Privacy Policy
Last updated: October 9, 2026
This English version is provided for your convenience and is awaiting legal review. In case of any discrepancy, the Czech version prevails.
View the Czech versionThis document describes what personal data volai processes, for what purpose, how long we retain it, and what rights you have under the GDPR. It applies to users of the Service as well as to people who are called or sent SMS through the Service, and to people who text a customer's SMS number.
1. Who is the data controller
The data controller is ANOVIA Finance s.r.o. (Company ID 01757237), with its registered office at Na Zámku 636, 250 81 Nehvizdy, Czech Republic, entered in the Commercial Register maintained by the Municipal Court in Prague (Městský soud v Praze), Section C, Insert 266323. For any questions about the processing of personal data, contact us at podpora@volai.cz.
The volai connector for OpenAI is published by Fabikonam, s.r.o. (Company ID 23918560), with its registered office at Dominikánské náměstí 656/2, Brno-město, 602 00 Brno, Czech Republic, with authorization from ANOVIA Finance s.r.o. Fabikonam acts solely as the connector publisher and does not process volai customer data. ANOVIA Finance s.r.o. continues to process that data in the roles described in this policy, including its role as the customer's processor for call content.
2. What data we process
- Account: email address, name, hashed password, and address (if you purchase a geographic phone number - required for emergency-calling purposes).
- Telephony metadata: phone numbers (for received SMS also the sender's number or name), time and duration of calls and SMS, direction and status, and the price charged for each action.
- Content of communication: the text of sent and received SMS (received ones only for customers with the SMS number add-on), and transcripts and summaries of calls with the voice agent.
- Call recordings: audio recordings of calls handled by the voice agent. Recording can be turned off on the agent; we delete recordings 90 days after the call.
- Data captured from calls: information the agent captures from a call as configured by the customer (for example a name, a date, or an order number). The customer determines the scope of this data through their agent configuration - we don't know in advance what they'll choose to capture.
- Payments and invoices: credit top-up history (amount, date), billing details (company name, Company ID, VAT ID, address), and issued tax invoices - card details are processed exclusively by the payment gateway and never reach us.
- Technical records: IP address, browser and API key identification, and access logs, for security and abuse detection.
- Registration source: how you found volai - campaign parameters from the address (utm_source and similar), the referring page address without parameters, and the first page you visited. We record these once when the account is created, to learn which paths lead to us; nothing is stored in your browser for this without your consent to measurement.
Google Calendar: connections and event data
Connecting Google Calendar is optional and uses Google's consent screen. Volai reads your calendar list (identifiers, names, time zones and access roles) and event data (title, start, end, status and revision). It uses this data to display calendars, change an event's title or time after your confirmation, and supply information to a task to which you attach the event.
We store OAuth access and refresh tokens encrypted. Our web infrastructure processes calendar requests and our database stores the connection record. We do not receive your Google password. Disconnecting in the portal deletes the stored connection and tokens; you can also revoke Volai's access in your Google Account. This does not delete your original Google events. Data already copied into tasks and history follows the retention periods in section 4.
When you use REST API or MCP, we return the requested calendar data to the client you authorized through volai sign-in (OAuth) or entrusted with your volai API key; this may include an external AI assistant. If you attach an event to a voice task, its title and time may become part of the call context processed by the relevant voice AI providers listed below. Sharing serves the feature you selected. We do not send Google tokens to these clients.
We do not sell Google Calendar data or use it for advertising targeting or training general-purpose AI models. Volai uses data obtained through Google APIs in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
3. Purpose and legal basis for processing
We process data primarily to perform our contract with you - so we can provide a number, connect a call, send an SMS, or run the voice agent, and bill it correctly. We process technical records and security logs on the basis of legitimate interest (fraud and abuse prevention). Emails about your account (verification, low credit) are a necessary part of the Service; any further communication would only be sent with your consent.
We also process call recordings and data the agent captures from a call on the basis of performing our contract - these are features the customer enabled on their agent, and we couldn't provide them otherwise. With respect to the caller, the controller of this data is the customer who operates the agent; we act as a processor in this relationship and follow their instructions. Informing the caller that the call is recorded, and what the agent captures, is therefore the customer's responsibility.
Beyond this role, once a week we also evaluate the calls handled by our own voice engine during the past week, to check and improve the quality of the service. The call transcript is first pseudonymized automatically, without using an AI model: names, companies, places, email addresses, websites, account numbers and other sensitive numbers are replaced with placeholders and phone numbers with random digits. Pseudonymization is automated and may occasionally miss something. The pseudonymized transcript is then assessed by a language model acting as an independent "judge". In this scope we do not act as your processor under your instructions but in our own interest as the operator; the legal basis is our legitimate interest in the quality and improvement of the service (Art. 6(1)(f) GDPR). The result is aggregate statistics and quality scores for our internal use; nothing is returned to customers or callers. If you do not want the calls of your agents to be included in the evaluation, email podpora@volai.cz and we will exclude your account from the evaluation. Anyone the agent spoke with can object in the same way at any time: just send your phone number to the same address and we will stop including your calls in the evaluation.
4. How long we retain data
We retain data for as long as your account exists. After it is cancelled, we delete phone numbers, transcripts and message content within 30 days, except for data we are required by law to keep longer (for example, accounting records on payments, for the period required by tax regulations). Security access logs are typically kept for 90 days. SMS received on an SMS number (text, sender's number and time) are kept for 90 days after receipt and then deleted. We delete call recordings 90 days after the call regardless of whether the account continues to exist - the call transcript remains in your account. Transcripts that we download for the weekly quality evaluation described in section 3 are kept in their original form for 14 days and in pseudonymized form, together with the assessments, for 8 weeks; once the period has passed, the next weekly clean-up deletes them. The exception is an anchor set of about 20 pseudonymized calls used to measure how stable the assessments are over time, which we renew every quarter. Closing your account does not delete these copies; they are kept for the periods above, and we delete them earlier on request. We keep aggregate evaluation results that can no longer be linked to a specific call for longer.
5. Processors and recipients of data
We are assisted in processing by vetted suppliers with whom we have data processing agreements in place. They fall into the following categories of recipients:
- Cloud infrastructure and database: Hosting for the application and the database that stores account, number, call and message data, plus anonymous website traffic measurement. Servers located in the EU.
- Telecommunications operator: Technically provides the phone numbers and carries calls and SMS. A Czech operator, operating within the Czech Republic. For the SMS number add-on, the number and SMS transport come from a US provider (see the table below), not from a Czech operator.
- Voice AI provider: Processes calls with the voice agent, their recordings, and their transcripts. For agents on the standard platform, audio recordings are stored with this provider for 90 days and never reside with us directly. Any transfer outside the EU is covered by Standard Contractual Clauses.
- Payment gateway: Processes payment cards when topping up credit. Card details never reach us directly.
- Email infrastructure: Sends transactional emails (account verification, low-credit alerts).
- Advertising platform: Measures the effectiveness of our advertising - only when you give consent for it (see section 8). We do not ourselves document the mechanism for any transfer outside the EU (for example the EU-US Data Privacy Framework) and rely on the supplier's own safeguards under GDPR.
- Own voice engine infrastructure: Servers that run volai's own voice engine (call control, the media layer, end-of-turn detection) - used for agents switched to this engine. Speech transcription and synthesis, and the language model that runs the conversation, are provided by suppliers in the following two categories. For agents on the own engine, these servers also store call recordings and transcripts. Servers in the EU.
- Own voice engine speech transcription and synthesis: Converts the caller's speech to text and the agent's reply back to speech, for agents on the own voice engine. Any transfer outside the EU is covered by Standard Contractual Clauses.
- Own voice engine language model: Runs the voice agent's conversation on the own engine - decides what the agent says during the call. For some suppliers in this category, any transfer outside the EU is covered by Standard Contractual Clauses; for others we do not document this ourselves and rely on the supplier's own safeguards under GDPR.
- Call summary and evaluation: After a call ends, generates a text summary and - if the agent has a goal set - evaluates from the transcript whether it was met. For calls handled by the own voice engine it additionally assesses, once a week, the quality of the voice agent on a pseudonymized transcript (see section 3). Any transfer outside the EU is covered by Standard Contractual Clauses.
We only transfer data to the US to the extent needed for the operation and the weekly quality evaluation described above. For Cartesia, ElevenLabs and Anthropic, this transfer is covered by EU standard contractual clauses under their own data processing addendum (DPA) - we verified this directly on their publicly available DPA page. For the other suppliers headquartered in the US (Resend, Stripe, Twilio, Google (Gemini) and Meta), we do not claim a specific transfer mechanism ourselves and rely on their own safeguards under GDPR.
We do not share data with anyone else, except where required by law, and except for the transfers to the customer's system or a client they connect, as described in the following paragraphs.
A special case is the voice agent tool: when a customer configures one, we send a request during the call to the address they specified, together with the data they defined in the tool - typically the caller's number and information gathered during the call. In that moment, the recipient is the customer's system, not another supplier of ours; the customer determines both the scope of data sent and the security of the destination system.
If you connect an external application or AI assistant through volai sign-in (OAuth) or an API key, we return the data requested by that client's authorized calls. The recipient is the client you choose and its provider, for example OpenAI when using ChatGPT or Anthropic when using Claude. Depending on the function called, this may include your account identifier and email, credit balance, phone numbers and settings including SIP credentials, contacts, calls, recordings, transcripts, SMS, agent configurations, tasks, invoices and connected calendar data. This transfer serves the function you use through the client; it does not make Fabikonam, the connector publisher, a recipient of customer data.
Before an OAuth connection is approved, we display the requested permissions, including account changes and paid actions. You can revoke access at any time under API and MCP in the portal; API keys can be revoked in Access management. Revocation prevents further use of that access, but does not delete data already sent to the external client or undo completed calls, messages or orders. The client provider's further handling, retention and deletion of its copies are governed by its terms, privacy policy and your account settings with that provider. Retention by volai continues to follow section 4 of this policy.
6. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Simply send your request to podpora@volai.cz, and we will handle it without undue delay. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů) at uoou.cz.
7. Security
We store passwords only as an irreversible hash (scrypt), and store API keys in the database only as a fingerprint - you see the plain-text value only once, at creation. All communication is encrypted over HTTPS. Sensitive data (passwords, keys, operator access tokens) is never written to operational logs.
8. Cookies and traffic measurement
We use essential cookies to keep you signed in and to make forms work. Without them the Service wouldn't function, so we don't ask for consent for these.
Website traffic is measured by a tool run by the operator of our cloud infrastructure (see section 5): it counts page views and coarse device, browser and country data. It stores no cookies or anything else in your browser and never links individual visitors to each other or across sites, so we don't ask for consent for it. We strip the page address before sending it: a link to account verification or a password reset never sends your email or one-time token.
In addition, we measure whether our advertising on Facebook and Instagram is working - specifically, how many people registered and topped up credit after seeing it. For this we use tools from Meta, which store their own cookies in your browser and send Meta the page you visited, your registration, and your credit top-up (your email only as an irreversible hash, never in readable form). We likewise measure the effectiveness of our advertising in Google Search: we save the click identifier from the address to your account at registration and later tell Google when you activated your account and when you first topped up credit (no email, just the click identifier, the time and the amount). We only turn this measurement on when you give consent for it in the banner that appears on your first visit. Until you consent, no advertising measurement code is loaded at all.
Consent is voluntary, has no effect on how volai works, and you can withdraw it at any time - delete this site's cookies in your browser and the banner will ask again. We remember your consent for one year.
9. Contact
For anything related to the processing of personal data, or to exercise your rights, contact us at podpora@volai.cz. The terms governing use of the Service are set out separately in the Terms of Service.