This Data Processing Agreement ("DPA") supplements and forms part of the agreement between you and your organization ("Customer," "you," or "Controller") and Vosy LLC ("Vosy," "we," or "Processor") governing your use of the Vosy AI platform (the "Service") — namely the Terms of Service or a Master Services Agreement, as applicable (the "Agreement"). It applies where, and to the extent that, Vosy processes Personal Data on your behalf in providing the Service.
This DPA reflects our standard data-processing terms. Enterprise customers may execute a countersigned copy or negotiate variations under a Master Services Agreement — contact contact@vosy.ai. In the event of a conflict, this DPA controls over the rest of the Agreement with respect to the processing of Personal Data.
Capitalized terms not defined here have the meaning given in the Agreement. "Personal Data," "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "CCPA" means the California Consumer Privacy Act as amended by the California Privacy Rights Act, and "Business," "Service Provider," "Sell," and "Share" have the meanings given there. "Data Protection Laws" means all privacy and data-protection laws applicable to the processing of Personal Data under this DPA. "Sub-processor" means any third party engaged by Vosy to process Personal Data. "Customer Personal Data" means Personal Data that Vosy processes on your behalf in providing the Service.
As between the parties, with respect to Customer Personal Data processed in the course of providing the Service, you are the Controller (or Business) and Vosy is the Processor (or Service Provider). Where you process Personal Data on behalf of a third party, you warrant that you are authorized to act as that party's Controller or processor and to engage Vosy. Vosy acts as an independent Controller for limited data it processes for its own purposes (for example, account-administration data, billing records, and security and usage logs), which is governed by our Privacy Policy rather than by this DPA.
The subject matter, duration, nature and purpose of the processing, the categories of Data Subjects, and the types of Personal Data are described in Annex A.
Vosy will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Vosy will, where legally permitted, inform you of that requirement before processing). Your instructions are set out in this DPA, the Agreement, and your configuration and use of the Service. You are responsible for ensuring that your instructions, and your collection and use of Customer Personal Data, comply with Data Protection Laws — including obtaining any necessary consents and providing any required notices to Data Subjects (such as call-recording and AI-disclosure notices). Vosy will inform you if, in its opinion, an instruction infringes Data Protection Laws.
Vosy will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis to provide the Service.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Vosy will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Those measures are described in Annex C. Vosy may update its security measures from time to time provided it does not materially reduce the overall level of protection.
You provide general authorization for Vosy to engage Sub-processors to process Customer Personal Data, subject to this Section. Vosy will: (a) impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA; and (b) remain liable for each Sub-processor's performance of its obligations.
The current list of Sub-processors is set out in Annex B. Which Sub-processors actually process Customer Personal Data depends on your configuration of the Service — for example, which AI model providers you select for an agent, and whether you supply your own provider credentials ("bring your own key"). Vosy will notify you (for example, by updating Annex B and notifying customers through the Service or by email) at least 30 days before adding or replacing a Sub-processor. If you reasonably object to a new Sub-processor on data-protection grounds, you may notify us within that period; we will work with you in good faith to address the objection and, if we cannot, you may terminate the affected portion of the Service.
Taking into account the nature of the processing, Vosy will assist you, by appropriate technical and organizational measures and insofar as possible, to:
Vosy will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Vosy will cooperate with you and take reasonable steps to mitigate and remediate the breach. Vosy's notification is not an acknowledgment of fault or liability.
Customer Personal Data is primarily processed and stored in the United States. Where Vosy transfers Personal Data originating in the EEA, UK, or Switzerland to a country that has not received an adequacy decision, such transfers are governed by the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum / Swiss addendum, as applicable), which are incorporated into this DPA by reference and completed using the information in Annexes A and B. Certain Sub-processors may process Personal Data outside the United States; their locations are identified in Annex B.
Note on non-US AI providers. Vosy's model catalogue includes models developed by non-US organizations, including PRC-linked organizations — for example Qwen (Alibaba). Where such a model is routed through Vosy's model gateway (OpenRouter), it may be served by infrastructure outside the United States; where it is served by a US-operated inference provider in the catalogue, the request does not leave that provider's US infrastructure. No such model is a default for any agent — a model is used only where you select it for an agent or supply your own key for it. If you select one, you are responsible for assessing the adequacy of that transfer for your use case. If you need those routes blocked at the account level, contact contact@vosy.ai.
Upon termination or expiry of the Agreement, and at your choice, Vosy will delete or return Customer Personal Data, and delete existing copies, except to the extent applicable law requires storage. Call recordings are subject to automated expiry as described in Annex A. On your request, Vosy can delete or anonymize Customer Personal Data associated with an identified Data Subject during the term, using its data-subject-erasure capability, subject to legal-hold and legal-retention exceptions.
Vosy will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party certifications and audit reports where available. Where that information is insufficient, you may request an audit no more than once per year (and following a Personal Data Breach), on reasonable prior notice, during business hours, subject to confidentiality obligations and without unreasonably disrupting Vosy's operations. The parties will agree on the scope and cost of any audit in advance.
With respect to Personal Data subject to the CCPA, Vosy acts as a Service Provider. Vosy will not: (a) Sell or Share such Personal Data; (b) retain, use, or disclose it for any purpose other than the specific purpose of performing the Service, or otherwise as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with Personal Data received from, or on behalf of, anyone else, except as the CCPA permits a Service Provider to do. Vosy certifies that it understands and will comply with these restrictions. You may take reasonable steps to ensure Vosy uses such Personal Data consistently with your CCPA obligations.
Where your Agreement is the click-through Terms of Service, this DPA is incorporated into it and applies without the need for signature. Where your Agreement is a Master Services Agreement, this DPA is the "standard Data Processing Agreement" referred to there and is incorporated on execution. If your organization requires a countersigned copy either way, send your request and signatory details to contact@vosy.ai.
| Subject matter | Provision of the Vosy AI voice-agent platform, including outbound and inbound calling, speech-to-text, AI conversation, text-to-speech, recording, transcription, and analytics. |
|---|---|
| Duration | For the term of the Agreement, plus any period required to return or delete data as set out in Section 10. |
| Nature and purpose | Collection, recording, transcription, storage, analysis, transmission to Sub-processors, and deletion of Personal Data, solely to provide and support the Service on the Customer's instructions. |
| Categories of Data Subjects | The Customer's authorized users; and the individuals whom the Customer's AI agents call or who call the Customer's agents ("Call Recipients" / end users). |
| Categories of Personal Data | Identifiers (name, email, phone number, IP address); account and organization details; call content (audio recordings where enabled, real-time transcriptions, AI-extracted information); call metadata (numbers, timestamps, duration, direction, outcome); and any additional Personal Data the Customer chooses to collect through its agent configurations. |
| Special categories | Not requested by Vosy. The Customer must not configure agents to collect special-category data (e.g., health, biometric, or financial-account data) without a lawful basis and appropriate safeguards. |
| Retention | Call recordings auto-expire approximately 30 days after the call by default; transcriptions, call metadata, and analytics are retained for the term of the account; operational and audit logs are retained per the Privacy Policy. Data may be deleted earlier on Customer request. |
Core infrastructure Sub-processors process Customer Personal Data for all customers. Configurable Sub-processors are AI model providers that process Customer Personal Data only where you select one of their models for an agent, or route data to them using your own key. Selecting a model is what engages its provider; no configurable provider receives data from an account that has not selected it.
| Sub-processor | Function | Type | Processing location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, object storage, KMS encryption, CloudFront content delivery, transactional email | Core infrastructure | United States (us-west-1), with cross-region disaster recovery in the United States |
| Telnyx | Telephony — call origination and termination, phone numbers, media transport | Core infrastructure | United States (default); other regions available |
| Deepgram | Speech-to-text transcription and text-to-speech synthesis | Core infrastructure | United States; EU endpoint available |
| Cartesia | Speech-to-text transcription and text-to-speech synthesis | Core infrastructure | In-region inference (residency-supporting) |
| Anthropic | AI language model (Claude) | Configurable (AI provider) | United States |
| OpenAI | AI language model; text-to-speech synthesis | Configurable (AI provider) | United States; multi-region residency available |
| Google (Gemini) | AI language model | Configurable (AI provider) | Customer-selectable regional endpoints |
| Groq | AI language model inference | Configurable (AI provider) | United States |
| xAI (Grok) | AI language model | Configurable (AI provider) | United States; EU region available |
| OpenRouter | AI model routing gateway — transmits requests to the infrastructure provider serving the selected model, which may be operated outside the United States | Configurable (AI provider) | United States gateway; downstream routing varies by selected model (see the note in Section 9) |
| ElevenLabs | Text-to-speech synthesis | Configurable (voice provider) | United States |
| Microsoft Azure | Text-to-speech synthesis (Azure AI Speech) | Configurable (voice provider) | United States; other Azure regions available |
Providers that support Vosy's own controller-side processing rather than Customer Personal Data — payment processing (accept.blue), website security and content delivery (Cloudflare, jsDelivr), and web fonts (Google Fonts) — are described in the Privacy Policy rather than listed here.
Additional AI providers may appear in Vosy's model catalogue without being selectable. A provider becomes a Sub-processor for your organization only when a model you have selected actually routes to it; catalogue entries that no account can select are not listed above. This Annex is point-in-time and is maintained against Vosy's live provider configuration as of the "Last updated" date.
For questions about this DPA, to request a countersigned copy, or to raise a Sub-processor objection, contact:
Vosy LLC
Attn: Legal
885 Tahoe Blvd STE C7, Incline Village, NV 89451, United States
Email: contact@vosy.ai