---
title: "Data Processing Agreement (DPA) | VoxisLive"
description: "The VoxisLive DPA template: controller and processor roles, data categories, sub-processor notice, security measures, 30-day deletion."
url: https://voxislive.com/dpa
language: "en"
source_html: https://voxislive.com/dpa
site: "Voxis — real-time voice translation"
og_image: https://voxislive.com/assets/og.png
generated_by: voxislive-markdown-pipeline
---

[Home](https://voxislive.com/) · / · [Trust center](https://voxislive.com/trust-center) · / · Data processing agreement

DATA PROCESSING AGREEMENT

# Data processing agreement

When an organisation buys VoxisLive for its team, the organisation is the data controller and VoxisLive is the data processor. This page is the template we sign, published so your legal and security people can read it before anyone asks you for a purchase order.

**Read this first.** The text below is a template, published for review. It is not the executed agreement. If you need a data processing agreement in force, ask us for a signed copy through the [enterprise channel](https://voxislive.com/enterprise) — the version both parties sign is the one that governs, and it overrides anything written on this page.

## Roles: who is the controller, who is the processor

In enterprise use the arrangement is the ordinary one. **Your organisation is the data controller**: you decide which meetings and which audio get translated, who in your team is given a seat, and how long you keep the transcripts that land on your people's machines. **VoxisLive is the data processor**: we process on your documented instructions, which in practice means we run the service you bought and nothing beyond it.

One consequence is worth stating plainly: the people whose voices are translated are frequently not your employees. The other side of a call is a data subject too, and the lawful basis for translating what they say is yours to establish, not ours.

For an individual consumer subscription there is no controller/processor split in this sense — that relationship is governed by the [Terms](https://voxislive.com/terms) and the [Privacy policy](https://voxislive.com/privacy). The DPA is for organisations.

## Subject matter, duration, and the data involved

**Subject matter and nature of the processing.** Real-time speech translation: capturing audio on the user's own machine, transmitting it to a translation engine, and returning translated speech and text. Plus the account and usage records needed to run a paid service — who has a seat, and how many minutes were used.

**Duration.** For as long as the organisation plan is live, plus the retention periods described under deletion below. Processing of any single session's audio lasts as long as the session does.

**Categories of data subjects.** Your members who hold a seat; and any person whose speech is captured during a session — the other participants in a meeting, or the speakers in whatever media is being translated.

| Category | Examples | Where it is processed |
| --- | --- | --- |
| Account data | Sign-in e-mail, licence tier, the organisation a licence is linked to | Our own server |
| Usage records | Minutes consumed, session start and stop, the plan they draw from | Our own server |
| Session audio | The speech captured during a live session, transmitted while the session runs | The translation engine provider for the target language — see the sub-processor list |
| Transcripts | The text of a session, written to the user's Documents folder, one folder per session | The user's own machine |
| Problem reports | A scrubbed application log and, if the user ticks the box, a transcript they choose to attach | Our own server |
| Payment data | Billing details for the purchase itself | Our payment provider, which acts as merchant of record |

**Special categories.** We do not ask for special-category data and the product has no feature that solicits it. But live speech is live speech: if your people translate a clinical conversation, health data passes through the pipeline because the meeting contained it. That is a decision for your controller assessment. We have no BAA and make no healthcare-specific claim — see the [trust center](https://voxislive.com/trust-center).

## Sub-processors, and what happens when the list changes

We publish our sub-processors **by name**, with what each one is used for, on [the sub-processor page](https://voxislive.com/subprocessors). It is not a category list — you can read the actual vendors and take them to your own review board.

Two points a reviewer normally asks about. Which provider receives the live audio depends on the **target language**, because engine routing is per target; the sub-processor page says which is which. And when the list changes, we update that page and notify enterprise customers, so a new processor does not appear in your supply chain without you hearing about it.

## Security measures

These are the controls we actually implement. We would rather describe a control you can verify than show you a badge.

- **Encryption in transit.** Traffic between the application and our server, and between the application and the translation engine, runs over TLS.
- **Keys encrypted on the device.** If your organisation uses its own engine API key, that key is stored encrypted at rest on the machine using Windows DPAPI, bound to the account and the install.
- **Work done on the device, not sent anywhere.** Speech detection and speaker-change detection run on the user's own CPU. Transcripts are written to the user's own disk, not to us.
- **Problem reports are scrubbed before they leave.** Redaction of tokens, keys, e-mail addresses and user paths happens on the device, and it is fail-closed: if scrubbing does not complete, the report is not sent.
- **Access.** Administrative access to the server holding account and usage records is limited to the people who operate the service.
- **Verification.** Part of the audio path is published as a read-only source excerpt, so a security reviewer can check the claims above against code rather than prose — see [licensing](https://voxislive.com/licensing) for what that excerpt is and is not.

**What we do not claim.** We hold no ISO certification, no SOC 2 report, no third-party attestation, and no BAA. We will not put a compliance badge on this page that we cannot back. If your procurement process requires one of those documents, we do not have it, and it is better that you learn that here than three weeks into a review.

## Data-subject rights and deletion

As processor, we assist you in answering the requests you receive: access, rectification, erasure, restriction, portability and objection. Route the request to us through your enterprise contact and we work it with you rather than answering your data subjects directly.

Much of what people ask for is not in our hands at all, which is worth knowing before you draft a response. Transcripts sit in the user's own `Documents` folder, one folder per session — deleting those is something the member does on their own machine, and no request to us is needed. Session audio is not kept as a file for us to go and find.

1. Send the request through your enterprise contact, identifying the account or the licence it concerns.
2. We confirm receipt and tell you what we hold for that account — typically account data and usage records.
3. Account data is deleted or anonymised within 30 days of the request. Usage records that must be retained for tax and accounting are anonymised rather than removed, so the figures still add up without naming a person.
4. We confirm back to you in writing, so you have something to close your own case file with.

Deletion of an individual consumer account follows the same 30-day route, described in the [Privacy policy](https://voxislive.com/privacy).

## Where processing happens — and the limit we will not paper over

**We do not guarantee EU-only data residency.** The translation engines are operated by large cloud providers and we do not contractually pin a session to an EU region. If your requirement is that no personal data ever leaves the EU, VoxisLive does not meet it today, and no clause we could sign would change the underlying routing.

If residency is a hard requirement, tell us at the start of the conversation — it is a short call either way. International transfers otherwise rely on the standard mechanisms, and the providers involved are named on [the sub-processor page](https://voxislive.com/subprocessors) so you can check their own transfer terms directly.

## Getting a signed copy

Write to us through the [enterprise page](https://voxislive.com/enterprise) or [contact form](https://voxislive.com/contact) with the legal entity name, the address, and the contact who will sign. We return an executable copy of this text. If your legal team has a preferred form of DPA, send it — we read it, and we say which clauses we can sign and which we cannot, rather than signing something we would then breach.

Seats and pooled minutes are set up on the same channel; see [enterprise plans](https://voxislive.com/enterprise) for how the pool works and [pricing](https://voxislive.com/pricing) for the rest.

## What this page is

A template, published so it can be reviewed before it is requested. It is not legal advice, it is not in force by being read, and it is not a substitute for your own assessment as controller. The document both parties execute is the agreement that governs; where it differs from this page, it wins.

FAQ

## Common questions

### Do you have a DPA we can actually sign, or is this just a web page?

There is a signable agreement. This page is its text, published so your legal and security reviewers can read it without asking first. Request the executable copy through the enterprise channel with your entity name and signatory, and we return it.

### Can you commit to processing our data in the EU only?

No. We do not guarantee EU-only data residency. The translation engines run on large cloud providers and we do not pin a session to an EU region. If that is a hard requirement for you, it is better to know now than after signature.

### Are you ISO 27001 certified or SOC 2 audited? Can you sign a BAA?

No to all three. We hold no certification, no third-party attestation and no BAA. What we offer instead is a named sub-processor list, described controls, and part of the audio path published as a read-only source excerpt so a reviewer can check the claims against code.

### Will you tell us if you add a new sub-processor?

Yes. Sub-processors are published by name on the sub-processor page, and when the list changes we update that page and notify enterprise customers, so a new vendor does not appear in your supply chain unannounced.

### One of our employees asked for their data to be deleted. What do you actually hold?

Account data and usage records on our server. Send the request through your enterprise contact and account data is deleted or anonymised within 30 days; usage records kept for tax and accounting are anonymised rather than removed. Transcripts are not part of this — they sit in the member's own Documents folder and they delete those themselves.

### Do the other people in the meeting count as data subjects?

Yes. Anyone whose speech is captured during a session is a data subject, including participants who are not your employees. Establishing the lawful basis for translating what they say is the controller's job, which in an enterprise deployment is you, not us.


## Structured data (JSON-LD)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://voxislive.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Trust center",
          "item": "https://voxislive.com/trust-center"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Data processing agreement",
          "item": "https://voxislive.com/dpa"
        }
      ]
    },
    {
      "@type": "WebPage",
      "name": "Data Processing Agreement (DPA) | VoxisLive",
      "url": "https://voxislive.com/dpa",
      "description": "The VoxisLive DPA template: controller and processor roles, data categories, sub-processor notice, security measures, 30-day deletion.",
      "inLanguage": "en",
      "isPartOf": {
        "@type": "WebSite",
        "name": "VoxisLive",
        "url": "https://voxislive.com/"
      },
      "publisher": {
        "@type": "Organization",
        "name": "VoxisLive",
        "url": "https://voxislive.com/"
      }
    },
    {
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Do you have a DPA we can actually sign, or is this just a web page?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "There is a signable agreement. This page is its text, published so your legal and security reviewers can read it without asking first. Request the executable copy through the enterprise channel with your entity name and signatory, and we return it."
          }
        },
        {
          "@type": "Question",
          "name": "Can you commit to processing our data in the EU only?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. We do not guarantee EU-only data residency. The translation engines run on large cloud providers and we do not pin a session to an EU region. If that is a hard requirement for you, it is better to know now than after signature."
          }
        },
        {
          "@type": "Question",
          "name": "Are you ISO 27001 certified or SOC 2 audited? Can you sign a BAA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No to all three. We hold no certification, no third-party attestation and no BAA. What we offer instead is a named sub-processor list, described controls, and part of the audio path published as a read-only source excerpt so a reviewer can check the claims against code."
          }
        },
        {
          "@type": "Question",
          "name": "Will you tell us if you add a new sub-processor?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Sub-processors are published by name on the sub-processor page, and when the list changes we update that page and notify enterprise customers, so a new vendor does not appear in your supply chain unannounced."
          }
        },
        {
          "@type": "Question",
          "name": "One of our employees asked for their data to be deleted. What do you actually hold?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Account data and usage records on our server. Send the request through your enterprise contact and account data is deleted or anonymised within 30 days; usage records kept for tax and accounting are anonymised rather than removed. Transcripts are not part of this — they sit in the member's own Documents folder and they delete those themselves."
          }
        },
        {
          "@type": "Question",
          "name": "Do the other people in the meeting count as data subjects?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Anyone whose speech is captured during a session is a data subject, including participants who are not your employees. Establishing the lawful basis for translating what they say is the controller's job, which in an enterprise deployment is you, not us."
          }
        }
      ]
    }
  ]
}
```
