directly from an End User about processing done for the Tenant, Wayhow will not respond substantively (except to acknowledge it or as required by law) and will promptly redirect the End User to the Tenant, and, where the request identifies the Tenant, notify the Tenant.
10. Assistance with impact assessments and consultations
10.1 Taking into account the nature of the processing and the information available to Wayhow, Wayhow will provide reasonable assistance to the Tenant with data protection impact assessments, transfer impact assessments, privacy impact assessments required under Quebec Law 25, and prior consultations with supervisory authorities, in each case where required of the Tenant by Applicable Data Protection Law and related to the Service.
10.2 This DPA, its Annexes, the Sylo security page, and the information available under Section 8.2 are the first line of that assistance; Wayhow will answer reasonable follow-up questions sent to info@wayhow.ai.
11. Security Incident notification
11.1 Wayhow will notify the Tenant without undue delay after becoming aware of a Security Incident affecting Tenant Personal Data. To the extent then known (and supplemented as information becomes available), the notice will describe the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed to address it, and a contact point.
11.2 Wayhow will take reasonable steps to contain and remediate the Security Incident and will cooperate reasonably with the Tenant's own notification obligations. Wayhow's notice is not an admission of fault.
11.3 Wayhow will not name the Tenant in any public statement about a Security Incident without the Tenant's permission, unless required by law.
12. International data transfers
12.1 The Service is operated on cloud infrastructure located primarily in the United States. The Tenant authorizes Wayhow to process Tenant Personal Data in the United States, Canada, and the other locations where Wayhow's Sub-processor categories operate, subject to this Section 12.
12.2 EEA transfers. To the extent Wayhow processes Tenant Personal Data subject to the GDPR that is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference, with the Tenant as data exporter and Wayhow as data importer, completed as follows: Module Two (controller to processor) applies; Clause 7 (docking) is included; under Clause 9, Option 2 (general authorization) applies with the notice period in Section 8.3; the optional redress language in Clause 11 is not included; under Clauses 17 and 18, the governing law and forum are those of Ireland unless the exporter's member state requires otherwise; and Annexes I, II, and III of this DPA serve as Annexes I, II, and III of the SCCs. Where the Tenant is itself a processor, Module Three applies instead, completed the same way.
12.3 UK transfers. For transfers subject to the UK GDPR, the SCCs as completed in Section 12.2 apply as amended by the UK Addendum, with the tables of the UK Addendum deemed completed with the corresponding details from this DPA and its Annexes, and with "neither party" selected for the ending provision of Table 4.
12.4 Swiss transfers. For transfers subject to Swiss data protection law, the SCCs as completed in Section 12.2 apply with these adaptations: references to the GDPR are read as references to Swiss data protection law; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the governing law and forum under Clauses 17 and 18 are those of Switzerland or of an EEA country permitted by the SCCs; and data subjects in Switzerland may enforce their rights in Switzerland.
12.5 Canadian tenants. For Tenant Personal Data subject to PIPEDA or substantially similar provincial law, Wayhow will, through this DPA, provide a comparable level of protection to the data while it is processed by Wayhow and its Sub-processors, wherever they are located. For Tenants subject to Quebec Law 25, Wayhow additionally commits that: it processes Tenant Personal Data only for the purposes of the mandate described in this DPA; it will notify the Tenant without delay of any confidentiality incident involving Tenant Personal Data so the Tenant's privacy officer can meet its own obligations; it will not use or communicate the data except as this DPA allows; and it will provide the information reasonably needed for the Tenant's privacy impact assessment of communicating personal information outside Quebec. The Tenant remains accountable for personal information it entrusts to Wayhow.
12.6 If a transfer mechanism relied on under this Section 12 is invalidated or replaced, the parties will cooperate in good faith to put a lawful successor mechanism in place promptly.
13. CCPA and US state law service provider terms
13.1 To the extent Tenant Personal Data includes personal information subject to the CCPA, Wayhow acts as the Tenant's service provider, and Wayhow certifies that it will not: (a) sell or share the personal information; (b) retain, use, or disclose the personal information for any purpose other than the business purposes specified in this DPA and the Agreement, including any commercial purpose other than providing the Service, or as otherwise permitted by the CCPA; (c) retain, use, or disclose the personal information outside the direct business relationship between the parties; or (d) combine the personal information with personal information received from or on behalf of another person, except as permitted by the CCPA (for example, to detect security incidents or protect against fraudulent or illegal activity).
13.2 Wayhow will notify the Tenant if it determines it can no longer meet its obligations under the CCPA, and the Tenant may then take reasonable and appropriate steps under the CCPA to stop and remediate unauthorized use of personal information. Wayhow grants the Tenant the rights to take reasonable and appropriate steps to ensure that Wayhow uses the personal information in a manner consistent with the Tenant's CCPA obligations.
13.3 Wayhow makes equivalent commitments as a "processor" under the Virginia, Colorado, Connecticut, Utah, and similar US state privacy laws to the extent they apply, and this DPA constitutes the required data processing contract under those laws.
13.4 Wayhow does not sell or share Tenant Personal Data, does not use it for targeted or cross-context behavioral advertising, and does not use one Tenant's data to train or improve AI models for any other tenant.
14. Data the Tenant must not submit
14.1 The Service is a business communications tool. Unless expressly agreed with Wayhow in writing with the required safeguards in place, the Tenant must not use the Service to collect or process: protected health information subject to health privacy laws such as HIPAA (Wayhow does not offer a business associate agreement); payment card numbers or security codes (tenant customer payments run through the Tenant's own payment processor account with Stripe, and card details go directly to Stripe, never to Sylo); government identifiers such as social insurance or social security numbers; biometric identifiers or biometric information used for identification; personal data of children where the Tenant knows the Service is directed at children; or other special category or sensitive data as a deliberate part of the Tenant's use.
14.2 The parties acknowledge that End Users may incidentally mention such information in a conversation. That incidental content is processed as conversation content under this DPA, and Section 14.1 is not breached by it, but the Tenant must not design its use of the Service to elicit it.
15. Return and deletion of Tenant Personal Data
15.1 During the subscription term, the Tenant can export its business data, including conversation records, through the self-serve export in the dashboard at any time.
15.2 After cancellation or termination of the subscription, Tenant Personal Data remains available for export for 30 days. Wayhow sends a warning email approximately one week before deletion. At the end of the 30 day period, Wayhow deletes the Tenant Personal Data from production systems through an automatic purge. The Tenant may also trigger immediate account deletion from the dashboard at any time.
15.3 Copies in encrypted backups are deleted as the backups expire in the ordinary backup cycle and remain protected by this DPA until then. Wayhow may retain data it is required by law to retain (such as billing and tax records for which Wayhow is the controller), which remains protected under this DPA or the Privacy Policy as applicable, and metadata-only operational logs that do not contain conversation content.
16. Audits and information rights
16.1 Wayhow will make available to the Tenant the information reasonably necessary to demonstrate compliance with this DPA. The parties agree that this obligation is met, in the first instance, by: this DPA and its Annexes; the Sylo security page; Wayhow's responses to a reasonable written security questionnaire (no more than once in any 12 month period, absent a Security Incident affecting the Tenant or a regulator's demonstrated requirement); summaries of third-party audit reports and penetration tests as they become available; and the Sub-processor information available under Section 8.2. As of the version date of this DPA, Wayhow's SOC 2 audit is planned but not yet completed, and Wayhow makes no certification claim.
16.2 Where Applicable Data Protection Law grants the Tenant a mandatory audit right that the Section 16.1 materials do not satisfy, the Tenant (or an independent auditor on its behalf that is not a competitor of Wayhow) may conduct an audit, including an inspection, subject to: at least 30 days' written notice; agreement on reasonable scope, timing, and duration; a confidentiality agreement covering everything observed; no access to other tenants' data or to information that would compromise Wayhow's security; performance during business hours without disrupting operations; and no more than one audit in any 12 month period, absent a Security Incident affecting the Tenant or a regulator's requirement. The Tenant bears its own costs and reimburses Wayhow's reasonable costs of supporting an on-site audit.
16.3 The Tenant will provide Wayhow a copy of any audit findings relating to Wayhow, which are Wayhow's confidential information.
17. Liability
17.1 Each party's liability arising out of or related to this DPA (including the SCCs, to the extent permitted by them) is subject to the exclusions and limitations of liability in the Agreement, and liability under this DPA and the Agreement counts toward a single shared cap. Nothing in this Section 17 limits either party's liability to data subjects or supervisory authorities where Applicable Data Protection Law does not permit that liability to be limited, and nothing in it restricts a data subject's third-party beneficiary rights under the SCCs.
18. Term and general
18.1 This DPA takes effect when the Tenant accepts the Agreement and remains in force as long as Wayhow processes Tenant Personal Data, including through the deletion period in Section 15, even if the Agreement has otherwise ended.
18.2 Wayhow may update this DPA as described in the Agreement's change process; material changes will be notified at least 30 days in advance, and no change will materially reduce the protections of this DPA during a subscription term except as required by law.
18.3 This DPA is governed by the law governing the Agreement (the laws of the Province of Ontario and the federal laws of Canada applicable in it), except where the SCCs require otherwise for the SCCs themselves.
18.4 Questions about this DPA go to info@wayhow.ai.
Annex I
Details of processing (also serving as Annex I of the SCCs where they apply)
A. List of parties. Data exporter: the Tenant, a business customer of Sylo, acting as controller (contact details as provided in the Tenant's account). Data importer: Wayhow, the operator of Sylo, an Ontario, Canada company, acting as processor; contact: info@wayhow.ai.
B. Description of processing.
-
Subject matter: provision of Sylo, an AI receptionist service that answers the Tenant's phone line, SMS, and website chat on the Tenant's behalf.
-
Duration: the term of the Tenant's subscription, plus the 30 day post-cancellation export and deletion period described in Section 15.
-
Nature of processing: collection, recording, transcription, storage, analysis, retrieval, AI response generation, disclosure to the Tenant, and deletion.
-
Purposes: answering End User conversations across voice, SMS, and web chat; transcribing conversations; generating AI responses from the Tenant's knowledge base; capturing bookings, orders, and messages; recognizing returning customers where the Tenant uses customer memory; sending the Tenant related notifications; recording calls where the Tenant has enabled recording and consent requirements are satisfied; and making conversation records and captured details available to the Tenant.
-
Categories of data subjects: End Users (the Tenant's customers and prospective customers who call, text, or chat, and individuals mentioned in those conversations) and the Tenant's staff who appear in conversation records or configuration.
-
Categories of personal data: contact details (name, phone number, email where provided); conversation content, including voice audio during calls, call recordings where the Tenant has enabled recording, transcripts, and chat and SMS message content; booking and appointment details; order details; messages left for the Tenant; customer profile details the Tenant keeps (such as name, phone number, notes, and history); and payment status of orders or bookings (never payment card numbers, which go directly to the Tenant's payment processor, Stripe, and never touch Sylo).
-
Sensitive data: none is required or intentionally collected by the Service. End Users may incidentally include sensitive details in what they say or write; such content is handled as conversation content under the security measures in Annex II.
-
Frequency: continuous, for as long as the Service is active on the Tenant's channels.
-
Retention: for the durations described in Section 15 (subscription term, then a 30 day export window followed by automatic purge; per-customer erasure and full account deletion available to the Tenant at any time).
-
Transfers to Sub-processors: as described in Section 8 and Annex III; the processing performed by each category is the portion of the purposes above that the category serves.
C. Competent supervisory authority (where the SCCs apply): the supervisory authority of the data exporter's EEA member state of establishment, or, where the exporter is outside the EEA, the supervisory authority determined under Clause 13 of the SCCs.
Annex II
Technical and organizational measures (also serving as Annex II of the SCCs where they apply)
The following measures are in place as of the version date of this DPA. They mirror the public description at the Sylo security page and do not claim more than what is built.
-
Encryption in transit: TLS 1.3 for client and server traffic.
-
Encryption at rest: at-rest encryption on the database, file storage (including voice recordings and transcripts), and backups.
-
Tenant isolation: every row of data carries a tenant identifier; row-level security policies in the database enforce the boundary on every read and write; the AI retrieval layer re-verifies tenant scope before any content reaches a model.
-
No cross-tenant learning: one tenant's data is never used to train or inform any other tenant's AI.
-
Access control: least privilege access to production systems; staff access to tenant data only through privileged internal credentials, protected by multi-factor authentication, used when the Tenant asks Wayhow to investigate something; no staff "log in as you" impersonation feature; multi-factor authentication (authenticator app with recovery codes) available on every Tenant account.
-
Least privilege runtime credentials: runtime AI and edge services operate with narrowly scoped, short-lived tokens rather than master credentials.
-
Secrets management: secrets kept in a dedicated secret store; no plaintext secrets in source code or logs.
-
Logging without content: operational and error logs carry outcomes and metadata (errors, latencies, call metadata), never conversation content; a redaction filter drops known sensitive fields before logs leave Wayhow's systems; AI model calls are logged metadata-only, with prompt and completion text stripped from error reports.
-
Recording consent controls: call recording is off by default and tenant-enabled; when enabled, a state-aware consent disclosure script is applied based on the caller's jurisdiction (including one-party and two-party consent handling and an EU consent script), and each disclosure is logged per call; recordings are playable only through an access-controlled proxy in the Tenant's dashboard.
-
Data subject tooling: self-serve data export (a single file of the business's data), self-serve full account deletion with cascade, and per-customer erasure that removes an individual customer's transcripts, learned details, and messages.
-
Retention and deletion: a 30 day post-cancellation data availability window followed by automatic purge, with an advance warning email; backups age out on the ordinary backup cycle.
-
Incident response: monitoring of errors and service health, an incident response process, and the Security Incident notification commitment in Section 11.
-
Personnel: confidentiality obligations for staff and contractors authorized to process Tenant Personal Data.
-
Vendor management: Sub-processors are vetted and bound by written data protection contracts as described in Section 8.5, with transfer safeguards where required.
-
Assurance status (stated honestly): SOC 2 is planned and not yet certified; an independent penetration test is planned; Wayhow claims no certification it does not hold.
Measures Wayhow will provide to assist the Tenant (SCC Annex II, second part): the tooling in items 9 through 11 above, plus the assistance commitments in Sections 9 and 10 of this DPA.
Annex III
Sub-processor categories (also serving as Annex III of the SCCs where they apply)
Wayhow engages Sub-processors in the following categories to provide the Service. The named list is confidential and available under a non-disclosure agreement as described in Section 8.2. Notice and objection rights for changes are in Sections 8.3 and 8.4.
-
Cloud hosting and content delivery: running the application, edge services, and delivering the dashboard and widget.
-
Database and storage: storing tenant data, conversation records, recordings, and files, with the isolation and encryption measures in Annex II.
-
Telephony and messaging carriage: connecting phone calls and delivering SMS to and from the Tenant's numbers.
-
Speech to text and text to speech: transcribing caller audio and generating the AI receptionist's voice.
-
Large language model providers: generating AI responses from conversation context and the Tenant's knowledge base, under contracts restricting use of Tenant Personal Data for training other parties' models.
-
Transactional email delivery: sending operational notifications (for example, message and booking notifications and deletion warnings).
-
Payment processing: Stripe processes the Tenant's subscription payments, and, where the Tenant connects its own Stripe account, the Tenant's customer payments go directly to the Tenant's Stripe account (Wayhow never holds those funds and never receives card numbers).
-
Error and performance monitoring: capturing errors and service health metadata; conversation content and model prompt or completion text is never sent to monitoring (see Annex II, item 8).