Trust Center & Regulatory Compliance

Privacy by design: your conversations, your rules

At VOIZ, privacy is not an added layer—it is the foundation of our engineering. We safeguard every phone call under the strictest European regulatory framework.

GDPR & LOPDGDD Compliant
EU AI Act (Art. 50)
Proprietary infrastructure hosted in the EU
Architectural Guarantees

Three fundamental principles of data protection

How we safeguard every phone call from the very first second:

Guarantee 01

Recording Disabled

We do not store audio recordings. Call audio is processed in real time to enable transcription and voice service delivery, but no persistent recording of the call is generated or retained.

Guarantee 02

Protection through de-identification and aggregation

Level 1 Immediate: Automatic de-identification of names, phone numbers, emails, or amounts prior to any analysis.

Level 2 Sector-level: Patterns used for industry intelligence are generated through a deterministic de-identification and aggregation protocol (N3) applied to transcripts. This process removes direct and indirect identifiers that could reasonably link the information to a specific individual, company, or conversation, consolidating solely aggregate industry-level patterns (k ≥ 20 conversations from at least 3 distinct companies).

Guarantee 03

Limited transcript retention

While the contractual relationship with the client remains active, VOIZ retains transcripts and logs necessary to deliver, maintain, audit, and technically enhance the service. Once the contract ends, transcripts are kept for a maximum period of 12 months and subsequently deleted in accordance with VOIZ deletion procedures.

Regulatory Framework

Legal compliance in the European Union

Engineered to pass any enterprise corporate legal and security audit:

GDPR & LOPDGDD

Binding DPA

Data Processing Agreement (DPA, Art. 28 GDPR) signed with strict legal delimitation of responsibilities.

EU AI Act (Art. 50)

Transparency

Transparent identification of the voice agent as an AI system during the initial greeting of each call, in compliance with Regulation (EU) 2024/1689.

EU Infrastructure

EU-based Hosting

Proprietary VOIZ infrastructure hosted within the EU. Transfers to global technology providers rely on valid adequacy mechanisms (DPF, SCCs).

Secure Flow

Lifecycle of a phone call

How data travels and is processed in every interaction:

01

Reception & Notice

The call connects; the agent identifies itself as an AI and discloses data processing pursuant to Art. 50 of the EU AI Act.

02

Call Processing

The agent handles the call; audio is processed in real time to perform transcription and voice response generation without persistent physical storage.

03

PII De-identification

Contact details are isolated, and direct identifiers are automatically replaced prior to any technical analysis.

04

Retention & Erasure

Transcripts are retained during service duration and up to a maximum of 12 months post-contract termination, after which they are permanently deleted.

Clear Answers

Frequently Asked Questions about Privacy and Security

We safeguard your business information with full transparency and regulatory rigor:

No. Audio recording is disabled by default across all plans. Voice is processed strictly in volatile memory in real time solely to generate text transcription and the call business report, without storing persistent physical audio files.

Only your team has access to your leads and conversations. Information is delivered directly to your own repositories (Google Sheets or email in standard tiers) or managed in databases featuring dedicated isolation policies (Row Level Security in Pro and Enterprise plans), ensuring that no unauthorized third party can access your data.

No. We operate exclusively through enterprise API connections under strict zero-data-retention and no-training policies. Your conversations are never used to train third-party public models. Any industry-level learning is conducted exclusively on anonymous, irreversible statistical patterns (pursuant to Recital 26 of the GDPR).

The agent transparently introduces itself as an AI virtual assistant in the opening greeting. If the user asks to speak with a human agent, the system routes the call to your designated team line or logs the request so you can follow up with top priority.

Certainly. You can request data erasure or export at any time. Following contract termination, operational call transcripts are retained for a maximum period of 12 months and subsequently deleted according to VOIZ erasure protocols, except for records required to satisfy mandatory legal obligations.

Security & Trust

Need to review our DPA agreement or technical specifications?

Our legal and security team will be glad to assist your Data Protection Officer (DPO): dpo@voiz.es

View Service Plans