Data Processing Agreement

Data Processing Agreement for MenyVoice

Version: 3.0
Status: Final approved
Last updated: 7 August 2026

This data processing agreement ("the Data Processing Agreement") is entered into between the company or organisation using MenyVoice ("the Customer" or "the data controller") and:

EzyAcnt ApS
CVR no.: 38362925
Olsbækeng 12
2670 Greve
Denmark
E-mail: hello@menyvoice.com

("MenyVoice" or "the data processor").

The Data Processing Agreement forms an integral part of the agreement between the Customer and MenyVoice regarding the provision of the MenyVoice service.

1. Purpose and scope

1.1. This Data Processing Agreement governs MenyVoice's processing of personal data on behalf of the Customer in connection with the provision of MenyVoice.

1.2. The Data Processing Agreement has been entered into in order to comply with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"), including in particular Article 28.

1.3. The Data Processing Agreement applies to the extent that MenyVoice processes personal data on behalf of the Customer.

1.4. When EzyAcnt ApS processes personal data for its own independent purposes, for example invoicing, bookkeeping, administration of the customer relationship, security, prevention of misuse or compliance with its own legal obligations, such processing takes place as an independent data controller and is not covered by this Data Processing Agreement.

1.5. The subject matter, duration, nature, purpose, categories of data subjects and categories of personal data of the processing are set out in more detail in Appendices A-D.

2. Definitions

In this Data Processing Agreement, the following terms shall mean:

The Customer: The company or organisation that has entered into an agreement for the use of MenyVoice.

Data controller: The party that, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data processor: EzyAcnt ApS/MenyVoice, when personal data is processed on behalf of the Customer.

Sub-processor: A third party that processes personal data on behalf of MenyVoice as part of MenyVoice's provision of the service to the Customer.

Data subject: An identified or identifiable natural person whose personal data is processed.

Personal data: Any information relating to an identified or identifiable natural person as defined in Article 4 of the GDPR.

Processing: Any operation or set of operations performed on personal data.

The Service: MenyVoice's AI-based telephony, voice, ordering, booking and customer service solution.

Personal data breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

3. Roles and responsibilities of the parties

3.1. As a starting point, the Customer is the data controller for personal data processed through MenyVoice regarding the Customer's callers, guests, end customers, employees or other data subjects.

3.2. MenyVoice acts as a data processor and processes personal data solely on behalf of the Customer and in accordance with the Customer's documented instructions.

3.3. Alayic Ltd provides the underlying AI voice platform and acts in this processing chain as a sub-processor for MenyVoice.

3.4. The Customer is responsible for:

  • ensuring that a valid legal basis for processing exists;
  • ensuring that applicable duties to inform data subjects are fulfilled;
  • ensuring that the purposes of the processing are lawful, explicit and legitimate;
  • ensuring that the instructions given to MenyVoice are lawful;
  • assessing the necessity and lawfulness of processing any special categories of personal data;
  • ensuring data minimisation in the Customer's configuration and instructions;
  • deciding on data subjects' rights.

3.5. MenyVoice does not independently determine the purpose of the Customer's processing of call data.

3.6. The parties do not become joint controllers solely as a result of this Data Processing Agreement or MenyVoice's provision of the service.

4. Subject matter, nature and purpose of the processing

4.1. MenyVoice processes personal data for the purposes of the provision, operation, support, maintenance and security of the agreed MenyVoice service.

4.2. Depending on the Customer's configuration, the processing may, among other things, include:

  • receiving and answering telephone calls;
  • processing of speech;
  • speech recognition;
  • conversion of speech to text;
  • generation of AI responses;
  • generation of synthetic speech;
  • recording of telephone conversations;
  • generation of transcriptions;
  • generation of AI summaries;
  • registration of orders;
  • registration of reservations;
  • forwarding of calls;
  • registration and forwarding of messages;
  • use of the Customer's instructions, menus, opening hours and other content;
  • integration with systems that the Customer chooses to connect to the service;
  • technical logging and troubleshooting;
  • export, rectification, restriction or deletion in accordance with the Customer's instructions.

4.3. The more detailed subject matter, nature, purpose and duration of the processing are set out in Appendices A-D.

5. Documented instructions

5.1. MenyVoice may only process personal data on documented instructions from the Customer, including with regard to transfers of personal data to third countries or international organisations, unless required to do so by Union or Member State law to which MenyVoice is subject.

5.2. If MenyVoice is legally required to carry out processing pursuant to point 5.1, MenyVoice shall inform the Customer of that legal requirement before the processing, unless the relevant law prohibits such information on important grounds of public interest.

5.3. The Customer's documented instructions include, among other things:

  • this Data Processing Agreement and its appendices;
  • the Customer's chosen configuration;
  • the functions and integrations activated by the Customer;
  • written instructions sent to MenyVoice;
  • other written agreements between the parties.

5.4. If MenyVoice considers that an instruction infringes the GDPR or other applicable data protection legislation, MenyVoice shall inform the Customer without undue delay.

5.5. MenyVoice is not obliged to carry out an instruction that MenyVoice reasonably considers to be unlawful, until the parties have clarified the instruction.

5.6. If a new or amended instruction results in significant additional work, technical changes or costs, the parties may agree reasonable commercial terms for this, provided that this does not limit MenyVoice's mandatory obligations under the GDPR.

6. Confidentiality

6.1. MenyVoice shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6.2. Access to personal data is limited to persons who have a relevant work-related need for access.

6.3. MenyVoice shall ensure that authorised persons only process personal data in accordance with this Data Processing Agreement and the Customer's documented instructions.

6.4. Confidentiality obligations continue after the termination of the relevant person's employment or cooperation relationship, where this follows from the agreement or applicable rules.

7. Security

7.1. MenyVoice shall implement and maintain appropriate technical and organisational security measures in accordance with Article 32 of the GDPR.

7.2. In determining the appropriate level of security, account shall be taken of, among other things:

  • the state of the art;
  • the costs of implementation;
  • the nature, scope, context and purposes of the processing;
  • the likelihood and severity of risks to the rights and freedoms of natural persons.

7.3. The measures shall, as appropriate, support:

  • confidentiality;
  • integrity;
  • availability;
  • resilience;
  • access control;
  • secure data transfer;
  • logging and monitoring;
  • incident management;
  • backup and recovery;
  • vendor management;
  • ongoing assessment of the effectiveness of the security measures.

7.4. MenyVoice uses relevant platform, telephony, cloud, voice and AI providers as part of the technical delivery of the service.

7.5. The technical and organisational security measures are described in more detail in Appendix H.

8. Sub-processors

8.1. The Customer gives MenyVoice general written authorisation to use sub-processors for processing that is necessary for the provision of the service.

8.2. MenyVoice shall ensure that any sub-processor that processes the Customer's personal data is subject to data protection obligations that are substantially equivalent to the obligations under this Data Processing Agreement and Article 28 of the GDPR.

8.3. If a sub-processor fails to fulfil its data protection obligations, MenyVoice shall remain fully liable to the Customer for the performance of the data protection obligations imposed on MenyVoice as a data processor under applicable law.

8.4. MenyVoice currently uses Alayic Ltd as the central sub-processor for the underlying AI voice platform:

Alayic Ltd
9 West Street
Congleton
England
CW12 1JN
United Kingdom
Company No. 16581244

8.5. MenyVoice maintains a separate, updated and continuously available Sub-processor List, which sets out the sub-processors approved for processing the Customer's personal data, together with their relevant processing purposes and, where relevant, processing locations.

8.6. The Sub-processor List forms part of the overall contractual basis for the processing and is incorporated into this Data Processing Agreement by reference.

8.7. Alayic uses further sub-processors for, among other things, cloud hosting, telephony, real-time media, speech recognition, language models, speech generation, e-mail, payment, security and integrations.

8.8. Alayic's current DPA is used as the authoritative external source for Alayic's own technical sub-processor chain:

https://www.alayic.com/data-processing-agreement

8.9. Under the general authorisation of sub-processors, MenyVoice shall inform the Customer of planned changes regarding the addition or replacement of sub-processors before the new sub-processor begins processing the Customer's personal data.

8.10. The notification shall give the Customer a genuine opportunity to object on reasonable and documented data protection grounds.

8.11. If the Customer raises a legitimate objection, the parties shall in good faith attempt to find a reasonable solution.

8.12. If a solution cannot be found, the affected function or processing may be discontinued, or the agreement may be terminated to the extent necessary as a result of the objection.

8.13. A change on an external supplier's public list does not in itself constitute the Customer's approval, unless MenyVoice has complied with the notification and approval arrangement set out in this section.

9. International transfers

9.1. MenyVoice may only transfer personal data to a country outside the EU/EEA if the transfer:

  • is covered by the Customer's documented instructions; and
  • meets the requirements of Chapter V of the GDPR.

9.2. A valid transfer basis under Chapter V of the GDPR does not in itself constitute an instruction from the Customer to carry out the transfer.

9.3. International transfers may, depending on the specific processing, be based on, among other things:

  • an applicable adequacy decision;
  • the European Commission's Standard Contractual Clauses (SCCs);
  • the UK International Data Transfer Addendum, where relevant in the specific processing chain;
  • other valid transfer mechanisms under applicable law.

9.4. Where necessary, supplementary contractual, technical or organisational measures shall be applied based on the specific transfer and risk.

9.5. The underlying platform currently uses, among other things, hosting in the United Kingdom and Ireland.

9.6. Certain providers of voice, language model, telephony or other technical services may process personal data outside the United Kingdom and the EU/EEA, including in the USA.

9.7. The specific processing locations and transfer mechanisms are set out in MenyVoice's current Sub-processor List and, where relevant, Alayic's applicable data processing agreement.

9.8. MenyVoice shall ensure that documentation of the relevant transfer basis can be made available to the Customer to the extent required under applicable data protection rules.

10. Assistance with data subjects' rights

10.1. MenyVoice shall assist the Customer, taking into account the nature of the processing, by appropriate technical and organisational measures, so that the Customer can fulfil its obligations in connection with data subjects' rights.

10.2. The assistance may, among other things, relate to:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection, where relevant;
  • handling of other rights under applicable data protection legislation.

10.3. If MenyVoice directly receives a request from a data subject concerning personal data processed on behalf of the Customer, MenyVoice will, as a starting point, forward or refer the request to the Customer without undue delay, unless otherwise provided by the Customer's documented instructions or applicable law.

10.4. The Customer is responsible for deciding whether and to what extent a data subject's request shall be complied with.

10.5. MenyVoice may request the Customer to provide such information as is reasonably necessary to identify the relevant processing or data subject.

10.6. MenyVoice may not, without the Customer's documented instruction, itself make substantive decisions on a data subject's rights in relation to the personal data processed on behalf of the Customer.

11. Assistance under GDPR Articles 32-36

11.1. MenyVoice shall assist the Customer in fulfilling relevant obligations under Articles 32-36 of the GDPR, taking into account the nature of the processing and the information available to MenyVoice.

11.2. The assistance may, among other things, relate to:

  • assessment and maintenance of appropriate information security;
  • assessment and handling of personal data breaches;
  • data protection impact assessments (DPIAs);
  • prior consultation with a relevant supervisory authority;
  • documentation of security measures;
  • information about relevant sub-processors and international transfers.

11.3. MenyVoice shall, to a reasonable extent, make available relevant information that the Customer legitimately needs in order to fulfil its obligations under Articles 32-36 of the GDPR.

11.4. If the Customer requests extraordinary assistance that goes significantly beyond MenyVoice's ordinary obligations as a data processor, the parties may agree reasonable payment for this, provided that this does not limit MenyVoice's mandatory obligations under applicable data protection legislation.

12. Personal data breaches

12.1. MenyVoice shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.

12.2. The notification shall, to the extent the information is available, include:

  • a description of the nature of the breach;
  • the categories of data subjects affected;
  • the categories of personal data affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach;
  • measures to mitigate any adverse effects;
  • relevant contact details.

12.3. If all the information cannot be provided at the same time, the information may be provided in phases without undue further delay.

12.4. MenyVoice shall document relevant personal data breaches to the extent required under applicable data protection legislation.

12.5. As data controller, the Customer is responsible for assessing whether the breach must be notified to a supervisory authority and/or communicated to affected data subjects.

12.6. MenyVoice shall, to a reasonable extent, assist the Customer with the information and documentation necessary for the Customer's assessment of the breach.

12.7. MenyVoice shall ensure that relevant sub-processors are subject to obligations to notify MenyVoice of personal data breaches without undue delay.

13. Audit, inspection and documentation

13.1. MenyVoice shall make available the information reasonably necessary to demonstrate compliance with the obligations under this Data Processing Agreement and Article 28 of the GDPR.

13.2. The Customer or an independent auditor authorised by the Customer may carry out audits and inspections regarding processing covered by this Data Processing Agreement.

13.3. As a starting point, an audit shall:

  • be notified with reasonable notice;
  • be carried out during normal business hours;
  • be limited to matters relevant to the Customer's processing;
  • be carried out under appropriate confidentiality;
  • not unduly disrupt MenyVoice's or other customers' operations;
  • not compromise the security or confidentiality of other customers or third parties.

13.4. As a first level of control, MenyVoice may make available existing and relevant documents, including for example:

  • security descriptions;
  • policies;
  • supplier documentation;
  • sub-processor information;
  • audit or assurance reports, where such exist;
  • other documentation that reasonably demonstrates compliance.

13.5. If such documentation cannot reasonably meet the Customer's legitimate control needs, a more extensive audit or inspection may be carried out.

13.6. An extraordinary audit may be carried out without the normal notice period if this is necessary as a result of:

  • a significant personal data breach;
  • an instruction from a competent supervisory authority;
  • reasonable suspicion of significant non-compliance;
  • other special circumstances that make normal notice inappropriate.

13.7. As a starting point, the Customer shall bear its own costs of an audit.

13.8. MenyVoice may charge a reasonable fee for extraordinarily extensive assistance in connection with an audit, unless the audit documents a material breach of MenyVoice's data protection obligations.

13.9. MenyVoice shall, to a reasonable extent, cooperate in audits of relevant sub-processors through the documentation and control rights available to MenyVoice itself in the relevant processing chain.

14. Duration

14.1. The Data Processing Agreement enters into force at the same time as MenyVoice begins processing personal data on behalf of the Customer.

14.2. The Data Processing Agreement remains in force for as long as MenyVoice processes personal data on behalf of the Customer.

14.3. The Data Processing Agreement does not terminate merely because the main agreement between the parties terminates, if MenyVoice continues to process personal data on behalf of the Customer.

14.4. Provisions that by their nature must apply after termination, including provisions on:

  • confidentiality;
  • deletion and return;
  • liability;
  • documentation;
  • audit relating to previous processing;

shall continue to the extent necessary.

15. Deletion and return upon termination

15.1. Upon termination of the services involving the processing of personal data, MenyVoice shall, at the Customer's choice, delete or return all personal data processed on behalf of the Customer, and delete existing copies, unless Union or Member State law requires continued storage.

15.2. MenyVoice shall ensure that equivalent deletion or return obligations are implemented throughout the relevant sub-processor chain.

15.3. The Customer shall, before or in connection with the termination, inform MenyVoice whether personal data is to be returned or deleted.

15.4. If the Customer requests return, MenyVoice may use a common and technically reasonable data format, unless otherwise agreed.

15.5. Practical procedures for export or return do not limit MenyVoice's obligations under point 15.1.

15.6. Information required by Union or Member State law to be retained after termination of the agreement may only be stored to the extent and for the period required by the legal requirement, and may not be used for incompatible purposes.

15.7. The current retention and deletion arrangements are set out in more detail in Appendix G.

16. Liability

16.1. The parties' liability in connection with the processing of personal data shall be governed by the GDPR, other applicable data protection legislation and the parties' other contractual basis.

16.2. Nothing in this Data Processing Agreement limits the rights that data subjects have under mandatory data protection legislation.

16.3. Any commercial limitations of liability between the parties are governed by the Terms of Business or another separate agreement, to the extent such limitations are valid and do not conflict with mandatory data protection legislation.

16.4. The provisions on liability in this Data Processing Agreement do not alter the allocation of liability that follows directly from the GDPR.

17. Priority and relationship to other contractual documents

17.1. In the event of a conflict between this Data Processing Agreement and other contractual documents relating to the processing of personal data on behalf of the Customer, this Data Processing Agreement shall take precedence with regard to data protection matters.

17.2. The Terms of Business govern the commercial relationship between the parties, while this Data Processing Agreement governs MenyVoice's processing of personal data on behalf of the Customer.

17.3. The Customer's documented and lawful subsequent instructions may supplement this Data Processing Agreement.

17.4. A subsequent instruction cannot unilaterally change MenyVoice's commercial obligations beyond the requirements under applicable data protection legislation, without a separate agreement between the parties.

18. Amendments to the Data Processing Agreement

18.1. MenyVoice may update this Data Processing Agreement when necessary as a result of:

  • changes in applicable data protection legislation;
  • regulatory requirements;
  • changes in the service's processing activities;
  • changes in security measures;
  • changes in the sub-processor chain;
  • other circumstances necessitating an update.

18.2. Material changes affecting the Customer's rights or MenyVoice's data protection obligations shall be notified to the Customer with reasonable notice before they take effect, unless the change must be implemented more quickly as a result of legislation, regulatory requirements or security considerations.

18.3. Changes to sub-processors are handled separately under section 8.

19. Governing law, venue and contact

19.1. The Data Processing Agreement is governed by Danish law, without limiting the application of mandatory EU law or other applicable data protection legislation.

19.2. Disputes between the parties relating to this Data Processing Agreement that cannot be resolved amicably shall be settled by the Danish courts, with the Copenhagen City Court (Københavns Byret) as the venue, to the extent such a venue agreement is valid.

19.3. Questions regarding the Data Processing Agreement may be sent to:

EzyAcnt ApS / MenyVoice
CVR no.: 38362925
Olsbækeng 12
2670 Greve
Denmark

E-mail: hello@menyvoice.com


Appendix A – Subject matter, nature, purpose and duration of the processing

A.1 Subject matter

The processing comprises personal data processed by MenyVoice on behalf of the Customer in connection with the provision of MenyVoice's AI-based telephony, voice, ordering, booking and customer service service.

A.2 Nature

Depending on the Customer's configuration, the processing may, among other things, consist of:

  • collection;
  • registration;
  • structuring;
  • storage;
  • organisation;
  • searching;
  • retrieval;
  • reading;
  • use;
  • disclosure by transmission to relevant sub-processors;
  • conversion of speech to text;
  • generation of AI-based responses;
  • generation of synthetic speech;
  • generation of transcriptions and summaries;
  • export;
  • rectification;
  • restriction;
  • erasure.

A.3 Purpose

The processing takes place for the purposes of:

  • receiving and answering telephone calls;
  • communicating with the Customer's callers;
  • providing automated customer service;
  • answering questions;
  • registering and handling orders;
  • registering and handling reservations;
  • registering and forwarding messages;
  • forwarding relevant calls;
  • generating transcriptions;
  • generating AI summaries;
  • generating speech and AI responses;
  • providing relevant information to the Customer;
  • supporting integrations activated by the Customer;
  • supporting technical operations, security, troubleshooting and support;
  • carrying out processing in accordance with the Customer's documented instructions.

A.4 Duration

The processing takes place for as long as MenyVoice provides the relevant service to the Customer and thereafter only to the extent necessary for:

  • deletion or return at the Customer's choice;
  • implementation of applicable retention periods;
  • handling of backups;
  • compliance with legal storage obligations.

The specific retention and deletion arrangements are set out in Appendix G.


Appendix B – Categories of data subjects

Depending on the Customer's use of the service, the processing may comprise:

  • persons who call the Customer;
  • the Customer's customers;
  • prospective customers;
  • guests;
  • persons making reservations;
  • persons placing orders;
  • persons who receive or leave messages;
  • the Customer's employees;
  • the Customer's administrators and platform users;
  • the Customer's contact persons;
  • suppliers;
  • business partners;
  • other persons whose information is included in a relevant call, message or workflow.

Appendix C – Categories of personal data

Depending on the Customer's configuration, purpose and the data subject's conversation, the processing may comprise the following categories of personal data.

C.1 Identification and contact information

  • name;
  • telephone number;
  • e-mail address;
  • physical address;
  • delivery address;
  • postal code;
  • company information;
  • other contact information provided by the data subject.

C.2 Call and communication information

  • audio recording;
  • transcription;
  • AI-generated summary;
  • time;
  • date;
  • duration;
  • technical call metadata;
  • information about the outcome of the call;
  • messages;
  • conversation content.

C.3 Order and reservation information

  • ordered goods or services;
  • order information;
  • reservation time;
  • number of persons;
  • delivery information;
  • pick-up information;
  • special instructions;
  • relevant remarks.

C.4 User, account and technical information

  • name and e-mail address of platform users;
  • user identifiers;
  • IP address;
  • device information;
  • system data;
  • log data;
  • technical metadata.

C.5 Special categories of personal data

MenyVoice is not, as a general rule, designed to ask callers for special categories of personal data under Article 9 of the GDPR.

Since telephone conversations are free-flowing conversations, a data subject may nevertheless voluntarily disclose such information.

The Customer is responsible for:

  • assessing whether the processing of such information is necessary and lawful;
  • ensuring a valid legal basis under Article 9 of the GDPR, where relevant;
  • configuring the service and instructions so that unnecessary processing is limited.

C.6 Criminal offence data

The service is not, as a general rule, designed for the processing of information about criminal offences.

If such information is nevertheless included in a call, the Customer is responsible for assessing the lawfulness and necessity of the processing.


Appendix D – Documented processing instructions

MenyVoice is instructed to:

  • process personal data to the extent necessary to provide the service and configuration chosen by the Customer;
  • follow the Customer's documented instructions;
  • use approved sub-processors;
  • carry out processing through the functions and integrations activated by the Customer;
  • maintain appropriate technical and organisational security measures;
  • assist the Customer with data subjects' rights;
  • assist the Customer in the event of a personal data breach;
  • assist the Customer with relevant obligations under Articles 32-36 of the GDPR;
  • delete or return personal data in accordance with the Customer's instructions and this Data Processing Agreement;
  • carry out international transfers solely in accordance with the Customer's instructions and Chapter V of the GDPR;
  • refrain from using the Customer's personal data for independent, incompatible purposes.

The Customer may give supplementary written instructions if these:

  • are lawful;
  • fall within MenyVoice's role as a data processor;
  • are technically possible or can be made technically possible under a separate agreement;
  • do not require MenyVoice to act in breach of applicable law.

If an instruction requires significant additional work or technical changes, the parties may agree reasonable commercial terms for this, provided that this does not limit MenyVoice's mandatory obligations under the GDPR.


Appendix E – Sub-processors

E.1 MenyVoice's Sub-processor List

MenyVoice maintains a separate, updated and continuously available Sub-processor List.

The list sets out the sub-processors approved for processing the Customer's personal data, including, as applicable:

  • the supplier's name;
  • purpose of processing;
  • relevant data categories;
  • processing location;
  • relevant international transfers;
  • any relevant transfer basis.

The Sub-processor List forms part of this Data Processing Agreement by reference.

E.2 Central sub-processor

MenyVoice currently uses:

Alayic Ltd
9 West Street
Congleton
England
CW12 1JN
United Kingdom
Company No. 16581244

Function: Underlying AI voice, telephony and platform service.

Alayic processes personal data as a sub-processor in the relevant processing chain.

E.3 Alayic's sub-processors

Alayic uses further sub-processors as part of the technical delivery of the platform.

Alayic's current data processing agreement is used as the authoritative external source of information about Alayic's own sub-processor chain:

https://www.alayic.com/data-processing-agreement

Alayic's sub-processors may, among other things, include suppliers of:

  • cloud hosting;
  • storage;
  • telephony;
  • real-time media;
  • speech recognition;
  • language models;
  • speech generation;
  • e-mail;
  • security;
  • payment;
  • integrations.

E.4 Relationship between MenyVoice's register and Alayic's DPA

MenyVoice's own Sub-processor List is the customer-facing overview of the sub-processors included in MenyVoice's processing on behalf of the Customer.

Alayic's DPA is used as external documentation of Alayic's technical sub-processor chain.

If a change at Alayic results in a new sub-processor processing the Customer's personal data, the change shall be handled in accordance with section 8 of this Data Processing Agreement.

A change on Alayic's public list does not in itself constitute the Customer's approval, if the relevant change requires notification under this Data Processing Agreement.


Appendix F – International transfers

F.1 Current hosting locations

The underlying platform currently uses, among other things:

  • Microsoft Azure, UK South – application, database and logging;
  • Amazon Web Services, Ireland – storage of call recordings.

F.2 Other processing locations

Certain providers of voice, language model, telephony and other technology services may process personal data outside the EU/EEA and the United Kingdom, including in the USA.

The specific processing locations depend on the suppliers and functions used in the relevant processing chain.

F.3 Transfer basis

International transfers shall, where relevant, be based on a valid transfer basis under Chapter V of the GDPR.

This may, among other things, be:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses (SCCs);
  • the UK International Data Transfer Addendum, where relevant;
  • other valid safeguards under applicable law.

F.4 Instruction and transfer basis

An international transfer may only be carried out if:

  • the transfer is covered by the Customer's documented instructions; and
  • the relevant transfer basis under Chapter V of the GDPR is in place.

A transfer basis does not in itself constitute an instruction from the Customer.

F.5 Supplementary measures

Where necessary based on a specific assessment, relevant supplementary contractual, technical or organisational measures shall be applied.

F.6 Documentation

MenyVoice shall, to a reasonable extent, be able to make available documentation of relevant transfer mechanisms to the Customer, where this is necessary for the Customer's compliance with applicable data protection rules.


Appendix G – Storage and deletion

G.1 Call recordings

Call recording is an integral part of the current functionality of the underlying platform.

Calls processed through MenyVoice are, as a starting point, recorded, and the recording function cannot currently be generally disabled.

The Customer is responsible for ensuring a valid legal basis, fulfilling the duty to inform callers, and configuring the service in accordance with applicable data protection legislation.

The current default retention period for call recordings is 365 days, unless the Customer has chosen a shorter retention period where this is technically supported.

G.2 Transcriptions

The current default retention period for transcriptions is 365 days, unless the Customer has chosen a shorter retention period where this is technically supported.

G.3 AI-generated summaries

The current default retention period for AI-generated summaries is 365 days, unless the Customer has chosen a shorter retention period where this is technically supported.

G.4 Shorter retention

Where the platform technically supports it, the Customer may choose a shorter retention period.

G.5 Manual deletion

The Customer may at any time request MenyVoice to manually delete relevant personal data.

The deletion may, among other things, comprise:

  • call recordings;
  • transcriptions;
  • AI summaries;
  • order information;
  • reservation information;
  • other identifiable call content.

G.6 Billing and system information

Information that a call has taken place, including for example:

  • time;
  • duration;
  • technical system information;
  • billing information,

may be stored for a longer period when necessary for bookkeeping, documentation or other legal obligations.

Such information shall, where possible, be stored without direct identifiers.

G.7 Termination

Upon termination of the agreement, personal data shall be returned or deleted at the Customer's choice and in accordance with point 15 of the Data Processing Agreement.

G.8 Backups

Backups may be stored for up to 7 days on a rolling basis.

Data deleted from active systems may therefore still exist in backup media until the relevant backup is overwritten.


Appendix H – Technical and organisational security measures (TOMs)

MenyVoice and relevant sub-processors shall maintain appropriate technical and organisational security measures.

The measures include, where relevant:

H.1 Access control

  • role-based access;
  • least-privilege principle;
  • restricted administrative access.

H.2 Authentication

  • secure passwords;
  • multi-factor authentication, where relevant;
  • secure management of privileged accounts.

H.3 Encryption

  • encryption of data in transit;
  • TLS-protected connections;
  • relevant encryption mechanisms at rest, where supported.

H.4 Logical separation

Customer data shall, as far as possible, be logically separated from other customers' data.

H.5 Call data

Call recordings and other call content shall be stored with appropriate access control.

H.6 Logging and monitoring

Relevant events are logged for the purposes of:

  • operations;
  • troubleshooting;
  • security;
  • incident management.

H.7 Backup and recovery

Appropriate backup and recovery procedures are used.

H.8 Confidentiality

Persons with access to personal data shall be subject to appropriate confidentiality obligations.

H.9 Vendor management

Sub-processors shall be contractually obliged to protect personal data in accordance with Article 28 of the GDPR.

H.10 Incident management

There shall be procedures for:

  • registration;
  • assessment;
  • containment;
  • remediation;
  • documentation;
  • relevant notification.

H.11 Ongoing assessment

Security measures are continuously assessed in relation to:

  • technological developments;
  • the risk landscape;
  • changes in the processing;
  • applicable legislation.

Appendix I – Assistance with data subjects' rights

MenyVoice shall assist the Customer, to the extent necessary and technically possible, with:

  • locating relevant information;
  • export;
  • rectification;
  • restriction;
  • deletion;
  • other processing necessary for the Customer's handling of data subjects' rights.

Since callers are normally identified by telephone number, it may be necessary to provide:

  • telephone number;
  • date or approximate time;
  • which company the call concerned;
  • other relevant information.

Appendix J – Procedure in the event of a personal data breach

In the event of suspicion or confirmation of a personal data breach:

  1. The incident is registered.
  2. Damage and unauthorised access are contained.
  3. The scope and affected information are assessed.
  4. Relevant sub-processors are involved.
  5. The Customer is notified without undue delay.
  6. Available information is shared with the Customer on an ongoing basis.
  7. Remedial measures are implemented.
  8. The incident is documented.
  9. Relevant improvements are assessed and implemented.

Appendix K – Audit and documentation

MenyVoice shall, on request, be able to make available relevant documentation regarding:

  • this Data Processing Agreement;
  • technical and organisational security measures;
  • relevant sub-processors;
  • international transfers;
  • personal data breaches;
  • retention and deletion procedures;
  • other documentation reasonably necessary for the Customer's compliance with Article 28 of the GDPR.

Where existing documentation reasonably meets the Customer's control needs, this may be used instead of a physical audit.


Appendix L – Return and deletion upon termination

L.1 The Customer's choice

Upon termination of the services involving the processing of personal data, MenyVoice shall, at the Customer's choice, return or delete the personal data processed by MenyVoice on behalf of the Customer.

The Customer's choice shall be communicated to MenyVoice before or in connection with the termination of the agreement.

L.2 Return

If the Customer chooses return, MenyVoice shall make the relevant personal data available in a common and technically reasonable format, unless otherwise agreed.

Once the return has been completed, the remaining copies shall be deleted in accordance with this Data Processing Agreement, unless Union or Member State law requires continued storage.

L.3 Deletion

If the Customer chooses deletion, MenyVoice shall delete the relevant personal data and ensure that equivalent deletion is carried out throughout the relevant sub-processor chain.

The deletion shall be carried out in accordance with the technical processes and retention arrangements described in Appendix G, without limiting MenyVoice's obligations under point 15 of the Data Processing Agreement.

L.4 Backups

Personal data deleted from active systems may still exist in backups for the limited period set out in Appendix G.

Such information may not be restored or used for any purpose other than necessary disaster recovery or other legitimate security-related restoration.

If data is restored from a backup, relevant previous deletion instructions must be carried out again.

L.5 Statutory storage

If Union or Member State law requires the continued storage of specific personal data, such data may only be stored to the extent and for the period required by the legal requirement.

Such information may not be processed for incompatible purposes.

L.6 Confirmation

MenyVoice shall, on request, be able to confirm to the Customer, to a reasonable extent, that the agreed return or deletion has been completed.