NewCall a live VoiFlow agent in your region. It picks up on the first ring.Call it now
VoiFlow

Privacy Policy

Version 1.07 min readEffective from enter the publication date

How VoiFlow collects and uses personal data to run its business, and what happens to personal data in the calls and records our customers handle.

This policy explains how VoiFlow collects and uses personal data when we run our business: when you visit our website, contact us, use a VoiFlow account, buy our services, or work with us as a partner or supplier. It also explains what happens to personal data in calls and records that our customers handle using VoiFlow. In those cases the customer, not VoiFlow, decides how the data is used.

1 Who we are

1.1VoiFlow is Legal company name, company number Company number, registered office Registered office address. For the processing described in this policy, we are the controller.

1.2You can contact us about privacy at Privacy contact email. Data protection officer: Name and contact details, or a statement that no data protection officer is appointed.

1.3We process personal data in line with the UK GDPR, the Data Protection Act 2018 and any other data protection law that applies to us.

2 Personal data our customers control

2.1Businesses use VoiFlow to make and receive calls with AI agents, keep customer records and run related workflows. Each business decides what personal data it collects through VoiFlow and how it uses it. We process that data on the business's behalf, as its processor or sub-processor, under a data processing agreement.

2.2If you spoke with an AI agent operated by a business that uses VoiFlow, or that business holds your details in VoiFlow, its own privacy notice explains how it uses your data. Please send requests about that data to the business. If you contact us instead, we will pass your request to the business where we can identify it.

2.3We keep limited records about those calls for our own purposes, such as session identifiers, times and durations used for billing, security and fraud prevention. Those records are covered by this policy.

3 What we collect and why

The table below sets out the personal data we collect, why we use it and the lawful basis we rely on under the UK GDPR.

Who Personal data Why we use it Lawful basis
Website visitors IP address, browser and device information, pages visited, and cookie data where section 4 lists cookies To operate and secure the website, and, if section 4 lists analytics cookies, to measure its use Legitimate interests in running a secure website; consent for any cookies that are not strictly necessary
People who contact us Name, business, role, contact details and the content of your message To respond to your enquiry and provide the information you ask for Legitimate interests in responding to business enquiries; steps before a contract only where you personally may contract with us
Customer and partner account users Name, business email, role, login details, account activity and support messages To provide and administer the account, authenticate users and give support Legitimate interests in administering our contract with your organisation; contract only where you personally are our customer
Billing contacts Name, contact details, billing address, invoices and payment records. Card details are handled by our payment processor, which may share limited details with us such as the card type and last four digits To charge for our services, issue invoices, collect payments and keep accounting records Legitimate interests in administering our contract with your organisation, or contract where you personally are our customer; legal obligation to keep tax and accounting records
Usage and security records Account, Workspace and session identifiers, call times and durations, telephone numbers involved in a call where needed for billing or abuse investigation, IP addresses and system logs. Never recordings, transcripts or other call content To measure and bill usage, prevent fraud and abuse, secure our services and investigate incidents Legitimate interests in accurate billing, security and fraud prevention; legal obligation where it applies
Business contacts receiving our updates Name, business email and your preferences To send news about our services Consent where the law requires it, otherwise legitimate interests in telling business contacts about our services. You can opt out at any time
Suppliers and partners Names, roles, business contact details and communications To manage our business relationships and contracts Legitimate interests in administering contracts with your organisation; contract only where you personally are the supplier or partner

3.1We collect personal data from you directly, from the organisation that sets up your account, and from our payment processor. We also collect some data automatically from your device when you visit our website, and from logs and usage records when you use our services.

3.2Where we need personal data to provide an account or a contract, we cannot provide it without that data. We will tell you when information is required.

3.3We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects for you.

4 Cookies

4.1Description of the cookies and similar technologies used on the VoiFlow website and app at publication, or a link to the cookie notice

4.2If we use cookies that are not strictly necessary, we do so only with your consent. You can withdraw consent at any time through Cookie settings link or privacy contact.

5 Who we share personal data with

5.1We share personal data with service providers that act for us, such as hosting, email, customer support, payment processing and accounting providers; with professional advisers; with authorities where the law requires it; with the organisation that manages your account; and with a buyer or successor if our business is sold or reorganised.

5.2A current list of the main service providers that process personal data for us is available at Link to the list, or the address to request it.

5.3We do not sell personal data.

6 International transfers

6.1Our service providers process personal data in Countries where the main service providers process personal data.

6.2Where a transfer of personal data from the UK is restricted, we rely on adequacy regulations or on safeguards approved under UK law, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for information about the safeguard used for a transfer.

7 How long we keep personal data

We keep personal data only for as long as we need it for the purposes above.

Record Retention period
Account user data While the account is open and 24 months after it closes
Invoices, payment and accounting records 6 years after the end of the financial year they relate to
Billing and security metadata about calls (usage and metering records) 24 months, or longer while a billing dispute is open
Security logs 12 months
Enquiries and business contact records 24 months after our last contact
Support communications 24 months after the case closes
Marketing opt-outs For as long as we need them to respect your choice

8 Your rights

8.1You have the right to ask for access to your personal data, and to ask us to correct, erase or restrict it. You can object to our use of it where we rely on legitimate interests, and you can object to direct marketing at any time. Where we rely on consent, you can withdraw it at any time without affecting earlier processing. You may also have the right to receive personal data you provided to us in a portable format.

8.2To exercise a right, contact us at the privacy email in section 1. We may need to confirm your identity. We respond within one month, which can be extended by up to two further months for complex or numerous requests, in which case we will tell you why.

9 Complaints

9.1If you are unhappy with how we have handled your personal data, please contact us first so that we can try to resolve it.

9.2You can also complain to the Information Commissioner's Office, the UK data protection regulator, through its website at ico.org.uk/make-a-complaint or on 0303 123 1113. If you live or work outside the UK, you may also complain to the data protection authority there.

10 Security

10.1We use technical and organisational measures appropriate to the risk to protect personal data, including access controls, encryption of data in transit over public networks and monitoring of our systems.

11 Children

11.1Our services are for businesses and are not directed at children. We do not knowingly collect children's personal data for our own purposes.

12 Changes to this policy

12.1We may update this policy. The effective date at the top shows when it was last changed. We will tell account holders about material changes before they take effect.