Data Processing Agreement
This Data Processing Agreement (“DPA”) supplements the Terms of Service between Voxif Technologies (Private) Limited (“Voxif”, the “Processor”) and the Customer (the “Controller”) and applies whenever Voxif processes personal data on the Controller’s behalf. This DPA is designed to satisfy Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the UK GDPR. To execute, the Controller signs this DPA via the Voxif dashboard or by countersigned PDF; once signed it becomes binding on both parties and supersedes any conflicting terms in the Terms of Service insofar as personal-data processing is concerned.
1. Definitions
Terms not defined here have the meaning given in the GDPR. Specifically: “personal data”, “processing”, “controller”, “processor”, “data subject”, “sub-processor”, “personal-data breach”, “supervisory authority”, “SCCs” (Standard Contractual Clauses approved by the European Commission for international data transfers).
2. Roles
The Controller determines the purposes and means of processing personal data of its end users (call recipients, contact list entries, transcript content). Voxif acts as a Processor for that data — we process it only on the Controller’s documented instructions.
For account-holder data (the Customer’s team members signing into the dashboard) and Voxif’s own service-operation data, Voxif is the Controller and the Privacy Policy governs.
3. Subject matter, duration, nature, purpose, categories, and subjects
Subject matter: processing of personal data by Voxif on behalf of the Controller in the course of providing the Voxif AI voice-agent platform (the “Service”).
Duration: the term of the Controller’s subscription plus the retention windows in Section 6 of the Privacy Policy.
Nature and purpose: orchestration of voice agents — speech-to-text, large-language-model inference (via the Controller’s BYOK providers), text-to-speech, SIP trunking; storage of call metadata, transcripts, contacts, bookings, knowledge-base documents; transactional notifications.
Categories of personal data: contact identifiers (name, phone, email), call metadata (numbers, durations, dispositions, latency), transcript text, optional call recordings, knowledge-base document content, webhook destinations. Sensitive categories may be processed only if the Controller has a lawful basis.
Categories of data subjects: end users (call recipients), the Controller’s contacts and leads, the Controller’s team members.
4. Processor obligations
Voxif shall:
- Process personal data only on the Controller’s documented instructions (including configuration choices, prompts, retention settings, sub-processor selections), or as required by applicable law — in which case Voxif will notify the Controller of that legal requirement before processing, unless the law forbids such notice.
- Ensure that persons authorized to process personal data have committed to confidentiality.
- Implement appropriate technical and organizational measures (set out in Annex II).
- Respect the conditions in Article 28(2) and (4) for engaging sub-processors (see Section 5).
- Assist the Controller in fulfilling its obligation to respond to data-subject requests, including by providing data export tools in the dashboard.
- Assist the Controller in complying with Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation).
- At the Controller’s choice, delete or return personal data at the end of the subscription and delete remaining copies subject to lawful retention obligations (e.g. billing records, security logs).
- Make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow audits as described in Section 9.
- Inform the Controller immediately if an instruction infringes the GDPR.
5. Sub-processors
The Controller authorizes Voxif to engage the sub-processors listed in the current version of the Privacy Policy (Section 4) and at voxif.tech/legal/privacy (updated as new sub-processors are added).
Voxif will notify the Controller of the addition or replacement of a sub-processor at least 30 days before that change takes effect. The Controller may object within 30 days for reasonable grounds (e.g. a credible jurisdictional or compliance concern). If we cannot accommodate the objection, the Controller may terminate the affected portion of the Service for convenience and receive a pro-rata refund of pre-paid fees.
Voxif imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract or equivalent legal act.
6. International transfers
Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, Voxif relies on the European Commission’s 2021 Standard Contractual Clauses (Module 2: Controller-to-Processor, and Module 3: Processor-to-Sub-processor where Voxif is a processor of an upstream processor). The SCCs are incorporated into this DPA by reference and form Annex I, II, and III as set out below. For UK transfers the UK International Data Transfer Addendum applies; for Swiss transfers the Swiss FDPIC’s template applies. Where a transfer impact assessment is required, Voxif will assist the Controller in conducting it.
7. Personal-data breaches
Voxif will notify the Controller of any personal-data breach affecting Controller data without undue delay and in any case within 72 hours of becoming aware of it. The notification will describe (to the extent then known): the nature of the breach, the categories and approximate number of records affected, the likely consequences, the technical and organizational measures taken or proposed to mitigate the breach, and the contact point for further information. Voxif will provide updates as the investigation progresses and assist the Controller in any required notifications to supervisory authorities and data subjects.
8. Return or deletion
On termination of the subscription or earlier on the Controller’s request, the Controller can export its data via the dashboard (CSV/JSON) or via the API. Voxif will then delete remaining copies of the Controller’s data within 30 days, subject to lawful retention obligations (billing records held 7 years for tax compliance; security logs held 12 months). Sub-processors are instructed to delete on the same timeline.
9. Audits
Voxif will provide the Controller, on request and no more than once per 12-month period, with documentation reasonably sufficient to demonstrate compliance with this DPA — including, where available, third-party audit reports (e.g. SOC 2 when issued) and a security-controls questionnaire response.
For Customers with regulatory or contractual audit obligations that cannot be satisfied by the documentation above, an on-site audit may be conducted on 30 days’ written notice, no more than once per 12 months, during business hours, by an independent third-party auditor subject to confidentiality, at the Customer’s expense, and limited to the systems used to process the Customer’s data.
10. Liability
The liability cap in the Terms of Service Section 10 applies to this DPA. Each party’s liability under this DPA is part of (not additional to) that aggregate cap. Nothing in this DPA limits the rights of data subjects under the GDPR.
11. Order of precedence
If there is a conflict between this DPA, the Terms of Service, or other agreements between the parties regarding processing of personal data, this DPA prevails. The SCCs prevail over this DPA only for the specific transfers they govern.
12. Term and termination
This DPA enters into force when both parties sign and remains in effect for the duration of the Terms of Service. It survives termination of the Service to the extent necessary to permit return, deletion, audit, or other post-termination obligations.
Annex I — List of parties
Data exporter (Controller): the Customer signing this DPA (name and address as provided in the Voxif account).
Data importer (Processor): Voxif Technologies (Private) Limited, Karachi, Pakistan. Contact for data-protection matters: privacy@voxif.tech.
Annex II — Technical and organizational security measures
Voxif implements at minimum the following measures, updated from time to time as technology evolves:
- Encryption at rest: AES-256-GCM envelope encryption for provider API keys, SIP credentials, and other secrets; per-organization Data Encryption Key wrapped by a Key Encryption Key held in Oracle Cloud Vault. Database-level encryption on block storage.
- Encryption in transit: TLS 1.2+ on all transport, HSTS, modern cipher suites; strict cert pinning on inter-service backend calls.
- Access control: JWT access tokens with short TTL; refresh tokens revocable per-session; Argon2id password hashing; optional TOTP-based 2FA; role-based access control (Owner / Admin / Operator).
- Webhook integrity: HMAC-SHA256 signing with replay protection (timestamp + nonce window).
- Network isolation: production database not publicly addressable; web tier behind Cloudflare WAF; private VCN between application and database.
- Monitoring: centralized logs with PII redaction; security-relevant events alerted in real time to the on-call engineer; quarterly access review.
- Personnel: all personnel under written confidentiality obligation; background checks for staff with production access; revocation procedure on role change or termination.
- Vendor management: due diligence on each sub-processor; written contract with no-less-protective terms; periodic review.
- Backups: encrypted, region-local, with documented recovery objectives.
- Incident response: documented runbook; 72-hour breach-notification commitment; tabletop exercises at least annually.
Annex III — List of sub-processors
See Privacy Policy Section 4 for the current list. Changes are announced 30 days in advance per Section 5 above.
13. Contact
Privacy / DPA: privacy@voxif.tech.
Legal: legal@voxif.tech.
Security: security@voxif.tech.