Data Processing Agreement (DPA)

For business customers processing personal data through Voice Omni

Download PDF: Voice Omni DPA v1.0

Parties and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Voice Omni ("Processor") for the processing of Personal Data in connection with the Services.

Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person collected through your use of Voice Omni, including call recordings, transcripts, and caller information.
  • Controller: You, the Voice Omni customer, who determines the purposes and means of processing Personal Data of your end users (callers).
  • Processor: Voice Omni, which processes Personal Data on your behalf.

Processing Details

Subject Matter

Provision of AI voice agent services including call handling, transcription, and analytics.

Nature and Purpose

Processing voice calls, generating transcripts, storing call recordings, and providing insights as instructed by Controller through the Service.

Type of Personal Data

  • Voice recordings (audio files)
  • Call transcripts (text)
  • Caller phone numbers (ANI/Caller ID)
  • Contact information provided in widget forms
  • Call metadata (duration, timestamp, outcome)

Categories of Data Subjects

  • End users calling your Voice Omni phone numbers
  • Website visitors using your Voice Omni chat widgets

Controller Obligations

You (Controller) warrant that:

  • You have a lawful basis for processing (consent, legitimate interest, contract performance)
  • You have provided appropriate privacy notices to data subjects
  • You have obtained necessary consents (e.g., call recording notices)
  • Your instructions to us comply with applicable data protection laws

Processor Obligations

We (Processor) agree to:

  • Process Personal Data only on your documented instructions
  • Ensure confidentiality of persons processing the data
  • Implement appropriate technical and organizational security measures
  • Engage sub-processors only with your consent (see Sub-processors list)
  • Assist with data subject rights requests
  • Assist with data breach notifications
  • Delete or return data upon termination
  • Make available information necessary to demonstrate compliance

Sub-Processors

Current sub-processors are listed at /legal/subprocessors. We will notify you 30 days before adding or changing sub-processors. You may object on reasonable grounds.

International Transfers

Data may be transferred outside the EEA/UK. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for such transfers.

Security Measures

  • Encryption at rest and in transit (TLS 1.3, AES-256)
  • Access controls and authentication (MFA for admin)
  • Regular security audits and penetration testing
  • Incident response procedures
  • Data backup and disaster recovery

Data Breach Notification

We will notify you without undue delay (target: within 24 hours) upon becoming aware of a Personal Data breach affecting your data.

Audit Rights

You may request evidence of our compliance (e.g., SOC 2 reports, security questionnaires). On-site audits require 30 days notice and reasonable compensation for our time.

Contact

DPA questions: dpo@voiceomni.ai


Note: Template DPA. Requires legal review and customization for your jurisdiction and compliance requirements.