Data Processing Agreement (DPA)

For customers using the Voxify API or Embedded SDK to process their own users’ data.

Effective date: 1 August 2026 · Last updated: 28 July 2026 · Version 1.1

This DPA forms part of the Terms of Service between GZK CONSULTING S.R.L. (“Processor”, “Voxify”) and the customer (“Controller”, “you”) when Voxify processes personal data on the Controller’s behalf via the public API or Embedded SDK. It implements Article 28 of the GDPR. Where there is a conflict on data protection, this DPA prevails over the Terms.

1. Definitions

“GDPR” means Regulation (EU) 2016/679. “Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “personal data breach” have the meanings in the GDPR. “Customer Personal Data” means personal data Voxify processes on the Controller’s behalf under the Terms.

2. Roles & scope

The Controller determines the purposes and means of processing Customer Personal Data; Voxify acts as processor. The subject-matter, duration, nature, purpose, types of data and categories of data subjects are described in Annex I.

3. Processing on documented instructions

Voxify processes Customer Personal Data only on the Controller’s documented instructions (including as set out in the Terms and the Controller’s use of the API/SDK), unless required by EU or Member State law, in which case Voxify informs the Controller unless legally prohibited. Voxify informs the Controller if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality

Voxify ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as needed to provide the Service.

5. Security (Art. 32)

Voxify implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, hashed credentials, logging, and measures to restore availability after an incident. A summary is in Annex II.

6. Sub-processors

7. Assistance to the Controller

8. Return or deletion

At the Controller’s choice, on termination of the Service Voxify deletes or returns all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage. Standard retention windows for backups and legally required records apply.

9. Audits & information

Voxify makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, notice and frequency limits. Voxify may satisfy audit requests through up-to-date third-party certifications or reports where available.

10. International transfers

Where Voxify or its sub-processors transfer Customer Personal Data outside the EEA, such transfers are covered by an adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework (where the recipient is certified), or another valid transfer mechanism.

11. Liability & governing law

Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the laws of Romania, consistent with the Terms.

Annex I — Description of processing

ItemDetail
Subject-matterProvision of AI audio-creative generation via the Voxify API / Embedded SDK.
DurationFor the term of the Controller’s subscription/use, plus deletion/retention periods.
Nature & purposeHosting, transmission, transcoding, AI text-to-speech, sound-effect generation, AI script generation, mixing/mastering, rendering and storage of content submitted via the API/SDK.
Types of personal dataEnd-user identifiers passed by the Controller (e.g. user IDs), content submitted (scripts, briefs, uploaded audio — which may contain recorded voices), technical/usage data (IP, device).
Special categoriesNone processed by the Processor. Voice cloning is not offered by the Service, so no voiceprint or other biometric identifier is created from submitted audio. The Controller must not submit special-category data through the Service; if the Controller submits recordings of identifiable individuals, the Controller remains responsible for the lawful basis for doing so.
Categories of data subjectsThe Controller’s end users and any individuals whose voice or data the Controller submits.

Annex II — Security measures (summary)

This is a summary of measures actually implemented, not a target state. Measures may be improved over time provided the level of protection is not reduced. A Controller may request current details, including the status of encryption at rest and of independent security testing, at support@voxify.studio.

Annex III — Authorised sub-processors

Sub-processorServiceLocation / transfer basis
ElevenLabsText-to-speech, sound-effect generationUS — SCCs / DPF
OpenAIAI script / recommendation generationUS — SCCs / DPF
Amazon Web Services (AWS)Application hosting, database (RDS), object storage (S3)US (us-east-1) — SCCs
Amazon SES (AWS)Transactional emailUS (us-east-1) — SCCs
StripeSubscription payments and invoicingIreland (EU) & US — SCCs / DPF
Google (Analytics, Fonts)Analytics, fontsEU/US — SCCs / DPF
ipapi.coIP geolocation at sign-up/sign-inEU
Melod.ieLicensed music library assetsEU

Note on hosting location: the Processor’s infrastructure runs in the United States (AWS, US East / N. Virginia). Personal data submitted through the API/SDK is therefore stored and processed outside the EEA, under the Standard Contractual Clauses referenced in this DPA. Controllers with an EU-only hosting requirement should raise it before contracting.

This annex is kept synchronised with the sub-processor list in the Privacy Policy.