फ्री ट्रायल शुरू करें — 7 दिन मुफ़्त

Start free trial

Legal

Data Processing Agreement

Effective 29 July 2026

This Data Processing Agreement (“DPA”) is between the organisation identified as the customer in the Voco account (“Customer”) and Joshua Stannard trading as Voco, of 9 Silk Mill Avenue, Leeds, LS16 6EA, United Kingdom(“Voco”).

It forms part of the Voco Terms of Serviceand is automatically binding when Voco processes personal data on the Customer's behalf. No separate signature is required, but either party may request a signed copy.

1. Roles and scope

For Customer Personal Data processed through a live service, Customer is the controller and Voco is the processor. Each party will comply with data protection law applicable to it, including UK GDPR and, where applicable, EU GDPR.

Terms such as controller, processor, personal data, processing, data subject, and supervisory authority have the meanings given by applicable data protection law.

2. Customer instructions

Voco will process Customer Personal Data only on documented instructions from Customer, including these Terms, Customer's configuration and use of the service, and written support instructions, unless law requires otherwise. If legally permitted, Voco will tell Customer before processing required by law.

Voco will promptly tell Customer if an instruction appears to infringe applicable data protection law. Voco may pause the affected processing while the parties clarify the instruction.

3. Confidentiality and personnel

Voco will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, receive access only where necessary, and are informed of relevant security and privacy responsibilities.

4. Security

Taking account of the nature and risk of processing, Voco maintains proportionate technical and organisational safeguards, including:

  • encryption in transit and provider-managed encryption at rest;
  • authenticated, organisation-scoped admin access and database access controls;
  • separation between public attendee delivery and private administrative functions;
  • restricted production credentials and server-side ownership checks;
  • logging, rate limiting, dependency updates, backups, and incident investigation;
  • transient live-audio processing without raw sermon recording by Voco; and
  • automatic content and analytics retention limits described below.

Customer is responsible for its devices, internet connection, team access, password or email security, microphone permissions, notices to speakers and attendees, and lawful configuration of the service.

5. Sub-processors

Customer gives Voco general written authorisation to use sub-processors for cloud hosting, database/authentication/realtime delivery, speech recognition, translation, limited AI wording, payment processing, email, support, and security operations.

Voco will impose data-protection obligations on each sub-processor that are no less protective in substance than the relevant obligations in this DPA, to the extent applicable to the service it provides. Voco remains responsible for its sub-processors' performance of those obligations.

A current named list, processing purpose, and primary processing location is available to Customer by emailing privacy@voco.church. Voco will give active Customers at least 14 days' notice before adding or replacing a sub-processor that materially processes Customer Personal Data, except where an urgent security or service-continuity change is reasonably necessary.

Customer may object during that notice period on reasonable data-protection grounds. The parties will work in good faith on a practical solution. If none is reasonably available, Customer may stop the affected processing or cancel the affected service before the change takes effect.

6. International transfers

Voco will not transfer Customer Personal Data outside the UK or EEA unless permitted by applicable law. Where no adequacy decision applies, Voco will use an appropriate safeguard, which may include the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or EU Standard Contractual Clauses, and will apply supplementary measures where required.

Customer authorises Voco to enter these safeguards on Customer's behalf where necessary for an authorised sub-processor.

7. Assistance

Taking account of the nature of processing and information available, Voco will provide reasonable assistance with:

  • data-subject access, correction, deletion, restriction, objection, and portability requests;
  • security obligations, data-protection impact assessments, and prior consultation with a supervisory authority; and
  • information reasonably needed to demonstrate compliance with this DPA.

If Voco receives a request directly concerning Customer Personal Data, Voco will normally refer it to Customer and will not respond substantively unless instructed or legally required.

8. Personal data breaches

Voco will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer to meet its notification duties. Voco's notification is not an admission of fault or liability.

9. Return and deletion

Customer may delete events through the service or request account closure. Voco automatically deletes stored transcript text and translations after 90 days and anonymous reader/service analytics after 24 months. Following confirmed account closure, Voco deletes remaining operational Customer Personal Data within 30 days unless law requires retention.

Secure backup copies may persist for a limited rolling period before being overwritten and remain protected from ordinary use. Billing, tax, fraud-prevention, legal, and suppression records are outside Customer Content and may be retained as described in the Privacy Notice.

10. Information and audits

Voco will provide information reasonably necessary to demonstrate compliance, ordinarily through this DPA, the Security & Trust page, provider documentation, and written answers.

If that information is insufficient, Customer may request one reasonable audit in a 12-month period on at least 30 days' notice, during normal business hours, without access to another customer's data or Voco's secrets. Additional or unusually burdensome assistance may be charged at a reasonable rate agreed in advance. This limit does not apply following a relevant breach or where a supervisory authority requires otherwise.

11. Processing details

Subject matter
Live church transcription, translation, caption delivery, transcript export, service analytics, support, and related account operations.
Duration
For the subscription and the deletion periods stated in this DPA.
Nature and purpose
Capture transient live audio, produce and deliver text, save limited service history, provide organisation-specific insights, secure the service, and support Customer.
Data subjects
Speakers, attendees using a reader, Customer's admin users and team members, and people mentioned in Customer Content.
Personal data
Voice audio processed transiently; spoken content; transcripts and translations; random browser identifier; language selection; timestamps and approximate reader duration; admin identity, role and support data; event settings and technical logs.
Special-category data
Not intentionally required, but spoken religious services may reveal religious belief and Customer Content may incidentally include other sensitive information. Customer must minimise unnecessary sensitive content and establish an appropriate lawful condition.
Frequency
Continuous during a live service and occasional for account, export, analytics, insight, and support operations.

12. Order of precedence and contact

If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. The Terms control other matters. Questions, signed-copy requests, and sub-processor requests should be sent to privacy@voco.church.