Data Processing Agreement (DPA)
For customers using the Voxify API or Embedded SDK to process their own users’ data.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings in the GDPR. “Customer Personal Data” means personal data Voxify processes on the Controller’s behalf under the Terms.
2. Roles & scope
The Controller determines the purposes and means of processing Customer Personal Data; Voxify acts as processor. The subject-matter, duration, nature, purpose, types of data and categories of data subjects are described in Annex I.
3. Processing on documented instructions
Voxify processes Customer Personal Data only on the Controller’s documented instructions (including as set out in the Terms and the Controller’s use of the API/SDK), unless required by EU or Member State law, in which case Voxify informs the Controller unless legally prohibited. Voxify informs the Controller if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
Voxify ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as needed to provide the Service.
5. Security (Art. 32)
Voxify implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, hashed credentials, logging, and measures to restore availability after an incident. A summary is in Annex II.
6. Sub-processors
- The Controller gives general authorisation for Voxify to engage the sub-processors listed in Annex III, including AI voice/text providers and hosting/analytics providers.
- Voxify imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance.
- Voxify will give the Controller prior notice of intended additions or replacements of sub-processors, allowing the Controller to object on reasonable data-protection grounds.
7. Assistance to the Controller
- Data-subject requests — Voxify assists the Controller, by appropriate technical and organisational measures and insofar as possible, to respond to requests to exercise data-subject rights.
- Compliance — Voxify assists the Controller in ensuring compliance with Articles 32–36 (security, breach notification, data-protection impact assessments, prior consultation), taking into account the nature of processing and information available.
- Breach notification — Voxify notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information the Controller reasonably needs to meet its own notification duties.
8. Return or deletion
At the Controller’s choice, on termination of the Service Voxify deletes or returns all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage. Standard retention windows for backups and legally required records apply.
9. Audits & information
Voxify makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, notice and frequency limits. Voxify may satisfy audit requests through up-to-date third-party certifications or reports where available.
10. International transfers
Where Voxify or its sub-processors transfer Customer Personal Data outside the EEA, such transfers are covered by an adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework (where the recipient is certified), or another valid transfer mechanism.
11. Liability & governing law
Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the laws of Romania, consistent with the Terms.
Annex I — Description of processing
| Item | Detail |
|---|---|
| Subject-matter | Provision of AI audio-creative generation via the Voxify API / Embedded SDK. |
| Duration | For the term of the Controller’s subscription/use, plus deletion/retention periods. |
| Nature & purpose | Hosting, transmission, transcoding, AI text-to-speech, sound-effect generation, AI script generation, mixing/mastering, rendering and storage of content submitted via the API/SDK. |
| Types of personal data | End-user identifiers passed by the Controller (e.g. user IDs), content submitted (scripts, briefs, uploaded audio — which may contain recorded voices), technical/usage data (IP, device). |
| Special categories | None processed by the Processor. Voice cloning is not offered by the Service, so no voiceprint or other biometric identifier is created from submitted audio. The Controller must not submit special-category data through the Service; if the Controller submits recordings of identifiable individuals, the Controller remains responsible for the lawful basis for doing so. |
| Categories of data subjects | The Controller’s end users and any individuals whose voice or data the Controller submits. |
Annex II — Security measures (summary)
- Encryption of data in transit (TLS); hashed passwords; scoped API keys/tokens.
- Role-based access control and least-privilege access for staff.
- Network and application security controls; logging and monitoring.
- Backup and recovery procedures; incident-response process.
- Segregation of Controller data by account, with authorisation checks on every project-scoped request.
- Infrastructure operated on Amazon Web Services, whose data centres are certified to ISO/IEC 27001, SOC 1/2/3 and comparable standards. Those certifications are the infrastructure provider’s; they are not a certification of Voxify Studio itself.
- The Processor does not train AI models on Controller data. How each AI sub-processor may use data submitted to it is governed by that provider’s own terms; current details are available on request.
Annex III — Authorised sub-processors
| Sub-processor | Service | Location / transfer basis |
|---|---|---|
| ElevenLabs | Text-to-speech, sound-effect generation | US — SCCs / DPF |
| OpenAI | AI script / recommendation generation | US — SCCs / DPF |
| Amazon Web Services (AWS) | Application hosting, database (RDS), object storage (S3) | US (us-east-1) — SCCs |
| Amazon SES (AWS) | Transactional email | US (us-east-1) — SCCs |
| Stripe | Subscription payments and invoicing | Ireland (EU) & US — SCCs / DPF |
| Google (Analytics, Fonts) | Analytics, fonts | EU/US — SCCs / DPF |
| ipapi.co | IP geolocation at sign-up/sign-in | EU |
| Melod.ie | Licensed music library assets | EU |