SONICVOX SUB-PROCESSOR LIST
Effective Date: June 1, 2026
Last Updated: August 8, 2026
Version: 1.2
This Sub-Processor List is provided by WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “we,” “us,” or “our”).
1. OVERVIEW
1.1 Purpose
This Sub-processor List identifies third-party service providers (“Sub-processors”) authorized by WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company”) to process Personal Data on behalf of customers in connection with the SonicVox platform and Services.
1.2 Definition
“Sub-processor” means any third party engaged by the Company to process Personal Data on behalf of customers.
1.3 Legal Basis
This list is provided pursuant to the SonicVox Privacy Policy and Data Processing Addendum (DPA).
1.4 No Direct Relationship
Sub-processors do not have a direct relationship with customers and are authorized to process Personal Data only on behalf of the Company in accordance with its contractual obligations.
2. Authorized Sub-processors
2.1 Current Sub-Processors
Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
Amazon Web Services (AWS) | Cloud hosting, storage, infrastructure | Account data, content data, voice/audio data, logs | United States |
Stripe, Inc. | Payment processing | Billing and transaction data | United States |
Amazon Web Services, Inc. (Amazon SES) | Transactional and marketing email delivery | Email address, name, message content | United States |
Zoho Books | Accounting and bookkeeping of payment transactions | Customer name, transaction amounts | India/United States |
Google LLC | "Sign in with Google" authentication (only if you choose it) | Name, email address, Google account ID | United States |
Inngest, Inc. | Background job orchestration | Job and event metadata (user IDs, job status) | United States |
ipapi (Kloudend Ltd.) | IP geolocation for login-security alerts | IP address | Global |
Atlassian Pty Ltd (Trello) | Internal operations ticketing | Limited service-event metadata (no customer message content) | United States / Australia |
Generative-media model providers, as enabled: OpenAI, Google, Anthropic, Stability AI, Black Forest Labs, Runway, Recraft, Bria, fal.ai, Microsoft; DeepL and Google Cloud Translation for translation features | Optional image/video generation and translation features | Prompts and media you submit to those features | United States / EU |
Customer support is handled in-house through the Company's own contact form and email systems — no third-party helpdesk service processes support data.
2.2 Future Sub-Processors
The Company may engage additional Sub-processors from time to time to support platform functionality, security, or compliance. Any new Sub-processors will be subject to the safeguards described below and added to this list in accordance with the notice provisions set forth in this document.
3. SUB-PROCESSOR SAFEGUARDS
3.1 Contractual Protections
All Sub-processors are subject to contractual obligations that are no less protective than those set forth in the Company’s Data Processing Addendum (DPA), incorporated into the Master Services Agreement. The Company does not engage Sub-processors that cannot demonstrate adequate data protection commitments consistent with applicable data protection laws.
3.2 Safeguard Requirements
These obligations include:
- Confidentiality obligations;
- Security safeguards;
- Data protection commitments; and
- Restrictions on use of Personal Data.
4. UPDATES & OBJECTIONS
4.1 Notice of Changes
The Company will provide at least fourteen (14) days’ prior written notice before engaging any new Sub-processor by:
- Updating this list; and
- Notifying customers via email or in-platform notification.
4.2 Customer Objection Rights
Customers may object to the engagement of a new Sub-processor on reasonable data protection grounds by contacting privacy@sonicvox.ai within the notice period.
5. INTERNATIONAL DATA TRANSFERS
EU STANDARD CONTRACTUAL CLAUSES (GDPR ARTICLE 46)
Version: EU Commission Decision 2021/914
Effective Date: June 1, 2026
5.1 Applicability
These Standard Contractual Clauses (“SCCs”) apply where the Company processes Personal Data originating from the European Economic Area (EEA) and transfers such data to the United States or other non-adequate jurisdictions pursuant to EU Commission Decision 2021/914.
For transfers of Personal Data originating from the United Kingdom, the Company relies on the UK International Data Transfer Agreement (IDTA) or the EU SCCs together with the UK Addendum as approved by the UK Information Commissioner’s Office.
For transfers originating from Switzerland, the Company applies supplementary measures consistent with the Swiss Federal Act on Data Protection (nFADP).
5.2 Roles
- Data Exporter: Customer (Controller)
- Data Importer: WP Global Syndicate LLC dba SonicVox (Processor)
5.3 Incorporated Clauses
The Company relies on the European Commission Standard Contractual Clauses (Controller-to-Processor) as set forth in Decision 2021/914, Module Two.
Where the Company transfers Personal Data to Sub-processors located in non-adequate jurisdictions, Module Three (Processor-to-Processor) of Decision 2021/914 shall apply.
The SCCs are incorporated by reference into the Company’s Data Processing Addendum and govern international data transfers unless superseded by an adequacy decision or other lawful transfer mechanism.
5.4 Supplementary Measures
To address Schrems II requirements, the Company implements:
- Encryption in transit and at rest;
- Access controls and least-privilege policies;
- Commitments to notify Customers of government access requests to the extent permitted by law, and to challenge overbroad or unlawful requests through available legal mechanisms;
- Data minimization and segregation; and
- Incident response and transparency procedures.
5.5 Availability
A full executed copy of the SCCs is available to Customers upon request by contacting privacy@sonicvox.ai.
