1Who we are and when this Policy applies

Privacy Policy

How VSL Global collects, uses, stores, and protects your personal information across our website and services.

Last Revision

27 July 2026

1.

Who we are and when this Policy applies

VSL is operated by

VSL Global Pte. Ltd., 32 Pekin Street #05-01, Singapore 048762; and
Voice Sonic Labs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

In this Policy, 'VSL', 'we', 'us' and 'our' refer to the VSL entity responsible for the relevant processing. The VSL entity identified in your order form, subscription, account documentation or other customer agreement is responsible for personal data connected with that customer relationship. For website visitors and platform users who do not have an agreement identifying a VSL entity, VSL Global Pte. Ltd. is the data controller.

This Policy applies where VSL determines why and how personal data is processed, including website,sales, account, billing, support, security and direct-marketing data.

Where VSL processes text, audio, video, images, scripts, translations, Voice Data or other content solely on behalf of an enterprise or business customer, that customer is generally the controller and VSL acts as its processor or service provider. That processing is governed by the customer agreement and, where applicable, a Data Processing Addendum or 'DPA'.

If a customer agreement or DPA conflicts with this Policy in relation to Customer Content, the customer agreement or DPA controls to the extent of that conflict.

2.

Personal data we collect

2.1Account, contact and business information

We may collect your name, business email address, telephone number, company, job title, billing address, account preferences, authentication details and other information needed to create and manage your account or business relationship.

2.2Sales, demo, pilot and marketing information

When you request a demonstration, discuss a pilot, contact our sales team, download a resource or subscribe to communications, we may collect information about your organisation, intended use case, content volumes, target languages, technical requirements, budget, timeline, procurement needs and communication preferences.

2.3Customer Content and generated outputs

We process the text, scripts, documents, audio, video, images and other files you upload or provide to the Services as 'Input'. We may also create or process transcripts, translations, subtitles, synthetic audio, dubbed audio, lip-synced video and other results generated from Input as 'Output'. Input and Output together are 'Customer Content'. Customer Content may contain personal data about speakers, performers, employees, customers or other individuals. You or the relevant business customer are responsible for ensuring that you have the rights, permissions and lawful basis needed to provide that content to VSL.

2.4Voice Data and verification information

We may process voice recordings, voice characteristics, reference samples and related information used to create, operate or verify a voice model as 'Voice Data'. When required to protect rights and prevent misuse, we may also request consent records, verification recordings, identity documents, proof of authority or licensing information. Voice Data is personal data when it relates to an identified or identifiable person. It may also be biometric or sensitive personal data where it is technically processed for identity verification or unique identification, depending on the purpose and applicable law.

2.5Workflow and collaboration data

We may process project names, workspaces, scripts, speaker assignments, comments, review notes, approvals, revisions, versions, delivery status, user roles, permissions, project activity and other collaboration records needed to operate the VSL workflow.

2.6Integrations, APIs and provider routing

If you use an API, connect another service, select an AI provider or use a bring-your-own-key configuration, we may process integration settings, provider selections, encrypted credentials or tokens, request and response metadata, routing decisions, usage records, error logs and other information needed to operate and support the integration.

2.7Billing and transaction information

We and our payment providers process subscription, usage, invoice, tax and transaction information. VSL generally receives limited payment metadata and does not receive full card details where payments are handled by a payment processor.

2.8Support, communications and rights requests

We process messages, support tickets, call notes, attachments, feedback, complaints, misuse reports and privacy-rights requests that you send to us.

2.9Information collected automatically

When you use the Services, we may collect IP address, approximate location derived from IP, browser and device information, operating system, identifiers, login and security events, page views, feature interactions, timestamps, performance data, API activity, crash information and operational logs.

2.10Cookies and similar technologies

We use cookies and similar technologies for authentication, security, preferences and, where permitted, analytics and support. Section 10 and our Cookie Notice explain these technologies and your choices.

2.11Information received from third parties

We may receive information from authentication providers, payment providers, business customers, authorised integrations, fraud-prevention services, rights holders and other parties that help us verify identity, authority, consent, account ownership or lawful use of the Services.

3.

How and why we use personal data

Depending on the relationship, purpose and applicable law, we process personal data to:

Provide the Services, including creating accounts, processing Customer Content and generating transcripts, translations, voices, dubbing and lip-sync outputs;
Operate projects, workspaces, provider routing, roles, permissions, review, approval, revision, versioning and delivery workflows;
Manage subscriptions, usage, invoices, payments, taxes and customer records;
Provide support, diagnose failures, conduct customer-requested quality review and resolve disputes;
Authenticate users, protect accounts, prevent fraud and unauthorised voice use, investigate misuse and enforce our policies;
Improve service reliability, safety and performance using limited telemetry, feedback and appropriately de-identified or aggregated information;
Respond to enquiries, manage demos and pilots, provide requested information and send permitted business communications;
Understand website and product performance using cookies and similar technologies in accordance with your choices;
Comply with legal obligations, respond to lawful requests, establish or defend legal claims and protect VSL and others; and
Manage financing, restructuring, a merger, an acquisition or a sale of assets.

Where laws such as the UK GDPR require a lawful basis, our bases may include performance of a contract, compliance with a legal obligation, legitimate interests, consent and, where VSL acts as a processor, the documented instructions of the relevant customer.

4.

AI, voice processing and provider choices

4.1Model-agnostic processing and provider routing

VSL operates a workflow and orchestration layer that may use VSL systems and selected third-party providers for transcription, translation, voice generation, dubbing, audio processing and lip-sync. Depending on your plan, configuration and instructions, Customer Content may be sent to one or more providers to generate the requested Output. We limit provider access to the data reasonably required for the requested task and apply contractual, technical and organisational safeguards appropriate to the service and risk.

4.2Customer Content and AI training

Unless you expressly authorise it in writing, VSL does not use Customer Content or Voice Data to train general-purpose AI models. For AI processing managed by VSL, we configure or contract with providers so that Customer Content and Voice Data are not used to train their models unless you have made an informed written choice allowing that use. VSL will not knowingly route managed enterprise content to a provider that is permitted to train on it without the customer's written authorisation. We may use limited operational telemetry, error information, customer feedback and appropriately de-identified or aggregated information to maintain, evaluate and improve the Services.

4.3Voice models, consent and identity protection

We process Voice Data to create and operate authorised voice models, confirm rights or consent where required, and prevent impersonation, fraud and other misuse. Higher-risk requests, including requests involving another person or a public figure, may require additional documentation or verification. Where Voice Data is processed for identity verification or unique identification and applicable law treats it as biometric or special-category data, we identify an appropriate legal basis.

4.4Bring-your-own-key and customer-selected providers

If you connect a provider under your own account or API key, VSL may route Customer Content and instructions to that provider on your behalf. Processing by that provider may also be governed by the agreement between you and the provider.

4.5Authorised access and review

Authorised VSL personnel or contractors may access limited Customer Content when necessary to provide customer-requested support, investigate security or misuse, perform an agreed quality review, or comply with law.

4.6Automated processing

The Services use automated systems to generate and route content. VSL does not use these systems to make decisions about individuals that produce legal or similarly significant effects.

5.

How we share personal data

We may share personal data with

Service providers that support hosting, storage, security, authentication, communications, customer support, payments, analytics and specialised AI processing;
Authorised administrators and users of a business customer's account or workspace, according to their permissions;
VSL affiliates, personnel and contractors who need the information to provide, secure or support the Services and are bound by confidentiality obligations;
Authorities, rights holders or other parties where reasonably necessary to comply with law, respond to a lawful request, protect rights or safety, investigate fraud or misuse, or enforce our agreements;
Professional advisers, investors and transaction participants in connection with financing, restructuring, a merger, acquisition or sale of assets, subject to appropriate safeguards; and
Third parties where you or the relevant customer instructs us to publish, share or transfer information.

VSL does not sell personal data. We do not share Customer Content or Voice Data for third-party behavioural advertising.

6.

Key service providers and Subprocessors

The following providers may process personal data or Customer Content for VSL, depending on the Services and configuration used:

Amazon Web Services (AWS): AWS provides cloud hosting, storage, email delivery, security, edge delivery and operational logging. Data may include account data, Customer Content, workflow records, communications and technical logs. Processing occurs in the AWS regions configured by VSL and through AWS's approved Subprocessors.
Clerk: Clerk provides authentication and account-security services. Data may include account identifiers,contact information, authentication data and login or security events.
ElevenLabs: ElevenLabs provides voice and speech-processing services. Data may include text, audio, Voice Data,generated audio and request metadata when that provider is selected for a project.
CAMB.AI: CAMB.AI provides voice and localisation processing. Data may include text, audio, Voice Data, generated content and request metadata when that provider is selected and the required contractual safeguards are in place.
Google Cloud: Google Cloud, including paid Gemini API services or Vertex AI where used, provides AI and cloud-processing services. Data may include text, audio, prompts, responses and technical metadata when the relevant service is selected.
PostHog: PostHog provides website and product analytics and, where enabled with the required user choice, session replay. Data may include device and usage information, page views, interaction data, identifiers and masked session information.
Intercom: Intercom provides customer support services. Data may include contact information, support messages, attachments and related account or technical information.
Google Workspace and AWS SES: Google Workspace and AWS SES support business communications and email delivery. Data may include contact details, message content, delivery metadata and attachments.
Payment Processors: VSL uses third-party payment processors for relevant purchasing routes. The active provider is identified at checkout, in the applicable order form or in VSL's current Subprocessor information. Paymentprocessors handle payment-card and transaction data under their own notices and agreements.

We assess Subprocessors on a risk-based basis and require confidentiality, security and data-protection commitments appropriate to their services.Enterprise notice and objection rights are governed by the applicable DPA or customer agreement.

7.

International transfers

VSL operates internationally. Personal data may be transferred to and processed in countries other than the country where it was collected, depending on the VSL entity, customer configuration, hosting environment and providers selected for a project.

Where required, we use recognised safeguards for international transfers, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or the UK Addendum, and contractual protections that provide a comparable standard of protection.

You may contact privacy@vslglobal.ai for information about the safeguards relevant to your personal data.

8.

Data retention and deletion

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, follow customer instructions, comply with law, resolve disputes, maintain security and enforce agreements. A customer agreement, DPA, order form, account setting or documented deletion request may set a different period.

Temporary processing copies

Temporary raw uploads and processing copies are normally deleted within 30 days after the relevant processing job completes, unless the applicable customer agreement, project setting, security investigation or legal obligation requires a different period.

Active Customer Content and generated Output

Customer Content and Output are retained while the relevant project, workspace or account remains active, or for the period specified in the customer agreement or account setting. Following a verified deletion request or account closure, VSL deletes the affected content from active systems within a reasonable period, subject to legal, security and dispute requirements.

Voice Data and voice models

Voice Data and voice models are retained until the customer deletes them, the relevant authority or consent ends, the account closes, or the agreed retention period expires. Limited consent, licensing, verification or misuse-prevention records may be retained where reasonably necessary to demonstrate authority, protect rights or address legal claims.

Workflow and collaboration records

Project, approval, revision, permission and delivery records are retained for the project and customer relationship and for a limited period afterwards, where needed for service history, disputes, security or legal obligations.

Operational and security logs

Operational event and security logs are normally retained for no more than 12 months, unless a longer period is required for an active investigation, legal obligation or claim.

Analytics and session replay

Analytics data is retained according to VSL's configured PostHog settings. When session replay is enabled with the required user choice, replay data is retained for no more than 90 days.

Support records

Support records are retained while the account or request remains active and for a limited period afterwards for service history, security and disputes. Earlier deletion may be requested where applicable.

Billing, tax and corporate records

Billing, tax, contract and corporate records are retained for the periods required by applicable accounting, tax, audit and limitation laws.

Backups

Production database backups use a rolling seven-day schedule. After information is deleted from active systems, residual copies may remain temporarily in restricted backups until the next scheduled expiry cycle. We may retain de-identified or aggregated information that can no longer reasonably identify an individual.

9.

Security

We use technical and organisational measures designed to protect personal data and Customer Content against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the system and risk, these measures include HTTPS and TLS encryption in transit, encryption at rest for supported AWS storage and production databases, role-based access controls through Clerk and AWS IAM, edge and web-threat protections through AWS CloudFront and Vercel, operational logging through AWS CloudWatch and PostHog, confidentiality obligations, vendor assessment and incident-response procedures.

No system can be guaranteed completely secure. You are responsible for protecting your credentials, configuring permissions appropriately and notifying us promptly if you suspect unauthorised access.

Where required by applicable law or an enterprise DPA, VSL will notify the relevant customer, individual or authority of a qualifying personal-data breach within the applicable timeframe.

10.

Cookies and similar technologies

We use strictly necessary technologies to provide functions such as authentication, account security, load balancing, fraud prevention and remembering privacy choices.

With your consent where required, we use analytics and performance technologies to understand how the website and product are used. PostHog analytics and session replay do not operate until you accept analytics through VSL's consent tool.

You can accept, reject or manage non-essential technologies through the consent tool and can change your choice at any time through the Cookie choices link in the footer. Our Cookie Notice provides further informations

11.

Your rights and choices

Depending on your location and VSL's role, you may have the right to:

request access to personal data;
correct inaccurate or incomplete data;
request deletion;
restrict or object to processing;
receive portable data;
withdraw consent;
object to direct marketing; and
complain to a data-protection authority.

To exercise a right, contact privacy@vslglobal.ai. We may need to verify your identity and clarify the request. Where VSL acts only as a processor for a business customer, we may refer the request to that customer or assist it in responding.

You can unsubscribe from marketing emails using the link in the message. Withdrawal of consent does not affect processing carried out lawfully before the withdrawal.

UK residents may complain to the Information Commissioner's Office at ico.org.uk. Individuals in Singapore may contact the Personal Data Protection Commission at pdpc.gov.sg. You may also complain to the authority responsible for data protection where you live or work.

12.

Children and minors

The Services are not directed to individuals under 18. You must be at least 18, or the age of legal majority in your jurisdiction, to create or operate an account.

A verified business or enterprise customer may provide Customer Content involving a minor only where it has a valid legal basis, all required rights and documented consent from a parent, guardian or other authorised representative. Creating a voice model of a minor requires prior written approval from VSL and any verification VSL reasonably requires.

VSL may restrict the providers or workflow available for content involving a minor and may decline a project where rights, safety, contractual or legal requirements are not satisfied.

VSL prohibits any use that exploits, sexualises, deceives or otherwise harms a child. If you believe a minor's personal data or voice has been provided without appropriate authority, contact privacy@vslglobal.ai.

13.

Third-party services and links

The Services may contain links to third-party websites or integrate with services controlled by others. Their privacy practices may apply to processing they carry out independently. Review their notices before providing personal data or enabling an integration.

14.

Changes to this Policy

We may update this Policy when our Services, providers, legal obligations or data practices change. We will update the date above and provide additional notice where required by law or contract.

15.

Contact us

Singapore Data Protection Officer & Privacy

privacy@vslglobal.ai

Support

support@vslglobal.ai

Singapore: VSL Global Pte. Ltd., 32 Pekin Street #05-01, Singapore 048762
United Kingdom: Voice Sonic Labs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.