Last updated 29 August 2026

Security

How VoiceSync protects call data, and what it deliberately does not store.

What we do not keep

The strongest control here is an absence: we do not retain call audio. Only the transcript is stored. A recording of someone's voice is far more sensitive and far more damaging if exposed, and not having it removes that risk entirely rather than mitigating it.

Access and isolation

  • Every table is isolated per business at the database level, enforced by the database rather than by application code.
  • A business that does not exist and a business you cannot access are indistinguishable from the outside, so account identifiers cannot be probed.
  • Console access requires authentication through a managed provider. We never store passwords ourselves.
  • The public enquiry form can write but cannot read: there is no path from the website to reading stored data.

In transit and at rest

All web traffic is served over HTTPS. Call media travels over encrypted real-time transport. Data at rest is encrypted by our database provider.

Breach response

If we become aware of a breach affecting personal data we will investigate immediately, notify affected businesses without undue delay, and notify the relevant authority within the deadline that applies — 72 hours under the GDPR, and as required under India's DPDP framework.

What we are still building

We would rather list this than imply a maturity we do not have:

  • Automatic deletion of expired transcripts is being implemented; retention is currently managed manually.
  • We do not yet hold an ISO 27001 or SOC 2 certification.
  • Penetration testing has not yet been carried out by a third party.

Who we are

Operator
[legal entity — to be completed]
Registered address
[address — to be completed]
Registration no.
[registration number — to be completed]
Data region
[data region — to be completed]
Privacy contact
privacy@voicesync.in
Grievance Officer (India)
[Grievance Officer — to be completed]