Last updated: September 10, 2026
When your business uses Petunia to answer calls, send messages, and book appointments, we handle personal data that belongs to your customers: names, phone numbers, call recordings, transcripts, and appointment details. Under privacy laws such as the GDPR and the CCPA/CPRA, you are the controller (or business) and Petunia is the processor (or service provider). A Data Processing Agreement (DPA) is the contract that sets out that relationship in writing.
If your business is subject to the GDPR, the UK GDPR, the CCPA/CPRA, or a similar privacy law, you are generally required to have a written agreement with any provider that processes personal data for you. Most compliance, procurement, and legal teams will ask for one before approving a purchase. Petunia offers a DPA to every customer, on any plan.
Email privacy@gardenpatch.xyz with the subject line “DPA request”, your company’s legal name, and the name and email address of the person who will sign. We will send the current version for signature. Enterprise customers can also raise this with their account contact.
Questions about how we process personal data can go to our Data Protection Officer at dpo@gardenpatch.xyz.
The DPA is incorporated into our Terms of Service and sits alongside our Privacy Policy, which describes what we collect, why, and who we share it with. Where the DPA and those documents differ on the processing of personal data, the DPA controls.