1. Scope
This DPA applies when Vocaler ("Processor") processes Personal Data on behalf of Customer ("Controller") in the course of providing the Vocaler service. It is incorporated by reference into the Master Subscription Agreement between the parties. PLACEHOLDER.
2. Roles
Customer is the Controller of any Personal Data it uploads or that its end-users submit. Vocaler is the Processor and acts only on Customer's documented instructions. PLACEHOLDER.
3. Categories of data
Account identifiers, billing records, audio uploads, renders, and usage logs. We do not process special categories of data; Customer agrees not to upload data falling under GDPR Article 9 without prior written agreement. PLACEHOLDER.
4. Sub-processors
Vocaler engages the sub-processors listed at /security. Customer authorises this list and will be notified at least 30 days before any addition. Customer may object in writing within 14 days of notice. PLACEHOLDER.
5. International transfers
Where Personal Data is transferred outside the EEA / UK / Switzerland, Vocaler relies on the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, incorporated here by reference. PLACEHOLDER.
6. Security measures
Technical and organisational measures include encryption at rest and in transit, least-privilege access controls, multi-factor authentication for all employees with production access, audit logging of administrative actions, and quarterly access reviews. A current detailed list is provided on request under NDA. PLACEHOLDER.
7. Breach notification
Vocaler will notify Customer without undue delay and in any case within 72 hours of confirming a Personal Data Breach affecting Customer data. Notice will include the categories of data affected, the approximate number of records, the likely consequences, and the measures taken. PLACEHOLDER.
8. Audit rights
Customer may audit Vocaler's processing operations on reasonable prior notice, no more than once per twelve-month period (more frequently if required by a supervisory authority). Vocaler will provide its most recent SOC 2 report in lieu of an on-site audit where acceptable. PLACEHOLDER.
9. Return / deletion
On termination, Vocaler will return or delete all Personal Data at Customer's choice within 30 days, unless retention is required by law. PLACEHOLDER.
Contact
Email privacy@vocaler.ai to request a counter-signed copy of this DPA.