Last updated 29 August 2026 · version 1.0

Data Processing Agreement

The processor terms between VoiceSync and the business, covering caller data.

Roles

You, the business, are the Data Fiduciary under India's Digital Personal Data Protection Act 2023 and the Controller under the GDPR, in respect of the people who call you. VoiceSync is the Data Processor. We process caller data only on your documented instructions, which are given by configuring the service and by using it.

This matters practically: the duty to tell your callers what happens on the call is yours, because you are the one they have a relationship with. We give you the wording.

Subject matter and scope

Subject matter: answering inbound telephone calls to your business and recording their outcome.

Duration: for as long as your account is open, plus the retention period you configure.

Categories of data subject: people who telephone your business.

Categories of personal data: telephone number, name where given, the content of what was said on the call as text, and any booking, order or enquiry arising from it.

Your obligations

  • Publish a notice telling your customers that calls may be answered by an automated assistant and that calls are transcribed. Put it where they will actually see it: your website, your Google listing, on hold, or on the door.
  • Have a lawful basis for the caller data you ask us to process.
  • Do not configure the agent to collect special-category data. If your business inherently involves health, financial or other sensitive information, tell us before you go live — it changes what we both have to do.
  • Do not use the service for outbound marketing.
  • Pass on any request from a caller to exercise their rights, so we can help you meet the deadline.

Our obligations

  • Process caller data only on your instructions, and not for our own purposes.
  • Keep it confidential and restrict access to people who need it.
  • Apply the security measures described on the Security page.
  • Assist you with data subject requests, impact assessments and regulator queries, so far as we reasonably can.
  • Tell you without undue delay if we become aware of a personal data breach affecting your callers.
  • Delete or return caller data when your account closes, at your choice.
  • Not engage a new sub-processor without updating the published list and giving you the chance to object.

Sub-processors and transfers

You authorise the sub-processors listed on the Sub-processors page. Some operate outside India and the EEA, and caller audio is processed by an AI provider that may be outside your country. That is inherent to the service; if it is unacceptable to you, this is the point to say so rather than after go-live.

Audit

We will answer reasonable written questions about our processing and provide what documentation we have. For a formal on-site audit, give us reasonable notice and expect to bear the cost.

Who we are

Operator
[legal entity — to be completed]
Registered address
[address — to be completed]
Registration no.
[registration number — to be completed]
Data region
[data region — to be completed]
Privacy contact
privacy@voicesync.in
Grievance Officer (India)
[Grievance Officer — to be completed]