← Voxa

Privacy Policy

Last updated 16 August 2026

Voxa answers a business's telephone. That means it handles recordings and transcripts of conversations with people who never signed up for anything, which is unusual enough to deserve a policy that is specific rather than reassuring. This page describes what is actually captured, where it goes, and how to get rid of it.

1. Information We Collect

Two different groups of people appear throughout this policy. Customers are businesses that subscribe to Voxa. Callers are the people who ring a customer's number and reach the assistant. Almost every difficult question in this document comes from the fact that callers did not choose to use Voxa.

1.1 Information You Provide Directly

From customers: name, email address, the telephone number being answered, sign-in credentials, and the configuration given to the assistant. That configuration includes the greeting, the instructions, and any knowledge entered for the assistant to state to callers, such as opening hours, prices, and policies.

From visitors to this website: the telephone number typed into the demo form, which exists only so the assistant can ring it back.

From callers: whatever they say during a call. Callers commonly state their name, a callback number, and what they need. That speech is captured as audio and as text.

1.2 Information Collected Automatically

Calls are recorded, not merely transcribed. The caller's voice is captured and kept as audio. Whether that recording is lawful depends on where the caller and the business are located: a number of states require every party to a call to consent before it may be recorded, and the rule that applies can be the caller's rather than the business's. Disclosing the recording to callers is the subscribing business's responsibility under our Terms of Service, and the assistant's greeting can be written to say so.

1.3 Information From Third Parties

When a customer imports a knowledge base by naming their business, we query a licensed local-business data service to retrieve that business's public listing: opening hours, address, telephone number, and services. That is information about a business, published by the business.

We do not buy personal information, do not append data to caller records from outside sources, and do not enrich or score callers.

2. How We Use Personal Information

Call recordings and transcripts are not used to train models, are not used for advertising, and are not analysed for any purpose beyond running the service for the customer whose calls they are.

3. Legal Bases for Processing

Where the UK GDPR or EU GDPR applies:

Where a customer is established outside those regimes, the customer remains responsible for identifying the basis on which it collects its callers' information.

4. Cookies and Similar Technologies

This site does not run advertising or analytics cookies. The dashboard sets one cookie, which keeps you signed in. It is strictly necessary, it is marked HttpOnly so page scripts cannot read it, and it is removed when you sign out. The marketing site sets no cookies at all.

Global Privacy Control and Do Not Track

Because we do not sell or share personal information and run no cross-site tracking, a Global Privacy Control or Do Not Track signal has nothing to switch off here. We honour such signals by default, in the sense that the behaviour they disable is behaviour we do not perform.

5. How We Disclose Personal Information

We do not sell personal information. We do not share it for cross-context behavioural advertising. It is disclosed only as follows.

5.1 Service Providers

Holding a spoken conversation in real time requires sending call content to specialist services. These are the only ones that receive it:

ProviderWhat it receivesWhy
DeepgramCall audioConverting speech to text, and generating the assistant's voice.
AnthropicCall transcriptDeciding what the assistant says, and writing the summary afterwards.
DreamHostAccount and call recordsHosting the dashboard and its database.

Each is bound to use the data only to provide its service to us.

5.2 Business and Professional Advisors

Accountants, insurers, and lawyers may see information where they need it to advise us, under a duty of confidence.

5.3 Legal and Safety Reasons

We may disclose information where the law requires it, in response to a valid legal process, or where disclosure is necessary to protect someone's safety, to investigate fraud, or to enforce our agreements. Where we are permitted to tell the customer that a request has been made, we will.

5.4 Business Transfers

If the business is sold, merged, or reorganised, customer and call records may transfer with it. The buyer would be bound by this policy until a replacement is notified.

5.5 With Your Direction or Consent

Where a customer connects Voxa to another system of their choosing, such as sending call details to their own webhook, that transfer happens on their instruction and this policy stops governing what the receiving system does.

6. Categories of Personal Information

Under California law, the categories collected in the past twelve months are set out below. All of it is collected from the sources described in section 1, used for the purposes in section 2, and disclosed only to the recipients in section 5.

CategoryExamples in Voxa
IdentifiersName, email address, telephone number, IP address.
Audio informationRecordings of calls.
Internet activityServer logs of dashboard use.
Commercial informationSubscription and payment records.
InferencesWhether a caller appears to need a callback, drawn from what they said.

We do not collect sensitive personal information deliberately. A caller may nonetheless mention something sensitive during a call, which is one reason recordings are kept no longer than they need to be.

7. Data Retention

A customer may delete any individual call, recording, or contact from the dashboard at any time. Deletion happens immediately rather than being queued.

8. Data Security

Traffic is encrypted in transit. Dashboard access requires a password, and passwords are stored as bcrypt hashes rather than in readable form. API keys live in server configuration and are never displayed in the dashboard once saved. Call audio is written to the machine that answers the calls and is not copied to the web host, so a compromise of the website would not expose recordings.

No system is perfect, and this one is run by a small company. If a breach affects your information we will tell you rather than wait to be asked.

9. Your Privacy Rights

Depending on where you live, you may have the right to request a copy of the information held about you, to have it corrected, to have it deleted, to object to or restrict how it is used, to receive it in a portable form, and to complain to a regulator. Exercising a right will never lead to worse service or a different price.

Requests go to matt@webpronc.com and are answered within 30 days. We will ask for enough information to be confident the request is genuinely yours, and an authorised agent may act for you with written permission.

If you are a caller rather than a customer, the business you telephoned controls its own call records. The quickest route is to ask that business directly. We will act on any request they pass to us, and we will also act on one sent to us directly by getting in touch with them.

10. Marketing Communications

We email customers about their account, billing, and material changes to the service, and those messages cannot be opted out of while an account is open. Anything promotional is sent only with consent and carries an unsubscribe link that works. Callers are never marketed to, and caller numbers are never used to build a marketing list.

11. Third-Party Websites and Services

This site and the dashboard link to other companies' websites, including our providers' documentation and our payment processor. Following a link takes you outside this policy and into theirs. We do not control what those sites collect.

12. International Visitors and Data Transfers

Voxa is operated from the United States and its providers are largely based there. Using the service means information is transferred to and stored in the United States, where privacy law differs from that in the United Kingdom, the European Economic Area, and elsewhere. Where such transfers are restricted, we rely on the standard contractual clauses published for that purpose.

13. Children's Privacy

Voxa is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. A child may telephone a business that uses Voxa, in which case their call is handled as any other call and deleted on the schedule in section 7. If you believe a child's information is held and should not be, write to us and it will be removed.

14. Changes to This Privacy Policy

If this policy changes in a way that affects what is collected, who receives it, or how long it is kept, customers are told by email before the change takes effect. Lesser changes are published here with a new date. The date at the top always reflects the version in force.

15. Contact Us

Voxa, Miami, Florida, United States.
matt@webpronc.com

Voxa is the data processor described in section 1 for caller information handled on a customer's behalf.