Effective 9 August 2026. This Data Processing Addendum applies where voiqq processes personal data in customer-controlled workspace content on behalf of a customer and forms part of the applicable service agreement.
Roles and instructions
The customer is controller or processor as applicable; voiqq acts as processor or subprocessor for project content. voiqq processes that data only to provide, secure, support, and improve the contracted service, according to documented instructions and applicable law.
People, security, and confidentiality
Access is limited to authorized personnel and providers subject to confidentiality duties. Safeguards include access controls, encrypted transport, role and row-level authorization, restricted credentials, logging, backups, vulnerability management, and incident procedures proportionate to risk.
Subprocessors and transfers
The customer authorizes the listed subprocessors. voiqq remains responsible for required subprocessor obligations and will use recognized transfer mechanisms where applicable. Material additions will be published on the Subprocessors page before or promptly after use where advance notice is impracticable for security or continuity.
Assistance and incidents
Taking account of the service and available information, voiqq will reasonably assist with data-subject requests, security obligations, impact assessments, regulator consultations, and verified personal-data incidents. Customers must use appropriate workspace controls and provide information needed for assistance.
Return, deletion, and audit
On termination or an eligible request, customer content is returned or deleted according to product controls, backups, ownership safeguards, and legal retention duties. voiqq will provide reasonable compliance information and support proportionate audits subject to confidentiality, security, scope, and cost protections.
Processing details
- Subject: audit, compliance, security, accessibility, and related project management
- Duration: the service term plus documented retention and deletion periods
- Data subjects: customer users and people referenced in authorized project content
- Data: account identifiers, assignments, findings, evidence, comments, URLs, reports, and customer-configured fields
- Purpose: hosting, collaboration, security, support, imports, exports, and requested report generation
