Documento legale ufficiale
Sub-responsabili
Questo è il documento legale ufficiale pubblicato da Voice2Evolve.
La traduzione italiana non è ancora disponibile. Viene mostrata la versione inglese ufficiale.
Data di efficacia
2026-03-02
Versione legale
2026-06-02
Ultimo aggiornamento
2026-06-02
Soggetto legale
Voice2Evolve UG (haftungsbeschränkt)
Sede legale registrata
Amtsgericht Stuttgart, HRB 803557
Last updated: June 2, 2026
Voice2Evolve UG (haftungsbeschränkt) ("Voice2Evolve") uses the following third-party subprocessors to deliver the Voice2Evolve Services. Subprocessors that process Personal Data on Voice2Evolve's behalf are subject to written data processing terms intended to provide protections appropriate to their role and consistent with the Master Data Processing Agreement (MDPA).
This list is maintained in accordance with GDPR Article 28(2). Voice2Evolve will provide reasonable prior notice of new or changed subprocessors. To receive notifications, contact help@voice2evolve.com.
Current Subprocessors
| Provider | Role | Data Location | Legal Safeguards |
|---|---|---|---|
| Supabase Inc. | Database, Authentication | EU (Stockholm, Sweden primary hosting); onward transfers to United States / Singapore subprocessors | Supabase DPA + SCCs + supplementary safeguards documented in Supabase TIA |
| OpenAI, L.L.C. | AI Inference / Voice API | EU-bound only where configured and available; US / international processing may apply outside that configuration, including Batch | OpenAI DPA + SCCs + CPRA Compliance; modified retention / abuse-monitoring terms for eligible configured API use; ZDR, no-training and regional-processing controls are provider- and project-configuration dependent |
| Google Cloud Platform (Google Cloud EMEA Limited / Google LLC) | AI Inference (Vertex AI / Gemini API where configured) | EU / United States / selected Google Cloud region depending on deployment | Google Cloud CDPA + SCCs + DPF where applicable |
| Microsoft Azure (Microsoft Ireland Operations Limited / Microsoft Corporation) | AI Inference (Azure-provided Microsoft Foundry Models / Azure OpenAI where configured) | Sweden Central project/resource; Global deployment for selected Azure-provided models | Microsoft Products and Services DPA + SCCs + DPF where applicable |
| Stripe Payments Europe Ltd. | Payment Processing | EU / United States | GDPR DPA + SCCs |
| Vercel Inc. | Frontend Hosting (CDN) | EU / United States (AWS + Microsoft Azure + GCP; EU edge regions: Paris, Frankfurt, Sweden) | SCCs (Module 2, C2P) + UK IDTA |
| Railway Corp. (railway.com) | Backend Infrastructure | US / EU-region deployment (underlying infrastructure: GCP) | Executed DPA + EU SCCs (Module 2, C2P) + DPF |
| Cloudflare, Inc. | DNS Resolution, WebRTC TURN Relay | EU / United States | GDPR DPA + SCCs |
| Sentry, Inc. | Error Monitoring | EU / United States | GDPR DPA + DPF + SCCs + UK IDTA |
| Rybbit | Website & Product Analytics | EU (EEA — Hetzner; Cloudflare Object Storage) | GDPR DPA (accepted by use) + SCCs |
| Plus Five Five, Inc. (Resend) | Transactional Email | United States | GDPR DPA + DPF + SCCs + UK IDTA |
| Anthropic PBC | AI Inference (LLM) | United States | GDPR DPA + SCCs |
| Haufe-Lexware GmbH & Co. KG (Lexware) | Invoice & Accounting Synchronisation | EU (Germany) | GDPR DPA (AVV) |
Notes
- Vendor due diligence: Voice2Evolve reviews core subprocessors before use and keeps detailed vendor assessments, transfer reviews and configuration evidence internally for audit purposes.
- Infrastructure and observability: Supabase is the primary EU-hosted database/authentication provider. Hosting, DNS, relay and monitoring providers process only the data needed to operate and secure the service. Logs and error events are minimised and scrubbed; Sentry is configured with EU data storage.
- AI inference: OpenAI, Anthropic, Google Cloud Platform and Microsoft Azure process prompts, model inputs and outputs only where configured for the relevant feature. Voice2Evolve applies data minimisation before model calls. OpenAI retention, modified abuse-monitoring, ZDR, no-training and regional-processing controls are provider- and project-configuration dependent. OpenAI Batch API processing remains outside ZDR; Voice2Evolve applies PII redaction before submission and attempts remote file cleanup after processing. Batch processing remains a documented residual retention risk.
- AI feature restrictions: Google Cloud and Microsoft Azure AI services may be used only under assessed commercial cloud configurations. Persistent AI features such as stored files, vector stores, stored completions, Assistants/Threads, batch processing, grounding or fine-tuning require a separate retention and transfer review before customer personal data is submitted. Azure currently uses a Sweden Central project/resource with Global deployment for selected Azure-provided models; third-party marketplace/provider models are not approved without separate review.
- Analytics, email, payments and accounting: Rybbit analytics is limited to the marketing site and selected app areas and is disabled on sensitive session, analysis, account, billing, authentication and administration areas. Resend is used for transactional email, Stripe for payment and fraud-prevention processing, and Lexware for accounting records. No end-user voice, session content or authentication secrets are sent to Lexware.
- External identity providers: Identity providers selected by end users (for example Google or Microsoft for social sign-in) may act as independent controllers for their own authentication services. Voice2Evolve lists them as subprocessors only where Voice2Evolve engages them to process Customer Personal Data on the customer's behalf.
Contact
To receive advance notice of subprocessor changes or to raise an objection under GDPR Article 28(2), contact: