Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Aivonic Labs AB (org. no. 559483-4961, Spovgränd 1, 383 35 Mönsterås, Sweden) ("Processor", "Aivonic Labs", "we") and the customer ("Controller", "you") for the Aivonic Labs services (the "Services").
Where you process personal data of third parties using the Services, you are the Controller and Aivonic Labs is the Processor. If there is a conflict between this DPA and the rest of the agreement, this DPA governs for data-protection matters.
How this DPA is entered into
This DPA is incorporated by reference into whichever agreement you took the Services under:
- the Aivonic Labs Service Terms, for Voice AI customers and for customers of bespoke AI agents; and
- the Aivonic Workspace Terms of Service, for Aivonic Workspace and AivoniClaw customers.
No separate signature is required for it to apply. If your organisation needs a countersigned standalone copy for its own records, request one at privacy@aivonic.ai and we will return an executed copy naming both parties.
1. Definitions
"GDPR", "personal data", "processing", "data subject", "controller", "processor", "sub-processor" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679). "Applicable Data Protection Law" means the GDPR and Swedish implementing law.
2. Roles and scope
2.1 The Controller determines the purposes and means of processing. Aivonic Labs processes personal data only as a Processor, on the Controller's documented instructions, in order to provide the Services. Using the Services in accordance with the agreement is a documented instruction.
2.2 The details of the processing are set out in Annex I (subject matter, duration, nature and purpose, data types, data subjects).
2.3 This DPA applies to all Services the Controller uses, including Aivonic Workspace, AivoniClaw, bespoke AI agents and the Voice AI product. Where the Controller uses Voice AI, Annex I-A applies in addition to Annex I and governs in the event of a conflict on voice matters.
2.4 Configuration choices the Controller makes for an agent, including whether calls are recorded and for how long recordings and transcripts are retained, are documented instructions for the purposes of clause 2.1.
3. Controller obligations and warranties
3.1 The Controller warrants that it has a valid legal basis, and has given all required notices, for the personal data it processes via the Services.
3.2 Outreach. Where the Controller uses the AivoniClaw outreach features, the Controller further warrants that it has a lawful basis (for example legitimate interest supported by a documented balancing test, or consent) to contact the recipients it loads into the Services, and that it complies with applicable e-privacy and marketing law, including the ePrivacy Directive and any local anti-spam law applicable where a recipient is located.
3.3 Voice AI recording. Where the Controller enables call recording, the Controller warrants that it has a valid legal basis for recording and for the retention period it has selected, and that it complies with applicable law on informing callers that a call is recorded. Aivonic Labs provides the technical means to give that notice, by having the agent state it in the opening seconds of the call, and will not disable that notice except on the Controller's instruction. Aivonic Labs supplying the words the agent speaks does not transfer the legal duty to inform the caller, which remains the Controller's. Where the Controller instructs that calls are not recorded, Aivonic Labs creates no call audio.
3.4 The Controller will not instruct Aivonic Labs to process personal data unlawfully.
4. Aivonic Labs (Processor) obligations
Aivonic Labs will:
- (a) process personal data only on the Controller's documented instructions, including as regards transfers, unless required to do otherwise by EU or Member State law, in which case Aivonic Labs informs the Controller before processing unless that law prohibits it;
- (b) ensure that persons authorised to process personal data are bound by confidentiality;
- (c) implement the technical and organisational measures set out in Annex II (Article 32);
- (d) respect the conditions for engaging sub-processors set out in clause 5;
- (e) assist the Controller, taking into account the nature of the processing, in responding to data-subject requests under Articles 12 to 23;
- (f) assist the Controller with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments, prior consultation);
- (g) at the Controller's choice, delete or return all personal data at the end of the provision of the Services, and delete existing copies unless retention is required by law;
- (h) make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, as set out in clause 8;
- (i) immediately inform the Controller if, in Aivonic Labs's opinion, an instruction from the Controller infringes the GDPR or other applicable Union or Member State data protection law. Aivonic Labs may suspend the affected processing, without liability for that suspension, until the instruction is confirmed, amended or withdrawn;
- (j) inform the Controller without undue delay of any request, inquiry or order it receives from a supervisory authority, court, or law enforcement or other public authority that relates to the Controller's personal data, unless that law prohibits the notification. Where the notification is prohibited, Aivonic Labs will use reasonable efforts to obtain a waiver of the prohibition and will challenge the request where there are reasonable grounds to consider it unlawful; and
- (k) refer to the Controller, without undue delay, any request or complaint it receives directly from a data subject or other third party concerning the Controller's personal data. Aivonic Labs will not respond to the substance of such a request itself, except to confirm that it has been referred, unless the Controller instructs otherwise or applicable law requires a response.
5. Sub-processors
5.1 The Controller gives Aivonic Labs general authorisation to engage the sub-processors listed at aivonic.ai/legal/subprocessors, reproduced in Annex III below. That page is the operative list and is kept current.
5.2 Aivonic Labs imposes on each sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.
5.3 Aivonic Labs gives at least 30 days' notice of an intended addition or replacement of a sub-processor. The Controller may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected Service without penalty for the unused remainder of any prepaid term.
6. International transfers
6.1 Where Aivonic Labs transfers personal data to a sub-processor outside the EEA, it does so under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three (processor to processor), which are incorporated into this DPA by reference, or under the EU-US Data Privacy Framework where the recipient is certified under it, in each case with supplementary measures where appropriate.
6.2 Where the Controller is established outside the EEA and personal data is transferred from Aivonic Labs to the Controller, Module Four (processor to controller) applies. Where personal data is transferred from a Controller inside the EEA to a recipient outside it under Aivonic Labs's instruction, Module Two (controller to processor) applies.
6.3 The transfer mechanism that applies to each sub-processor is stated against that sub-processor in Annex III.
6.4 Neither Anthropic nor OpenAI is relied upon under the EU-US Data Privacy Framework. Transfers to them, and to every other recipient outside the EEA listed in Annex III, are made under the Standard Contractual Clauses identified above. In addition to those clauses Aivonic Labs applies the following supplementary measures, and will provide further detail on any specific transfer at the Controller's request:
- (a) processing is carried out on Aivonic Labs's own hardware within the EEA wherever the Service allows it, including the language models used for voice calls and chat, so that the data in those requests is not transferred outside the EEA at all;
- (b) where a sub-processor offers processing in an EEA region, that region is selected; speech recognition is routed to an EU endpoint on this basis;
- (c) data minimisation: only the content necessary to produce the response is sent, and account identifiers rather than customer records are used wherever the Service allows;
- (d) personal data is encrypted in transit using TLS, and encrypted at rest on Aivonic Labs's own infrastructure using full-volume encryption;
- (e) each sub-processor receiving personal data outside the EEA is contractually bound, under its own terms for the interface Aivonic Labs uses, not to train models on data submitted through it and not to retain that data beyond the period needed to return the response and meet its own abuse-monitoring obligations;
- (f) Aivonic Labs maintains no standing bulk export of personal data to any recipient outside the EEA; transfers occur only as part of serving an individual request; and
- (g) where a public authority outside the EEA requests access to personal data, Aivonic Labs acts as set out in clause 4 and in the Standard Contractual Clauses: it notifies the Controller unless prohibited, seeks a waiver of any prohibition, and challenges requests it has reasonable grounds to consider unlawful.
7. Personal data breach
Aivonic Labs will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably available to it to assist the Controller with its obligations under Articles 33 and 34.
8. Audit
8.1 Aivonic Labs will make available the information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, once per twelve-month period, on reasonable notice, during business hours and subject to confidentiality.
8.2 The Controller may additionally audit or inspect, on reasonable notice and without waiting for the next twelve-month period, where: (a) a personal data breach has affected the Controller's personal data; (b) the Controller has reasonable grounds to believe Aivonic Labs is not complying with this DPA; or (c) a supervisory authority requires it.
8.3 Aivonic Labs may offer third-party reports, audits or certifications in the first instance, and the Controller will accept them where they genuinely address its questions. That does not limit the Controller's right to conduct an inspection under clause 8.2, and the choice of whether such a report answers the question is the Controller's, not Aivonic Labs's.
8.4 Each party bears its own costs, save that the Controller bears Aivonic Labs's reasonable costs of an audit under clause 8.1 beyond the first in any twelve-month period, unless the audit reveals a material failure by Aivonic Labs to comply with this DPA.
9. Liability and term
9.1 This DPA takes effect when the Controller first uses the Services and remains in effect for as long as Aivonic Labs processes personal data on the Controller's behalf.
9.2 The Controller may terminate this DPA and the affected Services on written notice, without penalty and without prejudice to any other remedy, if Aivonic Labs is in material breach of this DPA and has not remedied that breach within 30 days of written notice, or immediately where the breach is incapable of remedy. Clause 4(g) (deletion or return of personal data) survives termination.
9.3 Liability under this DPA is subject to the limitations of liability in the agreement it forms part of, except where applicable law does not permit those limitations to apply.
Annex I: description of the processing
- Subject matter. Provision of the Aivonic Labs Services to the Controller.
- Duration. The term of the agreement, plus the deletion or return period in clause 4(g).
- Nature and purpose. Hosting; AI processing of the Controller's content; workspace collaboration and CRM; for AivoniClaw, automated outreach and reply handling; and for Voice AI, answering and placing telephone calls on the Controller's behalf. In each case on the Controller's instruction and for the purpose of delivering the Services.
- Types of personal data. Account and contact details of the Controller's staff; contact details of the Controller's customers, leads and outreach recipients; the content of emails and messages sent or received through the Services; documents and files the Controller uploads; and, for Voice AI, the caller's telephone number, the audio recording of the call where recording is enabled, the transcript of the call, and anything the caller says during it.
- Special categories of personal data. None is requested or required. Aivonic Labs does not ask for special-category data. A caller may nevertheless volunteer such data during a call, in which case it is processed only as part of the recording and transcript under this DPA and deleted on the retention schedule in Annex I-A.
- Categories of data subject. The Controller's staff; the Controller's customers and prospective customers; recipients of outreach; and callers to or from a voice agent.
- Frequency. Continuous for the duration of the agreement.
Annex I-A: Voice AI processing
Applies where the Controller uses the Voice AI product.
- Recording. Whether calls are recorded is a per-agent setting configured on the Controller's instruction. Where recording is enabled, the agent discloses it in the opening seconds of the call. Where recording is disabled, no audio file is created at all, only a transcript.
- Retention. Unless otherwise agreed in writing, call audio is deleted after 30 days and transcripts after 90 days. Deletion is carried out by a scheduled process that runs nightly, not on request, and the same process also removes audio that is no longer referenced by a call record. Where a different period is agreed, the agent configuration is changed to match, so the configured period and the stated period cannot diverge.
- Storage. Call audio is stored on Aivonic Labs's own infrastructure. No third-party storage sub-processor is engaged for call recordings. Hosting location: Frankfurt, Germany (EEA).
- Client portal. The Controller accesses its call records, transcripts and recordings through the Voice AI client portal at
voice.aivonic.ai, which Aivonic Labs hosts and operates. Recordings are served from Aivonic Labs's own storage on the same infrastructure rather than from a third-party host. Access requires authentication, and each customer sees only its own agents' calls. - Deletion reaches the portal. When a recording passes its retention period it is deleted from storage and the reference to it is cleared, so it stops being retrievable through the portal at the same time. Retention is not a display rule.
- Sub-processors. The speech-to-text, text-to-speech, language model and media-transport providers listed under "Voice AI" in Annex III process call content. Which text-to-speech provider applies depends on the voice selected for the agent.
Annex II: technical and organisational measures (Article 32)
Aivonic Labs implements at least the following:
- Encryption in transit (TLS) for customer-facing traffic and for traffic between Aivonic Labs services and its sub-processors.
- Encryption at rest for the databases and for call recordings, which are held on an encrypted volume (LUKS2, AES-XTS, 512-bit key).
- Encrypted database backups (AES-256), taken nightly, held both on the server and on separate infrastructure, with the decryption key held apart from them.
- Per-tenant data isolation, so one customer's data is not reachable from another customer's session.
- Role-based access control, least-privilege access for operators, and hashed credentials.
- Authenticated access to the client portals, scoped so each customer sees only its own data.
- Self-hosted storage for call recordings and generated artifacts, rather than a third-party host.
- Logging and monitoring of the production services, with alerting on failure.
- A documented personal data breach response procedure.
- Automated deletion of call audio and transcripts at the end of the retention period, carried out by a scheduled job rather than on request, which also removes audio no longer referenced by a call record.
Aivonic Labs makes no claim in this Annex to any measure it has not implemented, and states the limits of the encryption above rather than leaving them to be inferred. The host operating system volume is not encrypted. The encrypted volume is opened with a passphrase that is not stored on the server, so a copy of the server's disks does not contain the means to read it. It does not protect against an attacker who has gained access to the running server while the volume is open. The nightly database backups are encrypted separately, with their key held apart from the backup files. Aivonic Labs holds no external security certification. Aivonic Labs will state the current position in writing on request, and will update this Annex if it changes.
Annex III: approved sub-processors
The authoritative list is published at aivonic.ai/legal/subprocessors and is reproduced below. It is kept current, and clause 5.3 governs changes to it. The list covers every Service; the sub-processors that apply to a given Controller are those for the Services that Controller uses.
Infrastructure and hosting
All services.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Hostinger International Ltd | Server hosting (VPS). Runs the voice stack, the Voice AI client portal at voice.aivonic.ai, the agent client portal at agents.aivonic.ai, and the call-recording storage. Hostinger also takes weekly whole-server backup images, which it stores in Lithuania. | Frankfurt, Germany (EEA). Hostinger-held server backups are stored in Lithuania (EEA). | Processing within the EEA |
Aivonic Labs operates its own object storage, its own databases and its own self-hosted language models on the infrastructure above. Those are run by Aivonic Labs and are not third-party sub-processors.
AI and language models
All services, depending on which model answers a given request.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Mistral AI | Language model inference. Mistral's hosted API serves voice calls for some agents, and is the automatic failover for agents that run a self-hosted Mistral model on Aivonic Labs' own hardware. | France (European Union) | Processing within the EEA |
| Anthropic, PBC | Language model inference where an Aivonic Labs-operated model is not used, including the automatic fallback for AI Agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenAI, L.L.C. | Language model inference where selected for an Aivonic Labs-operated feature. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic Labs runs its own language models on its own hardware. Where an Aivonic Labs-operated model answers, no third-party model provider receives the content.
Bring your own key: where a customer configures their own AI provider key, that provider is engaged by the customer under the customer’s own terms with that provider, and is not an Aivonic Labs sub-processor.
Outreach and email
Only customers using the AivoniClaw outreach features.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Smartlead | Email sending, warmup, inbox rotation and reply detection. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Apollo.io | Lead and contact sourcing and enrichment. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| AgentMail | Inbound and outbound email handling for agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| NeverBounce | Email address verification before sending. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Messaging, payments, scheduling and analytics
Customers using the corresponding channel or integration.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Meta Platforms (WhatsApp Cloud API) | WhatsApp messaging, where a customer enables the WhatsApp channel. | Ireland (European Union) and United States | Standard Contractual Clauses where the transfer leaves the EEA |
| Stripe | Subscription billing and payments. | Ireland (European Union) and United States | Standard Contractual Clauses. Stripe acts as an independent controller for card data. |
| Cal.com | Appointment scheduling, where an agent books meetings. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic Labs's own website and sales lead handling
No customer. These process data about people who visit aivonic.ai or submit our own enquiry form, where Aivonic Labs is the controller. They are recipients under our Privacy Policy, not sub-processors for anyone's data.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Netlify, Inc. | Hosting, CDN and authoritative DNS for the aivonic.ai marketing website. Netlify serves that website only. It is not part of the Voice AI stack, the client portals, Workspace or AivoniClaw, and it never receives customer data. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Google (Analytics and Tag Manager) | Visitor analytics on the aivonic.ai marketing website only, and only where the visitor has accepted analytics cookies. Not present in any product. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Tavily | Extracts the readable text of the website a sales enquiry names, so we can prepare for the call back. Receives the URL supplied on the form, not the enquirer's own details. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenRouter | Generates the business summary and the sales briefing used to prepare for a call back to someone who submitted our enquiry form. Receives the business name, website and the extracted website text. OpenRouter routes the request onward to the model providers it selects. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Voice AI
Only customers using the Voice AI product.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Deepgram | Speech to text. | United States company. Aivonic Labs routes speech recognition to Deepgram’s EU endpoint by default for all calls. | Standard Contractual Clauses (Module Three, processor to processor) |
| ElevenLabs | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor). The provider is additionally certified under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. DPF. |
| Inworld | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Cartesia | Text to speech, automatic failover only. Engaged when the selected voice provider is unavailable, so that a provider outage does not drop a call in progress. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Mistral AI | Language model for voice agents. Some agents run a self-hosted Mistral model on Aivonic Labs' own hardware, in which case Mistral's hosted API is the automatic failover only. | France (European Union) | Processing within the EEA |
| LiveKit | Real-time audio transport. | United States company. Aivonic Labs’s rooms are served from LiveKit’s European region, so call audio in transit is handled within the EEA. | Standard Contractual Clauses (Module Three, processor to processor) |
| 46elks | Telephony and SIP connectivity (Swedish numbers). | Sweden (European Union) | Processing within the EEA |
| Twilio | Telephony and SIP connectivity, where used for a given number. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Which text-to-speech provider processes a given call depends on the voice selected for that agent. Aivonic Labs confirms on request which providers apply to a specific customer’s agents.
Call recordings are stored on Aivonic Labs’s own infrastructure. No third-party storage provider is engaged for call audio.
The Voice AI client portal at voice.aivonic.ai is Aivonic Labs’s own product, not a third party. It adds no sub-processor, but it is where the customer accesses the data, so the hosting location above governs it.
Contact
Aivonic Labs AB, org. no. 559483-4961, Spovgränd 1, 383 35 Mönsterås, Sweden.
Data-protection matters: privacy@aivonic.ai