NewCall a live VoiFlow agent in your region. It picks up on the first ring.Call it now
VoiFlow

Data Processing Agreement

Version 1.016 min readEffective from enter the publication date

How VoiFlow processes personal data on a customer's behalf: instructions, security, sub-processors, transfers, retention and audit.

This agreement applies when VoiFlow processes personal data for a customer under the VoiFlow Terms of Use or a VoiFlow Partner Agreement. It sets out the instructions, safeguards and assistance required by Article 28 of the UK GDPR and by equivalent laws that apply to the processing. It forms part of the customer's agreement with VoiFlow from the date the customer accepts those terms, without a separate signature.

The VoiFlow contracting company is Legal company name, company number Company number, registered office Registered office address. Data protection enquiries go to Data protection contact email.

1 Definitions and scope

1.1In this agreement: Agreement means the Terms of Use, any Partner Agreement and the Orders between VoiFlow and the Customer; Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR where it applies to the processing, and any other data protection law that applies to the processing of Customer Personal Data; Customer Personal Data means personal data contained in Customer Content that VoiFlow processes on the Customer's behalf; Sub-processor means a third party that VoiFlow engages to process Customer Personal Data; and Restricted Transfer means a transfer of Customer Personal Data that Applicable Data Protection Law permits only with an adequacy decision or another transfer mechanism. Controller, processor, data subject, personal data, personal data breach and processing have the meanings given in the UK GDPR. Other capitalised terms have the meanings given in the Terms of Use.

1.2This agreement applies to Customer Personal Data. It does not apply to personal data that VoiFlow processes as a controller for its own business, such as account, contact, billing, payment, security and usage records, which the VoiFlow Privacy Policy describes.

1.3For the processing of Customer Personal Data, this agreement prevails over the Terms of Use, any Partner Agreement and any Order. A completed transfer mechanism in Annex 4 prevails over this agreement to the extent required by law.

2 Roles of the parties

2.1Where the Customer decides the purposes and means of processing Customer Personal Data, the Customer is the controller and VoiFlow is its processor.

2.2Where the Customer processes Customer Personal Data on behalf of another business, such as an End Customer under a Partner Agreement, the Customer is a processor and VoiFlow is its Sub-processor. The Customer confirms that its controller has authorised it to appoint VoiFlow and that the Customer's instructions are consistent with the controller's instructions.

2.3Where the Customer is a controller, it is responsible for having a lawful basis for the processing, giving required privacy notices, obtaining any required consents for calls and recordings, and the accuracy of Customer Personal Data. Where the Customer is a processor, it is responsible for obtaining its controller's documented instructions and authorisations, passing on to VoiFlow only instructions consistent with them, and passing to its controller the information and assistance this agreement provides. The lawful basis for that processing remains the controller's responsibility. In either role, the Customer must ensure that its instructions comply with Applicable Data Protection Law.

2.4VoiFlow keeps limited billing and security metadata as a controller for metering, billing, security, fraud prevention and legal compliance, under the Privacy Policy. This metadata is limited to session identifiers, account and Workspace identifiers, start and end times, duration, Managed AI Profile, and the telephone numbers needed to bill carrier charges or investigate abuse. It never includes recordings, transcripts, summaries or other call content, which remain Customer Personal Data.

3 Processing on documented instructions

3.1VoiFlow processes Customer Personal Data only on the Customer's documented instructions. The Customer's instructions are this agreement, the Agreement, the Customer's configuration and use of the Services, and any further written instructions that VoiFlow accepts. They include the international transfers recorded in Annex 4.

3.2VoiFlow may process Customer Personal Data otherwise only where domestic law that applies to VoiFlow requires it, and then only as far as Applicable Data Protection Law and clause 7 permit. In that case VoiFlow informs the Customer of the legal requirement before processing, unless that law prohibits the notice on important grounds of public interest. VoiFlow will challenge or seek to narrow a request from a foreign authority where there are reasonable grounds to do so.

3.3VoiFlow will inform the Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law. VoiFlow will not carry out the affected processing until the instruction is changed or the parties agree, on a reasonable basis, that it is lawful. Unaffected processing continues.

3.4Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.

3.5VoiFlow does not sell Customer Personal Data, use it for advertising, or combine it with other customers' data except as needed to provide the Services.

4 Confidentiality of personnel

4.1VoiFlow ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate data protection training and have access only to the extent their role requires.

5 Security

5.1VoiFlow implements the technical and organisational measures in Annex 2 to provide a level of security appropriate to the risk, as Article 32 of the UK GDPR requires. VoiFlow may update those measures, provided that the overall level of protection is not materially reduced.

5.2The Customer is responsible for the security of its own systems, devices, credentials, integrations and User access, and for the telephony and network services it contracts for.

6 Sub-processors

6.1The Customer gives general authorisation for VoiFlow to engage the Sub-processors listed in Annex 3 and those added under this clause.

6.2VoiFlow engages each Sub-processor under a written contract that imposes the same data protection obligations as this agreement, in particular sufficient guarantees of appropriate technical and organisational measures. VoiFlow remains fully liable to the Customer for each Sub-processor's performance of those obligations.

6.3VoiFlow will notify the Customer at least 30 days before adding or replacing a Sub-processor, stating its name, function and processing location.

6.4The Customer may object on reasonable data protection grounds within 15 days after the notice. The parties will discuss the objection in good faith. If it is not resolved before the change takes effect, the Customer may terminate the affected Services without penalty and receive a refund of unused prepayments and release from affected future commitments under Terms of Use clause 17.4.

6.5Where a Sub-processor must be replaced urgently to protect the security or continuity of the Services, VoiFlow may give shorter notice and will explain why. The objection right in clause 6.4 then applies from the notice. An urgent replacement must not create a Restricted Transfer that Annex 4 does not cover.

6.6A provider is VoiFlow's Sub-processor when it processes Customer Personal Data on VoiFlow's behalf to deliver the Services. A provider that processes some of that data for its own purposes, such as a telephone carrier routing calls and meeting its own legal obligations, may act as an independent controller for that activity, and Annex 3 records that role and the data it receives. A third party that provides a separate service under its own contract with the Customer, and receives Customer Personal Data only because the Customer directs the Services to send it there, is not VoiFlow's Sub-processor, and Annex 1 records those flows. Who selected or pays for a provider does not by itself decide its role.

7 International transfers

7.1VoiFlow makes a Restricted Transfer of Customer Personal Data only where the destination is covered by an adequacy decision or adequacy regulations under Applicable Data Protection Law, or where a transfer mechanism for that transfer is recorded as completed in Annex 4.

7.2Until Annex 4 records a completed mechanism for a Restricted Transfer, VoiFlow will not make that transfer. VoiFlow completes the Annex 4 entry, including any required transfer risk assessment, and gives it to the Customer before the transfer begins.

7.3Where the transfer mechanism is the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or the EU Standard Contractual Clauses, it applies only when its tables and annexes are completed for the actual transfer and it is signed or incorporated by reference to that completed version. This agreement does not complete those documents by itself.

7.4Where the law that applies to the Customer restricts transfers of personal data to VoiFlow, the Customer tells VoiFlow before processing begins and the parties complete the required mechanism.

7.5A new processing location for Customer Personal Data follows the notice and objection process in clause 6.

8 Requests from individuals

8.1VoiFlow forwards to the Customer any request from an individual about Customer Personal Data within 5 Business Days after receiving it, unless the law prevents this. VoiFlow does not respond to the request itself except to direct the requester to the Customer, unless the Customer instructs it to respond.

8.2VoiFlow assists the Customer to respond to requests to exercise data subject rights through the export, search, correction and deletion functions of the Services, and with reasonable further help where those functions are not enough.

8.3Where the Customer acts as processor for an End Customer and becomes unavailable, VoiFlow may respond to that End Customer as the controller under the process in the Partner Agreement, after verifying the requester's identity and authority and confirming that the response is lawful.

9 Assistance with compliance

9.1Taking into account the nature of the processing and the information available to it, VoiFlow assists the Customer to meet its obligations on security of processing, personal data breach notification, data protection impact assessments and prior consultation with a supervisory authority.

9.2Ordinary assistance is included in the fees. VoiFlow may charge for substantial assistance that goes beyond the functions of the Services only at rates agreed in advance, and not where the assistance is needed because of VoiFlow's breach. A discussion about charges does not delay assistance needed to meet a legal deadline.

10 Personal data breaches

10.1VoiFlow notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

10.2The notice describes, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. VoiFlow provides further information in phases as it becomes available.

10.3VoiFlow investigates the breach, takes reasonable steps to contain it and limit its effects, preserves relevant evidence and cooperates with the Customer's response.

10.4The Customer decides whether to notify supervisory authorities, its controllers and affected individuals, unless VoiFlow has its own legal obligation to notify. A notice from VoiFlow is not an admission of fault.

11 Retention, return and deletion

11.1During the Agreement, VoiFlow retains Customer Personal Data in line with Annex 5 and the retention settings the Customer configures. The Customer can delete Customer Personal Data using the functions of the Services or instruct VoiFlow to delete it.

11.2At the end of the Services, the Customer chooses whether Customer Personal Data is returned, by export in the formats the Documentation describes, or deleted. The Services end, for this purpose, when processing for the Customer actually stops, including after any agreed transition period. The Customer may export during the export period in Terms of Use clause 26.6, and may instruct deletion at any time, including before that period ends. VoiFlow does not withhold an export because of a dispute about fees, but may restrict account access to export functions.

11.3VoiFlow deletes Customer Personal Data from active systems within 30 days after the Customer's deletion instruction or, if the Customer gives none, after the export period ends. VoiFlow also deletes any other copies, unless the law requires it to keep them. Backups are kept isolated from ordinary use and expire within the backup period in Annex 5. If a backup is restored before it expires, VoiFlow applies the deletion again before the restored data is used.

11.4VoiFlow may keep Customer Personal Data longer only where the law requires it, and then only for that purpose and period.

11.5VoiFlow confirms deletion in writing on request.

12 Information and audits

12.1VoiFlow makes available to the Customer the information necessary to demonstrate compliance with Article 28 of the UK GDPR, including its security policies, a description of the measures in Annex 2 and any independent reports it holds. VoiFlow does not claim certifications or reports it does not hold.

12.2If that information is not sufficient, or a supervisory authority requires it, or after a personal data breach affecting the Customer, the Customer or an independent auditor bound by confidentiality may audit VoiFlow's compliance with this agreement. Audits require 30 days notice, except after a breach or at a supervisory authority's request, take place during business hours, and occur no more than once in any 12 months unless a breach or supervisory authority requires more.

12.3An audit does not give access to other customers' data, to systems in a way that could affect their security, or to VoiFlow's confidential information unrelated to the Customer. The Customer pays its own audit costs. VoiFlow pays the reasonable cost of verifying the remedy of a material breach the audit finds.

13 AI and voice processing

13.1VoiFlow does not use Customer Personal Data to train or fine-tune AI models, whether its own or a third party's, unless the Customer gives a specific written opt-in that identifies the data, purpose and suppliers.

13.2VoiFlow configures the settings and contracts of each model supplier listed in Annex 3 so that the supplier does not use Customer Personal Data for training and retains it no longer than Annex 3 records.

13.3VoiFlow does not use call audio to identify individuals by their voice, or to create voice models of them, unless the Customer enables a feature that the Documentation describes for that purpose and records that processing in Annex 1.

13.4VoiFlow processes special category data only where the Order permits it and Annex 1 records it with the safeguards that apply.

14 Liability and term

14.1Each party's liability under this agreement is subject to Terms of Use clause 24. Nothing in this agreement limits the rights of data subjects or the powers of a supervisory authority.

14.2This agreement applies for as long as VoiFlow processes Customer Personal Data, including during the export and deletion periods.

Annex 1 Description of the Processing

Item Description
Subject matter Provision of the VoiFlow Services under the Agreement, including AI voice calls, workflows, records and related support
Duration The term of the Agreement and the export and deletion periods in clause 11
Nature of processing Collection through calls and integrations, recording where enabled, transcription, AI analysis and response generation, storage, retrieval, organisation into records, transmission to integrations the Customer configures, support access and deletion
Purpose Providing, securing and supporting the Services as the Customer configures them
Data subjects People who call or are called by the Customer's AI agents; customers, patients, clients and other contacts whose records the Customer holds in the Services; staff and Users of the Customer and its End Customers
Types of personal data Names, telephone numbers, email addresses and other contact details; call audio and recordings; transcripts and summaries; appointment, task, ticket and case records; information that callers disclose during calls; technical and usage data linked to a call
Special category data None, or the categories permitted by the Order and the safeguards applied
Customer-specific additions Any additional data types, purposes or data subjects for this Customer
Customer-directed data flows Integrations and Customer-contracted services to which the Services send data on the Customer's instruction
Frequency Continuous for the term of the Agreement

Annex 2 Security Measures

VoiFlow will implement the following measures before it processes Customer Personal Data in production and will maintain them while it processes that data. They are contractual obligations. They do not state that VoiFlow holds any certification.

1Access control. Unique user accounts, role-based access granted on a least-privilege basis, multi-factor authentication for administrative access to production systems, and prompt removal of access when a role changes or ends.

2Tenant separation. Logical separation of each Partner Environment and Workspace, with authorisation checks on every request, and testing of that separation before production release of changes that affect it.

3Encryption. Encryption in transit over public networks for the API, hosted interfaces and connections between VoiFlow and its Sub-processors, and encryption at rest for stored Customer Content. If a connection to a Sub-processor cannot be encrypted, VoiFlow records the alternative safeguard in Annex 3 before using it. Telephone calls carried over the public telephone network may not be encrypted end to end.

4Credentials and secrets. Secrets and API keys stored in a controlled secret store or encrypted configuration, rotated after suspected exposure, and never placed in client applications.

5Logging and monitoring. Logging of security-relevant events and administrative actions, monitoring for abnormal activity, and retention of those logs for the period in Annex 5.

6Vulnerability management. Risk-based patching of systems and dependencies, and review of code changes before release.

7Backup and recovery. Backups at the frequency daily, retained for the period in Annex 5, with tested restore procedures. Recovery objectives: Recovery point and recovery time objectives, or no numerical objective.

8Incident response. A documented process for detecting, assessing, containing and notifying incidents, consistent with clause 10.

9Personnel. Confidentiality obligations and security awareness training for personnel with access to Customer Personal Data.

10Suppliers. Written contracts with Sub-processors, review of their security commitments, and the model supplier settings in clause 13.2.

11Physical security. Hosting in data centres operated by the hosting Sub-processors in Annex 3, which are responsible for physical safeguards.

12Data minimisation. Retention settings that the Customer can configure where the Services provide them, and deletion processes consistent with Annex 5.

Annex 3 Sub-processors and Provider Roles

VoiFlow completes this list before Customer Personal Data is processed in production and keeps it current under clause 6. VoiFlow does not engage a Sub-processor for Customer Personal Data until it is listed here, and records any provider that acts as an independent controller for part of the data with that role.

Function Legal entity Data processed Location Role, transfer mechanism and settings
Cloud hosting and storage Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings
Speech recognition Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings
Language model Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings
Speech generation Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings
Telephony supplied by VoiFlow Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings
Email or messaging Legal entity name Data categories Country Sub-processor or independent controller, mechanism in Annex 4, retention and training settings

Rows may be added or removed to reflect the actual suppliers. A function that VoiFlow does not use is deleted from the list rather than left blank.

Annex 4 International Transfers

VoiFlow records each Restricted Transfer of Customer Personal Data here before it begins. Mechanisms that may be used, where they fit the facts, include adequacy regulations or decisions, the UK Extension to the EU-US Data Privacy Framework for certified US recipients, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, and the EU Standard Contractual Clauses. The UK documents are published by the Information Commissioner's Office.

Transfer Exporter and importer Destination Mechanism Completed document and risk assessment
Description of transfer Exporter and importer Country Mechanism Document reference and date
Description of transfer Exporter and importer Country Mechanism Document reference and date
Description of transfer Exporter and importer Country Mechanism Document reference and date

Annex 5 Retention and Deletion

The periods below are VoiFlow's defaults, as processor, for Customer Personal Data while the Agreement is in force. Where the Services provide a retention setting, the Customer's setting applies instead. After the Services end, clause 11 applies to all Customer Personal Data. The billing and security metadata that VoiFlow keeps as controller under clause 2.4 is retained under the Privacy Policy, and VoiFlow may not keep call content by treating it as that metadata.

Record Default retention Customer control
Call recordings 90 days Configurable per Workspace where the Services provide a setting
Transcripts and call summaries 12 months Configurable per Workspace where the Services provide a setting
Workspace records such as contacts, tasks, tickets and appointments Until deleted by the Customer The Customer deletes or exports them
Knowledge, prompts and configurations Until deleted by the Customer The Customer deletes or exports them
Call logs and technical records linked to calls, held as processor 12 months Not configurable
Security and audit logs 12 months Not configurable
Backups Rolling 35 days Expire within the backup cycle