Privacy Policy

Vocito.ai · AI Voice Receptionist Platform

Data Controller: Vocito.ai B.V., registered in the Netherlands
Last Updated: May 2026
Effective Date: May 2026
Contact: privacy@vocito.ai

Table of Contents

  1. Introduction
  2. Data Controller
  3. Scope of This Policy
  4. Data We Collect
  5. Legal Basis for Processing
  6. How We Use Your Data
  7. Call Recording and Transcription
  8. AI Processing and EU AI Act
  9. Sub-Processors
  10. International Data Transfers
  11. Data Retention
  12. Your Rights
  13. Cookie Policy
  14. Data Security
  15. Children's Privacy
  16. Third-Party Links
  17. Changes to This Policy
  18. Contact Us

1. Introduction

Vocito.ai B.V. ("Vocito", "we", "us", or "our") is committed to protecting the privacy and personal data of our customers, their end users, and visitors to our website. This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the Vocito platform and related services.

Beta period notice (May 2026 – GA): Vocito is currently in Beta. During this period, call recordings, transcripts, and AI-generated conversation metadata are retained for 90 days by default (vs. the longer GA retention windows in Section 11). Aggregated, anonymized Beta usage data may be analyzed to improve the Service. We do not sell personal data and we do not share PII with third parties for marketing purposes. You may export or delete your data at any time via the dashboard.

We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), the EU AI Act (Regulation (EU) 2024/1689), and other applicable data protection laws.

2. Data Controller

2.1 Vocito as Controller

For personal data related to customer accounts, website visitors, and marketing, Vocito.ai B.V. is the data controller within the meaning of Article 4(7) GDPR.

2.2 Vocito as Processor

For personal data processed on behalf of our customers through the Service (including call recordings, transcripts, lead data, SMS, and email communications), Vocito acts as a data processor on behalf of the customer, who is the data controller. The processing relationship is governed by our Data Processing Agreement.

2.3 Controller Contact Details

3. Scope of This Policy

This Privacy Policy applies to:

4. Data We Collect

4.1 Account and Registration Data

Data CategoryExamplesPurpose
Identity dataFull name, business name, job titleAccount creation, identification
Contact dataEmail address, phone number, business addressCommunication, service delivery
Authentication dataPassword (hashed), SSO tokensAccount security
Billing dataPayment method details, billing address, invoicesSubscription management, payment processing
Business dataCompany size, industry, operating hours, services offeredAI agent configuration

4.2 Call and Communication Data

Data CategoryExamplesPurpose
Call recordingsAudio files of inbound phone callsService delivery, quality assurance
Call transcriptsText transcriptions of recorded callsLead extraction, review, analytics
Call metadataCaller ID, call duration, timestamp, call statusService delivery, analytics
SMS messagesContent of sent/received text messagesFollow-up communications
Email dataEmail addresses, subject lines, email content (via Gmail/Microsoft 365 integration)Email notifications, lead management

4.3 Lead and CRM Data

Data CategoryExamplesPurpose
Lead informationName, phone number, email, inquiry detailsLead management for customers
Booking dataAppointment dates, times, service typesScheduling on behalf of customers
CRM recordsCustomer interaction history, notes, tagsRelationship management

4.4 Usage and Technical Data

Data CategoryExamplesPurpose
Usage dataFeatures used, call volumes, login history, dashboard interactionsService improvement, analytics
Device and browser dataIP address, browser type, operating system, screen resolutionSecurity, compatibility, analytics
Log dataServer logs, error logs, API request logsDebugging, security monitoring
Cookie dataSession cookies, analytics cookiesSee Cookie Policy section

4.5 Special Categories of Data

Vocito does not intentionally collect special categories of personal data (Article 9 GDPR), such as health data, biometric data, or data revealing racial or ethnic origin. However, callers may voluntarily disclose such information during phone calls. Customers are responsible for implementing appropriate safeguards if their business context is likely to involve special category data.

We process personal data based on the following legal grounds under Article 6(1) GDPR:

Processing ActivityLegal BasisGDPR Article
Providing the Service to customersPerformance of a contractArt. 6(1)(b)
Processing customer data on behalf of customersPerformance of a contract (DPA)Art. 6(1)(b)
Billing and payment processingPerformance of a contractArt. 6(1)(b)
Call recording (platform level)Legitimate interest / Consent (managed by customer)Art. 6(1)(f) / Art. 6(1)(a)
Security monitoring and fraud preventionLegitimate interestArt. 6(1)(f)
Service improvement and analyticsLegitimate interestArt. 6(1)(f)
Marketing communicationsConsentArt. 6(1)(a)
Compliance with legal obligationsLegal obligationArt. 6(1)(c)
Responding to data subject requestsLegal obligationArt. 6(1)(c)

6. How We Use Your Data

We use personal data for the following purposes:

7. Call Recording and Transcription

7.1 How Calls Are Processed

When an inbound call is received by a Vocito AI Agent:

  1. The call is routed through Twilio's telephony infrastructure.
  2. The caller hears a disclosure that they are speaking with an AI assistant and that the call may be recorded.
  3. The call audio is processed in real-time by ElevenLabs (voice AI) and Anthropic/Google/OpenAI (language models) to generate responses.
  4. The call is recorded and stored in Supabase (EU region).
  5. The recording is transcribed and analyzed to extract lead information.

7.2 Consent for Recording

Each Vocito AI Agent is configured to inform callers that the call may be recorded and transcribed at the beginning of the conversation. By continuing the call after this disclosure, the caller provides implied consent for recording. Customers (as data controllers) are responsible for ensuring this consent mechanism complies with the laws of their jurisdiction.

7.3 Recording Storage and Access

Call recordings and transcripts are stored in Supabase infrastructure in the EU region. Access is restricted to the Customer who owns the AI Agent configuration and authorized Vocito support personnel (only when necessary for technical support).

8. AI Processing and EU AI Act Transparency

In accordance with Article 50 of the EU AI Act, we provide the following transparency information:

9. Sub-Processors

Vocito engages the following sub-processors to deliver the Service. We require all sub-processors to enter into data processing agreements that ensure an equivalent level of data protection.

Sub-ProcessorPurposeData ProcessedLocation
Twilio Inc. Telephony infrastructure, voice routing, SMS delivery Phone numbers, call audio (real-time), call metadata, SMS content USA (EU routing available); SCCs in place
ElevenLabs Inc. AI voice synthesis, speech-to-text Call audio (real-time streaming for voice generation) USA; SCCs in place
Anthropic PBC Large language model (Claude) for conversation understanding and response generation Call transcripts (real-time), conversation context USA; SCCs in place
Google LLC Large language model (Gemini) for conversation processing Call transcripts (real-time), conversation context USA / EU; SCCs in place
OpenAI Inc. Large language model (GPT) for conversation processing Call transcripts (real-time), conversation context USA; SCCs in place
Supabase Inc. Database hosting, file storage, authentication All Customer Data (account data, call recordings, transcripts, leads, CRM data) EU (Frankfurt region)
Railway Corp. Backend application hosting Application data in transit and processing EU region

We maintain an up-to-date list of sub-processors. Customers subscribed to our service will be notified at least 30 days in advance of any new sub-processor being engaged, providing the customer the opportunity to object.

10. International Data Transfers

10.1 Primary Data Storage

Customer Data is primarily stored in the European Union using Supabase infrastructure located in the Frankfurt (EU) region.

10.2 Transfers to Third Countries

Some of our sub-processors are based in the United States, which means personal data may be transferred outside the European Economic Area ("EEA"). For each transfer, we rely on one or more of the following safeguards:

10.3 Transfer Impact Assessments

Vocito conducts transfer impact assessments for each international transfer to evaluate whether the legal framework of the recipient country provides adequate protection for personal data. These assessments are reviewed periodically and updated as needed.

11. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

Data CategoryRetention PeriodBasis
Account dataDuration of the account + 30 days after deletionContract performance
Call recordings90 days from call date (default; configurable by customer)Service delivery, customer configuration
Call transcriptsDuration of the account (default; configurable by customer)Service delivery
Lead and CRM dataDuration of the account + 30 daysService delivery
SMS messages90 days from send dateService delivery
Billing data7 years after the transactionDutch fiscal retention obligations
Usage and log data12 monthsSecurity, analytics
Marketing consent recordsDuration of consent + 3 yearsLegal compliance
Cookie dataSee Cookie Policy sectionConsent

Customers may configure shorter retention periods for call recordings and transcripts through the dashboard. Upon account termination, Customer Data is deleted within 30 days unless a longer retention period is required by law.

12. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

12.1 Right of Access (Art. 15)

You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about the processing.

12.2 Right to Rectification (Art. 16)

You have the right to request correction of inaccurate personal data and completion of incomplete data.

12.3 Right to Erasure (Art. 17)

You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, you withdraw consent, or another ground under Article 17 applies. This right is subject to exceptions, such as legal retention obligations.

12.4 Right to Restriction (Art. 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.

12.5 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV) and to transmit it to another controller.

12.6 Right to Object (Art. 21)

You have the right to object to processing based on legitimate interest (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests. You have an absolute right to object to processing for direct marketing purposes.

12.7 Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

12.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for Vocito.ai B.V. is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority):

12.9 Exercising Your Rights

To exercise any of these rights, contact us at privacy@vocito.ai. We will respond to your request within 30 days. If we need more time (up to an additional 60 days), we will inform you of the extension and the reasons for the delay. We may request additional information to verify your identity before fulfilling your request.

12.10 End Users (Callers)

If you are a caller who interacted with a Vocito-powered AI Agent, your personal data is controlled by the business that deployed the AI Agent. Please contact that business directly to exercise your data protection rights. If you are unable to identify or reach the business, you may contact us at privacy@vocito.ai and we will assist in directing your request.

13. Cookie Policy

13.1 What Are Cookies

Cookies are small text files placed on your device when you visit our website. We use cookies and similar technologies to operate the website, analyze usage, and improve your experience.

13.2 Types of Cookies We Use

Cookie TypePurposeDurationLegal Basis
Strictly necessaryAuthentication, security, session managementSession / up to 30 daysLegitimate interest (no consent required)
FunctionalRemembering preferences, language settingsUp to 12 monthsConsent
AnalyticsUnderstanding usage patterns, page views, feature adoptionUp to 12 monthsConsent

13.3 Managing Cookies

You can manage your cookie preferences through the cookie banner displayed when you first visit our website. You can also control cookies through your browser settings. Note that disabling strictly necessary cookies may impair the functionality of the Service.

13.4 Third-Party Cookies

We do not use third-party advertising cookies. We may use analytics tools that set their own cookies, subject to your consent.

14. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

15. Children's Privacy

The Vocito Service is a business-to-business platform and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that data promptly. If you believe we have collected data from a child, please contact us at privacy@vocito.ai.

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

We encourage you to review this policy periodically. Your continued use of the Service after the effective date of a revised policy constitutes acceptance of the changes.

18. Contact Us

If you have questions or concerns about this Privacy Policy or our data processing practices, please contact us:

For formal data protection inquiries or to exercise your rights, please email privacy@vocito.ai with the subject line "Data Protection Request".