VOIZ.ES — B2B AI Telephony

PRIVACY AND DATA PROTECTION POLICY

VOIZ.ES PLATFORM — B2B2C INTELLIGENT TELEPHONY WITH ARTIFICIAL INTELLIGENCE

Platform: VOIZ.ES · B2B2C Intelligent Telephony with AI (https://voiz.es/en/)
Legal Framework: Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD)
Last Updated: August 2026
Data Protection Officer (DPO): dpo@voiz.es

1. WHO WE ARE

Yolanda Muñoz Bodeguero (hereinafter, "VOIZ.ES"), with Tax ID (NIF/CIF) 51084022X and registered address at C/ Camarena 244, 28047 Madrid, Spain, operates as the owner of the VOIZ.ES technology platform and acts as the Data Controller for personal data collected through this website.

In accordance with the nature of the conversational AI telephony services we provide, VOIZ.ES operates under two distinct legal capacities strictly defined by the GDPR:

For any inquiries or requests concerning your privacy, you may contact our Data Protection Officer at: dpo@voiz.es.

2. DEFINITION OF PERSONAL DATA

"Personal Data" refers to any information relating to an identified or identifiable natural person (the "Data Subject"). This includes direct identifying details (name, surname, national identity document/tax number), contact information (email address, telephone number, physical or corporate postal address), online identifiers (IP address, session identifiers, or technical cookies), as well as any information voluntarily provided during commercial inquiries or real-time telephone interactions.

3. DATA COLLECTION AND LEGAL BASES FOR PROCESSING

3.1 Data collected on our platform

We may collect or receive your personal data through website contact forms, the digital subscription process for service plans, technical demonstration requests, or while browsing our website.

3.2 Purposes and Legal Bases for Processing

The processing of your personal data is grounded on the following legal bases set out in Article 6 of the GDPR:

Purpose of Processing Role of VOIZ.ES Legal Basis (GDPR)
Handling requests for information, technical demonstrations, and commercial proposals submitted via the website. Data Controller Consent of the data subject (Art. 6(1)(a)) and performance of pre-contractual measures (Art. 6(1)(b)).
Execution of the B2B contractual relationship, platform provisioning, and technical support. Data Controller Performance of a contract (Art. 6(1)(b)).
Management of recurring monthly billing and electronic invoicing via Stripe Billing. Data Controller Performance of a contract (Art. 6(1)(b)) and compliance with legal tax obligations (Art. 6(1)(c)).
Operation of the Voice Agent (call handling, ephemeral real-time transcription, and lead routing). Data Processor Data Processing Agreement (DPA) on behalf of the Client (Art. 28 GDPR).
Network security, fraud prevention, and website infrastructure maintenance. Data Controller Legitimate interest of VOIZ.ES in safeguarding cybersecurity (Art. 6(1)(f)).

4. CONVERSATIONAL AUDIT, SALES PSYCHOLOGY, AND PROFILING

In delivering services to corporate clients (Pro and Enterprise Plans), VOIZ.ES deploys conversational analysis systems based on natural language processing to audit call quality:

4.1 Semantic Nature (No Biometrics)

The evaluation of commercial methodologies (SPIN Selling, Cialdini principles, Sandler, NLP/PNL, or DISC communication styles) is executed exclusively on the transcribed text of the call. VOIZ does not use voice biometric data to identify or authenticate individuals participating in calls. The system does not conduct acoustic analysis of physiological emotions nor does it generate persistent psychological profiles of callers (in strict compliance with Arts. 9 and 22 of the GDPR).

4.2 Automated Decisions Without Legal Effects

Decisions made by the voice agent during a call (such as qualifying a lead based on stated budget or escalating the call to a human operator) do not produce binding legal effects or significantly affect the end user.

4.3 Escalation to Human Agents and Customer Service Compliance

VOIZ provides routing mechanisms to transfer calls to human personnel where this functionality has been contracted or enabled, facilitating our clients' compliance with applicable customer service regulations, including obligations arising under Spanish Law 10/2025, of December 26, on customer service.

4.4 Transparency in AI Interactions

In accordance with Regulation (EU) 2024/1689 (EU AI Act), Art. 50(1) — transparency obligations for AI systems interacting with natural persons, the voice agent identifies itself as an artificial intelligence system in the opening greeting of each call.

5. RECIPIENTS AND SUB-PROCESSORS

VOIZ.ES does not sell, rent, or trade personal data to third parties under any circumstances.

5.1 As Data Controller

Access is granted strictly to our authorized personnel bound by formal confidentiality agreements and to essential technology service providers necessary for commercial operations (web hosting, Stripe Billing secure payment infrastructure, and transactional email providers).

5.2 As Data Processor (AI Telephony Operations)

VOIZ utilizes specialized technology providers that intervene, depending on the contracted service tier, in orchestration, natural language processing, speech-to-text transcription, text-to-speech synthesis, telephony routing, cloud infrastructure, and security. VOIZ selects and audits these providers in compliance with applicable data protection regulations.

The functional categories of sub-processors that may intervene in the processing include:

Model Training Policy

The technology providers utilized by VOIZ apply their respective data processing terms. In the case of AI services accessed via enterprise API, data transmitted to these services is not used to train or fine-tune public foundation models where specified under their commercial enterprise terms.

Information on Sub-processors

VOIZ's public documentation details the categories and functions of providers that may intervene in data processing without unnecessarily exposing proprietary system architecture. Additional information regarding specific providers will be made available when required under applicable regulations, contractual obligations, or upon formal order by a competent supervisory authority. The complete list of sub-processors, detailing identification, function, and processing location, is available in the Data Processing Agreement (DPA — Annex 1) executed with each corporate client.

6. DATA RETENTION PERIODS

Personal data is retained only for the duration strictly necessary to fulfill the purpose for which it was collected or to comply with statutory legal requirements:

Data Category Retention Period Erasure Criteria
Website inquiries and commercial communications. Maximum of 2 years from the last recorded interaction. Definitive deletion or upon withdrawal of consent.
Billing records and B2B client account data. 6 years (statutory legal obligation). Blocked pursuant to the Spanish Commercial Code and applicable tax regulations.
Persistent audio recordings. Not generated. Call recording is disabled in the VOIZ system configuration. Call audio is processed in real time to provide conversational voice services and transcription. This processing does not entail the generation of a persistent audio recording. Not applicable (no persistent audio storage is maintained).
Transcriptions and associated operational logs. During the term of the contractual relationship, retained for the duration strictly necessary for service delivery, maintenance, support, security, and service evolution. Following contract termination, retained for a maximum period of 12 months, unless required for a longer duration to fulfill legal obligations or address liabilities arising from the service. Legal blocking pursuant to Clause 7.6 of the DPA followed by irreversible erasure. VOIZ may retain versions, configurations, technical logs, and traceability metrics necessary to maintain, debug, restore, and evolve the contracted agents and services.
Aggregated sectoral patterns (Protocol N3). Indefinite statistical retention. Data is processed through a deterministic anonymization protocol that strips direct identifiers, generalizes or suppresses quasi-identifiers, and enforces a strict minimum aggregation threshold (k ≥ 20 conversations originating from at least 3 independent companies). Only aggregated statistical results are preserved. The output is evaluated against the identifiability criteria of Recital 26 of the GDPR; once it meets this threshold, it ceases to be personal data. See Technical Specification N3.

7. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES (ART. 32 GDPR)

VOIZ.ES implements robust technical and organizational security measures to safeguard data integrity, confidentiality, and availability:

7.1 Recording Disabled

Persistent audio recording is disabled in the platform configuration. Audio streams are processed in real time (in volatile memory) strictly to facilitate live transcription and agent response generation, with no subsequent storage. This mitigates the risk of voice biometrics exposure.

7.2 Tenant Data Isolation

VOIZ enforces tenant isolation mechanisms adapted to the technical architecture of each service tier:

7.3 Encrypted Private Network

The production VPS communicates via an authenticated, encrypted WireGuard tunnel to VOIZ's private backend infrastructure. Traffic directed to protected resources is routed through this tunnel without exposing database ports or internal services to the public Internet.

7.4 Encryption in Transit and at Rest

All external endpoints operate over secure HTTPS / TLS 1.2+ protocols, with AES-256 encryption applied at rest for all persistent data repositories.

7.5 Segregation of Data Between Clients

Information specific to each corporate client remains segregated from that of other clients. VOIZ does not utilize identifiable or proprietary client data to train public models or access information across customer boundaries. Where data is utilized to generate market intelligence, the de-identification and aggregation protocols established under the N3 methodology are strictly applied beforehand.

8. INTERNATIONAL DATA TRANSFERS

When VOIZ engages technology providers located outside the European Economic Area and data processing entails an international data transfer, such transfer is carried out under a recognized legal mechanism pursuant to Chapter V of the GDPR.

For transfers to service providers established in the United States, VOIZ relies on entities certified under the EU-U.S. Data Privacy Framework where applicable. When not applicable, VOIZ executes the European Commission's Standard Contractual Clauses (SCCs) or applies another valid international transfer mechanism under the GDPR.

VOIZ does not perform international data transfers to any provider in the absence of a valid legal transfer instrument.

Data transfers to the United Kingdom are conducted pursuant to the adequacy decision adopted by the European Commission for as long as it remains in force.

9. DATA SUBJECT RIGHTS AND EXERCISE PROCEDURES

Under the GDPR and the Spanish LOPDGDD, you are entitled to exercise the following data protection rights:

10. CONTACT CHANNELS AND SUPERVISORY AUTHORITY

Exercise of Rights and Data Protection Officer (DPO)

To exercise any of your statutory rights or submit questions regarding this Privacy Policy, you may contact our Data Protection Officer in writing via:

You also have the right to lodge a formal complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD) via its official electronic portal (www.aepd.es) if you consider that the processing of your personal data infringes applicable data protection law.