Last updated: 28 July 2026
This policy explains how Flireo B.V., trading as VoiceDock, handles personal data. Flireo B.V. is the legal entity; VoiceDock is the name of the platform.
VoiceDock is a business-to-business platform. Our customers build AI voice assistants on it. The people who call those assistants are our customers' end users, not ours. That distinction determines who is responsible for what, and this policy returns to it in Section 2.
1. Who we are and how to reach us
Flireo B.V. (trading as VoiceDock) Leeuwenbrug 89A, 7411 TH Deventer, the Netherlands Chamber of Commerce (KvK) 92548806
| For | Contact |
|---|---|
| Privacy questions and requests about your rights | privacy@flireo.com |
| Security vulnerabilities and suspected data breaches | security@flireo.com |
| Everything else | support@flireo.com |
Data protection officer. Flireo has not appointed a data protection officer. Article 37 GDPR requires one only where an organisation is a public authority, where its core activity requires large-scale regular and systematic monitoring of individuals, or where its core activity is large-scale processing of special categories of data.
Flireo is not a public authority, and does not process special categories of data as a core activity: our assistants are not designed to solicit health, biometric or similar data, and we do not use voice for biometric identification. On scale, the guidance from the European Data Protection Board points at organisations such as hospitals, transport operators, banks, insurers, search engines and telecommunications providers. Our volume is materially below that.
We keep this under review. If our processing grows to a scale where the assessment would change, we will appoint a data protection officer and say so here. Privacy questions go to privacy@flireo.com, which is monitored.
2. Our two roles
We hold different roles for different data, and the difference matters for who you should contact.
| We are | For | What that means |
|---|---|---|
| Controller | Account data, billing, our website and Trust Centre | We decide why and how this data is processed. This policy governs it, and you exercise your rights with us |
| Processor | Call content: audio, transcripts, recordings, summaries, analysis | Our customer decides why and how. We act on their instructions under a Data Processing Agreement. This policy does not govern it, and callers exercise their rights with that customer |
If you called a company's phone number and reached an AI assistant, we are not the controller of that conversation. The company you called is. Section 4 explains what that means for you.
3. What we process as controller
Purpose, legal basis and retention are stated together per category, so you can see what happens to a given piece of data without cross-referencing three sections.
3.1 Account and billing data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email address, organisation | Creating and authenticating your account, service notifications | Performance of a contract, Art. 6(1)(b) | Duration of the account, then 2 years |
| Billing address, VAT details | Invoicing and tax compliance | Legal obligation, Art. 6(1)(c) | 7 years (Dutch statutory retention for accounting records) |
| Payment details | Processing payment through our payment provider | Performance of a contract, Art. 6(1)(b) | Held by the payment provider; we keep transaction references for 7 years |
| Provider credentials you upload | Operating your assistants against the AI providers you choose | Performance of a contract, Art. 6(1)(b) | Until you delete them; stored as managed encrypted secrets |
| Usage and billing logs | Producing invoices, preventing fraud and abuse, capacity planning | Legitimate interest, Art. 6(1)(f) | 2 years |
Our legitimate interest, where we rely on it above, is being able to invoice accurately, to detect abuse of the platform before it harms other customers, and to plan capacity. We assessed this against your interests: the data is operational rather than sensitive, it concerns business use rather than private life, and you can object under Section 7.
3.2 Technical data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address | Securing the platform, detecting and preventing abuse | Legitimate interest, Art. 6(1)(f): protecting the service and its users | Up to 30 days in server logs |
| Browser and device information | Making the dashboard work correctly | Legitimate interest, Art. 6(1)(f): delivering a functioning interface | Session-bound |
| Application error reports | Diagnosing and fixing faults | Legitimate interest, Art. 6(1)(f): keeping the service reliable | 30 days |
| Aggregated page statistics | Understanding which pages are used | Legitimate interest, Art. 6(1)(f): improving the product | Aggregated, not linked to you |
Error monitoring. When something breaks on our servers, the error and its stack trace are sent to our error-monitoring provider, whose storage region is set to the European Union and with which we have a signed processor agreement. This is server-side only: the monitoring library is not loaded in your browser, so there is no browser telemetry and no session recording. Personal data is switched off at the library level and local variables are excluded from stack traces, so a report contains the fault and not the conversation. Call audio, transcripts, summaries and analysis are never sent to it.
Analytics. We use a cookieless analytics tool on our website and dashboard. It sets no cookies, stores nothing on your device, does not follow you to other websites, and produces aggregated counts only. We use no advertising trackers.
3.3 Trust Centre data
Our Trust Centre lets a reviewer request access to confidential security and compliance documents. For that process we are the controller.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, work email, company, reason for the request | Assessing and deciding on the request | Legitimate interest, Art. 6(1)(f): controlling who receives confidential material | 24 months from the decision |
| Decision, expiry, any revocation | Managing granted access | Legitimate interest, Art. 6(1)(f) | 24 months |
| Acceptance of the terms of access, with version and timestamp | Evidencing what was agreed | Legitimate interest, Art. 6(1)(f), and performance of that undertaking | 24 months |
| Access log: which document and version was opened, and when | Audit trail, so both sides can evidence what was shared | Legitimate interest, Art. 6(1)(f) | 24 months |
| IP address and browser user agent at those moments | Security and the integrity of the audit trail | Legitimate interest, Art. 6(1)(f) | 24 months |
We chose legitimate interest rather than consent deliberately: withdrawal of consent would require us to delete the audit trail, which would defeat its purpose for both parties. You can object under Section 7 and we will weigh that objection.
This data is held in a separate, isolated database, deliberately kept apart from the VoiceDock production platform, so that reviewer records and customer data never touch. We do not use it for marketing and we do not sell it.
3.4 Do you have to provide this data?
Providing account and billing data is a requirement for entering into and performing our agreement with you. Without it we cannot create an account, operate assistants for you or invoice you. There is no statutory obligation on you to provide it; the consequence of not doing so is simply that we cannot supply the service.
Providing data to the Trust Centre is voluntary. If you do not, we cannot assess an access request.
4. Call content: what we do and do not decide
When someone calls an assistant built on VoiceDock, we process the audio, the transcript, and any summary or analysis derived from it. We do so on the instructions of the customer who operates that assistant, who is the controller.
That customer decides what is collected and for how long, and is responsible for:
- having a lawful basis for processing the caller's data;
- informing callers, including about recording and about the fact that they are speaking with an AI system;
- responding to callers who exercise their rights.
What we provide so they can do that: a recording-consent flow, in which the caller actively opts in before any recording or AI processing begins, and GDPR Mode, in which no transcript, recording, summary or analysis is retained at all.
How long call content is kept is set by the customer's configuration, within the periods in Article 9 of the Data Processing Agreement and described in our Data Retention policy. We do not restate those periods here, because we do not set them: they are the customer's to choose within the limits we offer, and keeping a second copy of the figures in this policy would only create a version that can drift.
We do not use call content to train models. Not our own and not, by instruction, for our own purposes at any provider. Some AI providers do apply their own training defaults to API traffic; where that is so, it is stated per provider in our sub-processor list, and where a provider enables it by default we switch it off on our account.
If you are a caller and want access to, or deletion of, a conversation, contact the company you called. They hold the relationship and the decision. If you approach us, we will refer you to them without undue delay, because we are not permitted to act on your request ourselves.
5. Transparency about AI
An assistant built on VoiceDock is an AI system that speaks with people. Under Article 50 of the AI Act, which applies from 2 August 2026, people must be informed that they are interacting with an AI system unless that is obvious from the context.
That obligation rests on the party deploying the assistant, which is our customer. We support it by providing the consent and announcement flows described in Section 4, and we tell customers plainly that the obligation is theirs. We do not police how they use it.
6. Who we share data with
We share data with the sub-processors listed below. This is the single canonical list, maintained in one place, which every other document references.
It has two groups. Platform sub-processors are engaged for every customer. AI providers are engaged only where an assistant is configured to use them, so which of them apply differs per customer and per assistant.
Platform sub-processors
Engaged for every customer, whatever the agent is configured to do.
| Sub-processor | Purpose | Data residency | Transfer basis | Data categories |
|---|---|---|---|---|
| Hetzner Online GmbH Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany |
Voice infrastructure hosting (real-time media and orchestration) | Germany (Nuremberg). Gunzenhausen is the registered office, not the data centre | EU entity (Germany). No transfer mechanism required | call audio, orchestration, on-premise STT and TTS |
| Supabase, Inc. Supabase, Inc, 970 Toa Payoh North #07-04, Singapore 318992, privacy@supabase.io. Named as the data importer in Schedule 2, paragraph 1.7(c) of the executed DPA. |
Managed database and storage hosting | Germany (Frankfurt, eu-central-1) | EU SCCs 2021/914, completed in Schedule 2 of the executed DPA: Module Two where Flireo is controller (account data), Module Three where Flireo is processor on a customer's behalf (call data). Docking clause (Clause 7) excluded; Clause 9(a) Option 2 with a 30-day sub-processor notice period; Clause 17 Option 1, Irish law; Clause 18, courts of Ireland. UK and Swiss addenda included. | account data, call records, transcripts, recordings |
| Telnyx LLC Telnyx LLC, 311 West Superior Street, Suite 504, Chicago, IL 60654, USA |
Telephony (SIP inbound/outbound, numbers) | EU points of presence | HQ USA, EU SCCs in place | call audio (telephony leg), CDRs, phone numbers |
| Vercel Inc. Vercel Inc., 440 N Barranca Ave |
Dashboard and site hosting | EU region functions | HQ USA, EU SCCs in place | dashboard traffic, site traffic |
| Stripe Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (EU contracting entity of Stripe, Inc.) |
Payment processing | EU / Ireland | EU contracting entity; onward transfer to Stripe, Inc. under EU SCCs | billing data |
| Sentry (Functional Software, Inc.) Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA |
Server-side application error monitoring (crash reports and stack traces) | EU (Frankfurt, Germany) — organisation data-storage region set to European Union | HQ USA. Their DPA relies primarily on the EU-US Data Privacy Framework, with the 2021/914 SCCs as the stated fallback should the Framework be invalidated. Verified against their published DPA on 2026-07-28. No separate EU entity; their SCC schedule names the Irish Data Protection Commissioner as the competent supervisory authority. | error events, stack traces, request metadata |
| Resend Plus Five Five, Inc. (trading as Resend), 2261 Market Street |
Transactional email | EU (eu-west-1, Ireland) | HQ USA. Their DPA relies on the EU-US Data Privacy Framework (and its UK extension) alongside the 2021/914 SCCs for transfers out of the EEA. Incorporated automatically on entering their agreement; no separate signature. Verified against their published DPA and terms on 2026-07-28. | email addresses |
AI providers
Engaged only when the Customer's agent is configured to use them, so which of these apply differs per agent. A provider reached through the platform is Flireo's sub-processor whether the API key is Flireo's or the Customer's: supplying a key determines who pays, not who processes.
| Provider | Purpose | Data residency | Transfer basis | Training on Customer Data | Retention |
|---|---|---|---|---|---|
| Google (Gemini Developer API, via Google AI Studio) (platform default) Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, per Google's entity table for EMEA billing addresses. Google's processor terms define the contracting party more broadly as Google LLC, Google Ireland Limited or another Google affiliate. |
Realtime speech-to-speech and post-call analysis | No EU data residency on any tier. Google's terms state that data may be stored transiently or cached in any country where Google or its agents maintain facilities, and Google's data-residency product list does not include the Gemini Developer API. Vertex AI is the only EU-resident route. | HQ USA. Primary mechanism is the EU-US Data Privacy Framework, to which Google LLC has certified; EU SCCs (2021/914) apply as the fallback. | Not used for model improvement on the paid tier. On the unpaid tier Google does use submitted content to develop its products and human reviewers may read it. The boundary is whether an active Cloud Billing account is attached, not whether the interface is called AI Studio or the API. | Not published. Google's terms state prompts and responses are logged "for a limited period of time" for policy enforcement, without a number. The widely cited 55 days is a different thing: it is the developer-owned logging feature, which is opt-in and separate from abuse-monitoring logs. Zero data retention is available for paid projects on approval. |
| Google (Vertex AI) Google Cloud EMEA Limited, Dublin, Ireland (see the AI Studio entry on entity scope) |
Realtime speech-to-speech and post-call analysis, when the agent sets vertexai=true | europe-west4 (Netherlands), selected at the Google Cloud project and Vertex API level | HQ USA, EU region under the Data Privacy Framework with EU SCCs as fallback | Not used to train or fine-tune Google models | No persistent storage after the call; implicit caching is disabled at project level. Google may retain prompts up to 90 days in the region of origin where automated safety classifiers flag content for abuse review. |
| Mistral AI Mistral AI, French limited joint-stock corporation no. 952 418 325, 15 rue des Halles, 75001 Paris, France |
Language model inference and speech-to-text (Voxtral) | European Union by default. A US endpoint exists but is an explicit opt-in that VoiceDock does not use. Core inference runs on Microsoft (Sweden, Norway) and CoreWeave (EEA) infrastructure. | EU entity (France). Peripheral US sub-processors for payments, phone verification and agent tooling, under SCCs or adequacy | Excluded by default on the Scale plan; enabled by default on the free tier. Opt-out is available in the admin console for API traffic. | Thirty rolling days for abuse monitoring. Zero retention exists but is Scale-plan only, stateless endpoints only, and granted on application |
| Gladia Gladia, société par actions simplifiée with capital of €1,838.83, RCS Rennes 909 935 736, registered office 6B rue du Bas Village, 35510 Cesson-Sévigné, France, represented by Jean-Louis Queguiner, President. Taken from the contract itself, which supersedes the 90B rue de Fougères address on their website. Gladia Inc., 251 Little Falls Drive, Wilmington, Delaware 19808, is NOT an alternative contracting party: Annex III of the contract lists it as Gladia's own sub-processor, with outsourced operations "Storage, Processing" and data categories "Voice, transcripts". Their US entity therefore processes the call audio itself, not a peripheral function. |
Speech-to-text | VoiceDock selects their EU-West region by default, but the contract's own Annex I states data localization as **"Europe, USA"**, and Annex III lists Gladia Inc. (Delaware) as a sub-processor performing storage and processing of "Voice, transcripts". Their US entity handles the call audio itself. Further names in that annex, including OpenAI, Meta, Together, DeepL, Private AI and Mistral, also carry the USA in scope. Treat as EU-default with a materially non-EU chain, not EU-only. | EU entity (France) with a US affiliate; EU SCCs and/or the Data Privacy Framework | Excluded. Their privacy notice §1.3 states that the datasets used to test and improve their models are publicly available CC-BY corpora and that "the Datasets do not contain any voice recordings from the use of the AI Service". Separately, their security page confirms paid plans are excluded from model training; only free-plan data is used. Both statements point the same way. | Twelve months. Annex I of the contract defines the data retention period as "the length of time Gladia, as a vendor, stores customer data after it has been processed or received" and sets it at "Standard (12 months)". This matches their trust centre. Zero retention is available as an enterprise feature and Flireo has deliberately not taken it, so twelve months applies to call audio and transcripts routed through this provider. CORRECTION 2026-07-28: this entry previously claimed their documentation contradicted itself, citing "duration of the agreement plus five years" against the twelve months. That was a misreading on our side. Both figures appear in the same annex and mean different things: "Duration of processing" is how long the processing relationship runs, "Data retention period" is how long they keep the data. There is no contradiction, and this was wrongly flagged as the highest-priority open question. Customers who need call audio not to sit at a third party for a year should use on-premise speech-to-text instead. |
| Deepgram, Inc. Deepgram, Inc., 548 Market St, Suite 25104, San Francisco, CA 94104-5401, USA |
Speech-to-text | United States, because VoiceDock has not yet switched to their EU endpoint. That endpoint (api.eu.deepgram.com) reached general availability in December 2025 and, per Deepgram's own announcement, keeps processing "fully inside the EU legal boundary". It uses the same API keys and SDKs, has no waitlist, no activation step and no price difference, and requires only replacing the base URL. It covers speech-to-text, text-to-speech, the voice agent and text intelligence endpoints; the sole exclusion is their hosted Whisper models, which VoiceDock does not use because it runs Whisper on its own hardware. So the gap between this entry and EU residency is one configuration line, not a migration. Scheduled for v1.1 (ClickUp 869e9v97x). Until it ships, this entry states where the data actually goes rather than where it could go. Note their privacy policy still says data is stored on US servers. That policy dates from October 2021 and predates the EU endpoint; it is stale rather than contradictory. | HQ USA. Their privacy policy states they "frequently" enter into EU SCCs, which is not an unconditional commitment. No Data Privacy Framework certification is claimed | ENABLED by default. Deepgram's own pricing page states that the published rates opt in to their Model Improvement Program. Exclusion requires sending mip_opt_out=true on each request. Their sub-processor page also notes that data may be shared with third-party speech recognition providers, "including industry peers", for benchmarking unless opted out. | Not published. Their documentation says only that they store "fractional increments of data". Opted-out requests are retained only for the duration needed to process them. |
| ElevenLabs (Eleven Labs Inc.) Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, USA. Their EU terms name the US entity as the contracting party; an EU entity, Eleven Labs Poland sp. z o.o. (Warsaw), exists and forms part of the service delivery. |
Text-to-speech and speech-to-text (Scribe) | Hosting in the United States, the Netherlands and Singapore. EU data residency is an Enterprise feature. Note that residency limits storage only: their documentation states processing may still occur outside the selected location, including by affiliates and sub-processors. Only the combination of EU residency, Zero Retention Mode and API use restricts processing to the EU. | HQ USA. Certified under the EU-US, Swiss-US and UK Data Privacy Framework, with EU SCCs (2021/914) as an alternative | DISABLED on Flireo's account. ElevenLabs enables training by default on non-Enterprise accounts, including paid self-serve API use; the "Improve the models for everyone" setting under Terms and privacy, Data use has been switched off on our account, confirmed 2026-07-28. Customers using their own ElevenLabs key control this setting themselves and should check it. | Two years by default for agent conversation data (transcripts and audio recordings held separately), configurable per agent down to scheduled deletion. Zero Retention Mode is Enterprise-only. |
| OpenAI Ireland Ltd OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland |
Language model inference | Outside the EEA by default, primarily the United States. A Europe region (eu.api.openai.com) keeps both storage and processing in the EEA and Switzerland, but it can only be selected when a project is created, cannot be applied to existing projects, and is subject to eligibility via sales. | Contracting entity is Irish. Transfers to US affiliates rely on EU SCCs (2021/914) or an adequacy decision. OpenAI does not claim Data Privacy Framework certification in its own documentation. | Not used to train or improve models unless explicitly opted in | Thirty days for abuse-monitoring logs. The audio transcription and translation endpoints are listed with no retention. Zero retention is available for eligible customers on prior approval. |
| xAI (X.AI LLC) X.AI LLC. Their DPA leaves the data importer's address blank in Annex I of the SCCs, which is a formal defect; the only address in their documentation is the notice address, 1450 Page Mill Rd., Palo Alto, CA 94304, USA. |
Realtime speech-to-speech and language model inference | United States. Their EU privacy addendum states all personal information is processed in the US, and every entry on their sub-processor list is US-based except one UK subsidiary. Marketing pages mention "EU data residency options" but no EU endpoint is documented and the previously indexed regional endpoint now returns not-found. | HQ USA, EU SCCs (2021/914), Module Two or Three, governed by Irish law with Irish courts. No Data Privacy Framework certification claimed | Not used to train on API inputs or outputs without explicit permission | Thirty days, encrypted at rest, for abuse auditing. Zero data retention is available and, uniquely among these providers, self-serve from the console |
| Inworld (Theai, Inc.) Theai, Inc. dba Inworld AI, 1975 West El Camino Real, Suite 300, Mountain View, CA 94040, USA |
Text-to-speech | United States. All ten of their published sub-processors are US-located. EU data residency is listed as an Enterprise feature on their pricing page and an EU portal exists, but no technical documentation describes what stays in the EU. | HQ USA, EU SCCs 2021/914, completed in Schedule 1 §8 of their DPA: Module Two where Flireo is controller, Module Three where Flireo is processor. Docking clause excluded; Clause 9 Option 2 with the notice period from §2.9 (30 days). Notably, Clause 17 and Clause 18(b) both follow **the law and courts of the EU Member State in which the exporter is established**, so for Flireo that is Dutch law and Dutch courts, and the competent supervisory authority is the Autoriteit Persoonsgegevens. That is the most favourable SCC completion of any provider on this list: most name Irish law and Irish courts. UK addendum also included, with England and Wales for UK transfers. | Their terms state they do not train generally available models on non-public materials, except for feedback and content flagged for trust and safety review. Their speech-to-text documentation states audio is never used for training by Inworld or any upstream provider. Note the tension with the broad licence in their terms to use materials to "operate, maintain, and improve the Services". | Not published. Zero data retention exists but is configured per workspace via their sales team |
Sub-processors without a verified agreement
Most providers incorporate their data processing agreement automatically on acceptance of their terms. For the following, that is not the case and Flireo has not yet confirmed an executed agreement. They are listed rather than omitted, because a sub-processor engaged without an Art. 28 agreement is a gap the Customer is entitled to know about. Status as at 2026-07-27.
- Deepgram, Inc. — NOT VERIFIED. Deepgram does not publish a self-serve DPA; theirs is requested and executed. Check Flireo's records for an executed copy. Same consequence as Gladia if none exists. Note this compounds with the training default recorded below: without a DPA there is no contractual constraint on that processing either.
On your own provider credentials. Supplying your own API key changes who is billed, not who processes. We still route the audio and make the request from our infrastructure, so the provider remains our sub-processor and stays on this list. What your credential does change is the account settings at that provider, including its retention and training options, which are then yours to control.
Transfers outside the EEA. Our platform layer processes in the EEA. Several sub-processors have parent entities outside the EEA, and several AI providers process outside it. Every such transfer takes place under an adequacy decision (Art. 45 GDPR), the EU-US Data Privacy Framework where the provider is certified, or the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Art. 46 GDPR). The basis is stated per provider in the list above.
The Standard Contractual Clauses are published by the European Commission and are publicly available. To obtain a copy of the safeguards applying to a specific transfer, including the completed clauses as they apply to a particular sub-processor, write to privacy@flireo.com and we will provide them.
We do not sell personal data, and we do not share it for advertising.
7. Your rights
Where we act as controller, you have the following rights.
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain a copy of the personal data we hold about you |
| Rectification (Art. 16) | Have inaccurate or incomplete data corrected |
| Erasure (Art. 17) | Have your data deleted, where no legal obligation requires us to keep it |
| Restriction (Art. 18) | Have processing limited while a dispute is resolved |
| Portability (Art. 20) | Receive data you provided to us in a machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interest, including anything in Sections 3.2 and 3.3 |
| Withdraw consent (Art. 7(3)) | Where processing rests on consent, withdraw it at any time |
Write to privacy@flireo.com. We respond within one month, and will tell you if we need longer, as Article 12(3) allows in complex cases.
Callers should approach the company whose assistant they spoke with, for the reasons in Section 4.
Complaints. You may lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). If you are elsewhere in the EU, you may complain to your own national authority. We would appreciate the chance to resolve it first.
8. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR, in respect of the data for which we are controller. We do not profile you and we do not use your account data to score or rank you.
Assistants built on our platform generate automated summaries and analyses of calls. Those are produced on our customer's instructions, and how they are used is that customer's decision. If an assistant you spoke with makes decisions about you, the company operating it is the party to ask, and this is one reason Section 4 directs callers there.
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, encrypted secret storage, access control on a need-to-know basis, application-layer isolation between customer organisations, version-controlled change management, dependency auditing, and redundant infrastructure with automated failover.
The full description, including where our position is still developing, is in our Security Overview and Annex B of the Data Processing Agreement.
To report a vulnerability or a suspected breach: security@flireo.com.
10. Cookies
The dashboard and Trust Centre use strictly necessary cookies only, for authentication and session management. Our analytics is cookieless and stores nothing on your device. We set no advertising or tracking cookies, so no consent banner is required. Detail is in our Cookie Policy.
11. Children
VoiceDock is a business platform. We do not knowingly process the personal data of anyone under 16 as controller. Whether a caller may be a minor is a matter for the customer operating the assistant, as controller for that conversation.
12. Changes to this policy
We may update this policy. Where a change materially affects how we process your personal data, we will notify account holders by email or in the dashboard before it takes effect. The date at the top reflects the current version, and previous versions are available on request.
13. Contact
Flireo B.V. (trading as VoiceDock) Leeuwenbrug 89A, 7411 TH Deventer, the Netherlands KvK 92548806