Privacy Policy
This Privacy Policy explains how Efferex Technologies Ltd and its operating brand Voxif (“Voxif”, “we”, “us”) collect, use, store, and share personal data when you use voxif.tech, app.voxif.tech, the Voxif API, or place, receive, or exchange messages through the Voxif platform (collectively the “Service”). It applies to: (a) account holders and team members who sign in to the dashboard; (b) visitors to our website; and (c) end users whose data is processed when our client businesses (“Customers”) place or receive voice calls, or send or receive WhatsApp messages, through Voxif. Where (c) applies, our Customer is the data controller and Voxif acts as a data processor.
1. Introduction and who we are
Voxif is a B2B software service that helps businesses automate customer conversations across voice calls and the WhatsApp Business Platform. Voxif is operated by Efferex Technologies Ltd, a United Kingdom-registered company. Contact details appear at the end of this policy. Full corporate details are available on request to legal@voxif.tech.
2. What we collect
We collect personal data in the following categories:
(a) Account data — when you create an account or log in: email, full name, hashed password, two-factor authentication state, organization name, billing details (handled by our payment processor), team membership, and IP addresses you sign in from.
(b) Service-operation data — when you operate voice agents or WhatsApp automation on behalf of your business: provider API keys (encrypted at rest with AES-256-GCM using your organization’s Data Encryption Key), SIP trunk credentials (same encryption), call metadata (phone numbers, durations, dispositions, latency metrics), call transcripts, call recordings if you enable them, WhatsApp message content and metadata processed on your Customer’s WhatsApp Business Account, knowledge-base documents you upload, contact lists you import, and webhook subscription endpoints.
(c) Technical telemetry — when you interact with the site or API: user-agent string, IP, timestamp, the routes you accessed, and error logs. No third-party advertising trackers are loaded on voxif.tech.
3. Legal basis for processing
- Performance of a contract — for account data and service-operation data we need to deliver the Service you subscribed to.
- Legitimate interests — for security, fraud prevention, abuse handling, aggregated service-quality metrics, and product improvement that does not involve training AI on your data.
- Legal obligation — when we must respond to a lawful subpoena, court order, or regulatory request.
- Consent — for non-essential analytics or marketing communications. You can withdraw consent at any time.
4. How we use data
We use personal data to operate, secure, bill, and improve the Service:
- Authenticate you and your teammates and prevent unauthorized access.
- Route voice calls through the providers you have configured (your STT/LLM/TTS keys, your SIP trunk).
- Send and receive WhatsApp messages on behalf of your Customer’s WhatsApp Business Account, per the automation your Customer configures.
- Persist call logs, transcripts, message threads, contacts, and bookings so you can review and act on them in the dashboard.
- Send transactional email (verification, password reset, delivery confirmations, quota alerts).
- Compute aggregated, anonymized service metrics (call counts, latency percentiles, error rates) for engineering and operations purposes.
- Detect and respond to abuse, fraud, and security incidents.
- Comply with applicable laws and respond to lawful requests.
We do not sell personal data. We do not use your transcripts, prompts, contact lists, recordings, or WhatsApp message content to train AI models — ours or anyone else’s. We do not run third-party advertising trackers on voxif.tech.
5. WhatsApp Business Platform data
We access WhatsApp Business Platform data only to provide the messaging service our client businesses have engaged us to run on their own WhatsApp Business Account. We do not use this data for advertising, resale, model training, or any purpose beyond delivering that service.
Specifically: message content, phone numbers, contact profiles, media, and any other data flowing through the WhatsApp Business Platform on a Customer’s WhatsApp Business Account are processed solely to deliver the automation that Customer configures. There is no cross-Customer analytics, no third-party ad sharing, and no model training on this data. The Customer is the controller of that data; Voxif is a processor acting on the Customer’s instructions.
Voxif complies with the WhatsApp Business Messaging Policy, the WhatsApp Business Policy, and Meta’s Platform Terms. Customers are responsible for obtaining the end-user opt-ins their jurisdiction and category require, honoring opt-outs immediately, and staying within permitted message-template categories.
6. Sub-processors
We use the following sub-processors, each processing only the categories needed for the function noted. Customer-side BYOK providers you configure (your AI providers, your SIP carrier) act as controllers of your usage on their own platforms, with your traffic and credentials flowing directly between you and them through Voxif as a conduit.
- Microsoft Azure — compute, storage, networking. Default region: UAE North; other regions available for enterprise contracts. TLS 1.2+ in transit; encrypted at rest.
- Cloudflare — DNS, CDN, DDoS protection, WAF.
- LiveKit (self-hosted) — real-time media routing for voice calls.
- Telnyx or another SIP carrier you select — PSTN telephony.
- Meta Platforms, Inc. — WhatsApp Business Platform (only for Customers using the WhatsApp integration).
- Brevo — transactional email delivery.
- Your chosen AI providers — STT, LLM, TTS.
We maintain a current list of sub-processors and will give at least 30 days’ notice via the dashboard before adding a new one.
7. Data retention
- Account data — for the life of the account, then 30 days after termination for export, then deletion.
- Call transcripts and WhatsApp message threads — default 90 days, configurable per Customer.
- Call recordings — only retained if you explicitly enable recording; default 30 days.
- Encrypted provider keys — until you rotate or delete them; old keys destroyed within 7 days of rotation.
- Billing records — 7 years to comply with accounting and tax law.
- Security logs — 12 months.
- Aggregated, anonymized service metrics — indefinitely.
8. Security
- Provider API keys, SIP credentials, and other secrets encrypted at rest using AES-256-GCM with a per-organization Data Encryption Key (DEK).
- TLS 1.2+ on all transport, with HSTS and modern cipher suites.
- Argon2id password hashing; passwords never logged.
- HMAC-SHA256 signing on outbound webhooks with replay protection.
- JWT access tokens with short TTL; refresh tokens revocable per-session.
- Rate limiting and bot-mitigation at the edge.
- Production deployment in a hardened virtual private cloud; the database is not publicly addressable.
9. Data subject rights
Depending on where you live, you may have the following rights:
- Access, correction, deletion, portability, restriction, and the right to withdraw consent where processing is based on consent.
- Complain to a supervisory authority (EU: your national DPA; UK: the ICO).
To exercise any of these rights, email privacy@voxif.tech. We respond within 30 days. If you are an end user (call recipient or WhatsApp contact) and not a Voxif Customer, contact the Customer who initiated the conversation — they are the data controller for your data. If they cannot help, see our Data Deletion page.
10. International transfers
Default data residency for new accounts is Azure UAE North. Enterprise Customers may request EU or US residency, subject to a signed agreement. Cross-border transfers, where they occur, rely on Standard Contractual Clauses (SCCs) or an equivalent safeguard.
11. Children
The Service is not directed at children under 16. If we learn we have collected personal data from a child under 16 without parental consent, we will delete it promptly.
12. Changes to this policy
We will update this Privacy Policy from time to time. Material changes will be announced via the dashboard and (for enterprise customers) by email at least 30 days before they take effect.
13. Contact
Privacy / GDPR / CCPA: privacy@voxif.tech.
Security: security@voxif.tech.
Data controller: Efferex Technologies Ltd, United Kingdom.