Data Protection Addendum

Last updated: April 28, 2025

Document InformationDetails
Agreement TypeData Protection Addendum ("Addendum")
PartiesVOCALLABS AI and Customer
Effective DateApril 28, 2025
PurposeTo establish terms and conditions for data protection and processing
Governing TermsForms part of VOCALLABS AI Terms of Service

This Data Protection Addendum ("Addendum") between VOCALLABS AI ("VOCALLABS AI") and the Customer (as defined in the Agreement) forms part of the VOCALLABS AI Terms of Service set forth at https://vocallabs.ai/terms-and-conditions or such other written or electronic agreement incorporating this Addendum, in each case governing Customer's access to and use of the Services (the "Agreement"). This addendum was last updated in April, 2025.

Customer enters into this Addendum on behalf of itself and any Affiliates authorized to use the Services under the Agreement and who have not entered into a separate contractual arrangement with VOCALLABS AI. For the purposes of this Addendum only, and except where otherwise indicated, references to "Customer" shall include Customer and such Affiliates.

The Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Agreement.

Definitions

In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:

  • Affiliate: means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with either Customer or VOCALLABS AI (as the context allows), where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
  • Customer Personal Data: means any Personal Data provided by or made available by Customer to VOCALLABS AI or collected by VOCALLABS AI on behalf of Customer which is Processed by VOCALLABS AI to perform the Services;
  • Controller to Processor SCCs: means the standard contractual clauses for cross-border transfers published by the European Commission on June 4, 2021 governing the transfer of European Area Personal Data to Third Countries;
  • Data Protection Laws: means any local, state, or national law regarding the processing of Personal Data applicable to VOCALLABS AI in the jurisdictions in which the Services are provided to Customer;
  • EU Area: means the European Union, European Economic Area, United Kingdom, and Switzerland;
  • EU Area Law: means (i) Directive 95/46/EC and, from May 25, 2018, Regulation (EU) 2016/679 ("EU GDPR") together with applicable legislation implementing or supplementing the same or otherwise relating to the processing of Personal Data of natural persons; (ii) the Data Protection Act 1998 of the United Kingdom and the EU GDPR as saved into United Kingdom Law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (iii) the swiss Federal Data Protection Act of 19 June 1992 and its Ordinance ("Swiss DPA"); (iv) any other law relating to the data protection, security, or privacy of individuals that applies in the EU Area; or (v) any successor or amendments thereto;
  • Security Incident: means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by VOCALLABS AI;
  • Services: means the services to be supplied by VOCALLABS AI to Customer or Customer's Affiliates pursuant to the Agreement;
  • Third Country: means countries that, where required by applicable Data Protection Laws, have not received an adequacy decision from an applicable authority relating to cross-border data transfers of Personal Data, including regulators such as the European Commission, UK ICO, or Swiss FDPIC.

The terms "Business", "Business Purpose", "commercial purpose", "Contractor", "Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Process", "Processor", "Sell", "Service Provider", "Share", "Subprocessor", "Supervisory Authority", and "Third Party" have the same meanings as described in applicable Data Protection Laws and cognate terms shall be construed accordingly.

Capitalized terms not otherwise defined in this Addendum shall have the meanings ascribed to them in the Agreement.

Data Processing Terms

Customer shall comply with all applicable Data Protection Laws in connection with the performance of this Addendum and the Processing of Customer Personal Data. In connection with its access to and use of the Services, Customer shall Process Customer Personal Data within such Services and provide VOCALLABS AI with instructions in accordance with applicable Data Protection Laws. As between the Parties, Customer shall be solely responsible for compliance with applicable Data Protection Laws regarding the collection of and transfer to VOCALLABS AI of Customer Personal Data. Customer agrees not to provide VOCALLABS AI with any data concerning a natural person's health, religion or any special categories of data as defined in Article 9 of the GDPR.

VOCALLABS AI shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data and shall:

  • Process the Customer Personal Data for the purposes of the Agreement and for the specific purposes in each case as set out in Annex 1 to this Addendum and otherwise solely on the documented instructions of Customer;
  • Ensure that persons authorized to Process the Customer Personal Data have committed themselves to confidentiality;
  • Take all measures required to ensure the security of Processing;
  • Respect the conditions for engaging another Processor;
  • Assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR;
  • Delete or return all the Personal Data to Customer after the end of the provision of Services;
  • Make available to Customer all information necessary to demonstrate compliance with these obligations.

Security Measures

VOCALLABS AI implements and maintains appropriate technical and organizational security measures including:

  • Encryption of personal data in transit and at rest;
  • Ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems;
  • Ability to restore availability and access to personal data in a timely manner;
  • Regular testing, assessing and evaluating of technical and organizational measures.

International Transfers

The parties agree that when the transfer of Customer Personal Data from Customer and/or any of its Affiliates (as exporter) to VOCALLABS AI (as importer) is a Restricted Transfer and EU Area Law applies, the transfer shall be subject to the appropriate Controller to Processor SCCs.

For transfers of Personal Data to Third Countries, VOCALLABS AI shall:

  • Process Personal Data using AI and machine learning technologies within the Frankfurt Region, Germany;
  • Implement appropriate safeguards through Standard Contractual Clauses;
  • Conduct regular reviews of international transfers;
  • Implement additional technical measures where necessary.

Customer should routinely review all international transfers of Personal Data on a case-by-case basis in order to monitor new risks because of the changes in local laws, data practices, etc., and implement additional safeguards (such as encryption or pseudonymization) to mitigate identified risks to ensure the Personal Data remains protected to the standard required under Data Protection Laws.

Subprocessing

VOCALLABS AI may engage Subprocessors to Process Customer Personal Data, subject to:

  • Prior notification to Customer of intended changes;
  • Imposing data protection obligations on Subprocessors;
  • Remaining liable for Subprocessor compliance.

Security Management System

Organization

VOCALLABS AI designates qualified security personnel whose responsibilities include development, implementation, and ongoing maintenance of the Information Security Program.

Policies and Standards

  • Management reviews and supports all security related policies to ensure the security, availability, integrity and confidentiality of Customer Personal Data.
  • These policies are updated at least once annually.
  • VOCALLABS AI operates an information security management system that complies with the requirements of ISO/IEC 27001:2022 standard.

Risk Management

  • VOCALLABS AI engages a reputable independent third-party to perform risk assessments of all systems containing Customer Personal Data at least once annually.
  • Maintains a formal and effective risk treatment program including penetration testing, vulnerability management and patch management.
  • Reviews security incidents regularly, including effective determination of root cause and corrective action.

Access Controls

  • Maintains a formal access management process for all personnel with access to Customer Personal Data.
  • Access reviews are conducted periodically to ensure proper authorization.
  • Multi-Factor authentication required for all administrators and end users.
  • Implements least privilege and need-to-know principles for data access.

Infrastructure Security

  • Uses AWS as primary data center with Multi-Availability Zone configuration.
  • Conducts regular backup restoration testing to ensure resiliency.
  • Implements comprehensive logging and monitoring systems.
  • Performs regular vulnerability scans on all infrastructure components.
  • Maintains incident management policies and procedures.

Data Protection

  • Implements HTTPS encryption for data in transit.
  • Encrypts data at rest using industry-standard encryption.
  • Maintains logical isolation between different customers' data.
  • Implements secure data disposal processes.

Annex 1 to Data Protection Addendum

Description of Processing Activities for Customer Personal Data

This Annex includes certain details of the Processing of Customer Personal Data by VOCALLABS AI in connection with the Services.

List of Parties
Data Exporter
NameCustomer (as defined in the Agreement)
AddressAs set forth in the relevant Order Form.
Contact person's name, position and contact detailsAs set forth in the relevant Order Form.
Activities relevant to the data transferred under these ClausesRecipient of the Services provided by VOCALLABS AI in accordance with the Agreement.
Signature and dateSignature and date are set out in the Agreement.
Role (controller/processor)Controller
Data Importer
NameVOCALLABS AI
AddressNo. 39, 8th Main Road
Desk No. L22 Third Floor
Vasanth Nagar, Bangalore
Karnataka, India 560001
Contact person's name, position and contact detailsMritunjoy Das, [email protected]
Activities relevant to the data transferred under these ClausesProvision of the Services to the Customer in accordance with the Agreement.
Signature and dateSignature and date are set out in the Agreement.
Role (controller/processor)Processor
Processing Information
Categories of data subjects whose personal data is transferredCustomer's authorized users of the Services
Categories of personal data transferred

Processed automatically by the Services:

  • Names
  • email IDs

Processed where and to the extent provided by Customer or its authorized users in connection with audit services provided by VOCALLABS AI:

  • address
  • date of birth
  • past employment details
Sensitive personal data transferredNone
Frequency of the transferContinuous
Nature of the processingThe nature of the processing is more fully described in the Agreement and accompanying order forms but will include the following basic processing activities: The provision of Services to Customer. In order to provide people data, VOCALLABS AI receives identifying Customer Personal Data to permit VOCALLABS AI to query, cleanse, standardize, enrich, (when required) send to additional data to feed providers, and to store the query information.
Purpose of the data transfer and further processingThe purpose of the transfer is to facilitate the performance of the Services more fully described in the Agreement and accompanying order forms.
Period for which the personal data will be retainedThe period for which the Customer Personal Data will be retained is more fully described in the Agreement, Addendum, and accompanying order forms.
Subprocessor transfers – subject matter, nature, and duration of processingThe subject matter, nature, and duration of the Processing more fully described in the Agreement, Addendum, and accompanying order forms.

Contact Information

For any questions about this Data Protection Addendum, please contact:

India Office:

No. 39, 8th Main Road
Desk No. L22 Third Floor
Vasanth Nagar, Bangalore
Karnataka, India 560001

CIN: U63121KA2025PTC197380