Data Processing Agreement
Version 2026-07-28 · Last updated: 28 July 2026
1. Scope and formation
This Data Processing Agreement ("DPA") forms part of the VoiceFleet Business Terms or other agreement between VoiceFleet ("VoiceFleet" or "Processor") and the Customer ("Customer" or "Controller"). It applies where VoiceFleet processes personal data on Customer's behalf in providing the service. It takes effect when Customer accepts the Terms, signs an order, or first provides personal data for processing.
GDPR terms such as controller, processor, personal data, processing, data subject, and supervisory authority have the meanings in applicable data-protection law. Customer is the controller and VoiceFleet is the processor, except where each independently acts as a controller for its own account, billing, security, or legal-compliance data.
2. Customer instructions and responsibilities
VoiceFleet will process Customer Personal Data only to provide, secure, support, and maintain the contracted service; as configured by Customer; as documented in the agreement and this DPA; or as required by law. If law requires other processing, VoiceFleet will notify Customer first unless prohibited.
Customer is responsible for the lawfulness, fairness, accuracy, transparency, and proportionality of its instructions and data; its privacy notices; caller and recording notices; lawful bases and Article 9 conditions; retention choices; rights requests; and any required DPIA or consultation. VoiceFleet will promptly inform Customer if an instruction appears to infringe applicable data-protection law.
3. Confidentiality and personnel
VoiceFleet will ensure that persons authorised to process Customer Personal Data are bound by confidentiality duties, receive access only where needed for their role, and are informed of relevant security and data-protection obligations.
4. Security
VoiceFleet will maintain measures appropriate to the risk, taking account of the state of the art, implementation cost, processing context, and potential impact on people. The current baseline measures are described in Schedule 2. Customer remains responsible for secure account configuration, user access, integrations, prompts, exports, endpoints, and its own systems.
5. Subprocessors
Customer gives general written authorisation for VoiceFleet to use the subprocessors in Schedule 3 and to replace or add subprocessors needed to operate the service. VoiceFleet will impose data-protection obligations that provide materially equivalent protection and remains responsible for each subprocessor's performance of those obligations.
We will update this page and, for a new subprocessor materially affecting Customer Personal Data, provide reasonable advance notice to the account administrator where practicable. Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected feature.
6. International transfers
VoiceFleet will not transfer Customer Personal Data from the EEA, UK, or Switzerland to a country lacking an applicable adequacy decision unless it uses a lawful transfer mechanism. Where required, the European Commission Standard Contractual Clauses for controller-to- processor or processor-to-processor transfers are incorporated, together with the UK addendum where applicable. The DPA and schedules supply the annex information. VoiceFleet will apply supplementary measures where reasonably required by a transfer assessment.
7. Assistance
Taking account of the processing and information available, VoiceFleet will reasonably assist Customer with:
- data-subject access, correction, deletion, restriction, portability, and objection requests;
- security, breach assessment and notification, DPIAs, and prior consultation;
- information needed to demonstrate compliance with Article 28; and
- deleting or exporting Customer Personal Data using available service controls.
Customer should send requests to [email protected]. VoiceFleet will not respond directly to a caller on Customer's behalf unless instructed or legally required.
8. Personal data breaches
VoiceFleet will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will provide available information about the nature of the incident, affected data and people, likely consequences, containment, and a contact point. Notification is not an admission of fault. VoiceFleet may provide information in phases as the investigation develops.
9. Return, deletion, and audits
During the term, Customer may use available exports. On termination and at Customer's choice, VoiceFleet will delete or return Customer Personal Data, normally within 30 days, unless law requires retention. Restricted backup copies may remain until overwritten under normal backup cycles and will not be restored except for recovery, after which deletion rules resume.
VoiceFleet will provide relevant policies, summaries, and third-party assurance that it has available. If this is insufficient, Customer may conduct one reasonable audit per year, or after a material incident, on at least 30 days' notice, during business hours, subject to confidentiality, security, and reimbursement of reasonable costs. Audits must not expose another customer's data or disrupt the service.
10. Liability, conflict, and duration
The liability provisions in the main agreement apply to this DPA, subject to mandatory law. This DPA controls over the main agreement for a direct conflict about processing Customer Personal Data. It continues for as long as VoiceFleet processes Customer Personal Data.
Schedule 1 — Processing details
Subject matter and purpose
Providing AI telephone reception, routing, transcription, summaries, messaging, bookings, integrations, account support, security, and customer-configured workflows.
Duration and frequency
Continuous or as initiated by callers, Customer users, integrations, and configured automations during the service term, followed by the deletion periods in the agreement.
Data subjects
Customer staff and contractors; callers, customers, prospects, patients or service users; appointment attendees; contacts in Customer systems; and other people whose data Customer lawfully submits.
Personal data
Names, work and contact details, telephone numbers, caller ID, audio, transcript, summary, call metadata, messages, booking details, calendar availability and events, customer records, support content, technical identifiers, and other data included in Customer instructions.
Sensitive data
Not required by default. Depending on Customer's lawful configuration, callers may provide health or other special-category data. Customer must minimise such processing and satisfy Section 2 and the Terms. Payment-card credentials, passwords, and government identifiers must not be collected through ordinary call workflows.
Schedule 2 — Baseline technical and organisational measures
- Encrypted HTTPS/TLS transport and storage encryption supplied by core infrastructure providers.
- Authenticated accounts, scoped service credentials, role-based workspace access, and restricted administrative access.
- Logical organisation and tenant scoping in application and database access paths.
- Secrets stored outside source code and separated production/development environments.
- Application monitoring, security logging, abuse controls, rate limiting, and dependency maintenance.
- Provider resilience, backups, recovery procedures, and regional deployment options where available.
- A 30-day recording-retention job that deletes the provider call artifacts before clearing the local recording reference.
- Incident investigation and notification procedures and confidentiality obligations.
- Data minimisation controls, integration revocation, and deletion/export assistance.
Schedule 3 — Core subprocessors
| Provider | Purpose | Typical processing location |
|---|---|---|
| Vercel | Website and application hosting | EEA / United States |
| Supabase | Database, authentication, and storage | Customer-selected region / United States support |
| Vapi | Voice AI orchestration and call artifacts | Customer-selected region / United States |
| OpenAI | Language-model processing | EEA / United States depending on configuration |
| Deepgram | Speech-to-text transcription | EEA / United States depending on configuration |
| ElevenLabs | Text-to-speech and optional voice cloning | EEA / United States |
| Telnyx and Voximplant | Telephone numbers, routing, and communications | Regional / global |
| Stripe | Subscription and payment processing | EEA / United States |
| Resend | Transactional email delivery | United States / global delivery |
| Sentry | Application error monitoring | United States |
| Cloudflare | Network security, delivery, and bot protection | Global |
| Google and Microsoft | Customer-selected authentication, calendar, and productivity integrations | Regional / global |
| Customer-selected booking and CRM providers | Integrations enabled and controlled by Customer | As selected by Customer |
Contact
Data-protection questions: [email protected]. Legal notices: [email protected].