Last updated: 30 May 2026 · v2.0
Data Processing Agreement
If you use vokse in a household with other members, share access with an accountant, or run a small team, GDPR Article 28 likely applies. This DPA is pre-signed on our side and automatically incorporated into our Terms. You don't have to do anything to accept it. The PDF version is available at hello@vokse.ai on request.
On this page
1. Roles
You (the customer) are the data controller for the personal data you upload or generate in vokse. Exafire LLC, which operates vokse, is the data processor, acting on your documented instructions.
2. Scope of processing
We process your data only to deliver the service: storing transactions, running the AI assistant, syncing with banks via Open Banking, generating reports, and providing support. We do not use your data for any other purpose.
3. Data categories
Identifiers (name, email), financial data (accounts, transactions, balances), behavioural data (usage logs), and any free-text or attachments you choose to upload (memos, receipts, voice memos).
4. Sub-processors
Our current sub-processor list is at /sub-processors. We notify you in-app and by email at least 14 days before adding or replacing a sub-processor. You can object. If we can't accommodate the objection we'll let you terminate with a prorated refund.
5. International transfers
Primary processing is in the EU. Exafire LLC is established in the United States and accesses that data from there, and some sub-processors (Anthropic, OpenAI, Plaid, Apple, Google, RevenueCat) process it outside the EU; both rely on the Standard Contractual Clauses (SCCs 2021/914). Encryption and access controls travel with the data.
6. Security
TLS 1.3 in transit, AES-256 at rest, KMS-managed keys, scoped IAM, audit logging on every write, vulnerability scanning on every deploy, annual penetration test, ISO 27001 alignment. See /security for the long version.
7. Personal-data breach
We will notify you of a confirmed personal-data breach without undue delay and in any case within 48 hours. Notifications go to the email on the account and (where you've nominated one) to your security contact.
8. Data subject requests
You can satisfy access, rectification, erasure and portability requests from Settings → Privacy & data without contacting us. If you do need us, we'll respond within 30 days.
9. Audits
On request, we will share our most recent independent audit reports (ISO 27001 surveillance, SOC 2 Type II once obtained), penetration-test summary and architecture diagrams under NDA. For larger customers we accept third-party audits with 30 days' notice, capped at one per year.
10. End of the relationship
On termination, we return or delete your data within 30 days, at your option. Audit logs may be retained longer where regulatory obligations require.