Privacy Policy

Last updated: April 28, 2026 · Version 1.0

1. Who we are

Voxalytics, operated by VillaEx Technologies (Pvt) Limited, Karachi, Pakistan, is the data controller for personal information collected directly from you (account holders / operators). When you upload audio of third parties (e.g. your customers), you are the controller and Voxalytics is the processor — see our Data Processing Addendum for details.

2. What we collect

  • Account information: name, email, phone, organisation, role.
  • Audio uploads: the call recordings you choose to upload, plus any metadata you attach (filename, agent, campaign, customer name).
  • Derived analyses: transcripts, summaries, sentiment scores, QA scores, and compliance flags produced from your audio.
  • Usage data: requests, IP, browser type, timestamps. Used for security, fraud prevention, and capacity planning.
  • Billing data: billing address and payment method metadata (last4, brand). We never store full card numbers — payment data lives only in our gateway provider (HBL Pay).

3. How we use it

Operate and provide the Service; process and analyse your audio; bill for the Service; communicate about your account; investigate and prevent abuse; comply with legal obligations.

We do not use your audio or transcripts to train machine-learning models. We do not sell or rent personal data.

4. Sub-processors

To deliver the Service we use:
  • Google (Gemini API): transcription, summary, sentiment, scoring. Audio is sent to Gemini for processing and returned. Google's usage policy applies.
  • HBL Pay: payment processing for Pakistan- denominated SaaS plans.
  • AWS S3 (or equivalent): audio storage, encrypted at rest. Region varies by deployment.
  • Sentry (optional): error monitoring. Configured per deployment.
Enterprise on-prem customers may opt out of any sub-processor by bringing their own AI key (BYOK) and managing their own storage.

5. Data retention

Audio and derived analyses are retained for the life of your subscription plus 30 days, after which they are deleted unless you have an active legal hold or longer retention contract. Account information is retained for 7 years after termination for legal / tax compliance.

6. Security

  • TLS 1.2+ in transit; AES-256 at rest for audio storage.
  • Application secrets (BYOK keys, gateway credentials) are AES-GCM encrypted with rotatable keys.
  • Role-based access control across tenants; audit log of every sensitive action.
  • Backups are encrypted and stored separately from production data.
  • Vulnerability scans run continuously; third-party penetration test scheduled annually. The most recent report is available under NDA — request via [email protected].

7. Your rights

Depending on your jurisdiction (GDPR, PDPA, CCPA, etc.) you may have rights to access, correct, delete, port, or restrict processing of your personal data. Email [email protected] to exercise any of these. We respond within 30 days.

8. International transfers

Voxalytics' SaaS infrastructure is hosted in Frankfurt, Germany (EU) on Contabo cloud servers; AWS S3 storage is in ``eu-central-1`` by default. The transcription model (Google Gemini) processes audio in Google's nearest regional data center, which may include the United States. By using the Service you consent to those transfers. Enterprise customers can self-host on-prem to keep data within their preferred jurisdiction.

9. Children

The Service is not intended for individuals under 16. We do not knowingly collect data from anyone under 16.

10. Changes

Material changes will be announced 30 days in advance via in-product notification and email to account admins.

11. Contact

Questions: [email protected].