Skip to content

Privacy Policy

How voiqq collects, uses, shares, protects, and retains personal data, including data used by optional AI features.

Effective 9 August 2026. This Privacy Policy explains how voiqq processes personal data when you visit the site, create or use an account, join a workspace, manage assessment records, use optional AI features, contact us, or purchase a subscription.

Who is responsible for personal data

voiqq is the controller for website, account, direct billing-support, security, consent, and communication data. A customer organization generally controls personal data that it submits to its workspace, including project, finding, evidence, comment, import, and report content. For that customer-controlled content, voiqq acts as a processor or service provider according to the service agreement and applicable law.

Privacy questions and rights requests can be submitted through the signed-in Privacy Center or sent to admin@voiqq.com. Our business contact addresses are listed on the Contact page.

Information we process

  • Account and profile details, authentication identifiers, team memberships, roles, portfolio settings, and preferences
  • Workspace, project, requirement, finding, assignment, status, validation, comment, evidence, import, export, report, and public-share records supplied or generated by users
  • Subscription plan, invoice, transaction status, billing interval, and customer identifiers supplied by Paddle; voiqq does not receive or store full payment-card numbers
  • Device, browser, approximate request location derived from network data, security event, rate-limit, consent, and operational diagnostic information
  • Support messages, privacy requests, sales enquiries, and communication preferences
  • Structured context submitted to an optional AI-assisted drafting or spreadsheet-mapping action

Where information comes from

Information comes from you, workspace administrators and collaborators, uploaded files, public spreadsheet links you ask voiqq to retrieve, browser-extension assessment results you choose to import, authentication and billing providers, and routine use of the service. Customers are responsible for having authority to submit project content and for avoiding personal or confidential data that is not needed for the assessment.

Purposes and legal bases

  • Provide accounts, workspaces, collaboration, imports, exports, reporting, sharing, support, subscriptions, and requested product features under our contract
  • Authenticate users, enforce permissions, prevent fraud and abuse, investigate incidents, maintain reliability, and improve service operation based on legitimate interests and contractual necessity
  • Keep billing, tax, security, consent, and dispute records where required by law or legitimate accountability needs
  • Send necessary account, security, billing, invitation, and configurable service-briefing messages under the contract and legitimate service interests
  • Send optional marketing or use optional cookies only with the permission or other legal basis required in the relevant jurisdiction

Where processing relies on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal. Required account terms are recorded separately from optional cookie and marketing choices.

AI-assisted features

voiqq uses Google Gemini APIs and Groq-hosted model APIs for optional AI-assisted product-description drafting, VPAT or ACR remarks, and ambiguous spreadsheet-column mapping. The available provider or model may change as configured services become available, but voiqq applies the same product rules and deterministic fallbacks.

When you invoke an AI-assisted action, voiqq sends only the structured context needed for that request. Depending on the feature, this may include project and product names, supplied URLs or extracted first-party page text, requirement labels, finding summaries and descriptions, affected components, statuses, severities, or spreadsheet headers and representative cell values. Do not place secrets, payment data, health data, or other unnecessary sensitive information in an AI-assisted request.

AI output is a draft or mapping suggestion for review. It does not certify a product, determine a legal conclusion, replace professional judgment, or make a decision that produces legal or similarly significant effects about a person. Rule-based report outcomes remain subject to the applicable product workflow, and deterministic text or mapping logic remains available when AI providers fail.

Sharing and recipients

  • Authorized members of workspaces and projects according to roles, assignments, and permissions
  • Recipients of public project or portfolio links deliberately enabled by an authorized user
  • Supabase for authentication, PostgreSQL data, row-level authorization, and file storage
  • Google Cloud Run for application hosting and server execution
  • Paddle for hosted checkout, merchant-of-record billing, tax, invoices, and buyer support
  • Resend for transactional and configurable service email
  • Cloudflare Turnstile for bot and abuse protection
  • Google Gemini and Groq for optional AI-assisted processing
  • Professional advisers, acquirers, regulators, courts, or authorities where lawfully required

The current provider list and service purpose are maintained on the Subprocessors page. voiqq does not sell personal data. Workspace users control whether project or portfolio content is made available through a public link.

International processing

voiqq and its providers may process data in countries other than your own. Where required, we rely on contractual safeguards, adequacy decisions, provider data-protection terms, and technical and organizational controls appropriate to the transfer and service.

Retention and deletion

Account and workspace data is retained while the service is active and for limited periods needed for service recovery, security, billing, legal obligations, and disputes. Deleted projects remain recoverable for three days before permanent deletion. Generated downloads are delivered directly or retained only according to the storage method shown in the product.

Account deletion removes personal records and files that can safely be removed. If you own a workspace with other members, deletion is blocked until ownership is transferred. Shared historical records that must remain may be anonymized or have the user reference removed rather than deleting data owned by another customer. Provider backups and legally required records expire according to controlled retention processes.

Security

voiqq uses encrypted transport, server-only credentials, authenticated sessions, role and row-level authorization, request validation, rate limiting, bot protection, audit records for sensitive administration, storage ownership checks, dependency review, and account-deletion safeguards. No internet service can guarantee absolute security. Report suspected vulnerabilities through the published Vulnerability Disclosure Policy.

Your rights and choices

  • Access applicable personal data and receive a structured account export
  • Correct inaccurate or incomplete profile information
  • Request deletion, restriction, portability, or objection where applicable
  • Withdraw optional cookie or marketing consent and customize service briefings
  • Ask about international-transfer safeguards and lodge a complaint with an appropriate data-protection authority
  • Review recorded legal-document versions, cookie choices, and privacy-request history in the Privacy Center

We may verify your identity and may limit a request where law permits, including where another person has rights in shared content or a customer organization controls the requested workspace data. Authorized workspace leaders or administrators can request a separate workspace export.

Cookies and communications

Necessary storage supports authentication, security, and saved privacy choices. Optional preference, analytics, and marketing categories are controlled separately through the cookie interface. Daily, weekly, and monthly project briefings are configurable service messages enabled by default for customer accounts; each can be changed or disabled in Account Privacy & Communications. Optional marketing remains off unless selected.

Children

voiqq is intended for professional, educational, and organizational assessment work. It is not directed to children who cannot enter the applicable agreement without required parent, guardian, school, or organizational authorization.

Policy changes

Material changes are published with a new effective date and may be communicated to account holders. voiqq retains published policy versions and versioned account acknowledgements where needed to demonstrate what applied at a given time.

Open Privacy Center

Review subprocessors