Voice AI and your data: how we handle calls under UK GDPR
By The Voxline team
If an agent answers your phone, it handles personal data — names, numbers, and the reasons people are calling. Under UK GDPR that’s your responsibility as the data controller, and ours as the processor acting on your instructions. We design every deployment with that in mind.
Processing and residency
We act as your data processor and only use caller data to provide the service — never to train general models. Where our underlying voice and language providers offer UK or EU data regions, we use them, and we set out exactly which processors are involved in your Data Processing Agreement so there are no surprises.
The controls you get
- Configurable retention for recordings and transcripts, with export and deletion on request.
- Recording-consent handling, including a spoken notice at the start of calls where you need one.
- Encryption in transit and at rest; provider secrets are never exposed to the browser.
- A Data Processing Agreement, and a clear list of sub-processors.
Reference data, not instructions
There’s a subtler safeguard too. The business knowledge you give an agent is treated as clearly-labelled reference data — never as instructions it must obey. That boundary is a core defence against prompt injection: a caller can’t talk the agent into ignoring your rules or leaking information, because the system prompt always wins.
Never miss another call.
Hear a Voxline agent handle a real call, then we’ll scope one around your business.
Try Voxline