Privacy policy
How Voxbi collects, uses, shares and protects personal data across the website, the cloud phone system and connected services.
Last updated: 9 September 2026
The Privacy Policy (the "Policy") explains how VOXBI SA ("Voxbi", "we", "us", or "our") collects, uses, shares and protects personal data when you visit voxbi.com, contact us, book a meeting, use a Voxbi account or application, or interact with the Voxbi cloud telephone service and related integrations. This Policy is developed to demonstrate our ongoing commitment to protecting your privacy rights.
Voxbi provides a business cloud PBX with browser, desktop and mobile applications, phone number and routing services, analytics, call recording, AI-generated transcripts and summaries, and integrations with business systems (collectively the "Services"). The website identifies Voxbi as the Voxbi legal entity and states that the Provider Mixvoip SA provides the regulated telecommunications network underlying parts of the service.
Any processing of your personal data is made in accordance with applicable data protection laws, including but not limited to, the European General Data Protection Regulation 2016/679 of 27 April 2016 (the "GDPR") on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
By using the Services, you acknowledge that you have been duly informed of this Privacy Policy and that you understand and accept its content.
1. Who we are
The controller for personal data collected through the Voxbi website is:
VOXBI SA – 70 Rue des Prés, L-7333 Steinsel, Luxembourg
VAT: LU204667867, RCS B105502
Telephone: +352 20 50 90 50
Voxbi is part of the Emios group. The Voxbi service is built and supported b Mixvoip, which operates the regulated telecommunications network, numbers and carrier relationships supporting the service. Depending on the service, country, order form and contracting entity, an Emios group company may act as an independent controller, joint controller or processor for particular telecom, support, billing, recruitment or regulatory operations. Your order form, service agreement, applicable data processing agreement and any specific notice will identify the relevant entity and allocation of responsibilities.
2. Scope of the Policy
This Privacy Policy applies to personal data processed through:
| Area | Examples |
| Public website | Voxbi.com pages, forms, campaign attribution and security logs |
| Sales and relationship channels | Contact, demo and pricing enquiries; meeting booking; partner and reseller contacts; events and marketing communications |
| Voxbi service | Account administration, authentication, Voxbi Cockpit, voxbi.team, desktop and mobile apps, telephony, call history, voicemails, recordings, transcripts, summaries, analytics, monitoring and support |
| Connected services | Microsoft 365, Microsoft Teams, Odoo customer CRMs, BI tools, identity providers, SIP/BYOC providers, APIs and webhooks |
| Regulated telecom operations | Number assignment and porting, call routing, usage and billing records, fraud prevention, emergency services and legally required disclosures |
This Policy does not replace Voxbi business customer's own privacy notice to its employees, callers, contacts or other individuals. It also does not govern third-party websites or services that publish their own privacy notices, including social networks, app stores, a customer's identity provider, CRM, cloud storage or carrier.
3. When Voxbi is Controller and when Voxbi is Processor
Voxbi as Controller
Voxbi generally acts as Controller when it decides the purpose and essential means of processing, including for website operation and analytics, lead handling, contracting, account and subscription administration, billing customer support, product security, fraud prevention, service communications, corporate records, legal compliance and the establishment of defence of legal claims.
For certain regulated telecommunications activities, Voxbi or the Mixvoip entity identified in the customer contract may also process traffic, numbering, billing, security, emergency-service or regulatory records under its own legal obligations. The applicable order form and telecom terms determine the responsible entity.
Voxbi as Processor
A business customer normally determines whether and why its users, employees, callers and contacts are added to Voxbi; how calls are routed; whether calls are recorded; whether AI transcription, summaries, sentiment or keyword analysis is enabled; how long customer-controlled content is retained; and which CRM, calendar, storage, API or webhook destinations receive it. For these customer-directed activities, the customer is generally the Controller and Voxbi acts as its Processor under a Data Processing Agreement.
If your data was processed through a Voxbi customer's phone system, contact that customer first to exercise your rights. We will assist the customer as required by applicable law and our contract. You may also contact us using Section 9 if you are unsure who controls the data.
4. Source of personal data
We obtain personal data from you when you browse our site, submit a form, communicate with us, book a meeting, create or use an account, place or receive a call, use a Voxbi feature, apply for a role, or interact with our social-media pages.
We may also receive personal data from:
| Source | Type of data |
| Your employer or the Voxbi customer | Name, work contact details, role, extension, permissions, group/queue membership and account configuration |
| Callers and call recipients | Telephone number, caller identity, communications content, voicemail, call events and related metadata |
| Telecom operators and porting partners | Numbers, account or carrier references, porting status, network records and regulatory documentation |
| Identity and business platforms | Microsoft, Google, Okta or similar identity; Microsoft 365 users, contacts, calendar availability and presence; Odoo or other CRM records |
| Integrations selected by a customer | Contacts, customer records, webhook events, API data, call history, recordings, transcripts and summaries |
| Resellers and referral partners | Business contact, opportunity, service-location and account information necessary to handle a referral or provide local support |
| Public or professional sources | Company websites, business directories, conference lists and professional social networks, where lawful |
Where Article 14 of the GDPR applies, we provide the required information within the legally required period, including at the first communication or disclosure where relevant, unless a lawful exception applies.
5. Personal data we process
Depending on how you interact with Voxbi and which features your organisation enables, we may process the following categories.
| Source | Type of personal data |
| Identity and professional data | Name, employer, job title, team, business address, preferred language, user ID and profile image |
| Contact data | Work email, business or mobile telephone number, postal address and communication preferences |
| Contract and account data | Customer, tenant, subscription, plan, licence, user, extension, role, permissions, account settings and service history |
| Authentication and security data | Password hash, passwordless code, bearer token SSO identifier, MFA/identity-provider, result, login time, IP address, device/browser data and audit trail |
| Website and campaign data | Requested page, timestamp, referrer, link events, UTM campaign parameters, approximate network/device information and form-submission event |
| Form and correspondence data | Enquiry type, company, message, meeting request, support ticket, attachments, preferences and communications with us |
| Billing and verification data | Invoice and VAT information, payment status, transaction reference, billing contact, plan usage, and identity/authority verification information where required. Voxbi should not retain full card details when a payment provider tokenises them |
| Numbering and porting data | Telephone numbers, current carrier, service address, authority to port, account reference and supporting identification or company documents where legally required |
| Communications metadata | Calling and called numbers, caller ID, date/time, duration, direction, outcome, queue, extension, agent, routing events, transfers, holds and network/device details |
| Communications content | Call audio, voicemail, recording and any content spoken or provided during a communication when the relevant feature is enabled |
| AI-generated and inferred data | Transcripts, speaker labels, timestamps, summaries, key points, actions, keywords, tags, searchable indexes |
| Directory, contact and calendar data | Company directory entries, CRM contacts, calendar availability, meeting selections, presence and status information |
| Integration and developer data | Customer-system URL, tenant or data base identifier, administrator/user mapping, API key or OAuth token, webhook address, API request and response metadata and integration logs |
| Device and application data | App version, operating system, device/registration identifier, push-notification token, crash or diagnostic information, microphone/contacts permissions and connectivity details, where enabled and technically collected |
| Support and incident data | Trouble reports, diagnostic logs, configuration, affected number or account, test results, security alerts and evidence needed to resolve an incident |
| Social and event data | Social profile, public interaction, event registration, attendance, message and engagement information |
| Recruitment data | CV, contact details, education and employment history, application, interview notes, references and work-authorisation information |
Please do not include sensitive personal data in a website form unless we ask for it and it is necessary. Calls and recordings may nevertheless contain special-category or confidential data depending on what participants say. The customer that enables recording or AI features is responsible for assessing that risk configuring the Services appropriately.
6. Why we use personal data, our legal bases, and retention
The table below applies when Voxbi acts as Controller. Where Voxbi acts as Processor, the customer determines the lawful basis and retention, subject to the Services' available controls and legal requirements.
| Processing purpose | Personal data | Legal basis | Retention |
| Deliver, secure and troubleshoot voxbi.com | Website, device, network, request and security log data | Legitimate interests in providing a secure and reliable website; legal obligation where applicable | Operational logs 30-90 days; security incidents for the applicable limitation period |
| Measure website use and campaign performance using cookieless Matomo | Page views, referrer, link events, campaign parameters and limited technical data | Legitimate interests in understanding and improving our site, subject to applicable ePrivacy rules | Raw analytics 13 months; aggregated reports 24 months |
| Answer contact, demo, pricing and partner enquiries | Identity, business contact, company, telephone, topic, message, source and correspondence | Steps requested before a contract; legitimate interests in B2B communication and sales | Active enquiry plus 24 months after last meaningful contact |
| Book and conduct meetings | Contact details, chosen time, notes, calendar availability and call metadata | Steps requested before a contract; legitimate interests in scheduling and relationship management | Meeting record and related correspondence for 24 months |
| Create and administer accounts, trials and subscriptions | Identity, account, authentication, plan, role, configuration and service data | Contract; legitimate interests in account administration and security | Account term, ten 18 months except where longer retention is legally requires |
| Verify eligibility or identity and prevent fraud | Identity, authority, payment, device, network and risk data | Legal obligation where applicable; legitimate interests in preventing abuse; contract | For the required verification or fraud period |
| Provide and bill telecommunications services | Account, numbers, call usage, destination, duration, invoice and payment data | Contract; legal obligations applicable to telecom, accounting, tax and emergency services | Applicable statutory periods and plan terms |
| Provide customer support and service notices | Contact, account, ticket, correspondence, diagnostic, configuration and incident data | Contract; legitimate interests in support, continuity and recordkeeping; legal obligation where applicable | Ticket life plus 3 years, longer for unresolved disputes or legal duties |
| Prevent abuse, tool fraud and security incidents | Account, device, IP, login, audit and call-pattern data | Legitimate interests in protecting customers, networks and Voxbi; legal obligation where applicable | Risk-based period; incident evidence retained as needed for investigation or claims |
| Send marketing communications | Business contact, preferences, relationship and engagement data | Consent where required; otherwise, legitimate interests or applicable customer "soft opt-in" rules | Until opt-out or loss or relevance; a minimal suppression record is retained to respect the opt-out |
| Maintain corporate, accounting and legal records | Contract, invoice, payment, correspondence, authority and dispute data | Legal obligation; legitimate interests in governance and legal claims | Applicable statutory and limitation periods |
| Recruit staff | Application, CV, communications, assessments and interview notes | Steps before an employment contract; legal obligation | Recruitment cycle only. No talent-pool implemented. |
Where Voxbi relies on legitimate interests, those interests include operating and improving a secure B2B service, answering business enquiries, preventing abuse, maintaining evidence, supporting customers and communicating about related Services. We balance those interests against the individual's rights and expectations. You may object as explained in Section 9.
Where we rely on consent, it must be freely given, specific, informed and unambiguous, and you can easily withdraw it at any time without affecting processing carried out before withdrawal.
If information is required by law or necessary to enter into or perform a contract, we will identify the required fields. Without it, we may be unable to create an account, verify eligibility, assign or port a number, process payment, provide regulated telecom functions or respond to the request.
7. Cookies and local storage
Voxbi.com uses a self-hosted Matomo instance at matomo.mixvoip.com. The current site configuration disables Matomo cookies.
The website's embedded form provider may use browser local storage or similar technology for form functionality, security and bot protection. Voxbi account applications may use cookies or device storage needed for login, authentication, session continuity, security and user preferences. These technologies are not used for advertising merely because they are necessary to operate the requested service.
8. AI transcription, summaries and tags
For the purpose of proving the best assistance to the customer, Voxbi can process call audio to produce a transcript, speaker labels, timestamps, summary, key points, decisions, actions, keyword, alerts, tags, searchable indexes. The output can be shown in the Voxbi dashboard or sent to a customer's CRM or other selected system.
Voxbi states that call audio, transcripts and summaries are processed and stored in EU data centres and that its in-house AI processing uses MeluxINA in Luxembourg.
AI outputs can be incomplete or inaccurate. They should be treated as assistance rather than authoritative record, particularly for legal, employment, financial, healthcare, disciplinary or other consequential matters. Customers should provide human review, notices, lawful bases and challenge procedures appropriate to their use.
Voxbi does not use call transcripts or other AI outputs to make a decision based solely on automated processing that produces legal or similarly significant effects for an individual. If Voxbi introduces such processing, it will provide the required information about the logic, significance, likely consequences and safeguards before the processing begins.
9. Your data protection rights
Where Voxbi processes your personal data, the GDPR grants you these following rights, that you may exercise at any time and to extent permitted by law:
Right of access: you can ask your personal data and receive a copy and related information.
Right of rectification: you can claim to correct inaccurate or incomplete data.
Right of erasure: you can ask us to delete data where the legal conditions are met.
Right of restriction: you can request the limitation of processing in specified circumstances.
Right of portability: you can receive data you provided in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract, and request direct transfer where feasible.
Right of objection: you can object to processing based on legitimate interests or public task for reasons relating to your situation. We will stop direct marketing when you object.
Right to withdraw your consent: you can retract at any time where consent is the basis, without affecting earlier lawful processing.
Right to not be subject to a solely automated decision producing legal or similarly significant effects, except where law permits and safeguards apply.
Right to file a complaint to a competent supervisory authority and seek a judicial remedy.
The European Commission and EDPB describe these rights and the conditions applying to them in their official guidance. We normally respond without undue delay and within one month. For a complex or numerous request, the period may be extended by two further months, and we will explain the extension within the first month.
To exercise a right, contact dpo@voxbi.com. Please describe the request and the context in which Voxbi processed your data. If we reasonably doubt of your identity, we may require only the additional information necessary to verify it. We do not routinely require a government ID or utility bill where a less intrusive verification method is sufficient.
When Voxbi holds data only on behalf of a business customer, we may refer the request to that customer or ask you to identify it. We will support the customer as required by law and contract.
You may lodge a complaint with the Luxembourg supervisory authority:
Commission nationale pour la protection des données (CNPD)
15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg
Website and complaint form: https://cnpd.public.lu/en/particuliers/faire-valoir.html
You may also complain to the data protection authority in the EEA where you live or work or where the alleged infringement occurred.
10. International transfers
Voxbi states that calls, call metadata, recordings, transcripts, and summaries are hosted and processed in the European Union. Customer-configured exports, BYOC arrangements or API/webhook destinations may send data to a location selected by the customer.
Limited website, support, corporate, app-store, social media or supplier data may be processed outside the European Economic Area. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, and apply supplementary technical and organizational measures appropriate to the risk.
You may contact us for information about the transfer mechanism relevant to your data and, where available, a copy of the applicable safeguard with confidential information redacted.
11. Security measures
We use technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorised access. Measures described publicly for Voxbi include EU hosting, encryption in transit, encryption of recording at rest, role-based access, SAML or OAuth/OIDC single sign-on, identity provider MFA, access and configuration logs, and real-time anti-fraud monitoring.
No system is completely secure. Customers are responsible for choosing appropriate roles and retention settings, securing devices and credentials, configuring identity-provider policies, protecting integration secrets, and promptly removing access when a user leaves or changes role.
If a personal data breach affects data for which Voxbi is Controller, we will assess and provide legally required notifications. If it affects customer-controlled data for which Voxbi is Processor, we will notify and assist the customer in accordance with the data processing agreement and applicable law.
12. Retention and deletion
We keep personal data only for as long as necessary for the purpose described, including service delivery, customer selected retention, contract administration, security, dispute resolution and legal obligations. The more specific controller-side periods are set out in Section 6.
For customer-controlled recordings and AI outputs, the configured retention period applies to the active service. Deletion from active systems may not immediately remove encrypted backup copies. Those copies should be isolated from ordinary use and expire according to a fixed backup schedule. Data exported to a customer's storage, CRM, BI tool or webhook destination is controlled by the customer and is not deleted merely because it is removed from Voxbi.
When an account ends, we delete or return processor data as the contract and applicable law require, unless raw requires continued storage. We may retain limited evidence of deletion, account closure, billing, security events, legal claims and rights requests for the applicable period.
13. Children
Voxbi is a business communications service and is not directed to children. Individuals should not create a Voxbi business account unless they have legal capacity and authority to act for the organisation concerned. If you believe a child has provided personal data directly to Voxbi without appropriate authorisation, contact us so that we can investigate and take appropriate action.
14. Change to this Policy
We may update this Policy when our services, suppliers or legal obligations change. We will post the revised version with a new "Last updated" date. If a change materially affects how we use personal data, we will provide advance notice through the website, account interface, email or another appropriate channel before the change takes effect.
Questions about this document? Contact us