Legal
Data Processing Addendum
Last updated: July 21, 2026
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service (“ToS”) and any other agreement governing the direct relationship between the Parties hereto (the ToS and any other agreement collectively, the “Agreement”) by and between Voxjar AI Tech, Inc. (“Voxjar”, “we”, “us”, or “our”) and you, whether personally or on behalf of an entity (“Customer”) (each individually a “Party” and collectively the “Parties”). By agreeing to the ToS, Customer agrees to this DPA.
1. Definitions
In addition to capitalized terms defined elsewhere in this DPA, the following terms shall have the meanings ascribed to them herein.
1.1 “Adequacy Decision,” “data importer,” “data exporter,” “Process,” “Processing,” “Sub-Processor,” and “Supervisory Authority” shall each have the meaning ascribed to it under Data Protection Law.
1.2 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.
1.3 “Business” and “Controller” shall have the meanings ascribed to them in Data Protection Law and shall be used interchangeably herein.
1.4 “Consumer” and “Data Subject” shall have the meanings ascribed to them in Data Protection Law and shall be used interchangeably herein.
1.5 “Covered Data” means the data processed as detailed in the Agreement and for the purposes described in the Agreement.
1.6 “Data Protection Law” means all laws and regulations applicable to the Processing of Covered Data, including, as applicable, laws and regulations of the European Union (“EU”), the European Economic Area (“EEA”) and their member states, Switzerland, and the United Kingdom (“UK”), including without limitation Regulation (EU) 2016/679 (the “GDPR”), EU Directive 2002/58/EC (the “e-Privacy Directive”) or the superseding e-Privacy Regulation once effective, and the United Kingdom’s General Data Protection Regulation (“UK GDPR”), and, as applicable, the laws and regulations of the United States, including without limitation the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (collectively, the “CCPA”) and the comprehensive consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, and Maryland, each as amended from time to time.
1.7 “Member State” means a member state of the EU.
1.8 “Personal Data” and “Personal Information” shall have the meanings ascribed to them in Data Protection Law and shall be used interchangeably herein.
1.9 “Processor” and “Service Provider” shall have the meanings ascribed to them in Data Protection Law and shall be used interchangeably herein.
1.10 “Services” shall have the meaning ascribed to it in the Agreement.
1.11 “SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.12 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner’s Office under s.119A(1) of the Data Protection Act 2018.
2. Designation
The Parties acknowledge and agree that, with regard to the Covered Data, Customer is a Controller and a Business, and Voxjar is a Processor and a Service Provider.
3. Obligations
3.1 Compliance with Law. With respect to the Covered Data, the Parties shall comply with Data Protection Law. Each Party shall promptly inform the other if it is unable to comply with this DPA or Data Protection Law in performing its obligations under the Agreement. If the non-complying Party cannot comply within a reasonable period of time, or is in substantial or persistent breach of this DPA or Data Protection Law, the complying Party shall be entitled to remediate the non-compliant action and/or terminate the DPA and the Agreement insofar as it concerns Processing of Covered Data.
3.2 Limitations on Processing. Voxjar shall Process Covered Data only on and in accordance with Customer’s documented instructions, as set forth in the Agreement, this DPA, and Customer’s use and configuration of the Services, and shall Process Covered Data only for the limited purposes specified in the Agreement. Voxjar shall promptly inform Customer if, in its opinion, an instruction infringes Data Protection Law.
3.3 Restrictions on Use of Covered Data. Notwithstanding anything to the contrary in the Agreement, Voxjar shall not:
(a) use Covered Data to train, retrain, fine-tune, or improve any artificial intelligence or machine learning model, whether Voxjar’s own or any third party’s;
(b) use Covered Data for advertising or marketing purposes;
(c) sell or share Covered Data (as “sell” and “share” are defined under the CCPA); or
(d) Process Covered Data for any purpose other than providing the Services in accordance with Customer’s documented instructions, or as required by applicable law.
Voxjar shall ensure that its Sub-Processors, including all providers of artificial intelligence models, are contractually prohibited from retaining Covered Data beyond transient processing and from using Covered Data to train or improve any models.
3.4 CCPA. To the extent any Covered Data is Personal Information subject to the CCPA, Voxjar shall not: (i) sell or share the Personal Information; (ii) retain, use, or disclose the Personal Information for any purpose other than for the specific business purpose of performing the Services under the Agreement, or as otherwise permitted by the CCPA; (iii) retain, use, or disclose the Personal Information outside of the direct business relationship with Customer; or (iv) combine Personal Information received from Customer with Personal Information received from or on behalf of another person, or collected from Voxjar’s own interactions with Consumers, except where required to provide the Services and permitted under the CCPA. Voxjar certifies that it understands and will comply with the restrictions in this Section. In accordance with the CCPA, Voxjar may engage in the following business purposes solely as necessary to provide the Services: (1) helping to ensure the security and integrity of the Services; (2) detecting and protecting against malicious, deceptive, fraudulent, or illegal activity; (3) identifying and repairing errors that impair existing intended functionality; and (4) short-term, transient use, provided that the Personal Information is not disclosed to another third party and is not used to build a profile about a Consumer.
3.5 Data Subject Rights. Voxjar shall promptly notify Customer if Voxjar receives a request from a Data Subject exercising rights under Data Protection Law with respect to Covered Data, and shall not respond to the request itself except as authorized by Customer. Taking into account the nature of the Processing, Voxjar shall assist Customer, including through the Services’ search, export, and deletion functionality and, where necessary, manual assistance upon written request to privacy@voxjar.com, in responding to such requests.
3.6 Security. Voxjar shall implement and maintain appropriate technical and organisational measures to protect Covered Data against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss, alteration, damage, unauthorized disclosure, or access, as described in Annex II. Voxjar shall ensure that access to Covered Data is limited on a need-to-know/need-to-access basis and that all personnel receiving such access are subject to written confidentiality obligations or professional or statutory obligations of confidentiality.
3.7 Security Breach. Voxjar shall notify Customer without undue delay and, in any event, within seventy-two (72) hours of Voxjar or any Sub-Processor becoming aware of a breach of security leading to any actual or reasonably suspected accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Covered Data (a “Security Breach”). Such notification shall describe, to the extent then known, the nature of the Security Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the Security Breach and mitigate its possible adverse effects, with further information provided as it becomes available. Voxjar shall take reasonable steps to contain and remediate the Security Breach and shall cooperate with Customer’s reasonable requests for information.
4. Government Requests
Unless legally prohibited, each Party shall promptly inform the other Party if it receives a request or demand from a governmental or regulatory body relating to the Processing of Covered Data and shall reasonably cooperate with the other Party in connection with any response to such request or demand. Voxjar shall not disclose Covered Data to a government authority except where required by law, and shall, where legally permitted, redirect the authority to request the data directly from Customer.
5. Cross-Border Transfers
5.1 EU Transfers. To the extent the Services involve a transfer of Personal Data of Data Subjects in the EEA to a country or territory outside the EEA that has not received an Adequacy Decision, the Parties hereby incorporate by reference, and agree to comply with, the SCCs (available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), which are deemed entered into by the Parties and completed as follows:
(a) Module Two (Controller to Processor) applies, with Customer as data exporter and Voxjar as data importer;
(b) the optional docking clause in Clause 7 does not apply;
(c) in Clause 9, Option 2 (general written authorisation) applies, and the minimum time period for prior notice of Sub-Processor changes is ten (10) days;
(d) in Clause 11, the optional language does not apply;
(e) in Clause 13, all square brackets are removed and the competent Supervisory Authority is as set out in Annex I.C;
(f) in Clause 17, Option 1 applies, and the SCCs shall be governed by the laws of Ireland;
(g) in Clause 18(b), disputes shall be resolved before the courts of Ireland; and
(h) Annexes I, II, and III of the SCCs shall be deemed completed with the information set out in Annexes I, II, and III to this DPA, respectively.
5.2 UK Transfers. To the extent the Services involve a transfer of Personal Data subject to the UK GDPR to a country or territory outside the UK that is not covered by UK adequacy regulations, the Parties hereby incorporate by reference, and agree to comply with, the SCCs as amended by the UK Addendum (available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/), with the UK Addendum’s Tables completed as follows: Table 1 (Parties): as set out in Annex I.A; Table 2 (Selected SCCs): the SCCs as incorporated into this DPA, including the selections made in Section 5.1; Table 3 (Appendix Information): as set out in Annexes I, II, and III to this DPA; Table 4 (Ending this Addendum when the Approved Addendum Changes): both parties (neither party may end the Addendum except as set out in Section 19 of the Addendum). The UK Addendum is governed by the laws of England and Wales.
5.3 Swiss Transfers. For transfers of Personal Data subject to the Swiss Federal Act on Data Protection, the SCCs as completed in Section 5.1 apply with the following modifications: references to the GDPR are understood as references to the Swiss Federal Act on Data Protection; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and Data Subjects habitually resident in Switzerland may bring claims in Switzerland.
5.4 The Parties represent that they do not believe the laws and practices in any country to which Personal Data is transferred for purposes of the Agreement will prevent the importing Party from fulfilling its obligations under this DPA or the SCCs.
6. Indemnification
In addition to the terms set forth in the Agreement, Customer shall indemnify, defend, and hold harmless Voxjar and its subsidiaries, affiliates, officers, directors, employees, agents, assigns, and representatives from and against any and all third-party claims, actions, losses, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees and disbursements) arising out of Customer’s: (i) breach of this DPA; or (ii) violation of Data Protection Law or other applicable law, including without limitation the Telephone Consumer Protection Act (“TCPA”), including any failure by Customer to provide legally required notices to, or obtain legally required consents from, Data Subjects whose communications are recorded or processed through the Services.
7. Data Protection Impact Assessments and Prior Consultation
Taking into account the nature of the Processing and the information available to Voxjar, Voxjar shall provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities or other competent data protection authorities that Customer reasonably considers to be required under Data Protection Law in relation to the Processing of Covered Data by Voxjar.
8. Sub-Processors
8.1 General Authorisation. Customer provides general written authorisation for Voxjar to engage the Sub-Processors listed in Annex III to Process Covered Data. The current Sub-Processor list is also maintained at https://trust.voxjar.com/subprocessors.
8.2 Changes. Voxjar shall provide Customer at least ten (10) days’ prior written notice of the addition or replacement of any Sub-Processor (including via update to the page referenced in Section 8.1 together with a notification mechanism made available to Customer), giving Customer the opportunity to object. If Customer reasonably objects on data protection grounds and the Parties cannot resolve the objection within a reasonable period, Customer may terminate the affected Services upon written notice, and Voxjar will refund any prepaid, unused fees for the terminated Services.
8.3 Sub-Processor Obligations. Voxjar shall not permit any Sub-Processor to Process Covered Data unless Voxjar and the Sub-Processor have entered into a written agreement imposing data protection obligations that are no less protective of Covered Data than those imposed on Voxjar under this DPA. Voxjar shall remain fully responsible to Customer for the performance of each Sub-Processor’s obligations.
9. Return or Deletion of Personal Data
Customer may export its Covered Data at any time through the Services. Following expiration or termination of the Agreement, Customer’s account and Covered Data remain accessible to Customer for export and retrieval unless and until Customer requests deletion. Upon Customer’s written request (or deletion initiated via the Services), Voxjar shall delete Covered Data from production systems within thirty (30) days, with residual copies expiring from encrypted backups within a further thirty (30) days in accordance with Voxjar’s backup retention cycle, and shall provide written confirmation of deletion upon request. The foregoing shall not apply to the extent retention is required by applicable law, in which case Voxjar shall retain the data only for so long as, and to the extent, so required, and such data shall remain protected under this DPA.
10. Audit
Upon Customer’s reasonable request, Voxjar shall make available to Customer information reasonably necessary to demonstrate Voxjar’s compliance with this DPA, including, upon request and under confidentiality obligations, Voxjar’s then-current SOC 2 Type II report, and shall allow for and cooperate with reasonable assessments by Customer or Customer’s designated assessor. Customer shall not use any audit report or information obtained under this Section for any purpose other than assessing Voxjar’s compliance with this DPA. Customer shall have the right, upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Covered Data by Voxjar.
11. General Terms
11.1 Termination and Survival. This DPA shall remain in effect for so long as the Agreement is in effect. Provisions of this DPA that by their nature should survive termination (including Sections 3.7, 6, 9, and 10) shall survive termination or expiration of the Agreement until all Covered Data has been deleted or returned in accordance with Section 9.
11.2 Severability. If individual provisions of this DPA are or become ineffective, the effectiveness of the remaining provisions shall not be affected. The Parties shall replace the ineffective provision with a legally permissible provision that accomplishes the intended commercial intention as closely as possible.
11.3 Conflicts. In case of contradiction between this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail. In case of contradiction between this DPA and the SCCs or the UK Addendum, the SCCs or the UK Addendum (as applicable) shall prevail.
11.4 Amendment. Voxjar may update this DPA from time to time only to the extent reasonably required to reflect changes in Data Protection Law, in guidance from Supervisory Authorities, or in the Services, provided such updates do not materially diminish the protections for Covered Data under this DPA. Voxjar will provide notice of material updates.
11.5 Applicable Law and Jurisdiction. Except as provided in Sections 5.1(f)–(g) and 5.2 with respect to the SCCs and the UK Addendum, the applicable law and jurisdiction set forth in the Agreement apply to this DPA.
ANNEX I
A. LIST OF PARTIES
Data exporter:
Name: Customer (as identified in the Agreement) Address: As identified in the Agreement or Customer’s account Contact: As identified in the Agreement or Customer’s account Activities relevant to the data transferred under these Clauses: Use of the Services Role: Controller
Data importer:
Name: Voxjar AI Tech, Inc. Address: 336 E University Pkwy #1011, Orem, UT 84058, United States Contact: privacy@voxjar.com Activities relevant to the data transferred under these Clauses: Providing the Services Role: Processor
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred: Individuals authorized by or on behalf of Customer to access or use the Services (“Users”); individuals who communicate or interact with Customer’s contact centers (“Callers”).
Categories of personal data transferred: Call recordings; call transcripts; call metadata (e.g., date, time, duration, phone numbers, agent identifiers); User account data (e.g., names, email addresses); and any other information provided to Voxjar to provide the Services.
Sensitive data transferred: The Services do not require, and Voxjar does not seek to collect, special categories of personal data. However, call recordings and transcripts may incidentally contain sensitive data disclosed by Data Subjects in the course of their communications with Customer’s contact centers. All Covered Data, including any such incidental sensitive data, is protected without distinction by the full set of technical and organisational measures described in Annex II, including encryption in transit and at rest, restricted access, US-only processing, and the prohibition on use of Covered Data for model training or any purpose other than providing the Services.
Frequency of the transfer: Continuous, for the duration of the Agreement.
Nature of the processing: Collection, storage, transcription, AI-based evaluation and analysis, and disclosure to Customer of the Covered Data to provide the Services as detailed in the Agreement.
Purpose(s) of the data transfer and further processing: Providing the Services as detailed in the Agreement, including call transcription, quality-assurance evaluation, analytics presented to Customer, and related support.
Retention period: For the duration of the Agreement. Customer may export its Covered Data at any time. Following expiration or termination, Covered Data remains accessible to Customer unless and until Customer requests deletion; upon request, deletion from production within thirty (30) days and expiry from encrypted backups within a further thirty (30) days, except as retention is required by applicable law (see Section 9 of the DPA).
Transfers to (sub-)processors: As described above and in Annex III, for the duration described above.
C. COMPETENT SUPERVISORY AUTHORITY
Where the data exporter is established in an EU Member State, the Supervisory Authority of that Member State. Where the data exporter is not established in an EU Member State but falls within the territorial scope of the GDPR, the Supervisory Authority determined in accordance with Clause 13 of the SCCs. For transfers subject to the UK GDPR, the UK Information Commissioner’s Office.
ANNEX II
TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organisational measures implemented by Voxjar (as data importer) to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing.
1. Certifications and audits. Voxjar maintains SOC 2 Type II attestation covering security, confidentiality, and availability, with continuous controls monitoring. A copy of Voxjar’s most recent SOC 2 Type II report is available to Customer under confidentiality obligations via Voxjar’s Trust Center (https://trust.voxjar.com) or upon written request.
2. Hosting and physical security. Covered Data is hosted and processed on the following infrastructure, all located in the United States: Google Cloud Platform (“GCP”) in multi-region configuration (application hosting, primary compute, databases, and storage of call recordings and transcripts); Supabase (authentication services only, US region); and RunPod (US-region GPU workers performing transient processing for Voxjar’s in-house transcription models; call audio is not stored on RunPod volumes). Physical and environmental security of data centers is the responsibility of these infrastructure providers, each of which maintains independent security attestations (e.g., SOC 2 / ISO 27001); Voxjar reviews their attestation reports and performs a risk analysis of each provider at least annually. Voxjar personnel have no physical access to servers processing Covered Data.
3. Encryption. All Covered Data, including call recordings, transcripts, and associated metadata, is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256. Encryption at rest is provided by the hosting infrastructure’s default encryption, with keys managed and protected by the providers’ key management infrastructure.
4. AI processing controls. Automated transcription of call recordings is performed either by Voxjar’s in-house models running on dedicated US-region GPU infrastructure (RunPod) or via Microsoft Azure AI services in the United States. AI evaluation of transcripts is performed by a large language model selected by Customer from Voxjar’s supported models. All models are accessed exclusively through enterprise cloud platforms - Microsoft Azure (Azure OpenAI Service), Google Cloud (Vertex AI), and Fireworks AI (open-source models) - each in the United States and under zero-data-retention and no-training terms: Covered Data submitted for inference is not retained beyond transient processing, is not used to train or improve any models, and is not accessible to the underlying model developers. Voxjar has no direct data relationship with model developers such as OpenAI or Anthropic; Covered Data is never transmitted to them. Only the platform hosting Customer’s selected model processes Customer’s Covered Data for evaluation.
5. Access control and authentication. Access to production systems and Covered Data is restricted to authorized personnel on a least-privilege, need-to-know basis, using role-based access controls. Multi-factor authentication is required for all personnel access to production systems and cloud infrastructure. Access to customer call recordings and transcripts is limited to (i) engineers with production access, for purposes of operating, maintaining, and troubleshooting the Services, and (ii) customer support personnel granted access to a Customer’s account, for purposes of responding to that Customer’s support requests. User access and roles are reviewed on a quarterly basis, and access is deprovisioned within three (3) days of personnel termination.
6. Logging and monitoring. Access to production systems and Covered Data is logged using cloud-native logging, and Voxjar monitors its systems for security events. No third-party observability vendor receives Covered Data.
7. Availability, resilience, and backups. Covered Data is stored in GCP multi-region configuration, providing redundancy across geographically separated data centers within the United States. Customer data is backed up on a scheduled basis in GCP with a thirty (30) day backup retention cycle; backups are encrypted, access-restricted to key personnel, and monitored for completion and exceptions, with failed backups investigated and re-run. Voxjar maintains an incident response and business continuity process and monitors applications, databases, and storage against availability targets.
8. Testing and evaluation of security measures. Voxjar utilizes vulnerability scanning software covering source code and open-source dependencies, with an internal SLA for remediating findings by severity, and controls are monitored on a continuous basis as part of its SOC 2 program. Voxjar engages an external firm to perform penetration testing at least annually, with a remediation plan for identified vulnerabilities.
9. Secure development. Code changes are subject to review before deployment to production. Production and non-production environments are segregated, and Covered Data is not used in development or testing environments.
10. Data minimisation, retention, and deletion. Covered Data is processed only as necessary to provide the Services. Customer may export its Covered Data at any time through the Services. Upon Customer’s deletion or purge request, Covered Data is deleted from production systems within thirty (30) days and expires from encrypted backups within a further thirty (30) days in accordance with the backup retention cycle.
11. Incident response. Voxjar maintains a security incident response process covering identification, containment, assessment, remediation, and notification. Personal data breaches are notified to the Controller in accordance with Section 3.7 of the DPA (without undue delay and in any event within 72 hours of awareness).
12. Personnel. All Voxjar personnel with access to Covered Data are bound by written confidentiality obligations. New personnel undergo background checks and must complete policy review and security awareness training within fourteen (14) days of hire, with ongoing training to maintain skill levels for security-relevant roles.
13. Sub-processor oversight. Voxjar engages Sub-Processors only under written agreements imposing data protection obligations no less protective than those in this DPA, including, for AI providers, zero-data-retention and no-training commitments. Voxjar reviews Sub-Processors’ security certifications (e.g., SOC 2 / ISO 27001 reports) prior to engagement and at least annually thereafter. The current Sub-Processor list is set out in Annex III.
14. Assistance with data subject rights (Clause 10(b) of the SCCs). Voxjar assists the Controller in responding to Data Subject requests through the Services’ search, export, and deletion functionality and, where necessary, through manual assistance upon written request to privacy@voxjar.com.
ANNEX III
LIST OF SUB-PROCESSORS
Customer has authorised the use of the following Sub-Processors pursuant to Section 8 of the DPA and Clause 9(a) (Option 2) of the SCCs. Voxjar will provide at least ten (10) days’ prior written notice of any intended addition or replacement of Sub-Processors. The current list is also maintained at https://trust.voxjar.com/subprocessors.
| Sub-processor | Location | Processing activity | Data categories | Safeguards / transfer mechanism |
|---|---|---|---|---|
| Google Cloud Platform (Google LLC) | USA (multi-region, US only) | Cloud hosting, storage, and infrastructure for Covered Data; AI evaluation via Vertex AI models where selected by Customer | Call recordings, transcripts, call metadata, User account data | Google Cloud Data Processing Addendum incl. SCCs; zero data retention and no training for Vertex AI inference |
| Microsoft Corporation (Azure) | USA | Speech-to-text transcription of call recordings (where used); AI evaluation via Azure OpenAI Service models where selected by Customer | Call recordings, transcripts, call metadata | Microsoft Products and Services DPA incl. SCCs; zero data retention; no training on Customer data |
| RunPod, Inc. | USA (US regions only) | GPU compute for Voxjar’s in-house speech-to-text transcription models (where used); transient processing only - call audio is not stored on RunPod volumes | Call recordings, transcripts (transient) | Written DPA incl. SCCs; no persistent storage |
| Fireworks AI, Inc. | USA | AI evaluation of transcripts via open-source models, where selected by Customer | Transcripts, call metadata | Written DPA incl. SCCs; zero data retention; no training on Customer data |
| Supabase, Inc. | USA (US region) | Authentication services for the Voxjar application | User account and authentication data (names, email addresses, credentials); no call recordings or transcripts | Written DPA incl. SCCs |
| Intercom, Inc. | USA | Customer support, chat, and help center | User names, email addresses, support communications; Covered Data only where shared by Customer in a support request | Written DPA incl. SCCs |
| PostHog, Inc. | USA | Product usage analytics | User identifiers (names, email addresses, internal IDs) and product interaction events; no call recordings, transcripts, or Caller data | Written DPA incl. SCCs |
| Twilio Inc. (SendGrid) | USA | Sending transactional Service emails (e.g., invitations, notifications, password resets) | User names, email addresses | Written DPA incl. SCCs |
Voxjar does not transmit Covered Data to AI model developers (e.g., OpenAI, Anthropic) directly. All large language models are accessed through the enterprise cloud platforms listed above, under those platforms’ data processing agreements.