Legal

Last updated: July 21, 2026

Privacy Policy

1. Introduction

This Privacy Policy explains how VoxVanta ("VoxVanta", "we", "us", or "our") collects, uses, discloses, and protects personal data when individuals interact with our website, products, and services.

VoxVanta is a sole proprietorship operated by Rohit Krishna, based in Kerala, India.

This policy is intended for our business customers, their authorised users, call participants, website visitors, and any other individuals whose personal data is processed through VoxVanta's AI receptionist and related services.

By accessing or using our website or services, or by otherwise providing personal data to us, you acknowledge that you have read and understood this Privacy Policy.

2. Scope and our role

This Privacy Policy applies to personal data we process in connection with:

  • Our website and landing pages (the "Site").
  • Our AI voice receptionist, call handling, and appointment booking services (the "Services").
  • Communication and support channels, including email, phone, and messaging apps.

Where a business customer uses VoxVanta to handle calls for their own business, that customer acts as the data fiduciary / data controller for the personal data processed through the Services, and VoxVanta acts as their data processor. For Site visitors and our own marketing activities, VoxVanta acts as an independent data fiduciary / controller.

3. Legal basis

We process personal data in accordance with applicable Indian law and, where relevant to specific individuals, other data protection regimes. Depending on the context, we rely on:

  • Performance of a contract — to provide the Services to our customers.
  • Compliance with legal obligations — record-keeping and responding to lawful requests.
  • Legitimate interests — securing and improving the Services, preventing fraud and abuse.
  • Consent — for marketing communications, non-essential cookies, and connecting third-party accounts such as Google Calendar.

4. Personal data we collect

4.1 Information you provide

  • Account and profile data: name, business email address, phone number, business name, login credentials.
  • Billing details: billing contact details, address, tax identifiers, and transaction history. Card and payment instrument details are handled directly by our third-party payment processor and are not stored by VoxVanta.
  • Configuration and content: agent prompts, business information, knowledge base documents, working hours, appointment settings, and other configuration you create in the Services.
  • Support communications: information you share when contacting support or providing feedback.

4.2 Data generated when using the Services

When a business customer uses VoxVanta to handle calls, the Services may process:

  • Call metadata: caller and business phone numbers, call start and end time, duration, routing decisions, and call outcome.
  • Call content: call audio and transcripts, and derived analytics such as summaries, intent, and sentiment, where enabled by the customer.
  • Appointment data: where the appointment feature is enabled, the caller's name and phone number as provided by the caller during the call, together with the requested appointment date and time.
  • Interaction logs: inputs and outputs exchanged between callers and the AI agent.

Business customers are responsible for ensuring they have the necessary notices, consents, and lawful basis to process call data through VoxVanta in their jurisdiction.

4.3 Data collected automatically

  • Device and technical data: IP address, browser type and version, operating system, language settings.
  • Usage data: pages visited, features used, error logs, and performance metrics.
  • Cookie and similar tracking data, subject to consent where required.

4.4 Information from third parties

  • Business customers who provide data about their staff or customers to configure and use the Services.
  • Telephony providers and cloud platforms that transmit call data on a customer's behalf.
  • Third-party accounts a customer chooses to connect, such as Google Calendar (see Section 6).

5. How we use personal data

  • Providing and operating the Services: maintaining accounts, handling calls, generating AI responses, checking calendar availability, booking appointments, capturing leads, and providing dashboards and analytics.
  • Securing and maintaining the Services: monitoring performance, troubleshooting, incident response, and preventing abuse.
  • Customer support: responding to enquiries, onboarding, and investigating issues.
  • Billing and account management: processing payments, invoicing, and subscription changes.
  • Marketing to business contacts: information about features and offerings, where permitted by law and subject to opt-out.
  • Legal and compliance: enforcing our agreements, complying with legal obligations, and responding to lawful requests.

6. Google user data

Where a business customer enables the appointment booking feature, they may choose to connect their own Google Calendar account to VoxVanta. This section describes exactly how VoxVanta accesses and handles Google user data, and it takes precedence over any more general statement elsewhere in this policy.

6.1 Scopes we request and why

VoxVanta requests only the minimum scopes required for the feature to function:

https://www.googleapis.com/auth/calendar.freebusy

Read free/busy availability. Used to determine which time slots on the connected calendar are already occupied, so the AI agent can offer callers a genuinely available appointment time. We read only busy/free time blocks. We do not read event titles, descriptions, attendees, locations, or any other event content.

https://www.googleapis.com/auth/calendar.events

Create and manage calendar events. Used solely to create a new appointment event on the connected calendar when a caller confirms a time slot during a phone call.

openid, .../auth/userinfo.email

Identify the connected account. Used to display which Google account is connected in the VoxVanta portal, so the account owner can confirm and manage the connection.

We deliberately request calendar.freebusy rather than a broader calendar read scope in order to minimise the data we can access. calendar.events is the narrowest scope Google offers that permits creating an event, which is a core function of the product.

6.2 What we do and do not do with your calendar

We do:

  • Query free/busy time blocks for the connected calendar within a limited forward-looking booking window configured by the account owner.
  • Create new appointment events when a caller confirms a slot. Each event we create contains only the caller's name in the event title (for example, "Appointment: [caller name]"), the caller's phone number in the event description, a note that the booking was made by VoxVanta, and the start and end time.

We do not:

  • Read, list, download, or store the contents of any pre-existing event on your calendar.
  • Modify or delete any event that VoxVanta did not create.
  • Access any calendar other than the one you select.
  • Share Google user data with any third party.
  • Use Google user data for advertising, profiling, or any form of marketing.
  • Use Google user data to train, retrain, fine-tune, or improve any artificial intelligence or machine learning model, whether ours or a third party's. Google user data is never included in any prompt sent to an AI model.
  • Sell Google user data, or transfer it for any purpose other than providing or improving the user-facing appointment booking feature, complying with applicable law, or as required for security purposes.

6.3 Storage, security, and retention of Google data

  • OAuth access and refresh tokens are encrypted at rest using authenticated symmetric encryption before being written to our database. They are never written to logs, never returned by any VoxVanta API, never sent to any browser or client, and never included in any AI prompt.
  • Free/busy data is used transiently, in memory, to compute available slots for the duration of a call. It is not stored.
  • We retain a record of appointments booked by the AI agent (caller name, caller phone number, appointment time, and the Google event identifier) so that our customers have an auditable record of bookings made on their behalf.
  • We store the email address of the connected Google account and the identifier of the selected calendar, so the account owner can see and manage the connection.

6.4 Revoking access

A connected Google account can be disconnected at any time from the Appointments page of the VoxVanta portal. When you disconnect, VoxVanta revokes the token with Google and permanently deletes the stored access and refresh tokens from our systems. You may also revoke VoxVanta's access directly at https://myaccount.google.com/permissions. Revoking access does not delete appointment events already created on your calendar; you control those events and may delete them yourself.

6.5 Limited Use disclosure

VoxVanta's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. AI processing and model training

VoxVanta uses AI and machine learning technologies, including third-party AI providers, to recognise speech, generate responses, classify intent, and summarise calls.

We do not use customer data, call recordings, or call transcripts to train, retrain, or fine-tune AI models. Where we use third-party AI providers, we use their services under terms that prohibit the provider from using data submitted through our account to train their general-purpose models.

AI-generated responses may occasionally be inaccurate or incomplete. Customers are responsible for reviewing agent configuration and for any decisions made on the basis of AI output.

8. How we share personal data

We do not sell personal data. We share personal data only with the following categories of recipients, under contractual and legal safeguards:

  • Cloud infrastructure: Our cloud hosting provider, where our application and database are hosted.
  • Telephony providers: to originate, receive, and route calls.
  • AI providers: third-party providers we use for speech recognition, language generation, and speech synthesis, under terms that prohibit them from using data submitted through our account to train their models.
  • Payment processors: to process subscription payments.
  • Business customers: we return call data, transcripts, bookings, and analytics to the customer on whose behalf we processed them.
  • Professional advisers: auditors, lawyers, or consultants under confidentiality obligations.
  • Legal and regulatory authorities: where required by law or to protect rights, property, or safety.
  • Business transfers: in connection with a merger, acquisition, or sale of the business, subject to appropriate safeguards.

Google user data as described in Section 6 is not shared with any of the above categories other than our cloud hosting provider, and is never sent to any AI provider.

9. Data location and international transfers

Customer data is primarily stored and processed on cloud infrastructure located in India.

Certain features, in particular real-time AI inference, may involve transient processing of audio or text by AI providers whose infrastructure is located outside India. Where personal data is transferred outside India, we rely on contractual protections and vendor commitments to safeguard it.

10. Data retention

We retain personal data only as long as necessary to provide the Services, maintain security, comply with legal obligations, and resolve disputes.

  • Call recordings and transcripts: retained for the period configured for the customer's account, and deleted thereafter.
  • Appointment booking records: retained for the duration of the customer's account, as they form the customer's business records.
  • Google OAuth tokens: deleted immediately on disconnection or on revocation of the grant.
  • On account termination: customer data is deleted from our primary systems within 60 days, and from backups within 90 days, unless a longer period is required by law or by a legal hold.

11. Security

We use reasonable and appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit (TLS) and encryption at rest for sensitive credentials, including all third-party OAuth tokens.
  • Role-based access controls and authenticated access to the customer portal.
  • Strict tenant isolation, so a customer's data and connected accounts are accessible only to that customer's authorised users.
  • Logging and monitoring, with credentials and tokens excluded from all logs.

No system is perfectly secure and we cannot guarantee absolute security, but we work to reduce risk and to respond promptly to identified issues. Please report security concerns to hello@voxvanta.com.

12. Your rights

Depending on your jurisdiction, you may have the right to access your personal data, request correction of inaccurate data, request deletion, object to or restrict processing, request portability, and withdraw consent.

If you are a caller who interacted with a business using VoxVanta: the business you called is the data fiduciary and controls your data. Please direct your request to that business in the first instance. If they do not respond, contact us at hello@voxvanta.com and we will assist in routing your request.

To exercise your rights, email hello@voxvanta.com with your name, contact details, and a description of your request. We will respond within 30 days.

13. Cookies

We use cookies and similar technologies for essential site functionality, authentication, remembering preferences, and analysing traffic. Where required by law, you will be offered choices about non-essential cookies. You can also manage cookies through your browser settings, although some features may not work correctly if certain cookies are disabled.

14. Children's data

The Site and Services are intended for businesses and adults. We do not knowingly collect personal data from individuals under 18. If you believe a child has provided personal data to us, contact us so we can take appropriate steps to delete it.

15. Changes to this policy

We may update this Privacy Policy to reflect changes in technology, law, or our practices. When we do, we will revise the "Last updated" date above, and we will communicate material changes through the Site or within the Services. Material changes affecting how we handle Google user data will be notified before they take effect.

16. Contact us

Privacy enquiries and data rights requests: hello@voxvanta.com

General support: support@voxvanta.com

Security issues: hello@voxvanta.com

VoxVanta
Rohit Krishna, Sole Proprietor
Kerala, India
+91 75949 16949

We aim to respond to all privacy enquiries within 30 days.