Privacy policy

Vox Front AI provides AI phone answering and appointment booking for service businesses. This policy explains how we process, secure, and handle personal data in connection with that service.

Last updated · August 14, 2026

01

Who we are & our role

For call and booking data handled on behalf of the businesses that use Vox Front AI, we act as a Data Processor under the General Data Protection Regulation (GDPR). Our customers — the businesses whose phones we answer — are the Data Controllers. They decide why and how their callers' data is used, and we process it on their documented instructions.

For our own account, billing, and admin-user data, Vox Front AI acts as a Data Controller in the ordinary sense.

If you are a business using Vox Front AI, you are responsible for the lawful basis you rely on to process your callers' data and for any notices required under applicable law. A Data Processing Agreement is available on request.

02

What data we process

Account information. When a business signs up, we collect the account holder's name, business name, email address, phone number, and dashboard login credentials.

Call and booking data. We process call transcripts, structured call summaries, caller-provided details such as name, phone number, and appointment information, and the resulting booking records. Transcripts are scanned and sensitive identifiers — card numbers, Social Security numbers, phone numbers — are redacted before storage. Call audio itself is handled by our voice AI infrastructure provider and is not separately stored by Vox Front AI.

Service usage and technical data. We log dashboard and API activity to keep the service reliable, along with IP addresses and diagnostic logs used for troubleshooting.

03

How we use data

Service provision. We process account, call, and booking data to answer calls, check availability, and complete bookings on a business's behalf.

AI processing. Calls are processed by our voice platform to understand the caller and generate a response, and by our knowledge-base search to answer from the documents a business has uploaded. We do not sell call data, and we do not share it with third parties for their own purposes.

Support. We use account and service data to help configure a business's agent and resolve issues.

Legal obligations. We may process or disclose data where required to comply with applicable law or to enforce our Terms of Use.

04

Data sharing & sub-processors

We use the following categories of sub-processor to operate the service:

  • Voice AI infrastructure provider — speech recognition, response generation, text-to-speech, and telephony.
  • Calendar and scheduling integration providers — used to check availability and write bookings you authorize.
  • Database hosting provider.
  • Cloud storage and application hosting provider.
  • Transactional email delivery provider.

Where a sub-processor operates outside the UK or EEA, we take steps to ensure appropriate safeguards are in place. A full sub-processor list is available on request.

If Vox Front AI is involved in a merger, acquisition, or asset sale, customer data may transfer as part of that transaction, subject to the same protections described in this policy.

We never sell, rent, or trade personal data.

05

Data security

Personal data, including call transcripts, is encrypted in transit (TLS 1.2+) and at rest. Integration credentials are encrypted at the application layer before storage.

Access to the dashboard and admin functions requires authentication, and administrative access is role-based.

06

Data retention

Call transcripts and summaries are currently retained for as long as an account remains active. We do not yet offer an automatic, configurable deletion window — if you need data deleted sooner, contact us and we will delete it manually within 30 days.

Account information is retained while an account is active, and for a limited period after as required by law, such as financial recordkeeping.

07

Your rights

If you are a caller and want to exercise a data protection right — access, correction, deletion, restriction, portability, or objection — the business you called is generally the right first contact, since it controls how your data is used. You can also contact us directly and we will assist or forward your request.

California residents have the right to know what personal information we process, to request deletion, and to opt out of the sale of personal information — which we do not do — without discrimination for exercising these rights.

We do not claim blanket "HIPAA compliance," which is not a certification that exists. Medical and dental practices that need a Business Associate Agreement should contact us directly, and we will confirm exactly where things stand for that deployment.

Questions about this policy

If you have questions or want to exercise a data right, contact us:

[email protected]

If you are based in the UK or EU, you may also lodge a complaint with your local data protection authority. We will notify customers of material changes to this policy by email or via the dashboard.