Data Processing Agreement (DPA)
Last updated: August 11, 2026
1. Overview
This Data Processing Agreement (DPA) forms part of the VOXUB Terms of Service and applies to customers who process personal data through the VOXUB platform. It reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and similar data protection laws.
By entering into this DPA, VOXUB acts as a data processor on behalf of the customer (the data controller). The customer's use of VOXUB services to process personal data is governed by this DPA alongside the Terms of Service and Privacy Policy.
2. Processor Obligations
VOXUB, as the data processor, agrees to:
- Process personal data only on documented instructions from the customer, including with regard to transfers of personal data to a third country unless required by law.
- Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security testing.
- Respect the conditions for engaging another processor (sub-processor) as set out in Section 5.
- Assist the customer in responding to requests for exercising the data subject's rights under GDPR.
- Assist the customer in ensuring compliance with obligations regarding security of processing, breach notification, data protection impact assessments, and prior consultation.
- At the customer's choice, delete or return all personal data after the end of the services, and delete existing copies unless applicable law requires storage.
3. Customer Obligations
The customer, as the data controller, is responsible for:
- Ensuring that the processing of personal data through VOXUB is lawful and has a valid legal basis under applicable data protection law.
- Obtaining any necessary consents from data subjects (including callers) before their data is processed through VOXUB.
- Complying with call recording consent laws applicable in the customer's and caller's jurisdiction.
- Providing accurate instructions to VOXUB regarding the processing of personal data.
- Ensuring that the personal data provided to VOXUB is accurate and up to date.
4. Security Measures
VOXUB implements the following technical and organizational security measures:
- Encryption of data in transit using TLS 1.2+ and data at rest in the database and object storage.
- Role-based access control (RBAC) with least-privilege principles for all internal access.
- Regular security audits and penetration testing.
- Comprehensive audit logging of all data access and administrative actions.
- Automated data retention and deletion processes with documented retention schedules.
- Incident response procedures with breach notification capabilities within 72 hours.
5. Sub-Processors
VOXUB engages sub-processors to deliver its services. A current list of sub-processors is available on our Sub-Processors page. VOXUB will notify customers of any intended changes concerning the addition or replacement of sub-processors, giving customers the opportunity to object to such changes.
6. International Data Transfers
For transfers of personal data from the EU/EEA/UK to the United States, VOXUB relies on the EU-US Data Privacy Framework (where applicable) and Standard Contractual Clauses (SCCs) with its sub-processors. A Transfer Impact Assessment is conducted for countries without an adequacy decision.
7. Audit Rights
The customer may audit VOXUB's compliance with this DPA, subject to reasonable notice and confidentiality obligations. Alternatively, VOXUB may provide a third-party audit report (e.g., SOC 2) to demonstrate compliance.
8. Contact
For questions about this DPA or to request a signed copy, contact us at privacy@voxub.com.