Privacy Policy
This policy describes how BKB Voice handles personal information submitted through the website and during engagements, and references the technical controls documented in ourTrust Center.
Last updated: April 22, 2026
1. Information we collect
- Contact details submitted via lead intake forms (name, email, company, role, phone).
- Inquiry metadata (use case description, budget range, timeline, compliance sensitivity).
- Scripts and content you provide for voice production (processed under your directions; not persisted by default).
- Operational logs: correlation IDs, truncated user-agent strings, IP addresses and rate-limit counters retained for security monitoring.
2. How we use information
- To qualify inbound leads and recommend an appropriate tier.
- To deliver agreed voice workflows, renderings and integrations.
- To maintain the audit trail required for our SOC 2 control environment.
- To communicate about your inquiry, proposal, project or account.
3. Legal bases (EU / UK)
We process personal information on the basis of contract performance, our legitimate interest in operating and securing the service, compliance with legal obligations, and your consent where required.
4. Sharing and subprocessors
We do not sell personal information. We share it only with the vetted subprocessors listed on theSubprocessors page, under contractual data-protection obligations and a signed DPA.
5. Retention
Lead records are retained while active and for a reasonable period thereafter to support follow-up and compliance obligations. Audit logs are retained for 12 months by default. Scripts submitted to the voice generator or script optimiser are not persisted — only audit metadata (character count, timestamp, outcome) is recorded. Client script and audio assets delivered as part of an engagement are retained per the applicable order form.
6. Security
BKB Voice applies administrative, technical and physical safeguards appropriate to the sensitivity of the information, including TLS 1.2+, encryption at rest, least-privilege access, hardened security headers, rate limiting on public APIs, input validation and an immutable audit log. Detailed controls are published on theSecurity page and mapped to the SOC 2 Trust Services Criteria on theSOC 2 Readiness page.
7. Your rights
Depending on your jurisdiction (including GDPR, UK GDPR and CCPA), you may have rights to access, correct, delete, port or restrict the processing of your personal information, and to object to processing. Submit a verified request through thePrivacy Requestpage or email [email protected]. We action verified requests within thirty (30) days.
8. International transfers
Where personal data is transferred out of the EEA or the UK, BKB Voice relies on the European Commission’s Standard Contractual Clauses and the UK Addendum, as reflected in our Data Processing Addendum.
9. Cookies
The BKB Voice website uses only essential cookies required for site functionality. We do not deploy advertising trackers on bkbvoice.com.
10. Breach notification
In the event of a confirmed personal data breach, BKB Voice will notify affected customers without undue delay and in any event within seventy-two (72) hours, in accordance with theIncident Response policy.
11. Changes
We may update this policy from time to time. Material changes will be communicated through the website or direct notice.
12. Contact
Privacy inquiries: [email protected].
Trust & compliance: [email protected].
General: [email protected].