Back to Vosy AI

Data Processing Agreement

Vosy's standard Article 28 / service-provider terms · Last updated: July 27, 2026

This Data Processing Agreement ("DPA") supplements and forms part of the agreement between you and your organization ("Customer," "you," or "Controller") and Vosy LLC ("Vosy," "we," or "Processor") governing your use of the Vosy AI platform (the "Service") — namely the Terms of Service or a Master Services Agreement, as applicable (the "Agreement"). It applies where, and to the extent that, Vosy processes Personal Data on your behalf in providing the Service.

This DPA reflects our standard data-processing terms. Enterprise customers may execute a countersigned copy or negotiate variations under a Master Services Agreement — contact contact@vosy.ai. In the event of a conflict, this DPA controls over the rest of the Agreement with respect to the processing of Personal Data.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement. "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "CCPA" means the California Consumer Privacy Act as amended by the California Privacy Rights Act, and "Business," "Service Provider," "Sell," and "Share" have the meanings given there. "Data Protection Laws" means all privacy and data-protection laws applicable to the processing of Personal Data under this DPA. "Sub-processor" means any third party engaged by Vosy to process Personal Data. "Customer Personal Data" means Personal Data that Vosy processes on your behalf in providing the Service.

2. Roles and Scope

As between the parties, with respect to Customer Personal Data processed in the course of providing the Service, you are the Controller (or Business) and Vosy is the Processor (or Service Provider). Where you process Personal Data on behalf of a third party, you warrant that you are authorized to act as that party's Controller or processor and to engage Vosy. Vosy acts as an independent Controller for limited data it processes for its own purposes (for example, account-administration data, billing records, and security and usage logs), which is governed by our Privacy Policy rather than by this DPA.

The subject matter, duration, nature and purpose of the processing, the categories of Data Subjects, and the types of Personal Data are described in Annex A.

3. Customer Instructions

Vosy will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Vosy will, where legally permitted, inform you of that requirement before processing). Your instructions are set out in this DPA, the Agreement, and your configuration and use of the Service. You are responsible for ensuring that your instructions, and your collection and use of Customer Personal Data, comply with Data Protection Laws — including obtaining any necessary consents and providing any required notices to Data Subjects (such as call-recording and AI-disclosure notices). Vosy will inform you if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

Vosy will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis to provide the Service.

5. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Vosy will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Those measures are described in Annex C. Vosy may update its security measures from time to time provided it does not materially reduce the overall level of protection.

6. Sub-processors

You provide general authorization for Vosy to engage Sub-processors to process Customer Personal Data, subject to this Section. Vosy will: (a) impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA; and (b) remain liable for each Sub-processor's performance of its obligations.

The current list of Sub-processors is set out in Annex B. Which Sub-processors actually process Customer Personal Data depends on your configuration of the Service — for example, which AI model providers you select for an agent, and whether you supply your own provider credentials ("bring your own key"). Vosy will notify you (for example, by updating Annex B and notifying customers through the Service or by email) at least 30 days before adding or replacing a Sub-processor. If you reasonably object to a new Sub-processor on data-protection grounds, you may notify us within that period; we will work with you in good faith to address the objection and, if we cannot, you may terminate the affected portion of the Service.

7. Assistance to Customer

Taking into account the nature of the processing, Vosy will assist you, by appropriate technical and organizational measures and insofar as possible, to:

  • Respond to Data Subject requests. Vosy provides functionality and, where needed, reasonable assistance to help you respond to requests to access, correct, delete, restrict, port, or object to the processing of Personal Data. Where Vosy receives such a request directly from a Data Subject relating to Customer Personal Data, it will refer the Data Subject to you and will not respond except on your instructions or as legally required.
  • Meet your security, breach-notification, and impact-assessment obligations under Articles 32–36 GDPR, taking into account the information available to Vosy.

8. Personal Data Breach

Vosy will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Vosy will cooperate with you and take reasonable steps to mitigate and remediate the breach. Vosy's notification is not an acknowledgment of fault or liability.

9. International Transfers

Customer Personal Data is primarily processed and stored in the United States. Where Vosy transfers Personal Data originating in the EEA, UK, or Switzerland to a country that has not received an adequacy decision, such transfers are governed by the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum / Swiss addendum, as applicable), which are incorporated into this DPA by reference and completed using the information in Annexes A and B. Certain Sub-processors may process Personal Data outside the United States; their locations are identified in Annex B.

Note on non-US AI providers. Vosy's model catalogue includes models developed by non-US organizations, including PRC-linked organizations — for example Qwen (Alibaba). Where such a model is routed through Vosy's model gateway (OpenRouter), it may be served by infrastructure outside the United States; where it is served by a US-operated inference provider in the catalogue, the request does not leave that provider's US infrastructure. No such model is a default for any agent — a model is used only where you select it for an agent or supply your own key for it. If you select one, you are responsible for assessing the adequacy of that transfer for your use case. If you need those routes blocked at the account level, contact contact@vosy.ai.

10. Return and Deletion

Upon termination or expiry of the Agreement, and at your choice, Vosy will delete or return Customer Personal Data, and delete existing copies, except to the extent applicable law requires storage. Call recordings are subject to automated expiry as described in Annex A. On your request, Vosy can delete or anonymize Customer Personal Data associated with an identified Data Subject during the term, using its data-subject-erasure capability, subject to legal-hold and legal-retention exceptions.

11. Audits

Vosy will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party certifications and audit reports where available. Where that information is insufficient, you may request an audit no more than once per year (and following a Personal Data Breach), on reasonable prior notice, during business hours, subject to confidentiality obligations and without unreasonably disrupting Vosy's operations. The parties will agree on the scope and cost of any audit in advance.

12. CCPA / CPRA Terms

With respect to Personal Data subject to the CCPA, Vosy acts as a Service Provider. Vosy will not: (a) Sell or Share such Personal Data; (b) retain, use, or disclose it for any purpose other than the specific purpose of performing the Service, or otherwise as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with Personal Data received from, or on behalf of, anyone else, except as the CCPA permits a Service Provider to do. Vosy certifies that it understands and will comply with these restrictions. You may take reasonable steps to ensure Vosy uses such Personal Data consistently with your CCPA obligations.

13. General

  • Order of precedence. If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Personal Data, this DPA controls. The Standard Contractual Clauses control over both in the event of a conflict.
  • Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
  • Term. This DPA takes effect on the date it becomes part of your Agreement under Section 14, and continues until Vosy has ceased all processing of Customer Personal Data.
  • Governing law. Except where Data Protection Laws or the Standard Contractual Clauses require otherwise, this DPA is governed by the law and venue specified in the Agreement.

14. How to Execute

Where your Agreement is the click-through Terms of Service, this DPA is incorporated into it and applies without the need for signature. Where your Agreement is a Master Services Agreement, this DPA is the "standard Data Processing Agreement" referred to there and is incorporated on execution. If your organization requires a countersigned copy either way, send your request and signatory details to contact@vosy.ai.


Annex A — Details of Processing

Subject matterProvision of the Vosy AI voice-agent platform, including outbound and inbound calling, speech-to-text, AI conversation, text-to-speech, recording, transcription, and analytics.
DurationFor the term of the Agreement, plus any period required to return or delete data as set out in Section 10.
Nature and purposeCollection, recording, transcription, storage, analysis, transmission to Sub-processors, and deletion of Personal Data, solely to provide and support the Service on the Customer's instructions.
Categories of Data SubjectsThe Customer's authorized users; and the individuals whom the Customer's AI agents call or who call the Customer's agents ("Call Recipients" / end users).
Categories of Personal DataIdentifiers (name, email, phone number, IP address); account and organization details; call content (audio recordings where enabled, real-time transcriptions, AI-extracted information); call metadata (numbers, timestamps, duration, direction, outcome); and any additional Personal Data the Customer chooses to collect through its agent configurations.
Special categoriesNot requested by Vosy. The Customer must not configure agents to collect special-category data (e.g., health, biometric, or financial-account data) without a lawful basis and appropriate safeguards.
RetentionCall recordings auto-expire approximately 30 days after the call by default; transcriptions, call metadata, and analytics are retained for the term of the account; operational and audit logs are retained per the Privacy Policy. Data may be deleted earlier on Customer request.

Annex B — Approved Sub-processors

Core infrastructure Sub-processors process Customer Personal Data for all customers. Configurable Sub-processors are AI model providers that process Customer Personal Data only where you select one of their models for an agent, or route data to them using your own key. Selecting a model is what engages its provider; no configurable provider receives data from an account that has not selected it.

Sub-processorFunctionTypeProcessing location
Amazon Web Services (AWS)Cloud hosting, database, object storage, KMS encryption, CloudFront content delivery, transactional emailCore infrastructureUnited States (us-west-1), with cross-region disaster recovery in the United States
TelnyxTelephony — call origination and termination, phone numbers, media transportCore infrastructureUnited States (default); other regions available
DeepgramSpeech-to-text transcription and text-to-speech synthesisCore infrastructureUnited States; EU endpoint available
CartesiaSpeech-to-text transcription and text-to-speech synthesisCore infrastructureIn-region inference (residency-supporting)
AnthropicAI language model (Claude)Configurable (AI provider)United States
OpenAIAI language model; text-to-speech synthesisConfigurable (AI provider)United States; multi-region residency available
Google (Gemini)AI language modelConfigurable (AI provider)Customer-selectable regional endpoints
GroqAI language model inferenceConfigurable (AI provider)United States
xAI (Grok)AI language modelConfigurable (AI provider)United States; EU region available
OpenRouterAI model routing gateway — transmits requests to the infrastructure provider serving the selected model, which may be operated outside the United StatesConfigurable (AI provider)United States gateway; downstream routing varies by selected model (see the note in Section 9)
ElevenLabsText-to-speech synthesisConfigurable (voice provider)United States
Microsoft AzureText-to-speech synthesis (Azure AI Speech)Configurable (voice provider)United States; other Azure regions available

Providers that support Vosy's own controller-side processing rather than Customer Personal Data — payment processing (accept.blue), website security and content delivery (Cloudflare, jsDelivr), and web fonts (Google Fonts) — are described in the Privacy Policy rather than listed here.

Additional AI providers may appear in Vosy's model catalogue without being selectable. A provider becomes a Sub-processor for your organization only when a model you have selected actually routes to it; catalogue entries that no account can select are not listed above. This Annex is point-in-time and is maintained against Vosy's live provider configuration as of the "Last updated" date.

Annex C — Technical and Organizational Measures

  • Encryption in transit: All data transmitted over public networks is encrypted using HTTPS/TLS.
  • Encryption at rest: Data is stored on encrypted infrastructure. Sensitive credentials are encrypted using AWS Key Management Service (KMS).
  • PII protection: Phone numbers and email addresses are encrypted at rest with HMAC blind indexes used for search; only the last four digits of phone numbers are retained in plaintext for display.
  • Transcript protection: Call transcripts are encrypted at rest using envelope encryption backed by AWS KMS.
  • Credentials: Account passwords are hashed using a memory-hard algorithm (Argon2id) with per-user salts; API keys are stored only as bcrypt hashes; plaintext secrets are never stored.
  • Access control: Role-based access, least-privilege administrative access, and multi-factor authentication for administrative accounts.
  • Tenant isolation: Customer data is logically segregated by organization, including org-scoped storage paths and API credentials.
  • Application security: Content Security Policy, CSRF protection, rate limiting, session fingerprinting, and prepared-statement database access.
  • Auditing and integrity: Account and organization activity is recorded in audit logs. Vosy's internal administrative actions and security events are additionally recorded in logs protected by an HMAC integrity chain for tamper detection.
  • Data minimization and retention: Automated expiry of call recordings (approximately 30 days by default) and retention controls for other data categories.
  • Sub-processor oversight: Due diligence on Sub-processors and flow-down of data-protection obligations.
  • Incident response: Breach detection, operational alerting, and a notification process consistent with Section 8.

Contact

For questions about this DPA, to request a countersigned copy, or to raise a Sub-processor objection, contact:

Vosy LLC
Attn: Legal
885 Tahoe Blvd STE C7, Incline Village, NV 89451, United States
Email: contact@vosy.ai

Terms of Service Privacy Policy Acceptable Use Policy Enterprise MSA Refund Policy © 2026 Vosy LLC. All rights reserved.