Privacy Policy

Sutherland Commerce Group LLC, trading as Smooth Voice Marketing Effective Date: on publication · Version 1.0

In short: this policy explains what information Smooth Voice Marketing handles, why, who it goes to, how long we keep it, where it goes, and the rights you have under UK, EU, US and Australian law. The single most important point is in section 2: for people who enquire with us, and for leads generated by advertising we fund, we decide how the information is used, so we are the Controller. For a client's own existing customer data, the client decides and we only process on their behalf.


How to read this policy

Each section opens with a non-binding, italicised "In short:" line in plain English, then the formal text. Where the two differ, the formal text governs. Capitalised terms are defined in section 22.

This policy independently honours the UK GDPR, the EU GDPR, the UK Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and other US state privacy laws, and the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), because those laws apply according to where you live and not according to any contractual choice of law. Nothing in this policy waives any mandatory data-subject or consumer right that the law of your jurisdiction confers and does not permit to be waived.


Index

  1. Who we are
  2. Scope, and who decides what happens to your data
  3. The data we collect, by surface
  4. Why we use your data, and our lawful bases
  5. Leads generated through advertising we fund
  6. Who we share your data with
  7. International transfers
  8. How long we keep your data
  9. How we protect your data
  10. Your rights (UK and EU), and how to complain
  11. California and other US state privacy rights
  12. Australian privacy rights
  13. Cookies and similar technologies
  14. Marketing communications
  15. Automated decision-making and profiling
  16. Personal-data breach handling
  17. Children
  18. Data-protection contact
  19. Changes to this policy
  20. Related documents and acceptance
  21. Mandatory local rights, and how they interact with our governing law
  22. Defined terms
  23. How to contact us and how to complain

1. Who we are

In short: a Wyoming company trading as Smooth Voice Marketing, running Meta advertising for businesses. Here is how to reach us about your data.

This policy describes how Personal Data is handled by Sutherland Commerce Group LLC, a limited liability company organised under the laws of the State of Wyoming, USA, trading as Smooth Voice Marketing ("Smooth Voice", "we", "us", "our").

We are a marketing agency. We plan, build and run advertising campaigns, funnels, landing pages and lead generation systems for business Clients, principally on Meta platforms (Facebook and Instagram).

The "Site" means the websites, funnels and landing pages we operate, currently served at smooth-voice-marketing.vercel.app, together with any successor or additional domain we use for the same purpose.

Contact us about data protection:

We review this policy at least every twelve months and on any material change.


2. Scope, and who decides what happens to your data

In short: three situations. (A) You enquire with us about our services — we are the Controller. (B) You are a member of the public who responded to an advert we funded for one of our clients — we are the Controller, jointly with that client for parts of it, and the notice on that landing page tells you so. (C) A client's own existing customer list, which the client asks us to work with — the client is the Controller and we are only the Processor.

Read this section before the rest. It determines who is responsible for your data and who you should contact.

2.1 When we are the Controller

We are the Controller of Personal Data relating to:

For all of the above we decide why and how the data is processed, and this policy applies in full.

2.2 Where we and a Client share responsibility

For a Lead generated through advertising we fund, there is a point at which the Lead's details pass to the Client so the Client can contact them and provide its services. From that point:

This is set out for the Lead in a Lead Data Notice displayed on the landing page where their details were collected, which names both us and the Client. Section 5 explains the whole arrangement, including what happens if the enquiry is not a fit.

2.3 When we are the Processor

Where a Client gives us its own existing data — for example its current customer list, its historic enquiry records, or access to its own CRM — to use in campaigns such as retargeting or customer-list audiences, the Client is the Controller and Smooth Voice is the Processor. We process that data only on the Client's documented instructions, under the Data Processing Agreement which forms part of the Client Services Agreement.

The boundary, stated plainly so it is not argued about later: data that arrives because Smooth Voice paid to generate it is Controller-side data of ours (2.1 and 2.2, and section 5). Data the Client already held before the engagement, or obtained by its own means, is the Client's data and we are its Processor (2.3). Where a single individual appears in both categories, each category is treated according to how it was obtained.

If you are an individual whose data a Client asked us to process under 2.3, please contact that Client and read that Client's own privacy notice. We will assist the Client in responding to you as the law requires.


3. The data we collect, by surface

In short: different data depending on what you did. Browsing, submitting the assessment, booking a call, taking a guide, or responding to a client's advert. Here is exactly what, for each.

3.1 Site hosting and server logs

When you visit the Site, we and our hosting provider Vercel process your IP address, user-agent, device and browser information, the pages you requested, the referring URL, and request and security logs. This serves the Site, routes requests and keeps it secure.

3.2 Advertising measurement: the Meta pixel, the Conversions API and attribution

This is the most technical processing we do and it is described in detail because it is the least obvious.

The browser pixel. The Meta pixel loads on the Site. It sets the first-party cookies _fbp and, where you arrived from a Meta advert, _fbc, and reports page views and conversion events to Meta. See the Cookie Policy, which also explains the current position on consent honestly.

Advertising click identifiers. When you arrive from an advert, the identifier in the link (fbclid from Meta, and gclid, gbraid or wbraid from Google search advertising) is stored in your browser's local storage for up to 90 days, along with any utm_ tags for the session. This is first-party attribution: it lets us tell which advert produced an enquiry.

The Conversions API and the attribution record. When you submit the assessment, we send a conversion event from our server directly to Meta, in addition to the browser pixel. To make that event match the browser that saw the advert, we store a record in a database table called meta_attribution containing, against your email address:

When you later book a call, the booking reaches us from Cal.com's server with an email address and nothing else, and we look up that record so the conversion can be credited to the right advert.

What goes to Meta. Your email address, phone number and name are hashed with SHA-256 before transmission and are never sent to Meta in readable form. The _fbp and _fbc values, your IP address and your user-agent are sent as they are, because Meta requires them in that form to match the event. Meta uses this to measure and optimise advertising. Meta is an independent controller for its own purposes; see Meta's own terms and privacy policy.

We do not sell your data and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA. See section 11.

3.3 The qualification assessment

When you complete the assessment on the Site we collect:

We also record which advert or link brought you, the page path, and behavioural events on the page such as page views and how far you scrolled, against a first-party visitor identifier held in the sv_offer_vid cookie.

This goes into our CRM, GoHighLevel, and into our own database at Neon. Where the submission qualifies, it also opens a pipeline record and sends the server-side conversion described in 3.2.

We use this to respond to your enquiry, decide whether we can help you, prepare for the conversation, and sell to you.

3.4 The enrichment crawl and the AI brief

In short: after you submit the assessment we look at your business's public website and public advertising, and generate an internal summary before we speak. This is profiling and we are telling you about it.

When you submit the assessment, and after your details are already saved, we automatically:

The brief and the findings are stored in our database and written to your record in GoHighLevel so that whoever speaks to you has read it.

What this is and is not. It uses information the business has published publicly, plus the answers you gave us. It does not access anything private, it does not log in to anything, and it does not make any decision about you on its own — see section 15. It is preparation for a sales conversation.

Your right to object. This is profiling carried out on the basis of our legitimate interests. You can object at any time at privacy@smoothvoice.ai, and we will stop and delete the brief.

3.5 Booking a call

When you book a call with us through Cal.com, we collect your name, email address, the time of the meeting and anything you enter when booking. Cal.com's booking widget is embedded in our page and loads from Cal.com's servers. We use this to schedule and hold the call, and we send you confirmations and reminders.

3.6 The pre-call page, videos and lead magnets

If you book a call, we may send you a personal link to a pre-call page. That link is unique to you. On that page we record which videos you started, how far through you got, and which guides you opened or claimed, against your link, so we know what you have already seen before we speak.

Videos on the Site and on that page are hosted by Wistia, whose player loads on our pages and receives your IP address, user agent and viewing behaviour.

If you request a lead magnet (a guide or PDF), we collect your email address and name, create a contact record in GoHighLevel, and email you the guide.

3.7 The speed-to-lead demonstration

In short: we run a demonstration in which an AI voice agent calls you back within seconds of a form submission, to show a client what the system does. If you take part, you are speaking to an AI and the call is recorded.

We operate a demonstration of an automated "speed to lead" callback. Where you submit a demonstration form and it is enabled for your number, we process:

You are speaking to an AI voice agent, not a person, and the agent says so. The call is recorded and transcribed so the demonstration can be shown and reviewed. We do not create a voiceprint from your audio and do not use your voice to identify you.

This feature is restricted: calls and messages only go to numbers on an internal allow-list and are subject to daily caps and a per-number guard, because it is a demonstration and not a marketing channel.

3.8 Email, SMS and messaging

We send transactional and follow-up messages through GoHighLevel (so that the whole conversation sits on your record and anyone picking it up can see it), and through Resend for certain automated emails. SMS is delivered by Twilio. We process your email address, phone number, name and the message content, and whether a message was delivered and opened.

3.9 Internal alerts

When something needs a human — for example if a submission fails to reach the CRM — we post an internal alert to our own team channel on Discord. That alert can contain your email address and company name. It goes to our internal channel only.

3.10 Recipients, and automated processing, at a glance

Recipients are the providers named in section 6. Some processing is automated — the enrichment crawl and AI brief (3.4), the qualification rules (3.3), and the demonstration voice agent (3.7) — but we do not make a decision about you based solely on automated processing that produces a legal effect or similarly significantly affects you. See section 15. We do not sell your Personal Data and we do not share it for cross-context behavioural advertising.


4. Why we use your data, and our lawful bases

In short: for each thing we do, this says what we use and which legal ground under Article 6 applies. Where we rely on legitimate interests we have weighed our interest against your rights and can show that on request.

PurposeData usedLawful basis (UK/EU GDPR Art 6)If legitimate interests, the interest
Serving and securing the SiteIP, user-agent, request and security logsArt 6(1)(f) legitimate interestsOperating and protecting the Site
Advertising measurement and attribution (Meta pixel, Conversions API, meta_attribution, click identifiers)_fbp, _fbc, click identifiers, IP, user-agent, hashed email, phone and name, conversion eventsConsent (Art 6(1)(a)) where the law requires consent for the cookie or similar technology; Art 6(1)(f) for the server-side measurement that followsKnowing which advertising works, so we do not spend our own money blindly
Responding to and qualifying an enquiry (assessment, GoHighLevel, pipeline)Name, company, website, email, phone, assessment answersArt 6(1)(b) steps prior to a contract at your request; and Art 6(1)(f)Responding to a business that approached us and deciding whether we can help it
The enrichment crawl and AI brief (3.4)Public website content, public advertising records, tracking technology, published business contact details, assessment answersArt 6(1)(f) legitimate interestsPreparing properly for a sales conversation using information the business has published
Scheduling and holding calls (Cal.com)Name, email, meeting detailsArt 6(1)(b) pre-contract steps
Pre-call page, video and guide engagement (3.6)Link token, video progress, guide claimsArt 6(1)(f) legitimate interestsNot repeating at someone what they have already watched
The speed-to-lead demonstration (3.7)Name, mobile, call audio, transcript, SMS contentConsent (Art 6(1)(a)) — you submit the form to start it
Generating and qualifying Leads for Clients through advertising we fund (section 5)Name, contact details, enquiry details, qualification answersArt 6(1)(f) legitimate interests, with notice at collection; consent where the law requires it for the channelOperating a lead generation business, and connecting a person who asked for a service with a provider of it
Passing a Lead to the Client who will serve them (section 5)Name, contact details, enquiry detailsArt 6(1)(b) steps prior to a contract at the Lead's request; and Art 6(1)(f)Doing the thing the person asked for when they enquired
Passing an unsuitable enquiry to another provider (section 5.5)Name, contact details, enquiry detailsArt 6(1)(f) legitimate interests, disclosed at collection and with a right to objectConnecting someone we cannot help with someone who can
Transactional and follow-up messaging (GoHighLevel, Resend, Twilio)Email, phone, name, message content, delivery dataArt 6(1)(b) contract or pre-contract; Art 6(1)(f)Communicating with people who enquired
Marketing email to business contactsEmail, name, engagementConsent (Art 6(1)(a)), or the PECR soft opt-in in the UK; opt-out for B2B under US law; APP 7 in AustraliaPromoting our own similar services to interested business contacts
Internal alerting (Discord)Email, company nameArt 6(1)(f) legitimate interestsNoticing when an enquiry fails to reach the CRM so it is not lost
Managing the Client relationship and billingClient contact details, engagement recordsArt 6(1)(b) contract; Art 6(1)(c) legal obligation for tax and accounting
Establishing, exercising or defending legal claimsWhatever is relevantArt 6(1)(f) legitimate interests; Art 6(1)(c) where a legal obligation appliesDefending ourselves and meeting regulatory obligations

Where we act as Processor for a Client's own data (2.3), the lawful basis is the Client's to establish, and we act only on its documented instructions.


5. Leads generated through advertising we fund

In short: if you responded to an advert, filled in a form or booked a visit through a funnel that Smooth Voice paid for, we are a controller of your details, we pass them to the business that will actually serve you, and we tell you all of this on the page where you give them to us. If that business cannot help you, we may pass you to another provider who can — and you can say no.

This section explains an arrangement that is unusual enough to deserve its own section.

5.1 What we do

We fund and operate advertising, landing pages and booking funnels for our business Clients. When you respond to one of those adverts and enquire — by filling in a form, booking a call, requesting a quote or booking a visit — your details are collected through a system that Smooth Voice built, pays for and runs.

5.2 Our role

Because Smooth Voice decides how those funnels work, what is asked, how enquiries are qualified, where the data is stored and how long it is kept, Smooth Voice is a Controller of that data. The Client that will serve you is also a Controller, for what it does after we pass your enquiry to it.

We are describing a data protection role, not a claim to own you or your information. Personal data is not property and cannot be owned by anyone. What we hold is a controller's responsibility for the data, rights in the compiled database, and a contractual arrangement with our Client about who may use it and when. Your rights under section 10 apply to us in full, whatever our commercial arrangement with the Client says.

5.3 What you are told, and when

Every landing page and funnel we run for a Client carries a Lead Data Notice at the point your details are collected. It names Smooth Voice and it names the Client, says what is collected and why, says that your details are shared between us, says that we may pass you to another provider if the Client cannot help, and links to this policy. If you did not see it, tell us at privacy@smoothvoice.ai and we will investigate.

5.4 Passing your enquiry to the Client

We pass your details to the Client so it can contact you and provide the service you enquired about. The Client's licence to use your details comes from its agreement with us and can end — for example if that agreement ends. If it does, that does not by itself require the Client to stop contacting you: where the Client has built its own relationship with you, for example because you became its customer, it has its own lawful basis and its own responsibility as a Controller. Ask the Client directly about that, and see its own privacy notice.

5.5 If the enquiry is not a fit

Sometimes an enquiry does not match what the Client can do — wrong area, wrong service, or outside the criteria we agreed with them. Where that happens we may pass your details to another provider who may be able to help you. This is disclosed to you in the Lead Data Notice at the point of collection, and it is done on the basis of our legitimate interests.

You can stop this. Object at any time at privacy@smoothvoice.ai and we will not pass your details on. We only do this where the disclosure was present when your details were collected; where it was not, we do not do it at all.

5.6 Aggregated performance data

We use aggregated and anonymised information about how campaigns perform — conversion rates, costs, volumes — without limit, including in our own marketing. Once aggregated and anonymised this is no longer Personal Data and cannot be traced back to you.


6. Who we share your data with

In short: a defined set of named providers who process data for us under contract. The list below is the real one, checked against our own source code, not a generic list.

Each recipient below acts as our processor (or, where we act as Processor for a Client, as a Sub-processor) under a written contract incorporating Article 28 UK/EU GDPR terms where applicable.

RecipientRoleUsed forPrimary location
Vercel Inc.Hosting, serverless functions, edge networkServing the Site and running our API endpointsUSA / global
Neon Inc.Managed Postgres databaseOur application database: enquiries, assessment answers, behavioural events, attribution records, enrichment outputUSA / EU by region
HighLevel Inc. ("GoHighLevel")CRM, pipelines, email and SMS conversationsContact records, pipeline records, the AI brief, message threadsUSA
Meta Platforms, Inc. / Meta Platforms Ireland LtdAdvertising platform, pixel, Conversions API, Ad LibraryAdvertising measurement and optimisation; public advertising lookupsUSA / EU
Cal.com, Inc.Booking and schedulingBooking calls, and the booking widget embedded on our pagesUSA
OpenRouter, Inc.AI model routingGenerating the internal brief described in 3.4USA
Resend (Plus Five Five, Inc.)Transactional emailAutomated emailsUSA
Twilio Inc.SMSText messagesUSA
ElevenLabs Inc.Conversational AI voice agentThe speed-to-lead demonstration (3.7) onlyUSA
Wistia, Inc.Video hosting and playerVideos on the Site and pre-call pagesUSA
Discord Inc.Internal team alertsInternal notifications to our own channel (3.9)USA
PostHog Inc.Product analytics and session replaySite usage measurement: pages you view, how far through a video you watch, which steps of the assessment you reach, and clicks on links and buttons. Also session recordings of your visit, in which everything you type into a form field is masked in your browser before the recording is sent. Requests are routed through our own domain rather than sent direct to PostHogEU instance (eu.i.posthog.com)

Providers we do not use. We do not use Google Analytics, Google Ads conversion tracking, or any Google advertising technology on the Site at present. If that changes, this policy and the Cookie Policy will be updated before it goes live.

No model training on your data. We do not use your Personal Data to train, fine-tune or improve any AI model, and we do not permit our providers to use it to train their own or any third party's models. The AI brief in 3.4 is generated by sending information to a model for a single response; it is not training data.

We may also disclose Personal Data where required by law, court order or lawful request from a public authority; to establish, exercise or defend legal claims; or in connection with a sale or reorganisation of our business, in which case the recipient is bound to protect it.


7. International transfers

In short: most of our providers are in the United States, so your data goes there. For every US transfer we keep the Standard Contractual Clauses and the UK Addendum in place as the baseline, so no transfer becomes unlawful if any adequacy framework is struck down.

Our stack is predominantly US-based, so Personal Data we process is transferred to the United States and, for some providers, processed globally. We make those transfers under Chapter V of the UK/EU GDPR:

You can ask us about the safeguards for a specific provider, and for a copy of the relevant clauses, at privacy@smoothvoice.ai.


8. How long we keep your data

In short: only as long as we need it, then we delete or anonymise it. Here are the periods.

Data categoryRetentionWhy
Site server and security logs30 daysSecurity and operations
Advertising click identifiers in your browser90 days from captureAttribution window
meta_attribution records (_fbp, _fbc, IP, user-agent against an email)90 days from last updateLong enough to attribute a booking that follows an advert click; no longer
Behavioural events on the Site (offer_events)24 monthsUnderstanding and improving the funnel
Enquiry and CRM records for people who did not become Clients24 months from last contactSales lifecycle, and so we know we have already spoken
Enrichment findings and the AI brief24 months from generation, or on requestPreparing for and recalling a sales conversation
Pre-call page engagement (video progress, guide claims)12 monthsRelevant only around the call
Speed-to-lead demonstration call audio and transcript30 days, then deletedIt is a demonstration; there is no reason to keep it
SMS and email message records24 monthsRecord of what we sent to whom
Lead records generated for Clients (section 5)Duration of the Client engagement plus 12 monthsBilling evidence, dispute resolution, and the licence arrangement
Client relationship, billing, tax and accounting records7 yearsLegal obligation
Marketing suppression listKept for as long as needed to honour your opt-out, minimised to the email address onlyWe are required to keep suppressing you
Anything under legal holdUntil the matter concludesEstablishing, exercising or defending legal claims

Where data must be kept longer to comply with a legal obligation or to establish, exercise or defend legal claims, we keep only what is necessary for that purpose. For Client data we process as Processor (2.3), retention is governed by the Data Processing Agreement and set by the Client, not by this table.


9. How we protect your data

In short: encryption in transit, tight access, vetted providers, and we take incidents seriously.

We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS) for all connections and API calls, encryption at rest where our providers support it, least-privilege access controls with credentials held as environment secrets and never in source code, hashing of identifiers before transmission to advertising platforms (section 3.2), rate limiting and abuse controls on public endpoints, and engaging only providers who offer sufficient guarantees under Article 28 of the UK/EU GDPR.

No method of transmission or storage is completely secure, but we work to protect your data and to detect, investigate and respond to incidents.


10. Your rights (UK and EU), and how to complain

In short: you can ask to see your data, fix it, delete it, restrict or object to how we use it, take a copy elsewhere, or withdraw consent. It is free. Email us and we will answer within a month.

If you are in the UK or the EU you have the following rights in relation to Personal Data we hold as Controller:

To exercise any right, contact privacy@smoothvoice.ai. It is free. We may need to verify your identity first. We will respond within one month, extendable by two further months for complex or numerous requests, and we will tell you if we need the extension. Where more than one privacy regime applies to you, we apply the timeframe most favourable to you.

Complaints. Complain to us first at privacy@smoothvoice.ai. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk, 0303 123 1113); in the EU, your local data protection authority.


11. California and other US state privacy rights

In short: if you are in California or another US state with a privacy law, you have rights to know, delete, correct and opt out. We do not sell or share your personal information, and we honour Global Privacy Control signals.

This section applies to residents of California under the CCPA/CPRA and, to the extent they apply, residents of other US states with comprehensive privacy laws.

11.1 Categories collected, and our no-sale statement

Acting as a business, we collect: identifiers (name, email, phone, company, IP address, cookie and device identifiers); commercial information (your enquiry, your industry, the services you are interested in); internet and network activity (pages viewed, scroll depth, referring advert, video progress); professional information (your role, your business contact details, your business's public web presence); inferences (the internal brief described in 3.4); and, only where you take part in the demonstration in 3.7, audio information (the demonstration call and its transcript).

In the preceding 12 months Smooth Voice Marketing has not sold, and has not shared for cross-context behavioural advertising, the personal information of any consumer, and does not sell or share the personal information of consumers under 16.

Advertising technology on the Site is used for first-party measurement of our own advertising — knowing which advert produced an enquiry — and not to sell your information to anyone or to make it available to third parties for their own cross-context behavioural advertising.

11.2 Your rights

Subject to law and verification you may: know and access the personal information we collected; delete it; correct it; opt out of sale or sharing (we do not sell or share); limit the use of sensitive personal information; and not be discriminated against for exercising any right.

To exercise these rights, email privacy@smoothvoice.ai. We verify your identity against our records before acting. We respond within 45 days, extendable by a further 45 where reasonably necessary. Where more than one regime applies to you, we apply the timeframe most favourable to you.

11.3 Global Privacy Control

We honour the Global Privacy Control signal. If your browser sends one, we treat it as a valid opt-out of any sale or sharing associated with that browser. Because we do not sell or share, there is nothing for it to stop, but we recognise and honour it.

11.4 Sensitive personal information

We do not seek sensitive personal information. The only route by which it could reach us is if you volunteered it during a demonstration call (3.7) or typed it into a free-text answer. We use any such information only to provide and document the thing you asked for, within the limited purposes permitted by Cal. Civ. Code § 1798.121 and 11 CCR § 7027, and never to infer characteristics about you. On that basis we are not required to offer a "Limit the Use of My Sensitive Personal Information" link, but we will honour any such request sent to privacy@smoothvoice.ai.

11.5 Authorised agents

You may use an authorised agent. We may require written, signed permission from you and may ask you to verify your identity with us directly.

11.6 Automated decision-making technology

California's ADMT regulations give notice, access and opt-out rights where automated technology is used to make a significant decision about a consumer. We do not use automated technology to make a significant decision about you — the enrichment crawl and AI brief (3.4) prepare a human for a conversation, and the qualification rules (3.3) decide only whether we offer you a call. Neither determines your access to, or the price or terms of, any good or service. If that changes we will provide the required notice, access and opt-out. See also section 15.


12. Australian privacy rights

In short: if you are in Australia, the APPs give you rights to access and correct your information and to complain to us and then to the OAIC.

This section reflects our handling of personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Complaints. Complain to us first at privacy@smoothvoice.ai. If you are not satisfied, complain to the Office of the Australian Information Commissioner (oaic.gov.au).


13. Cookies and similar technologies

Cookies and similar technologies on the Site are covered by our Cookie Policy, which lists what is actually set, by whom, and for how long, and which states plainly the current position on consent. In the UK, PECR also applies.

Separately from cookies, the click identifiers described in 3.2 are held in your browser's local storage rather than in a cookie. They are covered by the same rules and are described in the Cookie Policy.


14. Marketing communications

In short: we email you marketing only where you agreed or where the B2B soft opt-in allows. Every marketing email has a one-step unsubscribe.

We send marketing emails where you have consented, or where you are an existing or prospective business customer who gave us your details and we are marketing our own similar services — the PECR soft opt-in in the UK, the opt-out standard for B2B in the US, and APP 7 in Australia. Every marketing email tells you how to unsubscribe in one step, at no cost. For US recipients our marketing emails carry a valid postal address and a working opt-out, consistent with CAN-SPAM.

If you unsubscribe, we keep your email address on a suppression list solely so we do not contact you again, and for no other purpose.


15. Automated decision-making and profiling

In short: we do profile you — we look at your business's public information and have a model write a brief about it. We do not let a machine decide anything significant about you.

Profiling. The enrichment crawl and AI brief described in 3.4 is profiling within the meaning of the UK/EU GDPR: we analyse information about a business to prepare for a sales conversation. We are telling you about it here rather than leaving it unsaid, and you can object under section 10.

Article 22. We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The qualification rules in 3.3 decide only whether we offer you a sales call and whether we treat the enquiry as a fit; a person reviews and decides everything that follows. Being told you are "not a fit" for our services is not a legal or similarly significant effect: it means we are not selling to you.

If that ever changed, we would tell you, explain the logic in general terms, and give you the right to obtain human intervention, express your view and contest the decision.

California ADMT. See section 11.6.


16. Personal-data breach handling

We assess personal-data breaches and, where required, notify the relevant supervisory authority and affected individuals within the timeframes the law sets — for the UK and EU, the ICO or the relevant supervisory authority within 72 hours of becoming aware where the threshold is met, and affected individuals where there is a high risk to their rights and freedoms; in Australia, the OAIC and affected individuals under the Notifiable Data Breaches scheme; and consistently with applicable US state breach-notification laws. Where we act as Processor for a Client, we notify the Client without undue delay so it can meet its own obligations, as the Data Processing Agreement sets out.


17. Children

The Site and our services are directed at businesses, not at children. We do not knowingly collect Personal Data from children under 16. If you believe a child has given us Personal Data, contact privacy@smoothvoice.ai and we will delete it.

Where we generate Leads for a Client through advertising we fund (section 5), the advertising is targeted at adults and the services advertised are for adults. Where a Client's own sector carries an age restriction, that restriction and any age screening is addressed in the Client Services Agreement.


18. Data-protection contact

In short: one email address reaches us about anything on this page, wherever you live.

Our data-protection contact is privacy@smoothvoice.ai. It is monitored, it is free to use, and all of the rights in section 10 apply in full however you contact us.

If you are in the UK or the EU, you may contact us at that address directly about any matter in this policy, including to exercise any right in section 10 or to make a complaint under section 23. Where we have appointed a representative under Article 27 of the UK or EU GDPR, their name and address will be published in this section.

Data Protection Officer. We have assessed our processing and concluded that we are not required to appoint a statutory Data Protection Officer under Article 37, because our core activities do not consist of large-scale processing of special-category data and do not involve large-scale, systematic monitoring of individuals as a core activity.


19. Changes to this policy

We may update this policy. The Effective Date and Version at the top show the current version. We review it at least every 12 months and on any material change to our processing or to the law. Where a change is material we will take reasonable steps to bring it to your attention.


20. Related documents and acceptance

This policy forms part of a set and should be read with our Cookie Policy, our Website Terms of Use, and — if you are a Client — the Client Services Agreement and the Data Processing Agreement annexed to it. If you enquired through a Client's funnel, also read the Lead Data Notice shown on that page and that Client's own privacy notice.

Where you see this policy and what you accept:


21. Mandatory local rights, and how they interact with our governing law

In short: our client contracts are governed by Wyoming law. That does not affect your data protection rights, which depend on where you live.

Our contractual relationship with Clients is governed by the law stated in the Client Services Agreement, which is currently the law of the State of Wyoming.

That choice of law does not, and cannot, reduce your data protection rights. The UK GDPR, the EU GDPR, the UK Data Protection Act 2018, PECR, the CCPA/CPRA and other US state privacy laws, and the Australian Privacy Act apply according to where you live and what we do, not according to what a contract between us and someone else says. This policy independently honours each of them. Nothing in this policy or in any contract we hold waives any mandatory data-subject or consumer right that cannot lawfully be waived, and any provision that purported to do so does not apply to you to that extent.


22. Defined terms


23. How to contact us and how to complain


Read alongside our Cookie Policy and Website Terms of Use.