Vox Talk AI Ltd ("the Company," "we," "us," or "our") provides an AI voice triage platform that handles inbound alarm-response calls for security monitoring centers across Ireland and the EU. This Privacy Policy explains how we collect, use, and protect personal data in connection with getvoxtalk.com and the triage platform service.
1. Data Controller
Vox Talk AI Ltd ("the Company") (10 Hanover Quay, Grand Canal Dock, Dublin D02 R573, Ireland) is the data controller for personal data processed through getvoxtalk.com. For all data-protection matters, including to exercise the rights described in Section 6, contact us at [email protected].
Where monitoring center operators use our platform to process the personal data of their callers, including voice recordings of inbound alarm-response calls, the monitoring center operator is the data controller and the Company acts as a data processor under Article 28 GDPR. In that role we process call data solely on the operator's documented instructions, governed by a separate Data Processing Agreement.
2. Personal Data We Process
- Account and contact data: name, work email address, phone number, company name, and role, provided by monitoring center staff when registering for or administering the platform;
- Voice recordings and call metadata: inbound alarm-response calls routed through the triage engine, including voice content, caller identification, call timestamps, and routing decisions. This data is processed as processor on behalf of the monitoring center operator as controller;
- Triage outputs, including AI-generated call transcripts, triage classifications, and action logs produced from voice recordings;
- Inquiry and correspondence data: messages and requests submitted through our website contact form or by email;
- Technical and usage data such as IP address, browser type, operating system, pages visited, and session identifiers, collected automatically when you access getvoxtalk.com.
3. Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Responding to website inquiries and pre-sales communications | Pre-contract steps / legitimate interest (Art. 6(1)(b)/(f)) |
| Providing the alarm-triage platform under service agreement | Contract performance (Art. 6(1)(b)) |
| Processing call recordings on behalf of monitoring center operators | Art. 28 processor; the operator's lawful basis governs |
| Platform security and integrity | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance and recordkeeping | Legal obligation (Art. 6(1)(c)) |
| Analytics (website, with consent) | Consent (ePrivacy Directive and Art. 6(1)(a)) |
4. Recipients and International Transfers
Personal data is shared only with sub-processors acting under our instruction under Article 28 GDPR data-processing agreements. Sub-processors provide services including cloud infrastructure, telephony and call routing, and voice transcription. All infrastructure used to process call recordings and triage outputs is located within the European Economic Area.
Where any transfer of personal data outside the EU/EEA is required, we rely on Standard Contractual Clauses (Article 46 GDPR) and assess supplementary safeguards as required following the Schrems II ruling.
5. Retention
We retain personal data only for as long as necessary for the purposes described:
- Call recordings: retained for 30 days from the date of the call, then permanently deleted;
- Call logs and triage outputs: retained for 12 months from the date of processing;
- Account and platform contract data: retained for the duration of the service agreement and for six years thereafter for legal and audit purposes;
- Inquiry and contact form submissions: retained for 24 months after last contact;
- Website server and access logs: retained for 90 days.
6. Your GDPR Rights
- Right of access (Art. 15): confirm whether we process your data and obtain a copy;
- Right to rectification (Art. 16);
- Right to erasure / "right to be forgotten" (Art. 17), subject to limited exceptions;
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20);
- Right to object (Art. 21), including to direct marketing without further conditions;
- Right not to be subject to automated decision-making (Art. 22). We do not make automated decisions with legal effects on individuals.
To exercise any right, email [email protected]. We respond within one month; this may be extended by two further months for complex or numerous requests. We will notify you of any extension within the first month. Where a request relates to data processed on behalf of a monitoring center operator, we will direct you to the relevant controller.
7. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Data Protection Commission (DPC) of Ireland (dataprotection.ie). A full list of EU/EEA national supervisory authorities is available at edpb.europa.eu.
8. Cookies
See our Cookie Policy. Non-essential cookies are not set until you give your prior consent through our cookie banner, as required by the ePrivacy Directive as implemented in Irish law.
9. Security
We apply technical and organisational measures appropriate to the risks our processing activities present, including TLS encryption in transit and access controls limiting call and transcript data to personnel who need it to deliver the service. Our Data Processing Agreements require sub-processors to maintain equivalent standards.
10. Changes to This Policy
Material changes will be reflected by an updated "Last updated" date. Where GDPR requires, we will seek renewed consent or notify affected individuals directly.
11. Contact
Vox Talk AI Ltd10 Hanover Quay, Grand Canal Dock
Dublin D02 R573, Ireland
Email: [email protected]
Phone: +353 1 566 9040