Privacy Policy
Compliance: UK GDPR & Data Protection Act 2018 • Region: EU/UK (London eu-west-2)
Template notice: This document is template-based, does not constitute legal advice, is pending solicitor review, and must not be relied on for real contracts or payments.
Drafted with AI assistance; requires solicitor sign-off before use with paying customers.
1. Overview & Data Controller vs. Data Processor
Voxflow Technologies Ltd acts as a Data Processor on behalf of our enterprise customers (the Data Controllers) who use our automated telephony services. We process caller information strictly in accordance with documented instructions from our customers. Where Voxflow determines the purposes and means of processing its own business data (for example, Customer account administration), it acts as Controller for that data.
2. Information We Collect
- Account Data: Business email, contact name, billing details, and company identifiers.
- Telephony Metadata: Inbound/outbound caller E.164 phone numbers (masked at rest and in logs), timestamps, call duration, and call resolution statuses.
- Conversational Transcripts: Audio transcripts generated during live calls, subject to configurable automated retention schedules (default 30-day purge).
- Call Recordings & Consent Evidence: Where the tenant enables recording, audio is recorded via Amazon Connect (recordings land in the Connect instance S3 bucket) together with IVR consent evidence stored against the call record.
3. Lawful Bases (UK GDPR Article 6)
We process personal data on the following bases: contract (providing the telephony service to the Customer); legitimate interests (service operation, security, and billing); legal obligation (tax and invoicing records); and consent (call recording, captured via IVR disclosure before recording begins). Controllers relying on Voxflow remain responsible for establishing their own lawful basis for directing caller data to the service.
4. Data Retention & Automated Purge Policy
Voxflow enforces automated data lifecycle policies with per-tenant configurable windows. Defaults: call transcripts 30 days, call records 90 days, and call recordings per tenant setting (recordings are off by default and retained only where the tenant enables them). Expired transcripts and recording pointers are permanently erased by automated purge jobs, and caller PII is scrubbed in line with customer-configured retention limits.
5. Data Subject Rights (DSAR & Right to Erasure)
In accordance with UK GDPR Chapter 3, individuals have the right to request:
- Right of Access (DSAR Export): Complete JSON bundle of all stored interactions associated with a phone number or email address.
- Right to be Forgotten (Erasure): Permanent anonymization and redaction of caller PII while preserving non-PII financial and inventory records.
- Rectification, Restriction & Objection: Correction of inaccurate data, restriction of processing, and objection to processing based on legitimate interests.
To exercise any of these rights, email privacy@voxflow.cc. Requests are tracked in our privacy-requests ledger and answered within one month as UK GDPR requires. Where the request concerns caller data held on a Customer's behalf, we will redirect or coordinate with the relevant Controller.
6. Sub-Processors & Data Hosting
Voxflow runs on the following infrastructure — and nothing else. Project data lives in PostgreSQL (AWS RDS in eu-west-2 as primary, Supabase Postgres where configured); authentication identities live in Supabase Auth. The API runs on AWS EC2 behind Caddy with automatic TLS (Oracle Cloud VM as standby) with production secrets in AWS Secrets Manager (KMS); the dashboard is served from the Vercel edge network at voxflow.cc behind Cloudflare DNS with Turnstile bot protection. Conversational inference is transient: Groq hosted LLM and Whisper STT process call content in flight and do not retain it. Telephony ingress is Amazon Connect with Amazon Lex speech capture; call recordings land in S3. Billing is Stripe; transactional email is Resend; error monitoring is PII-scrubbed Sentry; product analytics is PostHog EU (allow-listed non-identifying events, no IP capture); support chat is Crisp. Google Sheets acts as an optional per-tenant call-log mirror only, never the source of truth. We hold no ISO 27001 or SOC 2 certification — no such certification is claimed. Full processor list with data and locations: /subprocessors.
7. Call Recording Disclosure
Every call carries a recording disclosure: callers are told the call may be recorded before any recording starts, and their IVR consent response is stored as consent evidence against the call record. If a caller does not consent, recording stays off for that call.
8. Data Protection Officer (DPO)
To exercise data subject rights or submit privacy queries, email our Data Protection Officer at privacy@voxflow.cc.
9. Cookies & Site Tracking
The marketing site and dashboard use strictly-necessary cookies only: Supabase authentication session cookies that keep you signed in. We run no advertising trackers, no cross-site analytics, and no third-party marketing pixels. First-party product analytics (PostHog) runs only when configured, stores state in localStorage rather than cookies, never captures IP addresses, and sends only allow-listed non-identifying event properties. If a future release adds any non-essential cookie (for example product analytics), it will be off by default and gated behind an explicit consent banner — no non-essential cookie is ever set before you opt in. The banner implementation itself ships in a later release; this section is the policy it will enforce.