Skip to main content
VoicePABack to home

Privacy Policy

Last updated: 17 July 2026
Table of contents
Note: This document should be reviewed by a qualified legal professional before publication.

1. Data controller

Voice PA Limited (“Voice PA”, “we”, “us”, “our”) is the data controller responsible for your personal data.

  • Company number: 17057403 (registered in England and Wales)
  • Registered address: 14 Sollershott West, Letchworth Garden City, Hertfordshire, SG6 3PX
  • Privacy contact: privacy@voicepa.ai
  • Website: voicepa.ai

We operate an AI-powered phone receptionist service for tradespeople and small service businesses in the United Kingdom.

Who controls your data. For most of the data we handle — your provider account, our website analytics, and the prospect research we carry out — Voice PA is the sole data controller (we decide why and how it is processed). For the calls our AI receptionist answers on a tradesperson's behalf — including caller details, bookings and call recordings — Voice PA and the tradesperson are joint controllers: the tradesperson runs the customer relationship and acts on the booking, while Voice PA decides how the AI works, what is recorded, how long data is kept, and how it is kept secure. You can raise a data-protection request with either of us, and you can always reach Voice PA at privacy@voicepa.ai.

2. What data we collect

We collect and process the following categories of personal data:

  • Account information— name and email address provided via Google or Microsoft OAuth sign-in.
  • Business information— business name, trade category, services offered, pricing, working hours, service area, and contact details you provide during onboarding.
  • Call data— phone numbers, call recordings, call transcripts, AI-generated summaries, service requests, and booking details from calls handled by our AI receptionist.
  • Booking data— customer names, phone numbers, email addresses, postal addresses, postcodes, and appointment details collected during the booking process.
  • Calendar data— where you connect a calendar (Google, Microsoft or Apple), and only with your permission, we read the busy times of your existing events to work out which appointment slots you are free for, and we create, update, or delete booking events when an appointment is made, changed, or cancelled. See section 8 for how we handle Google Calendar data specifically.
  • Payment data— processed securely by Stripe. We store your Stripe customer ID and subscription status but do not store card numbers or bank details on our servers.
  • Website usage data— information about how you interact with our website and dashboard, collected through PostHog analytics (where you have given consent).
  • Cookie data— essential cookies required for the service to function, and analytics cookies (with your consent). See section 6 for full details.
  • Consent records— records of the consents you or your customers have given or withdrawn, including the type of consent, method, and timestamp.

3. Lawful basis for processing

Under UK GDPR Article 6, we must have a lawful basis for each processing activity. The table below sets out the lawful basis we rely on for each type of processing:

Processing activityLawful basis
Providing the AI receptionist service (answering calls, booking appointments, sending confirmations)Performance of a contract — Art 6(1)(b)
Recording phone calls handled by our AI receptionistLegitimate interests — Art 6(1)(f). Our legitimate interest in capturing booking and enquiry details accurately on behalf of the tradesperson. Callers are informed at the start of each call that it is AI-handled and is recorded; a Legitimate Interests Assessment is available on request.
Sending SMS booking confirmations and appointment remindersPerformance of a contract — Art 6(1)(b)
Sending SMS marketing messagesConsent — Art 6(1)(a). You can opt out at any time by replying STOP.
Website analytics and cookies (PostHog)Consent — Art 6(1)(a). Managed through our cookie consent banner.
Fraud prevention and service securityLegitimate interest — Art 6(1)(f). Our legitimate interest in protecting the service and users from fraud and abuse.
Tax compliance and financial record-keepingLegal obligation — Art 6(1)(c). Required by HMRC regulations.
Managing your calendar on your behalfPerformance of a contract — Art 6(1)(b)
Processing subscription paymentsPerformance of a contract — Art 6(1)(b)

4. Call recording

Our AI receptionist is powered by Telnyx. At the start of each call, callers are informed that they are speaking with an AI assistant and that the call is recorded. We rely on our legitimate interests as the lawful basis for recording (see section 3); the call-start disclosure means callers are on notice and can end the call if they do not wish to be recorded.

We store the following call data:

  • Call transcript — a text transcription of the conversation.
  • Call summary — an AI-generated summary of the call including any service requests and booking details.
  • Recording URL — a link to the audio recording, hosted by Telnyx.
  • Caller phone number — the number the caller dialled from.
  • Call metadata — duration, timestamp, and call disposition.

Call recordings and transcripts are retained for 12 months from the date of the call (see section 10 for full retention periods). You or the caller may request deletion of call data at any time by contacting privacy@voicepa.ai.

5. SMS and WhatsApp messaging

We send the following types of messages via SMS (using Telnyx):

  • Transactional messages— booking confirmations, appointment reminders, and missed call notifications. These are sent as part of the service you have requested and do not require separate marketing consent under PECR.
  • Marketing messages— promotional messages sent only with your explicit consent. These comply with PECR Regulation 22.

How to opt out: You can opt out of marketing messages at any time by replying STOP to any message, or by using the consent management page linked in your messages. Opting out of marketing will not affect transactional messages necessary for delivering the service.

All marketing SMS messages include opt-out instructions in compliance with PECR.

6. Cookies and analytics

We use the following types of cookies:

  • Essential cookies— required for the website and service to function (for example, session cookies for authentication). These do not require consent under PECR Regulation 6 as they are strictly necessary.
  • Analytics cookies— used by PostHog to understand how visitors use our website. These cookies are only set with your consent, which you can manage via our cookie consent banner (powered by Klaro).

What PostHog collects: page views, button clicks, session duration, device type, browser type, and approximate location (country/region level). PostHog does not collect precise geolocation. We use this data to improve the service and understand usage patterns.

You can change your cookie preferences at any time using the cookie consent banner, which is accessible via the link in the website footer.

7. Data sharing and sub-processors

We share personal data only with the following third-party service providers (sub-processors), solely to operate the service. We do not sell your personal data to any third party.

Sub-processorPurposeData location
TelnyxVoice AI runtime — call conveyance, call recording, text-to-speech (native Telnyx Ultra en-GB voices), SMS messaging, UK phone number provisioning, and orchestration of the AI assistant (whose transcription and language-model sub-processors are listed in the next two rows)European Union (Germany; assistant anchored in London, UK)
DeepgramSpeech-to-text transcription of call audio, within the Telnyx AI assistant pipelineEuropean Union (via Telnyx)
AnthropicLanguage model (Claude) powering the AI receptionist's conversation, within the Telnyx AI assistant pipeline. Where you have connected a calendar, the only calendar-derived information it receives is the availability we compute on our own servers — the date, start time and end time of free slots — so it can offer a caller a time. It never receives raw calendar content (event titles, descriptions, locations or attendees).European Union (via Telnyx)
StripePayment processing and subscription managementUnited States
ClerkProvider identity and authenticationUnited States
ResendTransactional and notification email to providersUnited States
ApifyProspect data collectionUnited States
OpenRouterAI gateway for three features that sit outside the call path: (1) the in-app support chat, (2) an automated check on the service names you enter during onboarding, and (3) internal drafting of our own marketing content. OpenRouter is not part of the AI receptionist and never handles call audio, call transcripts, or calendar data. No information from your Google Calendar — raw or derived — is sent to OpenRouter (see section 8).United States
GoogleAuthentication (OAuth) and calendar integrationUnited States / EEA
MicrosoftCalendar integrationUnited States / EEA
AppleApple Calendar integration (CalDAV)United States
SentryError monitoring (personal data scrubbed best-effort before transmission)European Union
NeonPrimary application databaseUnited Kingdom (eu-west-2, London)
AWSInfrastructure and flow execution environmentUnited Kingdom (eu-west-2, London)
PostHogWebsite analytics (consent-gated via Klaro)European Union (eu.i.posthog.com)
VercelFrontend hosting and runtimeUnited Kingdom — lhr1 (London)
UpstashRate limiting and webhook deduplicationUnited Kingdom (eu-west-2, London)
Ideal PostcodesUK address lookup and validation during calls (resolves a caller's postcode plus house name/number to a full address)United Kingdom

8. Google user data and Limited Use

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This section explains what that means in practice.

What we ask for. When you choose to connect your Google Calendar, we request a single Google Calendar permission and nothing else. We do not request access to Gmail, Google Contacts, or Google Drive.

What we do with it. We use your Google Calendar for exactly two things, both on your behalf and both necessary to run your AI receptionist:

  • Reading busy times— we read when your existing events are busy so we can work out which appointment slots you are genuinely free for, and so the AI receptionist does not offer a caller a time you have already blocked out.
  • Writing booking events— we create a booking event when the AI receptionist takes an appointment, and update or delete it if that appointment changes or is cancelled.

Raw calendar content never leaves our servers. The titles, descriptions, locations, and attendees of your existing events are not sent to the AI that speaks to your callers. The only calendar-derived information that AI ever receives is availability worked out on our own servers — a date, a start time, and an end time for the slots you are free for — so that it can offer a caller a time. It has no way to request or read the content of your calendar.

We do not use Google data to train AI models. We do not retain or use information received from Google Workspace APIs to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models. Your Google data is used only to provide the calendar features described above, at your direction.

Your Google Calendar data is not sent to our third-party AI provider. We use OpenRouter (United States) for three features that sit outside the call path entirely: the in-app support chat, an automated check on the service names you enter, and internal drafting of our own marketing content. None of them touches your calendar: no Google Calendar data — neither raw event content nor the availability we derive from it — is sent to OpenRouter. Those features run on information you have entered yourself and on our own content.

We do not share your Google data with third parties for advertising or any other unrelated purpose, and we do not sell it. You can disconnect your calendar at any time from your dashboard settings, and you can ask us to delete the data we hold by contacting privacy@voicepa.ai (see section 11).

9. International data transfers

Our voice AI runtime is EU-resident: Telnyx and the AI-pipeline providers it orchestrates (Deepgram for transcription and Anthropic for the language model) process call data in the European Union, and text-to-speech is handled natively by Telnyx. Neon, AWS, Vercel and Ideal Postcodes process data in the United Kingdom; Upstash processes data in the United Kingdom (London); and PostHog and Sentry process data in the European Union. Some of our other sub-processors process data in the United States — including Stripe, Clerk, Resend, Apify, OpenRouter, and Apple (with Google and Microsoft in the United States or EEA). OpenRouter is not part of the AI receptionist: it supports the in-app support chat, the service-name check, and our internal content drafting only, and it receives no call recordings, no call transcripts, and no calendar data (see section 8). Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place:

  • UK-EU adequacy— the United Kingdom and the European Union each recognise the other as providing an adequate level of data protection, and the EU renewed its adequacy decision for the UK in December 2025 (running to December 2031). Our EU-resident processing (Telnyx in Germany, and PostHog and Sentry in the EU) is therefore covered by adequacy and needs no further transfer safeguard.
  • UK-US Data Bridge— for our US-based providers that are certified under the UK Extension to the EU-US Data Privacy Framework (for example Stripe, Clerk, Resend, Google and Microsoft), transfers are covered by the UK-US Data Bridge.
  • Standard Contractual Clauses and transfer risk assessments— for any transfer outside the UK that is not covered by adequacy or the Data Bridge (for example Apify and Apple), we use the UK International Data Transfer Agreement or EU Standard Contractual Clauses (as adopted under UK law), backed by a transfer risk assessment. We treat these clauses as our primary safeguard even where a provider is also Data Bridge-certified.

You can request a copy of the safeguards we use by contacting privacy@voicepa.ai.

10. Data retention

We retain your personal data only for as long as necessary for the purposes set out in this policy. The specific retention periods are:

Data typeRetention period
Account and business dataWhile your account is active. If your trial ends without a subscription, we delete it 90 days after your trial ends, and we email you before we do. If you have ever subscribed, your account record is kept under the payment and billing records row below.
Call recordings and transcripts12 months from the date of the call
Booking records24 months from the date of the booking
Consent records6 years (limitation period for contract claims under the Limitation Act 1980)
Payment and billing records7 years (HMRC requirement for financial records)
Analytics data (PostHog)Governed by PostHog's retention settings; anonymised after 12 months

After the applicable retention period, data is securely deleted or anonymised. You can request early deletion of your data at any time (see section 11).

11. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access (Article 15) — you have the right to request a copy of the personal data we hold about you. You can do this via the consent management page or by emailing privacy@voicepa.ai.
  • Right to rectification (Article 16) — you have the right to ask us to correct any inaccurate personal data we hold about you. Contact us at privacy@voicepa.ai.
  • Right to erasure (Article 17)— you have the right to request deletion of your personal data. We will comply unless we have a legal obligation to retain it. You can request this via the consent management page or by emailing us.
  • Right to restriction of processing (Article 18)— you have the right to ask us to restrict how we process your data in certain circumstances, for example while we verify the accuracy of your data.
  • Right to data portability (Article 20)— you have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON), and to have it transferred to another controller where technically feasible.
  • Right to object (Article 21)— you have the right to object to processing based on legitimate interests (such as fraud prevention). We will stop processing unless we can demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Article 7(3))— where we process your data based on consent (such as marketing SMS or analytics cookies), you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Automated decision-making: We do not make decisions about you based solely on automated processing that produce legal effects for you or that similarly significantly affect you. Our AI receptionist takes your enquiry and books an appointment, but a real tradesperson decides whether and how to carry out the work. If this ever changes, we will tell you and explain your rights to a human review of the decision.

How to exercise your rights: You can exercise these rights via the consent management page (linked in your SMS messages), or by contacting us at privacy@voicepa.ai. We will respond within one month. We only ask you to give us what is reasonable and proportionate to help us find your data. If we need to confirm who you are, or ask you to narrow down a broad request, the one-month clock pauses until you reply (a “stop-the-clock” pause under the Data (Use and Access) Act 2025). Where a request is especially complex, or you have made a number of requests, we may extend the response time by up to a further two months and will tell you why within the first month.

12. Complaints and the Information Commission

Complaining to us: If you are unhappy with how we have handled your personal data, you can make a complaint to us at any time by emailing privacy@voicepa.ai. You do not need to use any particular form — just tell us what has gone wrong. We will acknowledge your complaint within 30 days, look into it without undue delay, and let you know the outcome. We would appreciate the chance to put things right first.

Complaining to the regulator:You also have the right to complain to the Information Commission (formerly the Information Commissioner's Office, or ICO), the UK's supervisory authority for data protection:

  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Website: ico.org.uk
  • Telephone: 0303 123 1113

Complaining to us first does not affect your right to go to the Information Commission at any time.

13. Children

Voice PA is a business-to-business service designed for tradespeople and service businesses. All users must be at least 18 years old. We do not knowingly collect personal data from children under the age of 18. If we become aware that we have collected data from a child, we will delete it promptly.

14. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email or through a prominent notice on our website. The “Last updated” date at the top of this page indicates when the policy was last revised.

We encourage you to review this policy periodically. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

15. Contact

If you have any questions about this privacy policy or how we handle your personal data, please contact us:

  • Email: privacy@voicepa.ai
  • Data controller: Voice PA Limited, 14 Sollershott West, Letchworth Garden City, Hertfordshire, SG6 3PX, company number 17057403