Data Processing Agreement

Last updated: August 24, 2026 · Version 1.0

Who this is for

This agreement applies to speech therapists, clinics, schools, and other professionals who use Verbalyft to work with children on behalf of their own clients. It is the GDPR Article 28 contract between you and us, and it takes effect automatically when you create a therapist account.

If you are a parent using Verbalyft for your own child, this agreement does not apply to you. Your relationship with us is covered by the Privacy Policy and the Terms of Use.

1. The Parties

This agreement is between Sorusly AI Labs, of 99/29, 2nd Floor, Zakir Nagar, New Delhi – 110025, India, operator of Verbalyft (“Verbalyft”, “we”, the Processor) and the professional or organisation holding the therapist account (“you”, the Controller).

It forms part of, and is governed by, the Terms of Use. Where this agreement and the Terms of Use conflict on the handling of personal data, this agreement takes precedence.

2. Which of us is responsible for what

You are the controller. You decide which children to add to the platform, what to record about them, and why. You are responsible for having a lawful basis for that processing, and for obtaining consent from each child's parent or legal guardian before you enter their data.

We are the processor. We process that data only to provide the service, and only on your documented instructions. Your use of the platform — creating a child profile, running a session, inviting a parent — constitutes those instructions.

Where a parent signs up directly and independently of any therapist, we act as controller for that account, and this agreement does not apply to it.

3. What we process, and why

Subject matter and purpose: providing a speech and language therapy platform — practice activities, progress tracking, and reporting back to you and the parent.

Duration: for as long as your account is active, plus the deletion period in section 9.

Categories of data subject: children receiving therapy; their parents or legal guardians; you and any colleagues on your account.

Categories of personal data:

  • Child's first name and age or date of birth
  • Speech practice records — the target word or sound, its position in the word, whether the attempt was accepted, and when
  • Progress metrics, session history, and assigned activities
  • Any notes you choose to write about a child
  • Parent email address, where a parent is invited to the account
  • Your own account details — name, email, organisation

Special category data: information about a child's speech or language difficulty may constitute health data under Article 9. You are responsible for establishing an Article 9 condition before entering it. We process it only as described here.

4. A child's voice is never sent to us

This is the most sensitive data the platform touches, so it is worth being precise about it.

Speech recognition runs inside the browser, using the browser's own built-in speech engine. Verbalyft's servers never receive an audio recording, and we do not store one. Only the resulting text — and whether the attempt was accepted — is sent to us.

You should be aware, and should tell parents, that some browsers perform that recognition on their own servers. Chrome, in particular, transmits audio to Google for processing. That happens between the browser and its vendor, outside our systems and outside our control, and is governed by the browser's own privacy terms rather than this agreement. A browser with on-device recognition avoids it entirely.

5. Our obligations

We will:

  • process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we will tell you first, unless the law forbids it
  • ensure everyone authorised to process the data is bound by confidentiality
  • implement the security measures in section 6
  • respect the conditions in section 7 before engaging another sub-processor
  • help you respond to data subject requests, as set out in section 8
  • help you with security obligations, breach notification, and data protection impact assessments, taking into account what we know and what you do not
  • delete or return the data at the end of the service, per section 9
  • make available the information needed to demonstrate compliance with Article 28, and allow for audits as described in section 11

6. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) for all connections
  • Encryption at rest for the database
  • Access to production data limited to personnel who need it, and authenticated individually
  • Session tokens that expire, and server-side authorisation on every request that returns child data
  • Automated database backups with point-in-time recovery
  • Separation of the therapist, parent, and administrator roles, so a therapist sees only children on their own caseload

What we do not currently hold: we are a small team and we do not yet hold SOC 2, ISO 27001, or an equivalent third-party certification, and we have not appointed a formal Data Protection Officer. We would rather tell you that plainly than imply otherwise. If your own compliance requires a certified processor, please raise it with us before onboarding children.

7. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. We will give you at least 30 days' notice by email before adding or replacing one, and you may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate your subscription and receive a pro-rata refund of any prepaid period.

Each sub-processor is bound by terms no less protective than these.

Sub-processorPurposeLocation
Vercel Inc.Application hosting and deliveryUnited States
Neon Inc.Primary database — all child and session recordsEU (London, eu-west-2)
Google LLCGemini API for activity content; sign-in with Google; analytics (only with consent)United States
OpenAI, L.L.C.Activity and story content generationUnited States
Groq, Inc.Content generation, used as a fallback providerUnited States
ResendTransactional email — invitations, password resets, noticesUnited States
Dodo PaymentsSubscription billing. Receives your billing details, never child dataUnited States

What goes to the AI providers: the prompts that generate practice content — target sounds, word lists, age band, and activity type. We do not send a child's name, and we do not send audio. These providers act on our instructions and do not train their models on the data we send.

8. International transfers

We are established in India, which the European Commission has not found to provide an adequate level of data protection. If you are established in the EEA, the UK, or Switzerland, engaging us is itself a restricted transfer, and you should treat it as such in your own records. We would rather you know this at the top of this section than find it in a footnote.

Where the data physically sits. Child and session records are stored in the European Union, in Neon's eu-west-2 (London) region. They are not replicated to India. What crosses the border is access: our personnel administer the service from India and can reach production data in the course of doing so.

The basis for that transfer. The transfer from you as exporter to us as importer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this agreement by reference. For UK data, the UK International Data Transfer Addendum applies to those same clauses. Sections 5, 6, 7, 9, 10, 11 and 12 of this agreement constitute the Annexes to those clauses, describing the processing, the security measures, and the sub-processors.

Onward transfers. The sub-processors in section 7 established in the United States constitute further transfers. Each is bound by the Standard Contractual Clauses incorporated into our agreement with them, or by certification under the EU–US Data Privacy Framework where they hold one.

Indian law. We are also subject to India's Digital Personal Data Protection Act, 2023. We are not aware of any Indian law that would prevent us from meeting our obligations under this agreement. If we receive a legally binding request from a public authority for data we process for you, we will notify you unless prohibited from doing so, will challenge a request we consider unlawful, and will disclose only the minimum the request requires.

If your own transfer impact assessment concludes that these safeguards are insufficient for your circumstances, tell us before onboarding children and we will discuss what additional measures are workable.

9. Helping you answer data subject requests

Parents and guardians may ask to see, correct, export, restrict, or delete their child's data. As controller, those requests are yours to answer.

You can action most of them yourself in the therapist dashboard. Where you cannot, email us and we will help within 5 working days. If a parent contacts us directly about a child on your caseload, we will not action the request ourselves — we will refer them to you and let you know.

10. Deletion and return

You can delete a child profile at any time from the dashboard. Deletion removes the child's records from the live database immediately, and from backups within 30 days as backup rotation completes.

When your account closes, we delete all personal data processed on your behalf within 30 days, unless we are legally required to keep it. You may request an export in a structured, machine-readable format at any point before then.

11. Personal data breaches

If we become aware of a breach affecting personal data we process for you, we will notify you without undue delay, and within 72 hours of becoming aware. The notice will describe what happened, which categories and roughly how many records are involved, the likely consequences, and what we are doing about it — as far as we know at the time, with updates as we learn more.

Notifying your supervisory authority and, where required, the affected parents, remains your responsibility as controller.

12. Audits

On reasonable written notice, and no more than once a year unless a regulator requires otherwise or a breach has occurred, we will provide the information necessary to demonstrate compliance with Article 28 and cooperate with an audit conducted by you or an auditor you appoint.

Audits must be during business hours, must not unreasonably disrupt the service, and are subject to confidentiality. We may satisfy an audit request with existing documentation where it reasonably answers your questions.

13. Liability and governing law

Liability under this agreement is subject to the limitations in the Terms of Use. Nothing here limits liability that cannot be limited under applicable data protection law, including a data subject's right to compensation under Article 82.

This agreement is governed by the laws of India, in line with the Terms of Use, with the courts at New Delhi having jurisdiction. That choice does not displace mandatory data protection law in your own jurisdiction, and it does not affect the Standard Contractual Clauses in section 8 — those are governed by the law of the EU member state they specify, and prevail over this section wherever the two conflict.

14. Contact

For anything about this agreement, a data subject request you need help with, or a suspected breach, email privacy@verbalyft.com.

For a countersigned copy of this agreement for your own records, email us and we will arrange it.

15. Changes

We will give at least 30 days' notice by email before a material change. Continuing to use the platform after a change takes effect means you accept the revised agreement. Previous versions are available on request.