Data Processing Agreement
This DPA forms part of the Terms of Service between Daniel Brummitt, trading as VoipMemory ("Processor", "we") and the customer ("Controller", "you") wherever you act as a controller of personal data processed through the Service. It takes effect when you accept the Terms and lasts as long as we process personal data for you (including the §7 deletion window). It is the written processing contract required by Article 28(3) UK GDPR — "UK GDPR" below includes the EU GDPR where it applies to you. If this DPA conflicts with the Terms on data protection matters, this DPA wins.
1. Processing details
Subject matter, duration, nature, purpose, data types and data subjects are set out in Annex A.
2. Our obligations as processor
- Instructions only. We process personal data only on your documented instructions — which are: the Terms, this DPA, your configuration of the Service (providers connected, transcription mode, emails you file, assistants you authorise) and your use of its interfaces — including for international transfers, unless UK or EU law requires otherwise, in which case we tell you first unless that law forbids it. We will tell you if, in our opinion, an instruction infringes data protection law. [Art 28(3)(a)]
- Confidentiality. Every person we authorise to process personal data (currently: the operator personally) is committed to confidentiality. [Art 28(3)(b)]
- Security. We implement and maintain the technical and organisational measures in Annex B (Art 32), reviewed as the Service evolves and never reduced below the protection described there. [Art 28(3)(c)]
- Sub-processors. You give general written authorisation for the sub-processors in Annex C. We'll give you at least 14 days' notice (email or in-app) before adding or replacing one; if you object on reasonable data-protection grounds and we can't offer a workaround, you may terminate the affected service and §7 applies. We bind every sub-processor to obligations no less protective than this DPA and remain fully liable to you for their performance. [Art 28(2), 28(3)(d), 28(4)]
- Data subject rights. Taking into account the nature of the processing, we assist you in responding to data subjects exercising their rights — first through the Service's own search, export and deletion features, and beyond that with reasonable direct assistance. If a data subject contacts us directly about your vault, we refer them to you. [Art 28(3)(e)]
- Assistance. We assist you, so far as reasonably possible given the information available to us, with your Art 32–36 obligations: security, breach notification, data protection impact assessments and prior consultation. [Art 28(3)(f)]
- Personal data breach. We notify you without undue delay after becoming aware of a personal data breach affecting your personal data, with the information Art 33(3) requires so far as available, supplemented as we learn more.
- Audit. On request (max once per 12 months, 30 days' notice, your cost) we make available the information reasonably necessary to demonstrate compliance with Art 28 — documentation, security descriptions and written answers first; an audit or inspection where that genuinely isn't enough, scoped to protect other customers' data and the Service's security. [Art 28(3)(h)]
3. Your obligations as controller
- You are responsible for the lawfulness of the processing you instruct: a lawful basis for the personal data in your vault, all recording-consent and notice obligations for your calls (Terms §4), and the accuracy of what you submit. You will not instruct us to process special category data except as it may be incidentally contained in your communications.
4. International transfers
Processing and storage happen in the UK/EEA (Annex C). Transfers to US sub-processors for hosted transcription and email-untangling are made under the EU Standard Contractual Clauses and UK Addendum incorporated in each sub-processor's data-processing terms, as Annex C records.
5. Liability
Liability under this DPA is subject to the exclusions and cap in Terms §12; nothing here enlarges them, and nothing in the Terms limits a data subject's own statutory rights.
6. Term
This DPA applies for as long as we process personal data on your behalf.
7. Deletion and return
At the end of the services — cancellation, blocking, or termination — the Service gives you a 90-day read-only window to export your data, with reminders, after which we permanently delete the vault, unless UK or EU law requires us to keep something (in which case we keep only that, only for as long as required). [Art 28(3)(g)]
Annex A — Processing details
| Subject matter | Provision of the VoipMemory relationship-memory service: ingesting the Controller's call recordings and filed emails, transcription, organisation into per-contact timelines, and serving that content back to the Controller and to AI assistants the Controller authorises. |
|---|---|
| Duration | The term of the Terms of Service plus the §7 deletion window. |
| Nature and purpose | Collection (from the Controller's phone system and forwarded email), transcription (audio processed transiently in memory, never stored), storage of transcripts and emails, structuring, retrieval, disclosure at the Controller's direction, deletion. |
| Categories of data subjects | The Controller and its personnel; the Controller's call participants and email correspondents (customers, suppliers, contacts). |
| Categories of personal data | Names, phone numbers, email addresses; call metadata (time, duration, direction); call transcripts with speaker labels; email content and headers; notes and tasks the Controller records. Communications may incidentally contain any category of personal data the participants chose to discuss, which the Controller is responsible for minimising. |
| Special category data | Not sought by the Service; processed only as incidentally contained in the Controller's communications. |
Annex B — Technical and organisational measures
- All traffic over TLS; the service makes no unencrypted external connections.
- Call audio is processed transiently in memory and is never written to disk or object storage.
- Stored credentials (phone-system tokens, customer-supplied API keys) are encrypted at rest with libsodium (XSalsa20-Poly1305); the encryption key lives outside the database and web root.
- Session and API tokens are stored as digests only; OAuth uses PKCE with rotating refresh-token families where reuse revokes the whole family.
- Strict per-tenant isolation: every query is keyed to the account; the MCP endpoint authenticates per customer and can only reach that customer's vault.
- Administrative interface is password-protected, IP-restricted and metadata-only by design (it cannot render vault content).
- Secrets are scrubbed from logs at write time. Passwords are stored as bcrypt hashes and checked against known-breach lists via k-anonymity at creation.
- Payment card data is never received; payments are processed by Stripe.
- Deletion: automated purge 90 days after account end, with warning notices; per-item deletion available in-app.
Annex C — Authorised sub-processors
| Sub-processor | What they do | Where | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting — every part of the service runs here | eu-west-1 (Dublin, Ireland) | Data stays in the EEA/UK; AWS Data Processing Addendum |
| AssemblyAI, Inc. | Speech-to-text with speaker labels (hosted transcription, primary) | USA | EU SCCs + UK Addendum via their data-processing terms |
| Deepgram, Inc. | Speech-to-text with speaker labels (hosted transcription, automatic failover) | USA | EU SCCs + UK Addendum via their data-processing terms |
| OpenRouter, Inc. | LLM gateway used to untangle forwarded email threads (text snippets); emergency no-speaker-labels transcription, off by default | USA | EU SCCs + UK Addendum via their data-processing terms |
Hosted transcription only. If you bring your own transcription key, use your own Pocket subscription, or run the local-Mac agent, that vendor (or your machine) is engaged by you under your own terms and is not our sub-processor. The same is true of any AI assistant you connect (§ "Your AI assistant" of the Privacy Policy).
The live version of this list is always at /dpa; changes are notified under §2.4.
Questions about any of these documents: hello@voipmemory.com.