Data Processing Addendum
Last updated 27 August 2026
[…] need a real answer before it is relied on.1. Roles
For personal data processed through your agents — the audio of a call, its transcript, the contact lists you upload and the information an agent collects — you are the controller and Woise is the processor. You decide what the agent is for, who it contacts and what it asks; Woise processes on your instructions.
For your own account data — your name, email, company details and how you use the dashboard — Woise is the controller, and the Privacy Policy governs it rather than this addendum.
2. Subject matter, duration, nature and purpose
Set out in Annex I. Processing continues for as long as your account is active and for the retention periods described in the Privacy Policy.
3. Processing on documented instructions
Woise processes personal data only on your documented instructions, which comprise this addendum, the Terms of Service, and the configuration you set in the product — your agents, prompts, phone numbers, recording settings and integrations. Woise will tell you if an instruction appears to it to infringe applicable data protection law.
Where Woise is required by law to process beyond your instructions, it will inform you before doing so unless that law forbids the notification.
4. Confidentiality
Woise personnel authorised to process personal data are bound by confidentiality obligations, and access is limited to those who need it to provide or support the service.
5. Security
Woise implements the technical and organisational measures described in Annex II, taking account of the state of the art, cost, and the risk to the people whose data is processed.
6. Sub-processors
You give Woise general authorisation to engage the sub-processors listed at woise.ai/sub-processors. Woise will give you […notice period…] notice before a new sub-processor begins processing, and you may object; if the objection cannot be resolved you may terminate the affected service without penalty.
Woise imposes on each sub-processor data protection obligations no less protective than those in this addendum, and remains liable to you for their performance.
[…The notice mechanism is not yet operational — transactional email is not configured on this deployment. Do not remove this note until it is.…]
7. Assistance with data subject rights
Taking account of the nature of the processing, Woise will assist you by appropriate technical and organisational measures in responding to requests from data subjects under Chapter III of the GDPR and the equivalent provisions of the DPDP Act.
Where a person who spoke to one of your agents contacts Woise directly — through the privacy request form — Woise will route that request to you rather than decide it, because the decision is the controller's. Woise does not verify the identity of a requester on your behalf; that remains your responsibility, and doing it badly is itself a disclosure risk.
8. Assistance with Articles 32 to 36
Woise will assist you in ensuring compliance with the obligations on security, breach notification and data protection impact assessments, taking account of the nature of the processing and the information available to it.
Woise will notify you without undue delay, and in any event within […notification window, e.g. 48 hours…] of becoming aware, of a personal data breach affecting your data, with the information reasonably available to it at the time.
9. Deletion and return
On termination, and at your choice, Woise will delete or return the personal data it processes for you, and delete existing copies, unless law requires it to be stored. Call content also ages out automatically under the retention windows described in the Privacy Policy.
10. Audit
Woise will make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. […State the practical form this takes: documentation and questionnaire responses, a third-party report if one exists, frequency limits, and who bears the cost. A clause that promises unbounded on-site audits to every customer is one nobody can honour.…]
11. International transfers
[…Set out the transfer mechanism relied on: the EU and UK standard contractual clauses with the relevant modules and their appendices, the UK Addendum, and the applicable DPDP transfer route. Name which entity contracts with which customers — the regional-site split makes this a real question, not boilerplate.…]
Annex I — Details of processing
Categories of data subject
People your agents call or who call your agents; people whose details appear in contact lists you upload; your own personnel who use the dashboard.
Categories of personal data
Names, phone numbers, the content of conversations (audio and transcript), any information a person gives to an agent, and information you supply in a contact list.
Special category data
[…State the position. Woise does not require special category data, but an agent operating in health, finance or debt collection will inevitably receive some, and a DPA that pretends otherwise is one a regulated customer cannot rely on. Say whether it is permitted, and under what conditions.…]
Frequency and duration
Continuous, for the duration of the agreement.
Purpose
Providing the Woise platform so you can operate voice and chat agents.
Annex II — Technical and organisational measures
[…This annex is the one a data protection officer reads closely, and it cannot be written from the codebase alone. It must describe, factually: encryption in transit and at rest; access control and how access is reviewed; authentication requirements for staff; logging and monitoring; the incident response process and who owns it; backup and restoration testing; secure development practices; personnel screening and training; and physical security at the hosting provider. Assert only what is actually done — an overstated Annex II is a misrepresentation in a contract, and it is the first thing checked after an incident.…]
Contact
Questions about this addendum, or to request a signed copy: privacy@woise.ai.