YPAI
Services Data Industries Company
AI Data & Evaluation
Data collection and sourcing Consent-led multimodal collection. Dataset licensing Rights-cleared datasets, ready to license. Annotation and curation Labelling, review and adjudication. Model and agent evaluation Human evaluation and regression testing. Explore AI Data & Evaluation Create, source and evaluate the data your AI depends on.
AI Implementation
Discovery and architecture Scope the use case and the system design. RAG and knowledge systems Retrieval over your own knowledge. Agents and workflow automation Agents and automation in production. Private and enterprise deployment Private, controlled deployment. Explore AI Implementation Turn a defined AI use case into a system you can operate.
Delivery
Connected Delivery Data, evaluation and implementation under one structure. Pilots Validate the delivery method before scale.
Explore all services
AI Data & Evaluation
Speech & Audio Data Multilingual speech, acoustic environments and voice data. Image, 3D & Sensor Data Images, documents, multi-view data, LiDAR and sensor fusion. Video, Physical AI & Robotics Data On-camera, conversational, egocentric and robotics data. Dataset Licensing & Sourcing Rights-cleared datasets, bespoke sourcing and acquisition. Annotation & Data Production Ontology design, labelling, review and model-ready delivery. Model & Agent Evaluation Human evaluation, multilingual testing and failure analysis.
Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Training data, preference data and evaluation loops. Automotive & Mobility In-cabin speech, perception, video and sensor data. Financial Services Document AI, knowledge systems and traceability. Healthcare & Life Sciences Specialist data, domain review and privacy-sensitive work. Industrial & Energy Field data, operational workflows and integration. Public Sector Controlled data operations and reviewable AI systems.
Explore industry solutions
Company
About YPAI Company, mission, operating model and delivery history. Partnerships Commercial, technology and delivery collaboration. AI Blog Research, technical perspectives and company updates. Contact Projects, partnerships, procurement and general enquiries.
Become a Contributor Contact us
YPAI
AI Data & Evaluation
Data collection and sourcing Dataset licensing Annotation and curation Model and agent evaluation Explore AI Data & Evaluation
AI Implementation
Discovery and architecture RAG and knowledge systems Agents and workflow automation Private and enterprise deployment Explore AI Implementation
Delivery
Connected Delivery Pilots Explore all services
AI Data & Evaluation
Speech & Audio Data Image, 3D & Sensor Data Video, Physical AI & Robotics Data Dataset Licensing & Sourcing Annotation & Data Production Model & Agent Evaluation Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Automotive & Mobility Financial Services Healthcare & Life Sciences Industrial & Energy Public Sector Explore industry solutions
About YPAI Partnerships AI Blog Contact
Contact us Become a Contributor

Speech data

DPA Overview

Last updated: July 2026

Data processing governance for enterprise speech data collection. The DPA is executed before production collection begins.

On this page

  • 1. Executive summary
  • 2. Roles and responsibilities
  • 3. Scope and data categories
  • 4. Consent and provenance
  • 5. Sub-processors
  • 6. Retention and deletion
  • 7. Security and audit readiness
  • 8. Procurement and legal FAQ

1. Executive summary

This page is an overview for internal review. The signed DPA and role definitions are finalized during scoping.

Execution
DPA executed before production collection begins
GDPR
Processing aligned with GDPR principles; Article 28 addressed in contract documentation
Roles
Processor or Independent Controller, defined per engagement
Consent
Consent and provenance verifiable for all collected data
Sub-processors
Governance and disclosure included in DPA terms
Audit
Documentation available for legal and compliance review
Retention
Retention and deletion terms defined contractually during scoping

2. Roles and responsibilities

Role designation between Controller and Processor is determined per engagement based on the nature of the data processing activities and contractual requirements.

Processor engagements: YPAI processes personal data on behalf of the client organization according to documented instructions. The client remains the Controller.

Independent Controller engagements: In certain arrangements, YPAI may act as an Independent Controller for specific processing activities. This is documented in the engagement agreement.

Role definitions and responsibilities are specified in the DPA and reviewed during scoping. Specific obligations are defined contractually.

3. Processing scope and data categories

Speech data collection workflows involve processing of audio recordings and associated metadata. Data categories processed include:

  • Voice recordings (audio files)
  • Transcripts and annotations
  • Speaker metadata (anonymized identifiers, demographic categories as defined per project)
  • Consent records and provenance documentation
  • Technical metadata (sample rate, format, duration)

Purpose limitation: Data is processed for the purposes of collection, validation, quality assurance, and delivery as defined in the engagement agreement. Specific data categories and processing purposes are documented in the DPA Annex and defined during scoping.

4. Consent, provenance, and auditability

All data collection occurs within our controlled platform. This enables verifiable consent and traceable provenance for each recording.

Consent: Consent is obtained from contributors before recording begins. Consent records are maintained and can be produced for internal review.

Provenance: Each recording is associated with provenance metadata including contributor identifier, timestamp, and consent reference.

Audit trail: Full audit documentation is available for legal and compliance review. Provenance is verifiable for long-term production use. Audit trail requirements and access procedures are defined contractually.

5. Sub-processors and third parties

Sub-processors engaged in data processing activities are disclosed as part of the DPA terms.

  • Sub-processor list or categories provided during scoping
  • Sub-processor governance procedures defined in the DPA
  • Update notification and approval mechanisms agreed contractually

6. Retention and deletion

Retention periods and deletion procedures are defined contractually during scoping.

  • Retention windows vary by engagement and are specified in the DPA
  • Deletion procedures aligned with GDPR requirements
  • Ability to support enterprise retention policies as defined per project

Post-engagement: Data handling after engagement completion is documented in the DPA, including return or deletion options. Specific retention periods and deletion timelines are provided for internal review during scoping.

7. Security, access control, and audit readiness

Internal controls and security measures are implemented to protect data during collection, processing, and delivery.

Access control: Access to data is limited to authorized personnel. Access control policies are documented and available for review.

Audit readiness: Full audit documentation is available for legal and compliance review. We can provide documentation of security practices upon request during scoping.

8. Procurement and legal FAQ

When is the DPA signed?

The DPA is executed before production collection begins. During scoping, we provide draft DPA terms for internal review. The signed agreement is finalized before any data processing activities commence.

Is YPAI a Controller or Processor?

Role designation depends on the engagement model. YPAI may act as Data Processor or Independent Controller depending on the contractual arrangement. Role definitions are specified in the DPA and reviewed during scoping.

Can we review sub-processors before signing?

Sub-processors are disclosed as part of the DPA terms. A list of sub-processors or categories of sub-processors is provided during scoping for internal review.

How is consent demonstrated?

Consent is obtained through our controlled platform and is verifiable. Provenance records are maintained for audit purposes. Details of consent mechanisms are documented in the DPA and available for compliance review.

What audit artifacts can you provide?

Full audit documentation is available for legal and compliance review. This includes provenance records, consent documentation, and processing logs. Specific audit requirements can be addressed during scoping.

What happens if requirements change after pilot?

Requirement changes are handled through contract amendment procedures defined in the engagement agreement. We work with your legal and procurement teams to document changes appropriately.

How do you handle deletion requests?

Deletion and retention terms are defined contractually during scoping. Procedures for handling deletion requests are documented in the DPA and aligned with GDPR requirements.

Do you support regulated environments?

Yes. Our approach is designed for organizations in regulated environments including healthcare, finance, and automotive. Specific regulatory requirements are addressed during technical and compliance scoping.

Can we use our own DPA template?

We are able to review and work with client-provided DPA templates. Template review and negotiation occur during the scoping phase.

How are sub-processor changes communicated?

Sub-processor update procedures are defined in the DPA. Notification mechanisms and approval workflows are agreed upon during contract negotiation.

Request an enterprise consultation

If you need a formal appendix for internal review, ask and we will provide it during scoping.

Speech data overview · Technical specifications · Data residency and sub-processors · How YPAI processes customer and project data

Start with the requirement, not a predefined package.

Bring the objective, current system or dataset, and known operating constraints. YPAI will map the appropriate service line, delivery structure and first validation step.

Contact us Scope a pilot

AI systems, data and evaluation under one accountable delivery model.

New projects · accepting data and AI requirements
Engagement scoped before build
Acceptance defined before delivery
Services
AI Data & Evaluation AI Implementation Controlled Delivery Dataset Licensing
Capabilities
Speech & Audio Image, 3D & Sensor Data Video Data Annotation & Evaluation
Company
About YPAI Partnerships Contact Become a Contributor
Resources & Legal
AI Blog Privacy Terms Cookie Policy Data processing
YPAI · Org. nr. 933 915 778 · Oslo, Norway · Global delivery
Disclaimer LinkedIn ↗ GitHub ↗
EEA-BASED PROCESSING AVAILABLE WHERE REQUIRED · ARTICLE 28 DPA TERMS AVAILABLE
© 2026 YPAI
Install YPAI Faster reopens, offline shell, share-target ready.

Add YPAI to your home screen

Tap the Share button, then Add to Home Screen.