Privacy Policy
This policy explains how Avanser Pty Ltd ABN 15 107 330 049 trading as VoxaLink manages personal information. It is our APP privacy policy under the Privacy Act 1988 (Cth). It applies to direct customers, resellers, end users of the mobile app and portals, callers whose calls or messages pass through the services, and people who contact us.
Contents
- 1. Who we are
- 2. Kinds of personal information we collect and hold
- 3. How we collect and hold it
- 4. Why we collect, hold, use and disclose it
- 5. Who we disclose it to
- 6. Overseas disclosure
- 7. Direct marketing
- 8. Sensitive information and government identifiers
- 9. Credit information
- 10. Recordings, transcripts and AI
- 11. Calendar connections
- 12. Cookies and similar technologies
- 13. Retention and deletion
- 14. Deleting an account and data
- 15. Access, correction and complaints
- 16. Data breach response
- 17. Children
- 18. Changes to this policy
1. Who we are
The APP entity is Avanser Pty Ltd, 81 Mooramie Ave, Kensington NSW 2033. Privacy contact: privacy@voxalink.cloud. This policy is version 2.3, last updated 8 September 2026.
You can deal with us anonymously or under a pseudonym where it is lawful and practicable. It is not practicable for a phone service, number port, emergency listing or billed account. It may be practicable for a general enquiry.
2. Kinds of personal information we collect and hold
- Account and contact details: names, email addresses, phone numbers, company details, job titles, billing contacts, authorised representatives and support contacts.
- Identity and service details: addresses, porting details, emergency-service location information, authority evidence, account numbers and service configuration.
- Technical and usage information: IP addresses, device data, browser data, authentication logs, API usage, webhook activity, call-detail records, call metadata, signalling metadata, routing logs and fraud events.
- Communications content where enabled or submitted: call recordings, voicemail, SMS bodies, transcripts, AI prompts and outputs, summaries, call-flow scripts and support messages. This can include information about callers who are not our customers.
- Billing and commercial information: plans, rates, invoices, payment status, usage charges and, for resellers, customer-ownership records. We do not store full payment-card numbers on our systems if a payment processor tokenises them.
- Credit information, if we assess credit, which may include information from a credit reporting body.
- Calendar data, if you connect Google Calendar or Microsoft Outlook: calendar names, free/busy availability, and event details we create or update for scheduling features you enable.
3. How we collect and hold it
We collect information from you when you apply, sign in, configure a service, contact support, or use the portals, APIs or apps. We collect it from your reseller if you are an end customer of a reseller. We collect it from carriers, number-porting processes, app stores, and the other party to a call or message. We collect it automatically from devices, browsers and the call path (logs, metadata, and content you have enabled).
If we collect personal information about you from someone else (for example a caller, a reseller, or a staff list you upload), we take reasonable steps to make you aware of this policy, unless that is unreasonable or impracticable in the circumstances, or the law says we do not have to.
We hold information in systems we operate in Australia and in systems operated by providers in Australia and overseas. We use access controls, authentication, encryption for selected secrets and recordings in transit and at rest where the product supports it, hashed API-token storage, signed download URLs for recordings, network controls, monitoring and least-privilege operational access.
If you do not provide information we need, we may not be able to assess an application, provide the service, port a number, list a service for emergency calling, or support your account.
4. Why we collect, hold, use and disclose it
- To assess applications, provision services, route calls and messages, support number porting, manage users and provide portal and app access.
- To provide AI voice agents, transcription, recording playback, analytics, summaries and workflow automation where those features are enabled.
- To bill, rate, reconcile, detect fraud, detect and disrupt scam and spam traffic, investigate faults, troubleshoot quality, provide support, maintain security and enforce agreements.
- To comply with law, including telecommunications, privacy, tax, accounting, fraud-prevention, consumer-protection and law-enforcement obligations, and to maintain the Integrated Public Number Database information we are required to hold.
- To improve reliability, security and product usability using de-identified or aggregated information where practical.
- To send service messages about the account, outages, billing and changes to terms. Direct marketing is described in clause 7.
5. Who we disclose it to
We disclose personal information to the types of bodies below, and only as needed for the purposes in clause 4.
- Hosting, database, object-storage, monitoring, email, support and security providers.
- Carriers, number providers, SMS providers and porting participants needed to carry calls, messages and numbers.
- AI, speech-to-text, text-to-speech, language-model, transcription or analytics providers that we select or that you connect.
- Payment processors and, if we assess credit, credit reporting bodies.
- Resellers, customer administrators and authorised representatives for the account they administer.
- Regulators (including the ACMA), the National Anti-Scam Centre, emergency services, carriers, other carriage service providers performing traceback, numbering and sender-ID operators, law-enforcement agencies, courts, the TIO, the OAIC and other government agencies where required or authorised by law, including to identify, trace, block or report scam or spam traffic.
- Professional advisers, insurers, auditors and a prospective purchaser of our business, on confidential terms.
6. Overseas disclosure
We are likely to disclose personal information to overseas recipients. The countries in which those recipients are likely to be located are the United States, Singapore, and countries in the European Union. Some support, carrier or AI providers may also operate in other countries from time to time.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles in relation to the information, typically by contract. We may remain accountable under the Privacy Act for that handling. This does not apply to a provider you connect yourself under the BYOC Policy. That provider is your disclosure.
Call audio, transcripts and messages may be processed overseas when AI, transcription or carriers are involved. If that is not acceptable for a particular workload, do not enable those features and talk to us before you send that traffic.
7. Direct marketing
We may use account contact details to tell you about VoxaLink products that are related to services you already have, where you would reasonably expect that. We will give you a simple way to opt out, and we will honour an opt-out. We do not sell personal information. We do not use call recordings, SMS bodies or calendar contents for advertising.
Reseller marketing to end customers is the reseller's activity. Resellers must comply with the Spam Act, Do Not Call rules and APP 7 themselves.
8. Sensitive information and government identifiers
Calls, voicemail and messages can contain sensitive information (for example health, union, or financial-hardship information) even if we did not ask for it. We do not solicit sensitive information unless a feature you enable requires it and collection is lawful. You must not use the services to collect sensitive information, payment-card data, or identity documents unless that collection is lawful, necessary and approved for the specific use case.
We do not adopt a government-related identifier (such as a driver licence or Medicare number) as our own identifier of an individual. We may use a government identifier only as the Privacy Act allows, for example to verify identity where reasonably necessary.
9. Credit information
If we carry out a credit assessment, we may collect credit information from you and from a credit reporting body. We use it only to assess an application, manage credit risk, and collect overdue amounts. We will not do this silently: if an external credit check is required for your application, we will tell you at that point.
10. Recordings, transcripts and AI
Recording, transcription and AI features are configurable. You (or your reseller or administrator) choose whether they are on. You must give call-recording, AI-assistance and privacy notices where the law or your own policy requires them.
We do not use customer content to train VoxaLink-owned AI models unless you agree in writing. We contract with third-party AI providers so they are not permitted to train their models on your customer content, except where you connect your own provider.
11. Calendar connections
If you connect Google Calendar or Microsoft Outlook, we access that account only to provide the scheduling features you enable: listing calendars, checking free/busy availability, and creating or updating appointment events on your behalf.
We do not use calendar information for advertising and we do not sell it. Calendar information is not read by humans except with your consent, where necessary for security or abuse investigation, or where required by law. Connection credentials are encrypted at rest and used only to operate these features.
You can disconnect a calendar in the portal, which deletes our stored connection tokens. You can also revoke access from your Google Account security settings or your Microsoft account permissions page.
VoxaLink's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Cookies and similar technologies
Our websites and portals use cookies and similar technologies that are needed to sign you in, keep a session, remember a preference such as theme, and protect against abuse. We do not use third-party advertising cookies on the customer portal. If we add optional analytics later, we will update this policy and, where required, ask before we set a non-essential cookie.
13. Retention and deletion
We keep personal information only as long as we need it for the purposes in this policy, or as the law requires. Typical operational periods are: account and billing records for seven years after the account ends (tax and corporations law); call-detail records for a period that meets telecommunications data-retention duties where those duties apply; recordings and transcripts for the period you configure, or a default product period if you do not configure one; support tickets for up to three years after closure; authentication logs for a shorter operational period unless they are needed for security investigation; scam, spam and fraud investigation records for as long as needed to report to the ACMA, complete traceback, or defend a claim.
Deletion may not remove information we must keep, including billing records, fraud and scam records, audit logs, backups until they cycle, and information a law requires us to retain.
14. Deleting an account and data
How deletion works depends on how the account was created.
If you are a direct customer or reseller who signed up with us, email privacy@voxalink.cloud from the account email to request closure and deletion. We will verify the request with an authorised representative. We will then close the account, stop the services, and delete or de-identify personal information we hold, except records we must keep.
If you are an extension user of a customer or reseller phone system, your administrator created the account. Email privacy@voxalink.cloud from the email on the account, or ask your administrator to submit the request. In the VoxaLink mobile app you can start this from Settings, then "Delete account & data". Include your extension number and domain (for example, extension 100 at yourcompany.example.com). We may confirm the request with your organisation's administrator, because the extension belongs to their phone system.
Once verified, we delete or de-identify personal data we hold about you, including stored credentials, device push tokens, voicemail, messages, call history, and recordings tied to your extension, except where we must retain billing or call-detail records. We will confirm when the request has been completed.
15. Access, correction and complaints
You may ask for access to personal information we hold about you, or ask us to correct it, by emailing privacy@voxalink.cloud. We will respond within a reasonable period. We may need to verify your identity. We may refuse or limit a request where the Privacy Act allows, and if we do we will tell you why, unless it is unreasonable to do so, and how to complain.
We will not charge you to make a request. If we charge for giving access, the charge will not be excessive.
Privacy complaints should go to privacy@voxalink.cloud. We will acknowledge the complaint within 5 business days and aim to resolve it within 30 calendar days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
16. Data breach response
If a privacy incident occurs, we will assess it and take the steps the Notifiable Data Breaches scheme and other applicable law require, including notifying affected individuals and the OAIC where that scheme applies.
17. Children
The services are for business users. We do not knowingly collect personal information from children for the purpose of offering them an account. If you believe we have done so, contact privacy@voxalink.cloud and we will delete it unless we are required to keep it.
18. Changes to this policy
We may update this policy. The current version will be published at this page with an updated date. If a change is material, we will also notify account contacts by email or a portal notice.