Data Processing Agreement
pursuant to Art. 28 GDPR
Last updated: 2026-09-09 · Version 1.2
Which language governs. This is a translation of the German Auftragsverarbeitungsvereinbarung, which is the version that was drafted and which both parties conclude. Where the two disagree, the German text prevails. It is available at <https://vibevoice.net/avv>.
Between
the Customer — hereinafter the "Controller" —
and
VibeVoice — Florian Schneider c/o Online-Impressum.de #37276 Europaring 90, 53757 Sankt Augustin, Germany Email: [email protected]
— hereinafter the "Processor" —
the following agreement is concluded.
§ 1 Subject matter and duration
(1) Subject matter. The Processor provides the Controller with automated speech recognition services (transcription of audio and video data into text) through the VibeVoice software and services. The details follow from the main contract concluded between the parties (Terms of Service at <https://vibevoice.net/terms>).
(2) Duration. This agreement begins when the main contract takes effect and ends when the main contract ends. Either party retains the right to terminate this agreement for cause, in particular in the event of a material breach of data protection law.
§ 2 Nature and purpose of processing, categories of data, data subjects
(1) Nature and purpose. Collection, storage for the duration of processing, automated conversion of speech into text, provision of the result to the Controller, and subsequent deletion of the raw data. Processing is carried out solely to provide the contractually owed service.
(2) Categories of personal data.
- Voice recordings (audio and video data), including the voices they contain
and what is said in them
- Transcripts generated from them
- Account and contact data of the Controller's user accounts (name, email
address)
- Usage and metadata (times, duration, device used, IP address)
(3) Categories of data subjects.
- Employees and other users of the Controller
- Third parties whose voice or personal data is contained in recordings
transmitted by the Controller
(4) Special categories (Art. 9 GDPR). The services are not designed or certified for the processing of special categories of personal data. If the Controller intends such processing — health data above all — this must be notified in text form in advance and agreed separately. Absent such an agreement, the Controller warrants that it will not transmit special categories of personal data.
§ 3 The Controller's right to issue instructions
(1) The Processor processes personal data solely on documented instructions from the Controller, unless required to process by Union or Member State law. In that case the Processor informs the Controller of that legal requirement before processing, unless the law in question prohibits such information on important grounds of public interest.
(2) The Controller's or its users' use of the services counts as an instruction within the meaning of paragraph 1. Instructions going beyond that require text form.
(3) The Processor informs the Controller without undue delay if it takes the view that an instruction infringes the GDPR or other data protection provisions. It is entitled to suspend the execution of a manifestly unlawful instruction.
(4) No use for the Processor's own purposes. The Processor uses the data processed on the Controller's behalf at no point for its own purposes. In particular, audio, video and transcript data are used neither for training, nor for fine-tuning, nor for improving AI models — neither its own nor those of third parties.
§ 4 Confidentiality
(1) The Processor places all persons authorised to process the data under an obligation of confidentiality, unless they are already subject to an appropriate statutory duty of confidentiality.
(2) The Processor currently operates as a sole trader without employees. Access to production systems is held by the owner alone. Should further persons be involved in future, they will be placed under obligation before they begin.
§ 5 Technical and organisational measures (Art. 32 GDPR)
(1) The Processor implements the technical and organisational measures described in Annex 1.
(2) The measures are subject to technical progress. The Processor is entitled to implement alternative measures provided the level of protection is not reduced. Material changes are to be documented.
§ 6 Sub-processors
(1) The Controller grants the Processor general authorisation to engage sub-processors pursuant to Art. 28(2) sentence 2 GDPR.
(2) The sub-processors currently engaged are listed in Annex 2 and are additionally published at <https://vibevoice.net/subprocessors>.
(3) The Processor informs the Controller in text form at least 30 days in advance of the addition or replacement of a sub-processor. The Controller may object within that period on important data protection grounds. In the case of a justified objection that cannot be remedied, either party is entitled to terminate the main contract with effect from the date of the change.
(4) The Processor imposes on every sub-processor, by contract, the same data protection obligations that apply to it under this agreement, and remains liable to the Controller for their compliance.
§ 7 Place of processing, transfers to third countries
(1) Core processing in Germany. The processing of audio, video and transcript data and the storage of user accounts takes place on the Processor's servers in Germany. No hyperscaler (such as Amazon Web Services, Microsoft Azure or Google Cloud) is used for this processing.
(2) Supporting services. The service providers named in Annex 2 are used for delivery, attack mitigation, email sending and payment processing. Where this involves a transfer to third countries, that transfer is safeguarded by the EU Commission's standard contractual clauses and, where applicable, certification under the EU-U.S. Data Privacy Framework.
(3) No transfer of audio or transcript data to a third country takes place.
§ 8 Assistance to the Controller
(1) Data subject rights. The Processor assists the Controller as far as possible, by appropriate technical and organisational measures, in responding to requests from data subjects (Art. 15 to 22 GDPR). If a data subject approaches the Processor directly, the Processor forwards the matter to the Controller without undue delay.
(2) Notification duties. The Processor informs the Controller without undue delay, and at the latest within 24 hours of becoming aware of any personal data breach, and provides the information required to comply with Art. 33 and 34 GDPR.
(3) Data protection impact assessment. The Processor assists the Controller with data protection impact assessments and prior consultations (Art. 35 and 36 GDPR), insofar as the necessary information lies within its sphere.
§ 9 Evidence and audits
(1) On request, the Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, in particular the current version of Annex 1.
(2) The Controller is entitled to satisfy itself of compliance. Audits are to be carried out with reasonable notice of at least 14 days, during normal business hours, and without disrupting operations. The Processor may make audits conditional on an obligation of confidentiality.
(3) The Processor expressly points out that it holds no certification under ISO 27001, SOC 2 or comparable standards. Compliance is demonstrated by the documentation under Annex 1 and by the audit right under paragraph 2.
§ 10 Deletion and return
(1) Raw data. Audio and video data are deleted from the Processor's systems immediately after the transcription completes or fails. No storage beyond that takes place.
(2) Transcripts. Generated transcripts are retained in the Controller's account for 365 days from the day the transcription job was created, and are then erased automatically together with the stored result file. The Controller can erase a transcript at any time before that.
(3) After the contract ends. After the main contract ends, the Processor deletes all personal data processed on the Controller's behalf within 30 days, unless a statutory retention obligation prevents this. At the Controller's request, the data is returned beforehand in a common, machine-readable format.
(4) Backup copies. Data contained in backups is not deleted separately. It is overwritten in the regular rotation cycle; the maximum retention period of a backup is stated in Annex 1. Where a restore from a backup takes place, data deleted in the meantime is deleted again.
§ 11 Liability
Art. 82 GDPR applies. The liability provisions of the main contract otherwise remain unaffected.
§ 12 Final provisions
(1) Amendments and additions require text form.
(2) In the event of contradictions between this agreement and the main contract, the provisions of this agreement prevail in matters of data protection.
(3) Should any provision be or become invalid, the validity of the remaining provisions remains unaffected.
(4) The law of the Federal Republic of Germany applies.
Annex 1 — Technical and organisational measures (Art. 32 GDPR)
Last updated: 2026-09-09.
This annex describes the actual state of affairs. Where a measure is not implemented, that is stated explicitly — an annex that promises more than exists is worse than none at all.
1. Confidentiality
Physical access control. The servers are located in secured premises in Germany. Physical access by the owner alone.
System access control. Access to production systems exclusively over SSH with key authentication. Password-based login disabled. The service is reachable from the internet only through the upstream reverse proxy; direct connections to the origin server are refused.
Data access control. API keys are stored as hashes only; the plaintext exists once, when it is issued. Passwords are stored salted and hashed. Administrative endpoints are separately protected. Rate limiting per IP address on all authentication-adjacent endpoints.
Separation control. Tenant separation at application level through the user assignment of every record. Production and test run in entirely separate environments; they share neither data nor processing resources.
2. Integrity
Transfer control. Transport exclusively over TLS 1.2 or higher. HSTS with includeSubDomains and preload. Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy set on all delivery paths.
Input control. Logging of security-relevant events (logins, key usage, administrative access) with timestamps. IP addresses are masked in logs. Logs are deleted automatically after at most 14 days.
3. Availability and resilience
Availability control. Automated monitoring of the service every two minutes with alerting on the first failure. Upstream service for mitigating overload attacks. A defined maintenance mode that serves a maintenance page during planned work and brings running processing to an orderly close beforehand.
Backups. Automated daily, weekly, monthly and annual backup of the database to a separate storage system at the same location. Consistent snapshot taken while the service is running. Maximum retention of a backup: one year.
Stated openly: the backups are not stored encrypted. They reside on a separate, physically secured storage system at the same location and do not leave it. The Controller is expressly informed of this so that it can take it into account in its own risk assessment.
Recoverability. Documented restore procedure.
4. Procedures for regular review
Data protection management. Documented legal review of the service, maintained on an ongoing basis. Data processing agreements are in place with all sub-processors.
Contract control. Sub-processors are selected on data protection criteria; the Processor's own obligations are passed on to them.
Data protection by default. Raw data is deleted immediately after processing. The website uses no cookies, no third-party analytics and no storage on end devices beyond what is technically necessary. The data is not used for training purposes.
Not in place: certifications under ISO 27001, SOC 2 or comparable standards. There is no designated data protection officer; no obligation to designate one arises under Art. 37 GDPR or § 38 BDSG.
Annex 2 — Sub-processors
Last updated: 2026-09-09. Current version at <https://vibevoice.net/subprocessors>.
| Service provider | Location | Purpose | Data concerned | Third-country basis |
|---|---|---|---|---|
| VibeVoice (own servers) | Germany | Transcription, account data | Audio, video, transcripts, account data | not applicable |
| Cloudflare, Inc. | USA / EU data centres | Delivery, attack mitigation, TLS | Connection data, IP address | SCC, DPF |
| ActiveCampaign (Postmark) | USA | Transactional email | Email address, sending metadata | SCC, DPF |
| Stripe Payments Europe, Ltd. | Ireland | Payment processing | Payment and invoicing data | not applicable (EU) |
| Meta Platforms Ireland Ltd. | Ireland | only when the WhatsApp route is used | Phone number, message content | not applicable (EU) |
Note on scope. Cloudflare and Postmark process no audio, video or transcript data. Cloudflare sees connection metadata, Postmark only email addresses and sending metadata. The content itself does not leave Germany.
This document is provided in signed form on request at [email protected].