Effective 13 August 2026
Privacy Policy
Overview
This Privacy Policy explains how Kabosh Digital Pty. Ltd. (“Voxa Speak,” “we,” “us”) collects, uses, and protects information when you use the Voxa Speak workflow automation platform (the “Service”), including the ops console, the workflow builder, and any Voxa Speak deployment we host or that you self-host.
Information we collect
Account and contact information. Name, email address, and any other details you provide when you sign up, request a demo, or contact us.
Workflow content. The workflow definitions you build, the instances that run from them, and their execution history - including step inputs and outputs to the extent your workflows produce them.
Connector credentials. API keys, OAuth tokens, and similar secrets you provide so Voxa Speak can call the systems your workflows use (HTTP APIs, email accounts, LLM providers). These are encrypted at rest and are only decrypted at the moment a workflow step needs them.
Usage data. Log and diagnostic data about how the Service is used, such as pages visited and actions taken in the ops console, for reliability and product-improvement purposes.
How we use information
We use the information above to:
- Operate, maintain, and secure the Service, including running the workflows you build.
- Authenticate connector integrations you explicitly configure (for example, connecting a Gmail inbox via OAuth so a workflow can react to inbound email).
- Respond to support requests and communicate with you about the Service.
- Monitor, debug, and improve reliability and performance.
- Meet legal, security, and compliance obligations.
AI and third-party providers
Some workflow steps (the AI agent step) send the data you configure to a third-party language model provider you choose and connect yourself - currently DeepSeek, OpenAI, Anthropic, or Google Gemini. That data is sent only when a workflow you built calls that step, and only to the provider your connector points at. We do not use your workflow content to train our own models. Review your chosen provider’s own privacy policy for how they handle data you send them.
Data retention
We retain workflow definitions, instance history, and account information for as long as your account is active or as needed to provide the Service, then delete or anonymize it within a reasonable period, except where we’re required to keep it longer for legal or security reasons.
Security
Connector secrets are encrypted at rest. Access to production systems is limited to what’s needed to operate the Service. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at privacy@example.com.
Self-hosted deployments
If you run Voxa Speak as a self-hosted deployment, you (or your organization) are the data controller for workflow content and connector credentials stored in your own deployment - this Privacy Policy covers our hosted Service and our own handling of the account information you give us directly.
Changes to this policy
We may update this Privacy Policy from time to time. We’ll update the effective date above and, for material changes, provide additional notice.
Governing law
This Privacy Policy is governed by the laws of Australia, without regard to conflict-of-law rules.
Contact us
Questions about this policy? Email us at privacy@example.com.