Effective 23 August 2026
1. Data we process
We process organisation and administrator details, caller names and phone numbers, imported contact names and contact details, campaign data, call metadata, recordings, transcripts, summaries, tags, authentication events, audit logs, billing identifiers, and support communications.
2. Why we process it
We use data to provide and secure the service, route calls, prevent duplicate work, record and analyse calls when enabled, bill usage, investigate abuse, support users, and meet legal obligations. Organisations are generally responsible for deciding why their contact data is processed; Zyntria Labs processes it to provide TavoxVoice under their instructions.
3. AI and service providers
Depending on configuration, data may be processed by Twilio for telephony, Railway for hosting, Deepgram for primary transcription, AssemblyAI for fallback transcription, OpenAI for summaries and classification, Google when an optional Google model is enabled, Stripe for billing, Resend for transactional email, and Sentry for error monitoring. Deepgram promotional credit does not change the data-processing role or retention controls.
4. Security and tenant isolation
Contact phone numbers are encrypted at rest and masked in the interface. Access is scoped to an organisation and audited. No internet service is risk-free, so organisations must also protect credentials, team join links, invite codes, devices, and exported data.
5. Retention
We retain account, billing, security, and call data only for the service, configured retention periods, dispute handling, fraud prevention, and legal obligations. Recordings and transcripts may have shorter operational retention than accounting records. Deletion requests can be limited where retention is legally required.
6. International processing
Our providers may process data in countries outside the organisation or contact's country. We use contractual and provider safeguards where required, but organisations must assess whether their intended calling programme is lawful in each destination.
7. Rights and requests
Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or receive their personal data. Contact the organisation that called you first where it controls the campaign. Privacy requests to Zyntria Labs may be sent to [email protected].