Privacy Policy
How Voxinly collects, uses and protects personal data under UK GDPR and the Privacy and Electronic Communications Regulations.
1. Who is the data controller?
Emberquay Ventures Ltd, a company registered in England and Wales (company number 17278440) whose registered office is 52 Grove Lane, Holt, Norfolk, NR25 6ED, trading as "Voxinly", is the data controller for personal data relating to Voxinly customers and prospective customers (people who sign up, log in, contact support, visit voxinly.com).
For personal data about your customers — the people who chat with the Voxinly widget on your website — you are the data controller and Voxinly is the data processor. The processing of that data is governed by our Data Processing Agreement (DPA) at /legal/dpa.
2. How to contact us about your data
All data-protection enquiries: privacy@voxinly.com (this is monitored and forwarded via ImprovMX to our compliance contact). General contact: hello@voxinly.com.
We are not currently required to appoint a Data Protection Officer (DPO) under Article 37 UK GDPR. Emberquay Ventures Ltd handles privacy enquiries directly through its named privacy contact, reachable at privacy@voxinly.com.
3. What we collect and why
The table below sets out each category of personal data we collect, why we collect it, and the lawful basis on which we rely under Article 6 UK GDPR.
| Data | Why we collect it | Lawful basis | Retention |
|---|---|---|---|
| Name, email, password hash, business name | Create and run your account, send service emails | Performance of a contract (Art 6(1)(b)) | Lifetime of account + 30 days |
| Billing details, VAT number, address | Take payment, issue VAT invoices | Performance of a contract; Legal obligation (Art 6(1)(b), 6(1)(c)) | 7 years from invoice (UK tax) |
| Knowledge-base content you upload | Power the chatbot's answers | Performance of a contract (Art 6(1)(b)) | Lifetime of account + 30 days |
| Chatbot conversations on your sites | Show you the leads; train your account-level prompt tuning | Legitimate interest as processor on your behalf (Art 6(1)(f)) | Lifetime of account, customer can earlier-delete via DSR |
| Server logs, IP, user agent | Security, abuse prevention, debugging | Legitimate interest (Art 6(1)(f)) | 30 days |
| Marketing email signups (newsletter) | Send product updates and tips | Consent (Art 6(1)(a)) | Until you unsubscribe + 30 days |
| Support correspondence | Answer your questions, improve support | Legitimate interest (Art 6(1)(f)) | 3 years from last contact |
We don't collect special-category data (health, biometrics, beliefs etc.) directly. If your customers volunteer such data in chat ("I'm housebound, I need an urgent boiler fix"), we process it on your behalf under your DPA, and you're responsible for the lawful basis for collecting it.
4. Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectify — ask us to correct inaccurate data
- Erase — ask us to delete your data (subject to legal-retention obligations)
- Restrict — pause processing while we resolve a dispute or check accuracy
- Port — receive your data in a structured, machine-readable format
- Object — to processing based on legitimate interest (we'll stop unless we have compelling grounds to continue)
- Withdraw consent — for anything we process under consent (e.g. marketing emails)
- Complain — to the Information Commissioner's Office at ico.org.uk
To exercise any of these rights, email privacy@voxinly.com. We'll respond within one calendar month. There's no charge unless the request is manifestly unfounded or excessive.
5. Cookies and similar technologies
We use cookies on voxinly.com for three purposes: strictly necessary (login session, CSRF), analytics (Vercel Web Analytics, anonymised), and — only with your consent — marketing measurement. Our cookie banner asks for consent the first time you visit. You can change your preferences at any time via the "Cookie preferences" link in the footer.
On customer websites where the Voxinly widget is embedded, the widget itself uses a single first-party cookie (vox_session) to keep the chat going between page loads. This is strictly necessary and falls under the PECR "strictly necessary" exemption — no consent required, but you should disclose it in your own cookie notice.
6. Subprocessors
We rely on the following subprocessors to deliver Voxinly. Each is contractually bound to UK-GDPR-equivalent terms and provides Standard Contractual Clauses where international transfers apply.
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Hosting (Next.js app, edge functions) | USA (UK/EU edge cache) | UK IDTA / EU SCCs |
| Supabase Inc. | Database, authentication, file storage | EU (eu-west-2) primary region | UK GDPR adequacy (data in EU) |
| Cloudflare Inc. | CDN, DDoS protection, embed-widget worker | Global edge (UK PoPs preferred) | UK IDTA / EU SCCs |
| Anthropic, PBC | LLM inference for chatbot responses | USA | UK IDTA + DPA |
| Resend Inc. | Transactional and marketing email | USA / EU | UK IDTA / EU SCCs |
| Stripe Payments UK Ltd | Card processing | UK / EU / USA | Stripe SCCs; controller-controller |
We'll give you 30 days' notice by email before adding a new subprocessor that processes customer-facing data. You can object via privacy@voxinly.com.
7. International transfers
Customer-facing chat data is stored in the EU (Supabase eu-west-2) by default. Where data is transferred to the USA (Vercel, Anthropic, Cloudflare control plane, Resend) we rely on the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, supplemented by technical measures (encryption in transit, encryption at rest with EU-managed keys for sensitive fields).
8. Security
We protect personal data with: TLS 1.2+ for all data in transit; encryption at rest for the production database; least-privilege access controls; logging and intrusion-detection on the application layer; mandatory MFA for any internal access to production. Passwords are stored as Argon2 hashes — we cannot read them and don't store them in clear.
If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we'll notify you and the ICO within 72 hours of becoming aware, in line with Article 33 UK GDPR.
9. Children
Voxinly is a B2B service intended for use by businesses. We do not knowingly collect data from anyone under 13. If you believe we have, email privacy@voxinly.com and we'll delete it.
10. Changes to this Policy
We'll post material changes at the top of this page and email registered customers at least 14 days before they take effect. The "Last updated" date below tells you the current version.
11. Contact and complaints
Email privacy@voxinly.com with any question. If you're not satisfied with our response, you can complain to the Information Commissioner's Office (ICO): ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.