Hi everyone
We are considering using vapi for running a closed UK healthcare pilot and plan to use Vapi to place outbound calls and process call audio/transcripts. Would anyone be able to help with:
customer Data Processing Addendum (DPA) covering UK GDPR,
international transfer mechanism (EU SCCs plus UK Addendum, or UK IDTA) and referenced appendices,
current sub-processor list specifically covering call audio, transcripts, ASR/TTS/LLM and storage,
Data location details (where audio/transcripts are processed and stored),
Retention and deletion controls for audio/transcripts/logs,
Confirmation whether customer call data is used for training models, and how to opt out,
A short security pack (SOC 2 / pen test summary / security overview) if available.
I have requested access on your security portal