VoxHive Data Processing Agreement
Last updated: 1 August 2026
This Data Processing Agreement ("DPA") forms part of the VoxHive Terms of Service and is incorporated into them by reference. It sets out the terms required by Article 28 of the UK GDPR where we process personal data on your behalf.
You do not need to sign this document. It applies automatically to every customer. If your organisation requires a signed copy on your own paper, email contact@voxhive.uk.
1. Parties and roles
1.1 This DPA is between:
You, the customer identified in your account (the "Controller"); and
Veto Swarm Intelligence Ltd, trading as VoxHive, a company registered in England and Wales under company number 17002319, whose registered office is at Apartment 18 Amber Court, Birmingham, B15 2NY (the "Processor", "we", "us").
1.2 You are the Controller of personal data processed through the Service. We are your Processor. You determine the purposes and means of processing; we act on your documented instructions.
1.3 Where you are yourself a processor acting for another controller, you warrant that you have authority to appoint us as a subprocessor, and this DPA applies as though references to Controller were to that other controller.
2. Definitions
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other data protection law applicable to the processing.
"Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data" and "Supervisory Authority" have the meanings given in the UK GDPR.
"Customer Personal Data" means Personal Data processed by us on your behalf through the Service.
"Subprocessor" means any third party engaged by us to process Customer Personal Data.
"Standard Contractual Clauses" means the clauses approved by the European Commission on 4 June 2021, as supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner.
3. Scope and subject matter of processing
3.1 Subject matter. Provision of the VoxHive platform, being AI agents that handle voice calls, emails, text messages and web chat on your behalf.
3.2 Duration. For the term of your subscription, plus the retention periods in clause 11.
3.3 Nature and purpose of processing. Collection, recording, organisation, storage, retrieval, transcription, analysis, transmission, and erasure, for the purpose of:
- (a)receiving and handling communications from your customers and enquirers;
- (b)generating agent responses from material you supply;
- (c)recording and transcribing voice calls;
- (d)creating and managing appointments;
- (e)verifying the identity of callers where you configure that function;
- (f)maintaining records of interactions for your review; and
- (g)providing you with analytics about your own use of the Service.
3.4 Types of Personal Data. Depending on your configuration and what your Data Subjects disclose:
- Names
- Telephone numbers
- Email addresses
- Postal addresses
- Account, order and reference numbers
- Voice recordings
- Transcripts of spoken conversations
- Message and email content
- Appointment details
- Authentication credentials in hashed form, where you use PIN verification
- Any other Personal Data contained in communications or in material you upload
3.5 Categories of Data Subject.
- Your customers and prospective customers
- Enquirers and callers
- Your employees and workspace users
- Any other individual whose Personal Data appears in a communication or in your uploaded material
3.6 Special Category Data. The Service is not designed to process Special Category Data and we do not require it. If your use involves such data, you must tell us before processing begins, satisfy yourself that you have a valid Article 9 condition, and accept that additional safeguards may be required. Nothing in this DPA constitutes agreement by us to process Special Category Data.
4. Your obligations as Controller
4.1 You warrant that:
- (a)you have a valid lawful basis under Article 6 of the UK GDPR for all processing you instruct;
- (b)you have provided all privacy information required by Articles 13 and 14 to your Data Subjects;
- (c)where you rely on consent, you have obtained it validly and can demonstrate it;
- (d)your instructions to us comply with Applicable Data Protection Law; and
- (e)you have informed Data Subjects that calls may be recorded, and obtained any consent required in the jurisdictions in which you operate.
4.2 You are responsible for the accuracy, quality and lawfulness of Customer Personal Data and of the material you upload to Knowledge Bases.
4.3 You must not upload to a Knowledge Base any Personal Data that is not necessary for an agent to answer questions, and in particular must not upload customer databases, staff records or Special Category Data.
5. Our obligations as Processor
5.1 Processing on instructions. We will process Customer Personal Data only on your documented instructions, including regarding international transfers, unless required otherwise by law. Where law requires other processing, we will inform you before processing unless that law prohibits it on important grounds of public interest.
5.2 Your instructions. Your instructions consist of this DPA, the Terms of Service, and the configuration you set within the Service. Any additional instruction must be agreed in writing and may attract a reasonable charge.
5.3 Unlawful instructions. If we consider an instruction infringes Applicable Data Protection Law, we will inform you promptly. We may suspend performance of that instruction until it is amended or confirmed.
5.4 Confidentiality. We ensure that every person authorised to process Customer Personal Data is subject to a binding obligation of confidentiality that survives the end of their engagement.
5.5 Access limitation. Access to Customer Personal Data is restricted to personnel who need it to provide the Service, to fulfil this DPA, or to comply with law.
5.6 No independent use. We will not use Customer Personal Data for our own purposes. In particular, and without limitation, we will not use it to train, fine-tune or otherwise develop any artificial intelligence or machine learning model, and we contract with our AI Subprocessors on terms that prohibit them from doing so.
5.7 Anonymised data. We may create and use anonymised, aggregated data derived from use of the Service, provided it cannot be used to identify you, any Data Subject, or any Customer Personal Data, and is not reversible.
6. Security
6.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, costs of implementation, and the nature, scope, context and purposes of processing.
6.2 Those measures include, as at the date of this DPA:
Access control
- Tenant isolation enforced at the database level by row-level security policies, so that data belonging to one customer is not accessible to another regardless of application behaviour
- Role-based access control within each customer workspace
- Passwords and PINs stored only as salted cryptographic hashes
- Multi-factor authentication available on administrative accounts
- Internal access granted on a least-privilege basis and reviewed periodically
Encryption
- TLS 1.2 or above for all data in transit
- Encryption at rest for all stored data, including recordings and transcripts
- Signed webhooks with cryptographic verification for all inbound integrations
Resilience and recovery
- Automated daily backups with point-in-time recovery
- Infrastructure hosted in a United Kingdom region
- Monitoring and alerting on availability and error rates
Operational
- Logging of access and administrative actions
- Segregation of production and development environments
- Documented incident response procedure
- Review of Subprocessor security practices before engagement
6.3 We may update these measures provided the level of security is not materially reduced.
6.4 You are responsible for security within your control, including the strength and confidentiality of account credentials, the users you grant access to, and the material you upload.
7. Subprocessors
7.1 General authorisation. You give general written authorisation for us to engage Subprocessors, subject to this clause.
7.2 Current Subprocessors. As at the date of this DPA:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, storage, authentication, serverless functions | United Kingdom (London) |
| Telnyx | Telephony, SMS and WhatsApp delivery | United States, with UK interconnect |
| Vapi | Voice call orchestration | United States |
| OpenAI | Language model inference and text embeddings | United States |
| Anthropic | Language model inference, where selected by you | United States |
| Language model inference, where selected by you | United States, European Union | |
| Deepgram | Speech recognition | United States |
| Cartesia | Speech synthesis | United States |
| ElevenLabs | Speech synthesis, where selected by you | United States |
| Resend | Transactional email delivery | European Union |
Some Subprocessors are engaged only where you select them in your agent configuration. Where you select no such provider, we do not transmit Customer Personal Data to them.
7.3 Obligations on Subprocessors. We impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA.
7.4 Our liability. We remain fully liable to you for the performance of each Subprocessor's obligations.
7.5 Changes. We will give you at least 30 days' written notice before adding or replacing a Subprocessor. Notice will be given by email to your account address and by updating this DPA.
7.6 Objection. You may object to a new Subprocessor on reasonable data protection grounds by written notice within 30 days. We will use reasonable efforts to make the Service available without that Subprocessor or to offer an alternative. If we cannot do so within a reasonable period, you may terminate the affected part of the Service without penalty and receive a pro rata refund of prepaid fees.
8. International transfers
8.1 Customer Personal Data is stored in the United Kingdom.
8.2 Certain Subprocessors process Customer Personal Data outside the UK, as set out in clause 7.2. Such transfers are made only where one of the following applies:
- (a)adequacy regulations made under section 17A of the Data Protection Act 2018 cover the destination;
- (b)the transfer is made under the Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, or under the UK International Data Transfer Agreement; or
- (c)the recipient is certified under the UK Extension to the EU-US Data Privacy Framework.
8.3 We have carried out transfer risk assessments for transfers made under (b) above, and will provide a copy on written request.
8.4 Where a safeguard we rely on is invalidated, we will notify you promptly and work with you in good faith to implement an alternative. If none can be implemented within a reasonable period, either party may terminate the affected processing.
9. Data subject rights
9.1 We will, taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data Subject rights under Chapter III of the UK GDPR.
9.2 The Service provides functionality enabling you to access, correct, export and delete Customer Personal Data directly. In most cases this will be sufficient to respond to a request without our involvement.
9.3 If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond substantively, but will promptly forward the request to you and direct the Data Subject to you.
9.4 Where you require assistance beyond the functionality provided in the Service, we will provide reasonable assistance. We may charge a reasonable fee for assistance that is disproportionate or that arises from your failure to configure the Service appropriately.
10. Personal data breach
10.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
10.2 Our notification will describe, to the extent known:
- (a)the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- (b)the likely consequences;
- (c)the measures taken or proposed to address it and mitigate its effects; and
- (d)a point of contact for further information.
10.3 Where all information is not available immediately, we will provide it in phases without undue further delay.
10.4 We will assist you in meeting your obligations under Articles 33 and 34 of the UK GDPR, including in notifying the Supervisory Authority and affected Data Subjects.
10.5 We will not notify any Supervisory Authority or Data Subject of a breach affecting Customer Personal Data on your behalf unless you instruct us to, or unless we are independently required to do so by law.
10.6 Notification of a breach is not an acknowledgement of fault or liability.
11. Deletion and return
11.1 On termination or expiry of your subscription, Customer Personal Data will remain available for export through the Service for 30 days.
11.2 After that period, we will delete Customer Personal Data within a further 60 days, save as set out in clause 11.3.
11.3 We may retain Customer Personal Data where required by law, and in that case will retain it only for as long as required and will continue to protect it under this DPA. This includes:
- (a)billing and transaction records, retained for 7 years under the Companies Act 2006 and HMRC requirements; and
- (b)records of messaging consent, retained for 4 years where required by network operator compliance obligations.
11.4 Backups containing Customer Personal Data are overwritten on a rolling cycle and fully purged within 90 days of deletion.
11.5 On written request made within the 30 day period in clause 11.1, we will provide Customer Personal Data in a structured, commonly used, machine-readable format.
11.6 We will certify deletion in writing on request.
12. Audit and information
12.1 We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.
12.2 You may audit our compliance with this DPA, subject to the following:
- (a)audits may be conducted no more than once in any 12 month period, unless required by a Supervisory Authority or following a Personal Data Breach;
- (b)you must give at least 30 days' written notice;
- (c)audits must be conducted during UK business hours, must not unreasonably disrupt our operations, and must not involve access to any data belonging to another customer;
- (d)any auditor you appoint must not be a competitor of ours and must be bound by confidentiality; and
- (e)you bear the cost of the audit, unless it reveals material non-compliance, in which case we bear the reasonable cost.
12.3 We may satisfy an audit request by providing relevant third party certifications, security documentation, or responses to a reasonable security questionnaire, where these adequately address the scope of your request.
13. Data protection impact assessments
13.1 We will provide reasonable assistance with any data protection impact assessment you carry out, and with any prior consultation with a Supervisory Authority, where required under Articles 35 and 36 of the UK GDPR and where the assessment relates to processing carried out by us on your behalf.
13.2 Such assistance will take account of the nature of the processing and the information available to us.
14. Liability
14.1 The limitations and exclusions of liability in the Terms of Service apply to this DPA, save that nothing limits either party's liability to a Data Subject or Supervisory Authority under Applicable Data Protection Law.
14.2 Each party's liability under this DPA forms part of, and does not increase, the aggregate cap set out in the Terms of Service.
15. General
15.1 Precedence. In the event of conflict between this DPA and the Terms of Service in relation to the processing of Personal Data, this DPA prevails.
15.2 Changes. We may amend this DPA where required by a change in Applicable Data Protection Law, by a Supervisory Authority, or to reflect a change in Subprocessors under clause 7.5. We will give at least 30 days' written notice of any material change.
15.3 Governing law. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
15.4 Severance. If any provision is held invalid or unenforceable, the remainder continues in force.
16. Contact
Data protection enquiries relating to this DPA:
Veto Swarm Intelligence Ltd, trading as VoxHive
Apartment 18 Amber Court
Birmingham
B15 2NY
United Kingdom
Company number: 17002319
ICO registration number: ZC189766
Email: contact@voxhive.uk
We have not appointed a Data Protection Officer, not being required to under Article 37 of the UK GDPR. Data protection matters are handled by the director at the address above.