Privacy Policy
Last updated: August 15, 2026
1. What Data We Collect
- Account data: name, email address, hashed password, organization name, role.
- HR conversation data: transcripts, audio recordings (if uploaded), metadata (timestamps, participants), sentiment scores, topics, and risk flags generated by our AI models.
- Usage & analytics: login timestamps, feature interactions, API calls, device/browser info, IP address (for security & geo‑location of sessions).
- Communication data: email correspondence (e.g., OTP, password‑reset, welcome emails), support tickets.
2. How We Use It
- Provide and improve the VooVr service (sentiment analysis, risk detection, reporting).
- Authenticate users, enforce access controls, and secure sessions.
- Send transactional emails (OTP, password reset, billing, product updates).
- Comply with legal obligations (e.g., data‑subject requests, audit logs).
- Aggregate, anonymized analytics to improve models—never linked to identifiable individuals.
3. Data Storage & Security
All data is stored in encrypted‑at‑rest MongoDB clusters (AES‑256) with envelope encryption (KMS‑wrapped DEKs). Transit uses TLS 1.2+. Access is limited to need‑to‑know personnel; we maintain SOC‑2‑type controls and conduct annual penetration tests. Conversation transcripts are retained for 90 days by default, then auto‑deleted unless the admin configures a longer retention window.
4. Third‑Party Sharing
We do not sell personal data. We share data only with:
- AI model providers (e.g., OpenAI, Anthropic) – only the minimal text needed for inference, processed under Data Processing Addenda, no training on your data.
- Email delivery – Brevo (transactional email API).
- Infrastructure – Cloud provider (AWS/GCP) for hosting, databases, and KMS.
- Legal requests – when compelled by law, we disclose the minimum necessary.
6. Your Rights (GDPR / CCPA)
- Access – request a copy of all personal data we hold.
- Rectification – correct inaccurate data.
- Erasure – request deletion of your account and associated data (subject to legal retention).
- Portability – receive your data in a structured, machine‑readable format.
- Objection / Restriction – object to processing for direct marketing or profiling.
Submit requests to privacy@voovrhr.com. We respond within 30 days.
7. Data Retention
Account data: kept while the account is active, then purged 30 days after deletion request. Conversation transcripts: default 90‑day rolling window, configurable up to 365 days. Audit logs: 13 months for security compliance.
8. Contact Information
If you have any questions about this Privacy Policy or how we handle your data, please contact us at voovrhr@gmail.com.