Dear VAPI Enterprise Team, My name is Fabian Pf...
# general-english
l
Dear VAPI Enterprise Team, My name is Fabian Pfliegendörfer, founder of LiftUp Socials, a German AI automation agency. We are currently using VAPI to deploy voice agents for clients in regulated industries in Germany, including medical practices and tax advisory firms. We have already enabled HIPAA mode on our account and have been in contact with your security Why this is urgent for us: Under EU GDPR Art. 28, any processor handling personal data on behalf of an EU controller must have a signed Data Processing Agreement in place. This is a legal requirement – not optional. Additionally, our clients in the healthcare and legal sector are subject to: - §203 German Criminal Code (professional secrecy for physicians and tax advisors) - §62a StBerG (IT outsourcing rules for tax advisors requiring written confidentiality obligations) - EU AI Act Art. 50 (transparency requirements for AI systems) We cannot onboard new clients in these sectors without a signed DPA from VAPI and a complete list of your sub-processors, including their location and data protection measures. What we specifically need: 1. A signed Data Processing Agreement (DPA) compliant with GDPR Art. 28 2. Your full sub-processor list (ElevenLabs, LLM providers, telephony providers etc.) with country of processing and applicable safeguards (SCCs, adequacy decisions) 3. Confirmation that EU data residency is available or that Standard Contractual Clauses (SCCs) are in place for all US-based sub-processors 4. A written confidentiality commitment that can be presented to our clients under §203 German Criminal Code Let me know if you guys have some help Thank you for your prompt attention to this matter. Best regards, Fabian Pfliegendörfer