About this summary
This page summarizes the data processing agreement (DPA) that SS Support Network LLC, trading through its AssistBPO division, signs with clients whose engagements involve personal data. Almost every engagement does: an assistant who answers your phones, works your inbox, replies to your customers or updates your CRM is processing personal data on your behalf. This summary is written so that a business owner, practice manager or compliance lead can see the main commitments without reading the full document.
This page is a summary only. It is not the agreement. The executed DPA, together with the services agreement and any statement of work, governs the relationship, and if anything here differs from the signed documents, the signed documents control. A copy of the full DPA template is available on request before you sign anything.
Who is the controller, and who is the processor?
The client is the controller (or “business” under US state privacy laws). The client decides why and how personal data is processed, owns the data and owns the systems it lives in.
AssistBPO is the processor (or “service provider”). We process personal data only on the client’s documented instructions, inside the client’s own systems wherever possible, and only for the purpose of delivering the contracted services. Where an agency or firm engages us to support its own clients, the agency remains the controller or processor towards its clients, and we act as the agency’s sub-processor.
Subject matter, duration, nature and purpose
The subject matter is the virtual assistant, receptionist, customer support, appointment setting, sales administration, marketing support, e-commerce operations, data and back-office services described in the statement of work.
The duration is the term of the services agreement, plus the wind-down period needed to return or delete data.
The nature of the processing is receiving and making calls, reading and sending messages, recording and organizing information, booking, retrieving, correcting, transmitting to the client and, at the end, deleting. We do not make automated decisions about individuals, and we do not use client data to train models or for our own purposes.
The purpose is to run the desk the client has delegated: answering and making calls in the client’s name, keeping the client’s inbox, calendar, tickets and records current, and reporting to the client.
Categories of data and data subjects
Depending on the desk, personal data may include names, business and personal contact details, the content of calls, messages, tickets and chats, appointment and booking details, customer and order history, lead and consent records, supplier details, and, for healthcare desks, patient names, dates of birth, insurance identifiers and appointment or trip details that are protected health information. Call recordings, where the client records calls, are made and stored in the client’s phone platform.
Data subjects may include the client’s employees and contractors, customers and their contacts, callers, leads and prospects, patients or service users, suppliers and their contacts, and, for agency engagements, the agency’s own clients.
Assistants never take or store card numbers, CVVs or bank credentials, so payment card data is outside the processing.
Special category, sensitive or health data is processed only where the desk requires it and only with the additional safeguards the DPA sets out, including a business associate agreement for US healthcare clients.
Our obligations as processor
We process personal data only on the client’s documented instructions, including on international transfers, unless the law requires otherwise, in which case we tell the client before processing where the law allows. Scripts, call flows, SOPs and consent rules agreed at onboarding count as instructions, and a change to them is a change of instruction.
Everyone who accesses client data is bound by confidentiality. Staff sign a confidentiality agreement on joining, and we sign a client-specific NDA for each desk. Access is limited to the named assistant, the trained backup and the team lead assigned to the desk, plus quality reviewers for the monthly QA scorecard.
We maintain technical and organizational security measures appropriate to the risk. The core measures are:
- Multi-factor authentication on every account used to reach client data.
- Access through the client’s own user accounts with the permissions the client sets, so the client can see, limit and revoke access at any time.
- Least-privilege access: staff see only the clients and functions assigned to them, and access is removed the day an assignment ends.
- Access logs kept for logins and, where the client’s software supports it, for actions taken.
- Encryption in transit and at rest for data we hold, and use of the client’s own platforms for everything else.
- Managed, company-owned devices with disk encryption, endpoint protection, remote wipe and blocked removable storage.
- No local storage of client data: work is done inside the client’s systems or our secured environment, with downloads, screenshots and printing blocked by policy and configuration.
- Work performed from the group’s offices under a secure workspace policy, never from home or through a marketplace.
- Background checks on all staff before they are assigned to client work.
- A per-client NDA, HIPAA training for staff on healthcare desks, and security training every year.
- Call-recording notices that follow the caller’s country and state rules, with recording off where the client instructs.
- No card numbers taken or stored by assistants.
- A documented incident response plan that is tested.
Certifications are listed on our security page only when they are held.
Which sub-processors do we use?
We use a small number of sub-processors. The client is told which ones apply at signing and is notified before any change, with the right to object.
Affiliates: SS Support Network LLC operates a second office in Pakistan, where part of the delivery team is based. Staff at that office are employed under the same confidentiality, background-check and security requirements as the US team. Our sister brands, SS Support Network (healthcare), TransportBPO (ground transportation) and LedgerBPO (accounting and billing), are divisions of the same company, share management and systems, and may be treated as affiliates for this purpose.
Cloud and tooling providers: website hosting and business email by Hostinger; analytics and tag management by Google (Google Analytics 4, Google Tag Manager) and Microsoft (Clarity), loaded only after consent and not used on client data; call booking by Calendly; form protection by Cloudflare Turnstile; our client and lead portal, operated by SS Support Network LLC; and, where we provide the softphone or call-recording platform for a desk rather than the client, the telephony provider named in the schedule. Document storage and communication tools are listed with their locations in the sub-processor schedule attached to each signed DPA.
The client’s own software (CRM, help desk, phone system, practice management system, store, calendar and similar) is contracted by the client, not by us, and is not our sub-processor.
How is client data transferred across borders?
Client data will be accessed from the United States and from our second office in Pakistan. The DPA includes the transfer mechanism that applies to the client’s jurisdiction.
For UK clients, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses is incorporated, supported by a transfer risk assessment. For EU clients, the EU Standard Contractual Clauses (controller-to-processor module, or processor-to-processor for agencies) are incorporated with the same assessment.
For Australian clients, the DPA records the disclosure to our second office in Pakistan and to US providers under Australian Privacy Principle 8, and binds us to handle the data in line with the Australian Privacy Principles. For Canadian clients, the DPA supports the client’s accountability under PIPEDA and, for Quebec clients, provides the information needed for the client’s privacy impact assessment under Law 25.
For US clients, the DPA includes the service-provider terms required by the CCPA/CPRA and comparable state laws.
Outbound calls, texts and email
Where a desk makes outbound calls or sends texts or email, the client’s consent records, list sources and do-not-call instructions are part of the documented instructions. We scrub lists against the registers that apply (National DNC, TPS and CTPS, the National DNCL, the Do Not Call Register), keep consent logs, and stop a campaign if the lawful basis is missing. The country rules are summarized on the compliance page.
Assistance to the client
We help the client respond to data subject requests received about data we process, within the time the client needs to meet its own deadline. We help with data protection impact assessments, transfer risk assessments and regulator enquiries where our processing is in scope. We tell the client promptly if an instruction appears to breach applicable data protection law.
What happens to the data when the engagement ends?
At the end of the engagement, the client chooses return or deletion. Because we work inside the client’s systems, most data never leaves them; we simply remove our users and wipe the assistant’s device profile. Notes, SOPs, reports and correspondence that we hold are returned in a standard format and then deleted from our systems within 30 days and from rolling backups within a further 30 days, unless the law requires us to keep a copy. We confirm deletion in writing on request.
Audits and information requests
The client may ask for the information needed to demonstrate compliance with the DPA, including our security policies, staff training records, access logs for the client’s desk and the sub-processor list. The client, or an auditor it appoints who is bound by confidentiality, may audit our processing on reasonable notice, no more than once a year unless a regulator requires it or a breach has occurred. Audits are carried out remotely or at our offices during business hours and must not disrupt other clients’ data.
Breach notification
We notify the client without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the client’s data. The notice describes what happened, the data and people affected as far as known, the likely consequences and the steps taken. We then cooperate with the client on its own notifications to regulators and individuals.
HIPAA and healthcare clients
For US healthcare clients, including medical and dental practices, home care, NEMT and other covered entities and business associates, we sign a business associate agreement (BAA) as a separate document. The BAA sits alongside the DPA and sets out the permitted uses and disclosures of protected health information, safeguards, breach reporting and termination terms required by HIPAA. Staff on healthcare desks are HIPAA trained, and access is limited to the minimum necessary for the desk.
Liability and term
Liability under the DPA is governed by the liability provisions of the services agreement. The DPA lasts as long as we process personal data for the client and survives termination of the services agreement until all data is returned or deleted.
Getting the full document
To receive the full DPA template, the BAA template or our sub-processor list, email privacy@assistbpo.com or ask your sales contact. Questions about how the DPA applies to your country can go to the same address.