Legal and compliance
Contracts and data processing terms
Who you contract with, the documents that make up an agreement, what the data processing terms cover, and how we support your security review and supplier registration.
On this page
Your legal, procurement and security teams will each want to see how the relationship is set down on paper before anything goes live. A Telonic agreement is made up of a small number of documents, each with a clear job: what you are buying, how your data is handled, and what service you can expect. This page describes each one, sets out what the data processing terms cover, and explains how we support the security review and supplier registration that large organisations run before they contract.
This page is a general description of how Telonic contracts. Your signed agreement is what governs the relationship, and where anything here differs from it, the agreement applies. It is not legal advice.
Who you contract with
Your agreement is with Mirchandani Technologies L.L.C-FZ, a company registered in the Meydan Free Zone, Dubai, United Arab Emirates. Telonic is its product brand.
The documents that make up an agreement
| Document | What it covers |
|---|---|
| Master agreement | The general terms of the relationship: term and renewal, fees and payment, confidentiality, intellectual property, warranties, liability, suspension and termination |
| Order form | What you are buying: your usage packages, your hosting option, the channels and departments in scope, the implementation fee and the start date |
| Data processing terms | How Telonic processes personal data on your behalf, as your processor (the party that handles data on the instructions of the organisation responsible for it) |
| Service level terms | Availability and support response commitments, how they are measured and reported, and the service credits that apply if they are missed |
Where you extend to another channel or department, a new order form is added under the same master agreement. See How pricing works and Service levels.
What the data processing terms cover
Your organisation is the controller of your customers' data: it decides why and how the data is used. Telonic processes the data on your behalf. The data processing terms set out that relationship in writing, as UAE and Saudi data protection law expect. See Data protection in the UAE and Saudi Arabia.
| Subject | What the terms say |
|---|---|
| Processing on your instruction | Telonic processes personal data only on your documented instructions, and only to provide the service |
| Purposes and data | The purposes of processing, the kinds of personal data and the categories of people it concerns, as described for your deployment |
| Where data is processed | The hosting option and region you chose, and the providers used there. All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it |
| Sub-processors | The list of sub-processors (other companies Telonic uses to provide the service) forms part of the terms and is available on request. You receive 30 days' notice of any change, with the right to object. See Sub-processors |
| Security measures | The technical and organisational measures that protect your data, including encryption in transit and at rest, access control, separation from other customers' data, logging and secure development. See Encryption |
| Staff | People who process your data are bound by confidentiality. Telonic staff access is limited to named engineers, time-limited and logged |
| Breach notification | Personal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data, with ongoing updates. See Incident response |
| Requests from individuals | Telonic assists you in responding to requests from the people your data concerns, such as requests for access, correction or deletion |
| Return and deletion | When the agreement ends, your data is returned in a standard format, then deleted from live systems and from backups as they expire, and the deletion is confirmed in writing |
| Audit | Telonic demonstrates how it meets the terms through documentation, completed security questionnaires and sessions with your security team |
Your data is yours
Your customers' data, your conversation records and your content belong to your organisation. Telonic processes them to provide your service, on your instructions, and returns and deletes them when the agreement ends. Every speech and language provider Telonic uses is contractually prohibited from using your data to train or improve its models, and zero data retention arrangements (the provider keeps no copy once it has processed a request) are used wherever a provider offers them.
Your data is used only to provide your service. No customer data is used to improve shared industry models. What carries across deployments is industry knowledge built by Telonic: workflows, edge cases and test patterns.
The Telonic platform, including the industry models, remains Telonic's. Your agreement sets out the details.
Liability and termination
Liability terms, including how liability is limited, are set out in the agreement. So are the initial term, renewal, and the notice either side gives to end the agreement. We discuss these with your legal team directly, and we are glad to understand the concern behind any clause your team raises.
Supporting your security review
Security review is where most enterprise agreements spend their time, and we would rather start it early than finish it late.
- We complete your security questionnaire, with answers from our technical team.
- We share our architecture and security documentation under a non-disclosure agreement.
- We meet your security team to answer questions directly.
- Penetration testing (authorised, simulated attacks to find weaknesses) is carried out by independent testers at least annually and after major changes, and vulnerabilities are remediated in order of severity.
See Security overview.
Supporting your supplier registration
Many organisations cannot issue a purchase order to a supplier until it is registered in their own system. We provide the company documents supplier registration usually asks for, such as the trade licence, certificate of incorporation, VAT registration and bank details. Tell us early if your organisation has a supplier portal or specific requirements, such as insurance cover or local content documentation, so registration runs alongside the rest of the process.
In practice
A Saudi insurer contracts for its claims line.
- Its procurement team starts supplier registration in the second week, and Telonic submits the company documents through the insurer's portal.
- Its security team sends a questionnaire. Telonic's technical team completes it and shares the architecture documentation under a non-disclosure agreement, followed by a session with the insurer's security architect.
- Legal reviews the master agreement, the data processing terms and the service level terms. The data processing terms name the Saudi Arabian region, the providers used there, and the insurer's named contacts for breach notices.
- The order form sets out a voice package and a messaging package for claims, the implementation fee and the start date.
- A year later, the insurer extends to renewals. A new order form is signed under the same master agreement.
What your team controls
- Your instructions for processing, set out in the data processing terms.
- Your named contacts for breach notices and security matters.
- Whether to object to a new sub-processor.
- Whether your data is returned, and in what form, at the end of the agreement.