IVR Studio — Privacy Policy
Effective date: 2026-08-04 · Version: 1.0 — previous versions remain available at this address.
This policy explains how 9436-7455 Québec inc., doing business as NQB AI ("NQB.ai", "we"), processes personal data in connection with IVR Studio (ivr.studio). It is written to the transparency standard of the EU GDPR, which we apply as our common denominator worldwide; mandatory local law may grant you additional rights.
1. Who you are, and who is responsible (roles)
If you are a member of a customer organization (owner, admin, invited member): the organization's content is processed under the organization's control; NQB.ai processes it on the organization's behalf (processor), under the Data Processing Addendum (Terms, Exhibit A). Your account, security and platform data (Section 2) is processed by NQB.ai as controller.
If you are a visitor without an account on a page opened from a link (a technician downloading a package, a client approving audio, a narrator recording their voice): the organization that issued the link — named on the page — decides why your data is collected; it is the controller (or acts for its own end-client). NQB.ai processes that data on its behalf, and remains controller of the platform's technical logs and abuse prevention.
If an agency prepared the page for its own client, the agency may itself act for that client; the organization named on the page remains your first contact, and [email protected] always works.
2. Data we process
Members of an organization:
- Identification: name, email address, interface language,
organization membership and role.
- Sign-in and security: password hash, two-factor (TOTP) secrets,
passkeys, sessions and their revocation, sign-in events, trusted device cookies; where you use social login or enterprise SSO, the identity data your identity provider sends us (name, email, identifiers).
- Product activity: projects and content you create or edit,
generation requests, credit consumption, exports, share links you create, activity journal entries.
- Legal records: Terms acceptance records (document, version, hash of
the text presented, language, method, timestamp), acknowledgments of this policy.
- Support: tickets and messages you send us; conversations with the
built-in assistant, including the account context the assistant reads to answer.
Visitors without an account:
- Delivery/approval pages: the name you type, your decision and
comments, view and download events, technical logs.
- **Studio (voice recording) pages: the audio you record or upload —
your voice —**, the name you provide, your contribution confirmation (with the version and language of the text you confirmed), task progress, technical logs. Uploaded originals exist only transiently during conversion and quality-checking and are deleted once processing completes; only the processed telephone format is stored.
- A signed cookie keeps your identity on the link; it is specific to
that link and lasts until the link expires (links expire by default 30 days after creation).
Other people we necessarily process: people who request an account (including requests we decline — retained up to 12 months, then deleted); ordinary visitors of the marketing site (minimal technical logs, no trackers); people who send an abuse, illegal-content or IP notice (their notice and contact details, kept with the case); and pre-authentication technical logs. Purposes: operating, securing and moderating the platform (legitimate interest).
Incidental content. Scripts, comments and recordings can incidentally contain sensitive information. We do not seek it and process such content only as content, on the organization's instructions.
3. Purposes and legal bases
| Purpose | Who | Basis (GDPR) | |---|---|---| | Operating the Service on the organization's instructions (content, generation, links, exports) | members' content, visitors' contributions | processor role — the organization's basis applies | | Managing your account and access | members | contract with the organization; for members who are not the contracting party: legitimate interest in providing them access (art. 6(1)(f)) | | Security, abuse prevention, tenant isolation | all | legitimate interest (art. 6(1)(f)) — running a safe multi-tenant service | | Credit accounting; future billing | members | performance of contract (members party to the contract) / legitimate interest in administering the Service for the Customer organization (other members) | | Terms-acceptance evidence (time stamp, accepted version and text hash, interface language, IP address, browser identifier) | members | legitimate interest / legal defense | | Transactional email (reset, notifications, tickets) | members | performance of contract (members party to it) / legitimate interest in providing the Service to the Customer organization | | Support and assistant answers | members | performance of contract (members party to it) / legitimate interest in providing the Service to the Customer organization | | Platform logs of public pages | visitors | legitimate interest — operating and protecting the link mechanism |
We do not sell personal data, do not use it for advertising, do not build advertising or tracking profiles, and make no automated decisions with legal or similarly significant effect. Aggregated, non-identifying statistics may be used to operate and improve the platform.
4. AI generation, the assistant, and provider training
Voice synthesis and music generation are performed by providers listed in Section 5, on servers they operate; we send only what generation requires (for example the script text of a prompt, a voice description, a music prompt). The built-in support assistant is powered by a third-party AI provider: your assistant conversations, and the account context needed to answer, are processed by that provider for that purpose. Human voice recordings ingested into the product are processed by our own pipeline and are not sent to generation providers.
Training: whether a provider may use API data to improve its models is governed by that provider's published API terms and the settings of our account with it. The positions below reflect the provider features we actually use, as last verified on 2026-08-04 against the providers' published terms and our account settings; they may evolve with those terms, and our internal provider register records the supporting evidence:
- Primary speech-synthesis provider: we use its real-time
synthesis endpoint, for which the provider states that input text and generated audio are not retained in its logs; this statement does not extend to batch or other provider features, which we do not use. Its data-protection addendum prohibits use of customer data beyond our documented instructions. No training on our content.
- Fallback speech-synthesis / support-assistant provider: does
not use API inputs or outputs to train its models by default, as a contractual commitment; opt-in data-sharing settings exist on the provider account and we keep them disabled. API abuse-monitoring logs (which may include content) are retained by the provider for a bounded period (currently up to 30 days per its published terms) and may be reviewed, including by its authorized contractors, solely for abuse prevention.
- Speech, voice-design and music-generation provider: its
published terms permit use of API content to improve its services by default; we exercised the provider's available training opt-out on our account on 2026-08-03 (recorded with time in our internal register) and maintain it. Per the provider's terms, the opt-out is not retroactive.
- Infrastructure providers (hosting, network, email) have no
generation role; their agreements restrict processing to providing the service, and the network provider states it does not train models on customer content without customer consent.
The sub-processor schedule tracks these positions. We do not grant any provider the right to use your content for advertising.
5. Recipients: sub-processors, identity providers, your PBX
The versioned sub-processor schedule — provider, service, data categories, country, transfer mechanism — is published with the DPA (Terms, Exhibit A, Annex 3) and maintained at this address. Current providers: OVH (hosting), Cloudflare (network), a primary speech-synthesis provider (Canada), a fallback speech-synthesis and support-assistant provider (United States), a speech, voice-design and music-generation provider (United States), Resend (email). Generation and assistant providers are identified by function: their identities are confidential commercial information, available to customers under a signed DPA on written request to [email protected] (Annex 3). Stripe is not active during the Pilot and will be added, with notice, before any payment activation.
Also recipients or sources: the identity provider you sign in with (Google, Microsoft, or your company's SSO provider) sends us your identity data and may process your sign-in for its own purposes under its own terms — we remain responsible for the collection and use we make of what we receive; the PBX system an organization designates as a push target receives the artifacts pushed to it. Public pages are served to whoever holds a link — a link is a secret credential: anyone holding the URL can open it — under the issuing organization's responsibility.
We may disclose data where required by law or to protect rights, safety or the integrity of the Service, and to a successor in a business transfer under equivalent commitments.
6. International transfers
We are established in Canada and operate internationally. Hosting and processing locations are those listed in the current sub-processor schedule (Terms, Exhibit A, Annex 3) and change as the Service evolves — we make no data-residency or data-sovereignty commitment, and your data may be processed in any country listed in that schedule. For each transfer, the mechanism relied on (adequacy, provider data-processing agreement incorporating standard contractual clauses, or equivalent) is stated in the sub-processor schedule; you may request a copy or summary of the safeguards for a given provider at [email protected].
7. Retention
- Organization content (projects, audio, exports): life of the
organization. Self-service purge: request, 7-day grace period (cancellable), then deletion from active systems; individual items (for example a voice take) can be deleted at any time from the product.
- Backups: rolling rotation — snapshots kept up to 48 hours
(hourly), 30 days (daily) and 12 months (monthly); database dumps 14 days. Purged data disappears from backups as the rotation expires; the restore procedure is designed to re-apply pending purges so that deleted data is not durably resurrected.
- Account data: life of the account; deleted with the organization
purge, except the records below.
- Terms-acceptance records: 6 years (evidence period), kept
even after purge, then deletable.
- Administrative audit journal (platform staff actions): retained
without a fixed term, for platform accountability; it records staff gestures, not your content.
- Abuse/health journals: bounded per scope (for example most
recent 500 generation failures per organization).
- Share-link event journals: most recent 200 events per link, and
deleted with the link's organization.
- Studio contributions (narrator name, confirmation, recordings):
under the issuing organization's control; deleted with the project, the organization, or on per-item deletion.
- Support tickets, email and assistant conversations: kept while
relevant to the support history, reviewed at least yearly; deleted on request via [email protected] where no longer needed.
- Dormant Pilot organizations: an organization inactive for more
than 12 months during the Pilot may be closed after notice to its owner, with the export window of the Terms.
8. Your rights
Whether or not you have an account, you may request: access, rectification, erasure, restriction, objection (for processing based on legitimate interest), and portability of data you provided. Where a processing operation were ever based on consent, you could withdraw it at any time without affecting prior processing.
We answer promptly and no later than 30 days after receiving a request; a different period or an extension applies only where, and to the extent that, applicable law expressly permits it (you would be informed); we may need to verify your identity, and manifestly unfounded or excessive requests may be charged or refused within the limits of the law.
- Self-service (organization owners/admins): full data export
(zip) and organization purge are built into Settings. The export includes the requester's own acceptance records.
- Everyone, including visitors without an account (for example a
narrator who recorded their voice): write to [email protected]. Where your data lives inside a customer organization's content, we route the request to that organization (the controller) and assist it until resolution.
- Complaints: you may complain to the data-protection authority
competent for your place of residence or for us.
Note for narrators: deleting a recording that has already been delivered and installed in a third party's telephone system is addressed to that system's operator; your statutory rights against each controller are unaffected. See the studio page notice.
9. Security
Tenant isolation by organization; TLS in transit; passwords hashed; optional two-factor authentication (TOTP) and passkeys; session listing and revocation; integration secrets encrypted at rest (AES-256-GCM) with key rotation; role-based staff access on least privilege; an audit journal of administrative actions designed to be append-only; support impersonation designed to be read-only, time-boxed, audited, and disclosed to the affected organization.
10. Cookies
In its current configuration the Service sets only cookies necessary to operate it: session authentication (including OAuth/SSO sign-in state), locale preference, two-factor trusted-device, and the signed identity cookie of studio links (specific to one link, lifetime = the link's validity). No advertising, analytics or cross-site tracking cookies. Because these are strictly necessary, no consent banner is shown; if we ever introduce non-essential cookies, consent will be requested where required. Blocking the necessary cookies prevents sign-in and link-page identity, but public informational pages remain readable.
11. Children
Accounts are for professional use by adults (18+). Organizations that invite external contributors are responsible for ensuring they are adults or act with appropriate authority; if we learn that a child's data was collected in breach of this policy, we will act to delete it with the responsible organization.
12. Changes to this policy
We may update this policy. Material changes are announced to account holders in the product at least 15 days before their effective date, with an acknowledgment that does not block your work. Previous versions and their dates remain available at this address. If a future change involved a new purpose requiring consent, we would ask for that consent specifically and separately.
13. Contact
9436-7455 Québec inc. (doing business as NQB AI) · NEQ 1176322874 · Québec, Canada — registered address on file in the public Québec enterprise register.
Privacy requests: [email protected] · Legal: [email protected]
Person in charge of the protection of personal information: President, reachable at [email protected]. · Abuse and illegal-content notices: [email protected]
EEA/UK: during the Pilot, the Service is not directed at the EEA or the UK — no EEA/UK organization is approved, and customers agree not to direct links at individuals located there (Terms, Section 3.5). No EU/UK representative is appointed at this stage; this position, with the related AI-transparency and hosting-service assessments, is settled before that restriction is lifted (GDPR art. 27).
Version 1.1 — effective 2026-08-04