Privacy Policy
Voxmith
|
Version 1.0
|
Last updated: 11 September 2026
VoxMith ("we", "our" or "us") provides product analytics for conversational AI agents. This Privacy Policy explains what personal data we collect when you visit our website and use our services, how we use it, who we share it with, and what rights you have.
By using our services you confirm you have read and understood this policy. If you do not agree with it, please do not use our services.
1. Information we collect
Personal data you give us
Your name, work email address, phone number, company name, job title and billing details when you create an account, contact us, or subscribe. We ask for the minimum we need and we do not require sensitive personal data to open an account.
Usage data
How you interact with our product and website: IP address, browser type, pages visited, features used, time spent, and approximate location derived from your IP address.
Cookies
Essential cookies to keep you signed in and keep the site secure, and analytics cookies to understand which pages are useful. We do not use advertising cookies. You can manage cookies through your browser settings, though the product will not work properly without the essential ones.
Customer conversation data
If you are a customer, our product analyses conversations between your AI agents and the people who contact you. This can include transcripts, recordings, conversation metadata and tool activity. You decide what is sent to us and for how long we keep it. See the next section, which sets out a different set of rules for this data.
2. Conversation data belongs to our customers, not to us
This is the most important section for anyone evaluating us, so it is short and direct.
For conversation data, our customer is the controller and we are the processor. We process it only on our customer's documented instructions and only to provide the service they bought: analysing conversations, producing metrics, finding problems and helping fix them.
We do not train, fine-tune or run reinforcement learning on customer conversation data. We do not pool one customer's data with another's. Any model we tune for a customer is trained on their data alone and serves only them. This extends to the providers we work with, who are contracted under no-training or zero-retention terms.
Personal data in conversations is detected and removed before storage by default, and customers can widen that further or send us metadata only.
If you are a person whose conversation was analysed, we have no direct relationship with you and cannot act on your data without our customer's authority. Contact the company you originally spoke to. If you cannot reach them, email us at the address at the end of this policy and we will pass your request on.
3. How we use your information
To provide, maintain and secure our services.
To set up and administer your account, and to bill you.
To answer your questions and provide support.
To tell you about changes to our services.
To understand how our product is used in aggregate so we can improve it.
To detect, prevent and fix technical problems, fraud and abuse.
To send you product updates and marketing, where you have agreed to receive them. You can unsubscribe at any time and it will not affect your service.
4. What we do not do
We do not sell or rent your personal data to anyone.
We do not share personal data for advertising.
We do not use customer conversation data to train models or to build features for other customers.
We do not use vague language such as "to improve the Services" as a basis for training on your data. If we ever wanted to do something not described here, we would ask you first.
5. Who we share it with
Service providers
We use third parties to run our business, including cloud hosting, model and speech processing providers, analytics, error monitoring and payment processing. They may access personal data only to perform work on our behalf and are contractually prohibited from using it for anything else. A current list of the providers that touch customer conversation data is available on request.
Legal reasons
We may disclose personal data where we are legally required to, or in response to a valid request from a public authority.
Business transfers
If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction. We will tell you before your data becomes subject to a different privacy policy.
We will not share your personal data with anyone else without your consent, unless the law requires it.
6. Where your data is stored
We store and process data in the region agreed with you. Where personal data is transferred outside India, we do so in line with the Digital Personal Data Protection Act 2023 and only to territories permitted under it. For customers in the European Economic Area and the United Kingdom, transfers are covered by Standard Contractual Clauses and the UK International Data Transfer Addendum, which form part of our Data Processing Addendum. That addendum is available on request.
7. Security
We encrypt data in transit and at rest, restrict access to the people who need it, log administrative and data access, isolate each customer's data, keep encrypted backups, and run security reviews. Staff access to customer conversation data requires a documented reason and is logged.
If a personal data breach affects you, we will notify you without undue delay and in any case within 72 hours of becoming aware of it.
No method of transmission or storage is completely secure, so while we use appropriate measures we cannot guarantee absolute security.
8. How long we keep it
We keep personal data only as long as we need it for the purposes in this policy, or as long as the law requires. Account data is kept while your account is open and for a reasonable period afterwards. Audio recordings, transcripts and derived metrics are kept for the retention period each customer sets, and customers can delete any of it at any time.
When you close your account we delete or anonymise your data within 30 days, unless you ask in writing for longer or we are required to keep it.
9. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time. Withdrawing consent does not affect processing we did before you withdrew it.
You also have the right to complain to your data protection authority. In California, you may request the categories and specific pieces of personal information we hold, request deletion and correction, and we will never treat you differently for asking.
To exercise any of these, email us. We may need to verify who you are first. We respond within 30 days and we do not charge for reasonable requests.
For conversation data we process on a customer's behalf, requests go to that customer.
10. Children
Our services are for businesses and are not directed at children. We do not knowingly collect personal data from children under 13. If your AI agents speak with minors, tell us before you connect them so we can agree the right terms first.
11. Changes to this policy
We may update this policy. The version number and effective date at the top tell you when it last changed, and we review it at least every six months whether or not anything has changed. For material changes affecting customer conversation data we give customers 30 days' notice by email before they take effect.
12. Contact us
For privacy questions, data requests, security questionnaires, our Data Processing Addendum or a Business Associate Agreement, email manvendra.singh@voxmith.com. It reaches a person, not a queue, and we respond within 30 days.
