Privacy Policy
Privacy policy of Voico GmbH for the Voico website and the Voico platform. Last updated: 10 August 2025.
Part 1: Privacy for the Voico Website
1. Controller and Data Protection Officer
Controller (Art. 4 No. 7 GDPR):
Voico GmbH, Weikenrott 19, 46499 Hamminkeln, Germany. Represented by the Managing Director Dean Koenning.
Data Protection Officer:
We have appointed an external data protection officer. You can reach him at: Felix Freyberg, support@voico.ai.
2. General Information on Data Processing
We take the protection of your personal data very seriously. We process personal data only to the extent necessary and in accordance with the statutory provisions (GDPR, BDSG, TMG/TTDSG). This privacy policy explains the type, scope and purpose of the processing of personal data on our public website.
Legal bases: Unless stated otherwise below, processing is based on Art. 6 (1) GDPR — depending on the purpose, in particular on our legitimate interest (lit. f) in the operation and security of the website, on the performance of a contract or pre-contractual measures (lit. b), or on your consent (lit. a) — as well as in compliance with the TTDSG for access to end devices.
Your rights: As a data subject under the GDPR you have in particular the following rights: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR). You also have the right to lodge a complaint with a supervisory authority (in particular the competent state data protection authority) (Art. 77 GDPR).
3. Provision of the Website and Server Log Files
Each time our website is accessed, our web server automatically processes the following data: IP address of the requesting device, date and time of the request, time zone, specific page/file requested, HTTP status code, amount of data transferred, referrer URL, and information about the browser and operating system used.
Purpose: Temporary storage is necessary to deliver the website to your device and to ensure the functionality and security of the website.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and uninterrupted operation of the website).
Retention period: IP addresses in log files are anonymized or deleted as soon as they are no longer required for the purpose. Storage in personally identifiable form lasts a maximum of 7 days.
Our hosting takes place in the OTC Cloud of Deutsche Telekom — certified German infrastructure. A data processing agreement is in place with the provider. No transfer to a third country takes place.
4. Use of Cookies and Tracking Technologies
Our website uses cookies and similar technologies. On your first visit to the website, we ask for your consent to non-essential cookies/tracking via a cookie banner. Technically necessary cookies are set without your consent (Art. 6 (1) lit. f GDPR). Non-essential cookies are only set with your prior consent (Art. 6 (1) lit. a GDPR in conjunction with § 25 (1) TTDSG).
If you consent, we may use the following external services:
- Web analytics (e.g. Google Analytics or Matomo): To improve our website we collect pseudonymized visitor data. With Google Analytics, your IP address is anonymized before evaluation. Third-country transfer to the USA; safeguarded by EU standard contractual clauses. Legal basis: consent.
- Marketing and remarketing services (e.g. LinkedIn Insight Tag, Google Ads): If you agree, we may use pixels or cookies from these platforms. Google Ads is used exclusively for conversion measurement (e.g. whether a contact request followed an ad click) — not to build user profiles or for interest-based retargeting based on Google account data. These services do not receive any data from Google user accounts. Third-country transfer to the USA where applicable; safeguarded by EU standard contractual clauses. Legal basis: consent.
Note on the use of Google APIs:Where Voico uses services via Google APIs (e.g. Google Sign-In or Google Cloud AI Services), the data received through them is used exclusively to provide and improve Voico's core services. Voico's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, retargeting or interest-based marketing and is not shared with third parties for these purposes.
You can change your cookie settings on our website at any time (link "Cookie Settings" in the footer). If you have enabled your browser's "Do Not Track" feature, we respect this and automatically disable all non-essential trackers.
5. Newsletter
On our website you have the option to subscribe to our email newsletter. We use a double opt-in process: after subscribing, you receive an email with a confirmation link.
Purpose: Sending the newsletter with information about our products, offers and news from Voico.
Legal basis:Art. 6 (1) lit. a GDPR (consent via double opt-in confirmation). You can withdraw your consent at any time by clicking the "unsubscribe" link in any newsletter or by sending a message to newsletter@voico.ai.
Sending provider: We currently use Sendinblue (Sendinblue GmbH, Germany) for email delivery. A GDPR-compliant data processing agreement is in place with the sending provider. Data is processed on European servers.
Retention period: The data stored for the newsletter is kept until you unsubscribe from the newsletter. Registration log data is retained for a maximum of 24 months on the basis of Art. 6 (1) lit. f GDPR.
6. Contacting Us (Contact Form, Email, Phone)
When you get in touch with us (e.g. via the web contact form, email or phone), we process the personal data you provide: e.g. your name, your email address, phone number and the content of your inquiry.
Legal basis: Depending on the type of inquiry, Art. 6 (1) lit. b GDPR (pre-contractual measures or contract performance) or Art. 6 (1) lit. f GDPR (legitimate interest in communicating with inquirers).
Retention period: We delete inquiries and correspondence as soon as they are no longer required to fulfil the purpose. Business correspondence belonging to a contractual relationship is stored in accordance with the statutory retention periods (usually 6 to 10 years under commercial and tax law).
7. Embedded Content and External Links
Embedded content:Our website may embed third-party content, e.g. videos (YouTube/Vimeo) or maps. Embedding this content technically sends your IP address to the third-party provider. Wherever possible, we use privacy-friendly defaults. Please refer to the respective provider's privacy policy for details.
Social media links: Our website may contain links to our presences on social networks (e.g. LinkedIn). These are integrated as simple links. No automatic data transfer to the platform operators takes place merely by displaying our website.
8. Security
We take technical and organizational security measures to protect your personal data against loss, misuse, unauthorized access or disclosure. These include encrypting the website connection (TLS/SSL) and access restrictions to our servers.
9. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy as needed, for example as the website evolves or legal requirements change. The version current at the time of your visit applies.
Part 2: Privacy for the Voico Platform
1. Introduction and Scope
This privacy policy explains how Voico GmbH processes personal data when you use our Voico web platform and AI voice agent services. It is addressed in particular to our customers and users of the Voico service and — for information — to persons whose data is processed in the course of use by our customers (e.g. callers, call participants).
Important: Voico provides a service that enables our customers to automate telephone calls using AI-powered voice assistance. In doing so, Voico processes data itself as a controller (e.g. customer data for account management) and also processes personal data on behalf of the customer (Art. 28 GDPR) — in particular data arising during telephone calls and integrations — with the customer remaining the controller under data protection law and Voico acting as a processor. We conclude a data processing agreement (DPA) with every customer.
2. Processed Data Categories and Purposes (Voico as Controller)
When using the Voico platform, we process various categories of personal data:
- Registration and account data: name, company name, address, email address, phone number, login credentials and, where applicable, payment information. Legal basis: Art. 6 (1) lit. b GDPR (user contract).
- Usage and metadata of the platform: logins (time, user ID, IP address), actions performed, API calls and system events. Legal bases: Art. 6 (1) lit. b and lit. f GDPR.
- Billing data: booked plan details, usage volumes, invoicing, payment status. Legal basis: Art. 6 (1) lit. b and lit. c GDPR.
- Support and communication data: when contacting support: contact details, problem description and, where applicable, log files. Legal basis: Art. 6 (1) lit. b or lit. f GDPR.
- Publicly available reference information: with your consent, we may publish your company name or short customer feedback. Legal basis: Art. 6 (1) lit. a GDPR.
3. Processing in the Course of Service Provision (Voico as Processor)
When our customers use the Voico AI voice agents, the following data is processed for which the customer is the controller and Voico is the instruction-bound processor:
- Telecommunications connection data: phone numbers of the parties involved, start and end time of the call, duration, technical events. This traffic data is subject to telecommunications secrecy (§ 3 TTDSG).
- Call content and recordings: voice content is processed to enable the AI agent (speech-to-text, AI analysis, text-to-speech). By default, neither audio recordings nor transcriptions are stored permanently — unless the customer explicitly activates the call recording or transcription function. Recording may only take place with the consent of all call participants. Voico does not use call content for its own purposes, in particular not for AI training outside the respective customer tenant.
- Integration of knowledge data and third-party systems: The Voico platform allows the connection of knowledge databases and third-party systems (e.g. CRM). The responsibility for the lawfulness of the data exchange with the third-party provider lies with the customer.
- Automated decisions: the Voico AI agents make automated decisions within the defined dialogue flows (e.g. call forwarding, appointment scheduling). As a rule, these have no legal or similarly significant effects on the data subjects. The customer must ensure that data subjects are informed about the use of AI and can request a human where applicable.
4. Legal Bases for Data Processing (Platform)
For data for which Voico is the controller, the following legal bases apply:
- Contract performance (Art. 6 (1) lit. b GDPR): processing of your account data, connection and usage data and all information required to provide the service under the user contract.
- Legal obligations (Art. 6 (1) lit. c GDPR): retention of invoice data, provision of information to law enforcement authorities in accordance with TKG/StPO, compliance with telecommunications laws.
- Legitimate interests (Art. 6 (1) lit. f GDPR): security of the platform (logging, monitoring), improvement of our services and customer communication.
- Consent (Art. 6 (1) lit. a GDPR): in certain cases, e.g. for recording calls for training purposes or publishing customer testimonials.
5. Recipients of Data and Disclosure
Within Voico, only those employees have access to personal data who need it to fulfil our contractual obligations (need-to-know principle). All employees are bound to confidentiality; call content is additionally subject to telecommunications secrecy.
Key external processors (subcontractors) are:
- Data center and cloud providers (Deutsche Telekom OTC Cloud, Germany) — server hosting within the EEA.
- Telecommunications service providers (carriers) — for terminating and receiving calls; subject to telecommunications secrecy.
- AI and speech technology providers — speech recognition and synthesis preferably via EU-based services (e.g. Microsoft Azure AI Services in EU data centers). AI services do not use the data for their own model training; this is contractually agreed.
- Email/notification service (e.g. Sendinblue, Germany) — for system emails.
- Payment processing (e.g. Stripe or BS Payone) — receive the necessary payment data; Voico itself does not store credit card numbers.
A data processing agreement pursuant to Art. 28 GDPR is in place with all named service providers. A list of the current sub-processors is made available to customers on request.
6. Retention Periods and Deletion Concept
- Account data: upon contract termination, master and contact data is initially kept for the duration of the notice period and deleted afterwards. Accounting data is archived for the legally required period (usually 6 or 10 years).
- Usage and connection data: log data in the admin interface is retained for 12 months. Traffic data (who called whom and when) is stored for a maximum of 6 months for billing and verification purposes.
- Call recordings/transcripts: if activated, these can remain stored in the customer account until the customer deletes them. By default, a maximum retention of 90 days is set. The customer can manually delete recordings at any time.
- Support tickets: generally stored for as long as you are an active customer. After the end of the contract, support data is usually deleted after 1–2 years.
- Backups: regular encrypted backups with a rolling retention window of typically 7–14 days.
7. Data Subject Rights and Support by Voico
You can exercise your rights as a customer/user of our platform (access, rectification, erasure etc.) at any time via support@voico.ai. You can view and change much of your basic data yourself in your customer account.
If you are an end customer of one of our customers (e.g. a caller who spoke with a Voico system), your primary point of contact is not Voico but the company you called. However, you are welcome to contact us as well — we will forward your request to our customer and support them in handling it (Art. 28 (3) lit. e GDPR).
8. Data Security and Confidentiality
The Voico platform is operated using high security standards. We use modern encryption (TLS) for all data transmissions. All stored data is located on secure servers within the EU. Voico has implemented extensive technical and organizational measures (TOM), including access control systems, regular security updates, penetration tests, logging and an authorization concept. Call data and confidential content is internally classified as confidential; all processing is subject to telecommunications secrecy and contractual confidentiality obligations.
9. Changes to the Privacy Information (Platform)
As we continuously develop our services, it may become necessary to adapt this privacy policy. We inform our customers about material changes (e.g. by email or at login) and make the updated version available on our website.
Last updated: 10 August 2025