• Skip to main content
  • Skip to navigation
  • Skip to search
    Petunia™
    FeaturesPricingIntegrationsAboutContact
    Log inStart free trialSign up
    Loading
    Petunia™

    Reimagining customer communication for the modern business.

    Product

    • Features
    • Pricing
    • Integrations
    • Roadmap
    • What's New

    Resources

    • Help Center
    • Documentation
    • Guides
    • API Reference
    • Community
    • Support

    Company

    • About Us
    • Careers
    • Blog
    • Press
    • Contact

    © 2026 Gray Group International LLC. All rights reserved.·
    Made by gardenpatch 🌱

    Privacy PolicyTerms of ServiceCookie PolicyData Processing Agreement

    Petunia™ is a trademark of Gray Group International LLC. The Petunia name, brand, product design, and content are proprietary. Unauthorized use, imitation, or copying is prohibited.

    Legal

    Data Processing Agreement

    Last updated: September 10, 2026

    Petunia processes your customers’ data on your behalf

    When your business uses Petunia to answer calls, send messages, and book appointments, we handle personal data that belongs to your customers: names, phone numbers, call recordings, transcripts, and appointment details. Under privacy laws such as the GDPR and the CCPA/CPRA, you are the controller (or business) and Petunia is the processor (or service provider). A Data Processing Agreement (DPA) is the contract that sets out that relationship in writing.

    Who needs a DPA

    If your business is subject to the GDPR, the UK GDPR, the CCPA/CPRA, or a similar privacy law, you are generally required to have a written agreement with any provider that processes personal data for you. Most compliance, procurement, and legal teams will ask for one before approving a purchase. Petunia offers a DPA to every customer, on any plan.

    What our DPA covers

    • Roles and instructions — You decide why and how your customers’ data is used. Petunia processes it only on your documented instructions.
    • Purpose limitation — We process personal data only to provide the service you signed up for. We do not sell it and do not use it for our own purposes.
    • Confidentiality and access — Access is limited to people and systems that need it to deliver the service, under confidentiality obligations.
    • Subprocessors — The third-party providers we rely on (telephony, hosting, database, payments, transcription and language-model providers) are listed, and we tell you before adding new ones.
    • Security measures — The technical and organizational safeguards we maintain, including encryption in transit and at rest. The current summary is in the security section of our Privacy Policy.
    • Incident notification — How and when we notify you if personal data we hold for you is affected by a security incident.
    • Helping you respond to your customers — Assistance with access, correction, and deletion requests from the people whose data we process for you.
    • Return and deletion — What happens to your data when the service ends.

    How to request a DPA

    Email privacy@gardenpatch.xyz with the subject line “DPA request”, your company’s legal name, and the name and email address of the person who will sign. We will send the current version for signature. Enterprise customers can also raise this with their account contact.

    Questions about how we process personal data can go to our Data Protection Officer at dpo@gardenpatch.xyz.

    Related documents

    The DPA is incorporated into our Terms of Service and sits alongside our Privacy Policy, which describes what we collect, why, and who we share it with. Where the DPA and those documents differ on the processing of personal data, the DPA controls.

    Privacy PolicyTerms of ServiceCookie PolicyContact Us