Law Enforcement Response Policy
This policy explains how Voxif Technologies (Private) Limitedresponds to legal requests from law-enforcement agencies, courts, and other government authorities. Our goal is to comply with lawful requests promptly while protecting the rights, data, and reasonable expectations of our Customers and the end users of their voice agents.
1. Who we are
Voxif is incorporated in Pakistan and serves Customers globally. We are not a telecommunications carrier and do not directly originate or terminate phone calls on the public switched telephone network — our Customers bring their own SIP carrier (typically Telnyx, Twilio, Plivo, or Bandwidth). If your request is about a call placed or received by a particular phone number, the carrier may have more direct data than Voxif.
2. What we can produce
On a valid request and within the limits of applicable law, we may produce:
- Account-holder data — the email and any contact details on the Voxif account, the IP addresses used to sign in, two-factor authentication state, and the billing entity (where stored).
- Call metadata — for calls placed or received via Voxif: timestamps, source and destination phone numbers, durations, dispositions, the agent template used.
- Call transcripts — if still within the Customer’s retention window (default 30 days; can be longer or shorter per contract).
- Call recordings — only if the Customer enabled recording and the recording is still within retention.
- Contact / lead data — the contact rows attached to the Customer’s account.
- Webhook delivery logs — where the request is investigating a downstream system.
We do not have access to:
- The plaintext of Customer-supplied provider API keys (OpenAI, Deepgram, ElevenLabs, etc.) — these are stored encrypted with AES-256-GCM under a per-organization key. We can confirm a key exists but cannot decrypt it for the requester.
- Raw audio frames as they pass between caller, LiveKit, and the Customer’s AI providers — we do not retain those.
- The underlying provider account data at OpenAI, Deepgram, ElevenLabs, or the SIP carrier — you must request from them directly.
- Bank account or credit-card data — held by our payment processor; we hold only billing metadata.
3. What we require
We respond only to legal process that is valid in our jurisdiction (Pakistan) or that comes through proper Mutual Legal Assistance Treaty (MLAT) channels or letters rogatory. Specifically:
- A subpoena, court order, search warrant, or equivalent legal instrument issued by a court of competent jurisdiction.
- A specific, narrow scope identifying the account, the data category, and the time window. We do not respond to fishing expeditions.
- The identity and contact information of the requesting officer and agency, on official letterhead.
- A statement of the legal basis for the request.
Requests from outside Pakistan must follow MLAT or letters-rogatory procedure unless the request relates to an immediate threat to life (see Section 5). Direct subpoenas from foreign courts are reviewed for enforceability before any data is produced.
4. Notice to the Customer
We will give the Customer prior written notice of any law-enforcement request that affects their account, so they have an opportunity to seek protective relief, unless:
- The legal process or applicable law prohibits us from giving notice (e.g. a non-disclosure order);
- We have a reasonable basis to believe that notice would create a risk of injury or death to a person, destruction of evidence, or obstruction of justice;
- The Customer’s account is itself the apparent target of a credible fraud or abuse investigation.
Where we are prohibited from giving notice, we will provide it as soon as we are permitted to.
5. Emergency requests
For requests involving an imminent threat of death or serious bodily harm to a person (e.g. a kidnapping, suicide threat, active-shooter situation), we will respond as quickly as we can on receipt of a sworn statement from a senior law-enforcement official describing the emergency and the data needed to address it. Emergency production is limited to the specific data necessary to address the emergency. Submit emergency requests to legal@voxif.tech with the subject line beginning “EMERGENCY DISCLOSURE REQUEST”.
6. How to send a request
Email scanned PDFs of legal process to legal@voxif.tech. We do not accept service of process by fax. We acknowledge receipt within 5 business days (sooner for emergencies).
Postal address for written service:
Voxif Technologies (Private) Limited
Attn: Legal — Law Enforcement Requests
Karachi, Pakistan
(A full registered-office street address is registered with our governing authority; please contact us by email to confirm before sending postal mail.)
7. Costs
We may charge reasonable costs for the time required to respond to requests, where permitted by applicable law (e.g. US 18 U.S.C. § 2706 reimbursement rules where applicable via MLAT).
8. Customers’ own end users
If law enforcement is investigating an end user who was called by one of our Customers’ voice agents (rather than investigating the Customer themselves), the appropriate target of the request is usually the Customer (who is the data controller for end-user data) and the SIP carrier (which has carrier-level call records). Voxif will refer such requests upstream where appropriate.
9. Transparency
We intend to publish an annual transparency report summarizing the number of law-enforcement requests received, the categories of data requested, and the proportion produced, withheld, or challenged. The first report will be issued 12 months after we receive our first request.
10. Contact
Law-enforcement requests: legal@voxif.tech.
Emergency disclosure: legal@voxif.tech (subject begins “EMERGENCY DISCLOSURE REQUEST”).
General legal: legal@voxif.tech.