Standard Contractual Reference: Article 28, EU Regulation 2016/679 (GDPR) and UK GDPR
This Data Processing Agreement (“DPA”) applies to Customer accounts utilizing AdventVoice for real-time translation, captioning, and speech synthesis services.
1. BACKGROUND AND PURPOSE
1.1. Customer and Company have entered into an agreement governed by the AdventVoice Terms of Service (“Principal Agreement”) under which Processor provides real-time speech translation, live captioning, transcription, and neural speech synthesis services for church worship services, conferences, educational seminars, and live assemblies (“Services”).
1.2. In providing the Services, Processor processes Personal Data on behalf of Customer. This Data Processing Agreement (“DPA”) governs the processing of such Personal Data in compliance with Applicable Data Protection Laws.
2. DEFINITIONS
- “Applicable Data Protection Laws” means all worldwide privacy and data protection laws applicable to the processing of Personal Data under the Principal Agreement, including the GDPR, the UK Data Protection Act 2018, and state statutory frameworks (e.g., California Consumer Privacy Act / CPRA).
- “Customer Personal Data” means any Personal Data processed by Processor on behalf of Customer pursuant to the Principal Agreement, including spoken speech audio, speaker recordings, verbatim transcripts, and administrative user credentials.
- “Special Category Data” means personal data revealing religious beliefs or philosophical convictions pursuant to GDPR Article 9.
3. ROLES AND SCOPE OF PROCESSING
3.1. Controller and Processor: Customer is the Controller of Customer Personal Data, and Processor is the Processor acting on behalf of Customer.
3.2. Subject Matter & Duration: The subject matter is the provision of real-time speech translation and live captions for spoken events and worship services. Processing endures for the term of the Principal Agreement plus applicable post-termination retention periods.
3.3. Nature & Purpose: Real-time ingestion of speech audio, machine translation, synthetic audio rendering, generation of meeting transcripts and summaries, and administrative account management.
3.4. Categories of Data Subjects: Preachers, pastors, guest speakers, lecturers, liturgy readers, translators, administrative staff, and congregational or event participants.
3.5. Categories of Personal Data: Spoken voice audio, vocal acoustic characteristics (voice models of consented adults), verbatim speech transcripts, personal names of speakers, and administrative account identifiers.
4. INSTRUCTIONS OF THE CONTROLLER
4.1. Processor shall process Customer Personal Data only on documented instructions from Customer, including with respect to transfers of personal data to a third country, unless required to do so by applicable law.
4.2. The Principal Agreement and Customer’s technical configuration within the AdventVoice admin console constitute Customer’s complete instructions. Processor shall notify Customer immediately if, in its opinion, an instruction infringes Applicable Data Protection Laws.
5. CONFIDENTIALITY AND PERSONNEL
5.1. Processor shall ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.2. Processor shall take reasonable steps to ensure the reliability and security clearance of any personnel who may have access to Customer Personal Data.
6. TECHNICAL AND ORGANIZATIONAL MEASURES (TOMS)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing (specifically including Special Category religious or philosophical content), Processor implements the following measures:
6.1. Pseudonymisation and Encryption:
- Strict TLS 1.3 encryption in transit across all WebSocket and HTTP communication channels.
- Robust AES-256 encryption at rest for all database tables, archives, and cloud storage volumes.
- Salted HMAC-SHA256 one-way hashing for viewer IP addresses; raw IPs are never stored.
- Cryptographic envelope encryption (AES-GCM-256) for tenant third-party provider API keys.
6.2. Tenant Isolation: Multi-tenant database isolation enforced via Supabase PostgreSQL Row-Level Security (RLS) policies preventing cross-tenant access.
6.3. Session Hardening: Single-use, time-bounded (30-second) WebSocket authorization tickets eliminating token exposure in URL strings.
6.4. Ephemeral Audio Pipelines: In normal operation, raw live microphone audio is processed in memory and never written to persistent disk storage.
6.5. Confidential Session Shield: Built-in server-side controls that programmatically block diagnostic audio capture whenever Confidential Mode is selected.
7. SUBPROCESSORS
7.1. Authorized Subprocessors: Customer provides general authorization for Processor to engage the third-party subprocessors listed in the Subprocessor Registry.
7.2. Subprocessor Obligations: Processor shall impose on each subprocessor data protection obligations no less protective than those imposed on Processor under this DPA.
7.3. Notice of Changes: Processor will provide thirty (30) days’ prior notice of any intended changes concerning the addition or replacement of subprocessors. Customer may object on reasonable data protection grounds within fourteen (14) days of notice.
8. DATA SUBJECT RIGHTS ASSISTANCE
8.1. Taking into account the nature of the processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligation to respond to requests exercising Data Subject rights (access, rectification, erasure, portability, objection).
8.2. If Processor receives a request directly from a Data Subject, Processor shall promptly notify Customer and instruct the Data Subject to direct their request to Customer.
9. PERSONAL DATA BREACH NOTIFICATION
9.1. Processor shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
9.2. The notification shall describe the nature of the breach, the categories and approximate number of Data Subjects concerned, the likely consequences, and the remedial measures taken or planned.
10. DELETION AND RETURN OF DATA
10.1. Upon termination of the Services or upon Customer’s written request, Processor shall, at Customer’s choice, securely delete or return all Customer Personal Data, unless applicable statutory law requires storage of the personal data.
10.2. Deletion is enforced automatically in accordance with the Retention Policy: 90-day purge for soft-deleted session content, 30-day purge for connection diagnostic logs, and 48-hour purge for temporary debug audio files.
11. AUDIT AND COMPLIANCE VERIFICATION
Processor shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to reasonable audits conducted by Customer or an independent auditor.

