When you use the VoiceHelden AI phone assistant, we process personal data belonging to the people who call your business. That requires a data processing agreement, and this is it. You accept it when you take out your subscription; we record which version you accepted, so it can later be established which text applied.
1Parties and precedence
This data processing agreement forms part of the terms and conditions and cannot be separated from them. You are the controller of the personal data processed through the AI phone assistant; Dirivian B.V. is the processor.
Where this agreement differs from the terms and conditions, this agreement prevails on matters of data processing.
2What we process, and why
Purpose and nature: answering your inbound calls with an AI assistant, answering questions, booking appointments in your calendar, and making a summary and transcript of each call available in your dashboard. We process only on your instruction; that instruction consists of your use of the service and the configuration you set in your account.
Data subjects: the people who call your business, and the users of your account.
Categories of data:
- The number the call is made from.
- The name the caller gives, and an email address if the caller volunteers one.
- The call audio, during the call, in order to understand and answer it.
- The transcript and a summary of the call, plus date, time and duration.
- The appointment details written into your calendar.
- About you: name, email, phone number, company name, opening hours and billing details.
A caller may volunteer sensitive information — a health complaint, for instance. We never ask for it; it is processed only because it occurs in the call. If you use the service in a sector where that happens structurally, contact us first: that needs more than this agreement.
3Confidentiality and security
Everyone at our end with access to this data is bound to confidentiality. Access is limited to those who need it to run or support the service.
The measures we take:
- Encryption in transit (TLS) and at rest with our cloud provider.
- Access to your data is partitioned per account: a user sees only their own account's calls.
- Sign-in runs through Google. We store no passwords ourselves.
- Administrative access to our systems is limited to named individuals and runs through Google Cloud identity and access management.
- Audit logs of system actions, which do not contain the content of calls.
We currently hold no ISO 27001, SOC 2 or equivalent certification, and we do not claim to. If your own policy requires one, tell us before you start using the service.
4Sub-processors
You give us general authorisation to engage sub-processors. These are the parties we use as of 1 September 2026:
- Google Cloud / Firebase — hosting, database and running our software. Database in Europe; some processing functions in the United States (see the next article).
- Google (Gemini) — the language model that understands and answers the call. Call audio and the transcript pass through it.
- Telnyx — telephony: your 085 number and call transport. Processes phone numbers and traffic data.
- Stripe — payments and invoicing. Processes your data, not your callers'. We store no card details ourselves.
- HighLevel (GoHighLevel) — only for enquiries you submit through our website and for WhatsApp messages to you. Not for your call data.
If we replace or add a sub-processor, we tell you at least thirty days in advance by email to your account address. If you object within that period and we cannot resolve it, you may terminate immediately at no cost for the remaining term.
5Where your data sits
We would rather be precise than reassuring here, because this is where suppliers usually turn vague.
- Your data is stored in Europe. The database holding calls, transcripts, appointments and account data runs in
europe-west1(Belgium). Verified 3 September 2026. - Telephony and the speech-processing service also run in Europe (
europe-west4, the Netherlands). - Part of our processing software, the background functions that read and write the database, currently runs in the United States. So your data is kept in Europe but passes a US server while being processed. That transfer relies on the EU-US Data Privacy Framework and, where it does not apply, the European Commission's standard contractual clauses.
- Google's language model processes calls outside an EU region we pin.
Those last two points are what still separates us from "everything in Europe", and the first of them is a move of days rather than months: the storage does not have to come along. If you have a hard requirement that all processing stays in the EU, contact us and we will tell you where we stand and when we expect to be there.
6Retention and deletion
Call data stays in your account for as long as your subscription runs. There is currently no automatic retention window on transcripts: they do not disappear by themselves after some months. If you want a shorter period, we agree it with you and put it in place.
If you cancel, you delete your account yourself in the app; we delete your data and your callers' data, except what we are legally required to keep (billing records, seven years under Dutch tax law). If you ask us to delete, we do it within thirty days.
One exception we name explicitly because it is easily forgotten: appointments the assistant wrote into your own Google Calendar sit in your calendar. We cannot delete those for you; you do that yourself.
7Requests from callers
A caller wanting access, correction or deletion turns to you — you are their point of contact. We help: tell us and we locate the calls concerned and delete or export them. We charge nothing for this, unless it becomes a structural stream of requests.
If a request reaches us by mistake, we refer the person to you and let you know. We never handle such a request ourselves without your instruction.
8Data breaches
If we become aware of a security breach involving your data or your callers' data, we report it without undue delay and in any case within 48 hours of discovery, by email and by phone using your account details. We say what happened, which data is involved, what we are doing, and what you should do.
Notifying the Dutch DPA and the data subjects is yours to do, as controller. We supply the information you need for it.
9Audit and information
You may ask us to demonstrate that we comply with this agreement, and we supply that information on request. If you want an audit by an independent party, that is possible once a year at most, at your expense, with at least thirty days' notice, and without exposing our other customers' data.
10Term, changes and liability
This agreement applies for as long as we process data for you, and ends when we stop and have deleted the data.
If we change this agreement, we publish a new version with a new version number and tell you by email. If a change materially worsens your position, you may terminate within thirty days. Every version stays available on request, so it can be established which text applied at the moment you accepted.
Dutch law applies. The liability provisions of the terms and conditions apply here too, save that they do not exclude a regulatory fine attributable to our own failure.
11Contact
Dirivian B.V., trading as VoiceHelden.
Science Park 608, Unit A.08, 1098 XH Amsterdam
info@voicehelden.nl
How we handle personal data outside this agreement is in our privacy policy. We have not appointed a data protection officer; a company of this size is not required to.
This agreement was last changed on 1 September 2026 (version 2026-09-01). We keep every version; to see an earlier one, request it at info@voicehelden.nl.