Data Processing Addendum
Last Updated: August 20, 2026
Effective Date: August 20, 2026
This Data Processing Addendum ("Addendum" or "DPA") supplements the Lokutor Terms of Service ("ToS") and governs the processing of personal data by Lokutor AI ("Processor") on behalf of the customer ("Controller") when the Controller uses the Services to process personal data of third parties.
By using the Services in a manner that involves processing personal data of third parties (e.g., deploying Voice Agents, making phone calls, or storing knowledge documents containing personal information), you agree to this Addendum.
1. Definitions
- "Controller" means the entity that determines the purposes and means of processing personal data (your organization).
- "Processor" means the entity that processes personal data on behalf of the Controller (Lokutor AI).
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Sub-Processor" means a third party engaged by the Processor to process personal data.
- "Personal Data" has the meaning given in GDPR Article 4(1).
- "Special Category Data" has the meaning given in GDPR Article 9(1), including biometric data for identification purposes.
- "Applicable Data Protection Laws" means GDPR, CCPA/CPRA, UK GDPR, and any other applicable data protection laws.
2. Scope and Roles
This Addendum applies when the Controller uses the Services to process personal data of third parties (e.g., end users calling Voice Agents, contacts stored in agent knowledge bases, or phone numbers associated with call routing).
- Controller: You (the customer). You determine what personal data is processed and for what purposes.
- Processor: Lokutor AI. We process personal data solely in accordance with your documented instructions.
3. Processing Details
| Attribute | Details |
|---|
| Subject matter | Speech-to-text, text-to-speech, and voice agent services |
| Duration | Duration of the Service agreement plus 30 days for data deletion |
| Nature & Purpose | Real-time audio processing, transcription, speech synthesis, AI conversation, call routing |
| Categories of Data Subjects | End users, callers, customers, agents of the Controller |
| Types of Personal Data | Voice recordings, audio signals, phone numbers, call metadata, conversation transcripts, knowledge base content |
| Special Categories of Data | Biometric voice data (when voice is used for identification); potential health data in agent conversations |
4. Controller Obligations
- You must have a valid legal basis under Applicable Data Protection Laws for each category of personal data you process through the Services.
- You must provide Data Subjects with required privacy notices, including disclosure of AI processing where required.
- You must obtain any necessary consents before providing personal data to us for processing.
- You must not instruct us to process personal data in violation of Applicable Data Protection Laws.
- You must implement appropriate technical and organizational measures for the security of personal data under your control.
- If processing Special Category Data (e.g., biometric voice data), you must ensure an appropriate legal basis under GDPR Article 9 exists.
- You are responsible for compliance with telecommunication laws for Voice Agent calls, including recording consent requirements.
5. Processor Obligations
- We process personal data only in accordance with your documented instructions, as set out in this Addendum and the ToS.
- We will not use personal data for our own purposes, except as permitted by this Addendum (e.g., aggregate analytics, service improvement).
- We will ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations.
- We will implement appropriate technical and organizational security measures (see Section 9).
- We will assist you in responding to Data Subject requests under GDPR Articles 15-22.
- We will notify you without undue delay (within 72 hours) upon becoming aware of a personal data breach affecting your data.
- Upon termination of the service, we will delete or return all personal data within 30 days, at your election, unless retention is required by law.
6. Sub-Processing
You provide general authorization for us to engage the Sub-Processors listed in Section 13 of our Privacy Policy. We will notify you of any new Sub-Processors at least 30 days before engagement. You may object to a new Sub-Processor for legitimate data protection reasons; if you object, we will either refrain from engaging that Sub-Processor or allow you to terminate the affected Services.
7. International Transfers
Personal data may be transferred to the following regions:
| Region | Purpose | Safeguards |
|---|
| EU (Ireland, eu-west-1) | Primary processing region | In-region |
| USA | Sub-processor operations | EU Standard Contractual Clauses; EU-US DPF |
| EU (Paris, eu-west-3) | Backup / regional processing | In-region |
Where transfers outside the EEA occur, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or the EU-U.S. Data Privacy Framework (DPF) certification.
8. Data Security
We implement the following measures to protect personal data:
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Access Controls: Role-based access, least privilege, multi-factor authentication
- Database Security: Row-level security (RLS) on all tables
- Infrastructure: AWS VPC isolation, security groups, no direct public access to workers
- Monitoring: Real-time monitoring, intrusion detection, automated alerting
- Auditing: Regular security audits, penetration testing, vulnerability assessments
- Incident Response: Documented incident response plan with 72-hour breach notification
9. Data Retention and Deletion
We retain personal data processed under this Addendum as follows:
- Audio recordings: Not stored unless recording is enabled for the Agent. Where enabled, stored encrypted for up to 90 days, then deleted. Recording is always enabled on free plans (see Privacy Policy ยง1.4); it can be disabled entirely on any paid plan, in which case audio is processed transiently and never written to disk.
- Conversation transcripts: Stored for up to 90 days for evaluation and quality assurance
- Knowledge base content: Stored for the lifetime of the associated Agent
- API usage logs: 12 months for billing and analytics
Upon termination of the Controller's account or upon written request, we will delete all personal data within 30 days, except where retention is required by applicable law.
10. Data Subject Rights Assistance
We will assist you in responding to Data Subject requests (GDPR Articles 15-22) by:
- Providing you with the personal data we hold about a Data Subject upon request
- Supporting you in rectifying inaccurate personal data
- Executing erasure of personal data when instructed
- Supporting data portability requests
To exercise these rights, contact privacy@lokutor.com.
11. Breach Notification
If we become aware of a personal data breach affecting data processed under this Addendum, we will:
- Notify the Controller within 72 hours of becoming aware
- Provide details of the breach, including categories of data, likely consequences, and measures taken
- Assist the Controller in notifying the relevant supervisory authority within 72 hours (GDPR Article 33)
- Assist the Controller in notifying Data Subjects where required (GDPR Article 34)
12. Liability
Each party is liable for its own acts and omissions under Applicable Data Protection Laws. Neither party will be liable for any claim, loss, or damage caused by the other party's failure to comply with its obligations under this Addendum.
To the maximum extent permitted by law, the Processor's aggregate liability under this Addendum shall not exceed the total fees paid by the Controller in the 12 months preceding the claim.
13. Term and Termination
- This Addendum is effective from the Effective Date and continues for the duration of the Controller's use of the Services.
- The Addendum terminates automatically upon termination of the ToS.
- Upon termination, we will delete or return personal data within 30 days, at the Controller's election.
- Sections 8 (Data Security), 12 (Liability), and 14 (Governing Law) survive termination.
14. Governing Law
This Addendum is governed by the laws of the European Union / Spain, without regard to conflict-of-law principles.
15. Changes
We may update this Addendum to reflect changes in our processing activities or Sub-Processors. Material changes will be communicated 30 days before taking effect. If you object to a change, you may terminate the affected Services without penalty.
16. Contact
Data Protection Officer: privacy@lokutor.com
Legal: legal@lokutor.com