1. Who we are and how to reach us
B3 Voice is a product of B3 VOICE. The data controller for this website and for B3 Voice customer accounts is B3 Voice, a company registered in England and Wales.
- General and privacy enquiries: [email protected]
- Data subject requests and complaints: [email protected]
We have not appointed a statutory Data Protection Officer, because we are not required to. Privacy questions are handled by the company directors at the addresses above.
2. Two different roles, read this first
This notice covers two relationships that are legally distinct, and the difference decides who you should contact about what.
We are the controller for personal data about people who visit this website, enquire, subscribe to the newsletter, book a demo, or hold a B3 Voice account. That data is ours to explain, and the rest of this notice explains it.
We are a processor for the personal data that passes through a bot on a customer’s campaign: call audio and the transcript of it, and the answers a caller gives. The customer supplies the list, decides why the calls happen and holds the recordings in their own dialer; we only process that data on their documented instructions, under the data processing agreement. If you received a call from an AI agent and want your details removed, the business that called you is the controller, contact them. If you cannot identify them, write to us at [email protected] and we will pass the request to the customer responsible.
3. What we collect, and where it comes from
When you use this website
- Enquiry and demo forms, your name, email address, telephone number where you give one, company name, and whatever you write in the message.
- Newsletter sign-ups, your email address, the page you subscribed from, and the date.
- Analytics, the page viewed, referrer, campaign parameters, approximate country, device type, scroll depth, time on page and clicks on tracked elements. We do not store IP addresses. Visitors are counted using a salted digest that is rotated every day, so a record cannot be tied back to a person or followed from one day to the next.
- Cookies, a session cookie, a cross-site request forgery token and your consent choice are strictly necessary. Anything else runs only after you opt in. See the cookie policy.
- Anti-spam, form submissions are scored by Google reCAPTCHA, which processes your interaction with the page under Google’s own terms.
When you hold an account
- Account details, name, email address, hashed password, the call center you belong to and the role you hold in it.
- Orders and invoices, the bots ordered, the invoice raised, the bank transfer recorded against it and the receipt you upload as proof. There are no card payments, so no card details exist anywhere in this product.
- Service data, the dialer credentials you supply, encrypted at rest against the connection they belong to; the script, disclosure and rebuttals you send us; and the call-flow configuration built from them.
- Support correspondence, emails you send us and our replies.
Call recordings and transcripts
Where our customer has enabled recording, the audio of a call, its transcript, a summary and any details the agent was asked to capture are stored. This applies to calls answered by an AI agent and to calls answered by the customer’s own team under human-first routing. We hold this as a processor. The obligation to tell people on the call that it is being recorded sits with the customer making or receiving it.
4. Why we are allowed to use it
Under Article 6 of the UK GDPR we rely on the following, and only the following:
| What we do | Lawful basis | Why |
|---|---|---|
| Reply to an enquiry or demo request | Legitimate interests | You asked us to get in touch; replying is what you expect. |
| Provide the product to an account holder | Contract | We cannot deliver the service without it. |
| Take payment and issue invoices | Contract, and legal obligation | UK tax law requires us to keep accounting records. |
| Send the newsletter | Consent | You opted in and can withdraw from any email we send. |
| Analytics and advertising measurement | Consent | PECR requires consent for non-essential cookies and similar storage. |
| Security, abuse prevention and rate limiting | Legitimate interests | Keeping the service available and unabused. |
| Process call data for a customer’s campaign | Our customer’s basis, not ours | We act on their instructions as a processor. |
Where we rely on legitimate interests we have weighed those interests against your rights, and you may object at any time using the contact details above.
5. How long we keep it
- Website analytics, deleted automatically 400 days after collection.
- Enquiries and demo requests, 24 months from the last contact, unless they become a customer record.
- Newsletter subscriptions, until you unsubscribe, plus a suppression record so we do not email you again by mistake.
- Account and configuration data, for the life of the account, then deleted within 90 days of closure.
- Call recordings and transcripts, held in the customer’s own dialer under their retention policy. Where a transcript passes through us it is deleted when the customer asks or when their account closes. This is their decision, not ours.
- Invoices and accounting records, six years after the end of the accounting period, as tax law requires.
- Consent records, 180 days, which is how long the consent cookie lasts before you are asked again.
7. Where your data goes
Several of our sub-processors are based outside the United Kingdom, principally in the United States. Where personal data is transferred outside the UK we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with the provider’s own supplementary measures.
Processing is not currently restricted to a single region. If your organisation needs data residency confined to the UK or the EEA, raise it before you sign, we would rather tell you plainly that we cannot guarantee it today than discover it during an audit.
8. Your rights
Under the UK GDPR you have the right to:
- ask what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no overriding reason to keep it;
- restrict how we use it while a dispute is resolved;
- receive data you gave us in a portable, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time, with no justification needed;
- withdraw consent, which does not affect anything done before you withdrew it.
Write to [email protected]. We respond within one calendar month, which can be extended by two further months for complex requests, we will tell you if that happens and why. We may ask you to confirm your identity before we release anything. There is no charge unless a request is manifestly unfounded or excessive.
For a request about a call you received, see section 2: the business that called you is the controller, and we will route your request to them.
9. Complaining to the regulator
If you are unhappy with how we have handled your data, please tell us first, most things are fixable quickly. You also have the right to complain to the UK supervisory authority at any point, and you do not have to come to us first.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk/make-a-complaint.
10. Children
B3 Voice is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, write to [email protected] and we will delete it.
11. Changes to this notice
We update this notice when what we do changes. The effective date at the top of the page always reflects the current version. Where a change materially affects how we use personal data, we will tell account holders by email before it takes effect rather than relying on you to re-read the page.
Other policies
