Trust Centre
Data Processing
Last updated May 2026 · v1.1 · Changelog
Where Vixio processes personal data on behalf of a customer organisation, a Data Processing Agreement is available for execution as an addendum to the Order Form.
A4.1 Data Processing Agreement
Where Vixio processes personal data on behalf of a customer organisation, a Data Processing Agreement (DPA) is available for execution as an addendum to the Order Form. The full DPA text is set out in Part B of this document set, published at trust.vixio.com. The DPA governs the relationship between Vixio as data processor and the customer as data controller.
A4.2 Nature & Location of Processing
Schedule B1 of the DPA sets out the particulars of processing. Customer personal data is stored and processed as follows:
| Activity | Description |
|---|---|
| Storage | Customer personal data is stored within Vixio's cloud infrastructure (Amazon Web Services, UK/EU region) for the purpose of service delivery. |
| AI feature processing | Customer inputs (prompts and document content) and associated metadata are transmitted to AI sub-processors where AI functionality is used. Sub-processor locations and transfer mechanisms are set out below and in Part C. |
| Document ingestion and retrieval | Documents uploaded to the Workspace Document Library are stored in Vixio's AWS (UK/EU) infrastructure. Document content is called transiently into AI processing pipelines when AI functionality is used and is not persistently stored within AI sub-processor infrastructure. |
A4.3 Sub-processors
The full sub-processor list, including AI sub-processors, is set out in Part C. Vixio provides not less than 30 days' written notice before adding a net-new sub-processor.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services | Primary cloud infrastructure; Amazon Bedrock AI platform | EU / UK | EU SCCs + UK Addendum |
| Microsoft Azure | Azure OpenAI Service: managed AI model hosting | EU / UK | EU SCCs + UK Addendum |
| Google Cloud | Vertex AI platform: managed AI model hosting | EU / UK | EU SCCs + UK Addendum |
| Anthropic PBC (via AWS Bedrock) | LLM reasoning with Claude family models for VIQ and SCANS | USA (via AWS region) | EU SCCs + UK Addendum |
| OpenAI L.L.C. (via Azure) | LLM reasoning with GPT family models for evaluation and deployment | USA (via Azure region) | EU SCCs + UK Addendum |
| Pinecone | Vector database; semantic retrieval; AI orchestration | USA | EU SCCs + UK Addendum |
| Elasticsearch B.V. | Search indexing for keyword and structured search | EU | Adequacy |
| Glyphic AI | AI sales-call assistant: recording, transcription and analysis of customer calls | USA | EU SCCs + UK Addendum |
| Amplemarket | Sales engagement and outreach platform | USA | EU SCCs + UK Addendum |
A4.4 AI and Data Use Policy
- Customer inputs, including prompts and document content, are not used to train foundation models for the benefit of other customers.
- AI sub-processors are contractually restricted from using customer data to train or improve models.
- AI services are accessed through enterprise-managed platforms (AWS Bedrock, Azure OpenAI, Google Vertex AI) with controlled execution environments and data isolation.
- Vector embeddings stored for semantic retrieval are derived representations. Original content is not stored in human-readable form within the vector database.
- Documents uploaded to the Workspace Document Library are processed transiently through AI pipelines and are not persistently stored within AI sub-processor infrastructure.
Restrictions on subscriber use of Service Data, including the prohibition on inputting Service Data into public AI models, are set out at Section 5 of the Acceptable Use Policy.
