Privacy Policy
Last updated 16 August 2026
Voxa answers a business's telephone. That means it handles recordings and transcripts of conversations with people who never signed up for anything, which is unusual enough to deserve a policy that is specific rather than reassuring. This page describes what is actually captured, where it goes, and how to get rid of it.
1. Information We Collect
Two different groups of people appear throughout this policy. Customers are businesses that subscribe to Voxa. Callers are the people who ring a customer's number and reach the assistant. Almost every difficult question in this document comes from the fact that callers did not choose to use Voxa.
1.1 Information You Provide Directly
From customers: name, email address, the telephone number being answered, sign-in credentials, and the configuration given to the assistant. That configuration includes the greeting, the instructions, and any knowledge entered for the assistant to state to callers, such as opening hours, prices, and policies.
From visitors to this website: the telephone number typed into the demo form, which exists only so the assistant can ring it back.
From callers: whatever they say during a call. Callers commonly state their name, a callback number, and what they need. That speech is captured as audio and as text.
1.2 Information Collected Automatically
- Call audio. The caller's side of a call is recorded and stored as an audio file.
- Transcript. Every turn of the conversation, with timings.
- Call metadata. Caller number, called number, direction, start time, duration, and how the call ended.
- Derived details. After the call ends, the caller's name, callback number, reason for calling, and whether a follow-up is needed, all extracted from the transcript.
- Server logs. Ordinary web-server records of requests to the dashboard, including IP address, kept for security and fault-finding.
Calls are recorded, not merely transcribed. The caller's voice is captured and kept as audio. Whether that recording is lawful depends on where the caller and the business are located: a number of states require every party to a call to consent before it may be recorded, and the rule that applies can be the caller's rather than the business's. Disclosing the recording to callers is the subscribing business's responsibility under our Terms of Service, and the assistant's greeting can be written to say so.
1.3 Information From Third Parties
When a customer imports a knowledge base by naming their business, we query a licensed local-business data service to retrieve that business's public listing: opening hours, address, telephone number, and services. That is information about a business, published by the business.
We do not buy personal information, do not append data to caller records from outside sources, and do not enrich or score callers.
2. How We Use Personal Information
- To answer calls, hold the conversation, and speak back to the caller.
- To produce the transcript, summary, and caller details the customer sees.
- To maintain a call history and contact record for the customer.
- To diagnose faults. Call audio is retained for this reason and no other: recognition and timing problems cannot be investigated from text alone.
- To operate accounts, take payment, and provide support.
- To keep the service secure and to investigate misuse.
Call recordings and transcripts are not used to train models, are not used for advertising, and are not analysed for any purpose beyond running the service for the customer whose calls they are.
3. Legal Bases for Processing
Where the UK GDPR or EU GDPR applies:
- Contract. Operating an account and providing the service to a customer.
- Legitimate interests. Securing the service, preventing misuse, and diagnosing faults, balanced against the interests of the people whose data is involved.
- Consent. Marketing email, and any call recording where consent is the basis relied on. Consent may be withdrawn at any time.
- Legal obligation. Retaining accounting records and responding to lawful requests.
Where a customer is established outside those regimes, the customer remains responsible for identifying the basis on which it collects its callers' information.
4. Cookies and Similar Technologies
This site does not run advertising or analytics cookies. The dashboard sets one cookie, which keeps you signed in. It is strictly necessary, it is marked HttpOnly so page scripts cannot read it, and it is removed when you sign out. The marketing site sets no cookies at all.
Global Privacy Control and Do Not Track
Because we do not sell or share personal information and run no cross-site tracking, a Global Privacy Control or Do Not Track signal has nothing to switch off here. We honour such signals by default, in the sense that the behaviour they disable is behaviour we do not perform.
5. How We Disclose Personal Information
We do not sell personal information. We do not share it for cross-context behavioural advertising. It is disclosed only as follows.
5.1 Service Providers
Holding a spoken conversation in real time requires sending call content to specialist services. These are the only ones that receive it:
| Provider | What it receives | Why |
|---|---|---|
| Deepgram | Call audio | Converting speech to text, and generating the assistant's voice. |
| Anthropic | Call transcript | Deciding what the assistant says, and writing the summary afterwards. |
| DreamHost | Account and call records | Hosting the dashboard and its database. |
Each is bound to use the data only to provide its service to us.
5.2 Business and Professional Advisors
Accountants, insurers, and lawyers may see information where they need it to advise us, under a duty of confidence.
5.3 Legal and Safety Reasons
We may disclose information where the law requires it, in response to a valid legal process, or where disclosure is necessary to protect someone's safety, to investigate fraud, or to enforce our agreements. Where we are permitted to tell the customer that a request has been made, we will.
5.4 Business Transfers
If the business is sold, merged, or reorganised, customer and call records may transfer with it. The buyer would be bound by this policy until a replacement is notified.
5.5 With Your Direction or Consent
Where a customer connects Voxa to another system of their choosing, such as sending call details to their own webhook, that transfer happens on their instruction and this policy stops governing what the receiving system does.
6. Categories of Personal Information
Under California law, the categories collected in the past twelve months are set out below. All of it is collected from the sources described in section 1, used for the purposes in section 2, and disclosed only to the recipients in section 5.
| Category | Examples in Voxa |
|---|---|
| Identifiers | Name, email address, telephone number, IP address. |
| Audio information | Recordings of calls. |
| Internet activity | Server logs of dashboard use. |
| Commercial information | Subscription and payment records. |
| Inferences | Whether a caller appears to need a callback, drawn from what they said. |
We do not collect sensitive personal information deliberately. A caller may nonetheless mention something sensitive during a call, which is one reason recordings are kept no longer than they need to be.
7. Data Retention
- Call audio: 30 days, then deleted.
- Transcripts, summaries, contacts, and call history: kept while the account is open, then deleted within 30 days of closure.
- Server logs: 30 days.
- Account and billing records: as long as tax and accounting law requires, currently seven years.
A customer may delete any individual call, recording, or contact from the dashboard at any time. Deletion happens immediately rather than being queued.
8. Data Security
Traffic is encrypted in transit. Dashboard access requires a password, and passwords are stored as bcrypt hashes rather than in readable form. API keys live in server configuration and are never displayed in the dashboard once saved. Call audio is written to the machine that answers the calls and is not copied to the web host, so a compromise of the website would not expose recordings.
No system is perfect, and this one is run by a small company. If a breach affects your information we will tell you rather than wait to be asked.
9. Your Privacy Rights
Depending on where you live, you may have the right to request a copy of the information held about you, to have it corrected, to have it deleted, to object to or restrict how it is used, to receive it in a portable form, and to complain to a regulator. Exercising a right will never lead to worse service or a different price.
Requests go to matt@webpronc.com and are answered within 30 days. We will ask for enough information to be confident the request is genuinely yours, and an authorised agent may act for you with written permission.
If you are a caller rather than a customer, the business you telephoned controls its own call records. The quickest route is to ask that business directly. We will act on any request they pass to us, and we will also act on one sent to us directly by getting in touch with them.
10. Marketing Communications
We email customers about their account, billing, and material changes to the service, and those messages cannot be opted out of while an account is open. Anything promotional is sent only with consent and carries an unsubscribe link that works. Callers are never marketed to, and caller numbers are never used to build a marketing list.
11. Third-Party Websites and Services
This site and the dashboard link to other companies' websites, including our providers' documentation and our payment processor. Following a link takes you outside this policy and into theirs. We do not control what those sites collect.
12. International Visitors and Data Transfers
Voxa is operated from the United States and its providers are largely based there. Using the service means information is transferred to and stored in the United States, where privacy law differs from that in the United Kingdom, the European Economic Area, and elsewhere. Where such transfers are restricted, we rely on the standard contractual clauses published for that purpose.
13. Children's Privacy
Voxa is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. A child may telephone a business that uses Voxa, in which case their call is handled as any other call and deleted on the schedule in section 7. If you believe a child's information is held and should not be, write to us and it will be removed.
14. Changes to This Privacy Policy
If this policy changes in a way that affects what is collected, who receives it, or how long it is kept, customers are told by email before the change takes effect. Lesser changes are published here with a new date. The date at the top always reflects the version in force.
15. Contact Us
Voxa, Miami, Florida, United States.
matt@webpronc.com
Voxa is the data processor described in section 1 for caller information handled on a customer's behalf.