// Data Processing Agreement
Data Processing Agreement
Last updated: 26 July 2026. This sits alongside our Terms and Privacy Policy. Questions? Email info@voan.ai.
1. What this agreement is
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between voan (“voan”, “we”) and the firm using the Service (“you”). It applies whenever we process personal data on your behalf, and it reflects Article 28 of the GDPR.
In plain terms: for the client contact details and documents that flow through voan, you are the controller and we are your processor. We act only on your instructions.
2. What we process, and why
We process personal data only to provide the Service — sending reminders, storing uploaded documents, and giving you access to them. The specifics:
- • Subject matter: providing the voan document-collection service to you.
- • Duration: for as long as your account is open, plus the deletion period below.
- • Nature and purpose: sending reminder emails, hosting an upload page, and storing and retrieving documents.
- • Types of personal data: client names and email addresses you enter, and the contents of the documents your clients upload.
- • Categories of data subjects: your clients and their representatives.
3. Our obligations
As your processor, we will:
- • process personal data only on your documented instructions, including the instructions built into your use of the app;
- • make sure people authorised to process the data are bound by confidentiality;
- • put in place appropriate technical and organisational security measures (Article 32) — including encryption at rest, access controls, and TLS in transit;
- • help you respond to requests from data subjects exercising their rights;
- • help you with security, breach notifications and data protection impact assessments, taking into account the information available to us;
- • delete or return the data at the end, as set out below.
4. Sub-processors
You give us general authorisation to use the sub-processors below to run the Service. Each is bound by data protection terms no less protective than this DPA:
- • Supabase — database, authentication and encrypted document storage.
- • Resend — sending reminder and notification emails.
- • Cloudflare — receiving the emails your clients reply to and passing them to us.
- • Vercel — hosting the application.
5. Changes to sub-processors
If we plan to add or replace a sub-processor, we will give you reasonable notice by email so you can object on reasonable data protection grounds. If we cannot resolve a valid objection, you may end the affected part of the Service.
Note: Paddle, our payment provider, is not a sub-processor under this DPA — it acts as merchant of record and an independent controller for payment data, covered in our Privacy Policy.
6. International transfers
Personal data is stored and processed in EU regions: Supabase (database, authentication and document storage) in an EU region, Vercel (application) in Dublin — eu-west-1, and Resend (outbound email) in Ireland — eu-west-1.
One part of the Service is not EU-pinned. When a client replies to a reminder with a document attached, that message reaches us through Cloudflare's email routing, which operates on a global network. Cloudflare passes the message to our application in Dublin, where the document is stored. Our use of Cloudflare is governed by Cloudflare's published Data Processing Addendum, which incorporates the European Commission's standard contractual clauses, and we rely on those for this transfer. If that route does not suit your firm, tell us before you start and we will agree how to handle it.
Our sub-processors are incorporated outside the EEA, so limited support or administrative access from outside the EEA remains possible. Any such transfer is protected by Standard Contractual Clauses or another safeguard approved under the GDPR.
7. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it.
That notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. Where we cannot provide all of it at once, we will send what we have within 72 hours and the rest as soon as it is available — so that you can meet your own 72-hour duty to the Data Protection Commission under Article 33.
8. Return and deletion
You can export or delete data from the app at any time. When your account closes, we delete stored documents and client personal data within 30 days, except where the law requires us to keep specific records for longer.
9. Audits
On reasonable written request, we will make available the information needed to show we meet these obligations, and support audits where the GDPR requires it, subject to reasonable confidentiality and security limits.
10. Liability and governing law
Liability under this DPA is subject to the limits in the Terms of Service. This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction.
11. Contact
Data protection questions: info@voan.ai.
See also our Terms of Service and Privacy Policy.