PRIVACY AND DATA PROTECTION POLICY
VOIZ.ES PLATFORM — B2B2C INTELLIGENT TELEPHONY WITH ARTIFICIAL INTELLIGENCE
1. WHO WE ARE
Yolanda Muñoz Bodeguero (hereinafter, "VOIZ.ES"), with Tax ID (NIF/CIF) 51084022X and registered address at C/ Camarena 244, 28047 Madrid, Spain, operates as the owner of the VOIZ.ES technology platform and acts as the Data Controller for personal data collected through this website.
In accordance with the nature of the conversational AI telephony services we provide, VOIZ.ES operates under two distinct legal capacities strictly defined by the GDPR:
- As Data Controller: With respect to the personal data of users browsing our corporate website (
voiz.es), requesting quotes or technical demonstrations, formalizing B2B service subscriptions, managing recurring billing via Stripe Billing, or maintaining commercial or support communications with our team. - As Data Processor (Art. 28 GDPR): With respect to voice interactions and personal data captured by Voice AI Agents on the telephone lines assigned to our corporate clients. In this scenario, the client company acts as the exclusive Data Controller, and VOIZ.ES processes the data solely on its behalf and pursuant to the documented instructions set forth in our Data Processing Agreement (DPA - Annex 1).
For any inquiries or requests concerning your privacy, you may contact our Data Protection Officer at: dpo@voiz.es.
2. DEFINITION OF PERSONAL DATA
"Personal Data" refers to any information relating to an identified or identifiable natural person (the "Data Subject"). This includes direct identifying details (name, surname, national identity document/tax number), contact information (email address, telephone number, physical or corporate postal address), online identifiers (IP address, session identifiers, or technical cookies), as well as any information voluntarily provided during commercial inquiries or real-time telephone interactions.
3. DATA COLLECTION AND LEGAL BASES FOR PROCESSING
3.1 Data collected on our platform
We may collect or receive your personal data through website contact forms, the digital subscription process for service plans, technical demonstration requests, or while browsing our website.
3.2 Purposes and Legal Bases for Processing
The processing of your personal data is grounded on the following legal bases set out in Article 6 of the GDPR:
| Purpose of Processing | Role of VOIZ.ES | Legal Basis (GDPR) |
|---|---|---|
| Handling requests for information, technical demonstrations, and commercial proposals submitted via the website. | Data Controller | Consent of the data subject (Art. 6(1)(a)) and performance of pre-contractual measures (Art. 6(1)(b)). |
| Execution of the B2B contractual relationship, platform provisioning, and technical support. | Data Controller | Performance of a contract (Art. 6(1)(b)). |
| Management of recurring monthly billing and electronic invoicing via Stripe Billing. | Data Controller | Performance of a contract (Art. 6(1)(b)) and compliance with legal tax obligations (Art. 6(1)(c)). |
| Operation of the Voice Agent (call handling, ephemeral real-time transcription, and lead routing). | Data Processor | Data Processing Agreement (DPA) on behalf of the Client (Art. 28 GDPR). |
| Network security, fraud prevention, and website infrastructure maintenance. | Data Controller | Legitimate interest of VOIZ.ES in safeguarding cybersecurity (Art. 6(1)(f)). |
4. CONVERSATIONAL AUDIT, SALES PSYCHOLOGY, AND PROFILING
In delivering services to corporate clients (Pro and Enterprise Plans), VOIZ.ES deploys conversational analysis systems based on natural language processing to audit call quality:
4.1 Semantic Nature (No Biometrics)
The evaluation of commercial methodologies (SPIN Selling, Cialdini principles, Sandler, NLP/PNL, or DISC communication styles) is executed exclusively on the transcribed text of the call. VOIZ does not use voice biometric data to identify or authenticate individuals participating in calls. The system does not conduct acoustic analysis of physiological emotions nor does it generate persistent psychological profiles of callers (in strict compliance with Arts. 9 and 22 of the GDPR).
4.2 Automated Decisions Without Legal Effects
Decisions made by the voice agent during a call (such as qualifying a lead based on stated budget or escalating the call to a human operator) do not produce binding legal effects or significantly affect the end user.
4.3 Escalation to Human Agents and Customer Service Compliance
VOIZ provides routing mechanisms to transfer calls to human personnel where this functionality has been contracted or enabled, facilitating our clients' compliance with applicable customer service regulations, including obligations arising under Spanish Law 10/2025, of December 26, on customer service.
4.4 Transparency in AI Interactions
In accordance with Regulation (EU) 2024/1689 (EU AI Act), Art. 50(1) — transparency obligations for AI systems interacting with natural persons, the voice agent identifies itself as an artificial intelligence system in the opening greeting of each call.
5. RECIPIENTS AND SUB-PROCESSORS
VOIZ.ES does not sell, rent, or trade personal data to third parties under any circumstances.
5.1 As Data Controller
Access is granted strictly to our authorized personnel bound by formal confidentiality agreements and to essential technology service providers necessary for commercial operations (web hosting, Stripe Billing secure payment infrastructure, and transactional email providers).
5.2 As Data Processor (AI Telephony Operations)
VOIZ utilizes specialized technology providers that intervene, depending on the contracted service tier, in orchestration, natural language processing, speech-to-text transcription, text-to-speech synthesis, telephony routing, cloud infrastructure, and security. VOIZ selects and audits these providers in compliance with applicable data protection regulations.
The functional categories of sub-processors that may intervene in the processing include:
- Foundational Large Language Models (LLM): Inference providers of foundational language models operating via enterprise APIs.
- Voice Orchestration and Real-Time Streaming: Low-latency conversational routing and stream management platforms.
- Transcription and Voice Synthesis Engines (STT / TTS): Real-time speech-to-text conversion and vocal synthesis providers.
- Segregated Databases and Cloud Infrastructure: Dedicated virtual private server (production VPS) storage connected via private encrypted tunnels.
Model Training Policy
The technology providers utilized by VOIZ apply their respective data processing terms. In the case of AI services accessed via enterprise API, data transmitted to these services is not used to train or fine-tune public foundation models where specified under their commercial enterprise terms.
Information on Sub-processors
VOIZ's public documentation details the categories and functions of providers that may intervene in data processing without unnecessarily exposing proprietary system architecture. Additional information regarding specific providers will be made available when required under applicable regulations, contractual obligations, or upon formal order by a competent supervisory authority. The complete list of sub-processors, detailing identification, function, and processing location, is available in the Data Processing Agreement (DPA — Annex 1) executed with each corporate client.
6. DATA RETENTION PERIODS
Personal data is retained only for the duration strictly necessary to fulfill the purpose for which it was collected or to comply with statutory legal requirements:
| Data Category | Retention Period | Erasure Criteria |
|---|---|---|
| Website inquiries and commercial communications. | Maximum of 2 years from the last recorded interaction. | Definitive deletion or upon withdrawal of consent. |
| Billing records and B2B client account data. | 6 years (statutory legal obligation). | Blocked pursuant to the Spanish Commercial Code and applicable tax regulations. |
| Persistent audio recordings. | Not generated. Call recording is disabled in the VOIZ system configuration. Call audio is processed in real time to provide conversational voice services and transcription. This processing does not entail the generation of a persistent audio recording. | Not applicable (no persistent audio storage is maintained). |
| Transcriptions and associated operational logs. | During the term of the contractual relationship, retained for the duration strictly necessary for service delivery, maintenance, support, security, and service evolution. Following contract termination, retained for a maximum period of 12 months, unless required for a longer duration to fulfill legal obligations or address liabilities arising from the service. | Legal blocking pursuant to Clause 7.6 of the DPA followed by irreversible erasure. VOIZ may retain versions, configurations, technical logs, and traceability metrics necessary to maintain, debug, restore, and evolve the contracted agents and services. |
| Aggregated sectoral patterns (Protocol N3). | Indefinite statistical retention. | Data is processed through a deterministic anonymization protocol that strips direct identifiers, generalizes or suppresses quasi-identifiers, and enforces a strict minimum aggregation threshold (k ≥ 20 conversations originating from at least 3 independent companies). Only aggregated statistical results are preserved. The output is evaluated against the identifiability criteria of Recital 26 of the GDPR; once it meets this threshold, it ceases to be personal data. See Technical Specification N3. |
7. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES (ART. 32 GDPR)
VOIZ.ES implements robust technical and organizational security measures to safeguard data integrity, confidentiality, and availability:
7.1 Recording Disabled
Persistent audio recording is disabled in the platform configuration. Audio streams are processed in real time (in volatile memory) strictly to facilitate live transcription and agent response generation, with no subsequent storage. This mitigates the risk of voice biometrics exposure.
7.2 Tenant Data Isolation
VOIZ enforces tenant isolation mechanisms adapted to the technical architecture of each service tier:
- Basic and Growth Plans: Data segregation is implemented through isolated individual resources and workflows per client (independent assistants, dedicated phone numbers, isolated automation flows, and segregated data sheets).
- Pro and Enterprise Plans: In multi-tenant PostgreSQL environments, Row-Level Security (RLS) policies are enforced to restrict access strictly to records matching each client's specific
cliente_id.
7.3 Encrypted Private Network
The production VPS communicates via an authenticated, encrypted WireGuard tunnel to VOIZ's private backend infrastructure. Traffic directed to protected resources is routed through this tunnel without exposing database ports or internal services to the public Internet.
7.4 Encryption in Transit and at Rest
All external endpoints operate over secure HTTPS / TLS 1.2+ protocols, with AES-256 encryption applied at rest for all persistent data repositories.
7.5 Segregation of Data Between Clients
Information specific to each corporate client remains segregated from that of other clients. VOIZ does not utilize identifiable or proprietary client data to train public models or access information across customer boundaries. Where data is utilized to generate market intelligence, the de-identification and aggregation protocols established under the N3 methodology are strictly applied beforehand.
8. INTERNATIONAL DATA TRANSFERS
When VOIZ engages technology providers located outside the European Economic Area and data processing entails an international data transfer, such transfer is carried out under a recognized legal mechanism pursuant to Chapter V of the GDPR.
For transfers to service providers established in the United States, VOIZ relies on entities certified under the EU-U.S. Data Privacy Framework where applicable. When not applicable, VOIZ executes the European Commission's Standard Contractual Clauses (SCCs) or applies another valid international transfer mechanism under the GDPR.
VOIZ does not perform international data transfers to any provider in the absence of a valid legal transfer instrument.
Data transfers to the United Kingdom are conducted pursuant to the adequacy decision adopted by the European Commission for as long as it remains in force.
9. DATA SUBJECT RIGHTS AND EXERCISE PROCEDURES
Under the GDPR and the Spanish LOPDGDD, you are entitled to exercise the following data protection rights:
- Access: Obtain confirmation as to whether we process your personal data and access the details of such processing.
- Rectification: Request the correction of inaccurate or incomplete personal data.
- Erasure ("Right to be Forgotten"): Request the deletion of your data when it is no longer necessary for the purposes for which it was collected.
- Restriction of Processing: Request the temporary restriction of processing in specific statutory circumstances.
- Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format (CSV/JSON).
- Objection: Object at any time to the processing of your data based on legitimate interest or for direct marketing purposes.
- Withdrawal of Consent: Withdraw previously granted consent at any time, without affecting the lawfulness of processing prior to withdrawal.
10. CONTACT CHANNELS AND SUPERVISORY AUTHORITY
Exercise of Rights and Data Protection Officer (DPO)
To exercise any of your statutory rights or submit questions regarding this Privacy Policy, you may contact our Data Protection Officer in writing via:
- Direct Email: dpo@voiz.es
- Postal Address: VOIZ.ES, C/ Camarena 244, 28047 Madrid, Spain.
You also have the right to lodge a formal complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD) via its official electronic portal (www.aepd.es) if you consider that the processing of your personal data infringes applicable data protection law.