Trusted Voice Research Infrastructure for NGOs, Governments & Global Development Partners
Legal

Privacy Policy

Last updated: July 2026

What we collect

When you use VoiceInsights Africa as a respondent, we collect the voice recording and/or text you provide in response to survey questions, along with basic metadata (channel used, timestamp, and — if you provide it — demographic information like gender or age band). When you use the platform as a client organization, we collect account information (name, email, organization) needed to operate your account.

What the mobile app captures in the field

When an interview is conducted on a phone or tablet using the VoiceInsights Workspace application, the saved record may also include the device's location coordinates, a photograph, and an identifier for the collecting device. Location and photographs are captured only where a question or a project asks for them. Both can be refused on the device, and an interview is completed, saved and synchronized normally without either.

The device identifier is generated by the application on that device and stored there. It is not the phone's hardware, advertising or network identifier, and it exists so that an administrator can tell which device collected which records for data-quality checks.

A respondent's name and phone number are collected only when the instrument in use asks for them. Anonymous collection — including public feedback gathered by scanning a printed QR code — records neither. Each Workspace account also carries an internal account identifier, which is what audit records attribute an action to.

How we use it

Respondent data is processed to generate transcripts, sentiment analysis, and aggregated insights for the client organization that commissioned the survey. We do not sell respondent data to third parties. Client account data is used solely to operate and bill for the service.

Service providers and subprocessors

We use contracted service providers to operate the platform. Depending on the channel and configuration selected by the commissioning organization, these may include Cloudflare for application hosting and storage, Twilio for phone, SMS and WhatsApp delivery, OpenAI or Anthropic for configured language and AI processing, and an email delivery provider for transactional notices. These providers process data on our instructions to deliver the service; this is not a sale of respondent data. A project-specific subprocessor and data-transfer schedule should be agreed during enterprise onboarding where required.

Consent

Approved collection workflows must present and record the consent process required by the applicable research protocol and channel. Respondents may stop participating in accordance with that protocol. See our Safeguarding & Compliance page for details.

Data retention and security

VoiceInsights uses encrypted connections for data in transit, and applies encryption at rest to supported sensitive data stores — including protected offline field records, which are encrypted on the device and removed after a confirmed synchronization. Security controls vary by data type, storage layer and service; we do not claim that every item held by a browser or device for a signed-in session is encrypted at rest, and no system can be described as absolutely secure. Access is restricted by role. Project retention periods, deletion schedules, permitted processing locations and international transfer safeguards must be configured in the client agreement; we do not claim a universal data-residency location for every provider. See our Security page for technical detail.

Legal basis — Tanzania Personal Data Protection Act, 2022

VoiceInsights Africa designs implementations to support applicable obligations under Tanzania's Personal Data Protection Act, No. 11 of 2022. The applicable agreement must identify controller and processor roles, permitted purposes, regulatory responsibilities and any transfer safeguards required for the customer and project. References to international principles describe design context and do not claim certification.

Your rights

If you are a respondent and want data associated with you removed, or if you are a client organization with questions about this policy, contact us at hello@voiceinsightsafrica.com.

Workspace accounts and data requests

VoiceInsights Workspace — including the Android application — is enterprise software. Accounts are provisioned and managed by your organization; there is no public self-registration and no consumer sign-up inside the application. If you need access, contact your organization administrator.

To request access to, correction of, or deletion of data held about you, or to request removal of a Workspace account, contact hello@voiceinsightsafrica.com or your organization administrator. We will acknowledge the request and identify who is able to action it.

We do not promise automatic or immediate deletion. Account and data removal may be subject to the client agreement, to the retention obligations of the organization that commissioned the research, and to legal, regulatory or research-governance requirements — including obligations to preserve consented research evidence. Where a request cannot be actioned in full, we will say so and explain why.

Status of this policy

Version: July 2026 · Next review: January 2027 · Controller/processor role: for research data collected through the platform, the commissioning organization is the controller and VoiceInsights Africa Ltd is the processor acting on its documented instructions. For account and billing data, VoiceInsights Africa Ltd is the controller.

What is operationally enforced and independently verifiable. The subprocessors and processing locations named on this page are published from a maintained register rather than typed into a page — see Subprocessors and the Trust Center, where every claim carries its own evidence and status. Consent is enforced in the product before any question is asked. Access is role-scoped and tenant-bound on every request. Retention and deletion are governed by the client agreement, which this policy does not override.

What requires an independent party, and is not claimed here. This policy has not been reviewed by external counsel, and no jurisdiction-specific adequacy assessment, transfer-mechanism opinion or data-protection impact assessment has been carried out by a third party. VoiceInsights Africa holds no SOC 2 report, no ISO/IEC 27001 certification and no independent data-residency guarantee, and the Trust Center says so by name rather than by omission.

If your organization requires a counsel-reviewed, jurisdiction-specific policy or a signed data-processing agreement for procurement, request a procurement pack and we will tell you what exists today and what has to be produced.