MAJ LeadsMAJ Leads
PrivacyTermsCookiesDPA
MAJ Leads · Dubai, United Arab Emirates · hello@majleads.com

Data Processing Addendum

Last updated: 28 May 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between MAJ Leads (“Processor”) and each client (“Controller”) for the use of the MAJ Leads Console at console.majleads.com. It governs the processing of personal data by MAJ Leads on behalf of the Controller in connection with the AI voice agent services. Capitalised terms not defined here have the meanings given in the Privacy Policy and Terms of Service.

This DPA is intended to satisfy the requirements of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “UAE PDPL”) and, where the Controller processes data of EU/EEA data subjects, the EU General Data Protection Regulation (“GDPR”).

1. Roles of the parties

  • Controller: The client organisation that engages MAJ Leads, determines the purposes and means of processing (for example, which leads to call and what data to collect), and is responsible for ensuring it has a lawful basis to share personal data with MAJ Leads.
  • Processor: MAJ Leads, which processes personal data only on the Controller’s documented instructions, as set out in this DPA and the agreed service scope.
  • Sub-processors: Third-party vendors engaged by MAJ Leads to support delivery of the service. A full list is in section 6.

2. Processing scope

Subject-matterAI voice agent operations: outbound/inbound call handling, transcript generation, lead management, calendar bookings, reporting, and billing.
DurationFor the term of the engagement, and for the post-termination period required to complete data deletion or export per section 8.
Nature of processingCollection, storage, retrieval, transmission, analysis (AI scoring), and deletion of personal data in connection with the voice agent service.
PurposeDelivering the contracted service, billing, fraud prevention, TDRA regulatory compliance, and debugging at the Controller’s request.
Types of personal dataLead phone numbers and names, call audio, call transcripts, caller IP addresses, client account credentials, and campaign configurations.
Categories of data subjectsThe Controller’s leads and prospects; the Controller’s staff who use the Console; callers who interact with deployed AI agents.

3. Processor obligations

MAJ Leads will:

  • Process personal data only on documented instructions from the Controller, unless required to do so by applicable law (in which case MAJ Leads will notify the Controller, unless prohibited by law).
  • Ensure that persons authorised to process personal data are under appropriate confidentiality obligations.
  • Implement the technical and organisational security measures described in section 5.
  • Not engage additional sub-processors without prior notice to the Controller, giving the Controller a reasonable opportunity to object.
  • Assist the Controller in responding to data subject requests (access, correction, deletion, portability) within 30 days of the Controller forwarding the request.
  • Delete or return personal data on termination, per section 8.
  • Make available all information reasonably necessary to demonstrate compliance with this DPA, and allow and contribute to audits by the Controller (or a mandated auditor) on 30 days’ written notice, no more than once per year.

4. Controller obligations

The Controller will:

  • Provide instructions to MAJ Leads in writing (including by configuring the Console) and ensure those instructions comply with applicable law.
  • Ensure it has a lawful basis to process and share with MAJ Leads any personal data of leads or data subjects (for example, legitimate interest or consent where required by UAE PDPL).
  • Comply with UAE TDRA telemarketing rules, including maintaining a valid permit where required and honouring Do Not Call (DNCR) lists.
  • Notify MAJ Leads promptly of any instruction that, in the Controller’s assessment, would infringe UAE PDPL or GDPR.

5. Security measures

MAJ Leads implements and maintains appropriate technical and organisational measures, including:

  • Encryption in transit: All data exchanged between clients, the Console, and sub-processors is encrypted with TLS 1.2 or higher.
  • Encryption at rest: Supabase (PostgreSQL) and Cloudflare R2 encrypt data at rest using AES-256.
  • Access control: Role-based access (ADMIN / USER) enforced in the Console. Internal MAJ Leads staff access to the database requires authenticated Supabase credentials with MFA.
  • Audit logging: Material admin actions (account provisioning, configuration changes) are logged with timestamp, actor, and IP address. Logs are retained for 24 months.
  • Webhook integrity: Inbound webhook callbacks are signed with per-client HMAC secrets and verified using timing-safe comparison to prevent replay attacks.
  • Error monitoring: Sentry is configured with all text masked and all media blocked in session replays, so personal data does not appear in error reports.
  • Vulnerability management: Dependencies are reviewed regularly. Critical security patches are applied within 7 days of disclosure.

6. Sub-processors

MAJ Leads currently uses the following sub-processors. MAJ Leads will give the Controller at least 14 days’ notice before adding or replacing a sub-processor (by updating this page and, for material changes, by email). The Controller may object to any change in writing within 14 days; if MAJ Leads cannot accommodate the objection, either party may terminate the service on 30 days’ notice.

Sub-processorPurposeLocation
Supabase (PostgreSQL)Managed relational database — stores all account data, call records, transcripts, lead lists, audit logs, and invoices.ap-southeast-2 (Sydney, Australia) — AWS infrastructure
Cloudflare R2Object storage for call recordings and media files. Recordings are mirrored from Vapi and stored here per client retention settings.Cloudflare global network (primary bucket region configured per deployment)
VapiAI voice infrastructure — handles inbound and outbound call routing, real-time speech-to-text, LLM turn-taking, and post-call webhooks.United States (Vapi infrastructure)
Green APIWhatsApp Business API gateway — sends clients automated reports, invoices, and campaign summaries via WhatsApp.Germany (Green API infrastructure)
Make.comNo-code automation platform — orchestrates workflows authorised by clients, such as CRM pushes, lead routing, and scheduled reports.European Union (Make.com infrastructure, EU region)
SentryApplication error and performance monitoring. Session replay is configured with all text masked and all media blocked.United States (Sentry infrastructure)
Anthropic (Claude API)AI model provider — transcripts are sent to Claude for automated quality scoring and conversation analysis.United States (Anthropic infrastructure)
Nodemailer / SMTP providerTransactional email delivery — password resets, account notifications, and invoice emails.Depends on configured SMTP relay (e.g., AWS SES eu-west-1 or equivalent)

7. International data transfers

Processing under this DPA involves cross-border transfers of personal data, including:

  • Transfer to Australia (Supabase, ap-southeast-2 / Sydney): Supabase Inc. is bound by EU Standard Contractual Clauses (SCCs, 2021 EU Commission version), which also serve as the contractual safeguard for UAE PDPL purposes. Australia maintains a comprehensive privacy framework (Privacy Act 1988).
  • Transfer to the United States (Vapi, Sentry, Anthropic): Each US-based sub-processor is bound by SCCs or equivalent contractual transfer mechanisms. MAJ Leads has conducted transfer impact assessments for each and assessed the risk as proportionate given the nature of the data and the supplementary safeguards in place.
  • Transfer within the EU/EEA (Make.com, Green API): Both processors are established in Germany and subject to GDPR. No additional transfer mechanism is required for EU data subjects; contractual safeguards under UAE PDPL also apply.

Copies of the relevant SCCs or transfer impact assessments are available on written request to hello@majleads.com.

8. Retention and deletion

  • Call transcripts and recordings are deleted per the retention window configured on the Controller’s account (default 45 days for transcripts). Automatic pruning runs daily.
  • On termination of the engagement, MAJ Leads will provide a data export on written request and delete all remaining Controller personal data within 30 days, except where retention is required by law (for example, invoices retained 5 years under UAE tax rules, or call records retained for TDRA compliance).
  • MAJ Leads will confirm deletion in writing within 5 business days of completion.

9. Data breach notification

MAJ Leads will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller data. Notification will include:

  • A description of the nature of the breach, including (where possible) the categories and approximate number of data subjects affected.
  • Contact details for the MAJ Leads point of contact.
  • A description of the likely consequences of the breach.
  • A description of the measures taken or proposed to address the breach and mitigate its effects.

The Controller remains responsible for notifying the UAE Data Office and any affected data subjects in accordance with UAE PDPL Article 27 and, where applicable, GDPR Article 33/34.

10. Governing law and precedence

This DPA is governed by the laws of the United Arab Emirates. In the event of a conflict between this DPA and the Terms of Service with respect to data processing matters, this DPA prevails.

11. Contact

Data protection queries, DSAR requests, and DPA-related correspondence: hello@majleads.com — MAJ Leads · Dubai, United Arab Emirates.

You may also lodge a complaint with the UAE Data Office or your local supervisory authority.