Data Processing Agreement (DPA)

For customers using the Voxify API or Embedded SDK to process their own users’ data.

Effective date: 8 June 2026 · Last updated: 8 June 2026 · Version 1.0

This DPA forms part of the Terms of Service between GZK CONSULTING S.R.L. (“Processor”, “Voxify”) and the customer (“Controller”, “you”) when Voxify processes personal data on the Controller’s behalf via the public API or Embedded SDK. It implements Article 28 of the GDPR. Where there is a conflict on data protection, this DPA prevails over the Terms.

1. Definitions

“GDPR” means Regulation (EU) 2016/679. “Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings in the GDPR. “Customer Personal Data” means personal data Voxify processes on the Controller’s behalf under the Terms.

2. Roles & scope

The Controller determines the purposes and means of processing Customer Personal Data; Voxify acts as processor. The subject-matter, duration, nature, purpose, types of data and categories of data subjects are described in Annex I.

3. Processing on documented instructions

Voxify processes Customer Personal Data only on the Controller’s documented instructions (including as set out in the Terms and the Controller’s use of the API/SDK), unless required by EU or Member State law, in which case Voxify informs the Controller unless legally prohibited. Voxify informs the Controller if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality

Voxify ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as needed to provide the Service.

5. Security (Art. 32)

Voxify implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, hashed credentials, logging, and measures to restore availability after an incident. A summary is in Annex II.

6. Sub-processors

7. Assistance to the Controller

8. Return or deletion

At the Controller’s choice, on termination of the Service Voxify deletes or returns all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage. Standard retention windows for backups and legally required records apply.

9. Audits & information

Voxify makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, notice and frequency limits. Voxify may satisfy audit requests through up-to-date third-party certifications or reports where available.

10. International transfers

Where Voxify or its sub-processors transfer Customer Personal Data outside the EEA, such transfers are covered by an adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework (where the recipient is certified), or another valid transfer mechanism.

11. Liability & governing law

Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the laws of Romania, consistent with the Terms.

Annex I — Description of processing

ItemDetail
Subject-matterProvision of AI audio-creative generation via the Voxify API / Embedded SDK.
DurationFor the term of the Controller’s subscription/use, plus deletion/retention periods.
Nature & purposeHosting, transmission, transcoding, AI text-to-speech, voice cloning, AI script generation, rendering and storage of content submitted via the API/SDK.
Types of personal dataEnd-user identifiers passed by the Controller (e.g. user IDs), content submitted (scripts, briefs, uploaded audio), voice samples / biometric voice data where voice cloning is used, technical/usage data (IP, device).
Special categoriesBiometric voice data, only where the Controller uses voice cloning. The Controller is responsible for obtaining explicit consent from data subjects.
Categories of data subjectsThe Controller’s end users and any individuals whose voice or data the Controller submits.

Annex II — Security measures (summary)

Annex III — Authorised sub-processors

Sub-processorServiceLocation / transfer basis
ElevenLabsText-to-speech, voice cloning, sound effectsUS — SCCs / DPF
OpenAIAI script / recommendation generationUS — SCCs / DPF
[Hosting / cloud provider]Application & data hosting[Region / basis]
Google (Analytics, Fonts)Analytics, fontsEU/US — SCCs / DPF
ipapi.coIP geolocation[Confirm]
[Email provider]Transactional email[Region / basis]

Keep this annex synchronised with the Privacy Policy sub-processor list and the live backend.