Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Aivonic AB (org. no. 559483-4961, Spovgränd 1, 383 35 Mönsterås, Sweden) ("Processor", "Aivonic", "we") and the customer ("Controller", "you") for the Aivonic services (the "Services").
Where you process personal data of third parties using the Services, you are the Controller and Aivonic is the Processor. If there is a conflict between this DPA and the rest of the agreement, this DPA governs for data-protection matters.
How this DPA is entered into
This DPA is incorporated by reference into whichever agreement you took the Services under:
- the Aivonic Service Terms, for Voice AI customers and for customers of bespoke AI agents; and
- the Aivonic Workspace Terms of Service, for Aivonic Workspace and AivoniClaw customers.
No separate signature is required for it to apply. If your organisation needs a countersigned standalone copy for its own records, request one at privacy@aivonic.ai and we will return an executed copy naming both parties.
1. Definitions
"GDPR", "personal data", "processing", "data subject", "controller", "processor", "sub-processor" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679). "Applicable Data Protection Law" means the GDPR and Swedish implementing law.
2. Roles and scope
2.1 The Controller determines the purposes and means of processing. Aivonic processes personal data only as a Processor, on the Controller's documented instructions, in order to provide the Services. Using the Services in accordance with the agreement is a documented instruction.
2.2 The details of the processing are set out in Annex I (subject matter, duration, nature and purpose, data types, data subjects).
2.3 This DPA applies to all Services the Controller uses, including Aivonic Workspace, AivoniClaw, bespoke AI agents and the Voice AI product. Where the Controller uses Voice AI, Annex I-A applies in addition to Annex I and governs in the event of a conflict on voice matters.
2.4 Configuration choices the Controller makes for an agent, including whether calls are recorded and for how long recordings and transcripts are retained, are documented instructions for the purposes of clause 2.1.
3. Controller obligations and warranties
3.1 The Controller warrants that it has a valid legal basis, and has given all required notices, for the personal data it processes via the Services.
3.2 Outreach. Where the Controller uses the AivoniClaw outreach features, the Controller further warrants that it has a lawful basis (for example legitimate interest supported by a documented balancing test, or consent) to contact the recipients it loads into the Services, and that it complies with applicable e-privacy and marketing law, including the ePrivacy Directive and any local anti-spam law applicable where a recipient is located.
3.3 Voice AI recording. Where the Controller enables call recording, the Controller warrants that it has a valid legal basis for recording and for the retention period it has selected, and that it complies with applicable law on informing callers that a call is recorded. Aivonic provides the technical means to give that notice, by having the agent state it in the opening seconds of the call, and will not disable that notice except on the Controller's instruction. Aivonic supplying the words the agent speaks does not transfer the legal duty to inform the caller, which remains the Controller's. Where the Controller instructs that calls are not recorded, Aivonic creates no call audio.
3.4 The Controller will not instruct Aivonic to process personal data unlawfully.
4. Aivonic (Processor) obligations
Aivonic will:
- (a) process personal data only on the Controller's documented instructions, including as regards transfers, unless required to do otherwise by EU or Member State law, in which case Aivonic informs the Controller before processing unless that law prohibits it;
- (b) ensure that persons authorised to process personal data are bound by confidentiality;
- (c) implement the technical and organisational measures set out in Annex II (Article 32);
- (d) respect the conditions for engaging sub-processors set out in clause 5;
- (e) assist the Controller, taking into account the nature of the processing, in responding to data-subject requests under Articles 12 to 23;
- (f) assist the Controller with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments, prior consultation);
- (g) at the Controller's choice, delete or return all personal data at the end of the provision of the Services, and delete existing copies unless retention is required by law;
- (h) make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, as set out in clause 8.
5. Sub-processors
5.1 The Controller gives Aivonic general authorisation to engage the sub-processors listed at aivonic.ai/legal/subprocessors, reproduced in Annex III below. That page is the operative list and is kept current.
5.2 Aivonic imposes on each sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.
5.3 Aivonic gives at least 30 days' notice of an intended addition or replacement of a sub-processor. The Controller may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected Service without penalty for the unused remainder of any prepaid term.
6. International transfers
6.1 Where Aivonic transfers personal data to a sub-processor outside the EEA, it does so under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three (processor to processor), which are incorporated into this DPA by reference, or under the EU-US Data Privacy Framework where the recipient is certified under it, in each case with supplementary measures where appropriate.
6.2 Where the Controller is established outside the EEA and personal data is transferred from Aivonic to the Controller, Module Four (processor to controller) applies. Where personal data is transferred from a Controller inside the EEA to a recipient outside it under Aivonic's instruction, Module Two (controller to processor) applies.
6.3 The transfer mechanism that applies to each sub-processor is stated against that sub-processor in Annex III.
7. Personal data breach
Aivonic will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably available to it to assist the Controller with its obligations under Articles 33 and 34.
8. Audit
Aivonic will make available the information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, once per twelve-month period, on reasonable notice, during business hours and subject to confidentiality. Aivonic may satisfy this by providing third-party reports or certifications where they are available and address the Controller's questions.
9. Liability and term
This DPA takes effect when the Controller first uses the Services and remains in effect for as long as Aivonic processes personal data on the Controller's behalf. Liability under this DPA is subject to the limitations of liability in the agreement it forms part of, except where applicable law does not permit those limitations to apply.
Annex I: description of the processing
- Subject matter. Provision of the Aivonic Services to the Controller.
- Duration. The term of the agreement, plus the deletion or return period in clause 4(g).
- Nature and purpose. Hosting; AI processing of the Controller's content; workspace collaboration and CRM; for AivoniClaw, automated outreach and reply handling; and for Voice AI, answering and placing telephone calls on the Controller's behalf. In each case on the Controller's instruction and for the purpose of delivering the Services.
- Types of personal data. Account and contact details of the Controller's staff; contact details of the Controller's customers, leads and outreach recipients; the content of emails and messages sent or received through the Services; documents and files the Controller uploads; and, for Voice AI, the caller's telephone number, the audio recording of the call where recording is enabled, the transcript of the call, and anything the caller says during it.
- Special categories of personal data. None is requested or required. Aivonic does not ask for special-category data. A caller may nevertheless volunteer such data during a call, in which case it is processed only as part of the recording and transcript under this DPA and deleted on the retention schedule in Annex I-A.
- Categories of data subject. The Controller's staff; the Controller's customers and prospective customers; recipients of outreach; and callers to or from a voice agent.
- Frequency. Continuous for the duration of the agreement.
Annex I-A: Voice AI processing
Applies where the Controller uses the Voice AI product.
- Recording. Whether calls are recorded is a per-agent setting configured on the Controller's instruction. Where recording is enabled, the agent discloses it in the opening seconds of the call. Where recording is disabled, no audio file is created at all, only a transcript.
- Retention. Unless otherwise agreed in writing, call audio is deleted after 30 days and transcripts after 90 days. Deletion is carried out by a scheduled process that runs nightly, not on request, and the same process also removes audio that is no longer referenced by a call record. Where a different period is agreed, the agent configuration is changed to match, so the configured period and the stated period cannot diverge.
- Storage. Call audio is stored on Aivonic's own infrastructure. No third-party storage sub-processor is engaged for call recordings. Hosting location: Frankfurt, Germany (EEA).
- Client portal. The Controller accesses its call records, transcripts and recordings through the Voice AI client portal at
voice.aivonic.ai, which Aivonic hosts and operates. Recordings are served from Aivonic's own storage on the same infrastructure rather than from a third-party host. Access requires authentication, and each customer sees only its own agents' calls. - Deletion reaches the portal. When a recording passes its retention period it is deleted from storage and the reference to it is cleared, so it stops being retrievable through the portal at the same time. Retention is not a display rule.
- Sub-processors. The speech-to-text, text-to-speech, language model and media-transport providers listed under "Voice AI" in Annex III process call content. Which text-to-speech provider applies depends on the voice selected for the agent.
Annex II: technical and organisational measures (Article 32)
Aivonic implements at least the following:
- Encryption in transit (TLS) for customer-facing traffic and for traffic between Aivonic services and its sub-processors.
- Encryption at rest for the databases and for call recordings, which are held on an encrypted volume (LUKS2, AES-XTS, 512-bit key).
- Encrypted database backups (AES-256), taken nightly, held both on the server and on separate infrastructure, with the decryption key held apart from them.
- Per-tenant data isolation, so one customer's data is not reachable from another customer's session.
- Role-based access control, least-privilege access for operators, and hashed credentials.
- Authenticated access to the client portals, scoped so each customer sees only its own data.
- Self-hosted storage for call recordings and generated artifacts, rather than a third-party host.
- Logging and monitoring of the production services, with alerting on failure.
- A documented personal data breach response procedure.
- Automated deletion of call audio and transcripts at the end of the retention period, carried out by a scheduled job rather than on request, which also removes audio no longer referenced by a call record.
Aivonic makes no claim in this Annex to any measure it has not implemented, and states the limits of the encryption above rather than leaving them to be inferred. The host operating system volume is not encrypted. The encrypted volume is opened with a passphrase that is not stored on the server, so a copy of the server's disks does not contain the means to read it. It does not protect against an attacker who has gained access to the running server while the volume is open. The nightly database backups are encrypted separately, with their key held apart from the backup files. Aivonic holds no external security certification. Aivonic will state the current position in writing on request, and will update this Annex if it changes.
Annex III: approved sub-processors
The authoritative list is published at aivonic.ai/legal/subprocessors and is reproduced below. It is kept current, and clause 5.3 governs changes to it. The list covers every Service; the sub-processors that apply to a given Controller are those for the Services that Controller uses.
Infrastructure and hosting
All services.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Hostinger International Ltd | Server hosting (VPS). Runs the voice stack, the Voice AI client portal at voice.aivonic.ai, the agent client portal at agents.aivonic.ai, and the call-recording storage. Hostinger also takes weekly whole-server backup images, which it stores in Lithuania. | Frankfurt, Germany (EEA). Hostinger-held server backups are stored in Lithuania (EEA). | Processing within the EEA |
Aivonic operates its own object storage, its own databases and its own self-hosted language models on the infrastructure above. Those are run by Aivonic and are not third-party sub-processors.
AI and language models
All services, depending on which model answers a given request.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Mistral AI | Language model inference. Mistral is the language model for every Voice AI call. | France (European Union) | Processing within the EEA |
| Anthropic, PBC | Language model inference where an Aivonic-operated model is not used, including the automatic fallback for chat agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenAI, L.L.C. | Language model inference where selected for an Aivonic-operated feature. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic runs its own language models on its own hardware. Where an Aivonic-operated model answers, no third-party model provider receives the content.
Bring your own key: where a customer configures their own AI provider key, that provider is engaged by the customer under the customer’s own terms with that provider, and is not an Aivonic sub-processor.
Outreach and email
Only customers using the AivoniClaw outreach features.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Smartlead | Email sending, warmup, inbox rotation and reply detection. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Apollo.io | Lead and contact sourcing and enrichment. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| AgentMail | Inbound and outbound email handling for agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| NeverBounce | Email address verification before sending. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Messaging, payments, scheduling and analytics
Customers using the corresponding channel or integration.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Meta Platforms (WhatsApp Cloud API) | WhatsApp messaging, where a customer enables the WhatsApp channel. | Ireland (European Union) and United States | Standard Contractual Clauses where the transfer leaves the EEA |
| Stripe | Subscription billing and payments. | Ireland (European Union) and United States | Standard Contractual Clauses. Stripe acts as an independent controller for card data. |
| Cal.com | Appointment scheduling, where an agent books meetings. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic's own website and sales lead handling
No customer. These process data about people who visit aivonic.ai or submit our own enquiry form, where Aivonic is the controller. They are recipients under our Privacy Policy, not sub-processors for anyone's data.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Netlify, Inc. | Hosting, CDN and authoritative DNS for the aivonic.ai marketing website. Netlify serves that website only. It is not part of the Voice AI stack, the client portals, Workspace or AivoniClaw, and it never receives customer data. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Google (Analytics and Tag Manager) | Visitor analytics on the aivonic.ai marketing website only, and only where the visitor has accepted analytics cookies. Not present in any product. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Tavily | Extracts the readable text of the website a sales enquiry names, so we can prepare for the call back. Receives the URL supplied on the form, not the enquirer's own details. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenRouter | Generates the business summary and the sales briefing used to prepare for a call back to someone who submitted our enquiry form. Receives the business name, website and the extracted website text. OpenRouter routes the request onward to the model providers it selects. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Voice AI
Only customers using the Voice AI product.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Deepgram | Speech to text. | United States company. Aivonic routes speech recognition to Deepgram’s EU endpoint by default for all calls. | Standard Contractual Clauses (Module Three, processor to processor) |
| ElevenLabs | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Inworld | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Cartesia | Text to speech, automatic failover only. Engaged when the selected voice provider is unavailable, so that a provider outage does not drop a call in progress. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Mistral AI | Language model for voice agents. | France (European Union) | Processing within the EEA |
| LiveKit | Real-time audio transport. | United States company. Aivonic’s rooms are served from LiveKit’s European region, so call audio in transit is handled within the EEA. | Standard Contractual Clauses (Module Three, processor to processor) |
| 46elks | Telephony and SIP connectivity (Swedish numbers). | Sweden (European Union) | Processing within the EEA |
| Twilio | Telephony and SIP connectivity, where used for a given number. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Which text-to-speech provider processes a given call depends on the voice selected for that agent. Aivonic confirms on request which providers apply to a specific customer’s agents.
Call recordings are stored on Aivonic’s own infrastructure. No third-party storage provider is engaged for call audio.
The Voice AI client portal at voice.aivonic.ai is Aivonic’s own product, not a third party. It adds no sub-processor, but it is where the customer accesses the data, so the hosting location above governs it.
Contact
Aivonic AB, org. no. 559483-4961, Spovgränd 1, 383 35 Mönsterås, Sweden.
Data-protection matters: privacy@aivonic.ai