Data processing addendum

Summary · Last updated 2026-04-22

This page summarizes the key points of Vorel's Data Processing Addendum (DPA). The full, executable version is available on request at [email protected]. It covers processing of personal data by Vorel on behalf of customers subject to the GDPR, UK GDPR, and equivalent regimes.

Roles

The customer is the data controller for the conversation content and end-user data processed through their Vorel agents. Vorel is the data processor. Where a regional sub-processor is required (for example a regional telephony carrier), Vorel remains the sole counterparty under the DPA.

Subject matter and duration

Processing is limited to what is necessary to run the service contracted under the MSA. Duration matches the contract term plus any deletion or return period the customer elects.

Sub-processors

We keep a current list of sub-processors (cloud hosting, telephony carriers, model providers) and notify customers at least 30 days before we add one. A customer may object; we work in good faith to provide an alternative or allow termination.

International transfers

Where data leaves the EEA, UK, or Swiss jurisdictions, we rely on the European Commission's Standard Contractual Clauses and the UK IDTA, with transfer impact assessments on request.

Security

Vorel maintains a written information security program including access controls, encryption in transit and at rest, least-privilege principles, security monitoring, incident response, and annual penetration testing. We hold a SOC 2 Type II report and are HIPAA eligible for customers that require it.

Data-subject rights

We assist the customer in responding to access, correction, deletion, portability, and objection requests from end-users. Where a request reaches us directly, we route it to the customer.

Breach notification

We notify affected customers without undue delay after becoming aware of a personal-data breach, and in any event within 72 hours. Notification includes the nature of the breach, categories affected, likely consequences, and the measures taken or proposed.

Return and deletion

At the end of the service, Vorel deletes or returns personal data on the customer's written instruction within 30 days, unless retention is required by law.

Requesting the executable DPA

Email [email protected] with your signer name, title, and the legal entity name on the agreement. We return an executable counterpart within two business days.