Data Processing Agreement
This DPA sets out how Vomyra processes personal data on your behalf when you use the Service, including security, sub-processors, and transfer safeguards.
Last updated: July 11, 2026
1. Roles of the parties
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between you ("Customer") and Vomyra. For personal data processed through the Service on the Customer's behalf, the Customer is the controller and Vomyra is the processor. Where Vomyra determines the means and purposes of processing (for example, account administration), Vomyra acts as controller.
2. Scope and subject matter
Vomyra processes personal data to provide the AI voice agent Service — including placing and receiving calls, speech recognition, language-model reasoning, text-to-speech, recordings and transcripts, and any actions the Customer's agents are configured to take in connected systems.
The categories of data subjects and personal data are determined by the Customer through its configuration and use of the Service.
3. Processing instructions
Vomyra processes personal data only on the Customer's documented instructions, including as set out in the Terms, this DPA, and the Customer's use of the Service, unless required to do otherwise by law.
4. Sub-processors
The Customer authorizes Vomyra to engage sub-processors to provide the Service — such as cloud infrastructure, telephony carriers, speech and language-model providers, and analytics and payment providers. Vomyra imposes data-protection obligations on sub-processors consistent with this DPA and remains responsible for their performance.
Vomyra will make available a current list of sub-processors and provide a mechanism to notify the Customer of changes so the Customer may object on reasonable grounds.
5. Security measures
Vomyra maintains appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, per-account authentication, role-based access control, and audit logging. See the Security page for further detail.
6. Assistance and data-subject rights
Taking into account the nature of processing, Vomyra will provide reasonable assistance to help the Customer respond to data-subject requests and to meet its obligations regarding security, breach notification, and data-protection impact assessments.
7. Personal data breach
Vomyra will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably necessary for the Customer to meet its notification obligations.
8. International transfers
Where personal data is transferred across borders, Vomyra relies on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.
9. Return and deletion
Upon termination of the Service, Vomyra will, at the Customer's choice, delete or return the personal data processed on the Customer's behalf, except where retention is required by law.
10. Contact
For questions about this DPA or to request a countersigned copy, contact privacy@vomyra.com.