Speech data · Data residency and sub-processors

Where the audio lives, who can reach it. Residency, access and sub-processors, on paper before collection.

Storage location, access roles, sub-processors and cross-border safeguards are agreed during scoping and written into the DPA. Once agreed, they bind.

EEA by default, Norwegian jurisdiction. Residency restrictions are scoped per engagement and documented in the DPA annex.

Custody of one corpus, by data type and stage
Audio recordings EEA contributors on the platform EEA QA reviewers EEA · Norwegian jurisdiction platform administrators your named route delivery personnel Transcripts and annotations EEA on the platform EEA QA reviewers EEA · Norwegian jurisdiction platform administrators your named route delivery personnel Speaker metadata EEA captured at intake EEA QA reviewers EEA · Norwegian jurisdiction platform administrators with the dataset anonymized identifiers Consent records and audit trail EEA recorded before the session EEA linked to every file EEA · retained as audit evidence platform administrators with the dataset consent id per file

Residency restrictions beyond the default are scoped per engagement. Transfers outside the EEA, where the engagement needs one, carry the safeguard named in the DPA.

The record eight terms · one annex

Eight things the residency annex fixes. Read them before security review.

This page is the overview for security, legal and procurement review. The binding terms sit in the engagement agreement and the DPA annex.

Residency
Defined contractually during scoping; binding once agreed
Scope
Commitments vary by engagement, jurisdiction, and client requirements
Access
Controlled infrastructure, restricted to authorized personnel
Sub-processors
Disclosed contractually before the engagement begins
Transfers
Cross-border safeguards documented in the DPA when applicable
Audit
Documentation available for internal and external review
Distribution
Enterprise speech data moves inside the controlled platform, to the named delivery route
Restrictions
Accommodated subject to scoping and feasibility

Residency per engagement · binding

Residency is set per engagement. Once agreed, it is a contractual obligation.

Data residency expectations are established during the scoping phase of each engagement. Residency commitments vary based on client requirements, jurisdictional constraints, and project scope.

Project-specific residency
Each engagement carries its own residency requirement. Storage locations, infrastructure regions and jurisdictional boundaries are set during scoping.
Contractual documentation
Residency commitments are documented in the engagement agreement and the DPA. Once agreed they bind and become part of the delivery terms.
Feasibility assessment
Residency restrictions are evaluated during scoping for technical feasibility and cost. Constraints are disclosed before commitment.

Access four roles · segregated

Four roles touch the data. Each one is named, scoped and traceable.

Access to enterprise speech data is controlled and limited to authorized personnel based on role, project scope, and business need. Access control policies are documented and available for review.

Separation of duties
Contributors, QA reviewers and delivery personnel operate in segregated workflows, so data handling stays controlled at each stage.
Platform-controlled access
All data access occurs within the controlled platform. Production workflows run through the platform's access layer, and every access is attributable to a named role.

Sub-processors disclosed · governed · notified

Who else processes the data is disclosed before the engagement begins.

Sub-processors are third-party entities or service providers engaged in processing personal data on behalf of YPAI. Sub-processor engagement is governed by contractual terms and disclosed as part of the DPA.

What counts as a sub-processor
Any entity that processes personal data in support of speech data collection, storage, quality assurance or delivery on YPAI's behalf.
Disclosure
A list of sub-processors, or categories of sub-processors, is provided during scoping for review and written into the DPA.
Notification of changes
Procedures for notifying you of sub-processor changes, and the approval workflow, are defined in the DPA.
Governance
Sub-processors are bound by contractual obligations aligned with YPAI's data protection commitments.

Cross-border transfers when · how · disclosed

A transfer happens only where the engagement needs one. When it does, the safeguard is in the DPA.

Cross-border data transfers may occur depending on the engagement structure, data residency commitments, and sub-processor locations. Where cross-border transfers occur, they are governed by contractual safeguards.

Necessity
Whether a transfer happens at all is determined during scoping from residency commitments, infrastructure needs and sub-processor locations.
Safeguards
When a cross-border transfer is required, the safeguard is documented in the DPA and aligned with GDPR and the applicable data protection law.
Transparency
Every transfer, its destination jurisdiction and its mechanism are disclosed during scoping for internal review.

Retention windows · deletion

How long the data lives is written into the DPA, per engagement.

Data retention and deletion policies vary by engagement and are defined contractually during scoping. Retention periods and deletion procedures are documented in the DPA.

Retention windows
Set from engagement requirements, your policy and regulatory obligations. Long-term retention needs are addressed in scoping.
Deletion procedures
Timelines and verification methods aligned with GDPR and documented in the DPA. The retention and deletion page carries the full lifecycle.

The full lifecycle, from the retention window to the deletion certificate, is on the retention and deletion page.

Security and audit artifacts · review · provenance

The audit artifacts exist for the whole retention period. Internal or external review reads the same record.

Security measures and audit artifacts are designed to support internal and external compliance review. Full audit documentation is available for legal and compliance teams.

Audit artifacts
Provenance records, consent documentation, processing logs, residency evidence and sub-processor disclosures.
Internal and external review
Audit procedures support internal compliance review and external audits as required. Access and procedures are defined in the engagement agreement.
Long-term traceability
Provenance records are maintained for the retention period, so multi-year audit requirements read the same record.

Security and procurement

Storage, access and transfers

Where is the data stored?

Data storage locations are defined contractually during scoping. Storage infrastructure may vary based on engagement requirements, project scope, and jurisdictional constraints. Specific residency commitments are documented in the engagement agreement and DPA.

Can we restrict data residency to specific jurisdictions?

Yes. Residency restrictions can be accommodated subject to scoping, technical feasibility, and contractual terms. Specific residency requirements are reviewed during the scoping phase and documented in the engagement agreement. Residency commitments are binding once agreed.

Who can access the data during collection and processing?

Access is limited to authorized personnel based on role and project requirements. Access control policies are documented and available for internal review. Specific access roles (contributors, QA reviewers, delivery personnel) are defined during scoping.

Are sub-processors disclosed before engagement?

Yes. Sub-processors engaged in data processing activities are disclosed as part of the DPA terms. A list of sub-processors or categories of sub-processors is provided during scoping for internal review before the engagement begins.

How are sub-processor changes communicated?

Sub-processor update procedures are defined in the DPA. Notification mechanisms and approval workflows are agreed upon during contract negotiation. Changes are communicated according to the agreed procedure before implementation.

Will data be transferred across borders?

Cross-border transfers may occur depending on the engagement structure and data residency commitments. Where cross-border transfers are required, safeguards are documented in the DPA and comply with applicable data protection frameworks. Transfer mechanisms and jurisdictions are disclosed during scoping.

What safeguards are in place for cross-border transfers?

When cross-border transfers occur, safeguards are defined in the DPA and aligned with GDPR and applicable frameworks. Specific transfer mechanisms (such as contractual clauses or adequacy decisions) are documented contractually and disclosed during scoping.

Can we audit data handling and residency claims?

Yes. Full audit documentation is available for legal and compliance review. Audit artifacts include provenance records, consent documentation, processing logs, and residency evidence. Audit procedures and access are defined contractually.

How is data segregated between engagements?

Data segregation and isolation procedures are implemented to separate data between engagements. Segregation mechanisms are documented and available for review. Specific segregation approaches are defined during technical scoping.

Is contributor data collected within Europe?

Contributor recruitment and data collection are geographically scoped per engagement. European-sourced data collection is supported. Specific geographic sourcing is defined contractually during scoping based on project requirements.

Can we require on-premises or private cloud infrastructure?

Infrastructure requirements, including on-premises, private cloud, or specific cloud providers, can be discussed during scoping. Feasibility, costs, and technical constraints are evaluated case by case. Non-standard infrastructure requirements are documented in the engagement agreement.

How long is provenance documentation retained?

Provenance and audit documentation retention periods are defined contractually during scoping. Retention windows vary based on engagement terms and client requirements. Long-term retention for audit readiness is supported where contractually agreed.

Bring the residency requirement. The annex comes back with the scoping brief.

Jurisdiction, infrastructure and sub-processor constraints are enough to start. Feasibility and cost come back in the same review.