Skip to content
vokse.

Last updated: 30 May 2026 · v2.0

Data Processing Agreement

2 min read

If you use vokse in a household with other members, share access with an accountant, or run a small team, GDPR Article 28 likely applies. This DPA is pre-signed on our side and automatically incorporated into our Terms. You don't have to do anything to accept it. The PDF version is available at hello@vokse.ai on request.

On this page
  1. 1. Roles
  2. 2. Scope of processing
  3. 3. Data categories
  4. 4. Sub-processors
  5. 5. International transfers
  6. 6. Security
  7. 7. Personal-data breach
  8. 8. Data subject requests
  9. 9. Audits
  10. 10. End of the relationship

1. Roles

You (the customer) are the data controller for the personal data you upload or generate in vokse. Exafire LLC, which operates vokse, is the data processor, acting on your documented instructions.

2. Scope of processing

We process your data only to deliver the service: storing transactions, running the AI assistant, syncing with banks via Open Banking, generating reports, and providing support. We do not use your data for any other purpose.

3. Data categories

Identifiers (name, email), financial data (accounts, transactions, balances), behavioural data (usage logs), and any free-text or attachments you choose to upload (memos, receipts, voice memos).

4. Sub-processors

Our current sub-processor list is at /sub-processors. We notify you in-app and by email at least 14 days before adding or replacing a sub-processor. You can object. If we can't accommodate the objection we'll let you terminate with a prorated refund.

5. International transfers

Primary processing is in the EU. Exafire LLC is established in the United States and accesses that data from there, and some sub-processors (Anthropic, OpenAI, Plaid, Apple, Google, RevenueCat) process it outside the EU; both rely on the Standard Contractual Clauses (SCCs 2021/914). Encryption and access controls travel with the data.

6. Security

TLS 1.3 in transit, AES-256 at rest, KMS-managed keys, scoped IAM, audit logging on every write, vulnerability scanning on every deploy, annual penetration test, ISO 27001 alignment. See /security for the long version.

7. Personal-data breach

We will notify you of a confirmed personal-data breach without undue delay and in any case within 48 hours. Notifications go to the email on the account and (where you've nominated one) to your security contact.

8. Data subject requests

You can satisfy access, rectification, erasure and portability requests from Settings → Privacy & data without contacting us. If you do need us, we'll respond within 30 days.

9. Audits

On request, we will share our most recent independent audit reports (ISO 27001 surveillance, SOC 2 Type II once obtained), penetration-test summary and architecture diagrams under NDA. For larger customers we accept third-party audits with 30 days' notice, capped at one per year.

10. End of the relationship

On termination, we return or delete your data within 30 days, at your option. Audit logs may be retained longer where regulatory obligations require.