[ Legal ]

Privacy Policy

Last updated: February 26, 2026

1. Introduction

Vomenta Technologies Inc. ("Vomenta," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our cloud contact center platform, websites, and related services (collectively, the "Service").

This policy applies to all users of the Service, including account administrators, agents, supervisors, and end-customers who interact with the Service through communication channels.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, company name, job title, phone number, and billing information (processed securely through our payment processor, Stripe).

2.2 Service Usage Data

We collect data generated through your use of the Service:

  • Communication Data: Call recordings, chat transcripts, SMS messages, email content, and other communications processed through the platform, as configured by your organization
  • Agent Activity Data: Login times, status changes, call handling metrics, and performance data
  • Analytics Data: Dashboard usage, report generation, and platform interaction patterns
  • Configuration Data: IVR flows, routing rules, AI agent configurations, and workspace settings

2.3 Technical Data

We automatically collect device information, browser type, IP address, operating system, and usage logs to ensure service reliability and security.

2.4 End-Customer Data

When end-customers interact with your organization through Vomenta, we process their data (phone numbers, chat messages, etc.) on your behalf as a data processor. You, as the data controller, are responsible for ensuring appropriate consent and legal basis for processing end-customer data.

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Process transactions and send billing notifications
  • Provide customer support and respond to inquiries
  • Improve the Service through analytics and usage patterns (aggregated and anonymized)
  • Send service-related notifications, updates, and security alerts
  • Detect, prevent, and address fraud, abuse, and security issues
  • Comply with legal obligations
  • Train and improve AI models (only with anonymized, aggregated data and explicit opt-in consent)

4. Data Sharing and Disclosure

4.1 Service Providers

We share data with trusted third-party service providers who assist in operating the Service:

  • Cloud Infrastructure: Hosting and data storage
  • Telecommunications: SIP trunk providers, SMS gateways for message delivery
  • AI Providers: OpenAI, Anthropic, Google for AI features (data sent per your configuration)
  • Payment Processing: Stripe for billing and payments
  • Analytics: Aggregated usage analytics for service improvement

4.2 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

4.3 Business Transfers

In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.

4.4 No Sale of Personal Data

We do not sell your personal data to third parties. We do not use your communication data for advertising purposes.

5. Data Retention

We retain your data for the duration of your subscription plus a reasonable period for backup and compliance purposes:

  • Account Data: Retained while your account is active, then deleted within 90 days of account closure
  • Communication Records: Retained per your plan tier (6 months for Starter, 12 months for Business, 24 months for Enterprise)
  • Billing Records: Retained for 7 years per financial regulations
  • Audit Logs: Retained per your plan tier (30 days for Business, unlimited for Enterprise)

You may request earlier deletion of your data subject to legal retention requirements.

6. Data Security

We implement comprehensive security measures to protect your data:

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Access Controls: Role-based access control (RBAC), multi-factor authentication, and audit logging
  • Infrastructure: SOC 2 Type II compliant data centers with geographic redundancy
  • Monitoring: 24/7 security monitoring, intrusion detection, and incident response procedures
  • Testing: Regular penetration testing and vulnerability assessments

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

7.1 GDPR Rights (EEA/UK)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a machine-readable format
  • Restriction: Restrict processing of your data
  • Objection: Object to processing based on legitimate interests

7.2 CCPA Rights (California)

  • Right to know what personal information is collected
  • Right to request deletion of personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

To exercise any of these rights, contact us at privacy@vomenta.com. We will respond within 30 days.

8. International Data Transfers

Your data may be processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, and compliance with applicable data transfer frameworks.

9. HIPAA Compliance

For healthcare customers, we offer HIPAA-compliant configurations and Business Associate Agreements (BAA). Contact compliance@vomenta.com to request a BAA.

10. Cookies and Tracking

Our website uses essential cookies for functionality. With your consent (via our cookie banner), we may load analytics cookies (e.g., Google Analytics) and, if you opt in to marketing cookies, advertising measurement tools such as Meta Pixel. Non-essential cookies are only set after you choose your preferences or accept all. You can change your choices anytime using the cookie controls on our site or your browser settings. For details, see our Cookie Policy.

11. AI and Automated Processing

Our Service includes AI-powered features such as sentiment analysis, call transcription, and automated quality scoring. You control which AI features are enabled for your organization. End-customers interacting with AI voice or chat agents are informed they are communicating with an AI system, as required by applicable law.

When using Platform-Managed AI keys, communication data is sent to AI providers for processing. When using BYOK (Bring Your Own Key) mode, data is sent directly to your AI provider under your API key and your provider's privacy terms apply.

12. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email and/or in-app notification at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

14. Contact Us

For privacy-related questions, data requests, or concerns:

For all other inquiries, please visit our Contact page or review our Terms of Service.