Data Processing Addendum
This addendum covers customer content we process on your behalf. It is part of the Reseller Agreement. It is also part of the Customer Terms where you use the services to process personal information of your staff, callers or customers. Australian law is the primary regime. GDPR-style labels are used only where they help describe the relationship.
Contents
1. Roles
For account administration, billing, security, fraud prevention and our own business operations, VoxaLink decides why and how personal information is handled and is an APP entity in its own right.
For customer content processed through the services, including call audio, recordings, transcripts, SMS content, AI prompts and outputs, contacts and API payloads, you decide why the processing happens (for example, to run your phone system or to record calls). We process that content to provide, secure, support and bill the services, and as otherwise documented in the agreement, a service setting, or a written instruction from you.
If the law treats us as having an independent obligation (for example a warrant, a numbering database, or a notifiable data breach on our systems), we will meet that obligation even if it is not an instruction from you.
2. Your instructions
Your instructions are this addendum, the product configuration you (or your administrator) set, and written instructions you send to privacy@voxalink.cloud or through an agreed support channel. We will not process customer content for our own marketing, and we will not use it to train VoxaLink-owned AI models unless you agree in writing.
You must make sure your instructions are lawful and that you have given required privacy notices and obtained required consents, including for recording, AI, overseas processing and sensitive information.
3. Subprocessors
You authorise us to use subprocessors for hosting, carriers, SMS, storage, databases, monitoring, workflow, AI, transcription, text-to-speech, support, payment and security, as needed to provide the services. We will use reasonable contractual, technical and organisational controls for those subprocessors, including for overseas recipients as described in the Privacy Policy.
A current description of the types of subprocessors is in the Privacy Policy. We will not sell customer content. If you need a named subprocessor list for a particular tenant, ask privacy@voxalink.cloud.
4. Security
We will take reasonable steps to protect customer content from misuse, interference, loss, and unauthorised access, modification or disclosure, as described in the Privacy Policy. You must protect credentials, end-user access and any system you connect.
5. Incidents
If we become aware of a confirmed security incident affecting customer content we process on your behalf, we will notify you without undue delay at your account contacts, and in any case in time for you to meet a legal notification duty we have told you about. We will give you the facts we reasonably have: what happened, what information was involved, and what we are doing.
6. Help with individual requests
If an individual asks us for access, correction or deletion of personal information that is customer content, we will tell you where the request should go, unless the law requires us to handle it ourselves. We will give you reasonable assistance, through product tools where they exist, so you can respond.
7. Return and deletion
On termination we will delete or return customer content in accordance with product functionality, your retention settings, backup cycles, legal obligations and reasonable operational constraints. You should export anything you need before the service ends. Billing, fraud, audit and legally retained records are kept as described in the Privacy Policy.
8. International processing
Customer content may be processed in Australia and in the countries listed in the Privacy Policy. We take the reasonable steps described there for overseas recipients we appoint. Recipients you appoint under the BYOC Policy are your responsibility.