Terms of Service
Last Updated: August 30, 2026 • Governing Law: England & Wales
Template notice: This document is template-based, does not constitute legal advice, is pending solicitor review, and must not be relied on for real contracts or payments.
Drafted with AI assistance; requires solicitor sign-off before use with paying customers.
1. Agreement to Terms
These Terms of Service ("Terms") constitute a legally binding agreement between Voxflow Technologies Ltd ("Voxflow", "we", "us", or "our") and the organization or individual accessing or using the Voxflow enterprise voice AI platform ("Customer", "you"). By creating an account or using the service you accept these Terms. These Terms are governed by the laws of England & Wales.
2. Description of Service
Voxflow provides automated, conversational voice AI telephony for enterprise call handling, order inquiries, supplier verification, appointment scheduling, and data synchronization (Postgres records with optional Google Sheets mirror and webhooks where enabled). Telephony ingress is provided by Amazon Connect with Amazon Lex speech capture; conversational inference runs on the Groq hosted API (LLM and Whisper STT); project data lives in PostgreSQL (AWS RDS in eu-west-2 as primary, Supabase Postgres where configured) with authentication identities in Supabase Auth; the API runs on AWS EC2 behind Caddy with automatic TLS (Oracle Cloud VM as standby); the dashboard is served from the Vercel edge network at voxflow.cc, behind Cloudflare DNS with Turnstile bot protection.
3. Subscriptions, Invoicing & Stripe Billing
Voxflow services are provided on a subscription basis (Starter, Growth, Enterprise). Subscriptions are billed in advance in GBP (£) or USD ($) on a recurring monthly or annual basis via Stripe.
- Free Trials: 14-day free trial periods grant full platform access without immediate charge.
- Failed Payments: If payment fails, an automated grace period applies before telephony services transition to inactive.
- VAT & Invoicing: Invoices with compliant UK VAT receipts are delivered via the Stripe Customer Portal.
4. Data Protection: Controller & Processor Roles
Under UK GDPR, the Customer acts as Data Controller for personal data processed through its telephony deployment (caller numbers, transcripts, recordings), and Voxflow acts as Data Processor, processing that data only on the Customer's documented instructions. The parties agree to enter a data processing agreement reflecting Article 28 UK GDPR terms on request. Voxflow's sub-processors are AWS (Connect telephony ingress and Lex speech capture with recordings in S3, RDS database, EC2 hosting, Secrets Manager/KMS), Supabase (authentication and Postgres where configured), Groq (transient LLM and transcription inference), Stripe (billing), Resend (transactional email), Sentry (PII-scrubbed error monitoring), PostHog EU (product analytics), Crisp (support chat), Vercel (frontend hosting), Cloudflare (DNS, bot protection, email routing), Microsoft (dashboard simulator text-to-speech only), and Google Sheets (optional per-tenant call-log mirror only) — see the full list at /subprocessors. Voxflow holds no ISO 27001 or SOC 2 certification; no such certification is claimed.
5. Call Recording Disclosure & Acceptable Use
Every call handled by Voxflow carries a recording disclosure: callers are informed that the call may be recorded before recording begins, and consent is captured via the IVR and stored as consent evidence against the call record. Customers must not use the platform for unlawful robocalling, deceptive impersonation, harassment, or in violation of Ofcom / FCC telephony regulations. Customers are responsible for any additional recording notifications their own regulatory position requires.
6. Tenant Data Isolation & Security
Each tenant workspace is isolated by application-level tenant scoping on shared Postgres tables, with three access tiers (Owner, Operator, Viewer). Transport is encrypted via TLS; database backups are retained for 7 days with point-in-time recovery; production secrets live in AWS Secrets Manager encrypted with KMS. Primary data residency is eu-west-2 (London).
7. Retention
Default retention windows are: call transcripts 30 days, call records 90 days, and call recordings per tenant setting (recordings are off by default and retained only where the tenant enables them). Expired data is purged automatically. See the Privacy Policy for detail and for how data subjects may request access or erasure via the privacy-requests process.
8. Limitation of Liability
To the maximum extent permitted by UK law, Voxflow shall not be liable for indirect, incidental, special, or consequential damages resulting from downtime, network outages, or third-party telephony provider carrier failures.
9. Contact Information
For legal inquiries or corporate contracts, contact us at legal@voxflow.cc.