01Scope and roles
This addendum forms part of the agreement between VoisX and each customer that uses the VoisX products. For personal data the customer puts into or collects through the products, the customer is the controller and VoisX is the processor. It applies alongside the UAE PDPL, India’s DPDP Act and, where applicable, the EU and UK GDPR.
02Details of processing
Subject matter and purpose: providing VoisX Cloud Platform and related products, including handling calls and chats, running agent tools and workflows, storing transcripts and, when enabled, recordings.
Duration: for the term of the customer’s account, plus any period needed to return or delete data.
Types of data: names, contact details, conversation content (audio, transcripts, messages), data passed to and from connected tools, and usage metadata.
Data subjects: the customer’s end users and callers, and the customer’s staff who use the console.
03Our obligations
VoisX processes customer personal data only on the customer’s documented instructions, including the settings it chooses in the product. We make sure staff with access are bound by confidentiality, and we help customers respond to data subject requests and carry out data protection impact assessments where needed.
04Security measures
We apply technical and organisational measures that include storing data in the region the customer chooses (India or UAE), keeping credentials in a dedicated secrets vault, isolating customer organisations and projects from each other, role-based access for customer users, audit logging of administrative actions, encryption in transit, and call recording that stays off until the customer enables it.
05Subprocessors
The customer authorises VoisX to use subprocessors to provide the service. Current subprocessors are Microsoft Azure (hosting), OpenAI, Google and ElevenLabs (AI models and speech), Twilio and Plivo (telephony), and Google Workspace (business communications).
We bind each subprocessor to data protection terms at least as protective as this addendum. We’ll give notice before adding or replacing a subprocessor, and the customer may object on reasonable data protection grounds.
06International transfers
Customer data is stored in the region the customer chooses. Where a subprocessor processes data outside that region, for example an AI model provider, we make sure the transfer is covered by appropriate safeguards under the applicable law.
07Personal data breaches
If we become aware of a personal data breach affecting customer data, we’ll notify the affected customer without undue delay, and in any case within 72 hours. We’ll share the information the customer needs to meet its own obligations and take steps to contain the breach.
08Return and deletion
When the service ends, the customer can export its data within 30 days, after which we delete it unless the law requires us to keep it. During the service, call recordings are deleted according to the retention period the customer sets.
09Audits
On reasonable request, we’ll provide the information needed to show compliance with this addendum. Customers can send requests to hello@voisx.ai.
