← WorldVC home

Data Processing Addendum

Effective July 27, 2026 · forms part of the Terms of Service

This Addendum applies where WorldVC processes personal data on behalf of a customer in the course of providing the Services. In that processing the customer is the controller and WorldVC is the processor. Where WorldVC processes data for its own purposes - running its accounts, billing and security - it acts as a controller and the Privacy Policy governs instead. If any term here conflicts with the Terms of Service, this Addendum wins for processing of customer personal data.

1. What we process, and why

We process customer personal data only to provide the Services, to keep them secure and available, to support you, and to meet legal obligations. We do not sell customer personal data and we do not use it to build unrelated products. The subject matter is set by the apps you enable; the duration is the term of your account plus the retention window in section 7.

The categories depend on the apps in use, and typically include:

2. Your instructions

We process customer personal data on your documented instructions. Your configuration of the Services - the apps you enable, the prompts and scripts you set, the integrations you connect, the retention you choose - is part of those instructions. If we believe an instruction breaks applicable data protection law, we will tell you rather than carry it out silently.

3. Confidentiality and access

Access to customer personal data is limited to people who need it to run or support the Services, under confidentiality obligations. Administrative access is restricted and logged, as described in the Privacy Policy.

4. Security

We encrypt data in transit, store credentials and API keys encrypted, restrict and log administrative access, and separate customer data by tenant. Security is a moving target: these measures may change, but not in a way that materially weakens protection during your term.

5. Sub-processors

You give general authorisation for the sub-processors we need to run the Services. By category these are cloud hosting and databases, telephony and SMS carriers, AI model providers, email delivery, and payment processing (including Dodo Payments as merchant of record for international card payments, alongside licensed local payment providers). Each receives only the data its role needs.

Each sub-processor is bound by terms no less protective than this Addendum for the data it handles, and we remain responsible for their performance. Ask us at the address in section 12 for the current list, including the identity and location of each. We will give you notice of a new or replacement sub-processor before it starts processing your data, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may stop using the affected app and receive a pro-rated refund for it.

6. AI model providers

Some features send content - call audio, chat messages, or text you ask to be generated - to third-party AI model providers to produce a response in real time. We send what the feature needs, and where a provider offers the control, we configure it not to use that content to train its general models. This is the processing most likely to matter to your own assessment, so it is called out separately rather than buried in the sub-processor list.

7. Retention and deletion

We keep customer personal data for as long as your account needs it, plus any period the law requires. On request, or after your account closes, we delete or return customer personal data within a reasonable period, except where we must keep it to meet a legal obligation. Backups age out on their own cycle.

8. Helping you meet your obligations

We will give you reasonable assistance with your own duties as controller: responding to requests from data subjects, carrying out impact assessments, and consulting regulators where that is required. Where a person asks us directly about data held in your account, we refer them to you as the controller.

9. Personal data breaches

If we become aware of a breach affecting customer personal data we will notify you without undue delay, with what we know about the nature of the breach, the data and people affected, our assessment of the likely consequences, and the steps taken. We will keep you updated as we learn more.

10. Audits

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information you reasonably need to confirm we are meeting this Addendum. Where an on-site audit is genuinely necessary we will agree scope and timing with you in advance, so that it does not compromise other customers' data or the security of the Services.

11. International transfers

We operate from the United States and our sub-processors may process data in other countries. Where personal data protected by the GDPR or UK data protection law is transferred out of the EEA, the UK or Switzerland, we rely on a transfer mechanism recognised under that law - typically the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies - and those clauses are incorporated into this Addendum by reference for such transfers. Tell us if your assessment needs the specific module and annexes and we will complete them with you.

12. Contact

Data protection questions, sub-processor lists, breach notices and audit requests: care@worldvc.business or +1 (920) 533-0466. Mailing address: 1317 Edgewater Dr #7549, Orlando, FL 32804, USA.

13. Changes

We may update this Addendum to reflect how the Services actually work. If a change materially reduces your protection we will give notice before it takes effect, so that you have time to object or stop using the affected app.