Data Processing Agreement
Last updated: 9 October 2026
This Data Processing Agreement (“DPA”) applies where VOQX processes personal data on behalf of a customer within the meaning of Art. 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. The customer is the controller (“Customer”); Evo Miles İletişim Hizmetleri – Mazhar Özgür, the operator of VOQX (“we”), is the processor. For customers with a paid plan, this DPA becomes part of our Terms of Service as soon as it is accepted in the account (Account → Data processing (DPA)); we record the date and the user who accepted it. If this DPA and the Terms of Service differ on data protection, this DPA prevails. Translations of this DPA are provided for information only; if a translation differs from this English version, the English version prevails.
1. Subject matter and duration
The subject matter is the provision of the VOQX software service under the Terms of Service. This DPA applies for as long as the Customer’s subscription runs and, after that, until we have deleted the Customer’s personal data as described in the section “Deletion and return”.
2. Nature and purpose of the processing
We process personal data only to provide the software service: monitoring publicly visible reviews, search results and mentions about the Customer’s businesses on the platforms the Customer selects; checking negative reviews against the platforms’ published rules; reply suggestions, translations and summaries; reports and email notifications; management of the account and of colleague logins; and software support.
Software support is read-only: to find and fix technical errors we can view the Customer’s dashboard without changing anything, and every such access is logged. We do not submit reports, contact platforms or publish anything on the Customer’s behalf.
Processing operations: collecting, storing, organising, analysing (including automated analysis by AI services), displaying, sending by email and deleting.
3. Types of personal data
Account and contact data of the Customer’s users and colleagues: name, email address, language, role and access rights, password (stored only as a hash) and sign-in data.
Publicly visible reviews and replies about the Customer’s businesses, including the name or nickname of the reviewer, text, rating and date, as shown by the platform.
Publicly visible search results, mentions and social media posts about the Customer: title, short text and link, not the author’s profile.
Usage data: settings, the status of reviews and reports in the dashboard, and technical logs.
We do not intend to process special categories of personal data (Art. 9 GDPR). They can, however, appear in public reviews written by third parties; we process them only as part of the review text.
4. Categories of data subjects
Users of the Customer’s account (the owner and colleagues), and authors of public reviews, replies, posts and other public content about the Customer’s businesses, including persons named in that content.
5. Instructions
We process personal data only on documented instructions from the Customer. The Terms of Service, this DPA and the Customer’s settings and actions in the dashboard are the Customer’s instructions. Further instructions must be given in writing (email is sufficient) and must be technically feasible within the standard service.
We process the data for other purposes only where applicable law requires it; in that case we inform the Customer beforehand unless that law prohibits it. We inform the Customer without undue delay if, in our opinion, an instruction infringes data protection law.
6. Confidentiality
Everyone who has access to the personal data on our side has committed to confidentiality or is under an appropriate statutory obligation of confidentiality. Access is limited to what is needed to run and support the service.
7. Security of processing
We take the technical and organisational measures described in Annex 1 (Art. 32 GDPR). We may adapt them to technical progress, provided the level of protection does not fall below the level described there.
8. Sub-processors
The Customer gives general authorisation for the use of sub-processors. Annex 2 describes the sub-processors used when this DPA is accepted. The full list with company names, purposes and locations is shown in the account; we also send it to anyone who asks at hello@voqx.ai.
We inform the Customer at least 30 days before we add or replace a sub-processor, by email or in the account. Within that period the Customer may object on reasonable data protection grounds. If we cannot resolve the objection, the Customer may cancel the affected plan before the change takes effect.
We bind every sub-processor by contract to data protection obligations that offer the same level of protection as this DPA, and we remain responsible to the Customer for their compliance.
9. International transfers
The Customer’s data is stored on servers in the EU (Frankfurt, Germany). We, the processor, are located in Türkiye and access the data remotely to run and support the service. Some sub-processors are located in, or access data from, countries outside the EU/EEA, for example the United States.
Where personal data is transferred to a country without an adequacy decision, the transfer is based on appropriate safeguards under Art. 46 GDPR. For transfers from the Customer to us, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: controller to processor) are incorporated into this DPA by reference. For onward transfers to sub-processors we rely on the Standard Contractual Clauses or on an adequacy decision, such as the EU-U.S. Data Privacy Framework for certified providers.
10. Assistance to the Customer
Taking into account the nature of the processing, we assist the Customer with appropriate measures in responding to requests from data subjects (Art. 12–23 GDPR). The Customer can view and export its data in the dashboard; for corrections, deletions and anything else, write to hello@voqx.ai.
If a data subject contacts us directly about data we process for the Customer, we forward the request to the Customer without undue delay and refer the person to the Customer.
We also assist the Customer, as far as the information is available to us, with the security of processing, the notification of personal data breaches, data protection impact assessments and prior consultation of supervisory authorities (Art. 32–36 GDPR).
11. Personal data breaches
We notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, by email to the address of the account. As far as known, the notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information we do not have yet follows as soon as it is available.
12. Deletion and return
Until the end of the paid period, the Customer can export its data from the dashboard. We delete the Customer’s personal data within 30 days after the Customer asks us to close the account, unless law requires us to keep certain data longer (for example invoices). Backups are overwritten in the regular backup cycle.
13. Information and audits
We make available the information necessary to demonstrate compliance with Art. 28 GDPR, in particular this DPA, the measures in Annex 1 and the list of sub-processors.
The Customer may check our compliance, primarily by requesting written information. Inspections are possible with at least 30 days’ notice, during normal business hours, without disrupting operations and at the Customer’s cost, at most once a year unless a personal data breach or a supervisory authority makes another inspection necessary. For sub-processors, their own certifications and audit reports are used.
14. Responsibilities of the Customer
The Customer is responsible for the lawfulness of the processing it instructs, including the choice of businesses, platforms and search terms, and for informing its own users and colleagues. The Customer must not use the service to identify anonymous reviewers or for purposes other than monitoring and responding to what is said about its businesses.
15. Liability and end of this DPA
Liability under this DPA follows the Terms of Service, unless mandatory law provides otherwise. This DPA ends automatically when we have deleted all personal data processed for the Customer.
16. Contact
Questions about this DPA and data protection: hello@voqx.ai. Processor: Evo Miles İletişim Hizmetleri – Mazhar Özgür, Kumbaba Mah. Yediveren Sk. No: 1/1, 34980 Şile / İstanbul, Türkiye.
Annex 1 – Technical and organisational measures
Hosting: the Customer’s data is stored in a managed database in the EU (Frankfurt, Germany); the application runs in the same region.
Encryption: all connections use HTTPS (TLS). The database provider encrypts stored data.
Separation and access control: every customer’s data is separated by row-level security in the database. Users only see the data of their own account; colleagues only see the businesses and areas the owner has released. Rights are checked on the server before every change.
Sign-in: passwords are stored only as salted hashes. Repeated sign-in, sign-up and password attempts are limited, and sign-in, sign-up and the free check can be protected by a bot check. For abuse protection, connections are stored only as salted hashes, never as IP addresses.
Operator access: only the operator has administrative access. Support access to a customer’s dashboard is read-only and time-limited, and every access is logged (who, which account, when, until when).
Availability: the database provider makes regular backups. Scheduled jobs are monitored, and the operator is alerted to errors.
Data minimisation: we only collect publicly visible content. Free check results are deleted after 90 days, abuse-protection entries after one day. We never receive payment card data; payments are handled by Dodo Payments as Merchant of Record.
Annex 2 – Sub-processors
Categories and data locations: hosting and database (EU, Frankfurt, Germany); running the application (EU, Frankfurt, Germany, with a worldwide delivery network); retrieval of publicly available reviews and search results (specialised data provider); AI analysis of public review texts, reply suggestions and translations (AI provider in the United States); email delivery (email provider); bot protection for sign-in, sign-up and the free check (provider with a worldwide network).
Not sub-processors: Dodo Payments processes payment data as an independent controller (Merchant of Record). The AI assistants ChatGPT and Perplexity only receive a fixed question with the business name, website and country, no personal data from the account.
The full list with company names, purposes and locations is shown to signed-in customers with a paid plan under Account → Data processing (DPA). You can also ask for it at hello@voqx.ai.