Skip to content

SONICVOX DATA PROCESSING ADDENDUM (DPA)

Effective Date: June 1, 2026
Last Updated: June 1, 2026

Version: 1.0

This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Master Services Agreement (“Agreement”) between WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “Processor,” “we,” “our,” or “us”) and the entity identified as the customer in an applicable Order Form (“Customer” or “Controller”).

This DPA applies where the Company processes Personal Data on behalf of Customer in connection with the Services.

1. DEFINITIONS

1.1 Defined Terms

Capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.

1.2 Data Protection Definitions

For purposes of this DPA:

    1. “Controller,” “Processor,” “Data Subject,” and “Personal Data” shall have the meanings assigned under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”);
    2. “Sub-processor” means any third party engaged by the Company to process Personal Data on behalf of Customer; and
    3. “Applicable Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under this DPA, including GDPR, UK GDPR, and relevant U.S. state laws where applicable.

2. SCOPE AND ROLES

2.1 Roles of the Parties

The Parties acknowledge and agree that:

    1. Customer is the Controller of Personal Data; and
    2. The Company is the Processor of such Personal Data.

2.2 Scope of Processing

The Company shall process Personal Data solely for the purpose of providing the Services as described in the Agreement and Order Form(s).

2.3 Customer Instructions

This DPA and the Agreement constitute Customer’s complete and final instructions to the Company for processing Personal Data.

3. PROCESSING OF PERSONAL DATA

3.1 Lawful Basis

Customer is solely responsible for ensuring that it has a valid lawful basis for processing Personal Data, including obtaining any required consents.

3.2 Processor Obligations

The Company shall:

    1. Process Personal Data only on documented instructions from Customer;
    2. Use Personal Data solely for purposes of providing the Services;
    3. Not sell, lease, or otherwise monetize Personal Data; and
    4. Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.

3.3 Prohibited Processing

The Company shall not:

    1. Use Personal Data for its own independent purposes; or
    2. Combine Customer Personal Data with data from other customers except as necessary to provide the Services

4. SECURITY MEASURES

4.1 Security Obligations

The Company shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data.

4.2 Security Measures Include

Such measures include, but are not limited to:

    1. Encryption of data in transit and at rest;
    2. Role-based access controls (RBAC);
    3. Multi-factor authentication (MFA);
    4. System monitoring and logging; and
    5. Backup and recovery procedures.

4.3 Security Limitations

Customer acknowledges that no system can be completely secure, and the Company does not warrant that the Services are immune from all vulnerabilities or attacks.

5. SUB-PROCESSORS

5.1 General Authorization

Customer provides general authorization for the Company to engage Sub-processors.

5.2 Sub-processor Obligations

The Company shall remain fully liable for the acts and omissions of its Sub-processors to the same extent as if performed by the Company.

The Company shall ensure that each Sub-processor:

    1. Is bound by written agreements; and
    2. Provides data protection obligations no less protective than those set forth in this DPA.

5.3 Sub-processor List

The Company maintains an up-to-date list of authorized Sub-processors, available to Customer in the SonicVox Sub-Processor List, and updated in accordance with Section 5.4 of this DPA. A copy may also be obtained upon written request to privacy@sonicvox.ai.

5.4 Notice and Objection

The Company will provide at least fourteen (14) days' prior notice before engaging a new Sub-processor.

Customer may object on reasonable data protection grounds within the notice period.

6. DATA SUBJECT RIGHTS

6.1 Assistance Obligations

The Company shall provide reasonable assistance to enable Customer to fulfill its obligations to respond to Data Subject requests.

6.2 Direct Requests

If the Company receives a Data Subject request directly, the Company shall:

    1. Notify Customer promptly (where legally permitted); and
    2. Not respond without Customer’s instructions.

7. DATA BREACH NOTIFICATION

7.1 Notification

The Company shall notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of the breach.

7.2 Information Provided

Such notification shall include, to the extent available:

    1. Description of the nature of the breach;
    2. Categories of affected data;
    3. Likely consequences; and
    4. Measures taken or proposed to mitigate the breach.

7.3 Cooperation

The Company shall provide reasonable cooperation to support Customer’s legal obligations.

8. DATA RETENTION AND DELETION

8.1 Retention

The Company shall retain Personal Data only as necessary to provide the Services or as required by law.

8.2 Deletion or Return

Upon termination of the Agreement or upon Customer request:

The Company shall delete or return Personal Data within thirty (30) days of termination of the Agreement, unless retention is required by law.

8.3 Backup Systems

Personal Data in backups shall be deleted in accordance with the Company’s standard data retention policies.

9. INTERNATIONAL DATA TRANSFERS

9.1 Transfer Mechanisms

Where Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, the Company shall rely on:

    1. Standard Contractual Clauses (SCCs); the Parties agree that Customer is the data exporter and the Company is the data importer for purposes of the SCCs;
    2. UK International Data Transfer Agreement (IDTA) or UK Addendum; and
    3. Other lawful transfer mechanisms.

10. STANDARD CONTRACTUAL CLAUSES (SCCs)

10.1 Incorporation

The European Commission Standard Contractual Clauses (Decision 2021/914) are incorporated by reference into this DPA.

10.2 Applicable Modules

    1. Module Two (Controller to Processor); and
    2. Module Three (Processor to Sub-processor).

10.3 Supplementary Measures

To address international transfer risks, the Company implements:

    1. Encryption in transit and at rest;
    2. Access controls and least-privilege access;
    3. Data minimization practices; and
    4. Procedures to challenge unlawful government access requests

10.4 Availability

A full copy of the SCCs is available upon request at: privacy@sonicvox.ai.

11. AUDIT AND COMPLIANCE

11.1 Audit Rights

Customer may conduct one (1) audit per twelve (12) month period with reasonable prior notice.

11.2 Conditions

Audits shall be:

    1. Conducted during normal business hours;
    2. Subject to confidentiality obligations; and
    3. At Customer’s expense, unless material non-compliance is identified.

11.3 Alternative Evidence

The Company may satisfy audit requirements by providing:

    1. SOC 2 reports;
    2. Security documentation; or
    3. Third-party certifications.

12. LIABILITY

12.1 Governing Agreement

Liability arising from this DPA shall be governed by the limitations set forth in the Agreement.

12.2 No Expansion of Liability

Nothing in this DPA expands the Company’s liability beyond what is set forth in the Agreement.

13. MISCELLANEOUS

13.1 Order of Precedence

In the event of conflict, the following document progression order is:

    1. This DPA;
    2. the MSA; and
    3. the Terms of Service.

13.2 Amendments

This DPA may be amended only by written agreement between the Parties.

14. ANNEX I – PROCESSING DETAILS

14.1 Subject Matter

Provision of AI-powered voice, translation, and related services.

14.2 Duration

For the duration of the Agreement.

14.3 Categories of Personal Data

    1. Account information
    2. Voice/audio data
    3. User-generated content
    4. Usage and log data

14.4 Categories of Data Subjects

    1. Customers
    2. End users
    3. Individuals whose data is uploaded by Customer

15. ANNEX II – SECURITY MEASURES SUMMARY

The Company implements the following safeguards:

    1. Encryption (TLS, encryption at rest);
    2. Role-based access control (RBAC);
    3. Multi-factor authentication (MFA);
    4. Logging and monitoring systems;
    5. Incident response procedures; and
    6. Backup and disaster recovery processes.

©2025 SONICVOX AI · All rights reserved.

Service Status