This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and DRAKB LLC, doing business as Vocenya and GH Business Solutions ("Vocenya"). It applies whenever Vocenya processes Personal Data on Customer's behalf through the Services. If there is a conflict, a signed Business Associate Agreement controls for protected health information, then this DPA, then the Terms.
1. Definitions
- Personal Data: information about an identified or identifiable person that Vocenya processes for Customer through the Services, such as callers', texters' and chat visitors' names, numbers, messages, recordings and transcripts.
- Data Protection Laws: the US federal and state privacy laws that apply to the processing, including the California Consumer Privacy Act (CCPA), the New Jersey Data Privacy Act and similar state laws.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- Sub-processor: a third party Vocenya engages to process Personal Data.
2. Roles
Customer is the controller (or "business") of Personal Data and decides why and how it is processed. Vocenya is Customer's processor (or "service provider" or "contractor") and processes Personal Data only on Customer's behalf. Vocenya is a separate controller only for the account, billing and usage information it needs to run its own business, which its Privacy Policy covers.
3. Customer's instructions
Vocenya processes Personal Data only to provide, secure and support the Services, as described in the Terms, this DPA and Customer's settings, or as the law requires. Customer's use and configuration of the Services are its instructions. Vocenya will tell Customer if it believes an instruction breaks the law. Customer is responsible for having a lawful basis and the notices and consents needed for the Personal Data it provides, including for call recording, AI interactions and outbound calls and texts.
4. Service-provider commitments
Vocenya will not:
- sell or share Personal Data, as those words are used in the CCPA;
- retain, use or disclose Personal Data outside the direct business relationship with Customer or for any purpose other than providing the Services;
- combine Personal Data with data from other sources except as the Services require and the law allows;
- use Customer's recordings, transcripts or messages to train third-party AI models.
5. Confidentiality
Vocenya ensures that people authorized to process Personal Data, including its employees, its affiliate GH Business Solutions and contractors, are bound by confidentiality obligations and access only what they need for their role.
6. Sub-processors
Customer authorizes Vocenya to use the sub-processors listed at /subprocessors. Vocenya will:
- impose data protection terms on each sub-processor that protect Personal Data at least as well as this DPA;
- update the list before a new sub-processor starts processing Personal Data, and notify customers who have asked to be told of changes;
- remain responsible for its sub-processors' performance.
Customer may object to a new sub-processor on reasonable data protection grounds within 30 days of notice. Vocenya will try in good faith to resolve the objection; if it can't, Customer may end the affected Services and receive a refund of prepaid fees for the unused period.
7. Security
Vocenya maintains administrative, technical and physical safeguards appropriate to the risk, described on our Security page. They include hosting in Amazon Web Services in the United States, encryption in transit, encryption of call recordings and stored credentials, access controls with two-factor authentication available to every user, read-only and logged staff access to customer accounts, and logging of access to recordings.
8. Security incidents
Vocenya will notify Customer without undue delay, and within 72 hours where feasible, after becoming aware of a Security Incident affecting Customer's Personal Data. The notice will describe what happened, the data affected, the steps taken and a contact point, with more detail as it becomes available. Vocenya will take reasonable steps to contain the incident and help Customer meet its own notification duties. Notifying Customer is not an admission of fault.
9. Assistance with requests
Taking into account the nature of the processing, Vocenya will help Customer respond to requests from individuals to access, correct, delete or obtain a copy of their Personal Data, and with data protection assessments Customer is required to carry out. Account owners can delete call recordings, transcripts and chat messages themselves in the portal or the app; other requests can be sent to [email protected]. If Vocenya receives a request directly from an individual about Customer's data, it will refer the individual to Customer.
10. Deletion and return
During the subscription, Customer can delete call recordings, transcripts and chat messages, or have recordings and transcripts deleted automatically after a period Customer chooses. Within 30 days after the Services end, Customer may ask for a copy of its Customer Data, which Vocenya will provide in a commonly used format. After that, Vocenya will delete or de-identify Personal Data within a reasonable period, except records it must keep by law (such as opt-out and Do-Not-Call records) or for billing, tax and dispute purposes, which remain protected by this DPA.
11. Audits
On written request, no more than once a year, Vocenya will answer Customer's reasonable written questions about its data protection practices and provide information needed to show compliance with this DPA. Any on-site audit needs mutual agreement on scope, timing and cost, and is subject to confidentiality.
12. International transfers
Vocenya stores Personal Data primarily in the United States. Some support and live-agent work is performed by GH Business Solutions from the Philippines, under confidentiality obligations and with access limited to what each conversation needs. Vocenya does not currently offer the Services to customers who need data transferred out of the European Economic Area, the United Kingdom or Switzerland under those regions' transfer rules; contact us first if that applies to you.
13. Healthcare information
Protected health information is processed only for customers who have HIPAA mode on and a Business Associate Agreement with Vocenya, and the Business Associate Agreement governs it.
14. Term and liability
This DPA lasts as long as Vocenya processes Personal Data for Customer. Each party's liability under this DPA is subject to the limitations in the Terms.
Contact
DRAKB LLC dba Vocenya Email: [email protected]