## Roles and Scope
- **Controller**: The customer determines the purposes and means of processing personal data.
- **Processor**: SectorVoice processes personal data solely to deliver, maintain, and support the Services, following the customer's documented instructions.
- **Subprocessing**: SectorVoice engages vetted subprocessors (e.g., hosting, analytics, communications). The current list, purposes, and locations are published in the [Trust Center](/trust-center/subprocessors). Customers receive advance notice before any material change. ## Security and Compliance
- SectorVoice maintains administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, logging, vulnerability management, and incident response testing.
- Annual penetration tests and continuous monitoring support our ISO 27001 roadmap.
- Employees with data access are bound by confidentiality agreements and complete regular security training. ## Data Subject Rights and Assistance
- SectorVoice assists customers in responding to data subject requests (access, rectification, deletion, restriction, portability, objection) received via privacy@sectorvoice.ai or customer support channels.
- We notify customers without undue delay of data protection incidents impacting customer data and cooperate with investigations and remediation. ## International Transfers
- When transferring personal data from the EEA, UK, or Switzerland, SectorVoice relies on Standard Contractual Clauses and implements supplementary safeguards. Regional hosting may be enabled under an Order or MSA. ## Retention and Deletion
- SectorVoice retains personal data only for the duration of the Services and as required for legal or contractual obligations.
- Upon termination, SectorVoice returns or deletes personal data as instructed by the customer, subject to applicable law. Confirmation can be provided upon request. ## Obtaining the DPA
- Request the latest DPA via [legal@sectorvoice.ai](mailto:legal@sectorvoice.ai) or the form at `/legal/data-processing-agreement`.
- Executed copies are delivered electronically via secure e-signature.