Legal
Privacy Policy
Effective 13 July 2026 · Version 1.0
1. Who we are, and the two roles we play
Whizz Voice is operated by Whizz Tech, Office 218, Binghatti Azure, JVC, Dubai, UAE. Contact: support@whizztech.ai.
Whizz Voice lets our customers — businesses — build AI voice agents that handle phone and web calls with their own callers. Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies, the GDPR, we wear two hats:
- Controller — for the account data of our customers (the organizations using the dashboard and API).
- Processor — for the content of the calls their agents handle. The customer that configured and deployed the agent is the controller of the personal data in those calls (its callers' voices and words); we process that data on their documented instructions. If you spoke to a Whizz Voice-powered agent, your first point of contact for access or deletion is the company you called — but you can also write to us and we will route the request and assist (see Section 8).
2. What we collect
From customers (organizations):
- Account data — email (one-time-passcode sign-in), organization name, plan and billing details.
- Agent configuration — personas, first messages, tools, knowledge-base content, voice and dialect choices, consent and disclosure settings, webhook endpoints.
- Usage data — API request logs, per-minute metering records, call metadata, and standard server logs (IP address, user agent) kept for security and billing.
Inside calls (processed for the customer):
- Call audio — the streamed conversation, and a recording only when the customer has recording enabled.
- Transcripts — diarized text with speaker labels and timestamps, in the call's language and dialect.
- Tool inputs and outputs — the arguments the agent passed to your functions and what came back, as needed to complete the task.
- Call outcomes — summary, sentiment, disposition, and any structured data your agent was configured to capture.
We do not run third-party advertising or analytics trackers on this site. Cookies are limited to what sign-in and language preference require.
3. Consent, recording, and AI disclosure
Whether a call may be recorded, and whether the agent must state that it is an AI, are controlled by the customer in each agent's configuration — and the platform provides gates to enforce both:
- AI disclosure. Agents can be required to disclose that the caller is speaking with an automated system; this gate is on by default.
- Recording consent. When recording is enabled, the agent can be required to announce it and capture consent before anything is stored, with the moment logged against the call.
- Zero-retention. Customers may run agents in a zero-retention mode where audio and transcripts are processed in-memory for the live call and not persisted.
The lawful basis for recording and for calling a given person rests with the customer, who warrants in our Terms that it has one.
4. How we use it
- To operate the service: run the customer's voice agents — recognize speech, reason, synthesize dialect-native replies, call the customer's tools, and return transcripts and outcomes via dashboard, API, and webhooks.
- To bill accurately: per-minute usage metering and pass-through telephony at cost.
- To secure the platform: abuse prevention, rate limiting, audit logs.
- To communicate: sign-in codes and service notices.
We do not sell personal data. We do not use call audio, transcripts, or outcomes to train models — content is sent to our model and speech providers solely to produce the customer's call, under API terms that exclude training use.
5. Retention — you control it
- Call audio, transcripts, and outcomes — retained under the organization's control, or not retained at all in zero-retention mode. Deleting a call removes its recording, transcript, and outcome together, via dashboard or API. Absent a configured retention window or a deletion request, this data is kept while the account remains active.
- Account data — kept while the organization is active; deleted within 30 days of account closure except records we must keep for legal or accounting reasons.
- Server logs — rotate within 90 days.
6. Subprocessors and hosting
We share data with these categories of subprocessor, each under a data-processing agreement:
- Cloud infrastructure — application hosting, call-audio storage (private buckets accessed via short-lived signed URLs), and model inference run on SOC 2 Type II-audited cloud providers. Enterprise workspaces can pin storage and processing to an EU region; in-region MENA options are scoped per contract.
- Speech subprocessors — speech-to-text and dialect-native text-to-speech that power the two engines.
- AI model subprocessors — a primary frontier-model provider runs the agent's reasoning, with a second provider as a fallback lane. API-submitted content is excluded from training under each provider's API terms.
- Telephony carriers — PSTN connectivity for platform numbers and, where you bring your own, your chosen carrier or SIP trunk.
- Email & payments — a transactional email provider (sign-in codes, service notices) and Stripe for paid plans; we do not store card numbers.
We will update this page before engaging a new subprocessor that handles personal data. The current list of subprocessors, by name, is available to customers on request at support@whizztech.ai. International transfers rely on appropriate safeguards, including standard contractual clauses where required.
7. Security
Call audio lives in private storage accessed only via short-lived signed URLs; API keys are stored hashed; webhook deliveries are signed so you can verify origin; production access is restricted and logged; and every API key is scoped to a single organization. We build on SOC 2 Type II-audited processors; we do not claim our own SOC 2 or HIPAA certification.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data.
Customers: email support@whizztech.ai from your account address. Call participants (people who spoke with an agent): contact the company whose agent you called, or email us and we will forward the request to the responsible organization and assist with its completion. We respond within 30 days. If you believe a concern is unresolved, you may complain to your local supervisory authority.
9. Changes
We will post changes here and update the effective date. Material changes are announced by email to organization owners before they take effect.