Privacy Policy
Sutherland Commerce Group LLC, trading as Smooth Voice Marketing Effective Date: on publication · Version 1.0
In short: this policy explains what information Smooth Voice Marketing handles, why, who it goes to, how long we keep it, where it goes, and the rights you have under UK, EU, US and Australian law. The single most important point is in section 2: for people who enquire with us, and for leads generated by advertising we fund, we decide how the information is used, so we are the Controller. For a client's own existing customer data, the client decides and we only process on their behalf.
How to read this policy
Each section opens with a non-binding, italicised "In short:" line in plain English, then the formal text. Where the two differ, the formal text governs. Capitalised terms are defined in section 22.
This policy independently honours the UK GDPR, the EU GDPR, the UK Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and other US state privacy laws, and the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), because those laws apply according to where you live and not according to any contractual choice of law. Nothing in this policy waives any mandatory data-subject or consumer right that the law of your jurisdiction confers and does not permit to be waived.
Index
- Who we are
- Scope, and who decides what happens to your data
- The data we collect, by surface
- Why we use your data, and our lawful bases
- Leads generated through advertising we fund
- Who we share your data with
- International transfers
- How long we keep your data
- How we protect your data
- Your rights (UK and EU), and how to complain
- California and other US state privacy rights
- Australian privacy rights
- Cookies and similar technologies
- Marketing communications
- Automated decision-making and profiling
- Personal-data breach handling
- Children
- Data-protection contact
- Changes to this policy
- Related documents and acceptance
- Mandatory local rights, and how they interact with our governing law
- Defined terms
- How to contact us and how to complain
1. Who we are
In short: a Wyoming company trading as Smooth Voice Marketing, running Meta advertising for businesses. Here is how to reach us about your data.
This policy describes how Personal Data is handled by Sutherland Commerce Group LLC, a limited liability company organised under the laws of the State of Wyoming, USA, trading as Smooth Voice Marketing ("Smooth Voice", "we", "us", "our").
We are a marketing agency. We plan, build and run advertising campaigns, funnels, landing pages and lead generation systems for business Clients, principally on Meta platforms (Facebook and Instagram).
The "Site" means the websites, funnels and landing pages we operate, currently served at smooth-voice-marketing.vercel.app, together with any successor or additional domain we use for the same purpose.
Contact us about data protection:
- Privacy and data-protection contact: privacy@smoothvoice.ai
- General enquiries: hello@smoothvoice.ai
- Legal notices: legal@smoothvoice.ai
- By post: Sutherland Commerce Group LLC, 1309 Coffeen Avenue, Sheridan, WY 82801, USA
We review this policy at least every twelve months and on any material change.
2. Scope, and who decides what happens to your data
In short: three situations. (A) You enquire with us about our services — we are the Controller. (B) You are a member of the public who responded to an advert we funded for one of our clients — we are the Controller, jointly with that client for parts of it, and the notice on that landing page tells you so. (C) A client's own existing customer list, which the client asks us to work with — the client is the Controller and we are only the Processor.
Read this section before the rest. It determines who is responsible for your data and who you should contact.
2.1 When we are the Controller
We are the Controller of Personal Data relating to:
- Visitors to the Site;
- people who enquire with us about our services, complete our qualification assessment, book a call with us, take a lead magnet, or otherwise engage with our sales process;
- our business Clients and their staff (relationship and billing contact data); and
- Leads generated through advertising we fund — the members of the public who respond to adverts, funnels and landing pages that Smooth Voice pays for and operates. This is explained in full in section 5.
For all of the above we decide why and how the data is processed, and this policy applies in full.
2.2 Where we and a Client share responsibility
For a Lead generated through advertising we fund, there is a point at which the Lead's details pass to the Client so the Client can contact them and provide its services. From that point:
- Smooth Voice remains a Controller for the generation, qualification, storage and licensing of that Lead;
- the Client is a Controller in its own right for what it then does — contacting the Lead, quoting, selling and servicing.
This is set out for the Lead in a Lead Data Notice displayed on the landing page where their details were collected, which names both us and the Client. Section 5 explains the whole arrangement, including what happens if the enquiry is not a fit.
2.3 When we are the Processor
Where a Client gives us its own existing data — for example its current customer list, its historic enquiry records, or access to its own CRM — to use in campaigns such as retargeting or customer-list audiences, the Client is the Controller and Smooth Voice is the Processor. We process that data only on the Client's documented instructions, under the Data Processing Agreement which forms part of the Client Services Agreement.
The boundary, stated plainly so it is not argued about later: data that arrives because Smooth Voice paid to generate it is Controller-side data of ours (2.1 and 2.2, and section 5). Data the Client already held before the engagement, or obtained by its own means, is the Client's data and we are its Processor (2.3). Where a single individual appears in both categories, each category is treated according to how it was obtained.
If you are an individual whose data a Client asked us to process under 2.3, please contact that Client and read that Client's own privacy notice. We will assist the Client in responding to you as the law requires.
3. The data we collect, by surface
In short: different data depending on what you did. Browsing, submitting the assessment, booking a call, taking a guide, or responding to a client's advert. Here is exactly what, for each.
3.1 Site hosting and server logs
When you visit the Site, we and our hosting provider Vercel process your IP address, user-agent, device and browser information, the pages you requested, the referring URL, and request and security logs. This serves the Site, routes requests and keeps it secure.
3.2 Advertising measurement: the Meta pixel, the Conversions API and attribution
This is the most technical processing we do and it is described in detail because it is the least obvious.
The browser pixel. The Meta pixel loads on the Site. It sets the first-party cookies _fbp and, where you arrived from a Meta advert, _fbc, and reports page views and conversion events to Meta. See the Cookie Policy, which also explains the current position on consent honestly.
Advertising click identifiers. When you arrive from an advert, the identifier in the link (fbclid from Meta, and gclid, gbraid or wbraid from Google search advertising) is stored in your browser's local storage for up to 90 days, along with any utm_ tags for the session. This is first-party attribution: it lets us tell which advert produced an enquiry.
The Conversions API and the attribution record. When you submit the assessment, we send a conversion event from our server directly to Meta, in addition to the browser pixel. To make that event match the browser that saw the advert, we store a record in a database table called meta_attribution containing, against your email address:
- the
_fbpand_fbccookie values from your browser, - your IP address,
- your user-agent string, and
- the URL you landed on.
When you later book a call, the booking reaches us from Cal.com's server with an email address and nothing else, and we look up that record so the conversion can be credited to the right advert.
What goes to Meta. Your email address, phone number and name are hashed with SHA-256 before transmission and are never sent to Meta in readable form. The _fbp and _fbc values, your IP address and your user-agent are sent as they are, because Meta requires them in that form to match the event. Meta uses this to measure and optimise advertising. Meta is an independent controller for its own purposes; see Meta's own terms and privacy policy.
We do not sell your data and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA. See section 11.
3.3 The qualification assessment
When you complete the assessment on the Site we collect:
- your name, company name, company website, work email address and phone number; and
- your answers to the assessment questions — currently what matters most to you, what success looks like in six months, your role in the business, whether you have run Meta adverts before, what your biggest difficulty with them is or what has stopped you, why you want to run them, your current monthly revenue band, whether you use AI automations, whether you use a call centre or appointment setters, and how many sales representatives you have.
We also record which advert or link brought you, the page path, and behavioural events on the page such as page views and how far you scrolled, against a first-party visitor identifier held in the sv_offer_vid cookie.
This goes into our CRM, GoHighLevel, and into our own database at Neon. Where the submission qualifies, it also opens a pipeline record and sends the server-side conversion described in 3.2.
We use this to respond to your enquiry, decide whether we can help you, prepare for the conversation, and sell to you.
3.4 The enrichment crawl and the AI brief
In short: after you submit the assessment we look at your business's public website and public advertising, and generate an internal summary before we speak. This is profiling and we are telling you about it.
When you submit the assessment, and after your details are already saved, we automatically:
- fetch your company's website — up to five pages (typically the homepage and any about, services, coverage-area, reviews and contact pages), reading the served HTML;
- extract from those pages the page text and titles, the tracking and marketing technology the site uses (for example whether a Meta pixel, Google Analytics or Google Tag Manager is present), links to social media profiles, and any business email addresses and phone numbers published on the site;
- search the Meta Ad Library — Meta's own public database of adverts — on your company name and any Facebook page handle we found, in the United Kingdom and Australia, to see whether the business is currently advertising; and
- send a summary of those findings, together with your assessment answers, to an AI language model operated by OpenRouter (currently the DeepSeek model
deepseek/deepseek-v4-flash), which writes a short internal brief about your business.
The brief and the findings are stored in our database and written to your record in GoHighLevel so that whoever speaks to you has read it.
What this is and is not. It uses information the business has published publicly, plus the answers you gave us. It does not access anything private, it does not log in to anything, and it does not make any decision about you on its own — see section 15. It is preparation for a sales conversation.
Your right to object. This is profiling carried out on the basis of our legitimate interests. You can object at any time at privacy@smoothvoice.ai, and we will stop and delete the brief.
3.5 Booking a call
When you book a call with us through Cal.com, we collect your name, email address, the time of the meeting and anything you enter when booking. Cal.com's booking widget is embedded in our page and loads from Cal.com's servers. We use this to schedule and hold the call, and we send you confirmations and reminders.
3.6 The pre-call page, videos and lead magnets
If you book a call, we may send you a personal link to a pre-call page. That link is unique to you. On that page we record which videos you started, how far through you got, and which guides you opened or claimed, against your link, so we know what you have already seen before we speak.
Videos on the Site and on that page are hosted by Wistia, whose player loads on our pages and receives your IP address, user agent and viewing behaviour.
If you request a lead magnet (a guide or PDF), we collect your email address and name, create a contact record in GoHighLevel, and email you the guide.
3.7 The speed-to-lead demonstration
In short: we run a demonstration in which an AI voice agent calls you back within seconds of a form submission, to show a client what the system does. If you take part, you are speaking to an AI and the call is recorded.
We operate a demonstration of an automated "speed to lead" callback. Where you submit a demonstration form and it is enabled for your number, we process:
- your name and mobile number;
- the call audio and transcript of the demonstration call, handled by ElevenLabs, which provides the AI voice agent; and
- SMS messages sent to you, delivered by Twilio, and emails delivered by Resend or GoHighLevel.
You are speaking to an AI voice agent, not a person, and the agent says so. The call is recorded and transcribed so the demonstration can be shown and reviewed. We do not create a voiceprint from your audio and do not use your voice to identify you.
This feature is restricted: calls and messages only go to numbers on an internal allow-list and are subject to daily caps and a per-number guard, because it is a demonstration and not a marketing channel.
3.8 Email, SMS and messaging
We send transactional and follow-up messages through GoHighLevel (so that the whole conversation sits on your record and anyone picking it up can see it), and through Resend for certain automated emails. SMS is delivered by Twilio. We process your email address, phone number, name and the message content, and whether a message was delivered and opened.
3.9 Internal alerts
When something needs a human — for example if a submission fails to reach the CRM — we post an internal alert to our own team channel on Discord. That alert can contain your email address and company name. It goes to our internal channel only.
3.10 Recipients, and automated processing, at a glance
Recipients are the providers named in section 6. Some processing is automated — the enrichment crawl and AI brief (3.4), the qualification rules (3.3), and the demonstration voice agent (3.7) — but we do not make a decision about you based solely on automated processing that produces a legal effect or similarly significantly affects you. See section 15. We do not sell your Personal Data and we do not share it for cross-context behavioural advertising.
4. Why we use your data, and our lawful bases
In short: for each thing we do, this says what we use and which legal ground under Article 6 applies. Where we rely on legitimate interests we have weighed our interest against your rights and can show that on request.
| Purpose | Data used | Lawful basis (UK/EU GDPR Art 6) | If legitimate interests, the interest |
|---|---|---|---|
| Serving and securing the Site | IP, user-agent, request and security logs | Art 6(1)(f) legitimate interests | Operating and protecting the Site |
Advertising measurement and attribution (Meta pixel, Conversions API, meta_attribution, click identifiers) | _fbp, _fbc, click identifiers, IP, user-agent, hashed email, phone and name, conversion events | Consent (Art 6(1)(a)) where the law requires consent for the cookie or similar technology; Art 6(1)(f) for the server-side measurement that follows | Knowing which advertising works, so we do not spend our own money blindly |
| Responding to and qualifying an enquiry (assessment, GoHighLevel, pipeline) | Name, company, website, email, phone, assessment answers | Art 6(1)(b) steps prior to a contract at your request; and Art 6(1)(f) | Responding to a business that approached us and deciding whether we can help it |
| The enrichment crawl and AI brief (3.4) | Public website content, public advertising records, tracking technology, published business contact details, assessment answers | Art 6(1)(f) legitimate interests | Preparing properly for a sales conversation using information the business has published |
| Scheduling and holding calls (Cal.com) | Name, email, meeting details | Art 6(1)(b) pre-contract steps | — |
| Pre-call page, video and guide engagement (3.6) | Link token, video progress, guide claims | Art 6(1)(f) legitimate interests | Not repeating at someone what they have already watched |
| The speed-to-lead demonstration (3.7) | Name, mobile, call audio, transcript, SMS content | Consent (Art 6(1)(a)) — you submit the form to start it | — |
| Generating and qualifying Leads for Clients through advertising we fund (section 5) | Name, contact details, enquiry details, qualification answers | Art 6(1)(f) legitimate interests, with notice at collection; consent where the law requires it for the channel | Operating a lead generation business, and connecting a person who asked for a service with a provider of it |
| Passing a Lead to the Client who will serve them (section 5) | Name, contact details, enquiry details | Art 6(1)(b) steps prior to a contract at the Lead's request; and Art 6(1)(f) | Doing the thing the person asked for when they enquired |
| Passing an unsuitable enquiry to another provider (section 5.5) | Name, contact details, enquiry details | Art 6(1)(f) legitimate interests, disclosed at collection and with a right to object | Connecting someone we cannot help with someone who can |
| Transactional and follow-up messaging (GoHighLevel, Resend, Twilio) | Email, phone, name, message content, delivery data | Art 6(1)(b) contract or pre-contract; Art 6(1)(f) | Communicating with people who enquired |
| Marketing email to business contacts | Email, name, engagement | Consent (Art 6(1)(a)), or the PECR soft opt-in in the UK; opt-out for B2B under US law; APP 7 in Australia | Promoting our own similar services to interested business contacts |
| Internal alerting (Discord) | Email, company name | Art 6(1)(f) legitimate interests | Noticing when an enquiry fails to reach the CRM so it is not lost |
| Managing the Client relationship and billing | Client contact details, engagement records | Art 6(1)(b) contract; Art 6(1)(c) legal obligation for tax and accounting | — |
| Establishing, exercising or defending legal claims | Whatever is relevant | Art 6(1)(f) legitimate interests; Art 6(1)(c) where a legal obligation applies | Defending ourselves and meeting regulatory obligations |
Where we act as Processor for a Client's own data (2.3), the lawful basis is the Client's to establish, and we act only on its documented instructions.
5. Leads generated through advertising we fund
In short: if you responded to an advert, filled in a form or booked a visit through a funnel that Smooth Voice paid for, we are a controller of your details, we pass them to the business that will actually serve you, and we tell you all of this on the page where you give them to us. If that business cannot help you, we may pass you to another provider who can — and you can say no.
This section explains an arrangement that is unusual enough to deserve its own section.
5.1 What we do
We fund and operate advertising, landing pages and booking funnels for our business Clients. When you respond to one of those adverts and enquire — by filling in a form, booking a call, requesting a quote or booking a visit — your details are collected through a system that Smooth Voice built, pays for and runs.
5.2 Our role
Because Smooth Voice decides how those funnels work, what is asked, how enquiries are qualified, where the data is stored and how long it is kept, Smooth Voice is a Controller of that data. The Client that will serve you is also a Controller, for what it does after we pass your enquiry to it.
We are describing a data protection role, not a claim to own you or your information. Personal data is not property and cannot be owned by anyone. What we hold is a controller's responsibility for the data, rights in the compiled database, and a contractual arrangement with our Client about who may use it and when. Your rights under section 10 apply to us in full, whatever our commercial arrangement with the Client says.
5.3 What you are told, and when
Every landing page and funnel we run for a Client carries a Lead Data Notice at the point your details are collected. It names Smooth Voice and it names the Client, says what is collected and why, says that your details are shared between us, says that we may pass you to another provider if the Client cannot help, and links to this policy. If you did not see it, tell us at privacy@smoothvoice.ai and we will investigate.
5.4 Passing your enquiry to the Client
We pass your details to the Client so it can contact you and provide the service you enquired about. The Client's licence to use your details comes from its agreement with us and can end — for example if that agreement ends. If it does, that does not by itself require the Client to stop contacting you: where the Client has built its own relationship with you, for example because you became its customer, it has its own lawful basis and its own responsibility as a Controller. Ask the Client directly about that, and see its own privacy notice.
5.5 If the enquiry is not a fit
Sometimes an enquiry does not match what the Client can do — wrong area, wrong service, or outside the criteria we agreed with them. Where that happens we may pass your details to another provider who may be able to help you. This is disclosed to you in the Lead Data Notice at the point of collection, and it is done on the basis of our legitimate interests.
You can stop this. Object at any time at privacy@smoothvoice.ai and we will not pass your details on. We only do this where the disclosure was present when your details were collected; where it was not, we do not do it at all.
5.6 Aggregated performance data
We use aggregated and anonymised information about how campaigns perform — conversion rates, costs, volumes — without limit, including in our own marketing. Once aggregated and anonymised this is no longer Personal Data and cannot be traced back to you.
6. Who we share your data with
In short: a defined set of named providers who process data for us under contract. The list below is the real one, checked against our own source code, not a generic list.
Each recipient below acts as our processor (or, where we act as Processor for a Client, as a Sub-processor) under a written contract incorporating Article 28 UK/EU GDPR terms where applicable.
| Recipient | Role | Used for | Primary location |
|---|---|---|---|
| Vercel Inc. | Hosting, serverless functions, edge network | Serving the Site and running our API endpoints | USA / global |
| Neon Inc. | Managed Postgres database | Our application database: enquiries, assessment answers, behavioural events, attribution records, enrichment output | USA / EU by region |
| HighLevel Inc. ("GoHighLevel") | CRM, pipelines, email and SMS conversations | Contact records, pipeline records, the AI brief, message threads | USA |
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd | Advertising platform, pixel, Conversions API, Ad Library | Advertising measurement and optimisation; public advertising lookups | USA / EU |
| Cal.com, Inc. | Booking and scheduling | Booking calls, and the booking widget embedded on our pages | USA |
| OpenRouter, Inc. | AI model routing | Generating the internal brief described in 3.4 | USA |
| Resend (Plus Five Five, Inc.) | Transactional email | Automated emails | USA |
| Twilio Inc. | SMS | Text messages | USA |
| ElevenLabs Inc. | Conversational AI voice agent | The speed-to-lead demonstration (3.7) only | USA |
| Wistia, Inc. | Video hosting and player | Videos on the Site and pre-call pages | USA |
| Discord Inc. | Internal team alerts | Internal notifications to our own channel (3.9) | USA |
| PostHog Inc. | Product analytics and session replay | Site usage measurement: pages you view, how far through a video you watch, which steps of the assessment you reach, and clicks on links and buttons. Also session recordings of your visit, in which everything you type into a form field is masked in your browser before the recording is sent. Requests are routed through our own domain rather than sent direct to PostHog | EU instance (eu.i.posthog.com) |
Providers we do not use. We do not use Google Analytics, Google Ads conversion tracking, or any Google advertising technology on the Site at present. If that changes, this policy and the Cookie Policy will be updated before it goes live.
No model training on your data. We do not use your Personal Data to train, fine-tune or improve any AI model, and we do not permit our providers to use it to train their own or any third party's models. The AI brief in 3.4 is generated by sending information to a model for a single response; it is not training data.
We may also disclose Personal Data where required by law, court order or lawful request from a public authority; to establish, exercise or defend legal claims; or in connection with a sale or reorganisation of our business, in which case the recipient is bound to protect it.
7. International transfers
In short: most of our providers are in the United States, so your data goes there. For every US transfer we keep the Standard Contractual Clauses and the UK Addendum in place as the baseline, so no transfer becomes unlawful if any adequacy framework is struck down.
Our stack is predominantly US-based, so Personal Data we process is transferred to the United States and, for some providers, processed globally. We make those transfers under Chapter V of the UK/EU GDPR:
- Standard Contractual Clauses and the IDTA as the standing baseline. For every US transfer, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum are in place, supported by a transfer risk assessment. This is deliberate: if the EU–US Data Privacy Framework or the UK Extension is suspended or invalidated, no transfer is left without a lawful basis.
- Data Privacy Framework as an additional route. Where a US recipient is self-certified under the EU–US Data Privacy Framework and its UK Extension, that mechanism may additionally apply. We do not rely on it as a single point of failure.
- Australia (APP 8). Where personal information of Australian individuals goes to overseas recipients, those recipients are the providers in section 6. We take reasonable steps under APP 8.1, through the contractual commitments above, so each recipient handles it consistently with the APPs, and we remain accountable under APP 8.1 for those recipients except where a permitted APP 8.2 exception applies.
You can ask us about the safeguards for a specific provider, and for a copy of the relevant clauses, at privacy@smoothvoice.ai.
8. How long we keep your data
In short: only as long as we need it, then we delete or anonymise it. Here are the periods.
| Data category | Retention | Why |
|---|---|---|
| Site server and security logs | 30 days | Security and operations |
| Advertising click identifiers in your browser | 90 days from capture | Attribution window |
meta_attribution records (_fbp, _fbc, IP, user-agent against an email) | 90 days from last update | Long enough to attribute a booking that follows an advert click; no longer |
Behavioural events on the Site (offer_events) | 24 months | Understanding and improving the funnel |
| Enquiry and CRM records for people who did not become Clients | 24 months from last contact | Sales lifecycle, and so we know we have already spoken |
| Enrichment findings and the AI brief | 24 months from generation, or on request | Preparing for and recalling a sales conversation |
| Pre-call page engagement (video progress, guide claims) | 12 months | Relevant only around the call |
| Speed-to-lead demonstration call audio and transcript | 30 days, then deleted | It is a demonstration; there is no reason to keep it |
| SMS and email message records | 24 months | Record of what we sent to whom |
| Lead records generated for Clients (section 5) | Duration of the Client engagement plus 12 months | Billing evidence, dispute resolution, and the licence arrangement |
| Client relationship, billing, tax and accounting records | 7 years | Legal obligation |
| Marketing suppression list | Kept for as long as needed to honour your opt-out, minimised to the email address only | We are required to keep suppressing you |
| Anything under legal hold | Until the matter concludes | Establishing, exercising or defending legal claims |
Where data must be kept longer to comply with a legal obligation or to establish, exercise or defend legal claims, we keep only what is necessary for that purpose. For Client data we process as Processor (2.3), retention is governed by the Data Processing Agreement and set by the Client, not by this table.
9. How we protect your data
In short: encryption in transit, tight access, vetted providers, and we take incidents seriously.
We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS) for all connections and API calls, encryption at rest where our providers support it, least-privilege access controls with credentials held as environment secrets and never in source code, hashing of identifiers before transmission to advertising platforms (section 3.2), rate limiting and abuse controls on public endpoints, and engaging only providers who offer sufficient guarantees under Article 28 of the UK/EU GDPR.
No method of transmission or storage is completely secure, but we work to protect your data and to detect, investigate and respond to incidents.
10. Your rights (UK and EU), and how to complain
In short: you can ask to see your data, fix it, delete it, restrict or object to how we use it, take a copy elsewhere, or withdraw consent. It is free. Email us and we will answer within a month.
If you are in the UK or the EU you have the following rights in relation to Personal Data we hold as Controller:
- Access — to be told whether we process your data and to receive a copy;
- Rectification — to have inaccurate data corrected and incomplete data completed;
- Erasure — to have your data deleted in certain circumstances;
- Restriction — to have our processing restricted in certain circumstances;
- Portability — to receive certain data in a portable format;
- Objection — to object to processing based on legitimate interests, including the enrichment crawl and AI brief in 3.4 and the passing of unsuitable enquiries to another provider in 5.5, and to object at any time to direct marketing;
- Withdraw consent — at any time where we rely on consent, without affecting processing already carried out;
- Complain, and seek a judicial remedy — under Articles 77 to 79 of the UK/EU GDPR.
To exercise any right, contact privacy@smoothvoice.ai. It is free. We may need to verify your identity first. We will respond within one month, extendable by two further months for complex or numerous requests, and we will tell you if we need the extension. Where more than one privacy regime applies to you, we apply the timeframe most favourable to you.
Complaints. Complain to us first at privacy@smoothvoice.ai. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk, 0303 123 1113); in the EU, your local data protection authority.
11. California and other US state privacy rights
In short: if you are in California or another US state with a privacy law, you have rights to know, delete, correct and opt out. We do not sell or share your personal information, and we honour Global Privacy Control signals.
This section applies to residents of California under the CCPA/CPRA and, to the extent they apply, residents of other US states with comprehensive privacy laws.
11.1 Categories collected, and our no-sale statement
Acting as a business, we collect: identifiers (name, email, phone, company, IP address, cookie and device identifiers); commercial information (your enquiry, your industry, the services you are interested in); internet and network activity (pages viewed, scroll depth, referring advert, video progress); professional information (your role, your business contact details, your business's public web presence); inferences (the internal brief described in 3.4); and, only where you take part in the demonstration in 3.7, audio information (the demonstration call and its transcript).
In the preceding 12 months Smooth Voice Marketing has not sold, and has not shared for cross-context behavioural advertising, the personal information of any consumer, and does not sell or share the personal information of consumers under 16.
Advertising technology on the Site is used for first-party measurement of our own advertising — knowing which advert produced an enquiry — and not to sell your information to anyone or to make it available to third parties for their own cross-context behavioural advertising.
11.2 Your rights
Subject to law and verification you may: know and access the personal information we collected; delete it; correct it; opt out of sale or sharing (we do not sell or share); limit the use of sensitive personal information; and not be discriminated against for exercising any right.
To exercise these rights, email privacy@smoothvoice.ai. We verify your identity against our records before acting. We respond within 45 days, extendable by a further 45 where reasonably necessary. Where more than one regime applies to you, we apply the timeframe most favourable to you.
11.3 Global Privacy Control
We honour the Global Privacy Control signal. If your browser sends one, we treat it as a valid opt-out of any sale or sharing associated with that browser. Because we do not sell or share, there is nothing for it to stop, but we recognise and honour it.
11.4 Sensitive personal information
We do not seek sensitive personal information. The only route by which it could reach us is if you volunteered it during a demonstration call (3.7) or typed it into a free-text answer. We use any such information only to provide and document the thing you asked for, within the limited purposes permitted by Cal. Civ. Code § 1798.121 and 11 CCR § 7027, and never to infer characteristics about you. On that basis we are not required to offer a "Limit the Use of My Sensitive Personal Information" link, but we will honour any such request sent to privacy@smoothvoice.ai.
11.5 Authorised agents
You may use an authorised agent. We may require written, signed permission from you and may ask you to verify your identity with us directly.
11.6 Automated decision-making technology
California's ADMT regulations give notice, access and opt-out rights where automated technology is used to make a significant decision about a consumer. We do not use automated technology to make a significant decision about you — the enrichment crawl and AI brief (3.4) prepare a human for a conversation, and the qualification rules (3.3) decide only whether we offer you a call. Neither determines your access to, or the price or terms of, any good or service. If that changes we will provide the required notice, access and opt-out. See also section 15.
12. Australian privacy rights
In short: if you are in Australia, the APPs give you rights to access and correct your information and to complain to us and then to the OAIC.
This section reflects our handling of personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- Open and transparent management (APP 1). This policy and our Cookie Policy set out how we manage personal information.
- Collection and notice (APP 3, APP 5). We collect by lawful and fair means, only as reasonably necessary for the activities in sections 3 and 4, and we take reasonable steps to notify individuals at collection — including through the Lead Data Notice described in 5.3.
- Use and disclosure (APP 6). We use and disclose for the purposes we collected the information for and related purposes you would reasonably expect, and as otherwise permitted.
- Direct marketing (APP 7). We provide a simple opt-out. See section 14.
- Cross-border disclosure (APP 8). See section 7.
- Security (APP 11). See section 9.
- Access and correction (APP 12, APP 13). Contact privacy@smoothvoice.ai.
Complaints. Complain to us first at privacy@smoothvoice.ai. If you are not satisfied, complain to the Office of the Australian Information Commissioner (oaic.gov.au).
13. Cookies and similar technologies
Cookies and similar technologies on the Site are covered by our Cookie Policy, which lists what is actually set, by whom, and for how long, and which states plainly the current position on consent. In the UK, PECR also applies.
Separately from cookies, the click identifiers described in 3.2 are held in your browser's local storage rather than in a cookie. They are covered by the same rules and are described in the Cookie Policy.
14. Marketing communications
In short: we email you marketing only where you agreed or where the B2B soft opt-in allows. Every marketing email has a one-step unsubscribe.
We send marketing emails where you have consented, or where you are an existing or prospective business customer who gave us your details and we are marketing our own similar services — the PECR soft opt-in in the UK, the opt-out standard for B2B in the US, and APP 7 in Australia. Every marketing email tells you how to unsubscribe in one step, at no cost. For US recipients our marketing emails carry a valid postal address and a working opt-out, consistent with CAN-SPAM.
If you unsubscribe, we keep your email address on a suppression list solely so we do not contact you again, and for no other purpose.
15. Automated decision-making and profiling
In short: we do profile you — we look at your business's public information and have a model write a brief about it. We do not let a machine decide anything significant about you.
Profiling. The enrichment crawl and AI brief described in 3.4 is profiling within the meaning of the UK/EU GDPR: we analyse information about a business to prepare for a sales conversation. We are telling you about it here rather than leaving it unsaid, and you can object under section 10.
Article 22. We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The qualification rules in 3.3 decide only whether we offer you a sales call and whether we treat the enquiry as a fit; a person reviews and decides everything that follows. Being told you are "not a fit" for our services is not a legal or similarly significant effect: it means we are not selling to you.
If that ever changed, we would tell you, explain the logic in general terms, and give you the right to obtain human intervention, express your view and contest the decision.
California ADMT. See section 11.6.
16. Personal-data breach handling
We assess personal-data breaches and, where required, notify the relevant supervisory authority and affected individuals within the timeframes the law sets — for the UK and EU, the ICO or the relevant supervisory authority within 72 hours of becoming aware where the threshold is met, and affected individuals where there is a high risk to their rights and freedoms; in Australia, the OAIC and affected individuals under the Notifiable Data Breaches scheme; and consistently with applicable US state breach-notification laws. Where we act as Processor for a Client, we notify the Client without undue delay so it can meet its own obligations, as the Data Processing Agreement sets out.
17. Children
The Site and our services are directed at businesses, not at children. We do not knowingly collect Personal Data from children under 16. If you believe a child has given us Personal Data, contact privacy@smoothvoice.ai and we will delete it.
Where we generate Leads for a Client through advertising we fund (section 5), the advertising is targeted at adults and the services advertised are for adults. Where a Client's own sector carries an age restriction, that restriction and any age screening is addressed in the Client Services Agreement.
18. Data-protection contact
In short: one email address reaches us about anything on this page, wherever you live.
Our data-protection contact is privacy@smoothvoice.ai. It is monitored, it is free to use, and all of the rights in section 10 apply in full however you contact us.
If you are in the UK or the EU, you may contact us at that address directly about any matter in this policy, including to exercise any right in section 10 or to make a complaint under section 23. Where we have appointed a representative under Article 27 of the UK or EU GDPR, their name and address will be published in this section.
Data Protection Officer. We have assessed our processing and concluded that we are not required to appoint a statutory Data Protection Officer under Article 37, because our core activities do not consist of large-scale processing of special-category data and do not involve large-scale, systematic monitoring of individuals as a core activity.
19. Changes to this policy
We may update this policy. The Effective Date and Version at the top show the current version. We review it at least every 12 months and on any material change to our processing or to the law. Where a change is material we will take reasonable steps to bring it to your attention.
20. Related documents and acceptance
This policy forms part of a set and should be read with our Cookie Policy, our Website Terms of Use, and — if you are a Client — the Client Services Agreement and the Data Processing Agreement annexed to it. If you enquired through a Client's funnel, also read the Lead Data Notice shown on that page and that Client's own privacy notice.
Where you see this policy and what you accept:
- Site footer: links to the Privacy Policy, Cookie Policy and Website Terms of Use on every public page.
- The qualification assessment: a notice under the submit button explaining what happens to your details and linking here.
- Client funnels: the Lead Data Notice at the point of collection, naming both Smooth Voice and the Client.
- Client engagement: the signed Client Services Agreement, with the Data Processing Agreement annexed.
21. Mandatory local rights, and how they interact with our governing law
In short: our client contracts are governed by Wyoming law. That does not affect your data protection rights, which depend on where you live.
Our contractual relationship with Clients is governed by the law stated in the Client Services Agreement, which is currently the law of the State of Wyoming.
That choice of law does not, and cannot, reduce your data protection rights. The UK GDPR, the EU GDPR, the UK Data Protection Act 2018, PECR, the CCPA/CPRA and other US state privacy laws, and the Australian Privacy Act apply according to where you live and what we do, not according to what a contract between us and someone else says. This policy independently honours each of them. Nothing in this policy or in any contract we hold waives any mandatory data-subject or consumer right that cannot lawfully be waived, and any provision that purported to do so does not apply to you to that extent.
22. Defined terms
- Smooth Voice / we / us / our — Sutherland Commerce Group LLC, trading as Smooth Voice Marketing.
- Site — the websites, funnels and landing pages we operate, as defined in section 1.
- Client — a business that engages us to provide marketing services. Clients are businesses, not consumers.
- Lead — a person who enquires through advertising, a funnel or a landing page that Smooth Voice funds and operates for a Client.
- Lead Data Notice — the short notice displayed at the point of collection on a Client funnel, naming Smooth Voice and the Client, described in 5.3.
- Visitor — a visitor to the Site.
- Personal Data — personal data under the UK/EU GDPR; includes "personal information" under the CCPA/CPRA and under the Australian Privacy Act.
- Controller / Processor — as defined in Article 4 of the UK/EU GDPR.
- Sub-processor — a processor engaged by us to carry out processing on behalf of a Controller, as contemplated by Article 28.
- Client Services Agreement — the signed agreement between Smooth Voice and a Client.
- Data Processing Agreement / DPA — the Article 28 terms annexed to the Client Services Agreement, governing data the Client is Controller of.
- Applicable Data Protection Law — UK GDPR, UK Data Protection Act 2018, EU GDPR, PECR, CCPA/CPRA and other US state privacy laws, and the Australian Privacy Act 1988 and APPs.
- De-identified / Aggregated Data — data that no longer identifies, and cannot reasonably be used to identify, an individual.
23. How to contact us and how to complain
- Privacy and data-protection requests and complaints: privacy@smoothvoice.ai
- General enquiries: hello@smoothvoice.ai
- Legal notices: legal@smoothvoice.ai
- By post: Sutherland Commerce Group LLC, 1309 Coffeen Avenue, Sheridan, WY 82801, USA
- Supervisory authorities: UK — Information Commissioner's Office (ico.org.uk, 0303 123 1113); EU — your local data protection authority; Australia — Office of the Australian Information Commissioner (oaic.gov.au).
Read alongside our Cookie Policy and Website Terms of Use.