Loading...
Last updated: June 18, 2026
Table of Contents
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ReVoice AI AB (org.nr 559505-0849), operating the ReVoice service ("The Data Processor"), and the Business Customer ("The Data Controller").
By accepting the Terms of Service for a paid Business plan, or by signing a separate business contract with ReVoice, this DPA is also executed.
For Enterprise customers requiring a manually signed DPA document, please contact privacy@re-voice.io to receive a PDF version.
The Processor shall process personal data only on the documented instructions of the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by Union or Member State law to which the Processor is subject; in that case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
This DPA, the Terms of Service, and the Controller's configuration and use of the Service together constitute the Controller's complete documented instructions for processing. The Processor does not process the personal data for its own purposes, and shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
To deliver the Service, the Processor engages carefully selected sub-processors for purposes including cloud storage, hosting, speech-to-text, AI processing, text-to-speech, meeting assistance, email delivery, and payment processing. The Processor shall remain fully liable to the Controller for the performance of its sub-processors.
Sub-processors process personal data solely to deliver their respective function and are bound by written agreements (including Standard Contractual Clauses where required) that prohibit them from retaining, logging, or using customer data to train their own models. A current and complete list of approved sub-processors is provided to the Controller on request. Any addition or change of sub-processor will be notified at least 30 days in advance, during which the Controller has the right to object.
The Processor undertakes to implement appropriate Technical and Organizational Measures (TOMs) to protect personal data:
All data at rest is encrypted using industry-standard AES-256. Data in transit is protected with modern TLS (1.2+).
Personnel engaged by the Processor to process data are bound by strict confidentiality agreements.
If the Processor becomes aware of a personal data breach affecting the Controller's data, the Processor shall notify the Controller without undue delay, and in any event no later than 48 hours after becoming aware of the breach.
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service export and deletion tools for this purpose. Where the Processor receives such a request directly, it shall promptly forward it to the Controller and shall not respond to it itself except on the Controller's documented instructions.
Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with the Controller's obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation with the supervisory authority.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits shall take place on reasonable prior notice, during normal business hours, no more than once in any twelve-month period (except where required by a supervisory authority or following a personal data breach), and subject to appropriate confidentiality undertakings. The Processor may discharge this obligation by providing its current security documentation together with any third-party audit reports or certifications it holds.
Upon termination of the Agreement, the Processor shall (at the choice of the Controller) delete or return all personal data. The Controller may export all data via the service's export function prior to closing the account. In accordance with our Data Retention Policy, audio and AI-data are deleted strictly after 30 days for free-use, or immediately upon account deletion by an Administrator.