Privacy Policy
Last updatedAt VaniAgent, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI voice agent platform and services.
Effective Date: August 21, 2026
By using VaniAgent, you agree to the collection and use of information in accordance with this policy.
1.Information We Collect
We collect several types of information to provide and improve our services:
1.1Personal Information
When you register for an account or use our services, we may collect:
- Name, email address, and contact information
- Company name and business information
- Billing and payment information
- Account credentials and authentication data
- Profile information and preferences
1.2Voice and Call Data
Our AI voice agent platform processes voice communications, which may include:
- Voice recordings and transcriptions of calls
- Call metadata (duration, timestamp, phone numbers)
- Conversation analytics and sentiment data
- Voice biometric data (when enabled)
- Call quality metrics and performance data
1.3Usage Data
We automatically collect information about how you use our platform:
- IP address, browser type, and device information
- Pages visited, features used, and time spent
- API calls and integration usage
- Error logs and diagnostic data
- Cookies and similar tracking technologies
2.How We Use Your Information
We use the collected information for the following purposes:
- To provide, operate, and maintain our AI voice agent services
- To process transactions and send billing notifications
- To improve, personalize, and expand our services
- To understand and analyze how you use our platform
- To develop new features, products, and services
- To communicate with you about updates, security alerts, and support
- To detect, prevent, and address technical issues and fraud
- To comply with legal obligations and enforce our terms
- To train and improve our AI models (with appropriate safeguards)
- To provide customer support and respond to inquiries
AI Model Training: We may use anonymized and aggregated voice data to improve our AI models. Healthcare data subject to HIPAA is never used for model training without explicit consent and de-identification.
3.Data Storage and Security
We implement industry-standard security measures to protect your data:
3.1Security Measures
- End-to-end encryption for voice data in transit (TLS 1.3)
- Encryption at rest using AES-256 for stored data
- SOC 2 Type II certified infrastructure
- Regular security audits and penetration testing
- Multi-factor authentication (MFA) for account access
- Role-based access controls (RBAC)
- Automated threat detection and monitoring
- Regular security training for employees
3.2Data Storage Location
Your data is stored in secure data centers located in the United States. We use industry-leading cloud infrastructure providers with certifications including SOC 2, ISO 27001, and HIPAA compliance.
For customers requiring data residency in specific regions, we offer regional deployment options. Contact our sales team for more information.
4.HIPAA Compliance
For healthcare customers handling Protected Health Information (PHI), VaniAgent provides HIPAA-compliant services:
4.1Business Associate Agreement (BAA)
We enter into Business Associate Agreements with healthcare customers as required by HIPAA. The BAA outlines our responsibilities for safeguarding PHI and our obligations under HIPAA regulations.
To request a BAA, please contact us at compliance@vaniagent.com
4.2PHI Safeguards
- Dedicated HIPAA-compliant infrastructure for healthcare customers
- Encrypted storage and transmission of all PHI
- Access controls and audit logging for PHI access
- Regular risk assessments and security updates
- Breach notification procedures in compliance with HIPAA
- Employee training on HIPAA requirements
- Secure disposal of PHI when no longer needed
5.GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR):
5.1Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract performance: To provide services you've requested
- Legitimate interests: To improve our services and prevent fraud
- Consent: When you've given explicit permission
- Legal obligation: To comply with applicable laws
5.2Your GDPR Rights
Under GDPR, you have the following rights:
- Right to access: Request copies of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a structured format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@vaniagent.com
6.CCPA Compliance
For California residents, we comply with the California Consumer Privacy Act (CCPA):
6.1Your CCPA Rights
California residents have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of personal information
- Opt-out of the sale of personal information (we do not sell your data)
- Non-discrimination for exercising CCPA rights
6.2Categories of Information Collected
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, IP address)
- Commercial information (transaction history)
- Internet activity (browsing behavior, usage data)
- Audio and voice data (call recordings)
- Professional information (company, job title)
- Inferences (preferences, characteristics)
We do not sell your personal information.
8.Third-Party Services
We work with trusted third-party service providers to operate our platform:
8.1Service Providers
- Cloud infrastructure providers (AWS, Google Cloud)
- Payment processors (Stripe)
- Analytics services (Google Analytics)
- Customer support tools (Intercom, Zendesk)
- Email service providers (SendGrid)
- Communication services (Twilio)
- AI and machine learning services
These service providers have access to your information only to perform specific tasks on our behalf and are obligated to protect your data in accordance with this Privacy Policy.
8.2Third-Party Integrations
Our platform integrates with 8,000+ third-party applications. When you connect these integrations, you authorize us to share data with those services according to their privacy policies. We recommend reviewing the privacy policies of any third-party services you connect.
8.3Meta (Facebook, Instagram, and WhatsApp)
If you choose to connect your Facebook or Meta Business account, we access data through the Meta Graph API and Marketing API using the permissions you explicitly grant during Facebook Login. We collect and store:
- Your Meta user ID and display name, used to identify the connection
- Access tokens and granted permission scopes, stored encrypted and used only to act on your behalf
- Ad account IDs, Page IDs, Instagram account IDs, Business IDs, and Pixel or dataset IDs that you select
- Advertising campaign, ad set, and ad configuration created through VaniAgent, together with their performance metrics
- Lead form submissions retrieved from your Facebook Lead Ads, including contact fields such as name, phone number, and email address
This data is used solely to deliver the advertising and lead-response features you enabled: creating and reporting on campaigns, and contacting the leads your ads generate. We do not sell Meta data, share it with advertising networks, or use it to train AI models. We never receive or store your Facebook password.
You can revoke our access at any time by clicking Disconnect on the Ads page in your dashboard, or by removing VaniAgentAds from Facebook Settings under Apps and Websites. For full instructions on deleting this data, see our Data Deletion Instructions.
Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.
9.Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
9.1Retention Periods
- Account information: Retained while your account is active
- Voice recordings: Retained according to your plan settings (default 90 days)
- Call metadata: Retained for 2 years for analytics and compliance
- Billing records: Retained for 7 years for tax and accounting purposes
- Support tickets: Retained for 3 years
- Audit logs: Retained for 1 year (HIPAA customers: 6 years)
9.2Data Deletion
When you close your account or request data deletion, we will:
- Delete your personal information within 30 days
- Anonymize voice recordings and call data
- Retain only what is required by law or for legitimate business purposes
- Provide confirmation of deletion upon request
Note that some data may remain in backup systems for up to 90 days before permanent deletion.
10.Your Rights and Choices
You have several rights regarding your personal information:
10.1Access and Control
- Access your data: View and download your information from your account dashboard
- Update your data: Modify your profile and account settings at any time
- Delete your data: Request deletion through your account settings or by contacting us
- Export your data: Download your data in machine-readable formats
- Opt-out of marketing: Unsubscribe from promotional emails via the link in each email
10.2How to Exercise Your Rights
To exercise any of these rights, you can:
- Log in to your account and use the settings dashboard
- Email us at privacy@vaniagent.com
- Submit a request through our support portal
- Contact our Data Protection Officer (contact details below)
We will respond to your request within 30 days (or as required by applicable law).
11.Children's Privacy
Our services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@vaniagent.com. We will take steps to delete such information from our systems.
For educational institutions using our platform for students under 18, we comply with applicable laws including FERPA (Family Educational Rights and Privacy Act) and COPPA (Children's Online Privacy Protection Act) where applicable.
12.International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
12.1Transfer Safeguards
When we transfer data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Adequacy decisions where applicable
- Binding Corporate Rules for intra-group transfers
- Encryption and security measures during transfer
12.2EU-US Data Transfers
For transfers from the EU to the US, we rely on Standard Contractual Clauses and implement additional technical and organizational measures to ensure data protection equivalent to EU standards.
13.Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
13.1How We Notify You
When we make material changes to this Privacy Policy, we will:
- Update the "Last Updated" date at the top of this page
- Send you an email notification (if you have an account)
- Display a prominent notice on our platform
- Request your consent if required by law
13.2Your Responsibility
We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes your acceptance of the updated Privacy Policy.
If you do not agree with any changes, you may close your account by contacting us.
14.Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Contact Information
Email: privacy@vaniagent.com
Address: Solvea Technologies (OPC) Private Limited, D-11-A, Acharya Niketan, East Delhi, Delhi 110091, India
Data Protection Officer
Email: dpo@vaniagent.com
For GDPR-related inquiries, you may also contact your local data protection authority.
HIPAA Compliance Inquiries
For healthcare-related privacy questions or to request a Business Associate Agreement:
Email: compliance@vaniagent.com
Note: This Privacy Policy is provided for informational purposes and should be reviewed by legal counsel. VaniAgent is committed to protecting your privacy and maintaining compliance with all applicable data protection regulations including HIPAA, GDPR, and CCPA.