VoiCommerce

GDPR Compliance

Last updated: July 7, 2026

1. Scope & Commitment

The General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR govern how personal data of individuals in the European Economic Area and the United Kingdom is collected, processed, and protected.

Voicommerce is committed to processing personal data in accordance with the GDPR, the UK GDPR, and comparable privacy laws in the jurisdictions we serve. This page summarises how those obligations apply to our Service. It should be read together with our Privacy Notice.

2. Controller vs Processor

Voicommerce operates in two distinct capacities under the GDPR:

  • Controller — for merchant account data: Voicommerce determines the purposes and means of processing our merchants' account details, billing contact information, product-usage telemetry, and support correspondence.
  • Processor — for end-user data flowing through the widget: when a merchant embeds the Voicommerce widget on their own site, the merchant is the controller of that site's visitors' personal data. Voicommerce acts as a processor and only processes conversation transcripts, cart context, and order-lookup data on the merchant's documented instructions and in accordance with our Data Processing Agreement.

4. Data Subject Rights & How to Exercise Them

Individuals in the EEA and UK have the following rights over their personal data:

  • Access a copy of the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") in the circumstances defined by the GDPR.
  • Restriction of processing in defined circumstances.
  • Data portability — receive your data in a structured, machine-readable format.
  • Object to processing carried out on the basis of legitimate interests or for direct marketing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local supervisory authority (see Section 9).

To exercise a right in relation to data for which Voicommerce is the controller, contact support@voicommerce.com. We respond within one month of receiving a verifiable request and may extend this by up to two additional months for complex requests, notifying you of the extension.

Where an end-user submits a request about data collected via a merchant's website, that request should be directed to the merchant as controller. Merchants can view, export, and delete individual customer conversations from their Voicommerce dashboard to fulfil those requests.

5. Sub-processors

Voicommerce engages a limited number of sub-processors to deliver the Service, each under a written contract that imposes GDPR-compliant obligations:

  • Paddle.com Market Ltd. — Merchant of Record for billing, payments, invoicing, and tax compliance.
  • Cloud hosting and database providers operating our application and database infrastructure.
  • AI model providers that generate responses for individual chat requests.
  • Analytics providers loaded only where the end-user has given consent.
  • Support and communications tools used to respond to customer enquiries.

A current sub-processor list, including locations and the safeguards in place, is available on request via support@voicommerce.com. We give reasonable prior notice of material changes to the sub-processor list.

6. International Data Transfers

Some of our sub-processors operate outside the EEA and the UK. Where we transfer personal data outside these regions, we rely on approved transfer mechanisms — typically the European Commission's Standard Contractual Clauses (2021/914) and, where applicable, the UK International Data Transfer Addendum, together with supplementary technical and organisational measures such as encryption in transit and at rest, per-tenant isolation, and strict access controls.

7. Data Retention & Deletion

  • Account data is retained while your account is active and for up to 90 days after closure to permit reactivation and dispute resolution.
  • Conversation transcripts and uploaded knowledge assets can be exported and deleted at any time from the dashboard. Once deleted, records are purged from active systems within 30 days and from backups within the standard backup rotation.
  • Billing and tax records handled by Paddle are retained by Paddle for the periods required by applicable tax and accounting law.
  • Security and audit logs are retained for up to 12 months.

8. Security Measures

Voicommerce implements appropriate technical and organisational measures to protect personal data as required by Article 32 GDPR, including:

  • TLS encryption for data in transit and encryption at rest for the primary database.
  • Per-tenant logical isolation so each merchant's data is scoped to their account.
  • Least-privilege access controls, authentication requirements, and audit logging for administrative actions.
  • Regular review of security practices and prompt handling of security incidents, including notification to affected controllers and, where required, supervisory authorities within statutory deadlines.

9. DPA, Contact & Supervisory Authority

Merchants who process personal data of EEA or UK individuals through Voicommerce can request our pre-signed Data Processing Agreement (DPA), which incorporates the Standard Contractual Clauses where relevant. Email support@voicommerce.com to receive a copy.

If you believe our processing of your personal data infringes the GDPR or UK GDPR, we would appreciate the opportunity to address your concerns directly. You also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement.

Looking for a Data Processing Agreement (DPA)?

We provide a pre-signed DPA that satisfies GDPR requirements for European merchants and operators. Contact support to request a copy.

Request DPA