This Data Processing Agreement ("DPA") forms part of the Terms of Service between NexaVoxa and the Customer.
1. Roles and Scope
Customer as Controller: Customer determines the purposes and means of processing personal data through the NexaVoxa platform.
NexaVoxa as Processor: NexaVoxa processes personal data solely on the documented instructions of the Customer to provide the Services.
2. Security Obligations
NexaVoxa implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction. This includes stream encryption, logical environment separation, and restricted access controls for all support personnel.
3. Sub-processing
NexaVoxa utilizes third-party sub-processors to deliver core functionality (e.g., Google Cloud, AWS, Twilio, Deepgram). We ensure that all sub-processors are bound by data protection obligations at least as restrictive as those in this DPA.
4. Breach Notification
In the event of a confirmed personal data breach affecting Customer data, NexaVoxa will notify the Customer without undue delay (within 72 hours) and provide reasonable assistance in mitigating the impact.
For a signed PDF version of this DPA, please email [email protected].