SONICVOX DATA PROCESSING ADDENDUM (DPA)
Effective Date: June 1, 2026
Last Updated: June 1, 2026
Version: 1.0
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Master Services Agreement (“Agreement”) between WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “Processor,” “we,” “our,” or “us”) and the entity identified as the customer in an applicable Order Form (“Customer” or “Controller”).
This DPA applies where the Company processes Personal Data on behalf of Customer in connection with the Services.
1. DEFINITIONS
1.1 Defined Terms
Capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.
1.2 Data Protection Definitions
For purposes of this DPA:
- “Controller,” “Processor,” “Data Subject,” and “Personal Data” shall have the meanings assigned under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”);
- “Sub-processor” means any third party engaged by the Company to process Personal Data on behalf of Customer; and
- “Applicable Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under this DPA, including GDPR, UK GDPR, and relevant U.S. state laws where applicable.
2. SCOPE AND ROLES
2.1 Roles of the Parties
The Parties acknowledge and agree that:
- Customer is the Controller of Personal Data; and
- The Company is the Processor of such Personal Data.
2.2 Scope of Processing
The Company shall process Personal Data solely for the purpose of providing the Services as described in the Agreement and Order Form(s).
2.3 Customer Instructions
This DPA and the Agreement constitute Customer’s complete and final instructions to the Company for processing Personal Data.
3. PROCESSING OF PERSONAL DATA
3.1 Lawful Basis
Customer is solely responsible for ensuring that it has a valid lawful basis for processing Personal Data, including obtaining any required consents.
3.2 Processor Obligations
The Company shall:
- Process Personal Data only on documented instructions from Customer;
- Use Personal Data solely for purposes of providing the Services;
- Not sell, lease, or otherwise monetize Personal Data; and
- Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
3.3 Prohibited Processing
The Company shall not:
- Use Personal Data for its own independent purposes; or
- Combine Customer Personal Data with data from other customers except as necessary to provide the Services
4. SECURITY MEASURES
4.1 Security Obligations
The Company shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data.
4.2 Security Measures Include
Such measures include, but are not limited to:
- Encryption of data in transit and at rest;
- Role-based access controls (RBAC);
- Multi-factor authentication (MFA);
- System monitoring and logging; and
- Backup and recovery procedures.
4.3 Security Limitations
Customer acknowledges that no system can be completely secure, and the Company does not warrant that the Services are immune from all vulnerabilities or attacks.
5. SUB-PROCESSORS
5.1 General Authorization
Customer provides general authorization for the Company to engage Sub-processors.
5.2 Sub-processor Obligations
The Company shall remain fully liable for the acts and omissions of its Sub-processors to the same extent as if performed by the Company.
The Company shall ensure that each Sub-processor:
- Is bound by written agreements; and
- Provides data protection obligations no less protective than those set forth in this DPA.
5.3 Sub-processor List
The Company maintains an up-to-date list of authorized Sub-processors, available to Customer in the SonicVox Sub-Processor List, and updated in accordance with Section 5.4 of this DPA. A copy may also be obtained upon written request to privacy@sonicvox.ai.
5.4 Notice and Objection
The Company will provide at least fourteen (14) days' prior notice before engaging a new Sub-processor.
Customer may object on reasonable data protection grounds within the notice period.
6. DATA SUBJECT RIGHTS
6.1 Assistance Obligations
The Company shall provide reasonable assistance to enable Customer to fulfill its obligations to respond to Data Subject requests.
6.2 Direct Requests
If the Company receives a Data Subject request directly, the Company shall:
- Notify Customer promptly (where legally permitted); and
- Not respond without Customer’s instructions.
7. DATA BREACH NOTIFICATION
7.1 Notification
The Company shall notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of the breach.
7.2 Information Provided
Such notification shall include, to the extent available:
- Description of the nature of the breach;
- Categories of affected data;
- Likely consequences; and
- Measures taken or proposed to mitigate the breach.
7.3 Cooperation
The Company shall provide reasonable cooperation to support Customer’s legal obligations.
8. DATA RETENTION AND DELETION
8.1 Retention
The Company shall retain Personal Data only as necessary to provide the Services or as required by law.
8.2 Deletion or Return
Upon termination of the Agreement or upon Customer request:
The Company shall delete or return Personal Data within thirty (30) days of termination of the Agreement, unless retention is required by law.
8.3 Backup Systems
Personal Data in backups shall be deleted in accordance with the Company’s standard data retention policies.
9. INTERNATIONAL DATA TRANSFERS
9.1 Transfer Mechanisms
Where Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, the Company shall rely on:
- Standard Contractual Clauses (SCCs); the Parties agree that Customer is the data exporter and the Company is the data importer for purposes of the SCCs;
- UK International Data Transfer Agreement (IDTA) or UK Addendum; and
- Other lawful transfer mechanisms.
10. STANDARD CONTRACTUAL CLAUSES (SCCs)
10.1 Incorporation
The European Commission Standard Contractual Clauses (Decision 2021/914) are incorporated by reference into this DPA.
10.2 Applicable Modules
- Module Two (Controller to Processor); and
- Module Three (Processor to Sub-processor).
10.3 Supplementary Measures
To address international transfer risks, the Company implements:
- Encryption in transit and at rest;
- Access controls and least-privilege access;
- Data minimization practices; and
- Procedures to challenge unlawful government access requests
10.4 Availability
A full copy of the SCCs is available upon request at: privacy@sonicvox.ai.
11. AUDIT AND COMPLIANCE
11.1 Audit Rights
Customer may conduct one (1) audit per twelve (12) month period with reasonable prior notice.
11.2 Conditions
Audits shall be:
- Conducted during normal business hours;
- Subject to confidentiality obligations; and
- At Customer’s expense, unless material non-compliance is identified.
11.3 Alternative Evidence
The Company may satisfy audit requirements by providing:
- SOC 2 reports;
- Security documentation; or
- Third-party certifications.
12. LIABILITY
12.1 Governing Agreement
Liability arising from this DPA shall be governed by the limitations set forth in the Agreement.
12.2 No Expansion of Liability
Nothing in this DPA expands the Company’s liability beyond what is set forth in the Agreement.
13. MISCELLANEOUS
13.1 Order of Precedence
In the event of conflict, the following document progression order is:
- This DPA;
- the MSA; and
- the Terms of Service.
13.2 Amendments
This DPA may be amended only by written agreement between the Parties.
14. ANNEX I – PROCESSING DETAILS
14.1 Subject Matter
Provision of AI-powered voice, translation, and related services.
14.2 Duration
For the duration of the Agreement.
14.3 Categories of Personal Data
- Account information
- Voice/audio data
- User-generated content
- Usage and log data
14.4 Categories of Data Subjects
- Customers
- End users
- Individuals whose data is uploaded by Customer
15. ANNEX II – SECURITY MEASURES SUMMARY
The Company implements the following safeguards:
- Encryption (TLS, encryption at rest);
- Role-based access control (RBAC);
- Multi-factor authentication (MFA);
- Logging and monitoring systems;
- Incident response procedures; and
- Backup and disaster recovery processes.
