GDPR Compliance at VoxPort AI
GDPR Compliance Depends on Correct Configuration
VoxPort AI provides tools and configuration to support GDPR-compliant use. However, GDPR compliance is not automatic and depends on correct configuration of your service, your governance as the Data Controller, and your operational practices. We provide setup support, ongoing guidance, and technical tools. Ultimate compliance responsibility rests with you as Data Controller.
Our Commitment
Full compliance with UK GDPR and Data Protection Act 2018.
Data Protection Roles Explained
Your Business (Data Controller)
- • You determine what data to collect and why
- • You decide retention periods
- • You're responsible for lawful basis
- • You must inform callers
- • You maintain privacy notices for your customers
VoxPort AI (Data Processor)
- • We process data on your behalf per your instructions
- • We configure and customise AI agents
- • We manage the platform for GDPR setup
- • We provide tools and support
- • We don't use your data for any other purpose
Infrastructure Providers (Sub-Processors)
- • Enterprise cloud platform providers
- • Bound by strict Data Processing Agreements
- • We maintain oversight
- • List available upon request
GDPR-Focused Setup (Included)
When you become a customer:
AI Customisation
- • Configured for your industry requirements
- • Tailored for regulated sectors (healthcare, legal, finance)
- • Call scripts with data minimisation
Data Minimisation
- • Only essential information collected
- • Unnecessary fields disabled
- • Regular reviews
Call Recording & Retention
- • Configurable recording (on/off, selective)
- • Customisable retention periods
- • Automatic deletion after retention expires
- • Secure, encrypted storage
Data Ownership
- • You retain 100% ownership
- • Full access to export data anytime
- • Ability to delete on demand
- • No vendor lock-in
Access Controls
- • Role-based permissions for your team
- • Audit logs
- • Multi-factor authentication
Key GDPR Principles
Your Rights Under GDPR
To Exercise Rights: Email: info@voxport.ai Response: Within 30 days (may extend to 60 days for complex requests)
Critical: Data Subject Rights
YOUR Responsibility (For Business Customers):
When YOUR customers/callers exercise GDPR rights, YOU must respond within 30 days.
- • Dashboard search and export tools
- • Bulk data capabilities
- • Deletion tools
- • Response templates
- • Priority support
We provide data to you within 5 business days, but YOU must respond to the data subject.
Customer Responsibilities
As Data Controller, you remain responsible for:
Lawful Basis
Identify and document why you're processing data. Common bases: Consent, Contract, Legitimate Interest
Informing Callers
IVR message: "This call may be recorded...", Privacy notice on your website, Information before/at collection
Privacy Notices
Keep your privacy policy updated, Include information about AI call handling, Reference VoxPort AI as processor
Compliant Operations
Train your staff on GDPR, Don't use service beyond stated purposes, Regularly review practices, Report data breaches to us immediately
Configuration Management
Review settings regularly, Update retention as needed, Manage user access, Disable unused features
International Data Transfers
Transparency: Data may be processed outside UK/EEA, including United States.
Safeguards:
- • Standard Contractual Clauses (SCCs) with all sub-processors
- • Transfer Impact Assessments conducted
- • Technical measures (encryption, access controls)
- • Organisational measures (training, policies)
- • You retain full ownership regardless of location
Sensitive Data Warning
Extra Care Required For:
- ⚠️ Healthcare data (PHI) - Requires HIPAA package
- ⚠️ Children's data (under 16) - Parental consent may be needed
- ⚠️ Special category data - Explicit consent required
- ⚠️ Criminal conviction data - Legal basis required
Prohibited Without Safeguards:
- • Payment card information
- • National Insurance numbers
- • Biometric data
- • Genetic data
Contact info@voxport.ai before processing any sensitive data.
Data Breach Procedures
Our Process:
- Immediate detection and containment
- Assessment of scope and severity
- ICO notification (within 72 hours if required)
- Customer notification (immediately)
- Individual notification (if high risk)
- Documentation and remediation
Your Obligation: Report any suspected breaches to us immediately.
Contact
Privacy Enquiries: info@voxport.ai General Support: info@voxport.ai
ICO Complaints: Information Commissioner's Office 0303 123 1113 www.ico.org.uk
VoxPort AI Limited · Company Number NI705644 · info@voxport.ai · +44 7588 376834