FastLajna
cs en Log in

Documents

  • Terms & Conditions
  • DPA
  • Price List
  • Privacy
  • Cookies
Terms & Documents →

Contents

  • 1. Definitions
  • 2. Subject Matter of Processing
  • 3. Controller's Instructions
  • 4. Processor's Obligations under Art. 28(3) GDPR
  • 5. Confidentiality
  • 6. Security of Processing (Art. 32 GDPR) — Technical and Organisational Measures
  • 7. Sub-processors
  • 8. International Transfers
  • 9. Data Subjects' Rights — Processor's Cooperation
  • 10. Notification of Personal Data Breach
  • 11. DPIA and Prior Consultation — Cooperation
  • 12. Audit
  • 13. Erasure or Return of Data after Termination
  • 14. Liability and Sanctions
  • 15. Final Provisions
  • Annex No. 1 (DPA) — List of Sub-processors
  • Annex No. 2 (DPA) — Technical and Organisational Measures (TOM)
  • Annex No. 3 (DPA) — Description of Processing under Art. 28(3) GDPR

DPA

Effective from July 20, 2026 · version v1

Informative translation. The binding version is the Czech text; in case of any discrepancy, the Czech version prevails.

Data Processing Agreement (DPA)

concluded pursuant to Art. 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) between:

the Controller: the Client, i.e. the entrepreneur which has set up a customer account in the Provider's application, whose identification data are kept in that customer account (Art. 2.5 of the GTC), and which has accepted the GTC and this DPA in accordance with Art. 2.9 and Art. 2.10 of the GTC (hereinafter the "Controller")

and

the Processor: Fastlajna s.r.o., with its registered office at Školská 1736/12, Nové Město, 110 00 Praha 1, Company ID (IČO) 29543908, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 448213 (hereinafter the "Processor")

(the Controller and the Processor together hereinafter the "Parties").

This Data Processing Agreement (hereinafter the "DPA") forms an integral part of the General Terms and Conditions (hereinafter the "GTC") and of the overall contractual documentation between the Parties.

Version effective as of 20 July 2026.

1. Definitions

For the purposes of this DPA, the terms defined in Art. 4 GDPR are used (in particular controller, processor, personal data, processing, data subject, sub-processor, supervisory authority, personal data breach).

The terms "Service," "Provider," "Client," "Subcontractor," "User," "Baseline AI Assistant Configuration," "AI Act," "GDPR," and "ZEK" have the meaning given to them in the GTC.

The term "Sub-processor" corresponds to the term "another processor" under Art. 28(2) and (4) GDPR; in this DPA it is used interchangeably with the term "Subcontractor" as introduced in the GTC.

2. Subject Matter of Processing

2.1 Nature, Purpose, and Subject Matter of Processing

The Processor processes the personal data of Users in the course of providing the Service, i.e., the AI voice assistant providing for the receipt of incoming telephone calls, automated speech synthesis and recognition, dialogue orchestration with a language model, retrieval of answers from the Controller's knowledge base, and booking in its calendar, for the duration of the Agreement.

2.2 Duration of Processing

For the duration of the Agreement and thereafter for the period necessary to fulfil Art. 13 of this DPA (return or erasure of personal data).

2.3 Categories of Data Subjects

a. Users — natural persons calling the telephone number made available to the Controller as part of the Service (in particular consumers — the Controller's customers);

b. the Controller's contact persons — employees, statutory body, contact persons of the Controller (operational administration, invoicing).

2.4 Categories of Personal Data

The Processor processes the following categories of Users' personal data:

a. identification data — first name, surname (given by the User during the call), the caller's telephone number, e-mail address (given by the User);

b. content of communication — the audio recording of the call, the transcript of the call (incl. structured JSON with Users' personal data), structured response configuration;

c. traffic and location data — date and time of the call, duration, call identifier (Twilio call SID, VAPI call ID), the caller's country, technical metadata (operator, codec);

d. booking data — date, time, place, name of the person making the booking (passed to the Controller's calendar via the Google Calendar API);

e. logs and audit — records of events in the Processor's system (authentication logs, OAuth tokens in encrypted form).

The processing of special categories of personal data under Art. 9 GDPR is excluded in accordance with the prohibited uses under Art. 4 of the GTC and in accordance with the Subcontractors' prohibitions (OpenAI DPA Schedule 1.5, ElevenLabs ElevenAgents Terms § 2.E). If a User spontaneously discloses such data during a call, neither the Processor nor the Sub-processors process it separately beyond the ordinary content of the call.

2.5 Purposes of Processing

The purpose of the processing is exclusively the provision of the Service to the Controller to the extent agreed in the Agreement and the GTC, in particular:

a. ensuring telecommunications connectivity of the incoming call;

b. automatic speech recognition (Speech-to-Text);

c. dialogue orchestration with a language model (LLM);

d. speech synthesis (Text-to-Speech) for responses to the User;

e. recording the call for the Controller's purposes in accordance with § 89 ZEK;

f. booking in the Controller's calendar;

g. retrieval of answers from the Controller's knowledge base;

h. compliance with the legal obligations of the Processor and the Sub-processors (in particular obligations under the ZEK).

3. Controller's Instructions

3.1 The Processor processes personal data exclusively on the basis of the Controller's documented instructions. The Controller's instructions are given by this DPA, the GTC, and the specific configuration of the Service in the Processor's management interface (dashboard).

3.2 Extraordinary instructions beyond the scope of the agreed configuration of the Service must be given in writing (by e-mail from the Controller's registered contact address).

3.3 The Processor will inform the Controller without undue delay if, in its opinion, a given instruction infringes the GDPR or other data protection legislation. The Processor is not obliged to carry out such an instruction.

3.4 The Processor processes Users' personal data falling within the scope of abuse prevention operated by Sub-processors (in particular OpenAI) under the Sub-processors' own instructions, not on the Controller's instruction. This part of the processing takes place within the independent controller role of the relevant Sub-processor; this fact is accepted by the Controller as the conscious acceptance of a specific risk (Art. 3.6(b) of the GTC; express confirmation under Art. 2.10 GTC).

4. Processor's Obligations under Art. 28(3) GDPR

The Processor undertakes:

4.1 (a) to process personal data only on the Controller's instructions (Art. 3);

4.2 (b) to ensure that persons authorised to process personal data are bound by confidentiality or are subject to a statutory duty of confidentiality (see Art. 5);

4.3 (c) to take all measures required by Art. 32 GDPR (see Art. 6);

4.4 (d) to comply with the conditions for engaging further processors under Art. 28(2) and (4) GDPR (see Art. 7);

4.5 (e) taking into account the nature of the processing, to assist the Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to requests from data subjects (see Art. 9);

4.6 (f) to assist the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (in particular data protection impact assessments, prior consultation with the supervisory authority) — see Art. 11;

4.7 (g) in accordance with the Controller's decision, to delete or return all personal data to the Controller after the end of the provision of the Service, and to delete existing copies, unless European Union or Member State law requires otherwise (see Art. 13);

4.8 (h) to provide the Controller with all information necessary to demonstrate compliance with its obligations and to allow for audits (see Art. 12).

5. Confidentiality

5.1 The Processor undertakes that the persons who process Users' personal data on its behalf are bound by a contractual duty of confidentiality that survives the termination of their employment or similar relationship.

5.2 The Processor will similarly bind all Sub-processors to confidentiality and will require the Sub-processors to extend this obligation to their employees and suppliers.

5.3 The specific confidentiality obligation of the hosting Subcontractor (Forpsi — INTERNET CZ, a.s.) is set out in Art. XVIII.1 of its general terms and conditions; the Processor has not required Forpsi to provide extended contractual confidentiality beyond the clause referred to, and the Controller acknowledges this fact.

6. Security of Processing (Art. 32 GDPR) — Technical and Organisational Measures

6.1 General Principle

The Processor takes appropriate technical and organisational measures corresponding to the risks associated with the processing of Users' personal data, the state of the art, and the costs of implementation, always having regard to the nature, scope, and purposes of processing (Art. 32(1) GDPR).

6.2 Measures Implemented at the Processor's Level

a. Encryption in transit: TLS 1.3+ by default for all communication between components of the Service (client ↔ Twilio, Twilio ↔ VAPI, VAPI ↔ OpenAI/ElevenLabs/Google, the receiving interface ↔ the VPS); TLS 1.2 as a fallback protocol exclusively for legacy clients where TLS 1.3 is not available; TLS 1.3+ for access to the Processor's console and API.

b. Encryption at rest at the operating-system level: LUKS (block-level encryption) on the Forpsi VPS disk.

c. Encryption of Google Calendar OAuth tokens: application-level encryption using the Fernet algorithm (AES-128-CBC + HMAC-SHA256) for the access_token_enc and refresh_token_enc fields; the key is stored in the application environment.

d. SSH authentication: key-based only (no password), a non-standard port (2242), the fail2ban tool against brute-force attacks.

e. Network isolation: the VPS has no publicly accessible services other than the HTTPS endpoint and SSH.

f. Logging of access and operations at the application layer.

g. HMAC SHA-256 signing of webhooks between VAPI and the Processor's receiving interface with timing-safe validation (per the Baseline AI Assistant Configuration).

h. Isolation of individual customers' data in the database via an identifier (UUID).

i. Management of API keys at the Subcontractor Vapi: the Subcontractor Vapi processes the Processor's API keys to further Subcontractors (OpenAI, ElevenLabs). The Processor applies measures to limit exposure and to periodically rotate these keys; it treats any compromise of a key as a security incident under Art. 10.

6.3 Expressly Non-Implemented Measures and Conscious Acceptance

The Controller acknowledges and accepts that, for operational, cost, and technical reasons (system latency), the Processor consciously does not implement the following measures; their absence is taken into account in the overall assessment of appropriateness under Art. 6.1, and the Controller expressly confirms this under Art. 2.10 GTC:

a. field-level application encryption (call transcripts, telephone numbers, the audit log) — data is stored in the Processor's database in plaintext; encryption is provided only at the disk level (LUKS) and in transit (TLS);

b. prior removal (redaction) of personal data from the call transcript before it is passed to the Subcontractor OpenAI (LLM) — not implemented, for reasons of system latency; the consequence is 30-day retention of the unredacted text input (transcript) at OpenAI (Art. 7.4.4). Call audio is not passed to the Subcontractor OpenAI; transcription is provided by the Subcontractor Soniox without retention (Art. 7.4.3);

c. backups beyond ordinary operational recovery of infrastructure — not performed; the Controller is responsible for its own backup by exporting data (Art. 9.4 of the GTC);

d. row-level access control in the database (Row-Level Security) and key management in a separate system (KMS/HSM) — placed on the development backlog, not currently implemented; data isolation is provided at the application level (UUID), and the Fernet encryption key is stored in the application environment, constituting a single point of failure.

6.4 Measures at the Level of the Sub-processors

The Processor's Sub-processors adopt their own technical and organisational measures corresponding to Art. 32 GDPR, evidenced typically by SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, or equivalent certification (scope depending on the relevant Sub-processor):

a. Twilio Inc. — SOC 2 Type II, ISO 27001/27017/27018, Binding Corporate Rules (BCR);

b. OpenAI Ireland Ltd. / OpenAI OpCo, LLC — Annex II TOM under DPA v.010126 (AES-256, TLS 1.2+, SOC 2 Type II summary available on request);

c. ElevenLabs Inc. / Eleven Labs Poland sp. z o.o. — SOC 2 Type II (per DPA § 10.1);

d. VAPI Inc. — SOC 2 Type II, PCI DSS v4.0.1, HIPAA compliance (non-public documents accessible via SafeBase under NDA);

e. Google LLC — ISO/IEC 27001, SOC 2, SOC 3;

f. INTERNET CZ, a.s. (Forpsi) — measures appropriate to the type of IaaS hosting;

g. Microsoft: SOC 2 Type 2, ISO/IEC 27001, 27018, and 27701.

Current details of the Sub-processors' technical and organisational measures (TOM) are the subject of Annex No. 2 to this DPA.

6.5 Call Recording and § 88a/§ 89 ZEK

The Controller acknowledges that:

a. call recording is permanently active at the Subcontractor VAPI Inc. with no technical means of disabling it; the Processor fulfils the information obligation towards the User through the mandatory opening disclosure under Art. 3.4 of the GTC;

b. the retention of traffic and location data (§ 88a ZEK) is ensured by the telecommunications Subcontractor Twilio Inc. and the local carrier; Twilio also processes CDR data as an independent controller (Twilio DPA § 3.3); local carriers act as independent controllers (Art. 14 GDPR).

6.6 Complementary User Entity Controls (CUEC) as TOMs

Microsoft's SOC 2 report presupposes Complementary User Entity Controls on the part of the user of the service. These are divided as follows:

a) On the Controller's side (as administrator of its own Microsoft 365 tenant): authorisation and periodic review of access permissions of its own administrator and user accounts in the tenant; enforcement of multi-factor authentication for these accounts; reporting identified security incidents to the Processor. (Corresponds to CUEC-01, CUEC-03, and CUEC-08 in the part relating to tenant administration.)

b) On the Processor's side (as operator of the application with delegated access):

  • security of the application registration in Microsoft Entra: a certificate instead of a shared secret, its rotation and storage in Key Vault; management of its own operational and developer accounts;

  • strong authentication and multi-factor authentication of these accounts;

  • encryption of network sessions (TLS);

  • security of the infrastructure used for access (Forpsi VPS, patch management, restricted access), including the conscious acceptance of a single master encryption key (Fernet) as a single point of failure under Art. 32 of Regulation (EU) 2016/679 and the associated risk;

  • internal training of personnel in the secure handling of tokens and data;

  • compliance with Microsoft's contractual terms;

  • controls over the completeness and accuracy of inputs, processing, storage, and output of calendar data (validation of data passed to and from Microsoft Graph and reconciliation with the Processor's database).

(Corresponds to CUEC-01 in the part relating to application registration and operational accounts, CUEC-02, CUEC-03 in the part relating to the Processor's accounts, CUEC-04, CUEC-06, CUEC-07, CUEC-08 in the part relating to reporting to Microsoft, and CUEC-10 to CUEC-14.)

The Processor will further implement an internal procedure for revoking access upon personnel changes within 24 hours of notice of termination (SSH keys to Forpsi, administrator roles in Microsoft Entra, the secrets manager).

7. Sub-processors

7.1 Controller's Generic Consent

The Controller grants the Processor general authorisation to engage the Sub-processors listed in Annex No. 1 to this DPA (List of Sub-processors). The Processor will notify the Controller of a change to the list of Sub-processors (addition or replacement) at least 10 days in advance by e-mail to the Controller's contact address and by updating Annex No. 1. For the Microsoft Sub-processors, for whom a longer notification period applies on the Sub-processor's side (6 months for customer data, 30 days for the AI sub-processor), the Processor forwards the notification to the Controller within 5 business days of receiving it (3 business days for the AI sub-processor); the general 10-day period under the first sentence does not apply in that case. The period runs from the moment the Processor receives the notification from Microsoft. A change of Sub-processor also includes the transfer of its activities or data to a successor entity as part of a merger, acquisition, or similar transaction; the notification and objection regime under this article applies.

7.2 Controller's Objection

The Controller is entitled, within 10 days of the notification, to raise a written objection on the grounds of justified doubts as to the new Sub-processor's compliance with the GDPR. The Parties undertake to resolve the objection by agreement within 30 days. If agreement cannot be reached, the Controller is entitled to terminate the Agreement on this ground as of the effective date of the change, without any right to damages arising for the Controller.

7.3 Contractual Binding of Sub-processors

The Processor will impose on each Sub-processor the same data protection obligations as are set out in this DPA, in particular the provision of sufficient guarantees under Art. 28(4) GDPR. If a Sub-processor fails to fulfil its obligations, the Processor is liable to the Controller for the performance of the Sub-processor's obligations to the extent set out in Art. 28(4) GDPR.

7.4 Specifics of Sub-processors (Transparent Disclosure)

7.4.1 Twilio Inc.

a. Role: telecommunications Subcontractor for incoming CZ numbers, PSTN connectivity.

b. Location of processing: USA (default storage); for Regional Twilio, Ireland (IE1) is available — the Processor selects Regional Twilio Ireland for Customer Content where available. Customer Account Data (incl. KYC subscriber records) remains in the USA.

c. Transfer mechanism: EU-U.S. Data Privacy Framework + Twilio BCR + EU SCC (cascading regime under Twilio DPA Schedule 3 § 2.1).

d. Dual role: Twilio is an independent controller of Communications Usage Data (CDR metadata) under Twilio DPA § 3.3 and, under Twilio DPA § 3.4, reserves a partial controller role over Customer Content for the purposes of product development, business analytics, and training AI/ML models for fraud detection and security. The telecommunications providers (local carriers) used by Twilio are independent controllers for call metadata.

e. Recording on Twilio's side: disabled (the Twilio-side recording feature is OFF); recording takes place at the level of the Subcontractor VAPI.

f. Subscriber Records (KYC): retained for the period of the statutory obligation.

SMS scope (outbound transactional SMS):

g. Extension of the Subcontractor's role: Twilio now provides, in addition to incoming voice, the transmission of outbound transactional SMS. Twilio acts as an electronic communications service provider and as a Sub-processor under Art. 28 of Regulation (EU) 2016/679.

h. Status of the parties for SMS: the Controller (Client) = the controller and sender of the message (in the legal sense); the Processor (Provider) = the processor; Twilio = the Sub-processor. Notwithstanding that Twilio's terms and conditions regard the account holder (the Processor) as the "Customer," the sender of the message (in the legal sense) is the Controller; this role is evidenced by the Sender ID bearing the name of the Controller's place of business, identification of the Controller in the body of the message, and the registration record held by Twilio.

i. Retention of SMS data: Twilio's Message Logs have a default retention period of 400 days (13 months); the Processor sets a shorter retention period. Minimum retention period for PII (Minimum Time Limit): the body of the message for at least 30 days, the telephone number for at least 120 days. The Processor will consider and apply Message Redaction (not storing the telephone number and the body of the message) as a minimisation measure under Art. 25 and Art. 5(1)(c) of Regulation (EU) 2016/679. After account termination, Twilio deletes Customer Content within 30 days and Customer Account Data within approximately 60 days; Twilio reserves a longer retention period for legal, security, and anti-fraud purposes.

j. Transfers to third countries (SMS): SMS data may by default be processed by Twilio in the USA; the transfer is secured by Twilio's DPA, standard contractual clauses under Commission Implementing Decision (EU) 2021/914, and the EU-U.S. Data Privacy Framework. The Processor may select Regional Twilio (Ireland) for data residency in the EU.

k. Incident notification (SMS): Twilio notifies a security incident "without undue delay" without a fixed numerical deadline; the Processor will notify the Controller of a breach within 48 hours from the moment it becomes aware of it with reasonable certainty, regardless of the source of the discovery (aligned with Art. 33(2) of Regulation (EU) 2016/679 and with the anchor used for the other Sub-processors — Art. 13a.6 of the GTC).

7.4.2 VAPI Inc.

a. Role: orchestration layer — manages the dialogue in real time (speech recognition, language model via BYOK, speech synthesis), call recording, transcript, and structured logs.

b. Location of processing: USA (AWS); within the Pay-as-you-go tier, without an account-wide choice of EU region. VAPI's documented BYOK STT list (Deepgram, Gladia, AssemblyAI, Speechmatics, Google, Azure) does not explicitly name either the previous OpenAI gpt-4o-transcribe or the new primary Sub-processor Soniox Inc. (Art. 7.4.3); the Processor therefore treats the integration regime (a BYOK direct sub-processor relationship vs. a VAPI-managed sub-processor) as an internally unresolved matter and applies a conservative approach to its disclosure, analogous to item i. (Anthropic, PBC) — it lists Soniox as its direct Sub-processor until VAPI expressly confirms otherwise.

c. Transfer mechanism: Standard Contractual Clauses (modules 2/3) with the choice of Irish law, the EU-U.S. Data Privacy Framework, a documented transfer impact assessment (TIA) (available on request after concluding an NDA via SafeBase).

d. DPA: VAPI provides a separate DPA under Art. 28 GDPR only to enterprise customers; the Processor does not have one. The contractual framework relies on VAPI's general Terms of Service. The Controller acknowledges this fact (Art. 2.10 GTC) and undertakes to inform Users in accordance with Art. 13/14 GDPR.

e. Call recording: permanently active in the VAPI cloud, with no client-side means of disabling it (the parameters recordingEnabled, loggingEnabled, pcapEnabled, transcriptPlan.enabled are ON by default).

f. AI model training: VAPI expressly excludes model training only for data from the Google Workspace API; for voice recordings and transcripts, the Processor relies on VAPI's general terms of service (ToS Art. 4.2). The Processor acknowledges, and discloses to the Controller, that VAPI may, under its terms, use data to train its orchestration models; the Processor has applied the available opt-out options.

g. Retention: 14 days for calls, 30 days for chats (Pay-as-you-go); system logs and usage metrics remain on VAPI's infrastructure with no option to redirect them to custom storage.

h. Fallback speech transcription: see Art. 7.4.7 (Google LLC).

i. Sub-sub-processor Anthropic, PBC: VAPI names Anthropic, PBC (USA) as a sub-sub-processor in its PCI AOC documentation. The specific data flow through Anthropic cannot be unambiguously verified in the Pay-as-you-go regime; the Processor therefore lists Anthropic in the list of Sub-processors out of caution. Transfer mechanism: SCC module 3 + the EU-U.S. Data Privacy Framework (Anthropic holds an active certification).

7.4.3 Soniox Inc. — Primary Speech-to-Text

a. Role: Speech-to-Text (recognition of speech from incoming call audio) via API access from the VAPI configuration; replaces the previous STT function of the Subcontractor OpenAI (see Art. 7.4.4(a)). The integration regime (a direct Sub-processor of the Processor in the BYOK regime, analogous to OpenAI/ElevenLabs, vs. a VAPI-managed sub-processor) is not unambiguously confirmed by VAPI Inc. (see Art. 7.4.2(b)); the Processor conservatively lists Soniox as its direct Sub-processor.

b. Contracting party: Soniox Inc., 1045 Helm Lane, Foster City, CA 94404, USA. In its documentation (SOC 2 report), Soniox also lists a place of business in Ljubljana, Slovenia; this fact does not establish a separate EU contracting entity, nor is it mentioned as such in the self-served DPA of Soniox.

c. Location of processing: EU region (endpoint api.eu.soniox.com) — the Processor has internally verified the activation for its account and VAPI's routing to this endpoint. Without active EU activation, the default location of audio processing is the USA (endpoint api.soniox.com); the Processor undertakes to periodically re-verify this state. System data (account, usage statistics, and billing data) is expressly excluded from the region selection and may be processed outside the EU region (self-served DPA § 6/7).

d. Transfer mechanism: Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, incorporated into the self-served DPA by reference. The self-served DPA is structured in terms of Module 2 (Controller-to-Processor) and does not expressly name Module 3 (Processor-to-Processor), although the relationship between the Processor (as processor towards the Controller) and Soniox (as its Sub-processor) factually corresponds to Module 3; the Processor records this inconsistency and the Controller acknowledges it. The EU-U.S. Data Privacy Framework is not mentioned in Soniox's self-served DPA; transfers of system/billing data outside the EU region rely exclusively on the SCC. The governing law of the self-served DPA (derived from the Terms of Service) is the law of the State of California, USA, with the exclusive jurisdiction of the courts of San Francisco, California — this choice relates exclusively to the relationship between the Processor and Soniox, not to the Agreement between the Parties (Art. 14 of the GTC, Art. 15.2 of this DPA).

e. Retention: no retention of audio or the text transcript by default ("does not store audio or text by default unless explicitly configured"); this is ongoing in-memory processing without persistent storage for the duration of transcription. The self-served DPA does not state an express exception for abuse prevention or security review; the Processor records this fact as open and does not base any claim of absolute zero retention on it. The Processor configures the Service exclusively in real-time streaming mode without enabling asynchronous/batch storage on Soniox's side.

f. Sub-processors of Soniox: AWS, Google Cloud Platform, Oracle Cloud Infrastructure, and Cloudflare (infrastructure); Stripe, Google Workspace, and Vanta (operational). Soniox's list states the location in summary form ("United States, European Union, Japan, other AWS/GCP/OCI regions"; Cloudflare "Global") without an exhaustive list of countries; the exact scope of the physical processing route (in particular for the Cloudflare edge network) cannot be verified from the available documentation. The self-served DPA contains no mechanism for prior notification of a change of sub-processor nor a right of objection; the current list is available only in the Soniox Console.

g. Model training: contractually excluded without an opt-in exception ("Soniox does not use Customer Content to train, fine-tune, evaluate, benchmark, or improve Soniox models or services") across the Terms of Service, Privacy Policy, and self-served DPA; only content-free, aggregated, and de-identified operational telemetry may be processed.

h. Limitation of Soniox's liability: the greater of an amount equal to the Processor's fees for 12 months, or USD 100 (Terms of Service Art. 29); with no uncapped exception for a personal data breach.

i. Security incident notification: the self-served DPA provides for notification "without undue delay" without a numerical deadline; see Art. 10.3 of this DPA.

j. Certification: SOC 2 Type II (unqualified opinion, period 21 January 2025 – 10 February 2026, scope exclusively the Security TSC, auditor Prescient Assurance LLC) and ISO/IEC 27001:2022 (valid until 22 February 2029, certifying body Prescient Security LLC), both covering AWS/GCP/OCI infrastructure.

k. Healthcare: Soniox offers separate HIPAA compliance documentation; given the exclusion of healthcare from the Service (Art. 4 of the GTC), this documentation is not relevant to the Processor and no claim towards the Controller is based on it.

7.4.4 OpenAI Ireland Ltd. / OpenAI OpCo, LLC (Large Language Model)

a. Role: Large Language Model (the GPT-5.1 model) for dialogue orchestration via API access from the VAPI BYOK configuration. Since the deployment of the Sub-processor Soniox (Art. 7.4.3), OpenAI no longer performs Speech-to-Text or processes the audio recording of the call; the input to OpenAI is exclusively the text transcript produced by the Sub-processor Soniox, containing Users' personal data (in particular names and telephone numbers disclosed during the call).

b. Contracting party: OpenAI Ireland Ltd. (EU contracting party); the data importer under the SCC is OpenAI OpCo, LLC (USA).

c. Location of processing: USA (default); the EU region for the Pay-as-you-go tier is not guaranteed without an Enterprise upgrade (see Art. 3.6(c) of the GTC).

d. Transfer mechanism: Standard Contractual Clauses (modules 2/3) with the choice of English law (Clause 17 Option 1), supervisory authority the ICO (Information Commissioner's Office, UK).

e. Dual role: OpenAI is a processor under DPA v.010126, but within the scope of abuse prevention (Business TOS Art. 4.2 and Art. 11.3) reserves an independent controller role for flagged content (Customer Content) (currently: flagged text content of the transcript); this role is disclosed to the Controller.

f. Retention: by default 30 days for API logs (Chat Completions API — the text input/output of the transcript and the model's response; the Audio API is no longer used since the deployment of Soniox); the Zero Data Retention (ZDR) Addendum is not agreed (it requires an Enterprise upgrade, which the Processor has not chosen). The Controller acknowledges this fact (Art. 2.10 GTC).

g. Sub-processor TaskUs, LLC (Philippines): content moderation of flagged text content; transfer on the basis of SCC module 3. The Philippines is neither a country with an adequate level of protection under Art. 45 GDPR nor a DPF member. The Controller acknowledges this fact (Art. 2.10 GTC) and undertakes to inform Users.

h. Model training: default exclusion from training (opt-out) (Business TOS Art. 4.2 — "OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use").

i. Prohibition on sensitive data: OpenAI DPA Schedule 1.5 and OpenAI Business TOS Art. 5.4 expressly prohibit the processing of sensitive personal data, including Protected Health Information, without a separate agreement; the Controller undertakes (in accordance with the prohibited uses under Art. 4 of the GTC) not to send such content.

j. Residual exposure: the transition of the Speech-to-Text function to the Sub-processor Soniox (Art. 7.4.3) does not affect OpenAI's obligations described in this article; the text transcript containing Users' personal data remains subject to OpenAI's 30-day retention and to transfer to the USA without an agreed zero data retention regime.

7.4.5 ElevenLabs Inc. (United States) / Eleven Labs Poland sp. z o.o. (EEA controller for Voice Data)

a. Role: Text-to-Speech (TTS); stock voices from the ElevenLabs Voice Library on the Processor's Starter plan, integrated in BYOK mode (the Processor's API key managed within the environment of the Subcontractor VAPI); ElevenLabs is a direct Sub-processor of the Processor, not a sub-processor of VAPI.

b. Voice cloning: the Processor does not use voice cloning (its own User Voice Models, custom voice training) or other biometric functionality; it uses exclusively voices from the Voice Library. The particular voice used is technically "cloned" from the Voice Library, but the commercial use of stock voices relies on ElevenLabs' general terms of service (ToS) and Acceptable Use Policy (the Voice Library Agreement does not contain a separate per-voice commercial licence), and consent from the voice talent is handled by ElevenLabs. For Users, this constitutes synthetic speech, not biometric data.

c. Location of processing: USA + Netherlands + Singapore (storage); the EEA controller for Voice Data, to the extent it arises, is Eleven Labs Poland sp. z o.o.

d. Transfer mechanism: the EU-U.S. Data Privacy Framework (only for the Eleven Labs Inc. entity in the USA), SCC 2021/914 (DPA § 11.1 and § 11.2 — Irish law + Courts of Ireland), the UK Addendum.

e. OEM Terms / B2B2C: the Processor operates in a B2B2C configuration (Making-Available of the Service's outputs to the Controller's Users). Making the outputs of ElevenLabs available to third parties (B2B2C Making-Available) is not licensed under the Starter or Business plan and would require a separate OEM/Enterprise Order Form. This residual licensing risk is borne by the Processor; its potential impact is the suspension or cancellation of the Processor's account with ElevenLabs and the loss of prepaid credit, not a sanction against the Controller. This risk has no effect on the processing of Users' personal data or on the Processor's obligations under this DPA.

f. Model training: the Processor has activated and maintains an opt-out from training on customer data with the Subcontractor ElevenLabs; ElevenLabs does not use customer data to train its models.

g. Retention of Voice Data / biometric data: up to 3 years (Privacy Policy § 6 and § 12); of no practical impact for the Processor, since voice cloning is OUT.

h. Moderation team outside Data Residency: ElevenLabs reserves the right to access Customer Content from various locations for content moderation purposes (DPA § 13.1.3); the Controller acknowledges this.

7.4.6 INTERNET CZ, a.s. (Forpsi) — Hosting Sub-processor

a. Role: VPS hosting (VPS Optimal) + PostgreSQL database, self-managed by the Processor.

b. Location of processing: European Union (the Privacy Policy states "EU"; the specific data centre for VPS Optimal has not been confirmed to the Processor; for housing within the Forpsi group, the Ktiš data centre in the Czech Republic is documented).

c. DPA under Art. 28 GDPR: within its terms and conditions and Privacy Policy, Forpsi does not provide a separate DPA under Art. 28 GDPR; it acts as an independent controller in relation to the personal data of the Processor as its customer. Within its contractual documentation towards the Controller, the Processor designates it as a Sub-processor and discloses to the Controller the technical measures that Forpsi in fact provides (LUKS, network isolation, contractual confidentiality under Art. XVIII.1 of Forpsi's terms and conditions).

d. Forpsi's subprocessor list: the Privacy Policy contains only a general mention of the "Aruba S.p.A. group" and external network providers; a specific list is not publicly available.

e. Deletion period after termination: Forpsi's terms and conditions for VPS Optimal do not state a specific period; for DNS hosting it is 30 days (DNS Art. III.2). After termination of the Agreement, the Processor performs its own deletion of data from its application layer.

f. Security incident notification: Forpsi's parsed documents do not state a deadline, channel, or scope of information for notification. The Processor relies on its own monitoring and, in the event of an incident, complies with the notification obligation under Art. 10 of this DPA.

g. Cap on Forpsi's liability: CZK 30,000 under Forpsi's terms and conditions Art. XVI.2, exclusion of liability for data loss under Art. X.15 and X.17.

h. Backup: for VPS Optimal, Forpsi expressly excludes liability for backups (terms and conditions Art. XI.1; server hosting Art. III.2–4); the Processor does not operate backups beyond the default operational behaviour (Art. 2.10 GTC).

i. Confidentiality and data analysis: under its terms and conditions (Art. X.4), Forpsi is entitled to analyse hosting service data even without the customer's consent for the purposes of ensuring the proper provision of the service; the confidentiality of Forpsi's employees under Art. XVIII.1 remains preserved.

7.4.7 Google LLC — DUAL ROLE Sub-processor

Google LLC acts in the Service in two separate roles:

(a) Google Calendar API (OAuth integration for calendar functions):

  • Purpose: reading free/busy times (availability queries on the Client's primary calendar) and writing appointments;

  • OAuth scope: https://www.googleapis.com/auth/calendar.events (reading and writing events in the calendar of the connected account, including determining availability) and https://www.googleapis.com/auth/calendar.calendarlist.readonly (reading the list of the connected account's calendars so that the Controller can choose which calendar bookings are written to; it does not allow the contents of the calendars to be read). The Processor does not request the full https://www.googleapis.com/auth/calendar scope, nor the scopes for calendar settings or calendar sharing. Availability is determined under the event permissions, strictly within the queried time range and without storing the events read. All of the scopes listed are classified by Google as sensitive and are subject to Google's application verification;

  • The openid and email scopes are used exclusively for the Client's login to the Provider's application; this processing is carried out by the Provider in its capacity as controller, does not fall within the scope of this DPA, and is governed by the Information on the Processing of Personal Data (Art. 13c GTC);

  • Status depending on the type of the Client's account:

  • Workspace client (paid business Google subscription): Google acts as a direct Sub-processor of the Client under a separate Google Cloud DPA concluded between the Client and Google; the Processor is not a party to this relationship and Google does not constitute a Sub-processor of the Processor. The Processor accesses the Google Calendar API only through the Client's OAuth delegation as its technical agent. The Google Cloud DPA + SCC modules 2/3 + the EU-U.S. Data Privacy Framework apply between the Client and Google;

  • Gmail client (personal free account): Google acts as an independent controller towards both Users and the Client; the Client bears responsibility for informing Users and ensuring the legal basis for their consent within the meaning of Art. 13/14 GDPR;

  • The Controller declares the account type in the application when connecting the calendar (Art. 13a.1 GTC); a change of account type is made by a new declaration in the application;

  • Storage of tokens: the Processor stores OAuth tokens in encrypted form (the Fernet algorithm, AES-128-CBC + HMAC-SHA256); the Google refresh token structurally does not rotate, only the access token is renewed;

  • Revocation: when the integration is disconnected by the Client, the Processor immediately and irreversibly deletes the tokens and metadata from its database; revocation of the token with Google is carried out using reasonable efforts. If revocation with Google fails (e.g., the token has expired), the Processor deletes the record from its database and logs the failure; the token may formally survive at Google until its technical expiry (the Controller acknowledges this fact);

  • Assistant ↔ calendar mapping: the assignment of an assistant to a calendar is verified from the assistant identifier in the data from VAPI and is protected by tamper-resistant verification; its security depends on the confidentiality of the receiving interface's secret key (webhook secret) (Art. 2.10 GTC);

  • Retention of data at Google after termination of the Agreement: up to 30 days of recovery + 180 days for deletion = up to 210 days in total (Google Cloud DPA § 6.1 and § 6.2); Google's encrypted backups may retain data for up to 6 months after the Client deletes its Google account.

(b) Google Gemini 2.0 Flash (Czech) — fallback Speech-to-Text:

  • Purpose: fallback transcription at the moment of unavailability of the primary speech recognition Sub-processor, now Soniox Inc. (Art. 7.4.3, formerly OpenAI gpt-4o-transcribe); activation is controlled at the level of the Subcontractor VAPI Inc.;

  • Location of processing: USA;

  • Transfer mechanism: SCC, or DPF where applicable (scope per the Google API ToS);

  • Model training: for the Google Gemini API, no equivalent written opt-out is agreed such as the Processor guarantees for Soniox and OpenAI BYOK; the Controller acknowledges this fact (Art. 2.10 GTC);

  • Open question of fallback architecture: following the deployment of Soniox as the primary STT, the Processor is internally reassessing whether Google Gemini 2.0 Flash will remain the sole fallback element, whether the previous OpenAI STT will also be engaged as a secondary fallback, or whether Soniox will offer its own internal fallback. Pending this decision, the configuration described (Google Gemini 2.0 Flash as the sole fallback) remains unchanged;

  • Change of fallback Sub-processor: any future change of the default fallback speech recognition Sub-processor (e.g., replacing Google Gemini with another Sub-processor available in the VAPI orchestration layer, or adding a further fallback Sub-processor) is covered by the standard subprocessor change notification clause under Art. 7.1 of this DPA.

7.4.8 Microsoft — DUAL ROLE Sub-processor / Independent Controller

a) Business accounts (Microsoft 365 work/school) — Microsoft as Sub-processor: contracting entity Microsoft Ireland Operations Limited (Dublin); standard contractual clauses under Commission Implementing Decision (EU) 2021/914 (modules 2 and 3), the UK IDTA for any transfers from the United Kingdom; the EU Data Boundary (with an exception for Entra ID authentication data); a retention period of 180 days after the end of processing; an undertaking not to use customer data to train generative models; a 6-month (customer data) / 30-day (other personal data) notice period for a change of sub-processor, which the Processor forwards to the Controller within 5/3 days. For business accounts too, Microsoft processes a limited scope of operational data (invoicing, account management, internal and financial reporting) as an independent controller, with express minimisation and without profiling or advertising; this role is separate from the sub-processor role for customer data.

b) Personal accounts (Outlook.com) — Microsoft as an independent controller: on the basis of the Microsoft Services Agreement; the availability of free/busy data is provided via the calendarView method (Art. 13a.3 of the GTC), without the EU Data Boundary, relying only on the Data Privacy Framework; the governing law of the relationship is Irish law.

Revocation of access authorisation is carried out using reasonable efforts; failures are logged. The refresh token is replaced with a new one upon each use, and Microsoft does not revoke the previous token; the Processor securely removes the previous token. The Processor is not liable for any persistence of the token on Microsoft's side until the end of its validity.

7.5 Controller's Right to the List of Sub-processors

The current list of Sub-processors is available in Annex No. 1 to this DPA. The Processor updates it upon every change and notifies the Controller of the change in accordance with Art. 7.1.

7.6 Telecommunications Operators (Local Carriers)

Local telecommunications operators that provide the technical connectivity of the incoming call up to the Subcontractor Twilio Inc. are not Sub-processors within the meaning of the Twilio DPA (Twilio DPA § 1 and the Subprocessor List); in relation to traffic and location data (CDR), they act as independent controllers. The Controller communicates this fact to Users in accordance with Art. 14 GDPR.

8. International Transfers

8.1 Transfer Mechanism

The Controller acknowledges that the provision of the Service requires the transfer of personal data to third countries, in particular to the USA, and potentially to the United Kingdom, the Philippines, Singapore, India, Mexico, Israel, and other countries within the chain of Sub-processors. The transfer is secured on the basis of:

a. Standard contractual clauses under Commission Implementing Decision (EU) 2021/914, modules 2 (Controller-to-Processor) and 3 (Processor-to-Processor / Processor-to-Sub-processor) — for each relevant transfer between the Processor and a Sub-processor, or between a Sub-processor and its further sub-processors;

b. the EU-U.S. Data Privacy Framework for Sub-processors holding a valid certification (Twilio Inc., OpenAI OpCo LLC, ElevenLabs Inc. — for the US entity, Google LLC, VAPI Inc.);

c. the UK Addendum for the transfer of personal data of data subjects from the United Kingdom;

d. Twilio BCR (Binding Corporate Rules) as a secondary mechanism for the Twilio chain (Twilio DPA Schedule 3 § 2.1 cascading regime DPF → BCR → SCC);

e. supplementary technical and organisational measures corresponding to the recommendations of the European Data Protection Board (EDPB Recommendations 01/2020).

8.2 Data Privacy Framework and Fallback Mechanism

Where relevant, the transfer to third countries (the USA) relies on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection). In the event the EU-U.S. Data Privacy Framework is invalidated by a decision of the Court of Justice of the European Union, the transfer will automatically rely exclusively on Standard Contractual Clauses under Art. 8.1(a), without the need to conclude an amendment to this DPA. The Processor will publish an update of the subprocessor documentation on its website and will notify the Controller in accordance with Art. 7.1.

8.3 Transfer Impact Assessment (TIA)

For relevant transfers, the Processor performs (or adopts from the Sub-processors) a transfer impact assessment (TIA). The Sub-processors' TIAs are made available to the Controller on request through the relevant Sub-processors' Trust Center / Trust Portal (typically after concluding an NDA).

8.4 Transfer outside a Country with an Adequate Level of Protection

For transfers to countries without an adequate level of protection (in particular the Philippines — TaskUs LLC for OpenAI content moderation; India, Mexico, Israel — Google's sub-providers), SCC module 3 (onward transfer) applies in accordance with the Sub-processors' documentation. The Controller acknowledges this fact (Art. 3.6(f) of the GTC; express confirmation under Art. 2.10 GTC) and undertakes to inform Users.

8.5 SCC Governing Law

Within the meaning of Clause 17 of the SCC, the Parties choose the law of Ireland as the governing law of the SCC between the Controller and the Processor; disputes will be resolved before the courts of Ireland (Clause 18(b)) — this provision relates exclusively to the SCC framework. The principal contractual relationship between the Parties is governed by Czech law (Art. 14 of the GTC).

8.6 Microsoft — Transfers to Third Countries

For business accounts, the transfer relies on the EU Data Boundary and standard contractual clauses under Commission Implementing Decision (EU) 2021/914 (module 3 for onward transfers to sub-processors); for personal accounts, on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795, the validity of which was confirmed by the General Court in Case T-553/23). Microsoft's list of sub-processors includes entities in countries without an adequacy decision; these transfers rely on standard contractual clauses (module 3).

9. Data Subjects' Rights — Processor's Cooperation

9.1 The Processor assists the Controller, by appropriate technical and organisational measures, so that the Controller can fulfil its obligation to respond to requests from data subjects exercising rights under Art. 15 to 22 GDPR (the right of access, rectification, erasure, restriction of processing, portability, objection, and the right not to be subject to automated decision-making).

9.2 If the Processor receives a request directly from a data subject, it will forward the request to the Controller without undue delay and will not itself respond to it, unless obliged to do so by law.

9.3 The Processor provides the Controller with cooperation in particular by:

a. locating a particular User's records within its application database by telephone number or call identifier;

b. exporting the User's data in a commonly used structured format (JSON);

c. deleting the User's data from its application database and requesting deletion from the relevant Sub-processors to the extent of their contractual obligations.

9.4 The Controller acknowledges that the deletion of data across Sub-processors has practical limitations arising from the architecture of the Service:

a. recordings and transcripts at the level of VAPI Inc. are subject to the retention under Art. 7.4.2;

b. audio processed by the Sub-processor Soniox is not retained by default (Art. 7.4.3(e)), subject to the open question of an exception for abuse prevention;

c. the unredacted text transcript at OpenAI is subject to 30-day retention (Art. 7.4.4);

d. metadata at the level of Twilio Inc. may be retained for the period of a statutory obligation (Subscriber Records, CDR);

e. local telecommunications operators are independent controllers and the Processor has no contractual leverage over them.

9.5 The Processor is obliged to fulfil a data subject's request to the extent reasonably technically possible and to the extent it has technical access to the User's data. For actions requiring extraordinary effort beyond ordinary operational activity, the Processor is entitled to charge the Controller reasonable reimbursement of costs.

10. Notification of Personal Data Breach

10.1 The Processor will notify the Controller of a personal data breach (Security Incident) without undue delay, and in any event no later than within 48 hours from the moment it demonstrably became aware of the breach, whether through its own discovery or on the basis of a Sub-processor's notification.

10.2 The notification contains information to the extent necessary for the Controller to fulfil its obligation under Art. 33(3) GDPR towards the supervisory authority, in particular:

a. a description of the nature of the breach;

b. the categories and approximate number of data subjects and records concerned;

c. the likely consequences of the breach;

d. the measures taken or proposed to address the breach and mitigate its effects;

e. a contact point for further information.

If the Processor obtains the information referred to progressively, it will provide it to the Controller in successive notifications.

10.3 Dependency on Sub-processors.

a) The Parties acknowledge that the Processor's ability to meet the deadline under Art. 10.1 depends on the speed of notification by the Sub-processors, who typically undertake in their contractual documents only to notify "without undue delay" without a specific hourly deadline (e.g., Twilio DPA § 10.3(a), Soniox's self-served DPA (no numerical deadline), OpenAI DPA § 2.7, Google Cloud DPA § 7.2.1, ElevenLabs DPA § 8.1, VAPI SafeBase Schedule 2 (a fixed cap of 72 hours from confirmation of the incident), Microsoft DPA "Security Incident Notification" — "promptly and without undue delay" without a numerical hourly deadline; the 72-hour period is exclusively the controller's obligation towards the supervisory authority under Art. 33 GDPR, not an undertaking by Microsoft; Forpsi's terms and conditions contain no clause).

b) In relation to data processed in the Microsoft environment: Microsoft notifies an incident "without undue delay" without a fixed numerical deadline; the Processor will notify the Controller of a breach within 48 hours from the moment it becomes aware of it with reasonable certainty, regardless of the source of the discovery (Art. 13a.6 of the GTC).

c) The Controller undertakes to forward to the Processor, promptly and no later than within 12 hours of receipt, any incident notification received from Microsoft.

d) The Processor is not liable for a delay in notification caused by a Sub-processor's delay, provided it acted in good faith and passed the information to the Controller without undue delay after receiving it.

10.4 The notification is sent to the Controller's e-mail address stated in the customer account (Art. 16.3 GTC).

10.5 The Processor maintains its own operational monitoring (tracking Sub-processors' incident pages and security notices) and, on a reasonable periodic basis, verifies that the notification channels are functional.

11. DPIA and Prior Consultation — Cooperation

11.1 The Processor assists the Controller in carrying out a data protection impact assessment (DPIA) under Art. 35 GDPR, where such an assessment is required.

11.2 The Processor will provide the Controller with the information necessary to carry out the DPIA, in particular:

a. a description of the nature, scope, context, and purposes of the processing carried out by the Processor and the Sub-processors;

b. a description of the technical and organisational measures adopted to secure the processing (Art. 6);

c. available information on transfers to third countries (Art. 8);

d. available information on the risks arising from processing by an AI system;

e. a sample DPIA structure for an AI voice assistant within the agreed use case (booking), which the Controller will adapt to its specific situation.

11.3 The Processor further assists the Controller in a prior consultation with the supervisory authority (Art. 36 GDPR), where required.

11.4 If the Service is classified under the AI Act as a high-risk artificial intelligence system, the Processor will assist the Controller in carrying out a fundamental rights impact assessment (FRIA) under Art. 27 of the AI Act.

12. Audit

12.1 The Processor will demonstrate compliance with its obligations under this DPA primarily by submitting:

a. valid certificates and audit reports of the Sub-processors (in particular SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018);

b. completed standardised security questionnaires;

c. its own technical and organisational documentation corresponding to Art. 6 of this DPA.

12.2 The Controller is entitled to carry out an on-site audit at the level of the Processor:

a. no more than once per calendar year;

b. with at least 30 days' advance notice;

c. at its own expense (except for an audit that reveals a material breach of this DPA by the Processor);

d. during the Processor's normal business hours;

e. after concluding a separate non-disclosure agreement (NDA).

12.3 An extraordinary audit beyond Art. 12.2 is possible following a confirmed security incident affecting the Controller's personal data.

12.4 The Controller agrees that the audit of Sub-processors is carried out through:

a. certifications and audit reports of the Sub-processors, which the Processor makes available to it (typically under NDA);

b. publicly available Trust Center / Compliance Resource Center information;

c. not through physical audits by the Controller at the level of the Sub-processor (Twilio DPA § 11.2(d)(e), OpenAI DPA, Google Cloud DPA § 7.5).

12.5 A right of audit may be exercised against the Processor by the Sub-processors (in particular ElevenLabs OEM Terms § 3.C), at most once a year with 10 business days' advance notice, and for the duration of the agreement and 3 years after its termination. The Controller will provide the Processor with cooperation in facilitating such an audit to the extent it may concern the personal data of the Controller's Users.

13. Erasure or Return of Data after Termination

13.1 After termination of the Agreement, the Processor will, on the Controller's instruction, delete or return the Controller's Users' personal data to the Controller in the format under Art. 9.3(b). The Controller will give its instruction no later than within 30 days after the end of the Agreement.

13.2 Period for data export at the Controller's request: 30 days from the termination of the Agreement (Art. 9.4 of the GTC).

13.3 After the expiry of 30 days (or after prior deletion on the Controller's instruction), the Processor will delete the Controller's data from its active systems and request the Sub-processors to delete data to the extent of their contractual obligations.

13.4 The actual deletion periods across Sub-processors, which the Controller acknowledges:

a) Twilio: 30 days for export and 60 days' retention of backups, up to 90 days in total;

b) OpenAI: 30 days from termination, with exceptions for mandatory retention for legal proceedings and abuse detection purposes;

c) Google Calendar: up to 30 days of recovery and 180 days for deletion, up to 210 days in total (Google Cloud DPA § 6.1 and § 6.2); encrypted backups may retain data for up to 6 months after termination of the Google account;

d) ElevenLabs (Self-Serve plan): no contractual deletion obligation; the Processor performs ongoing deletion via the API;

e) VAPI: 14 days (calls under the Pay-as-you-go regime) / 30 days (chats); system logs remain on VAPI's infrastructure;

f) Forpsi: no specific contractual period for the VPS; the Processor requests deletion after termination;

g) Google and Microsoft OAuth tokens: revocation is carried out using reasonable efforts; a token may formally survive at the provider until its technical expiry;

h) Microsoft 365 (work/school account): up to 180 days (90 days of an account with limited functionality for extraction and 90 days for deletion);

i) Microsoft (personal Outlook.com account): data is managed by Microsoft as an independent controller under the Microsoft Privacy Statement; after 2 years of account inactivity, Microsoft closes the account and deletes the data.

13.5 The Processor may retain part of the personal data after the end of the Agreement, where required by European Union or Member State law (in particular § 88a ZEK, tax legislation, Act No. 563/1991 Sb., on Accounting). In such a case, the Processor will restrict access to this data and use it exclusively for the purpose for which the law permits its retention.

13.6 Upon the Controller's written request delivered no later than 60 days after the end of the Agreement, the Processor will issue a confirmation of the deletion of data from its systems.

14. Liability and Sanctions

14.1 The Parties' contractual liability under this DPA is limited in accordance with Art. 6 of the GTC. The limitation of liability does not apply to the exceptions under Art. 6.3 of the GTC (intent, gross negligence, fraud, infringement of intellectual property rights, breach of the DPA, breach of confidentiality).

14.2 This is without prejudice to claims by data subjects against the controller and the processor arising directly from Art. 82 GDPR. The Processor and the Controller are each liable to the other for damage caused to a data subject by a breach of obligations under this DPA to the extent set out in Art. 82 GDPR.

14.3 The Controller (Client) shall fully indemnify the Processor, in accordance with Art. 10 of the GTC (indemnification), against third-party claims arising from a breach of its obligations as controller, in particular the obligation to inform Users and to ensure the legal basis for processing.

15. Final Provisions

15.1 Relationship to the GTC and the Agreement. This DPA forms an integral part of the Agreement and the GTC. In the event of a conflict between the DPA and another part of the contractual documentation, this DPA prevails on matters of personal data protection.

15.2 Governing law and jurisdiction. This DPA is governed by Czech law; for disputes, the general court having local jurisdiction over the Processor under Art. 14 of the GTC has jurisdiction. For the Standard Contractual Clauses, the choice of governing law and forum under Art. 8.5 applies.

15.3 Term. This DPA is concluded together with the Agreement (Art. 2a.2 of the GTC) and takes effect together with it (Art. 2.5 of the GTC). It lasts for the duration of the Agreement, extended by the period necessary to fulfil the obligations under Art. 13. This version of the DPA is effective as of 20 July 2026 and supersedes previous versions; for Agreements concluded before that date it applies in accordance with Art. 15.4.

15.4 Amendment of the DPA. This DPA may be amended in accordance with the rules of Art. 8.4 of the GTC. The reflection of changes in the Sub-processors' contractual terms (in particular changes to the SCC under Commission Implementing Decision (EU) 2021/914 or its successor) is considered a change compelled by law.

15.5 Annexes. The following form an integral part of this DPA:

  • Annex No. 1 (DPA) — List of Sub-processors (with location, role, transfer mechanism)

  • Annex No. 2 (DPA) — Technical and Organisational Measures (TOM) — details of the Processor's TOM and a summary of the Sub-processors' TOM

  • Annex No. 3 (DPA) — Description of processing under Art. 28(3) GDPR (recap of Art. 2 of this DPA + onboarding data)

Annex No. 1 (DPA) — List of Sub-processors

Sub-processorRoleLocation of ProcessingTransfer MechanismStatus
Twilio Inc. (US) / Twilio Ireland Limited (IE — EU contracting party)Telecommunications connectivity, PSTN inbound, CZ numbers; outbound transactional SMS (+420)USA (default) / Ireland (if Regional Twilio); local operators as independent controllersEU SCC modules 2/3 + Twilio BCR + DPF cascading regime (Twilio DPA Schedule 3 § 2.1)active
VAPI Inc.Call orchestration, recording, transcript, BYOK callsUSA (AWS) — no account-wide EU region on PAYGSCC modules 2/3 + DPF + Irish law + TIA (via SafeBase NDA)active; DPA only for Enterprise (conscious acceptance per Art. 2.10 GTC)
Anthropic, PBC (USA) — sub-sub-processor via the VAPI chainPossible sub-sub-processor identified in VAPI's PCI AOC declaration; the specific data flow in the Pay-as-you-go regime cannot be verifiedUSASCC module 3 (onward transfer) + DPFactive; listed out of caution
Soniox Inc. (USA)Speech-to-Text (primary) via the VAPI configuration; the BYOK vs. VAPI-managed integration regime not confirmed by VAPI (listed out of caution)EU region (activation for the account internally verified); system/billing data outside the region selectionSCC under Commission Implementing Decision (EU) 2021/914, the self-served DPA structured as Module 2 (inconsistency with the factual Module 3 recorded); DPF not mentionedactive; no retention of audio/text by default; replaces OpenAI's STT function
OpenAI Ireland Ltd. (EU contracting party) / OpenAI OpCo, LLC (US — data importer)Large Language Model (GPT-5.1) via BYOK from VAPI; since the deployment of Soniox, text input only (transcript), not audioUSA (default); EU region not guaranteed on Pay-as-you-goEU SCC modules 2/3 (Clause 17 Option 1 — English law) + DPFactive; 30-day retention of the unredacted text transcript; zero data retention regime not agreed
TaskUs, LLC (Philippines)Content moderation for OpenAI flagged content (text transcript)PhilippinesSCC module 3 (onward transfer)sub-subprocessor of OpenAI; conscious acceptance per Art. 2.10 GTC
ElevenLabs Inc. (US) / Eleven Labs Poland sp. z o.o. (PL — EEA controller for Voice Data)Text-to-Speech (Voice Library voice, Starter plan / BYOK)USA + Netherlands + SingaporeSCC 2021/914 + DPF (US entity) + UK Addendum; DPA § 11.2 — Irish lawactive; voice cloning OUT
INTERNET CZ, a.s. (Forpsi)VPS hosting (VPS Optimal) + PostgreSQL DBEU (Privacy Policy states "EU"; the specific data centre for VPS Optimal not stated)EU/EEAactive; no separate DPA under Art. 28 GDPR (conscious acceptance)
Google LLC — DUAL ROLE: (a) Google Calendar API (OAuth) + (b) Google Gemini 2.0 Flash (Czech) as fallback STT(a) Calendar integration (availability queries + write); (b) fallback transcription during an outage of the primary STT (Soniox, formerly OpenAI)USA + sub-providers in India, the Philippines, Mexico, Israel, Sri Lanka (current list: the Google Cloud Sub-processors page — https://cloud.google.com/terms/subprocessors; SCC module 3 for countries without adequacy)(a) Workspace: Google Cloud DPA + SCC modules 2/3 + DPF; Gmail: Privacy Policy + DPF (independent controller); (b) SCC + DPF per the Google API ToS; SCC module 3 for sub-providers in countries without adequacyactive; the fallback STT architecture is being internally reassessed following the deployment of Soniox (see Art. 7.4.7); may change depending on availability at VAPI (an operational change per Art. 7.1)
Microsoft (Microsoft Ireland Operations Limited — EU contracting; Microsoft Corporation) — DUAL STATUS depending on account typeMicrosoft 365 / Outlook.com calendar integration (free/busy availability + write); the 2nd calendar provider, at parity with GoogleEU/EEA under the Microsoft EU Data Boundary (Variant A work/school); globally (Variant B consumer); Microsoft's sub-processors include, among others, the USA, India, Israel, Cyprus, ChinaVariant A (work/school): Microsoft DPA (Art. 28) + 2021 SCC modules 2/3 + UK IDTA + EU Data Boundary + DPF; Microsoft = Sub-processor. Variant B (Outlook.com consumer): Microsoft Services Agreement + Privacy Statement + DPF; Microsoft = independent controller (no DPA/EUDB)prepared, not yet active (deployed upon the first linking of a Microsoft account by a Client); see Art. 7.4.8; Microsoft's subprocessor notice 6 months / 30 days (AI), forwarded to the Controller within 5 / 3 business days

Standard subprocessor change notification clause: 10 days in advance (Art. 7.1 of this DPA); right of objection 10 days (Art. 7.2).

Publicly available data protection documentation of the Sub-processors may not reflect the current state of their processing; the Controller therefore fulfils the transparency obligation towards Users under Art. 13 and 14 of Regulation (EU) 2016/679 through its own information notice, not by reference to a Sub-processor's documentation.

Annex No. 2 (DPA) — Technical and Organisational Measures (TOM)

A. TOM of the Processor

(Detail per Art. 6 of this DPA — expressly disclosed non-implementations per Art. 6.3.)

AreaMeasure
Encryption in transitTLS 1.3+ by default; TLS 1.2 fallback protocol only for legacy clients
Encryption at rest (OS)LUKS (block-level encryption) on the Forpsi VPS
Application-level encryption (selective)Fernet (AES-128-CBC + HMAC-SHA256) for Google Calendar OAuth tokens
Application-level encryption (transcripts, telephone numbers, audit log)OUT — conscious acceptance under Art. 6.3(a)
Redaction (removal) of personal data before OpenAIOUT — conscious acceptance under Art. 6.3(b)
Backup beyond operational recoveryOUT — conscious acceptance under Art. 6.3(c)
Row-Level Security (PostgreSQL)OUT — backlog; application-level isolation via UUID
KMS / HSM key managementOUT — backlog (internal operational trigger)
SSH authenticationkey-based only, port 2242, fail2ban
Network isolationVPS with no publicly accessible services other than HTTPS + SSH
Security of receiving interfacesHMAC SHA-256 + timing-safe validation
Loggingapplication-level records of operations
Assistant onboardingverification against the Baseline AI Assistant Configuration
STT configuration (Soniox)exclusively real-time streaming; asynchronous/batch storage on the side of the Subcontractor Soniox not enabled (Art. 7.4.3(e))

B. TOM of the Sub-processors (Summary)

Details of the Sub-processors' TOM are the subject of their respective DPAs / Trust Center documentation. Main sources:

Sub-processorCertification / DocumentationAccess for the Controller
Twilio Inc.SOC 2 Type II, ISO 27001/27017/27018, BCR; Twilio DPA Schedule 2NDA via Twilio account
Soniox Inc.SOC 2 Type II (exclusively the Security TSC, unqualified, 21.1.2025–10.2.2026, auditor Prescient Assurance LLC); ISO/IEC 27001:2022 (valid until 22.2.2029, certifying body Prescient Security LLC)Soniox Console (trust portal)
OpenAIAnnex II TOM (DPA v.010126), SOC 2 Type II summaryTrust portal trust.openai.com
ElevenLabsSOC 2 Type II (DPA § 10.1)compliance.elevenlabs.io under NDA
VAPI Inc.SOC 2 Type II, PCI DSS v4.0.1, HIPAA compliance (non-public)SafeBase under NDA
Google LLCISO/IEC 27001, SOC 2, SOC 3Cloud Compliance Resource Center; SOC 3 publicly available
MicrosoftSOC 2 Type 2 (M365 Microservices, Deloitte, unqualified, categories Security/Availability/Processing Integrity/Confidentiality); ISO 27001/27017/27018/27701/42001; M365 Central Services SOC 2 for Exchange Online + Graph (pre-launch request)Microsoft Service Trust Portal under NDA + tenant login
ForpsiNo publicly documented certification (gap)n/a

Annex No. 3 (DPA) — Description of Processing under Art. 28(3) GDPR

ItemContent
Subject matter of processingAI voice assistant for incoming calls (bookings + Knowledge Base)
Duration of processingFor the duration of the Agreement + per Art. 13
Nature of processingCollection, storage, analysis of call content, response synthesis, calendar operation
Speech-to-Text providerSoniox Inc. (primary, Art. 7.4.3); Google LLC — Gemini 2.0 Flash (fallback, Art. 7.4.7(b))
Large Language Model providerOpenAI Ireland Ltd. / OpenAI OpCo, LLC — GPT-5.1 (Art. 7.4.4)
Purposes of processingSee Art. 2.5 of this DPA
Type of personal dataSee Art. 2.4 of this DPA
Categories of data subjectsSee Art. 2.3 of this DPA
Controller's obligations and rightsPer Art. 4 GDPR + the GTC + this DPA

Want to try FastLajna?

Get started
FastLajna

AI phone assistant for Czech small businesses and local operations.

Terms & Documents

  • Terms & Conditions
  • DPA
  • Price List
  • Privacy
  • Cookies

Contact

  • General enquiries: hello@fastlajna.cz
  • Technical support: tech@fastlajna.cz
  • +420 728 436 188

© 2026 Fastlajna s.r.o. · Školská 1736/12, Nové Město, 110 00 Praha 1, Czech Republic · Company ID 29543908 · File No. C 448213, Municipal Court in Prague

Your privacy

We always use essential technologies for sign-in, security and language settings. With your consent we also use analytics cookies (Google Analytics) to understand traffic and improve the site. Without consent, analytics stays off.

Cookie information