Back to home

Legal

Data Processing Agreement

This DPA governs how Voxelo processes personal data on your behalf as a data processor under POPIA.

Last updated: 1 June 2026

This Data Processing Agreement (“DPA”) forms part of the Voxelo Terms of Service between you (“Controller”) and Voxelo (Pty) Ltd (“Processor”). By using the Voxelo platform you agree to this DPA.

1. Definitions

  • Controller — the Tenant (business customer) who determines the purposes and means of processing personal data via the Voxelo platform.
  • Processor — Voxelo (Pty) Ltd, which processes personal data on behalf of the Controller.
  • Data Subject — callers, website visitors, or customers of the Controller whose personal data is processed.
  • Personal Information / Personal Data — as defined in POPIA: information relating to an identifiable, living natural person.
  • Processing — any operation performed on personal data, including collection, storage, transmission, and deletion.

2. Processing Description

Subject matter

Voxelo processes personal data to operate the AI receptionist service on behalf of the Controller, including answering voice calls, handling chat and WhatsApp messages, generating transcripts, and routing communications.

Duration

Processing continues for the duration of the Controller’s subscription and for up to 30 days after termination (for data retrieval), after which data is deleted.

Categories of data subjects

Callers, chat users, WhatsApp contacts, and any individual who contacts the Controller via channels routed through Voxelo.

Types of personal data processed

  • Voice recordings and transcripts.
  • Chat and WhatsApp message content.
  • Caller phone numbers (CLI), if provided by the carrier.
  • Names, booking details, and other information shared voluntarily by data subjects.
  • IP addresses and device identifiers (dashboard and web widget only).

3. Processor Obligations

Voxelo shall:

  • Process personal data only on documented instructions from the Controller (as configured in the dashboard or as required by applicable law).
  • Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement and maintain appropriate technical and organisational security measures (see Security page).
  • Notify the Controller without undue delay upon becoming aware of a personal data breach affecting Controller data.
  • Delete or return all personal data upon termination of the agreement, at the Controller’s choice.
  • Make available all information necessary to demonstrate compliance and support audits.

4. Controller Obligations

The Controller warrants that:

  • It has a lawful basis for processing personal data via the Voxelo platform.
  • Data subjects have been given appropriate disclosure that their calls may be handled by an AI agent, and (if recording is enabled) that calls are recorded.
  • It has implemented caller consent mechanisms where required by RICA and POPIA.
  • It will not instruct Voxelo to process data in a manner that would violate applicable law.

5. Sub-processors

The Controller grants Voxelo a general authorisation to engage the following categories of sub-processor:

  • Twilio Inc. — voice call routing, SMS, and WhatsApp Business API.
  • Deepgram Inc. — automatic speech recognition / transcription.
  • OpenAI LLC — large language model inference.
  • ElevenLabs Inc. — text-to-speech voice synthesis.
  • Auth.js / NextAuth — authentication and session management.
  • Xneelo (Pty) Ltd — primary hosting infrastructure (South Africa).

Voxelo will notify the Controller at least 30 days before adding or replacing a sub-processor. If the Controller objects on reasonable grounds, Voxelo will use reasonable efforts to make an alternative arrangement or permit termination without penalty.

6. International Data Transfers

Primary data storage is in South Africa. Some sub-processors (e.g., Twilio, Deepgram, OpenAI) may process data outside South Africa. Voxelo enters into Data Processing Agreements with all such sub-processors that include appropriate safeguards equivalent to those required by POPIA, including standard contractual clauses where applicable.

7. Audit Rights

Enterprise customers may request, no more than once per 12-month period, a summary of Voxelo’s security audit results or, with 30 days’ notice and reasonable cost reimbursement, an on-site audit. Voxelo may satisfy audit requests by providing its most recent third-party audit reports under NDA.

8. Governing Law

This DPA is governed by the laws of the Republic of South Africa and POPIA. Disputes shall be resolved under the same jurisdiction as the Terms of Service.

9. Contact

DPA enquiries: legal@voxelo.co.za