Skip to content

Privacy Policy

Last updated: August 27, 2026

This English version is provided for your convenience and is awaiting legal review. In case of any discrepancy, the Czech version prevails.

View the Czech version

This document describes what personal data volai processes, for what purpose, how long we retain it, and what rights you have under the GDPR. It applies to users of the Service as well as to people who are called or sent SMS through the Service.

1. Who is the data controller

The data controller is ANOVIA Finance s.r.o. (Company ID 01757237), with its registered office at Na Zámku 636, 250 81 Nehvizdy, Czech Republic, entered in the Commercial Register maintained by the Municipal Court in Prague (Městský soud v Praze), Section C, Insert 266323. For any questions about the processing of personal data, contact us at podpora@volai.cz.

2. What data we process

  • Account: email address, name, hashed password, and address (if you purchase a geographic phone number - required for emergency-calling purposes).
  • Telephony metadata: phone numbers, time and duration of calls and SMS, direction and status, and the price charged for each action.
  • Content of communication: the text of sent SMS, and transcripts and summaries of calls with the voice agent.
  • Call recordings: audio recordings of calls handled by the voice agent. Recording can be turned off on the agent; we delete recordings 90 days after the call.
  • Data captured from calls: information the agent captures from a call as configured by the customer (for example a name, a date, or an order number). The customer determines the scope of this data through their agent configuration - we don't know in advance what they'll choose to capture.
  • Payments and invoices: credit top-up history (amount, date), billing details (company name, Company ID, VAT ID, address), and issued tax invoices - card details are processed exclusively by the payment gateway and never reach us.
  • Technical records: IP address, browser and API key identification, and access logs, for security and abuse detection.

3. Purpose and legal basis for processing

We process data primarily to perform our contract with you - so we can provide a number, connect a call, send an SMS, or run the voice agent, and bill it correctly. We process technical records and security logs on the basis of legitimate interest (fraud and abuse prevention). Emails about your account (verification, low credit) are a necessary part of the Service; any further communication would only be sent with your consent.

We also process call recordings and data the agent captures from a call on the basis of performing our contract - these are features the customer enabled on their agent, and we couldn't provide them otherwise. With respect to the caller, the controller of this data is the customer who operates the agent; we act as a processor in this relationship and follow their instructions. Informing the caller that the call is recorded, and what the agent captures, is therefore the customer's responsibility.

4. How long we retain data

We retain data for as long as your account exists. After it is cancelled, we delete phone numbers, transcripts and message content within 30 days, except for data we are required by law to keep longer (for example, accounting records on payments, for the period required by tax regulations). Security access logs are typically kept for 90 days. We delete call recordings 90 days after the call regardless of whether the account continues to exist - the call transcript remains in your account.

5. Processors and recipients of data

We are assisted in processing by vetted suppliers with whom we have data processing agreements in place. They fall into the following categories of recipients:

  • Cloud infrastructure and database: Hosting for the application and the database that stores account, number, call and message data, plus anonymous website traffic measurement. Servers located in the EU.
  • Telecommunications operator: Technically provides the phone numbers and carries calls and SMS. A Czech operator, operating within the Czech Republic.
  • Voice AI provider: Processes calls with the voice agent, their recordings, and their transcripts. Audio recordings are stored with this provider for 90 days and never reside with us directly. Any transfer outside the EU is covered by Standard Contractual Clauses.
  • Payment gateway: Processes payment cards when topping up credit. Card details never reach us directly.
  • Email infrastructure: Sends transactional emails (account verification, low-credit alerts).
  • Advertising platform: Measures the effectiveness of our advertising - only when you give consent for it (see section 8). Transfer outside the EU is covered by the EU-US Data Privacy Framework.

We will send you the current named list of specific processors on request at podpora@volai.cz. We do not share data with anyone else, except where required by law, and except for the transfer to the customer's system described in the following paragraph.

A special case is the voice agent tool: when a customer configures one, we send a request during the call to the address they specified, together with the data they defined in the tool - typically the caller's number and information gathered during the call. In that moment, the recipient is the customer's system, not another supplier of ours; the customer determines both the scope of data sent and the security of the destination system.

6. Your rights

You have the right to access your personal data, to have it corrected or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Simply send your request to podpora@volai.cz, and we will handle it without undue delay. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů) at uoou.cz.

7. Security

We store passwords only as an irreversible hash (scrypt), and store API keys in the database only as a fingerprint - you see the plain-text value only once, at creation. All communication is encrypted over HTTPS. Sensitive data (passwords, keys, operator access tokens) is never written to operational logs.

8. Cookies and traffic measurement

We use essential cookies to keep you signed in and to make forms work. Without them the Service wouldn't function, so we don't ask for consent for these.

Website traffic is measured by a tool run by the operator of our cloud infrastructure (see section 5): it counts page views and coarse device, browser and country data. It stores no cookies or anything else in your browser and never links individual visitors to each other or across sites, so we don't ask for consent for it. We strip the page address before sending it: a link to account verification or a password reset never sends your email or one-time token.

In addition, we measure whether our advertising on Facebook and Instagram is working - specifically, how many people registered and topped up credit after seeing it. For this we use tools from Meta, which store their own cookies in your browser and send Meta the page you visited, your registration, and your credit top-up (your email only as an irreversible hash, never in readable form). We only turn this measurement on when you give consent for it in the banner that appears on your first visit. Until you consent, no advertising measurement code is loaded at all.

Consent is voluntary, has no effect on how volai works, and you can withdraw it at any time - delete this site's cookies in your browser and the banner will ask again. We remember your consent for one year.

9. Contact

For anything related to the processing of personal data, or to exercise your rights, contact us at podpora@volai.cz. The terms governing use of the Service are set out separately in the Terms of Service.