Legal
Data Processing Agreement
This DPA governs how Voxelo processes personal data on your behalf as a data processor under POPIA.
1. Definitions
- Controller — the Tenant (business customer) who determines the purposes and means of processing personal data via the Voxelo platform.
- Processor — Voxelo (Pty) Ltd, which processes personal data on behalf of the Controller.
- Data Subject — callers, website visitors, or customers of the Controller whose personal data is processed.
- Personal Information / Personal Data — as defined in POPIA: information relating to an identifiable, living natural person.
- Processing — any operation performed on personal data, including collection, storage, transmission, and deletion.
2. Processing Description
Subject matter
Voxelo processes personal data to operate the AI receptionist service on behalf of the Controller, including answering voice calls, handling chat and WhatsApp messages, generating transcripts, and routing communications.
Duration
Processing continues for the duration of the Controller’s subscription and for up to 30 days after termination (for data retrieval), after which data is deleted.
Categories of data subjects
Callers, chat users, WhatsApp contacts, and any individual who contacts the Controller via channels routed through Voxelo.
Types of personal data processed
- Voice recordings and transcripts.
- Chat and WhatsApp message content.
- Caller phone numbers (CLI), if provided by the carrier.
- Names, booking details, and other information shared voluntarily by data subjects.
- IP addresses and device identifiers (dashboard and web widget only).
3. Processor Obligations
Voxelo shall:
- Process personal data only on documented instructions from the Controller (as configured in the dashboard or as required by applicable law).
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures (see Security page).
- Notify the Controller without undue delay upon becoming aware of a personal data breach affecting Controller data.
- Delete or return all personal data upon termination of the agreement, at the Controller’s choice.
- Make available all information necessary to demonstrate compliance and support audits.
4. Controller Obligations
The Controller warrants that:
- It has a lawful basis for processing personal data via the Voxelo platform.
- Data subjects have been given appropriate disclosure that their calls may be handled by an AI agent, and (if recording is enabled) that calls are recorded.
- It has implemented caller consent mechanisms where required by RICA and POPIA.
- It will not instruct Voxelo to process data in a manner that would violate applicable law.
5. Sub-processors
The Controller grants Voxelo a general authorisation to engage the following categories of sub-processor:
- Twilio Inc. — voice call routing, SMS, and WhatsApp Business API.
- Deepgram Inc. — automatic speech recognition / transcription.
- OpenAI LLC — large language model inference.
- ElevenLabs Inc. — text-to-speech voice synthesis.
- Auth.js / NextAuth — authentication and session management.
- Xneelo (Pty) Ltd — primary hosting infrastructure (South Africa).
Voxelo will notify the Controller at least 30 days before adding or replacing a sub-processor. If the Controller objects on reasonable grounds, Voxelo will use reasonable efforts to make an alternative arrangement or permit termination without penalty.
6. International Data Transfers
Primary data storage is in South Africa. Some sub-processors (e.g., Twilio, Deepgram, OpenAI) may process data outside South Africa. Voxelo enters into Data Processing Agreements with all such sub-processors that include appropriate safeguards equivalent to those required by POPIA, including standard contractual clauses where applicable.
7. Audit Rights
Enterprise customers may request, no more than once per 12-month period, a summary of Voxelo’s security audit results or, with 30 days’ notice and reasonable cost reimbursement, an on-site audit. Voxelo may satisfy audit requests by providing its most recent third-party audit reports under NDA.
8. Governing Law
This DPA is governed by the laws of the Republic of South Africa and POPIA. Disputes shall be resolved under the same jurisdiction as the Terms of Service.
9. Contact
DPA enquiries: legal@voxelo.co.za