Data Processing Agreement

This Data Processing Agreement (“DPA”) describes how VoiceLine processes personal data on behalf of its customers when users use the VoiceLine application.


  1. ROLES OF THE PARTIES

  • The customer’s company acts as the Data Controller within the meaning of Art. 4(7) GDPR.

  • VoiceLine GmbH acts as the Data Processor within the meaning of Art. 4(8) GDPR.

VoiceLine processes personal data solely on documented instructions of the customer and in accordance with this DPA.



  1. SUBJECT MATTER AND PURPOSE OF PROCESSING

VoiceLine processes personal data to provide the VoiceLine application and its voice-based functionality, including:

  • Recording voice input

  • Generating and storing transcriptions

  • Storing related metadata (e.g. timestamps, device identifiers)

Processing is limited to what is necessary to deliver, operate, and improve the agreed services.



  1. TYPES OF PERSONAL DATA AND DATA SUBJECTS

Types of personal data:

  • Voice recordings (audio files)

  • Text transcriptions

  • Usage and technical metadata


Data subjects:

  • Authorized users of the VoiceLine application (employees of the customer)



  1. DURATION OF PROCESSING

Personal data is processed for the duration of the contractual relationship between the customer and VoiceLine, unless deletion is requested earlier or legal retention obligations apply.



  1. PROCESSOR OBLIGATIONS (VOICELINE)

VoiceLine commits to:

  • Process personal data only for the agreed purposes

  • Ensure confidentiality of all personnel involved in data processing

  • Implement appropriate technical and organizational measures to protect personal data

  • Support the customer in fulfilling data subject rights (e.g. access, deletion)

  • Notify the customer without undue delay in the event of a personal data breach



  1. SUBPROCESSORS

VoiceLine may engage subprocessors (e.g. cloud infrastructure or speech-to-text providers) solely for service delivery.


All subprocessors are:

  • Contractually bound by GDPR-compliant agreements

  • Subject to appropriate security and confidentiality obligations

A current list of subprocessors is available upon request.



  1. DATA SECURITY

VoiceLine implements industry-standard technical and organizational security measures, including:

  • Access controls

  • Encryption

  • Secure hosting environments within the EU



  1. DATA SUBJECT RIGHTS

VoiceLine supports the customer in responding to data subject requests, including requests for access, correction, deletion, or restriction of processing.



  1. DELETION AND RETURN OF DATA

Upon termination of the service or upon customer request, VoiceLine will delete or anonymize personal data unless retention is required by law.



  1. GOVERNING LAW

This DPA is governed by the laws of the Federal Republic of Germany and the GDPR.