Dear VAPI Enterprise Team,
My name is Fabian Pfliegendörfer, founder of LiftUp Socials, a German AI automation agency. We
are currently using VAPI to deploy voice agents for clients in regulated industries in
Germany, including medical practices and tax advisory firms.
We have already enabled HIPAA mode on our account and have been in contact with your security
Why this is urgent for us:
Under EU GDPR Art. 28, any processor handling personal data on behalf of an EU controller must
have a signed Data Processing Agreement in place. This is a legal requirement – not optional.
Additionally, our clients in the healthcare and legal sector are subject to:
- §203 German Criminal Code (professional secrecy for physicians and tax advisors)
- §62a StBerG (IT outsourcing rules for tax advisors requiring written confidentiality
obligations)
- EU AI Act Art. 50 (transparency requirements for AI systems)
We cannot onboard new clients in these sectors without a signed DPA from VAPI and a complete
list of your sub-processors, including their location and data protection measures.
What we specifically need:
1. A signed Data Processing Agreement (DPA) compliant with GDPR Art. 28
2. Your full sub-processor list (ElevenLabs, LLM providers, telephony providers etc.) with
country of processing and applicable safeguards (SCCs, adequacy decisions)
3. Confirmation that EU data residency is available or that Standard Contractual Clauses
(SCCs) are in place for all US-based sub-processors
4. A written confidentiality commitment that can be presented to our clients under §203 German
Criminal Code
Let me know if you guys have some help
Thank you for your prompt attention to this matter.
Best regards,
Fabian Pfliegendörfer