Legal
Data Processing Agreement (DPA)
Last Updated: July 18, 2026
This Data Processing Agreement ("DPA") is incorporated into and forms part of the Terms & Conditions between VOICELI LLC ("voiceli.ai," "we," "us," "our") and the Customer ("you," "your").
This DPA applies only to Customers who are subject to the General Data Protection Regulation (GDPR), UK GDPR, or other applicable data protection laws, and who process Personal Data of End Users through our Service.
By using our Service, you agree to the terms of this DPA. If you do not agree, do not use the Service for processing Personal Data of End Users subject to GDPR/CCPA.
1. DEFINITIONS
Capitalized terms not defined in this DPA have the meanings set forth in the Terms & Conditions.
- "Controller" means the entity that determines the purposes and means of processing Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data (collection, storage, use, disclosure, etc.).
- "Sub-Processor" means any Processor engaged by us to process Personal Data on your behalf.
- "Data Protection Laws" means the GDPR (Regulation (EU) 2016/679), UK GDPR, CCPA/CPRA, and any other applicable privacy laws.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Data.
- "Standard Contractual Clauses (SCCs)" means the contractual clauses approved by the European Commission for international data transfers (Decision 2021/914/EU).
2. ROLES AND RESPONSIBILITIES
2.1. You are the Controller of all Personal Data you provide to us through the Service, including contact lists, customer data, call recordings, and transcripts.
2.2. We are the Processor of that Personal Data, acting only on your documented instructions.
2.3. We will process Personal Data only for the following purposes:
- Providing and maintaining the Service.
- Processing voice and SMS communications.
- Call recording and transcription (where enabled).
- Analyzing usage data for service improvement (anonymized).
- Complying with legal obligations.
2.4. We will not process Personal Data for any other purpose without your prior written consent.
3. DATA SUBJECT RIGHTS
3.1. We will assist you in responding to Data Subject requests (access, rectification, deletion, restriction, portability, objection) as required by Data Protection Laws.
3.2. If a Data Subject contacts us directly with a request, we will:
- Acknowledge receipt within 3 business days.
- Forward the request to you within 5 business days.
- Not respond to the request without your authorization.
3.3. We will provide you with the tools and functionality within the Service to enable you to respond to Data Subject requests.
4. SECURITY MEASURES
4.1. We implement the following technical and organizational security measures to protect Personal Data:
| Measure | Description |
|---|---|
| Encryption | TLS 1.2+ for data in transit; AES-256 for data at rest. |
| Access Controls | Role-based access, least privilege principle, multi-factor authentication (MFA). |
| Monitoring | 24/7 logging and monitoring for unauthorized access. |
| Backups | Regular encrypted backups stored in secure locations. |
| Incident Response | Documented incident response plan for security breaches. |
| Employee Training | Annual privacy and security awareness training. |
| Data Minimization | Collect only data necessary for the Service. |
4.2. We will ensure that all personnel authorized to process Personal Data:
- Are bound by confidentiality obligations.
- Have received appropriate privacy and security training.
- Access Personal Data only on a need-to-know basis.
5. SUB-PROCESSORS
5.1. You authorize us to engage the following Sub-Processors to process Personal Data on your behalf:
| Sub-Processor | Purpose | Location |
|---|---|---|
| OpenAI | AI language processing (LLM) | USA |
| ElevenLabs | Text-to-speech (TTS) | USA |
| Google Cloud | Speech-to-text (STT), infrastructure | USA/EU |
| Twilio | SMS, voice calls, SIP infrastructure | USA |
| Stripe | Payment processing | USA |
| Pinecone | Vector database (memory/context) | USA |
5.2. We will ensure that each Sub-Processor enters into a written agreement with us that imposes data protection obligations at least as stringent as those in this DPA.
5.3. We will notify you of any intended changes to Sub-Processors. You have the right to object to such changes within 14 days of notification. If you object, we will discuss your concerns in good faith.
5.4. We remain fully liable to you for the performance of our Sub-Processors.
6. INTERNATIONAL DATA TRANSFERS
6.1. Your Personal Data may be transferred to and processed in countries outside your country of residence, including the United States.
6.2. For transfers from the EEA/UK to the USA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- UK Addendum to the SCCs (where applicable).
- Data Processing Agreements (DPAs) with our Sub-Processors.
6.3. You may request a copy of our data transfer safeguards by contacting us at: Legal-Privacy@Voiceli.ai.
7. DATA RETENTION AND DELETION
7.1. We retain Personal Data as follows:
| Data Type | Retention Period |
|---|---|
| Account data | Until account is deleted |
| Call recordings & transcripts | Per your plan settings (default: 30 days) |
| Usage logs | Up to 12 months |
| Billing records | 7 years (tax/legal requirement) |
| Marketing data | Until consent is withdrawn |
7.2. Upon termination of your account or your written request, we will:
- Delete or return all Personal Data within 30 days.
- Provide you with a copy of your data in a structured, machine-readable format upon request.
- Delete all copies unless retention is required by law.
7.3. We may retain anonymized data for analytical purposes where such data cannot identify individuals.
8. SECURITY INCIDENT NOTIFICATION
8.1. We will notify you without undue delay (and in any event, within 48 hours) after becoming aware of a Security Incident affecting your Personal Data.
8.2. Our notification will include:
- Description of the incident (nature, scope, likely consequences).
- Measures taken or proposed to address the incident.
- Contact information for further questions.
8.3. We will investigate the incident and provide you with a written report within 14 days.
8.4. You are responsible for notifying Data Subjects, regulators, or other parties as required by applicable law. We will provide reasonable assistance to help you fulfill your notification obligations.
9. AUDITS AND INSPECTIONS
9.1. Upon reasonable advance notice (at least 30 days), we will allow you to conduct an audit or inspection of our data processing practices to verify compliance with this DPA.
9.2. Audits will be:
- Conducted during normal business hours.
- At your expense (unless required by law).
- Subject to reasonable confidentiality and security restrictions.
9.3. We reserve the right to require you to enter into a separate non-disclosure agreement before sharing proprietary audit documentation.
10. DATA PROTECTION IMPACT ASSESSMENTS (DPIAs)
If you are required to conduct a DPIA under GDPR, we will provide reasonable assistance, including:
- Information about our processing activities.
- Documentation of our security measures.
- Cooperation in good faith to address any identified risks.
11. INDEMNIFICATION
You agree to indemnify and hold voiceli.ai harmless from any claims, damages, penalties, or expenses arising from:
- Your failure to obtain proper consent from End Users.
- Your violation of Data Protection Laws.
- Any fines or penalties imposed on us as a result of your processing instructions that violate applicable law.
12. TERM AND TERMINATION
12.1. This DPA takes effect on the date you first use the Service and continues until the termination of your account.
12.2. Either party may terminate this DPA upon termination of the underlying Terms & Conditions.
12.3. Sections relating to:
- Security Incident Notification (Section 8)
- Data Retention and Deletion (Section 7)
- Indemnification (Section 11)
- Governing Law (Section 13)
shall survive termination of this DPA.
13. GOVERNING LAW AND DISPUTE RESOLUTION
13.1. This DPA is governed by the laws of Florida, USA, without regard to conflict of law principles.
13.2. Any dispute shall be resolved through binding arbitration in Miami, FL, in accordance with the rules of the American Arbitration Association (AAA).
13.3. The arbitration shall be conducted in the English language. The parties waive any right to class actions or class arbitration.
14. CONTACT INFORMATION
For any questions or requests regarding this DPA:
VOICELI LLC
7224 NW 31ST STREET
MIAMI, FL 33122
United States
Email: Legal-Privacy@Voiceli.ai
Website: https://voiceli.ai/