Privacy Policy

Last updated: 2 September 2026

Controller

HelpVox Ltd., 1 Demo Street, Sofia 1000, Bulgaria. Data protection contact: privacy@helpvox.ai.

Data we process about vendor accounts

Account details (company name, contact name, email, hashed password), billing records handled by Stripe (we never see full card numbers), product/knowledge/order data you upload, and technical logs needed to operate and secure the service. Legal bases: performance of contract and legitimate interest in service security.

Data we process on vendors' behalf (your customers)

When your customers talk to your AI agent, we process on your behalf: voice recordings and transcripts of the conversations, automated summaries and sentiment analysis, order details (name, phone number, delivery address, purchased items) and delivery tracking events. For this data the vendor is the controller and HelpVox is a processor acting on documented instructions.

Sub-processors

Operating the service involves the following categories of sub-processors:

  • Voice AI and speech processing (ElevenLabs, USA)
  • Telephony carriers (Twilio and regional carrier partners)
  • AI analysis of transcripts (Anthropic, USA)
  • Payments (Stripe)
  • Hosting and databases (Vercel, Neon — EU/US regions)
  • Transactional email (Resend, EU region)

Transfers outside the EEA rely on adequacy decisions or standard contractual clauses.

How long we keep it

Conversation content — recordings, transcripts, automated summaries, the caller's phone number and the details collected during the call — is deleted 12 months after the conversation. What remains is the conversation's duration, channel and outcome, which we need for billing and statistics and which no longer identifies anyone. Order, product and knowledge data belongs to the vendor and is kept while their account is open; 90 days after an account is closed, we delete all of it. A vendor can ask for earlier deletion at any time.

How we protect it

Data is encrypted in transit (TLS) and at rest, and so are our database backups; credentials we hold on a vendor's behalf — shop tokens, API keys — are additionally encrypted with AES-256-GCM before they are written, so they are unreadable even to someone holding a copy of the database. Access to production data is limited to the people who operate the service, is protected by individual accounts with strong password requirements, and is granted only for as long as the work requires. Inside the product, every query is scoped to a single vendor; a platform administrator viewing a vendor's account sees it read-only. Every read of a customer's personal data — by the AI agent, by a person in the dashboard, or through our API — is written to an append-only access log: who, from where, and which order, kept for 12 months.

If something goes wrong

We maintain a written incident response policy: a severity scale, who is responsible at each level, when work escalates, and what has to happen — contain, assess what data was involved, notify. Vendors affected by a confirmed personal-data breach are informed without undue delay and in any case within 72 hours of us becoming aware, with what we know and what we are doing about it. Where the law requires it, we notify the supervisory authority as well.

Cookies

The dashboard uses strictly necessary session cookies only. The marketing site sets no tracking cookies.

Your rights

You may request access, rectification, export or deletion of your personal data at privacy@helpvox.ai. End customers of our vendors should address requests to the respective vendor (the controller); we assist vendors in fulfilling them. You may lodge a complaint with your supervisory authority — in Bulgaria, the Commission for Personal Data Protection (КЗЛД).

Changes

We will announce material changes to this policy by email or in-app notice at least 14 days in advance.

Request a demo

Tell us what you do and how many calls you get. We'll get in touch to show HelpVox with your products or services.