Last updated 29 August 2026
Security
How VoiceSync protects call data, and what it deliberately does not store.
What we do not keep
The strongest control here is an absence: we do not retain call audio. Only the transcript is stored. A recording of someone's voice is far more sensitive and far more damaging if exposed, and not having it removes that risk entirely rather than mitigating it.
Access and isolation
- Every table is isolated per business at the database level, enforced by the database rather than by application code.
- A business that does not exist and a business you cannot access are indistinguishable from the outside, so account identifiers cannot be probed.
- Console access requires authentication through a managed provider. We never store passwords ourselves.
- The public enquiry form can write but cannot read: there is no path from the website to reading stored data.
In transit and at rest
All web traffic is served over HTTPS. Call media travels over encrypted real-time transport. Data at rest is encrypted by our database provider.
Breach response
If we become aware of a breach affecting personal data we will investigate immediately, notify affected businesses without undue delay, and notify the relevant authority within the deadline that applies — 72 hours under the GDPR, and as required under India's DPDP framework.
What we are still building
We would rather list this than imply a maturity we do not have:
- Automatic deletion of expired transcripts is being implemented; retention is currently managed manually.
- We do not yet hold an ISO 27001 or SOC 2 certification.
- Penetration testing has not yet been carried out by a third party.
Who we are
- Operator
- [legal entity — to be completed]
- Registered address
- [address — to be completed]
- Registration no.
- [registration number — to be completed]
- Data region
- [data region — to be completed]
- Privacy contact
- privacy@voicesync.in
- Grievance Officer (India)
- [Grievance Officer — to be completed]