# VoiceRun Enterprise Data Processing Addendum

Version 2026-10-01

This Data Processing Addendum (DPA) forms part of the VoiceRun Enterprise Services Agreement when incorporated into a mutually executed Order Form. It applies to VoiceRun's processing of personal data on Customer's behalf in providing the purchased Services. It does not apply to self-service offerings solely because it is available online.

## 1 Scope and roles

**1.1 Definitions.** Applicable Data Protection Law means privacy and data-protection laws applicable to the processing under the Agreement, including applicable US state privacy laws, the EU General Data Protection Regulation (GDPR), UK GDPR and UK Data Protection Act, and Mexico's Federal Law on Protection of Personal Data Held by Private Parties and applicable implementing rules, in each case as amended or replaced. Personal Data means personal information within Customer Data processed on Customer's behalf. Processing, controller, processor and equivalent terms have their meanings under the applicable law. Subprocessor means a provider VoiceRun engages to process Personal Data on Customer's behalf.

**1.2 Roles.** Customer acts as controller or, where acting for another controller, as processor authorized to appoint VoiceRun. VoiceRun acts as processor or subprocessor as applicable. Customer determines the lawful purposes and means of its processing and supplies documented instructions. Each party will comply with obligations applicable to its role. Annex A describes the processing and is supplemented by the Order Form and Customer's permitted configuration.

**1.3 Account administration.** Each party may process business contact and billing information as an independent controller only to administer its contractual relationship, meet legal obligations and secure that relationship. This does not permit VoiceRun to reclassify interaction content, prompts, recordings, transcripts or Customer-specific artifacts as controller data for generalized training, advertising or product development. The Agreement's more protective data-use restrictions continue to apply.

## 2 Instructions and personnel

VoiceRun will process Personal Data only on Customer's documented instructions in the Agreement, Order Form, authorized configuration and reasonable written requests consistent with the purchased Services, unless law requires other processing. Where legally permitted, VoiceRun will inform Customer of a legal requirement before processing and identify an instruction it reasonably believes violates Applicable Data Protection Law. VoiceRun may pause the affected processing while the parties resolve that instruction.

Customer is responsible for the legal basis for its processing, required notices and consents, and its authority to provide the data and instructions. VoiceRun will limit personnel access to the need to perform authorized duties and ensure persons permitted access are bound by confidentiality obligations. VoiceRun will not sell Personal Data, use it for targeted advertising, or use it to train, fine-tune, evaluate or improve general, other-customer or third-party models or services without Customer's express written authorization. Customer-specific training must be within Customer's instructions and solely for Customer.

## 3 Security and incidents

VoiceRun will maintain appropriate technical and organizational measures under the [Security Terms](/legal/security/) and Annex B, taking account of the nature and risk of processing. The [VoiceRun Trust Center](https://trust.voicerun.com/) is the source for current security-control descriptions, certification status, available assurance materials and the subprocessor register. A posting does not reduce an incorporated contractual protection during a committed term.

VoiceRun will notify Customer without undue delay and in any event within 48 hours after confirming a material Security Incident affecting Customer Data. Security Incident means accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data in systems under VoiceRun's or its Subprocessors' control. If Applicable Data Protection Law requires earlier notice or notice of an incident below that materiality threshold, the legal requirement controls. VoiceRun will investigate suspected incidents promptly and will not postpone confirmation to delay notice. Unsuccessful attempts that do not compromise Customer Data are not Security Incidents.

Notice will go to Customer's designated security or privacy contact in the Order Form, or its account administrator if no separate contact is designated. VoiceRun will provide information reasonably available about the incident, affected data, likely consequences, containment and remediation, a contact for follow-up, and updates as information becomes available. Incomplete information will not delay initial notice. VoiceRun will take reasonable containment and remedial action, preserve relevant evidence and reasonably assist Customer with legally required notifications. Customer controls notifications to its data subjects and regulators unless law requires VoiceRun to act. Notice is not an admission of liability.

## 4 Subprocessors

**4.1 Authorization and disclosure.** Customer generally authorizes VoiceRun to engage the Subprocessors disclosed through the Trust Center for the purchased Services. VoiceRun will maintain information sufficient to identify each relevant entity, its processing function and processing locations, including providers used for automatic fallback. A technical provider integration is not a statement that it receives every customer's data. Customer may obtain the applicable register through the Trust Center or its designated VoiceRun contact.

**4.2 Obligations.** VoiceRun will complete a vendor risk review before connecting a Subprocessor's technology to the production environment, obtain required internal approval before onboarding, and bind each Subprocessor to written data-protection and confidentiality obligations no less protective in substance than those relevant to its processing, including the applicable no-training restrictions. VoiceRun remains responsible to Customer for its Subprocessors' performance of those obligations.

**4.3 Changes.** VoiceRun will give at least 30 days' advance written notice of an intended new or replacement Subprocessor with access to Personal Data, using the agreed notice channel or a Trust Center subscription maintained for that purpose. Customer may object within that period on reasonable, documented privacy or security grounds. VoiceRun will work in good faith to resolve the objection through a reasonable alternative or other appropriate safeguards before the new processing begins. Notice by a passive website edit alone does not satisfy this advance-notice obligation.

**4.4 Unresolved objection.** If no reasonable resolution is available, Customer may terminate only the affected Service on written notice before the new processing begins or on an agreed transition date. VoiceRun will refund prepaid fees for the unprovided affected Service and release the corresponding future commitment under the Enterprise Services Agreement. Unaffected Services remain in force. Where an urgent replacement is reasonably necessary to protect data or comply with law, VoiceRun will provide as much advance notice as practicable, notify Customer promptly, and preserve the objection and affected-service termination rights. An emergency does not waive due diligence or required transfer safeguards.

## 5 Assistance and individual rights

Taking account of the nature of processing and information available, VoiceRun will reasonably assist Customer with individual access, correction, deletion, portability and other privacy rights, and with impact assessments, transfer assessments and regulatory consultations. VoiceRun will promptly forward a request concerning Customer's Personal Data to Customer and will not substantively respond except on Customer's instructions or as legally required. Standard available self-service functions and reasonable assistance are included; substantial additional work requested by Customer may be charged only under an agreed Work Authorization. Assistance made necessary by VoiceRun's breach is not separately chargeable.

## 6 Return deletion and retention

**6.1 Ordinary retention and requests.** Stored recordings, transcripts and applicable interaction data have a default retention period of 365 days from creation unless Customer requests or configures a shorter period or the Order Form specifies another period. No obligation is created to retain ephemeral data that the Service does not ordinarily store. Customer may submit a deletion request to support@voicerun.com or the agreed support channel. VoiceRun will complete valid Customer-requested deletion within 30 days, subject only to Section 6.3.

**6.2 End of service and copies.** For 60 days after termination or expiration of the affected Services, Customer may retrieve then-existing Customer Data through available export functions or reasonable assistance. VoiceRun will delete remaining Customer Data at the end of that period, or earlier upon Customer's valid request, subject only to Section 6.3. Backup copies are included in these deletion obligations; backup schedules do not extend an applicable deletion deadline. Pending deletion, backup data remains protected and unavailable for ordinary processing. If restored for recovery before deletion is due, applicable restrictions and pending deletion instructions will be reapplied. VoiceRun will confirm completion of deletion on reasonable request. Retrieval does not include model weights or require continuing model inference.

**6.3 Limited retained records.** VoiceRun may retain only records it has a legal or documented business obligation to retain, such as necessary security audit logs, incident evidence, or records required to establish or defend legal claims, and only to the extent consistent with Customer's documented instructions, Applicable Data Protection Law and mandatory transfer provisions. Where a mandatory processor return-or-deletion obligation applies, Personal Data may be retained after that obligation takes effect only where the applicable law requires storage. An internal retention policy alone does not override that obligation. VoiceRun will minimize retained data, document the basis and period, restrict access and use to that purpose, maintain the Agreement's protections, and delete the records when the obligation ends. This exception does not authorize blanket retention of recordings, transcripts, prompts, Customer Models or other Customer-specific artifacts, or their reuse for generalized training, advertising or unrelated product development.

## 7 Assurance and audits

On written request and subject to confidentiality, VoiceRun will provide available independent assurance materials and information reasonably necessary to demonstrate compliance. Current report and certification availability is stated in the Trust Center. Customer will first use those materials and written questions; ordinary compliance questionnaires may be submitted once per calendar year.

Where legally required audit rights cannot reasonably be satisfied that way, an independent qualified auditor may examine the relevant processing under a mutually agreed plan, reasonable prior notice and normal business hours. Direct audits ordinarily occur no more than annually, are limited to relevant systems and Customer data, and must protect other customers, confidential information and security. Customer pays its auditor and VoiceRun's reasonable assistance at agreed rates. These limits and charges do not restrict a regulator, mandatory transfer-clause rights, or an additional audit required by law, a material incident or substantiated noncompliance; assistance required to remedy VoiceRun's breach is not separately chargeable. Audit rights do not authorize penetration testing without separate written permission.

## 8 US state privacy provisions

Where VoiceRun processes personal information as a service provider or contractor under the California Consumer Privacy Act as amended, or as a processor under another applicable US state privacy law, the parties agree that the processing is for the specified business purposes in Annex A and the Order Form. VoiceRun will not sell or share Personal Data as those laws define those terms; retain, use or disclose it outside those purposes or the direct business relationship; or combine it with personal information from other sources except as the applicable law permits for those purposes. VoiceRun will provide the same level of privacy protection required by applicable law and will notify Customer if it determines it can no longer do so. Customer may take reasonable and appropriate steps to verify compliant use and to stop and remediate unauthorized processing. VoiceRun certifies that it understands and will comply with these restrictions.

## 9 Mexico provisions

For Personal Data subject to Mexican law, Customer is the responsable or an authorized encargado, and VoiceRun is the encargado or sub-encargado acting on Customer's documented instructions, as applicable. VoiceRun will process only for the instructed purposes, maintain confidentiality and appropriate safeguards, avoid unauthorized onward disclosure or independent use, and return or delete the data as required by this DPA and applicable law. Customer is responsible for its privacy notice, required consents and disclosures and lawful instructions, including any required basis for handling sensitive personal data. VoiceRun will reasonably assist with applicable access, rectification, cancellation and opposition requests and incident obligations. Processing in the United States or another agreed location must comply with applicable requirements for the relevant remisión or transfer; neither the hosting location nor this DPA dispenses with those requirements. No Mexico-only residency promise is created unless the Order Form expressly states it.

## 10 International transfers

**10.1 Safeguards.** VoiceRun will process data in the locations disclosed for the purchased Services and subject to the agreed hosting commitments. The parties will implement the transfer mechanism and supplementary measures legally required for a restricted transfer. A regional hosting request does not alone restrict support access or provider processing to that region. No certification under an adequacy framework is asserted by this DPA.

**10.2 EEA transfers.** Where required for a transfer subject to the GDPR from Customer to VoiceRun in a country without an applicable adequacy decision, the [European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng) (SCCs) are incorporated in full by reference. Module Two applies when Customer is a controller and VoiceRun a processor; Module Three applies when Customer is a processor and VoiceRun a subprocessor. Only the applicable module applies to each transfer. The clauses are completed as follows: Clause 7's optional docking clause applies; Clause 9(a) uses Option 2, general written authorization, with 30 days' advance notice; the optional language in Clause 11 does not apply; Clause 17 uses Irish law; and Clause 18 identifies the courts of Ireland. Annexes I and II are completed by Annexes A and B below and the applicable Order Form. Annex I(C)'s competent authority is determined under Clause 13 based on Customer's establishment, representative or relevant data subjects. Annex III is not required under the selected general-authorization option; the current subprocessor information is maintained in the Trust Center.

**10.3 UK transfers.** Where required for a restricted transfer subject to UK data-protection law, the [ICO International Data Transfer Addendum to the EU SCCs, version B1.0 in force 21 March 2022](https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf) (UK Addendum), including its mandatory clauses as revised under its own terms, is incorporated. Table 1 uses the parties, contacts, effective date and signatures in the Order Form and Annex A. Table 2 uses the SCCs and module selections in Section 10.2. Table 3 uses Annexes A and B and the applicable Order Form. For Table 4, neither party may end the UK Addendum solely through the optional termination selection in Section 19; mandatory termination rights remain. The UK Addendum makes the required UK-law and jurisdiction substitutions.

**10.4 Effect and conflict.** Execution of an Order Form incorporating this DPA constitutes execution of the applicable SCCs and UK Addendum. The parties will complete transaction-specific annex details before a restricted transfer and cooperate with required transfer assessments and supplementary safeguards. If a mechanism becomes invalid or insufficient, the parties will implement a lawful replacement or suspend the affected transfer until permitted. Mandatory transfer provisions prevail over conflicting Agreement terms, including limits on audit, notice, governing law or liability. No term modifies third-party-beneficiary rights granted by those provisions.

## 11 General

The DPA continues for as long as VoiceRun or its Subprocessors retain Personal Data subject to it. The Agreement's liability provisions apply between the parties to the extent consistent with mandatory law and transfer instruments. Updates follow the Enterprise Services Agreement's version protections. The parties' security and privacy contacts are those designated in the Order Form or updated by written notice.

## Annex A Description of processing

**Parties and roles.** The exporter is the Customer legal entity, address and contact identified in the executed Order Form, acting as controller or processor as stated there. The importer is VoiceRun, Inc., One Kendall Square, Suite 2102, Cambridge, MA 02139, acting as processor or subprocessor. Its designated privacy contact is the contact identified in the Order Form. Signature and date are the signatures and effective date of the Order Form. The relevant activity is provision and use of the purchased enterprise Services.

**Individuals.** Customer's customers, prospective customers, callers, end users, employees, contractors and other individuals whose information Customer submits or causes to be processed within the purchased scope. The Order Form narrows these categories where appropriate.

**Data.** Contact and account identifiers; audio and voice recordings; transcripts; prompts and interaction content; Customer-provided business records; routing, session and technical metadata; and Customer-specific outputs, annotations, evaluation results and training materials, to the extent present in the purchased Services. Payment credentials, identity documents and other additional categories are included only if actually instructed within the agreed scope and lawfully supported.

**Sensitive data.** Interaction content may contain sensitive data, such as health information, where Customer lawfully instructs that processing. The Order Form records known sensitive categories and any additional safeguards needed for the use case. Access is limited by role and purpose, processing is limited to instructions, onward access is restricted, and the confidentiality, security and retention measures in this DPA apply. This description does not assert that VoiceRun is certified for a particular regulatory regime or replace a separately required agreement. PHI subject to HIPAA may be made available to VoiceRun only under an executed BAA and the eligible Services and configuration expressly agreed under the Enterprise Services Agreement. Merely identifying health information in this Annex or an Order Form does not authorize PHI processing.

**Nature and purpose.** Collection, receipt, transmission, routing, hosting, storage, transcription, analysis, evaluation, simulation, retrieval and deletion necessary to provide and support the purchased Services; Customer-specific training only if ordered and instructed. No generalized training purpose is included.

**Frequency and duration.** Transfers are continuous or intermittent as Customer uses the Services. Processing continues for the Order Form term and the limited retrieval and permitted retention periods in Section 6. Subprocessor processing is limited to the applicable disclosed function for the same authorized purpose and duration.

## Annex B Technical and organizational measures

VoiceRun will maintain measures appropriate to the risks of the purchased processing, including authorization and access management, personnel confidentiality, protection of data in transit and at rest where applicable to systems under VoiceRun's control, logging and monitoring, vulnerability management, incident response, provider diligence, and secure deletion. VoiceRun will maintain business continuity, disaster recovery and backup practices without a fixed recovery-time or recovery-point commitment unless expressly agreed in the Order Form.

The Security Terms and applicable security-control descriptions made available in the Trust Center are incorporated into this Annex. Before a restricted transfer, the parties will identify and retain the applicable security description with the Order Form, including any deployment-specific protections. Customer-specific provider, integration or residency restrictions and additional safeguards are recorded there. Neither publication of this Annex nor a Trust Center link represents that every advertised control applies to every deployment; VoiceRun must identify the measures actually applicable to the purchased processing and may not materially reduce agreed protections during a committed term.
