Data Processing Agreement

Last updated: June 24, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Veyce ("Processor") and you, the customer ("Controller"). This DPA reflects the parties' agreement with regard to the processing of personal data in accordance with Article 28 of the General Data Protection Regulation ("GDPR") and other applicable data protection laws.

By accepting the Terms of Service or continuing to use the Service, you agree to this DPA. If you are acting on behalf of an organization, you represent that you have authority to bind that organization to this DPA.

2. Definitions

"Personal data," "processing," "controller," "processor," and "data subject" have the meanings given in the GDPR.

"Service Data" means personal data that the Controller submits to the Service, including lead and contact information imported into the platform.

"Sub-processor" means any third party engaged by Veyce to process Service Data on behalf of the Controller.

3. Subject Matter, Nature, and Purpose

Subject matter:The processing of personal data in connection with the Controller's use of the Veyce power dialer service.

Nature: Storage, retrieval, organization, and display of lead and contact data; generation of call metadata and session records; integration with third-party CRM and communication platforms as directed by the Controller.

Purpose: To provide the Controller with outbound calling infrastructure, lead management, call session analytics, and associated features as described in the Terms of Service.

Duration: For the period during which the Controller holds an active subscription, until the earlier of account termination or deletion of the relevant data. Upon termination, Veyce will delete or return Service Data as described in Section 9.

4. Types of Personal Data and Data Subjects

Categories of personal data: Names, telephone numbers, email addresses, company names, job titles, mailing addresses, and any custom fields defined and populated by the Controller. Call session metadata (call duration, outcome, disposition, agent notes) associated with individual contacts.

Categories of data subjects:Business contacts, leads, prospects, and consumers whose information the Controller imports into or generates within the Service. Veyce has no direct relationship with these individuals and processes their data solely at the Controller's direction.

5. Controller Obligations

The Controller represents, warrants, and agrees that:

  • It has a lawful basis under applicable data protection law for all personal data it submits to the Service
  • It has provided all required privacy notices and obtained all required consents from data subjects whose data is submitted to the Service
  • It will comply with GDPR, CCPA, CASL, PECR, and all other applicable data protection and privacy laws in connection with its use of the Service
  • It will respond to data subject rights requests for data it controls, including access, correction, deletion, and portability requests
  • It is solely responsible for the accuracy, legality, and integrity of Service Data it provides

6. Processor Obligations

Veyce agrees, as Processor, to the following obligations with respect to Service Data:

Instructions:Veyce will process Service Data only on documented instructions from the Controller (including as set out in the Terms of Service and this DPA), except where required to do so by applicable law. If Veyce is required by law to process Service Data in a manner inconsistent with the Controller's instructions, Veyce will notify the Controller before such processing unless prohibited by law.

Confidentiality: Veyce will ensure that persons authorized to process Service Data are bound by confidentiality obligations and only process Service Data as necessary to provide the Service.

Security:Veyce will implement appropriate technical and organizational measures to protect Service Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including TLS encryption in transit, AES-256 encryption at rest for credentials, and row-level security (RLS) policies restricting data access to the Controller's account only.

Data subject rights:To the extent technically feasible, Veyce will assist the Controller in responding to data subject rights requests, including deletion of an individual's data from the Service upon the Controller's instruction.

Security incidents:Veyce will notify the Controller without undue delay after becoming aware of a personal data breach affecting Service Data, to the extent required by applicable law. Notification will be sent to the email address on the Controller's account.

Audits:Veyce will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, subject to reasonable confidentiality protections. Audits may be conducted upon 30 days' prior written notice, at the Controller's expense, no more than once per year.

7. Sub-processors

The Controller grants Veyce general authorization to engage sub-processors. Veyce will ensure that sub-processors are bound by data processing agreements with obligations equivalent to those in this DPA. Veyce remains liable to the Controller for the acts and omissions of its sub-processors.

Veyce will notify the Controller of any intended changes to sub-processors by updating this page. The Controller may object to a new sub-processor within 14 days of notice; if the parties cannot resolve the objection, the Controller may terminate the subscription for cause.

Current sub-processors:

ProviderPurposeLocation
SupabaseDatabase hosting and authenticationUnited States
VercelApplication hosting and deliveryUnited States
StripePayment processing (billing data only)United States
SentryError monitoring and diagnosticsUnited States

Twilio is integrated at the Controller's direction and using the Controller's own Twilio account credentials. Call recordings are stored in the Controller's Twilio account. Twilio is a sub-processor of the Controller, not of Veyce.

8. International Data Transfers

Veyce's sub-processors are located in the United States. If the Controller is subject to GDPR and transfers personal data from the European Economic Area (EEA) to the United States, the Controller is responsible for ensuring that such transfers comply with applicable transfer mechanisms (including Standard Contractual Clauses where required).

If you require Standard Contractual Clauses or other transfer documentation, contact us at info@veyce.com.au.

9. Data Deletion and Return

Upon termination of the Controller's account, Veyce will delete Service Data within 30 days, except where retention is required by law or where data is included in routine backups not yet purged in the ordinary course.

The Controller may export their Service Data at any time from within the application, or request an export by contacting us before account termination. After the 30-day period following termination, Veyce has no obligation to retain or provide Service Data.

10. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.

The Controller agrees to indemnify, defend, and hold harmless Veyce from any claims, penalties, fines, or regulatory actions arising from the Controller's failure to comply with its obligations as data controller under applicable data protection law, including but not limited to the failure to have a lawful basis for processing, failure to obtain required consents, and failure to honor data subject rights requests.

11. Contact

For questions about this DPA, to request Standard Contractual Clauses, or to submit a data subject rights request, contact us at:

Veyce
Email: info@veyce.com.au

Or use our contact form.