Volofio← Back to site

Data Processing Agreement

Last updated: 18 July 2026

Template — review before use. This DPA is provided as a starting point. Have it reviewed by a qualified adviser and complete the bracketed details before signing with a Clinic.

This Data Processing Agreement ("DPA") forms part of the agreement between the Clinic ("Controller") and [Legal entity name] ("Volofio" / "Processor") for the Volofio service ("Service"). It applies where Volofio processes personal data on the Controller's behalf and reflects Article 28 of the UK GDPR.

1. Definitions

"UK GDPR", "personal data", "processing", "controller", "processor" and "data subject" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Sub-processor" means any processor engaged by Volofio.

2. Roles

The Controller is the controller and Volofio is the processor of the personal data processed under the Service. Volofio processes personal data only on the Controller's documented instructions (including those given through configuring the Service), unless required by law.

3. Subject matter and details of processing

Subject matterProvision of the AI receptionist Service (answering calls/messages, booking, reminders).
DurationFor the term of the agreement and until data is deleted or returned per clause 9.
Nature and purposeReceiving, recording, transcribing and responding to calls/messages; scheduling appointments; sending notifications; analytics for the Controller.
Categories of data subjectsThe Controller's patients and callers; the Controller's staff users.
Categories of personal dataNames, phone numbers, optional email addresses, appointment details, call recordings, transcripts, summaries and message content.
Special category dataNot required by the Service. Call content may incidentally reveal health-related information; the agent does not solicit clinical detail, triage, or give medical advice.

4. Volofio's obligations (Art 28(3))

  • Process personal data only on the Controller's documented instructions, including for transfers, unless required by law (in which case we notify you unless legally prohibited).
  • Ensure persons authorised to process the data are under a duty of confidentiality.
  • Implement appropriate technical and organisational security measures (clause 6).
  • Respect the conditions for engaging sub-processors (clause 5).
  • Assist the Controller, taking account of the nature of processing, to respond to data subject rights requests.
  • Assist the Controller with security, breach notification, data protection impact assessments and prior consultation (Art 32–36).
  • At the Controller's choice, delete or return personal data at the end of the Service, and delete existing copies unless retention is required by law (clause 9).
  • Make available information necessary to demonstrate compliance and allow for and contribute to audits (clause 8).

5. Sub-processors

The Controller gives general authorisation for Volofio to engage the sub-processors listed below to provide the Service. Volofio imposes data-protection obligations on each sub-processor substantially the same as those in this DPA and remains responsible for their performance. We will give reasonable notice of changes to sub-processors and allow the Controller to object on reasonable data-protection grounds.

Sub-processorPurpose
SupabaseDatabase, authentication, storage
VercelApplication hosting
ElevenLabsConversational AI voice and speech-to-text
TwilioTelephony and SMS
GoogleCalendar availability and booking (where connected)
AnthropicLarge-language-model responses (where enabled)
ResendTransactional and summary email

6. Security measures

  • Encryption of data in transit (TLS) and encryption of sensitive credentials at rest.
  • Per-Controller logical data isolation and row-level access controls.
  • Role-based, least-privilege access to systems; access limited to authorised personnel.
  • Secrets held in a secure server-side environment, never exposed to browsers.
  • Signed/verified webhooks for inbound integrations; audit logging where appropriate.
  • Regular review of measures against the risk of the processing.

7. International transfers

Where a sub-processor processes personal data outside the UK, Volofio ensures an appropriate transfer mechanism is in place (UK adequacy regulations, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed).

8. Audit

Volofio will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or its authorised auditor on reasonable notice, subject to confidentiality and not more than once per year unless required by a supervisory authority or following an incident.

9. Personal data breach

Volofio will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provide information reasonably required to help the Controller meet its own notification obligations.

10. Deletion or return

On termination or expiry of the Service, and at the Controller's choice, Volofio will delete or return the Controller's personal data and delete existing copies, unless UK law requires storage. The Service provides an export and a permanent-deletion function to support this.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the main agreement.

12. Signature

Controller: [Clinic legal name] — signed [name], [title], [date].
Processor: [Legal entity name] — signed [name], [title], [date].

← HomePrivacyTermsCookiesDPAContact