Skip to main content
Back to home

Privacy Policy

Effective date: 2026-06-25

Last updated: 2026-06-25

This Privacy Policy explains how Voxif Technologies (Private) Limited (“Voxif”, “we”, “us”) collects, uses, stores, and shares personal data when you use voxif.tech, app.voxif.tech, the Voxif API, or place or receive phone calls through the Voxif platform (collectively the “Service”). It applies to: (a) account holders and their team members who sign in to the dashboard; (b) visitors to our website; and (c) end users (call recipients) whose data is processed when our Customers place or receive calls. Where (c) applies, our Customer is the data controller and Voxif acts as a data processor under their Data Processing Agreement.

1. What we collect

We collect personal data in three categories:

(a) Account data — when you create an account or log in: email, full name, hashed password, two-factor authentication state, organization name, billing details (handled by our payment processor), team membership, and IP addresses you sign in from.

(b) Service-operation data — when you operate voice agents: provider API keys (encrypted at rest with AES-256-GCM using your organization’s Data Encryption Key), SIP trunk credentials (same encryption), call metadata (phone numbers, durations, dispositions, latency metrics), call transcripts, call recordings if you enable them, knowledge-base documents you upload, contact lists you import, and webhook subscription endpoints.

(c) Technical telemetry — when you interact with the site or API: user-agent string, IP, timestamp, the routes you accessed, and error logs. No third-party advertising trackers are loaded on voxif.tech.

2. Why we collect it (lawful bases under GDPR)

Our lawful bases for processing are:

3. How we use it

We use personal data to operate, secure, bill, and improve the Service:

We do not sell personal data. We do not use your transcripts, prompts, contact lists, or recordings to train AI models — ours or anyone else’s. We do not run third-party advertising trackers on voxif.tech.

4. Sub-processors

We use the following sub-processors. Each is listed with the data category they process. Customer-side BYOK providers (OpenAI, Deepgram, ElevenLabs, your SIP carrier) are controllers of their own usage because your traffic and credentials flow directly between you and them through Voxif as a conduit.

We maintain a current list of sub-processors and will give at least 30 days’ notice via the dashboard before adding a new one. Enterprise customers under a signed DPA receive direct email notice.

5. Where data lives

Default region for new accounts is United States (Oracle US-East, Ashburn). Enterprise customers may request EU residency (Oracle Frankfurt) or Pakistan residency, subject to a signed DPA. Encrypted backups are stored in the same region as the primary data. Cross-border transfers, where they occur, rely on Standard Contractual Clauses (SCCs) and our DPA.

6. How long we keep it

Default retention windows. Enterprise customers can shorten any of these by contract.

7. Security

We apply commercially reasonable safeguards:

8. Breach notification

If we become aware of a personal-data breach affecting your account or data, we will notify you without undue delay and in any case within 72 hours of confirming the breach, by email to your account’s primary contact and via the in-product banner. Our notice will describe (to the extent then known) the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the steps we have taken or propose to take to mitigate it.

9. Your rights

Depending on where you live, you have some or all of the following rights:

To exercise any of these rights, email privacy@voxif.tech with the request and the email address on your Voxif account. We will respond within 30 days. If you are an end user (call recipient) and not a Voxif Customer, contact the Customer who placed the call — they are the data controller for your data.

10. California residents (CCPA / CPRA)

California residents have the rights described in Section 9 plus the right to know which categories of personal information we have collected, the sources, the business purposes, and any third parties with whom we have shared it. Voxif does not sell personal information and does not share personal information for cross-context behavioral advertising. To exercise CCPA rights, email privacy@voxif.tech. You may also designate an authorized agent.

11. Children

The Service is not directed at children under 16. If we learn we have collected personal data from a child under 16 without parental consent, we will delete it promptly. Contact privacy@voxif.tech if you believe a child has provided us data.

12. Cookies and similar technologies

voxif.tech uses strictly-necessary cookies for session, authentication, and CSRF protection. app.voxif.tech additionally uses local storage to persist UI preferences (active campaign, sidebar state) on your device. We do not run third-party advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings; signing in to the dashboard will not work if you block all cookies.

13. Changes

We will update this Privacy Policy from time to time. Material changes will be announced via the dashboard and (for enterprise customers) by email at least 30 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

14. Contact

Privacy / GDPR / CCPA: privacy@voxif.tech.
Security: security@voxif.tech.
Mailing address: Voxif Technologies (Private) Limited, Karachi, Pakistan. We will publish a full registered-office address as soon as our EU and US registered agents are appointed.