Legal

Privacy Policy

Last updated: 11 August 2026

This policy explains what personal data VoiceSkill collects when you run AI sales simulations, how we use it, how long we keep it, and the rights people have under the EU General Data Protection Regulation (GDPR) and the UK GDPR / Data Protection Act 2018. For our technical controls, see the Security & GDPR page; for the commercial agreement, see the Terms of Service.

Who is responsible for what

We are the controller for the data of our own customers: your account, workspace, billing and support correspondence, and website analytics.

You are the controller and we are the processor for the data of the people you invite into a simulation — candidates, sellers and trainees. You decide who is invited, what the simulation asks, and how long results are kept. We process that data only on your documented instructions, which are the settings you choose in the product plus this policy and the Terms. Section "Processing terms (DPA)" below sets out the processor commitments; we will sign a standalone DPA on request.

Data we process about you (our customer)

  • Account: name, work email, password credentials handled by our auth provider, workspace name, role, language and branding settings.
  • Usage: simulations created, calls run, feature usage, log data (IP, timestamp, user agent) for security and troubleshooting.
  • Billing: plan, subscription status, invoices and Stripe customer id. Card details are handled by Stripe — we never see or store them.
  • Support: messages you send us and, if you use the in-app assistant, the questions you ask it.

Data we process about candidates and trainees (on your behalf)

  • Identity: name and email address you add manually, upload in bulk, or import from Teamtailor.
  • CV and job material: the CV you upload (or the candidate uploads themselves) and the job ad, script or recorded call used to build the scenario. These are analysed to calibrate the scenario and difficulty.
  • Voice recording: the audio of the simulation call, including the warm-up check where applicable.
  • Transcript: the text of the conversation, with timestamps.
  • Scores and reports: stage scores, behavioural stress-test results, ranking, strengths, weaknesses, coaching drills and the exported PDF.
  • Call metadata: attempt number, duration, difficulty applied, device/browser diagnostics and connection quality.

Voice recordings can constitute biometric-adjacent data in some jurisdictions. We do not perform voice identification, emotion inference for legal purposes, or biometric matching of any kind. Candidates are told before the call that it is an AI role-play and that the conversation is recorded, transcribed and scored, and they must actively start the call.

Why we process it and on what legal basis

  • To provide the service to you — performance of a contract, Art. 6(1)(b).
  • To run, transcribe and score simulations — processed for you; your lawful basis towards the candidate is typically legitimate interest in assessing suitability, Art. 6(1)(f), or pre-contractual steps, Art. 6(1)(b). You are responsible for identifying and documenting that basis and for informing the individual.
  • Security, abuse prevention and service improvement in aggregate — legitimate interest, Art. 6(1)(f).
  • Billing and accounting records — legal obligation, Art. 6(1)(c).
  • Product emails and marketing to customers — consent or soft opt-in; you can unsubscribe at any time.

Automated decision-making

Scores, difficulty calibration, ranking tiers and coaching feedback are generated by AI models. They are decision support only. VoiceSkill does not automatically reject anyone; auto-advance in Teamtailor, if you enable it, only moves candidates forward. You must keep meaningful human review in your process, tell candidates that AI is used, and offer a route to human review and to contest a result.

What we never do

We do not sell or rent personal data. We do not use your content, candidate audio, transcripts or CVs to train AI models, and we contractually require the same of our AI subprocessors. We do not profile candidates across customers, run advertising, or share data with anyone other than the subprocessors listed below.

Subprocessors

  • Cloudflare — application hosting and edge delivery.
  • Supabase (AWS, EU region) — database, file and recording storage.
  • Clerk — authentication and session management.
  • ElevenLabs — realtime speech-to-text and text-to-speech for the AI prospect.
  • Google (Gemini) — scenario generation, transcription of uploaded calls, scoring and report generation.
  • Teamtailor — only if you connect it, for job and candidate sync.
  • Stripe — payments and subscriptions.
  • Resend — transactional email.
  • Google Drive — only if you connect it, for files you choose to attach.

We have a data processing agreement with each subprocessor. We will give notice before adding a new subprocessor so you can object.

International transfers

Data is stored in the EU. Some subprocessors process data in the United States; those transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with the EU–US Data Privacy Framework where the provider is certified, plus supplementary technical measures such as encryption in transit and at rest.

Retention

  • Recordings, transcripts, scores and CVs: kept for as long as your workspace keeps them, up to a default maximum of 12 months, then deleted. You can delete any candidate, trainee or result immediately from the dashboard — the recording, transcript and score go with it.
  • Account and workspace data: for the life of the account, then deleted within 30 days of closure.
  • Invoices and accounting records: retained up to 7 years where legally required.
  • Security logs: up to 12 months.

Security

TLS 1.2+ in transit, encryption at rest, row-level access control per workspace, signed short-lived URLs for recordings, role-based permissions, and least-privilege access for our staff. We notify you without undue delay — and within 72 hours where the GDPR requires it — if a personal data breach affects your workspace.

Cookies

Strictly necessary cookies for authentication, security and language preference only. No third-party advertising or tracking cookies.

Your rights

You have the right to access, correct, export (portability), restrict, object to, and delete your personal data, and to withdraw consent where processing is based on it. Email privacy@getflyt.co and we respond within 30 days. If you are a candidate or trainee, the employer or recruiter who invited you is the controller — contact them first; if you contact us we will forward your request to them without undue delay and assist them in answering it. You may also complain to your local supervisory authority, or to the UK Information Commissioner's Office.

Children

The service is not intended for anyone under 16. We do not knowingly process the data of children.

Processing terms (DPA)

When acting as your processor we will: process personal data only on your documented instructions; ensure our personnel are bound by confidentiality; implement the technical and organisational measures described above; engage subprocessors only under equivalent written terms and with prior notice; assist you with data subject requests, breach notification and data protection impact assessments; and delete or return the data at the end of the service, subject to legal retention. You may audit compliance once per year on reasonable notice, or accept our documentation in place of an on-site audit. This section applies as an Art. 28 GDPR data processing agreement unless we sign a separate one with you.

Changes to this policy

We update this policy when the product or the law changes. Material changes are announced by email or in-app before they take effect.

Controller and contact

Interfront Ltd., 120 High Road, London N2 9ED, United Kingdom.
Privacy contact: privacy@getflyt.co

← Back to home