Data Processing Agreement (DPA)
For customers using the Voxify API or Embedded SDK to process their own users’ data.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings in the GDPR. “Customer Personal Data” means personal data Voxify processes on the Controller’s behalf under the Terms.
2. Roles & scope
The Controller determines the purposes and means of processing Customer Personal Data; Voxify acts as processor. The subject-matter, duration, nature, purpose, types of data and categories of data subjects are described in Annex I.
3. Processing on documented instructions
Voxify processes Customer Personal Data only on the Controller’s documented instructions (including as set out in the Terms and the Controller’s use of the API/SDK), unless required by EU or Member State law, in which case Voxify informs the Controller unless legally prohibited. Voxify informs the Controller if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
Voxify ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as needed to provide the Service.
5. Security (Art. 32)
Voxify implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, hashed credentials, logging, and measures to restore availability after an incident. A summary is in Annex II.
6. Sub-processors
- The Controller gives general authorisation for Voxify to engage the sub-processors listed in Annex III, including AI voice/text providers and hosting/analytics providers.
- Voxify imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance.
- Voxify will give the Controller prior notice of intended additions or replacements of sub-processors, allowing the Controller to object on reasonable data-protection grounds.
7. Assistance to the Controller
- Data-subject requests — Voxify assists the Controller, by appropriate technical and organisational measures and insofar as possible, to respond to requests to exercise data-subject rights.
- Compliance — Voxify assists the Controller in ensuring compliance with Articles 32–36 (security, breach notification, data-protection impact assessments, prior consultation), taking into account the nature of processing and information available.
- Breach notification — Voxify notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information the Controller reasonably needs to meet its own notification duties.
8. Return or deletion
At the Controller’s choice, on termination of the Service Voxify deletes or returns all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage. Standard retention windows for backups and legally required records apply.
9. Audits & information
Voxify makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, notice and frequency limits. Voxify may satisfy audit requests through up-to-date third-party certifications or reports where available.
10. International transfers
Where Voxify or its sub-processors transfer Customer Personal Data outside the EEA, such transfers are covered by an adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework (where the recipient is certified), or another valid transfer mechanism.
11. Liability & governing law
Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the laws of Romania, consistent with the Terms.
Annex I — Description of processing
| Item | Detail |
|---|---|
| Subject-matter | Provision of AI audio-creative generation via the Voxify API / Embedded SDK. |
| Duration | For the term of the Controller’s subscription/use, plus deletion/retention periods. |
| Nature & purpose | Hosting, transmission, transcoding, AI text-to-speech, voice cloning, AI script generation, rendering and storage of content submitted via the API/SDK. |
| Types of personal data | End-user identifiers passed by the Controller (e.g. user IDs), content submitted (scripts, briefs, uploaded audio), voice samples / biometric voice data where voice cloning is used, technical/usage data (IP, device). |
| Special categories | Biometric voice data, only where the Controller uses voice cloning. The Controller is responsible for obtaining explicit consent from data subjects. |
| Categories of data subjects | The Controller’s end users and any individuals whose voice or data the Controller submits. |
Annex II — Security measures (summary)
- Encryption of data in transit (TLS); hashed passwords; scoped API keys/tokens.
- Role-based access control and least-privilege access for staff.
- Network and application security controls; logging and monitoring.
- Backup and recovery procedures; incident-response process.
- [Add encryption-at-rest, data-centre certifications, pen-test cadence, etc. as implemented.]
Annex III — Authorised sub-processors
| Sub-processor | Service | Location / transfer basis |
|---|---|---|
| ElevenLabs | Text-to-speech, voice cloning, sound effects | US — SCCs / DPF |
| OpenAI | AI script / recommendation generation | US — SCCs / DPF |
| [Hosting / cloud provider] | Application & data hosting | [Region / basis] |
| Google (Analytics, Fonts) | Analytics, fonts | EU/US — SCCs / DPF |
| ipapi.co | IP geolocation | [Confirm] |
| [Email provider] | Transactional email | [Region / basis] |