Loading
Preparing your workspace
Effective Date: 22 July 2026 | Last Updated: 22 July 2026
This Data Processing Agreement ("DPA") describes how Voaise Technologies ("Voaise," "we," "our," or "us") processes personal data in connection with the Voaise platform, the VoaiseGlass mobile application, Voaise AI Smart Glasses, and the in-app AI assistant (together, the "Service"), as described in our Privacy Policy and Terms of Service.
For the great majority of Voaise users — individuals who create a personal account and use the Service for their own purposes — Voaise acts as the data controller (or "data fiduciary" under India's Digital Personal Data Protection Act, 2023), and our Privacy Policy is the primary document governing that relationship. This DPA becomes operative, in addition to the Privacy Policy, when an organization deploys the Service to its own members, employees, or end users — in that case Voaise acts as a data processor on the organization's behalf, and Section 3.2 through Section 12 of this DPA apply to that processing. If you are such an organization and require a countersigned DPA (for example, under GDPR Article 28) for your own compliance records, contact legal@voaise.com and we will provide one reflecting the terms below.
When you create a personal Voaise account and use the Service for yourself, Voaise determines the purposes and means of processing your data (subject to the choices and controls described in our Privacy Policy) and is therefore the Controller. This DPA's sub-processor list, security measures, and breach-notification commitments (Sections 5, 6, and 8) describe our practices to you as well, but the formal processor obligations in Sections 4 and 7 are addressed to organizational customers.
If you are an organization that provisions Voaise accounts for your members, employees, or end users under a business arrangement with Voaise, you are the Controller of the Personal Data of those individuals, and Voaise is the Processor, acting only on your documented instructions as set out in your order form, admin console configuration, or a signed agreement referencing this DPA.
Where Voaise acts as Processor under Section 3.2, Voaise will:
Voaise uses the following categories of Sub-processors to provide the Service. We select Sub-processors that offer appropriate technical and organisational safeguards, and we limit what each one receives to the minimum needed for its function.
Organizational Controllers under Section 3.2 may request the current named-vendor list for these categories by emailing legal@voaise.com, and will be notified of any new Sub-processor with a category above before it begins processing, with an opportunity to object on reasonable data-protection grounds.
Voaise implements the technical and organisational measures described in Section 6 of our Privacy Policy, including per-account envelope encryption of sensitive data at rest, TLS 1.2+ in transit, AES-256-GCM encryption of third-party credentials, JWT-based authentication, automated isolation checks between accounts, and per-device rate limiting. These measures are reviewed and updated as the Service evolves.
Voaise provides individual users the self-service rights described in Section 9 of our Privacy Policy (access, correction, deletion, export, and others). Where Voaise acts as Processor for an organizational Controller under Section 3.2, and a Data Subject contacts Voaise directly regarding their rights, Voaise will promptly redirect the request to the Controller and provide reasonable assistance to the Controller in fulfilling it, unless the Controller has instructed otherwise.
If Voaise becomes aware of a Personal Data breach affecting your data, we will notify you without undue delay, and in the case of an organizational Controller under Section 3.2, no later than 72 hours after becoming aware of the breach, with the information reasonably available to us at that time, including the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address it. We will provide further information as our investigation progresses.
As described in Section 7 of our Privacy Policy, Personal Data may be processed by Sub-processors located in India, the United States, or the European Union, depending on which provider is invoked for a given request. Where a transfer is subject to GDPR Chapter V or an equivalent cross-border transfer regime, Voaise relies on the transfer mechanism recognised under that Sub-processor's own compliance program (such as Standard Contractual Clauses or an adequacy decision), and will provide details on request.
Personal Data is retained in accordance with Section 8 of our Privacy Policy. On account deletion, data is preserved for a 30-day grace period and then permanently purged, with a small number of exceptions (payment/tax records retained for statutory periods, and safety-incident logs retained for audit purposes) as described there. Organizational Controllers under Section 3.2 may request deletion or export of their end users' data on the same basis, subject to the same statutory exceptions.
Organizational Controllers under Section 3.2 may request information reasonably necessary to demonstrate Voaise's compliance with this DPA, including responses to written security questionnaires. On reasonable prior written notice, and no more than once per 12-month period (except following a confirmed Personal Data breach), Voaise will make relevant personnel reasonably available to discuss compliance with this DPA. On-site or third-party audits are subject to a separate mutually agreed scope, confidentiality terms, and cost allocation.
This DPA remains in effect for as long as Voaise processes Personal Data on your behalf. It is governed by, and forms part of, the same governing law and dispute resolution terms as our Terms of Service (Section 16: laws of India, arbitration in Guwahati, Assam). Liability under this DPA is subject to the limitation of liability in Section 14 of the Terms of Service, except where such limitation is not permitted by applicable data protection law.
For questions about this DPA, to request the current named Sub-processor list, or to request a countersigned copy referencing your organization:
Email: legal@voaise.com
Address: Akshoy Rani Bhawan, Kamakhaya Gate, Guwahati City, Assam.
Website: voaise.com