Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between VOID ("Processor") and the customer ("Controller") for the use of VOID's AI workforce platform.
1. Definitions
- Controller: The customer who determines the purposes and means of processing personal data
- Processor: VOID, who processes personal data on behalf of the Controller
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data, including collection, storage, use, and deletion
- Sub-processor: Third parties engaged by VOID to process personal data
2. Scope and Purpose of Processing
What We Process
- Contact information (names, emails, phone numbers)
- Conversation data (messages exchanged with AI agents)
- Usage data (interaction patterns, session data)
- Payment information (processed via Stripe, not stored by VOID)
- Technical data (IP addresses, browser type, device information)
Why We Process It
- Operating AI agents for customer conversations
- Capturing and managing sales leads
- Generating analytics and performance reports
- Sending transactional emails and notifications
- Processing payments and invoices
3. Security Measures
Technical Measures
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Multi-factor authentication via Clerk
- Role-based access control
- 90-day audit log retention
- Logical data isolation per customer
Infrastructure Providers (All SOC 2 Type 2)
- MongoDB Atlas — Database hosting
- Vercel — Application hosting
- Stripe — Payment processing
- Clerk — Authentication
- Groq — AI inference
- Resend — Email delivery
4. Data Subject Rights
VOID shall assist the Controller in responding to data subject requests, including:
- Right of Access — Providing copies of personal data
- Right to Rectification — Correcting inaccurate data
- Right to Erasure — Deleting personal data
- Right to Restriction — Limiting processing
- Right to Data Portability — Exporting data in JSON format
- Right to Object — Ceasing processing
5. Data Breach Notification
- VOID will notify the Controller within 72 hours of becoming aware of a breach
- Notification includes: nature of breach, affected data subjects, likely consequences, measures taken
- VOID will cooperate with the Controller to investigate and mitigate the breach
6. Data Retention and Deletion
Retention Periods
- Conversation data: 90 days from last activity
- Lead information: 1 year from creation
- System logs: 90 days
- Invoice/financial records: 7 years (legal requirement)
- User account data: Account lifetime + 30 days
Deletion Upon Termination
- All Personal Data deleted within 30 days of Service Agreement termination
- VOID will certify deletion in writing upon request
- Financial records retained for legal compliance will be securely isolated
7. Sub-processors
VOID engages sub-processors as listed in Section 3. VOID will notify the Controller of any changes to sub-processors at least 30 days in advance.
8. Data Transfers
Personal Data may be transferred to and processed in the United States. VOID ensures appropriate safeguards including Standard Contractual Clauses (SCCs) where required.
9. Audit Rights
- The Controller may audit VOID's compliance with 30 days prior written notice
- Audits limited to once per year (unless a breach has occurred)
- VOID may satisfy audit requests with SOC 2 reports or written certifications
10. Governing Law
This DPA shall be governed by the laws of the State of Delaware, United States, unless otherwise required by applicable data protection law.
11. Contact
For questions about this DPA, contact: dpa@void.ai
VOID — Data Processing Agreement v1.0