Data Processing Terms
Last updated: 6 September 2026
These terms describe processing of customer-controlled information when incorporated into the relevant service agreement. A signed processing schedule may add or override specifics. They do not replace the platform’s Privacy Policy for its independently managed billing, security and account records.
1. Parties, instructions and scope
The customer determines the purposes and permitted use of recipient and campaign information. The platform processes it to provide the agreed service on documented customer instructions. In a reseller arrangement, the customer may instruct the reseller, which instructs the platform as a further processor. The parties must document that chain and identify any separate independent processing.
Processing includes receiving, storing, transmitting and analyzing contact details, supplied content, audio, transcripts, summaries, ratings and call metadata for communications and workspace administration. Individuals may include customers, prospects, applicants, employees and other authorized recipients. Processing continues for the service duration and any documented return/deletion period, subject to lawful retention exceptions.
2. Customer responsibilities
The customer provides lawful instructions, appropriate notices and any necessary consent, observes telecom requirements, minimizes information, controls user access and verifies its authority over uploaded content. Special categories or minors’ information require an expressly supported lawful arrangement. The customer handles requests from individuals, with processor assistance as appropriate.
3. Platform responsibilities
Process customer information for the agreed service and documented instructions, or where law requires otherwise. Restrict access to authorized personnel with confidentiality obligations and appropriate operational roles. Maintain reasonable access, credential and security controls; assist with justified access, correction, export and deletion requests within available capabilities.
Notify the customer or responsible reseller without undue delay after confirming a personal-data incident affecting its information, provide available details and updates, and cooperate on containment and legally required notifications. This is separate from general service-outage notices. Each party remains responsible for its own statutory reporting duties.
4. Providers and transfers
The customer authorizes the providers necessary for its selected features as described in Providers & Subprocessors and the agreed processing schedule. Apply appropriate contractual protection when engaging further processors. Communicate material additions or replacements affecting customer data and allow concerns to be raised through the privacy contact before the change where practicable; urgent security replacements may need shorter notice.
Resolve justified objections through an alternative configuration or agreed service change where feasible. Record actual processing regions and applicable transfer safeguards in the customer’s schedule if residency is a requirement. Customer-appointed providers, exports and credentials are also governed by the customer’s own agreements.
5. Return, deletion and retained copies
At closure or on an authorized request, agree the data to return or delete, available export format, timing, retained categories and backup treatment. Disabling an account or deleting a recording is not deletion of every related record. Keep legally required records only for their applicable purpose and period, restrict residual copies and reapply applicable deletion instructions following a restore. The Privacy Policy describes the current retention approach.
6. Accountability and assistance
Provide reasonably necessary information to demonstrate the agreed processing controls and cooperate with proportionate reviews, assessments and regulatory requests. Agree scope, confidentiality, security and any reasonable assistance costs in advance; protect other customers’ information. Raise instructions believed to conflict with applicable law for resolution. Use the published privacy and escalation contact for processing issues.
Operator, privacy requests & grievances
Platform brand: Veytrix AI
Legal operator: Contact us for the contracting entity’s confirmed details.
Business address: Hyderabad, Telangana, India. Full business address pending confirmation.
Privacy / grievance contact: Contact the support team to reach the responsible privacy / grievance representative.
contact@veytrixai.com
For a request or complaint, include your workspace or the business that contacted you, the relevant date and a description. We may need to verify authority before sharing records. If a response does not resolve your concern, reply to the same correspondence with “Grievance escalation” and the earlier reference, requesting review by the responsible representative. Applicable statutory complaint rights remain available.
White-label customers should also use the seller’s legal and grievance details on their order or invoice. These platform details do not replace the reseller’s identity.
Policy version 2026-09-06