Skip to content

ENNOVAQ (SMC-PRIVATE) LIMITED

Data Processing Addendum

Last updated Effective

1. Scope and how this DPA applies

This DPA forms part of the Terms of Service, or any other agreement for the Services, between ENNOVAQ (SMC-PRIVATE) LIMITED ("Ennovaq") and the business customer that accepts them ("Customer"). It applies whenever Ennovaq processes Customer Personal Data in providing the Services and Data Protection Laws apply to that processing. It takes effect when Customer accepts the Terms. Ennovaq will countersign a copy on request.

If this DPA conflicts with the Terms, this DPA prevails on data protection matters. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.

2. Definitions

  • Data Protection Laws: all laws on personal data that apply to the processing, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA").
  • Customer Personal Data: personal data that Ennovaq processes on Customer's behalf in providing the Services.
  • Standard Contractual Clauses or SCCs: the clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, version B1.0, in force since 21 March 2022.
  • Sub-processor: a third party engaged by Ennovaq to process Customer Personal Data.
  • Terms such as controller, processor, data subject, personal data breach and processing have the meanings given in the GDPR.

3. Roles

Customer is the controller of Customer Personal Data, or a processor acting for its own controller. Ennovaq is a processor, or a sub-processor. Ennovaq is an independent controller of the account, billing and usage data it needs to run its business, as described in the Privacy Policy.

4. Customer's responsibilities

Customer is responsible for having a lawful basis for the processing, for giving data subjects the information the law requires, and for the accuracy of the data it uploads. Where Customer uploads the voice or likeness of any person, Customer confirms that it holds that person's explicit consent, as our Acceptable Use Policy requires.

5. Ennovaq's obligations

Ennovaq will:

  1. Instructions. Process Customer Personal Data only on Customer's documented instructions, which are the Terms, this DPA and Customer's use and configuration of the Services, unless the law requires otherwise; in that case Ennovaq will tell Customer first, unless the law forbids it. Ennovaq will tell Customer if, in its opinion, an instruction infringes Data Protection Laws.
  2. Confidentiality. Ensure that everyone authorised to process Customer Personal Data is bound by confidentiality.
  3. Security. Implement the technical and organisational measures in Annex 2, appropriate to the risk.
  4. No model training. Not use Customer Personal Data to train AI models made available to anyone other than Customer.
  5. Data subject requests. Help Customer respond to requests from data subjects, through the Services' features or, where that is not possible, with reasonable assistance, and promptly pass on any request Ennovaq receives directly.
  6. Assistance. Provide reasonable help with Customer's security obligations, data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing and the information available to Ennovaq.

6. Sub-processors

Customer gives Ennovaq general authorisation to engage sub-processors. The current list is published on our Sub-processors page.

Ennovaq will update that page at least 30 days before a new sub-processor starts processing Customer Personal Data and will email Customers who have asked to receive notices. Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith; if they cannot resolve it, Customer may terminate the affected Service and receive a refund of any prepaid fees for the period after termination.

Ennovaq will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible to Customer for its sub-processors' performance of those obligations.

7. Personal data breaches

Ennovaq will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the data and data subjects affected, the likely consequences and the measures taken or proposed. Ennovaq will provide further information as it becomes available and take reasonable steps to contain the breach. Notifying a breach is not an admission of fault.

8. Deletion and return

When the Services end, Ennovaq will delete Customer Personal Data within 30 days, or return it first if Customer asks before the Services end, unless the law requires Ennovaq to keep it. Copies in backups are deleted as the backups are overwritten and remain protected by this DPA until then.

9. Audits

Ennovaq will make available the information reasonably necessary to demonstrate compliance with this DPA, including by answering a reasonable security questionnaire once a year. Where the law or a supervisory authority requires it, or after a personal data breach, Customer may audit Ennovaq's compliance on at least 30 days' written notice, during business hours, at Customer's cost, under confidentiality and without access to other customers' data.

10. International transfers

Ennovaq is established in Pakistan, which does not have an adequacy decision from the European Commission or the UK. To the extent Ennovaq processes Customer Personal Data that is subject to the GDPR, the UK GDPR or Swiss law, the following safeguards apply and are incorporated into this DPA:

  • EEA. The SCCs apply, with Module 2 (controller to processor) where Customer is a controller and Module 3 (processor to processor) where Customer is a processor. Customer is the data exporter and Ennovaq the data importer. The optional docking clause (Clause 7) applies. Under Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in section 6 of this DPA. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one determined by Customer's establishment or representative. Under Clauses 17 and 18, the SCCs are governed by the law of Ireland, and disputes are resolved by the courts of Ireland. Annexes I, II and III of the SCCs are completed by Annex 1, Annex 2 and section 6 of this DPA.
  • United Kingdom. The UK Addendum applies to transfers subject to UK law. Its Tables 1 to 3 are completed with the information in this DPA and its Annexes, and in Table 4 either party may end the Addendum as set out in its Section 19.
  • Switzerland. The SCCs apply with the changes Swiss law requires: references to the GDPR include the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner is the competent authority for transfers subject to Swiss law, and data subjects in Switzerland may bring claims in their place of habitual residence.

11. United States privacy laws

Where the CCPA or similar US state laws apply, Ennovaq acts as a service provider or processor. Ennovaq will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Services, or combine it with personal data it receives from others except as the law permits. Ennovaq will tell Customer if it can no longer meet these obligations, and Customer may take reasonable steps to stop and remedy unauthorised use.

12. Liability and duration

Each party's liability under this DPA is subject to the limitations in the Terms, except where the law or the SCCs do not allow it. This DPA lasts as long as Ennovaq processes Customer Personal Data.

Annex 1: Details of processing

ItemDetails
PartiesData exporter: Customer, as identified in its account. Data importer: ENNOVAQ (SMC-PRIVATE) LIMITED, Chandia House, Street No. 1 East, Rehman Colony, Khanpur, Rahim Yar Khan, Punjab, Pakistan, info@ennovaq.com
Subject matter and purposeProviding the Services Customer uses: generating speech, voice models, video, avatars, images, text and analyses; storing Inputs and Outputs; support
Nature of processingCollection, storage, structuring, transmission to AI model providers to generate results, retrieval, and deletion
Data subjectsCustomer's users, and people whose voice, image or details Customer includes in its Inputs
Categories of dataAccount details, Inputs (text, files, audio, images and video) and Outputs, usage records
Special categoriesVoice recordings and images of faces, used only to provide features Customer requests and not to identify individuals
FrequencyContinuous, for as long as Customer uses the Services
RetentionAs set out in the Privacy Policy, and section 8 of this DPA

Annex 2: Technical and organisational measures

  • Encryption. Data is encrypted in transit with TLS, and uploaded files and voice data are encrypted at rest.
  • Access control. Access is limited to staff who need it, protected by multi-factor authentication, and reviewed regularly.
  • Separation. Each customer's data is logically separated, and voice models are tied to the account that created them.
  • Secure development. Code review, dependency updates and separate environments for development and production.
  • Monitoring and logging. Security-relevant events are logged and monitored, and logs are kept for up to 90 days.
  • Resilience. Regular backups, tested restoration and infrastructure from established cloud providers.
  • Incident response. A documented process to contain, assess and notify personal data breaches.
  • Supplier management. Due diligence on sub-processors and written data protection terms with each one.
  • Minimisation and deletion. Only the data needed for a request is sent to model providers, and deletion follows the schedules in the Privacy Policy.