Voxinly
Legal

Privacy Policy

How Voxinly collects, uses and protects personal data under UK GDPR and the Privacy and Electronic Communications Regulations.

Last updated: 29 June 2026·Version 1.0

1. Who is the data controller?

Emberquay Ventures Ltd, a company registered in England and Wales (company number 17278440) whose registered office is 52 Grove Lane, Holt, Norfolk, NR25 6ED, trading as "Voxinly", is the data controller for personal data relating to Voxinly customers and prospective customers (people who sign up, log in, contact support, visit voxinly.com).

For personal data about your customers — the people who chat with the Voxinly widget on your website — you are the data controller and Voxinly is the data processor. The processing of that data is governed by our Data Processing Agreement (DPA) at /legal/dpa.

2. How to contact us about your data

All data-protection enquiries: privacy@voxinly.com (this is monitored and forwarded via ImprovMX to our compliance contact). General contact: hello@voxinly.com.

We are not currently required to appoint a Data Protection Officer (DPO) under Article 37 UK GDPR. Emberquay Ventures Ltd handles privacy enquiries directly through its named privacy contact, reachable at privacy@voxinly.com.

3. What we collect and why

The table below sets out each category of personal data we collect, why we collect it, and the lawful basis on which we rely under Article 6 UK GDPR.

DataWhy we collect itLawful basisRetention
Name, email, password hash, business nameCreate and run your account, send service emailsPerformance of a contract (Art 6(1)(b))Lifetime of account + 30 days
Billing details, VAT number, addressTake payment, issue VAT invoicesPerformance of a contract; Legal obligation (Art 6(1)(b), 6(1)(c))7 years from invoice (UK tax)
Knowledge-base content you uploadPower the chatbot's answersPerformance of a contract (Art 6(1)(b))Lifetime of account + 30 days
Chatbot conversations on your sitesShow you the leads; train your account-level prompt tuningLegitimate interest as processor on your behalf (Art 6(1)(f))Lifetime of account, customer can earlier-delete via DSR
Server logs, IP, user agentSecurity, abuse prevention, debuggingLegitimate interest (Art 6(1)(f))30 days
Marketing email signups (newsletter)Send product updates and tipsConsent (Art 6(1)(a))Until you unsubscribe + 30 days
Support correspondenceAnswer your questions, improve supportLegitimate interest (Art 6(1)(f))3 years from last contact

We don't collect special-category data (health, biometrics, beliefs etc.) directly. If your customers volunteer such data in chat ("I'm housebound, I need an urgent boiler fix"), we process it on your behalf under your DPA, and you're responsible for the lawful basis for collecting it.

4. Your rights

Under UK GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you
  • Rectify — ask us to correct inaccurate data
  • Erase — ask us to delete your data (subject to legal-retention obligations)
  • Restrict — pause processing while we resolve a dispute or check accuracy
  • Port — receive your data in a structured, machine-readable format
  • Object — to processing based on legitimate interest (we'll stop unless we have compelling grounds to continue)
  • Withdraw consent — for anything we process under consent (e.g. marketing emails)
  • Complain — to the Information Commissioner's Office at ico.org.uk

To exercise any of these rights, email privacy@voxinly.com. We'll respond within one calendar month. There's no charge unless the request is manifestly unfounded or excessive.

5. Cookies and similar technologies

We use cookies on voxinly.com for three purposes: strictly necessary (login session, CSRF), analytics (Vercel Web Analytics, anonymised), and — only with your consent — marketing measurement. Our cookie banner asks for consent the first time you visit. You can change your preferences at any time via the "Cookie preferences" link in the footer.

On customer websites where the Voxinly widget is embedded, the widget itself uses a single first-party cookie (vox_session) to keep the chat going between page loads. This is strictly necessary and falls under the PECR "strictly necessary" exemption — no consent required, but you should disclose it in your own cookie notice.

6. Subprocessors

We rely on the following subprocessors to deliver Voxinly. Each is contractually bound to UK-GDPR-equivalent terms and provides Standard Contractual Clauses where international transfers apply.

SubprocessorPurposeLocationTransfer mechanism
Vercel Inc.Hosting (Next.js app, edge functions)USA (UK/EU edge cache)UK IDTA / EU SCCs
Supabase Inc.Database, authentication, file storageEU (eu-west-2) primary regionUK GDPR adequacy (data in EU)
Cloudflare Inc.CDN, DDoS protection, embed-widget workerGlobal edge (UK PoPs preferred)UK IDTA / EU SCCs
Anthropic, PBCLLM inference for chatbot responsesUSAUK IDTA + DPA
Resend Inc.Transactional and marketing emailUSA / EUUK IDTA / EU SCCs
Stripe Payments UK LtdCard processingUK / EU / USAStripe SCCs; controller-controller

We'll give you 30 days' notice by email before adding a new subprocessor that processes customer-facing data. You can object via privacy@voxinly.com.

7. International transfers

Customer-facing chat data is stored in the EU (Supabase eu-west-2) by default. Where data is transferred to the USA (Vercel, Anthropic, Cloudflare control plane, Resend) we rely on the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, supplemented by technical measures (encryption in transit, encryption at rest with EU-managed keys for sensitive fields).

8. Security

We protect personal data with: TLS 1.2+ for all data in transit; encryption at rest for the production database; least-privilege access controls; logging and intrusion-detection on the application layer; mandatory MFA for any internal access to production. Passwords are stored as Argon2 hashes — we cannot read them and don't store them in clear.

If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we'll notify you and the ICO within 72 hours of becoming aware, in line with Article 33 UK GDPR.

9. Children

Voxinly is a B2B service intended for use by businesses. We do not knowingly collect data from anyone under 13. If you believe we have, email privacy@voxinly.com and we'll delete it.

10. Changes to this Policy

We'll post material changes at the top of this page and email registered customers at least 14 days before they take effect. The "Last updated" date below tells you the current version.

11. Contact and complaints

Email privacy@voxinly.com with any question. If you're not satisfied with our response, you can complain to the Information Commissioner's Office (ICO): ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.