GDPR Compliance

Last updated: January 2025

GDPR Overview

VoiceHub is committed to full compliance with the General Data Protection Regulation (GDPR), the EU's comprehensive data protection law. We process personal data lawfully, fairly, and transparently, and we respect the rights of all data subjects. This page outlines our GDPR compliance measures and your rights under the regulation.

Lawful Basis for Processing

We process personal data under the following lawful bases as defined in Article 6 of the GDPR:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
  • Contract: Processing is necessary for the performance of a contract with you (e.g., providing our services)
  • Legal Obligation: Processing is necessary to comply with legal obligations (e.g., tax records, regulatory requirements)
  • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, network security)

Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

Right to Access (Article 15)

You have the right to request a copy of all personal data we hold about you. We will provide this within 30 days in a structured, commonly used format.

Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data without undue delay.

Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when there is no compelling reason for us to continue processing it.

Right to Restrict Processing (Article 18)

You have the right to request that we limit the processing of your personal data in certain circumstances.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a machine-readable format and transmit it to another controller.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent (Article 7)

Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) as required by Article 37 of the GDPR. Our DPO oversees our data protection strategy and GDPR compliance.

  • DPO Contact: dpo@voicehub.ai
  • Responsibilities: Monitoring compliance, training staff, conducting audits, serving as point of contact for supervisory authorities

International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place as required by Chapter V of the GDPR:

  • Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses for data transfers to third countries
  • Adequacy Decisions: We transfer data to countries deemed adequate by the EU Commission
  • Binding Corporate Rules: For intra-group transfers within our organization
  • Additional Safeguards: Encryption, access controls, and transfer impact assessments

Data Breach Procedures

We have implemented comprehensive data breach procedures in accordance with Articles 33 and 34 of the GDPR:

  • Detection and Assessment: 24/7 monitoring systems to detect potential breaches immediately
  • Notification to Supervisory Authority: Within 72 hours of becoming aware of a breach (when applicable)
  • Notification to Data Subjects: Without undue delay if the breach is likely to result in high risk to rights and freedoms
  • Documentation: All breaches are documented, including facts, effects, and remedial actions

Privacy by Design and by Default

In accordance with Article 25 of the GDPR, we implement privacy by design and by default principles. Our services are designed with data protection built-in from the ground up. We collect only the minimum data necessary (data minimization), use pseudonymization and encryption by default, and ensure that personal data is not made publicly accessible without explicit action. Our technical and organizational measures are regularly reviewed and updated.

Data Protection Impact Assessment

We conduct Data Protection Impact Assessments (DPIAs) as required by Article 35 for processing operations that are likely to result in high risk to individual rights. Our DPIAs systematically describe processing operations, assess necessity and proportionality, evaluate risks to data subjects, and outline measures to mitigate those risks. DPIAs are reviewed and updated regularly, especially when there are changes to processing activities.

Data Processor Agreements

When we engage third-party processors, we ensure GDPR-compliant processor agreements are in place as required by Article 28:

  • Processors only process data on our documented instructions
  • All processors sign confidentiality commitments
  • Appropriate security measures are implemented and verified
  • Sub-processors are only engaged with our prior authorization
  • We conduct regular audits of processor compliance

Data Retention Policy

We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy:

  • Voice Conversation Data: 90 days (configurable, minimum 30 days for quality assurance)
  • Account Data: Duration of subscription + 12 months after cancellation
  • Billing Records: 7 years (legal requirement for financial records)
  • Marketing Data: Until consent is withdrawn or 2 years of inactivity
  • Logs and Technical Data: 12 months for security and troubleshooting

How to Exercise Your Rights

You can exercise your GDPR rights by contacting us through any of the following methods:

  • Email: privacy@voicehub.ai or dpo@voicehub.ai
  • Account Settings: Manage your data directly through your VoiceHub account dashboard
  • Mail: VoiceHub Data Protection Officer, 123 Market Street, San Francisco, CA 94103

We will respond to your request within 30 days. In complex cases, we may extend this by an additional 60 days and will notify you of the extension. We may request additional information to verify your identity before processing your request.

Filing Complaints

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or where an alleged infringement occurred. While we encourage you to contact us first to resolve any concerns, you may file a complaint with your local data protection authority at any time. A list of EU supervisory authorities can be found at: https://edpb.europa.eu/about-edpb/board/members_en