Privacy Notice
Effective 20 August 2026 · Ash Systems, operator of Voxae
What personal information Voxae handles across calls and messaging channels, why, who it is shared with, how long it is kept, and how to have it deleted.
Every category of personal data handled, and where it comes from
Meta channel data used only to serve the connected business — never sold, never advertising
Retention windows, with the platform defaults stated in days
Deletion and rights requests answered within 30 days, free of charge
Who we are, and what this notice covers
Voxae is an AI communication platform operated by Ash Systems. Businesses use Voxae to run AI agents that answer their phone calls and reply to messages on their own WhatsApp, Instagram, Messenger, website and in-app channels.
This notice explains what personal information the platform handles, why, who it is shared with, how long it is kept, and how it can be deleted. It covers two different groups of people, and the difference matters for your rights:
- Account users — the people at a business who sign in to Voxae to build, run and review their agents.
- End customers — the people who call, message or talk to an agent that a business is running on Voxae, without ever having a Voxae account themselves.
Our role: whose data it is
For everything that happens inside a conversation — what a caller said, what someone sent on WhatsApp, the contact record built from it — the business running the agent is the data controller. They decide what their agent asks, what it stores and how long it is kept. Ash Systems is their data processor: we handle that information on their instructions and for no purpose of our own.
For the account itself — who has a login, billing, security logs, and the operation of the platform — Ash Systems is the controller.
In practice this means an end customer's request is usually fastest through the business they were talking to. We will always act on a request sent to us directly, and where we are the processor we pass it to that business and act on their instruction. We never refuse a deletion request by pointing at somebody else.
Information we handle
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and workspace data | Name, business email, phone number, job role, workspace and organisation identifiers, hashed credentials, multi-factor settings, session tokens, and an audit log of actions taken in the console. | Provided when an account is created or used. |
| Voice call data | Caller and called numbers, the time, duration and direction of the call, the telephony provider's call identifier, transcripts, recordings where the business has enabled them and consent requirements are met, and the outcome the agent recorded. | The call itself, through the connected telephony provider. |
| Messaging data | Message text, the sender's channel identifier (a WhatsApp number, an Instagram-scoped identifier, a Messenger page-scoped identifier, or an application user identifier), timestamps, delivery and read status, and the conversation thread they belong to. | Delivered to us by Meta, or by the business's own application, when a person messages a connected account. |
| Media in conversations | Photos, voice notes and documents that a person sends. Images are described and any visible text is read so the agent can respond; voice notes are transcribed and treated as if the person had typed them. | Sent by the person during the conversation. |
| Contact records and conversation memory | A contact record per person — name, phone number, email and other details they gave — together with a summary the agent uses to remember them, so a returning customer is not asked the same questions again. | Built from the conversations themselves. |
| Meeting data | Where a business enables the meeting agent: the meeting title and agenda, participant names and email addresses taken from the calendar invitation, the transcript, and the summary produced afterwards. | The connected calendar and the meeting itself. |
| Billing data | Billing contact, subscription and plan state, invoice and payment metadata. Card numbers are handled by our payment processor and are never stored on our systems. | Provided by the account holder. |
| Technical data | IP address, browser and device information, and application logs recording that a request happened, how long it took, and whether it failed. | Generated automatically when the service is used. |
We do not ask for, and the platform is not designed to collect, special category information such as health, biometric, racial, religious or political data. A person can of course say anything to an agent, and if they do it is protected and deleted under the same rules as the rest of the conversation.
Message content, transcripts, images and voice notes are never written to our application logs. Logs record that a message or a photo was handled, its type and size, and whether it succeeded — never what it said or showed.
Why we handle it
- To run the conversation: understand what a person said or sent, and produce the agent's reply.
- To deliver messages and calls through the channel the business has connected.
- To keep a conversation continuous, so someone returning to the same business is recognised rather than starting from nothing.
- To transcribe voice notes and calls, and to describe photos and read text in them, so the agent can act on what was sent.
- To give the business analytics and quality review over its own conversations.
- To keep the service secure — detecting abuse, fraud and misuse, and investigating incidents.
- To operate the account: billing, support, and telling account holders about service changes.
- To meet legal obligations, including tax, accounting and lawful requests.
We do not sell personal information. We do not share it with data brokers. We do not use conversation content for advertising or profiling, and we do not use our customers' conversation data to train our own or any third party's general-purpose AI models.
Where we are the controller we rely on: performing our contract with the account holder; our legitimate interest in operating and securing the platform; consent where it is required, such as call recording in places that require it; and our legal obligations. Where we are the processor, the lawful basis for the conversation is the business's to establish.
WhatsApp, Instagram and Messenger
When a business connects its WhatsApp Business account, Instagram professional account or Facebook Page to Voxae, Meta delivers that account's incoming messages to us and we send the agent's replies back through Meta's APIs. We receive only the conversations belonging to the connected business account — never a person's wider Facebook, Instagram or WhatsApp activity, their friends or contacts, or anything outside the message thread with that business.
Information obtained through Meta's platforms is used solely to operate the messaging service for the business whose account it is. We do not sell it, do not use it for advertising or ad targeting, do not use it to build profiles for any purpose other than that business's own customer service, and do not transfer it to anyone except the service providers listed below who process it on our behalf to deliver the service. We handle it in line with Meta's Platform Terms and Developer Policies.
The access token a business grants us is stored encrypted and used only to send and receive that business's messages. A business can disconnect at any time, from inside Voxae or from its own Meta Business settings, which immediately ends our access.
Calls, recordings and transcripts
Calls to and from an agent are transcribed so the agent can understand and respond. Recording is a separate setting, off unless the business turns it on, and the business is responsible for meeting the notice and consent rules of the places it operates in.
Where a recording is redacted, the original audio is a temporary input only: within 24 hours either a redacted version is produced or the original is deleted and no recording is exposed.
AI and automated decisions
Replies are generated by AI models. An agent can also record what it understood — an order, an appointment, a set of details — and pass it to the business's own systems.
Voxae does not make decisions producing legal or similarly significant effects about a person on its own. Agents route, gather and answer; substantive decisions rest with the business. Every business can hand a conversation to a human, and a person can always ask to speak to one.
Where it is processed
The platform and its providers operate across several countries, so personal information may be processed outside the country it was collected in — including in the European Union, the United Kingdom, the United States and the United Arab Emirates. Where information leaves a region with transfer restrictions we rely on the appropriate safeguard for that region, such as the European Commission's standard contractual clauses and the UK addendum. Region-specific detail and the data processing addendum are available on request.
How long it is kept
Conversation content — transcripts, recordings and the analytics derived from them — is kept for 90 days by default and then deleted automatically. Each business can set a shorter or longer window for its own workspace, and can set different windows per category.
- Transcripts, recordings and session analytics: 90 days by default, configurable per workspace.
- Contact records and conversation memory: kept while the contact is active in the business's workspace, and removed when the contact or its memory is erased.
- Raw audio awaiting redaction: deleted within 24 hours if a redacted version is not produced.
- Security and audit logs: 90 days.
- Account and billing records: for the life of the account, and afterwards for as long as tax and accounting law requires.
When an account is closed, its workspace data is deleted within 30 days, except for billing records we are legally required to keep. Backups are overwritten on their own cycle and fully rotated within 35 days.
Deleting your information
Anyone can ask for their information to be deleted, whether or not they have a Voxae account, and there is no charge. Full instructions — what to send us, what gets deleted, and how long it takes — are on the data deletion page.
The short version: email privacy@ash-systems.net from the address you want deleted, or tell us the phone number or handle you used, and name the business you were talking to if you know it. We acknowledge within 5 working days and complete deletion within 30 days.
Your rights
Depending on where you live, you may have the right to ask for a copy of your information, to have it corrected, to have it deleted, to receive it in a portable format, to object to or restrict how it is used, and to withdraw consent you previously gave. Withdrawing consent does not undo what was lawfully done beforehand.
Send any of these to privacy@ash-systems.net. We respond within 30 days. We will ask enough to confirm you are who you say you are — deleting the wrong person's history on an unverified request is its own privacy failure — and no more than that.
We will never treat you differently for exercising these rights. If you are in the European Economic Area or the United Kingdom you can also complain to your local supervisory authority, though we would rather you came to us first.
Children
Voxae is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If a child's information reaches us, tell us at privacy@ash-systems.net and we will delete it.
How it is protected
- Encrypted in transit, and at rest in our databases and object storage.
- Channel access tokens and provider credentials stored encrypted — never in plain text, and never in logs.
- Each workspace's data is separated, and every read is scoped to the workspace it belongs to.
- Role-based access, with multi-factor authentication available on every account.
- Staff access limited to those who need it to run and support the service, and recorded in an audit log.
- Message content, transcripts and media excluded from application logging by design.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires.
Changes to this notice
If we change this notice we update the effective date shown at the top of this page. For changes that materially affect how personal information is used, we notify account holders by email before the change takes effect.
Contact us
For privacy questions, deletion requests and any of the rights above, write to privacy@ash-systems.net. For contracts, the data processing addendum and commercial questions, write to sales@ash-systems.net. Postal enquiries can be addressed to Ash Systems and sent to either address, and we will respond by email.
