Skip to content
Euphona

Legal

Data processing agreement

The short version

When you send us your users' audio through the API, you are the controller and we are your processor. We process only on your instructions, never for training, hold it under stated security measures, tell you about a breach without undue delay, help you answer your users' rights requests, and return or delete everything when we are done.

A summary is not the agreement. Where the two differ the clauses apply — but if the summary is misleading, that is our mistake to fix rather than yours to discover.

When this applies

This agreement applies where you use Euphona to process personal data on behalf of your own users — in practice, the API. It forms part of the API terms and takes effect automatically; you do not have to sign it for it to bind us. A signed counterpart is available on request at legal@euphonaai.com if your compliance process needs one on file.

It does not apply to audio you upload to the Studio for yourself. There we are the controller, not your processor, and what governs is the privacy policy. Handing you a DPA for that relationship would describe it wrongly.

Subject matter, duration, nature and purpose

  • Subject matter — processing audio recordings and associated metadata that you submit, in order to return analysis and processed results.
  • Duration — for as long as your account is open, plus the retention periods stated below.
  • Nature and purpose — automated audio analysis and enhancement. Decoding, measurement, and the processing you requested. No profiling, no automated decision-making about individuals, no advertising use.
  • Types of personal data — audio recordings, which may contain a person’s voice and therefore be personal data in themselves; identifiers you send with a request; and technical metadata such as timings and request identifiers.
  • Categories of data subject — your users, and any person audible in the recordings they submit.

A recorded voice can be biometric data in some jurisdictions and under some uses. We do not perform voice identification, speaker recognition or any biometric matching, and the engine has no capability to do so — which is the reason we can say the special-category rules are not engaged rather than merely asserting it.

We act only on your instructions

We process the data only on your documented instructions. The API request is the instruction; there is no other channel by which we decide what to do with your users’ audio.

It is never used to train models. Not ours, not anyone else’s, not in aggregated or derived form. This is not a setting you have to find and disable, and there is no consent we could collect from you that would change it for your users — their consent is not yours to give.

If we ever believe an instruction of yours would breach data-protection law, we will tell you rather than quietly comply or quietly refuse.

Confidentiality

Everyone with any access is under a binding confidentiality obligation. More usefully than that: our staff cannot listen to customer audio. There is no control in any internal tool that plays it and no path that mints a link to it, so confidentiality here is enforced by the absence of a capability rather than by a promise about behaviour.

Every internal read of customer data is recorded in an append-only audit store held in a separate database, and the operations console refuses to display anything if that record cannot be written first.

Security measures

  • Encryption in transit, and encryption of backups at rest.
  • Audio reachable only by short-lived signed URLs scoped to a single object. It is never served from the API, never sits behind a cookie, and has no public address.
  • Per-workspace storage prefixes, so one customer’s files sit apart from another’s.
  • Untrusted media decoded in a sandbox with its own user, network and process namespaces, no capabilities, a memory ceiling and a wall-clock deadline.
  • Append-only auditing of internal access, in a separate database with insert-only grants.
  • Encrypted backups on a fixed cycle, with a weekly restore drill that actually restores.

The current state of all of this is on our security page, which is maintained to a rule of nothing we do not operate.

Sub-processors

You give general authorisation for the sub-processors listed on the processors named in our privacy policy. No third party holds your users’ audio — it stays on hardware we operate — and the list is short for that reason.

We give thirty days’ notice before adding one, and you may object. If you do and we cannot accommodate you, you may terminate and we refund the unused balance. Each sub-processor is engaged under terms no weaker than these, and we remain liable to you for what they do.

Helping you meet your own obligations

Your users will exercise rights against you, not us, and we will help you answer them. Deletion and export are available through the API, so most requests are something you can satisfy directly without waiting on us — which is faster for your user and is the point of building it that way.

Where a request needs us, write to privacy@euphonaai.com. We will also give you what you reasonably need for a data-protection impact assessment or a consultation with your regulator, at no charge.

If there is a breach

We notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event in time for you to meet your own seventy-two-hour obligation. The notice describes what happened, which data and roughly how many people are affected, what we have done, and what we recommend you do.

We will send an initial notice with incomplete information rather than a complete one late. A breach report that waits for certainty is a breach report that arrives after your deadline.

Return and deletion

On termination, or at any time on request, we delete or return the data at your choice. Deletion is real deletion, not flagging. Copies persist in encrypted backups for up to 14 days, and a restore never resurrects deleted material into a live account.

We retain nothing afterwards except what law requires us to keep, and we will tell you what that is if you ask.

Audit

You may audit our compliance with this agreement, once a year or after a breach affecting you, on reasonable notice. In the first instance we will answer with documentation and a questionnaire, because that satisfies most audits without either of us spending a week on it. If that is genuinely insufficient for your regulator, we will accommodate an on-site or remote audit, and we will not use scheduling to make it impractical.

There is no third-party certification to hand you. We have not completed SOC 2 or ISO 27001 and are not claiming either; when a customer contract requires one, it gets budgeted then.

Liability under this agreement

This agreement is part of the terms of service, and the limit of liability there applies to everything in it. It is one cap across both documents rather than a second one stacked on top — otherwise the same incident could be claimed twice, which is not what either of us is agreeing to.

Three things that cap does not touch, because it cannot and should not: what the GDPR gives a data subject directly against a processor; what the Standard Contractual Clauses give the people whose data it is; and anything the law says may not be limited at all. A processor agreement that claimed to cap those would be unenforceable in the part that mattered, and would tell you something about the rest of it.

International transfers

Euphona is operated from Hong Kong and its servers are in the European Economic Area, so data you send is processed in the European Economic Area and administered from Hong Kong.

Hong Kong has no European adequacy decision, so transfers of EEA or UK personal data to us rely on the Standard Contractual Clauses, which are incorporated into this agreement and which we will execute separately on request. Under Hong Kong’s own Personal Data (Privacy) Ordinance we handle the data as a data user bound by its six Data Protection Principles.

One thing an assessor should know rather than discover. PDPO section 33, Hong Kong’s cross-border transfer restriction, has been on the statute book since 1996 and has never been brought into force. So Hong Kong has no operative statutory export control, and the protection your data gets from us does not rest on one.

It rests on things you can check instead: the data stays on our machines in the European Economic Area and is processed there, not moved to Hong Kong; access from Hong Kong is remote administrative access by named people, logged in an append-only store; the Standard Contractual Clauses are incorporated into this agreement and we will execute them on request; and the six Data Protection Principles bind us as a data user regardless. We would rather tell you where the floor is missing and show you what we built over it than have your reviewer find the gap and assume we did not know.