Data Processing Addendum
This Data Processing Addendum governs Voxvey Research LLC’s processing of personal data on behalf of customers using the Voxvey AI gateway, APIs, console, routing services, and related services.
This Data Processing Addendum (“DPA”) forms part of the agreement, order form, online terms, or other written or electronic agreement governing Customer’s use of the Services (the “Agreement”) between Voxvey and the customer accepting or entering into the Agreement (“Customer”). This DPA applies where Voxvey Processes Customer Personal Data on behalf of Customer in connection with the Services.
By entering into an Agreement that incorporates this DPA, executing an order form referencing this DPA, or using Services subject to terms incorporating this DPA, Customer agrees to this DPA on its own behalf and, where applicable, on behalf of its authorized Affiliates. Voxvey and Customer are each a “Party” and together the “Parties.”
1. Scope and Roles
1.1 Services. “Services” means the Voxvey AI gateway, hosted APIs, management console, chat or testing interfaces, model routing functionality, usage and billing functionality, supporting infrastructure, and related products or services provided under the Agreement.
1.2 Roles. To the extent Customer Personal Data is Processed by Voxvey to provide the Services:
- where Customer determines the purposes and means of Processing, Customer acts as Controller and Voxvey acts as Processor;
- where Customer Processes Personal Data on behalf of another Controller, Customer acts as Processor and Voxvey acts as Customer’s Sub-processor; and
- under applicable U.S. Privacy Laws, Customer is the business or controller and Voxvey is the service provider, contractor, or processor, as those terms apply.
1.3 Customer Affiliates. Customer may enter into this DPA on behalf of Affiliates authorized to use the Services under the Agreement. Customer remains responsible for coordinating instructions and communications on behalf of those Affiliates unless otherwise required by law.
1.4 Order of Precedence. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls. If applicable Standard Contractual Clauses or the UK Addendum conflict with this DPA, those transfer terms control for the applicable Restricted Transfer.
2. Processing Instructions and Purpose Limitation
2.1 Documented Instructions. Voxvey will Process Customer Personal Data only on documented instructions from Customer, unless Processing is required by applicable law. The Agreement, this DPA, Customer’s permitted use of the Services, API calls, routing rules, model selections, administrator configurations, support instructions, and written instructions consistent with the Agreement constitute Customer’s documented instructions.
2.2 Permitted Purposes. Voxvey may Process Customer Personal Data only as necessary to provide, operate, route, secure, maintain, support, monitor for abuse, troubleshoot, and administer the Services; to perform obligations under the Agreement and this DPA; to comply with applicable law; or as otherwise instructed or authorized in writing by Customer.
2.3 AI Model Routing. Customer acknowledges that the Services may route prompts, messages, files, images, embeddings, outputs, account identifiers, request metadata, or other Customer Data to third-party model providers selected, enabled, permitted, or invoked by Customer through its configuration or use of the Services. Customer’s activation or use of a model, provider, fallback route, or routing policy constitutes an instruction to Voxvey to disclose the information reasonably necessary to fulfill that request to the applicable authorized Sub-processor.
2.4 Model Training Restriction. Unless Customer expressly instructs or agrees otherwise in writing, Voxvey will not use Customer Personal Data to train or fine-tune a general-purpose artificial intelligence model, and Voxvey will not authorize its Sub-processors to use Customer Personal Data received from Voxvey for such training or fine-tuning. This restriction does not prohibit Processing necessary to provide the requested model response, maintain security, prevent abuse, comply with law, or provide the Services in accordance with Customer’s instructions.
2.5 Unlawful Instructions. Voxvey will promptly inform Customer if, in Voxvey’s reasonable opinion, an instruction violates applicable Data Protection Laws. Voxvey may suspend affected Processing until the Parties resolve the issue.
2.6 Legally Required Processing. If applicable law requires Voxvey to Process Customer Personal Data other than on Customer’s documented instructions, Voxvey will inform Customer before Processing unless legally prohibited from doing so.
3. Customer Obligations
3.1 Authority and Lawful Basis. Customer represents, warrants, and covenants that it has provided all required notices and obtained all rights, consents, authorizations, and lawful bases necessary for Voxvey and its authorized Sub-processors to Process Customer Personal Data as contemplated by the Agreement, this DPA, and Customer’s use and configuration of the Services.
3.2 Customer Responsibility. Customer is responsible for:
- the lawfulness, accuracy, quality, and content of Customer Data;
- determining whether the Services and each enabled model provider are appropriate for Customer’s intended use;
- managing credentials, API keys, user permissions, routing policies, models, fallback providers, retention selections, and deletion actions under Customer’s control;
- responding to Data Subject Requests except to the extent assistance from Voxvey is required under this DPA; and
- ensuring its instructions do not cause Voxvey or a Sub-processor to violate applicable law.
3.3 Sensitive Data. Unless expressly authorized in a written agreement signed by Voxvey, Customer must not submit to the Services protected health information regulated by HIPAA, payment card data subject to PCI DSS, biometric identifiers used for identification, government-issued identification numbers, authentication secrets, financial account credentials, precise geolocation, children’s personal data requiring parental consent, or other Sensitive Data.
Customer routing responsibility: Prompts, uploads, model inputs, and model outputs may contain Personal Data. Customer should enable only those model providers and routing options appropriate for its compliance requirements and should not submit prohibited or unnecessary Sensitive Data.
4. Confidentiality and Authorized Personnel
4.1 Confidentiality. Voxvey will ensure that each person authorized by Voxvey to Process Customer Personal Data is subject to an appropriate contractual or statutory duty of confidentiality.
4.2 Access Limitation. Voxvey will take reasonable steps to limit access to Customer Personal Data to personnel and authorized Sub-processors that require access to provide, support, secure, or administer the Services or to comply with applicable law.
4.3 Confidential Treatment. Customer Personal Data will be treated as Customer Confidential Information under the Agreement, if the Agreement includes confidentiality obligations.
5. Security
5.1 Security Measures. Taking into account the nature, scope, context, and purposes of Processing, as well as the risks to the rights and freedoms of natural persons, Voxvey will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
5.2 Measures. Voxvey’s security measures are described in Schedule 2 and may be updated from time to time, provided that updates do not materially reduce the overall protection of Customer Personal Data during the applicable Services term.
5.3 Customer Security Responsibilities. Customer is responsible for securely configuring its use of the Services, protecting credentials and API keys, limiting user access, selecting suitable model routes, and using available security and retention controls appropriately.
6. Data Subject and Consumer Rights Requests
6.1 Notice. To the extent legally permitted, Voxvey will notify Customer if Voxvey receives a request from an individual to exercise rights under applicable Data Protection Laws concerning Customer Personal Data.
6.2 Customer Response. Except where required by applicable law, Voxvey will not independently respond to a Data Subject Request concerning Customer Personal Data without Customer’s written authorization. Customer authorizes Voxvey to redirect a requester to Customer where appropriate.
6.3 Assistance. Taking into account the nature of Processing and insofar as reasonably possible, Voxvey will assist Customer through appropriate technical and organizational measures in fulfilling Customer’s obligation to respond to Data Subject Requests.
7. Assistance, Data Protection Assessments, and Regulatory Cooperation
7.1 Assistance. Taking into account the nature of Processing and information available to Voxvey, Voxvey will provide reasonable assistance to Customer with Customer’s obligations concerning security of Processing, breach notification, data protection impact assessments, data protection assessments required under applicable U.S. Privacy Laws, and consultations with supervisory authorities where required by applicable law.
7.2 Information. Voxvey will make available to Customer information reasonably necessary to demonstrate Voxvey’s compliance with its obligations as Processor under applicable Data Protection Laws and this DPA.
7.3 Government Requests. Unless prohibited by applicable law, Voxvey will notify Customer if it receives a legally binding demand from a public authority requiring disclosure of Customer Personal Data. Voxvey will not disclose more Customer Personal Data than legally required.
8. Personal Data Breaches
8.1 Notification. Voxvey will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data Processed by Voxvey or its Sub-processors.
8.2 Information Provided. To the extent available and applicable, Voxvey’s notification will include:
- a description of the nature of the Personal Data Breach;
- the categories of affected Customer Personal Data and Data Subjects, where known;
- the likely consequences of the Personal Data Breach, where known;
- measures taken or proposed to address or mitigate the Personal Data Breach; and
- a point of contact for reasonable follow-up questions.
8.3 Cooperation. Voxvey will provide reasonable assistance to Customer in meeting Customer’s legally required breach notification obligations, taking into account the nature of Processing and the information available to Voxvey.
8.4 No Admission. Notification of a Personal Data Breach is not an acknowledgment of fault, liability, or violation of law by Voxvey.
9. Sub-processors
9.1 General Authorization. Customer provides general written authorization for Voxvey to engage the Sub-processors identified in Schedule 3 to Process Customer Personal Data as necessary to provide the Services.
9.2 Sub-processor Requirements. Voxvey will enter into written arrangements with each Sub-processor that Processes Customer Personal Data requiring data protection obligations no less protective in material respects than the obligations imposed on Voxvey under this DPA, to the extent applicable to the nature of the Sub-processor’s services.
9.3 Responsibility. Subject to any limitations of liability in the Agreement, Voxvey remains responsible for the performance of its Sub-processors’ data protection obligations with respect to Customer Personal Data Processed on Voxvey’s behalf.
9.4 Changes and Notice. Voxvey may update Schedule 3 by adding or replacing a Sub-processor. Except where a new Sub-processor is required on an expedited basis to address an emergency, security issue, service availability issue, or legal requirement, Voxvey will provide Customer at least thirty (30) days’ notice before permitting a newly added Sub-processor to Process Customer Personal Data by updating this page or providing another reasonable notice.
9.5 Objections. Customer may object in writing to a new Sub-processor on reasonable data protection grounds by contacting legal@voxvey.com within thirty (30) days after notice. Voxvey and Customer will work in good faith to address the objection. If the Parties cannot resolve the objection through commercially reasonable measures, either Party may terminate the affected Services that cannot reasonably be provided without that Sub-processor.
9.6 Model Providers. Certain AI model providers listed in Schedule 3 Process Customer Personal Data only when Customer elects, enables, permits, or invokes a route using that provider, including through an automatic routing, fallback, or model selection configuration authorized by Customer.
10. Return and Deletion of Customer Personal Data
10.1 During the Term. Customer may access, export, or delete Customer Data through available Service functionality where offered, or may request reasonable assistance where required by applicable Data Protection Laws.
10.2 Termination. Upon expiry or termination of the Agreement, Voxvey will, at Customer’s choice and subject to the Agreement, delete or return Customer Personal Data and delete existing copies, unless applicable law requires continued retention.
10.3 Required Retention. Where applicable law requires Voxvey to retain Customer Personal Data, Voxvey will isolate and protect the retained data from further Processing except as required by applicable law.
10.4 Backups. Customer Personal Data retained in backups will be deleted or rendered inaccessible in accordance with Voxvey’s ordinary backup lifecycle, provided such data remains protected under this DPA until deletion.
11. Compliance Information and Audits
11.1 Documentation. Upon Customer’s reasonable written request, Voxvey will provide information reasonably necessary to demonstrate compliance with this DPA and applicable Processor obligations.
11.2 Audits. Where required by applicable Data Protection Laws, Customer may conduct an audit or inspection of Voxvey’s relevant Processing practices, either itself or through a qualified independent auditor, subject to the following conditions:
- Customer gives reasonable advance written notice;
- the audit occurs no more than once in any twelve-month period unless required by a regulator or following a Personal Data Breach;
- the audit is limited to information and systems relevant to Customer Personal Data;
- the audit is conducted during normal business hours in a manner designed to minimize disruption and protect confidentiality and security;
- the auditor is not a competitor of Voxvey and is bound by confidentiality obligations; and
- Customer bears its audit costs unless otherwise required by applicable law.
11.3 Alternative Assurance. Where permitted by applicable law, Voxvey may satisfy an audit request by supplying current security documentation, audit summaries, certifications, or independent assessment reports reasonably relevant to the request, if available.
12. International Data Transfers
12.1 Global Processing. Customer acknowledges that Customer Personal Data may be Processed in countries other than the country in which Customer or a Data Subject is located, including where Voxvey or its Sub-processors operate infrastructure or provide AI model services.
12.2 EEA Transfers. To the extent Customer Personal Data protected by the GDPR is transferred from the European Economic Area to Voxvey in a country not recognized as providing an adequate level of protection, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this DPA and apply as completed in Schedule 4.
12.3 United Kingdom Transfers. To the extent Customer Personal Data protected by United Kingdom Data Protection Laws is transferred to Voxvey in a manner requiring transfer safeguards, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses is incorporated into this DPA and applies as completed in Schedule 4.
12.4 Switzerland. To the extent Customer Personal Data protected by Swiss data protection law is transferred to Voxvey in a manner requiring transfer safeguards, the applicable Standard Contractual Clauses will apply with adaptations necessary to comply with Swiss data protection law, including references to the competent Swiss authority and Swiss governing concepts where required.
12.5 Supplementary Measures. Voxvey will implement reasonable supplementary technical, contractual, and organizational measures appropriate to the relevant transfer and the nature of Customer Personal Data.
13. U.S. Privacy Law Terms
13.1 Applicable U.S. Privacy Laws. This Section applies to the extent Customer Personal Data is subject to a U.S. Privacy Law that imposes contractual requirements between a business or controller and a service provider, contractor, or processor, including the Colorado Privacy Act and the California Consumer Privacy Act, as amended.
13.2 Processing Restrictions. Voxvey will:
- Process Customer Personal Data only on Customer’s instructions and for the limited and specified purposes set out in the Agreement and this DPA;
- not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising as those terms are defined under applicable U.S. Privacy Laws;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship between Voxvey and Customer except as permitted by applicable law or Customer’s documented instructions;
- not combine Customer Personal Data with Personal Data received from another person or collected from Voxvey’s own interactions with a consumer except as permitted under applicable U.S. Privacy Laws or directed by Customer;
- ensure persons Processing Customer Personal Data are subject to confidentiality obligations;
- assist Customer with consumer rights requests, security obligations, breach notifications, and required data protection assessments as set out in this DPA;
- notify Customer if Voxvey determines it can no longer meet its applicable obligations under this Section; and
- permit Customer to take reasonable and appropriate steps to ensure Voxvey Processes Customer Personal Data consistently with Customer’s obligations under applicable U.S. Privacy Laws.
13.3 Colorado Privacy Act. For Customer Personal Data subject to the Colorado Privacy Act, this DPA is intended to be a binding contract between Controller and Processor that sets out the Processing instructions, nature and purpose of Processing, type of Personal Data, duration of Processing, confidentiality obligations, Sub-processor requirements, assistance obligations, audit and compliance information obligations, and return or deletion requirements applicable to Voxvey’s Processing.
13.4 Deidentified Data. If Customer instructs Voxvey to Process Customer Personal Data in deidentified form, Voxvey will take reasonable measures designed to ensure the data cannot reasonably be associated with an individual or household, publicly commit where required by applicable law to maintain and use the information in deidentified form, and not attempt to reidentify the information except as permitted by applicable law.
13.5 Customer Covenant. Customer will not instruct Voxvey to Process Customer Personal Data in a manner that would prevent Voxvey from qualifying as a service provider, contractor, or processor under applicable U.S. Privacy Laws where the Parties intend Voxvey to act in such role.
14. Liability and General Terms
14.1 Liability. The liability of each Party and its Affiliates arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent such limitation is prohibited by applicable law or the applicable Standard Contractual Clauses or UK Addendum provide otherwise.
14.2 Term. This DPA remains in effect for as long as Voxvey Processes Customer Personal Data subject to the Agreement.
14.3 Governing Law. Unless applicable Data Protection Laws or transfer terms require otherwise, this DPA is governed by the governing law provision in the Agreement.
14.4 Electronic Acceptance. This DPA may be accepted electronically, incorporated by reference into an Agreement or order form, or executed in counterparts. Electronic acceptance and electronic signatures have the same force and effect as original signatures to the extent permitted by law.
14.5 Updates. Voxvey may update this DPA prospectively to reflect changes in law, Services, or Sub-processors, provided that updates do not materially reduce Customer’s data protection rights during an existing committed Services term without Customer’s agreement, except where required by applicable law.
15. Definitions
“Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a Party.
“Controller” means the entity that determines the purposes and means of Processing Personal Data, or an analogous term under applicable Data Protection Laws.
“Customer Data” means data, content, prompts, messages, files, inputs, outputs, metadata, or other information submitted to, transmitted through, stored in, or otherwise Processed by the Services on Customer’s behalf.
“Customer Personal Data” means Personal Data contained in Customer Data that Voxvey Processes on behalf of Customer to provide the Services.
“Data Protection Laws” means applicable laws and regulations concerning privacy, data protection, or the Processing of Personal Data, including where applicable the GDPR, UK GDPR, Swiss Federal Act on Data Protection, Colorado Privacy Act, California Consumer Privacy Act, and other applicable U.S. state privacy laws.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, including a consumer where applicable under U.S. Privacy Laws.
“GDPR” means Regulation (EU) 2016/679.
“Personal Data” means personal data, personal information, or an analogous term defined under applicable Data Protection Laws.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Voxvey or its Sub-processors.
“Process,” “Processed,” or “Processing” means any operation performed on Personal Data, including collection, storage, transmission, disclosure, use, analysis, deletion, or modification.
“Processor” means an entity that Processes Personal Data on behalf of a Controller, or an analogous term under applicable Data Protection Laws.
“Restricted Transfer” means a transfer of Personal Data subject to applicable international data transfer restrictions requiring an approved transfer mechanism.
“Sensitive Data” means Personal Data designated as sensitive, special category, biometric, protected health, precise geolocation, children’s data, financial account, authentication, government identifier, or similarly protected data under applicable law.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, as amended, replaced, or superseded.
“Sub-processor” means a third party engaged by Voxvey to Process Customer Personal Data on Voxvey’s behalf in connection with the Services.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner’s Office, as amended, replaced, or superseded.
“U.S. Privacy Laws” means applicable U.S. state privacy laws governing Customer Personal Data, including where applicable the Colorado Privacy Act and California Consumer Privacy Act, as amended.
Schedule 1: Details of Processing
1. Subject Matter and Purpose
Voxvey Processes Customer Personal Data to provide the Services under the Agreement, including API gateway operation, authentication and account administration, model request routing, prompt and output transmission, service monitoring, billing and usage measurement, abuse prevention, support, debugging, reliability, security, and legally required compliance activities.
2. Duration
Processing will occur for the duration of the Agreement and for any period thereafter necessary to perform deletion, return, backup expiration, security, dispute resolution, legal retention, or other obligations permitted by the Agreement, this DPA, or applicable law.
3. Nature of Processing
The Processing may include collection, receipt, transmission, organization, structuring, storage, hosting, retrieval, routing, disclosure to authorized Sub-processors, generation of requested model responses, monitoring, logging, analysis for security or support purposes, deletion, and return of Customer Personal Data.
4. Categories of Data Subjects
- Customer employees, contractors, representatives, administrators, and authorized users;
- Customer’s customers, prospects, end users, suppliers, business contacts, or partners;
- individuals whose information Customer includes in prompts, files, messages, API requests, or other Customer Data; and
- other natural persons whose Personal Data is submitted by or on behalf of Customer through the Services.
5. Categories of Customer Personal Data
- identifiers and contact data, such as names, usernames, email addresses, phone numbers, organization names, and account identifiers;
- authentication and account-administration metadata, excluding Customer’s obligation not to submit unnecessary authentication secrets;
- prompts, messages, chat content, instructions, documents, images, attachments, model inputs, model outputs, embeddings, and other unstructured content submitted by Customer;
- usage, request, routing, operational, diagnostic, device, browser, network, IP address, timestamp, token-count, model-selection, and billing metadata;
- support communications and information submitted in connection with troubleshooting; and
- any other Personal Data Customer elects to transmit through the Services in accordance with the Agreement.
6. Sensitive Data
No Sensitive Data is intended to be Processed unless expressly authorized in a written agreement signed by Voxvey. Customer must not submit prohibited Sensitive Data through prompts, files, model inputs, or other Customer Data. If Customer submits Sensitive Data despite this restriction, Customer is responsible for ensuring the Processing is lawful and appropriately instructed.
7. Processing Frequency
Processing occurs on a continuous or recurring basis depending on Customer’s use of the Services, including each API request, console request, model interaction, routing action, support request, or administrative activity initiated or authorized by Customer.
8. Processor Obligations
Voxvey will Process Customer Personal Data in accordance with the Agreement, this DPA, Customer’s documented instructions, and applicable Data Protection Laws. Voxvey will not determine new independent purposes for Customer Personal Data in its role as Processor.
Schedule 2: Technical and Organizational Security Measures
Voxvey maintains technical and organizational measures designed to protect Customer Personal Data appropriate to the nature of the Services and the risk presented by the Processing. Such measures include, as appropriate to the Services and applicable environment:
| Control Area | Measures |
|---|---|
| Access Control | Logical access controls designed to restrict access to systems and Customer Personal Data to authorized users, personnel, and service accounts with a business need. |
| Authentication and Credentials | Administrative controls for credentials and API keys; measures designed to prevent unauthorized access; Customer responsibility for protecting Customer-issued credentials. |
| Transmission Security | Encryption in transit using industry-standard secure transport protocols where Customer Personal Data is transmitted over public networks. |
| Infrastructure Security | Use of reputable cloud and edge infrastructure providers; environment configuration, monitoring, access limitation, and operational controls appropriate to the Services. |
| Logging and Monitoring | Operational logging and monitoring designed to detect service disruption, unauthorized activity, abuse, security events, and reliability issues, subject to retention controls and applicable law. |
| Sub-processor Management | Written data protection obligations imposed on Sub-processors that Process Customer Personal Data, together with notice and objection procedures described in this DPA. |
| Incident Response | Procedures intended to identify, investigate, respond to, mitigate, and communicate Personal Data Breaches affecting Customer Personal Data. |
| Data Minimization | Processing limited to data reasonably necessary to provide the Services, support Customer-authorized routing, maintain security, comply with law, or satisfy documented Customer instructions. |
| Deletion and Retention | Processes designed to delete or return Customer Personal Data following termination or Customer instruction, subject to backups, legal retention, security, and technical limitations described in this DPA. |
| Personnel Confidentiality | Confidentiality obligations applicable to personnel authorized to Process Customer Personal Data. |
Schedule 3: Authorized Sub-processors
Customer authorizes Voxvey to use the following Sub-processors in connection with the Services. Infrastructure providers may Process Customer Personal Data as required to host, transmit, secure, deliver, monitor, or support the Services. AI model providers may Process Customer Personal Data only when Customer enables, selects, permits, or invokes the applicable provider or an authorized route that uses that provider.
Infrastructure, Hosting, Edge, and Cloud Service Providers
| Provider or Service | Processing Purpose | Data Potentially Processed |
|---|---|---|
| Cloudflare | Edge networking, DNS, traffic delivery, security, tunnel or proxy functionality, application protection, and related infrastructure services. | Network metadata, IP addresses, request metadata, transmitted Customer Data, security logs, and content routed through applicable Cloudflare services. |
| Oracle Cloud Infrastructure | Cloud compute, hosting, networking, storage, database, backup, and related infrastructure services. | Customer Data stored or transmitted through applicable workloads, operational metadata, and system logs. |
| Google Cloud Platform | Cloud compute, hosting, networking, storage, database, analytics, security, and related infrastructure services. | Customer Data stored or transmitted through applicable workloads, operational metadata, and system logs. |
| Amazon Web Services | Cloud compute, hosting, networking, storage, database, logging, backup, and related infrastructure services. | Customer Data stored or transmitted through applicable workloads, operational metadata, and system logs. |
| Microsoft Azure | Cloud compute, hosting, networking, storage, database, identity, security, and related infrastructure services. | Customer Data stored or transmitted through applicable workloads, operational metadata, and system logs. |
AI Model, Inference, Search, and Routing Providers
Provider activation: The providers below Process Customer Personal Data only where Customer selects, enables, permits, or invokes a model or route using that provider, including through a Customer-authorized automatic router or fallback configuration.
| Provider or Model Service | Processing Purpose | Data Potentially Processed |
|---|---|---|
|
OpenAI Including GPT and ChatGPT-branded model services where made available through Voxvey |
AI model inference, generation, embeddings, multimodal processing, and related model functionality requested or permitted by Customer. | Prompts, messages, files, images, model inputs, model outputs, request metadata, and other content necessary to fulfill the selected request. |
|
Anthropic Including Claude models |
AI model inference, generation, analysis, and related model functionality requested or permitted by Customer. | Prompts, messages, files, model inputs, model outputs, request metadata, and other content necessary to fulfill the selected request. |
|
Google Including Gemini models |
AI model inference, generation, multimodal processing, embeddings, and related model functionality requested or permitted by Customer. | Prompts, messages, files, images, model inputs, model outputs, request metadata, and other content necessary to fulfill the selected request. |
|
xAI Including Grok models |
AI model inference, generation, analysis, and related model functionality requested or permitted by Customer. | Prompts, messages, files, model inputs, model outputs, request metadata, and other content necessary to fulfill the selected request. |
| DeepSeek | AI model inference, generation, coding, reasoning, and related model functionality requested or permitted by Customer. | Prompts, messages, files, model inputs, model outputs, request metadata, and other content necessary to fulfill the selected request. |
| OpenRouter | Third-party model routing, model access aggregation, inference delivery, fallback routing, and related gateway services requested or permitted by Customer. | Prompts, messages, files, model inputs, model outputs, selected model or provider information, routing metadata, and request metadata. |
| Perplexity | AI model inference, answer generation, retrieval-assisted functionality, search-assisted functionality, and related services requested or permitted by Customer. | Prompts, messages, search or retrieval queries, files where supported, model outputs, citations or retrieved context, and request metadata. |
| Meta / Llama | Llama model inference or related AI functionality where Customer selects a Meta-operated service or a route that uses a Meta-operated endpoint. | Prompts, messages, files where supported, model inputs, model outputs, and request metadata necessary to fulfill the selected request. |
Hosted Llama clarification: Where a Llama model is hosted and operated by another authorized provider rather than Meta, the hosting or routing provider that receives Customer Personal Data is the applicable Sub-processor for that request.
Provider availability: Listing a provider in this Schedule authorizes its use where made available through the Services; it does not represent that every listed provider or model is enabled for every Customer account or continuously available.
Schedule 4: International Data Transfer Terms
1. European Economic Area Transfers
Where the transfer of Customer Personal Data from the European Economic Area to Voxvey requires an approved transfer mechanism under the GDPR, the Standard Contractual Clauses are incorporated into this DPA as follows:
- Module Two: Controller to Processor applies where Customer is a Controller and Voxvey is a Processor.
- Module Three: Processor to Sub-processor applies where Customer is a Processor and Voxvey is a Sub-processor.
- In Clause 7, the optional docking clause applies.
- In Clause 9, Option 2, general written authorization, applies. The notice period for new Sub-processors is the period specified in Section 9.4 of this DPA.
- In Clause 11, the optional redress language does not apply.
- In Clause 17, Option 1 applies and the governing law is the law of Ireland.
- In Clause 18(b), disputes will be resolved before the courts of Ireland.
- Annex I and Annex III are completed using the information in this DPA, including Schedule 1 and Schedule 3.
- Annex II is completed using the technical and organizational measures described in Schedule 2.
- The competent supervisory authority will be determined in accordance with Clause 13 of the SCCs.
2. United Kingdom Transfers
Where the transfer of Customer Personal Data protected by United Kingdom Data Protection Laws requires an approved transfer mechanism, the UK Addendum is incorporated into this DPA and completed as follows:
| UK Addendum Information | Completion |
|---|---|
| Exporter | Customer and, where applicable, its authorized Affiliates, as identified in the Agreement or applicable order form. |
| Importer | Voxvey Research LLC, a Colorado limited liability company. Contact: legal@voxvey.com. |
| Approved EU SCCs | Module Two or Module Three, as applicable under the Parties’ roles described in this DPA. |
| Appendix Information | The information in Schedule 1, Schedule 2, and Schedule 3 of this DPA. |
| Termination Rights | The Parties may terminate the affected Restricted Transfer in accordance with the mandatory termination provisions of the UK Addendum. |
3. Swiss Transfers
For Customer Personal Data protected by Swiss data protection law, the SCCs apply with the modifications necessary to give effect to Swiss law. References to the GDPR will be interpreted to include applicable Swiss data protection law, references to EU or Member State concepts will be interpreted to include corresponding Swiss concepts where applicable, and the competent authority will be the competent Swiss data protection authority where required.
Execution and Contact
This DPA is entered into by Voxvey Research LLC and Customer when Customer accepts an Agreement incorporating this DPA, executes an order form referencing this DPA, or otherwise executes this DPA.
Voxvey Research LLC
Colorado limited liability company
Email:
legal@voxvey.com
Requests relating to this DPA, Sub-processor objections, deletion or return instructions, or data protection inquiries may be submitted to legal@voxvey.com.