Privacy Policy
1. Who we are
Void is a voice-activated global emergency and people directory service. We provide an API that lets telephony operators connect callers to emergency services and registered individuals worldwide. We are not an emergency dispatch operator.
Data controller: VOID TECHNOLOGIES (PTY) LTD. Contact: dboysen@voidtech.co.za.
2. What data we collect
People registered in the directory:
- Full name
- Phone number (stored AES-256 encrypted at rest)
- City and country (optional)
- Relationship shortcuts you define (e.g. "my brother")
API partners and website visitors:
- Email address (for API key issuance and account management)
- API key usage logs: endpoint called, timestamp, response code. No call audio or content.
- IP address (server logs, retained 30 days)
Callers using Void via telephony (IVR):
- Caller phone number, used only to resolve country context and relationship shortcuts. Not stored beyond the call session unless a relationship shortcut is saved.
- Call session ID (Twilio call SID) and duration, retained for billing and abuse detection
- Call transcripts (the text of what was said, produced by real-time speech-to-text) and a log of the actions Void took during the call (e.g. which service was searched for and connected). Phone numbers within transcripts are masked before storage. Retained for up to 90 days to review and improve routing accuracy and safety, then automatically deleted.
- No audio recordings are kept. Voice audio is processed in real time for transcription and is never stored.
Mobile app users (Void app):
- GPS coordinates at the time of an emergency query, used to find the nearest emergency service. Not stored beyond the request session.
- Expo push notification token, stored to deliver directory alerts (e.g. when someone tries to reach you). Retained until you deregister or revoke notification permission.
3. How we use your data
- To provide the directory and call-routing service
- To resolve relationship shortcuts ("call my dad") you have saved
- To improve service accuracy (aggregate analytics only, no individual profiling)
- To detect and prevent abuse of the API
- To comply with legal obligations
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Legal basis for processing (GDPR / POPIA)
- Consent: you register yourself in the directory and may withdraw at any time
- Legitimate interests: fraud prevention, security, and service improvement
- Contract performance: delivering the contracted service to API partners
- Legal obligation: where the law requires retention
5. Third-party processors
- Twilio Inc.: telephony infrastructure. Processes call metadata and audio in transit. Twilio's data processing addendum is available at twilio.com/legal/data-protection-addendum.
- Groq Inc.: real-time speech-to-text. Audio is processed and discarded; no persistent storage by Groq.
- ElevenLabs Inc.: text-to-speech for voice output.
- Railway (Railway Corp.): cloud hosting for the API and database.
All processors have signed data processing agreements. We only use processors that meet comparable data protection standards.
6. International transfers
Your data may be processed in the United States (Twilio, Groq, ElevenLabs, Railway). Where GDPR applies, transfers rely on Standard Contractual Clauses or the processor's existing adequacy mechanisms. Under POPIA, we take reasonable steps to ensure equivalent protection.
7. Data retention
- Directory registrations: retained until you request deletion
- Relationship shortcuts: retained until you delete them or deregister
- API usage logs: 12 months, then anonymised
- Call session metadata: 90 days
- Call transcripts and call action logs: 90 days, then automatically deleted
- Server access logs (IP): 30 days
8. Security
Phone numbers are stored encrypted with AES-256. Database access requires authenticated, encrypted connections. API keys are hashed. We apply the principle of least privilege across all internal systems.
No transmission over the internet is 100% secure. We take commercially reasonable measures to protect your data but cannot guarantee absolute security.
9. Your rights
Under POPIA and/or GDPR you have the right to:
- Access: request a copy of your personal data
- Correction: request inaccurate data be corrected
- Deletion: request erasure of your data ("right to be forgotten")
- Objection: object to processing based on legitimate interests
- Portability: receive your data in a machine-readable format (GDPR)
- Withdrawal of consent: at any time, without affecting past processing
To exercise any of these rights, email dboysen@voidtech.co.za with the subject line "Privacy Request". We will respond within 30 days.
To delete your registration immediately, use the "Data & Privacy" link in the footer of the main site.
10. Cookies and tracking
The Void website does not use advertising cookies, third-party trackers, or analytics SDKs. We use no persistent cookies. Server-side access logs (IP address, user agent, path) are retained for 30 days for security purposes.
11. Children
Void is not directed at children under 18 (or under 13 where local law sets a lower threshold). We do not knowingly collect personal data from minors. If you believe a minor's data has been submitted, contact us for immediate deletion.
12. Changes to this policy
We may update this policy from time to time. If something material changes, we will update the "Last updated" date above. Continued use after that date means you accept the updated version.
13. Contact & complaints
Data controller: dboysen@voidtech.co.za
If you are in South Africa and believe your rights under POPIA have been violated, you may lodge a complaint with the Information Regulator at inforegulator.org.za.
If you are in the EU/EEA, you may lodge a complaint with your local supervisory authority.