1. Roles
1.1 The Customer is the controller of the personal data of the people who call its phone lines and of its own staff ("Customer Personal Data"). Vorelai processes it as the Customer's processor, within the meaning of the EU General Data Protection Regulation (GDPR) and the UK GDPR, and as a "service provider" under US state privacy laws that use the term.
1.2 Annex 1 describes the processing: its subject, duration, nature and purpose, the kinds of personal data and of people concerned.
1.3 Vorelai is a controller, not a processor, of the data it needs to run its own business: dashboard users' accounts, billing, and the security of its service. Its privacy policy covers that data.
2. Instructions
2.1 Vorelai processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's use and settings of the service (its agents, trunks, recording, retention and integrations) are those instructions.
2.2 Vorelai tells the Customer if it believes an instruction breaks data protection law, and may suspend the processing concerned until the Customer confirms or changes it.
2.3 If a law requires Vorelai to process Customer Personal Data otherwise, Vorelai tells the Customer first, unless that law forbids it.
3. Confidentiality
Everyone Vorelai authorises to process Customer Personal Data is bound to confidentiality. Vorelai's staff access a Customer's calls only to provide the service, to diagnose a problem, or when the Customer asks; access to live calls is logged.
4. Security
4.1 Vorelai takes the technical and organisational measures in Annex 2 (the Security overview) to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
4.2 Vorelai may update those measures, as long as the protection they give doesn't decrease.
4.3 The Customer is responsible for the security of what it controls: its dashboard accounts, its phone system and the trunk credentials in it, its own API keys and integrations, and the settings it chooses (for example, whether a trunk requires encryption).
5. Personal data breaches
5.1 Vorelai notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and within 48 hours of confirming it, by email to the workspace's owners.
5.2 The notice says, as far as Vorelai knows at the time: what happened, the kinds and approximate number of people and records concerned, the likely consequences, and what Vorelai has done and proposes to do. Vorelai adds what it learns later.
5.3 The Customer makes its own notifications to supervisory authorities and the people concerned. Vorelai helps by giving it the information they need, as in 5.2, and answering its reasonable questions about the breach. Notifying the Customer is not an admission of fault.
6. Helping the Customer
6.1 Callers' requests. The service lets the Customer answer the people whose data it holds: it shows each call, deletes one call's content, and deletes all content from one caller's number at once. If a caller writes to Vorelai directly, Vorelai passes the request to the Customer and doesn't answer it itself.
6.2 Assessments and consultations. For a data protection impact assessment or a prior consultation with a supervisory authority, Vorelai gives the Customer the information it reasonably needs about Vorelai's part in the processing. These documents normally provide it; Vorelai answers reasonable further questions in writing.
7. Subprocessors
7.1 The Customer authorises Vorelai to use the subprocessors listed in Subprocessors.
7.2 Vorelai tells the Customer at least 14 days before adding or replacing a subprocessor, by email to the workspace's owners and on the list. When a subprocessor must be replaced at short notice to keep the service secure or running, Vorelai tells the Customer as soon as it can, and the Customer's right to object below still applies. The Customer may object on reasonable data protection grounds within that time; if Vorelai can't reasonably accommodate the objection, the Customer may end the service concerned and receive a refund of what it prepaid for the time after it ends.
7.3 Vorelai binds each subprocessor by contract to data protection obligations no less protective than this DPA's, and remains responsible to the Customer for them.
7.4 Services the Customer connects itself (its calendar, its own tools and webhooks, its own Gemini API key) process data on the Customer's instruction under the Customer's own agreements, and are not Vorelai's subprocessors.
8. International transfers
8.1 Some subprocessors process Customer Personal Data outside the European Economic Area and the UK (see Subprocessors). Each such transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework, for certified recipients) or by the European Commission's Standard Contractual Clauses (and the UK Addendum), with the measures in Annex 2.
8.2 The Customer acknowledges that the AI model that answers its calls (Google's Gemini API) processes call audio and text in Google's global infrastructure.
9. Retention, return and deletion
9.1 During the service, Customer Personal Data is kept as the Data retention page and the Customer's settings say.
9.2 When the service ends, Vorelai deletes Customer Personal Data within 90 days, or within 30 days of the Customer asking. If the Customer asks before then for a copy of its call records, Vorelai provides one in a common machine-readable format before deleting. Data in backups is deleted as the backups roll over. A law that requires Vorelai to keep some data overrides this, for that data, as long as the law requires.
10. Audits
10.1 Vorelai makes available the information needed to show it meets this DPA: these documents, written answers to a reasonable security questionnaire at most once a year, and its subprocessors' certifications and audit reports where they allow it.
10.2 If that isn't enough, or a supervisory authority requires it, the Customer may audit Vorelai's compliance once a year, itself or through an independent auditor bound to confidentiality, on 30 days' notice, during business hours, without access to other customers' data, and at its own cost. An audit starts with a remote review of documents; it includes a visit only if that review can't answer what the Customer needs to know, and the Customer then also pays Vorelai's reasonable costs of hosting it.
11. General
11.1 This DPA lasts as long as Vorelai processes Customer Personal Data for the Customer.
11.2 If this DPA and the Terms conflict about personal data, this DPA wins. If the Standard Contractual Clauses apply and conflict with this DPA, they win.
11.3 Each party's liability under this DPA is subject to the limits in the Terms.
11.4 This DPA is governed by the law that governs the Terms, unless the Standard Contractual Clauses require otherwise.
Annex 1: the processing
| Subject and purpose | Answering the Customer's phone calls with AI voice agents the Customer configures, and giving the Customer the calls' records: transcripts, summaries, recordings if it chooses, figures and costs. Sending the Customer emails and webhooks about calls if it chooses. Booking appointments and calling the Customer's own tools during calls if it configures them |
| Duration | The term of the service, then as in section 9 |
| Nature | Receiving call audio and signalling, transcribing and generating speech with an AI model, storing call records and recordings, deleting them on the Customer's schedule |
| People concerned | People who call the Customer's phone lines; the Customer's staff who use the dashboard or are named in agents and knowledge |
| Personal data | Callers: phone number, voice, what they say and key in, what the agent records for them in a booking or tool (for example name, email, appointment times), the call's summary. Staff: name, email, role in the workspace. Whatever the Customer puts in its agents' instructions and knowledge |
| Special categories | Not intended. Callers may mention health or other sensitive matters on a call; the Customer decides whether its use of the service suits such calls, and its retention settings apply to them |
| Frequency | Continuous, on each call |
Annex 2: technical and organisational measures
See the Security overview.
Annex 3: subprocessors
See Subprocessors.