Privacy Compliance

GDPR Compliance

Voxvaani is fully dedicated to safeguarding the privacy and data of EU residents in accordance with the General Data Protection Regulation.

Last Updated: June 13, 2026

1. GDPR Overview

The General Data Protection Regulation (GDPR) regulates how organizations gather, manage, and protect personal data belonging to individuals within the European Union (EU) and the European Economic Area (EEA).

At Voxvaani, privacy by design is incorporated into our voice engines, lead capture scrapers, and communication frameworks. We ensure that our systems maintain maximum compliance, integrity, and safety.

2. Processor vs. Controller

Under GDPR guidelines, responsibilities are split between **Data Controllers** and **Data Processors**:

  • Voxvaani as a Processor: When you upload contact CSVs, call registries, or lead logs, we process this personal data solely on your behalf (under your direction) to route campaigns, synthesize speech, or trigger WhatsApp messaging.
  • Voxvaani as a Controller: We act as a controller for basic user account registry data, such as your billing records, administrator emails, profile names, and portal settings.

3. Data Subject Rights

European residents can trigger several rights regarding their voice and contact records:

  • Access & Portability: Obtain details and structured exports of all conversation transcripts and contact attributes.
  • Rectification: Instantly fix or modify inaccurate phone records, names, or settings.
  • Erasure ("Right to be Forgotten"): Purge old call registries, scrapings, or billing items from our database clusters.
  • Object / Restrict Processing: Restrict AI model transient audio analysis or WhatsApp outbound triggers.

To submit requests, please email our compliance desk at dpo@voxvaani.com.

4. Third-party Subprocessors

Voxvaani utilizes third-party infrastructure entities to support database operations, payment processing, and core telecom routing channels:

EntityService ProvidedLocation
Supabase / AWSDatabase hosting and cloud compute clustersUnited States
StripePCI-compliant credit card processingUnited States
Deepgram / OpenAIReal-time transcription and voice generationUnited States
Indian Route GatewaysIndian region telecom call and SMS routingIndia

5. International Data Transfers

As Voxvaani cloud servers reside primarily in the United States, personal data collected from the EU/EEA is transferred to the US.

We guarantee the safety of these transfers by executing **Standard Contractual Clauses (SCCs)** approved by the European Commission, along with robust technical security measures.

6. Technical & Organizational Measures

To meet GDPR compliance specifications, Voxvaani implements top-tier structural security including:

  • **End-to-End TLS Encryption:** All API hooks and web dashboard traffic are encrypted in transit.
  • **AES-256 Storage Encryption:** Data stored at rest on DB clusters is fully protected.
  • **Automatic Data Purges:** Telecommunication logs are automatically pruned after 90 days.

7. Data Protection Officer (DPO)

We have designated a Data Protection Officer to supervise compliance queries, privacy audits, and rights requests:

Voxvaani DPO / Legal Office

100 Pine Street, Suite 2100

San Francisco, CA 94111