Data processing addendum
Last updated 9 September 2026. Draft for review before launch.
This addendum applies when Voiceflint processes personal data on behalf of a customer subject to the GDPR, UK GDPR or similar laws, and forms part of the terms of service.
Roles. The customer is the controller of call data; Voiceflint is the processor and acts only on documented instructions given through the dashboard, API and these terms.
Sub-processors. Voiceflint uses the sub-processors listed on the sub-processors page and will give at least 14 days' notice of additions by updating that page; the customer may object on reasonable grounds.
Security. Voiceflint maintains technical and organisational measures including encryption in transit and at rest, least-privilege access, encrypted storage of provider keys, per-workspace isolation, and retention controls.
Assistance. Voiceflint will assist with data subject requests (erasure is self-service via the API), with data protection impact assessments on request, and will notify the customer without undue delay after becoming aware of a personal data breach.
Transfers. Where data leaves the EU or UK, Voiceflint relies on the EU Standard Contractual Clauses or the UK Addendum with each sub-processor; EU-region agents keep media, workers and supported provider endpoints in the EU.
Deletion. On termination, Voiceflint deletes customer data within 30 days except where retention is required by law or for billing records.
Audit. Voiceflint will make available information reasonably necessary to demonstrate compliance and allow audits on reasonable notice, no more than annually unless required by a supervisory authority.