LEGAL

Data Processing Addendum

Last updated: 3 August 2026.

Roles

Where a customer submits personal data through UVOX on behalf of its users, the customer generally acts as controller and UVOX acts as processor, subject to the applicable agreement and law.

Instructions

UVOX processes customer data only to provide, secure, support and measure the service, and according to documented customer instructions expressed through service configuration and requests.

Confidentiality and security

Personnel and service providers with access to customer data are subject to appropriate confidentiality obligations. UVOX maintains technical and organisational measures including encrypted transport, access controls, tenant isolation, hashed UVOX keys and operational logging controls.

Subprocessors

Infrastructure, email, payment and customer-selected AI providers may act as subprocessors or independent providers depending on the service arrangement. Customers are responsible for their provider-account choices.

Assistance

UVOX will provide reasonable assistance with data-subject requests, security incidents and compliance information where required and proportionate.

Processing instructions and engine modes

The customer instructs UVOX to receive, authenticate, classify, optionally context-optimise, cache-route and forward AI requests to the selected provider. Auto and Maximum Savings may omit historical messages; Zero-Loss Cache preserves complete request content. UVOX records operational route and fallback metadata without intentionally storing prompt or generated-answer bodies in normal logs.

Deletion and return

Upon account termination, customer data is deleted or retained according to service settings, legal obligations, security requirements and backup cycles.

Execution

To request a signed DPA or subprocessors information, contact privacy@uvox.tech.

Zero-Risk and verification disclosure: “Zero-risk” applies only to Zero-Loss Cache Mode and means prompt content is not rewritten or deleted, provider/model are not switched, and generated responses are not substituted from a semantic answer cache. Provider-supported cache metadata may be added. Proof Lab requests are sent to the selected provider and UVOX using customer-supplied keys held in process memory. Reports exclude API keys and full prompt content by default. Savings and exclusivity claims are workload- and evidence-dependent and are not guarantees.