VerifyTheCall analyzes live call audio to detect synthetic speech and to enforce payment verification protocols. That means we handle voice — one of the most sensitive categories of personal information there is. This Policy sets out exactly what we collect, the legal basis for it, how long we keep it, who we share it with, and the rights you can exercise.
Legal
Privacy Policy
Effective August 1, 2026 · Last updated August 1, 2026
1. Scope, roles, and who we are
This Privacy Policy describes how VerifyTheCall ("VerifyTheCall", "we", "us") handles personal information in connection with verifythecall.com (the "Site") and the VerifyTheCall service for call-identity verification, AI voice detection, and payment protocol enforcement (the "Service").
Two distinct roles. Our obligations depend on the relationship:
- We act as a controller (a "business" under U.S. state privacy law) for information we collect for our own purposes: Site visitors, demo requests, marketing contacts, prospect and customer administrative contacts, and our own security and billing records.
- We act as a processor (a "service provider" under U.S. state privacy law) for Customer Data — call audio, voice-derived signals, participant identifiers, meeting metadata, verification outcomes, and audit logs processed on behalf of a business customer under a written agreement and Data Processing Addendum ("DPA"). For Customer Data, the customer is the controller, determines the purposes and retention, and is responsible for the lawfulness of the processing, including obtaining any call recording, monitoring, or biometric consents required by law.
Where the DPA and this Policy conflict as to Customer Data, the DPA controls. If you are an individual whose call was processed through a customer's account, please direct requests to that customer; we will assist them as their processor.
2. Information we collect
2.1 Information you give us. Name, work email, company, role, team size, phone number where provided, and the free-text content of demo requests, support tickets, and correspondence. Billing contact and tax details for paying customers. Account credentials and authentication factors for authorized users.
2.2 Information collected automatically. IP address, approximate location derived from IP, browser and device type, operating system, referring URL, pages viewed, timestamps, session and security event logs, and API request logs (endpoint, status, latency, rate-limit counters).
2.3 Customer Data processed through the Service. Depending on the modules a customer enables: call and meeting audio streams or segments; voice-derived feature representations used for synthetic-speech detection; participant display names, email addresses, phone numbers, SIP URIs, and platform user IDs; meeting identifiers and timestamps; verification decisions and confidence scores; callback and approval records; payment-instruction metadata (amounts, thresholds, approvers, change-of-bank-details events) — not bank account contents or credentials; and the resulting audit log entries.
2.4 Information from third parties. Conferencing and telephony platforms the customer connects (Zoom, Microsoft Teams, Google Meet, Slack, SIP/PBX), identity and directory providers, resellers and partners, fraud and abuse intelligence sources, and publicly available business information used for prospecting.
2.5 What we do not want. We do not seek, and ask you not to submit, government identification numbers, financial account credentials, health records, or special-category data outside the voice data inherently present in call audio. If such data is submitted, we handle it under this Policy and delete it where practicable.
3. Voice data, biometric identifiers, and how our detection works
Because our product analyzes human speech, we treat voice data as sensitive and describe our handling explicitly rather than by implication.
3.1 What we compute. AI voice detection operates on acoustic and statistical properties of an audio segment to produce an authenticity score. In our default configuration, the intermediate feature representation is used for inference and is discarded when the analysis completes; we retain the score, the model version, and the associated metadata, not a persistent voiceprint.
3.2 Enrolled voiceprints. Some customers enable optional speaker enrollment, in which a durable voice template is stored for a named individual. Where a template is stored, it is a "biometric identifier" under laws including the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), and comparable statutes. Enrollment is off unless a customer switches it on.
3.3 Consent. Where enrollment is enabled, the customer is required by contract to obtain informed written consent from each enrolled individual before collection, disclosing that a voice identifier is collected, the specific purpose, and the retention period. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
3.4 Retention and destruction schedule. Enrolled voice templates are destroyed at the earliest of: (a) satisfaction of the purpose of collection; (b) one year after the individual's last interaction with the customer's account; (c) deletion requested by the customer or the individual; or (d) termination of the customer agreement plus the wind-down window in Section 6. Absent any earlier trigger, destruction occurs no later than three years after the individual's last interaction.
3.5 Call recording is a customer decision. VerifyTheCall can operate on transient audio without producing a retained recording. Whether audio is recorded or stored, and whether participants are notified, is configured by the customer, who is responsible for compliance with federal and state wiretap and eavesdropping laws, including all-party consent regimes such as California, Illinois, Florida, Pennsylvania, Washington, Massachusetts, and Montana, and with employee monitoring notice laws where applicable.
4. How and why we use information
We use personal information to:
- provide, configure, secure, and support the Service;
- perform call-identity verification, synthetic-voice detection, protocol enforcement, and audit logging as instructed by the customer;
- authenticate users, prevent fraud and abuse, and investigate security incidents;
- respond to demo requests, sales inquiries, and support tickets;
- bill, collect payment, and maintain financial and tax records;
- send service and security notices, and, subject to your choices, marketing;
- produce aggregated and de-identified statistics about threat patterns and Service performance; and
- comply with law and enforce our agreements.
4.1 Model training. We do not use Customer Data — including call audio, voice-derived data, or audit logs — to train, fine-tune, or improve our detection models, unless the customer opts in through a written agreement. Where a customer opts in, data is de-identified before use and biometric identifiers are excluded. We may always use our own data, licensed datasets, synthetic data, and aggregated statistics that do not identify any individual or customer.
4.2 Automated decision-making. Our scores are probabilistic signals intended to trigger human verification, not to make legal or similarly significant decisions about individuals on their own. Customers are contractually required to keep a human in the loop for any consequential action.
5. Legal bases for processing (EEA, UK, Switzerland)
- Contract (Art. 6(1)(b)) — providing the Service, account administration, billing, and support.
- Legitimate interests (Art. 6(1)(f)) — securing our systems, preventing fraud, improving reliability, and business-to-business marketing, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and responses to lawful requests.
- Consent (Art. 6(1)(a) and, for biometric data, Art. 9(2)(a)) — optional cookies, certain marketing, and any storage of enrolled voice templates. Consent may be withdrawn at any time without affecting prior processing.
Where we act as a processor, the customer is responsible for establishing the legal basis for the underlying processing and for any Article 9 condition applicable to voice data.
6. Retention
We keep personal information only as long as needed for the purpose collected, then delete or de-identify it.
- Demo requests and sales correspondence: 24 months from last contact.
- Call audio (where recording is enabled): customer-configured; default 30 days, then deletion.
- Verification scores and audit logs: customer-configured; default 12 months, extendable where the customer has a regulatory record-keeping obligation.
- Enrolled voice templates: per the destruction schedule in Section 3.4.
- Security, access, and API logs: up to 12 months.
- Billing, tax, and contract records: up to 7 years as required by law.
- Backups: deleted data persists in encrypted backups for up to 35 days and is not restored to production.
On termination, Customer Data is deleted or returned within 30 days of the customer's request, and in any event within 90 days of termination, except where retention is legally required or subject to a litigation hold.
8. Security
We maintain an information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control with least privilege, mandatory multi-factor authentication for staff, tenant isolation, key management, centralized logging and alerting, vulnerability management and penetration testing, secure development review, vendor due diligence, and personnel background checks, confidentiality obligations, and security training. Compliance attestations available to our program are provided to enterprise customers under NDA on request.
No system is perfectly secure. We do not warrant that the Service cannot be compromised, and you are responsible for safeguarding credentials and configuring access appropriately.
9. Incident response and breach notification
We maintain a documented incident response plan. Where we act as a processor, we notify the affected customer without undue delay and, where feasible, within 72 hours of confirming a personal data breach affecting their Customer Data, and provide the information reasonably needed for the customer to meet its own notification duties. Where we act as a controller, we notify affected individuals and regulators as required by applicable law. Notification is not an acknowledgment of fault or liability.
10. International transfers
We are based in the United States and use sub-processors in multiple countries. For transfers of personal data from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum, together with supplementary technical and organizational measures and a transfer impact assessment. Copies of the relevant clauses are available on request. Customers requiring regional data residency should contact us before onboarding.
11. Your privacy rights
10.1 EEA/UK/Swiss residents. Subject to conditions, you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests or direct marketing, and lodge a complaint with your supervisory authority.
10.2 California (CCPA/CPRA) and other U.S. states. You may request to know the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of recipients; to delete; to correct; to opt out of sale or sharing (we do neither); to limit the use of sensitive personal information; and to be free from retaliation for exercising these rights. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable statutes have equivalent rights, including appeal rights where provided by law.
10.3 Sensitive personal information. Voice data used to verify identity may constitute sensitive personal information. We use it only for the purposes permitted under Cal. Civ. Code § 1798.121 and analogous laws — performing the Service requested, security, fraud prevention, and legal compliance — and not to infer characteristics.
10.4 How to exercise. Email privacy@verifythecall.com. We verify your identity in a manner proportionate to the sensitivity of the request and respond within 45 days (extendable by a further 45 days with notice) or within one month under GDPR (extendable by two months). An authorized agent may submit a request with written proof of authorization. Requests concerning Customer Data are forwarded to the relevant customer.
13. Children
The Site and Service are intended for business use by adults. We do not knowingly collect personal information from anyone under 18, and the Service is not directed to children. If we learn we have collected such information other than incidentally through a customer's call audio, we delete it promptly. Contact us at privacy@verifythecall.com to report a concern.
14. Changes to this Policy
We may update this Policy. We will revise the "Last updated" date and, for material changes, provide notice through the Site or by email to account administrators at least 30 days before the change takes effect where required. Continued use after the effective date constitutes acceptance of the updated Policy.
15. Contact
Privacy requests and questions: privacy@verifythecall.com
Security and vulnerability reports: security@verifythecall.com
Legal notices: legal@verifythecall.com
EEA and UK data subjects may also contact their local supervisory authority. If you are dissatisfied with our response, you may escalate to us in writing before doing so and we will review the matter at a senior level.