VoilitAI (“VoilitAI,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our marketing website, create an account on the product application at app.voilitai.com, book a demo, or otherwise interact with our services (together, the “Services”).
If you do not agree with this policy, please do not use the Services. Questions: contact@voilitai.com.
1. Who we are
VoilitAI is a voice AI platform operated by Aventrex Digital. We provide tools to design, deploy, and operate voice agents that answer calls, take actions (such as booking or CRM updates), and hand off to humans. Our public contact address is contact@voilitai.com.
2. Scope
This policy covers:
- The marketing website and content (including blog posts we publish or syndicate).
- Demo, contact, and sales requests submitted through our forms or email.
- The hosted product at app.voilitai.com, including accounts, billing, agent configuration, telephony, analytics, and related APIs.
It does not replace a customer’s own privacy notice to their callers. If you deploy a VoilitAI agent on a phone number you control, you are typically the controller (or “business”) for that conversation data. We process it on your instructions as a processor / service provider, except where we process data for our own operations (accounts, billing, security), in which case we are a controller.
An order form, business associate agreement (BAA), or data processing addendum (DPA) will control if it conflicts with this policy for that customer relationship.
3. Information we collect
Information you give us
- Demo and contact forms. Name, work email, phone, company, monthly call volume, and your message. We use this to reply within about 24 hours and to follow up about the Services. Form submissions may be delivered through a form processor (currently FormSubmit) to contact@voilitai.com.
- Account and profile. Name, email, password or SSO identifiers, company, role, and preferences when you register on the product.
- Billing. Plan selection, billing contact, tax information, and payment method details processed by our payment provider. We do not store full card numbers on our servers.
- Support. The content of emails, tickets, and any files you send us.
- Integrations you connect. Credentials or tokens, and the data those tools expose (for example calendar availability, CRM records, or knowledge-base documents), so the agent can take actions you configure.
Information collected automatically
- Device and log data. IP address, browser or client type, operating system, referring URL, pages or API routes requested, and timestamps. We use this to operate, secure, and debug the Services.
- Usage data. Feature use, agent configuration metadata, call counts, minutes, outcomes, and similar product analytics so we can bill accurately and improve reliability.
- Cookies. See Cookies and similar tech.
Information from voice and messaging
When a customer uses the Services to place or receive calls, chats, or SMS, we may process on their behalf:
- Phone numbers and call metadata (time, duration, direction, disposition).
- Audio recordings and real-time audio streams.
- Transcripts, summaries, sentiment or QA labels, and tool-call logs.
- Messages sent over chat or SMS, including media you attach.
- Caller-provided details (appointments, names, account numbers) captured by the agent.
That content can include personal information — and, in some deployments, sensitive data such as health or financial details. Customers decide what their agents ask for and how long recordings are kept.
Information from others
We may receive information from carriers or telephony partners (delivery receipts, STIR/SHAKEN or spam-label signals), identity providers (SSO), payment processors (successful charge, failure reason), and publicly available or commercially available sources used for fraud prevention.
4. How we use information
We use personal information to:
- Provide, maintain, and secure the Services, including routing calls and running agents.
- Create and administer accounts, authenticate users, and enforce access controls.
- Process payments, prevent fraud, and send invoices or usage notices (for example at 80% of minutes).
- Respond to demo requests, sales questions, and support tickets.
- Send service, security, and (where permitted) product-update messages. You can opt out of marketing email; transactional mail still goes through.
- Monitor quality, latency, uptime, and abuse.
- Comply with law, enforce our terms, and protect callers, customers, and VoilitAI.
- Improve the product using aggregated or de-identified metrics.
We do not sell personal information. We do not use customer conversation audio or transcripts to train public foundation models. We may use de-identified or aggregated data to improve reliability and features of VoilitAI itself.
5. Legal bases (EEA, UK, and similar)
Where GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Services you or your organization requested (account, billing, running an agent).
- Legitimate interests — to secure the platform, prevent abuse, understand product usage, and respond to business inquiries, balanced against your rights.
- Consent — where we ask for it (for example optional marketing, or certain cookies). You can withdraw consent at any time.
- Legal obligation — tax, accounting, lawful requests, and similar duties.
When we process caller data solely on a customer’s instructions, the customer is responsible for its legal basis (for example notice and consent to record a call).
6. How we share information
We share personal information only as needed to run the business:
- Service providers / subprocessors who host infrastructure, send email, process payments, accept demo forms, provide telephony or SIP, transcribe speech, or store backups — under contracts that limit their use of the data.
- Integrations you enable (CRM, calendar, helpdesk, automation tools). Data flows to those providers under your settings and their policies.
- Your organization. Workspace admins can access agents, recordings, transcripts, and member accounts according to roles you assign.
- Professional advisors (legal, accounting) under confidentiality.
- Corporate transactions. In a merger, acquisition, or asset sale, information may transfer subject to this policy or a successor notice.
- Legal and safety. If we believe disclosure is required by law, or necessary to protect rights, safety, or the integrity of the Services.
A current subprocessor list is available on request at contact@voilitai.com for customers under a DPA.
7. Voice, transcripts, and recordings
Voice is the core of the product. Customers should treat call audio and transcripts as confidential business records.
- Audio and transcripts are encrypted in transit and at rest.
- Access is limited by role-based controls and audit logs.
- Optional PII redaction can mask personal information in QA views.
- Retention windows are configurable so you are not keeping recordings “just in case.”
- You are responsible for call-recording notices, two-party consent rules, TCPA / PECR / equivalent outbound consent, and any industry scripts required in your markets.
8. Cookies and similar tech
We use:
- Essential cookies — session, authentication, CSRF, load balancing, and theme preference. The site will not work correctly without these.
- Functional cookies — remember UI settings such as light or dark theme.
We do not currently use advertising or cross-site tracking cookies on the marketing site. If we add analytics cookies later, we will update this policy and, where required, ask for consent. You can control cookies in your browser; blocking essentials may break sign-in.
9. Retention
We keep information only as long as needed for the purposes above:
- Demo and sales inquiries — typically up to 24 months, unless you ask us to delete sooner or we need them for a dispute.
- Account and billing records — for the life of the account plus the period required for tax and accounting (often 7 years).
- Call recordings, transcripts, and logs — according to the customer’s retention settings, then deleted or de-identified.
- Security logs — for a limited period appropriate to detect abuse.
Backup copies may persist for a short time after deletion until they rotate out.
10. Security
We use administrative, technical, and physical safeguards appropriate to a production voice platform: encryption in transit and at rest, access control, SSO support, audit logging, and network protections. No method of transmission or storage is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and regulators as required by law. See also our trust center.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority.
Residents of California and certain other U.S. states may also have rights to know what we collect, request deletion, correct inaccuracies, and opt out of “sale” or “sharing” for cross-context advertising. We do not sell personal information and we do not share it for cross-context behavioral advertising.
To exercise rights, email contact@voilitai.com from the address we have on file. We may need to verify your identity. If we process data only as a customer’s processor, we will direct you to that customer or handle the request on their documented instructions.
We will not discriminate against you for exercising privacy rights.
12. International transfers
We may process and store information in the United States and other countries where we or our providers operate. Those countries may not provide the same level of data protection as your home country. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms.
13. Children
The Services are built for businesses, not for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact contact@voilitai.com and we will delete it.
14. Healthcare and HIPAA
VoilitAI can be configured for healthcare workflows and supports a HIPAA-ready architecture (access control, encryption, auditability). The marketing website and general demo inbox are not a HIPAA environment — do not send protected health information (PHI) through the public contact form.
Covered entities and business associates should execute a BAA with us before pointing a production number that will handle PHI at an agent. Contact contact@voilitai.com to start that review.
15. Changes
We may update this policy from time to time. The “Last updated” date at the top will change. Material changes will be posted on this page and, where appropriate, emailed to account owners or announced in the product. Continued use after the effective date means you accept the updated policy.
16. Contact
Privacy, DPA, and BAA requests: contact@voilitai.com
You can also use our contact page or review the terms of service that govern use of the Services.