Legal

Data Processing Agreement

Last updated August 12, 2026

When your users type into the widget, you decide why that data is collected and we act on your instructions. In GDPR terms you are the controller and we are the processor, and Article 28 requires the arrangement to be written down. This is it. It forms part of the Terms of Service, and using Voicebox accepts it, so there is nothing to sign or send back.

01What we process, and why

  • Subject matter. Providing the Voicebox feedback collection and analysis service.
  • Duration. For as long as your account exists, plus the backup window in clause 08.
  • Nature and purpose. Collecting, storing, analyzing, grouping, displaying, and exporting end-user feedback.
  • Types of personal data. Feedback text, feedback type and rating, an optional email address the submitter provides, page URL and referring page, browser user-agent, language, the identify traits you choose to send, and the submitter's IP address.
  • Categories of data subject. Your users and site visitors, and the members of your team who use the dashboard.

Do not send special category data (health, biometrics, political or religious views, and the rest of Article 9) through the widget. The product is not built for it and the acceptable use clause forbids it.

02We act on your instructions

We process end-user personal data only on your documented instructions. Your configuration in the product is those instructions: which projects exist, what the widget asks for, whether AI analysis is on, where webhooks point, and who is on your team.

If we ever have to process something because the law requires it, we will tell you first unless that law forbids the warning.

03Confidentiality

Access is limited to people who need it to run or support the service, each under a duty of confidentiality that survives them leaving.

04Security

Our technical and organizational measures include: encryption in transit; tenant isolation enforced on the server for every read and write, so one customer's data cannot be addressed by another; API keys stored only as hashes; signed webhook payloads; role-based access inside an organization; automatic deletion of submitter IP addresses after seven days; and outbound request filtering that prevents the service being pointed at private networks.

Measures change as the product does. They will not get materially weaker while you are a customer.

05Subprocessors

You give general authorization for the subprocessors listed in the privacy policy, which names each one, what it does, and where it is. Each is bound by terms no less protective than these.

We'll give you at least 30 days' notice by email before adding or replacing one. If you object on reasonable data-protection grounds, tell us within those 30 days and we'll work it out or you may terminate the affected part of the service without penalty.

06International transfers

The AI analysis provider, DeepSeek, is in China, which has no UK or EU adequacy decision. Where restricted transfer rules apply we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and we minimize what is transferred: feedback text, type, and rating only, never email addresses, identify traits, IP addresses, or page URLs.

If that transfer doesn't work for your risk assessment, switch AI analysis off in Settings. Nothing goes to the provider while it's off, and the rest of the product carries on working.

Our other subprocessors are in the United States.

07Helping you with your obligations

Data subject requests. Mostly you won't need us: search the inbox by email address to find someone's submissions, delete them from the same screen, and export everything from Settings. Where you do need us, we'll help, and we'll forward any request that reaches us directly rather than answering it ourselves.

Breach notification. We'll tell you without undue delay and within 72 hours of becoming aware, with what happened, who is affected, the likely consequences, and what we're doing about it, so you can meet your own Article 33 deadline.

Assessments. We'll give you the information you reasonably need for a DPIA or a prior consultation.

08Deletion and return

Export everything, any time, from Settings, as a single file covering every project, submission, and theme.

Deleting your organization erases it and everything belonging to it immediately. Backups containing deleted data roll off within 30 days, and are not restored except in a disaster-recovery event.

09Audit

On reasonable written request, no more than once a year unless a regulator requires otherwise, we'll answer a security questionnaire and provide the information needed to show we're meeting this agreement. Where an on-site audit is genuinely required, we'll agree scope and timing in advance so it doesn't interfere with other customers.

10Contact

Data protection questions go to support@usevoicebox.dev. The processor under this agreement is Arc Labs LLC. Where this agreement and the Terms of Service disagree about personal data, this one wins.