AttestVoice
עבריתSign inStart free trial

Data Processing Agreement — AttestVoice

Version: 1.0 ·

This is a convenience translation; the binding version is the Hebrew original. זהו תרגום נוחות; הנוסח המחייב הוא המקור העברי.

Annex to the subscription agreement for business customers.

Between: the Customer — the controller of the database (Controller), and the operator of AttestVoice — the holder (Processor).

1. Definitions and scope

"Customer Data" — any personal data in content the Customer uploads or creates in the Service. This agreement applies to all processing of Customer Data by the Processor on behalf of the Customer, under the Protection of Privacy Law (as amended by Amendment 13), the Protection of Privacy (Data Security) Regulations, 5777-2017 — and it also constitutes the agreement required under regulation 15 of the Regulations (outsourcing) — and under GDPR Art. 28 where applicable.

2. Processing instructions

2.1 The Processor shall process Customer Data solely for the purpose of providing the Service and in accordance with the Customer's documented instructions (storage region, retention period, "local only" flag).

2.2 The Processor shall not use Customer Data for model training, advertising or any independent purpose.

2.3 The recording announcement and its documentation are part of the Service's default protective measures (Privacy by Default). Any deviation from the default is a processing instruction of the Customer (the controller), documented in the audit log, and under the Customer's sole responsibility.

3. Confidentiality

Everyone accessing Customer Data on the Processor's behalf (including proofreaders in the Certified service) is bound by confidentiality; their access is limited to what is necessary and documented in an audit log.

4. Security (regulation 15(a)(2) and the Data Security Regulations)

High security level: encryption in transit and at rest; a dedicated data key (DEK) for every recording under KMS; role-based access controls and two-factor authentication (mandatory for administrators); a SHA-256 signature for every evidentiary file; an append-only audit log protected at the database level; WORM storage for evidentiary content; environment separation; daily backup and documented restore drills (RTO target: minutes); ongoing adversarial reviews. A change of measures shall not reduce the level of protection.

5. Sub-processors

5.1 The Customer approves the sub-processors in Annex A. An addition — with 14 days' prior notice; the Customer has a reasonable right to object.

5.2 Annex A (07.09.2026): Hetzner (Germany — compute); AWS (Israel il-central-1 / Germany eu-central-1 — storage and KMS); RunPod (GPU processing — data centres in the European Union only, pinned region, no retention of content beyond processing time); Anthropic and Google (text polishing — text segments only, never audio or identifiers; does not apply to a "local only" organisation); Cardcom (payment processing, Israel); Paddle (international payment processing); operational mailing and SMS providers as will be specified.

5.3 The Processor is liable to the Customer for the acts of its sub-processors as for its own acts, and binds every sub-processor to an undertaking as required by regulation 3 of the Transfer of Data Regulations (privacy measures and prohibition of onward transfer).

6. Assistance with data subject rights

A request under sections 13–14 of the Law (access, rectification, deletion of inaccurate data) or under the GDPR that reaches the Processor directly — shall be forwarded to the Customer within 5 business days, together with assistance through the system's tools (locating, exporting, documented deletion).

7. Security incident

The Processor shall notify the Customer of a security incident concerning its data without delay and no later than 72 hours from its discovery, together with what is known, the actions taken and recommendations. A serious security incident as defined in the Regulations shall also be reported by the Processor to the Privacy Protection Authority as required by regulation 11; the Processor's notice does not derogate from the Customer's independent reporting duties.

8. Retention, return and deletion

At the end of the engagement: export available for 30 days; thereafter full deletion with a certificate. Deletion of evidentiary content is performed by destroying the encryption key (crypto-erasure): the locked content becomes permanently unreadable, a signed destruction certificate is issued, and deletion becomes final after 7 days (the key-backup window). Deletion is deferred only where a statutory retention duty, a court order or a retention period set by the Customer on the Comply track applies — and is performed when they expire. The parties confirm that this mechanism is the agreed means of deletion for content locked against changes.

9. Audit

Once a year, coordinated 30 days in advance, the Customer (or an auditor on its behalf who is not a competitor) shall receive the audit and security reports; an independent penetration test — by agreement and on reasonable terms.

10. International transfers

Customer Data is stored in the region chosen by the Customer and is not transferred from it except to the sub-processors in Annex A. The basis for transfers outside Israel: regulation 2(8) of the Transfer of Data Regulations (countries party to the European Convention for the protection of individuals or receiving data from EU member states under the same conditions) together with the undertakings of regulation 3, and for GDPR customers — the provisions of Chapter V thereof.

11. Liability

The Processor's liability under this agreement is subject to the liability cap in the subscription agreement, except for damage caused wilfully or by gross negligence, and except for liability that cannot be limited by law.

Annex B (description of processing): data subjects — the Customer's employees, its customers and parties to recorded conversations; data types — voice, transcripts, contact details, metadata; may include data of special sensitivity depending on the content; duration — as set out in section 8.