Skip to content
Voxtra
Try it now

Voxtra

Data Processing Agreement (DPA)

Last updated: September 25, 2026

This Data Processing Agreement (Swiss FADP Art. 9, GDPR Art. 28) applies whenever Voxtra processes personal data on a practice's behalf. It forms part of the Terms of Service and prevails on data-protection matters in case of conflict.

Not yet lawyer-reviewed

We have prepared this document with great care. It has not yet been reviewed by a Swiss law firm and may change once that review takes place. Binding executions are available on request.

1. Parties and subject matter

The controller is the Practice as a customer of the Voxtra services; the processor is Voxtra GmbH (in formation), Zurich. Voxtra processes personal data of callers and other data subjects exclusively on the Practice's documented instructions, for the duration of the subscription plus the transition period for return and deletion.

2. Nature and purpose of the processing

  • Answering phone calls in the Practice's name.
  • Transcribing call recordings.
  • Booking, rescheduling and cancelling appointments in the connected scheduling system.
  • Sending notifications by SMS and email to callers and staff.
  • Retaining call recordings and transcripts for the periods stated in the Privacy Policy.
  • Generating anonymised, aggregated metrics for the Practice.

3. Categories of data and data subjects

  • Categories of data: contact identifiers (phone number, name, where applicable email), call audio, transcripts derived from it, booking details (service, time, notes), and technical data such as timestamps and system logs.
  • Categories of data subjects: the Practice's callers, staff members mentioned in calls, and other persons mentioned during a call.

4. Obligations of the Practice

The Practice determines the purposes and means of processing, issues instructions via the service configuration or in writing, informs Voxtra promptly of changes, and ensures the required notices and consents towards callers, in particular the recording notice.

5. Obligations of Voxtra

  • Processing exclusively on documented instructions, including for transfers to third countries; we inform the Practice in advance of conflicting legal obligations, where permitted.
  • Binding all persons involved to confidentiality.
  • Implementing the technical and organisational measures in Annex A.
  • Engaging sub-processors only per section 7.
  • Assisting the Practice with data-subject requests, data-protection impact assessments and notification duties.
  • Notifying personal-data breaches without undue delay, at the latest within 72 hours (section 8).
  • Returning or deleting data at the end of the contract (section 9) and demonstrating compliance, including reasonable audits (section 10).

6. Confidentiality

Every person at Voxtra with access to personal data is bound by a contractual or statutory duty of confidentiality.

7. Sub-processors

The Practice authorises the sub-processors listed in Annex B. Voxtra binds each sub-processors contractually at least to the same extent as this agreement. New or replaced sub-processors are announced at least 30 days in advance by email or in the portal; the Practice may object within 14 days on data-protection grounds. If no agreement is reached, the Practice may terminate the subscription without penalty.

8. Breach notification

Voxtra notifies the Practice of any breach of the security of personal data without undue delay, at the latest 72 hours after becoming aware, including the nature and scope, likely consequences, measures taken and a contact point. Voxtra documents all incidents and supports the Practice's notification duties.

9. Data-subject requests, return and deletion

If a data subject sends a request directly to Voxtra, we forward it to the Practice without delay and respond only on the Practice's instruction. After the contract ends, Voxtra returns all personal data in a commonly used, machine-readable format or deletes it within 30 days at the Practice's choice, subject to statutory retention obligations.

10. Audits

On reasonable request, at most once per twelve months, Voxtra provides up-to-date attestations or answers to a reasonable data-protection questionnaire. On-site audits are permitted only where required by law or a supervisory authority, with 30 days' notice, during business hours, confidentially, and without unreasonable disruption.

11. Third-country transfers

Where data is processed outside Switzerland or the EU, Voxtra relies on the European Commission's adequacy decisions or on the Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, supplemented by technical measures. The current overview is in Annex B.

12. Liability, precedence, law

Liability is governed by the Terms of Service. In case of conflict this agreement prevails on data-protection matters. Swiss law applies; jurisdiction per the Terms of Service.

Annex A: Technical and organisational measures

  • Confidentiality: role-based access control on least-privilege principles with named accounts; strong authentication and multi-factor authentication for privileged access; database access only via secured access paths; TLS 1.2+ for all external connections; encryption of data stores; network segmentation between website, application, telephony and database.
  • Integrity: complete logging of administrative actions with actor, timestamp and purpose (12-month retention); code review and automated tests for every production change; validated inputs via API contracts.
  • Availability: daily database backups with a documented and regularly tested recovery procedure; continuous monitoring of all public endpoints with alerting on degradation.
  • Recovery: documented runbooks with defined recovery-time and recovery-point objectives; incident-response plan with a 72-hour notification deadline.
  • Data minimisation: caller data only to the extent required for appointment mediation; pseudonymisation where technically feasible; automatic deletion when retention periods expire.
  • No model training: customer data is not used to train own or third-party AI models without explicit consent.
  • Review: these measures are reviewed at least annually, plus continuous monitoring of security advisories for components in use.

Annex B: Sub-processors

Before launching future features (in particular payment processing) we will extend the list in good time per section 7.

  • Hetzner Online GmbH: server hosting; Germany (EU).
  • Cloudflare Inc.: DNS, CDN, marketing-site hosting, bot protection; USA/global; Standard Contractual Clauses plus FDPIC addendum.
  • Sipcall (sipcall.ch): SIP telephony and phone numbers; Switzerland.
  • Twilio Inc.: telephony infrastructure and webhooks; USA; Standard Contractual Clauses plus FDPIC addendum.
  • Google LLC: speech processing (recognition, synthesis, language model) and Google Calendar integration; USA; Standard Contractual Clauses plus FDPIC addendum.
  • Scaleway SAS: email delivery; France (EU).
  • TextBee (textbee.dev, open-source project): SMS delivery via our own gateway device with a Swiss number; relay service global; Standard Contractual Clauses plus FDPIC addendum for transfers outside CH/EU.
  • OneDoc SA: booking integration, where the Practice uses OneDoc; Switzerland.
  • ePhysio (Pharmed Solutions AG): booking integration, where the Practice uses ePhysio; Switzerland.

Annex C: Instructions

The instruction is: provide the Voxtra services as described in the Terms of Service and the documentation. The concrete configuration (services, locations, schedules, absences, notifications) is made by the Practice in the portal. Instructions are changed via the portal or in writing to hello@voxtra.ch.