Speech data · Data processing agreement
Executed before the first recording. The DPA, and what it puts on paper.
Roles, processing scope, consent and provenance, sub-processors, retention and audit access, fixed in the agreement before production collection begins. Draft terms come to your legal team during scoping.
Draft for legal review
Data Processing Agreement
Speech data collection and processing
- Roles and responsibilities
- Processing scope and data categories
- Consent, provenance and audit trail
- Sub-processors
- Retention and deletion
- Security, access and audit readiness
Executed before production collection begins
Clause · Roles controller · processor
Who is the controller is decided per engagement, and written down.
Role designation between Controller and Processor is determined per engagement based on the nature of the data processing activities and contractual requirements.
- Processor engagements
- YPAI processes personal data on behalf of the client organization according to documented instructions. The client remains the Controller.
- Independent Controller engagements
- In certain arrangements, YPAI acts as an Independent Controller for specific processing activities. This is documented in the engagement agreement.
Role definitions and responsibilities are specified in the DPA and reviewed during scoping. Specific obligations are defined contractually.
Clause · Scope five categories · one purpose
What is processed, and for which purposes.
Speech data collection workflows involve processing of audio recordings and associated metadata. The DPA Annex lists the categories and the purposes each one serves.
| Data category | Held as | Purpose |
|---|---|---|
| Voice recordings | Audio files, per recording | Collection, validation, quality assurance, delivery |
| Transcripts and annotations | Text, linked to the recording | Validation, quality assurance, delivery |
| Speaker metadata | Anonymized identifiers, demographic categories as defined per project | Quota reporting, delivery record |
| Consent records and provenance | Consent id, timestamp, version, scope | Lawful basis, audit trail |
| Technical metadata | Sample rate, format, duration | Validation, delivery record |
Purpose limitation: Data is processed for the purposes of collection, validation, quality assurance, and delivery as defined in the engagement agreement. Specific data categories and processing purposes are documented in the DPA Annex and defined during scoping.
Clause · Consent and provenance per recording
Every recording carries its consent. The audit trail is the platform's own record.
All data collection occurs within our controlled platform. This enables verifiable consent and traceable provenance for each recording.
-
Consent
Obtained from the contributor before recording begins. Records are maintained and can be produced for internal review.
-
Recording
Captured on the platform, under the specified conditions, against the consent record.
-
Provenance
Each recording is associated with contributor identifier, timestamp and consent reference.
-
Audit trail
Full audit documentation is available for legal and compliance review. Provenance is verifiable for long-term production use.
Audit trail requirements and access procedures are defined contractually.
Clause · Sub-processors disclosed · governed · notified
Who else touches the data is in the agreement, with the change procedure.
Sub-processors engaged in data processing activities are disclosed as part of the DPA terms.
-
Disclosed
Sub-processor list or categories provided during scoping.
-
Governed
Sub-processor governance procedures defined in the DPA.
-
Notified
Update notification and approval mechanisms agreed contractually.
Clause · Retention and deletion windows · deletion · return
How long the data lives, and what happens when the engagement ends.
Retention periods and deletion procedures are defined contractually during scoping.
-
During the engagement
Retention windows vary by engagement and are specified in the DPA. Enterprise retention policies are supported as defined per project.
-
Deletion
Deletion procedures aligned with GDPR requirements, with timelines provided for internal review during scoping.
-
After the engagement
Return or deletion, as documented in the DPA. Post-engagement handling is written into the agreement before signature.
Clause · Security and audit access · documentation
Access is limited and documented. The documentation is yours to review.
Internal controls and security measures are implemented to protect data during collection, processing, and delivery.
- Access control
- Access to data is limited to authorized personnel. Access control policies are documented and available for review.
- Audit readiness
- Full audit documentation is available for legal and compliance review. Documentation of security practices is provided on request during scoping.
The review asks
Signing, roles and sub-processors
When is the DPA signed?
The DPA is executed before production collection begins. During scoping, we provide draft DPA terms for internal review. The signed agreement is finalized before any data processing activities commence.
Is YPAI a Controller or Processor?
Role designation depends on the engagement model. YPAI may act as Data Processor or Independent Controller depending on the contractual arrangement. Role definitions are specified in the DPA and reviewed during scoping.
Can we review sub-processors before signing?
Sub-processors are disclosed as part of the DPA terms. A list of sub-processors or categories of sub-processors is provided during scoping for internal review.
How is consent demonstrated?
Consent is obtained through our controlled platform and is verifiable. Provenance records are maintained for audit purposes. Details of consent mechanisms are documented in the DPA and available for compliance review.
What audit artifacts can you provide?
Full audit documentation is available for legal and compliance review. This includes provenance records, consent documentation, and processing logs. Specific audit requirements can be addressed during scoping.
What happens if requirements change after pilot?
Requirement changes are handled through contract amendment procedures defined in the engagement agreement. We work with your legal and procurement teams to document changes appropriately.
How do you handle deletion requests?
Deletion and retention terms are defined contractually during scoping. Procedures for handling deletion requests are documented in the DPA and aligned with GDPR requirements.
Do you support regulated environments?
Yes. Our approach is designed for organizations in regulated environments including healthcare, finance, and automotive. Specific regulatory requirements are addressed during technical and compliance scoping.
Can we use our own DPA template?
We are able to review and work with client-provided DPA templates. Template review and negotiation occur during the scoping phase.
How are sub-processor changes communicated?
Sub-processor update procedures are defined in the DPA. Notification mechanisms and approval workflows are agreed upon during contract negotiation.
Bring the requirement. The draft DPA comes back with the scoping brief.
A formal appendix for internal review is part of scoping. Your own DPA template is reviewed in the same step.
Speech data overview Technical specifications Data residency and sub-processors How YPAI processes customer and project data