Privacy Policy

How Voxify Studio collects, uses and protects personal data.

Effective date: 1 August 2026 · Last updated: 28 July 2026 · Version 1.1

This policy explains how we process personal data when you use Voxify Studio. It is written to comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and Romanian Law no. 190/2018. For cookies and similar technologies see our Cookie Policy. If you use our API/Embedded SDK to process your own users’ data, see the Data Processing Agreement. For what is generated by AI and how that output is marked, see our AI Transparency Notice.

1. Who is the controller

The data controller is GZK CONSULTING S.R.L., a Romanian limited liability company, Trade Registry no. J2026029220009, tax ID (CUI) 54615390, intra-community VAT no. RO54713445, registered office Str. Dr. Daraban nr. 400 BIS 1, Sat Samurcași, Comuna Crevedia, Dâmbovița County, Romania.

Data-protection contact: support@voxify.studio. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; you can reach our data-protection contact at the address above.

2. Scope

This policy covers personal data of: visitors to our website, registered users and Account Admins, people invited as team Users, prospects and people who contact us. Where we act as a processor for API/Embedded customers, that customer is the controller of their end users’ data and the DPA applies.

3. What data we collect

CategoryExamples / fields
Identity & accountFirst name, last name, organisation, country, email address, password (stored hashed), role, account/subscription status.
Authentication, device & security logsIP address, browser user-agent, session identifiers; and approximate geolocation derived from your IP at sign-up/sign-in via a third-party service (ipapi.co): city, region, country and country code, latitude/longitude, timezone, UTC offset, currency, ISP/organisation, ASN/network, and whether the IP is in the EU.
Usage dataProjects and creatives, actions in the editor, Credits granted/used/remaining, feature usage, timestamps, support interactions.
User ContentScripts and text you enter; audio files you upload (which may contain recorded voices — see section 6); brand assets; generated Output.
BillingSubscription plan, billing period, invoices and billing details. Card/payment data is handled by our payment processor; we do not store full card numbers.
CommunicationsEmails, support tickets, and (if you opt in) newsletter/marketing subscription preference.
Cookies & analyticsSee the Cookie Policy. We use Google Analytics 4 and store some data in your browser’s local/session storage.

We store authentication state (session id, account, user, subscription) in your browser’s local or session storage rather than in cookies set by the front-end.

4. How we collect it

5. Why we process data and our legal bases

PurposeLegal basis (Art. 6 GDPR)
Create and manage your account; provide the Service and Output; process projects and uploads.Performance of a contract (Art. 6(1)(b)).
Process audio you upload (transcription, speaker separation, mixing and mastering) to produce your ad.Performance of a contract (Art. 6(1)(b)). See section 6 for recordings that contain someone’s voice.
Billing, invoicing, fraud prevention, debt collection.Contract performance; legal obligation (Art. 6(1)(c)) for tax/accounting.
Security, abuse prevention, logging, troubleshooting, service improvement, aggregated analytics.Legitimate interests (Art. 6(1)(f)) in operating a secure, reliable service.
Analytics cookies (Google Analytics) and marketing emails.Consent (Art. 6(1)(a)); withdrawable at any time.
Comply with legal obligations and respond to lawful requests; establish/defend legal claims.Legal obligation; legitimate interests.

6. Recorded voices and biometric data

Voice cloning is not currently offered. Voxify Studio does not create a synthetic copy of a real person’s voice. The voices available in the product are either licensed catalogue voices or voices generated from a written description — neither is derived from a recording of an identifiable person.

You can still upload audio that contains a recorded voice, for example to import an existing advertisement. We process that audio to transcribe it, separate speakers and mix your ad. We do not use it to build a voice model, and we do not create a voiceprint from it. Because a recording of an identifiable person is personal data, you must have the rights or consents needed to upload it — see our Acceptable Use Policy. You are the controller of that lawful basis where the voice is someone else’s.

A voiceprint used to uniquely identify a natural person would be special-category (biometric) data under Article 9 GDPR. If we introduce voice cloning in future, we will process such data only on the basis of explicit consent (Art. 9(2)(a)), will update this policy before doing so, and will not knowingly clone the voice of a public figure or of any person without their documented consent.

7. Who we share data with (processors & sub-processors)

We do not sell personal data. We share it with service providers (sub-processors) who process it on our behalf under contracts that meet Article 28 GDPR, and with authorities where legally required. Our current sub-processors are:

7.1 AI, voice & speech providers

ProviderLocationPurposeData involved
ElevenLabsUSAText-to-speech and sound-effect generationScripts, generation parameters
OpenAIUSAAI script & recommendation generationPrompts, briefs, scripts, URLs you provide

7.2 Platform, infrastructure & analytics providers

ProviderLocationPurposeData involved
Amazon Web Services (AWS)USA — US East (N. Virginia)Application hosting, database (RDS), object storage (S3)All categories above
Amazon SES (AWS)USA — US East (N. Virginia)Transactional email (account, billing and service notices)Email address, name, message content
StripeIreland (EU) & USASubscription payments, invoicing, billing portalBilling details, payment card data (handled by Stripe; we never receive full card numbers)
Google Analytics (Google Ireland Ltd)EU / USAWebsite & app analyticsUsage events, device, IP-derived data
Google Fonts / Fonts CDN (Google)EU / USAServing fontsIP, user-agent (technical)
Cloudflare, jsDelivr (CDNs)GlobalServing icon/flag assetsIP, user-agent (technical)
ipapi.coEUIP geolocation at login/sign-upIP address (returns approximate location)
Melod.ieEULicensed music library assetsTrack selections (no account identifiers required)

We keep this list current and update it as our providers change. You can request the current list, and details of the safeguards for each transfer, at support@voxify.studio.

8. International transfers

Our infrastructure is hosted in the United States. The servers, database and file storage that run Voxify Studio are operated on Amazon Web Services in the US East (N. Virginia) region, and our transactional email is sent through Amazon SES in the same region. This means that personal data covered by this policy — including your account details, projects, scripts, uploaded audio and generated Output — is stored and processed outside the European Economic Area.

Several of our other providers (in particular the AI, analytics and CDN providers listed above) are also located in, or transfer data to, countries outside the EEA, including the United States.

Where we transfer personal data outside the EEA we rely on the safeguards permitted by Chapter V GDPR: an adequacy decision where one applies, the EU Standard Contractual Clauses, and/or the EU–US Data Privacy Framework where the provider is certified under it. We also assess, for each transfer, whether the law and practice of the destination country undermine those safeguards, and apply supplementary measures (such as encryption in transit and access controls) where needed. You can ask us which mechanism applies to a specific provider, and request a copy of the relevant safeguards, at support@voxify.studio.

If EU-region hosting is a requirement for your organisation, contact us before subscribing — we will tell you honestly whether we can meet it.

9. How long we keep data

10. Your rights

Subject to the GDPR, you have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing (including direct marketing); data portability; and to withdraw consent at any time (without affecting prior processing). You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects — we do not make such decisions.

To exercise your rights, contact support@voxify.studio. We respond within one month. You may lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro, or with the authority in your country of residence.

11. Security

We implement appropriate technical and organisational measures, including encryption in transit, hashed passwords, access controls and session management. No system is perfectly secure; we will notify you and the authority of a personal-data breach where legally required.

12. Children

The Service is not intended for children under 16. We do not knowingly collect their data; if you believe a child has provided data, contact us and we will delete it.

13. When we act as a processor

If you reach us through a customer’s website or app via our Embedded SDK or public API, that customer is the controller and we process the data on their behalf under the DPA. Please refer to that customer’s privacy notice for how they use your data.

14. Changes

We may update this policy. We will post the new version with an updated date and, for material changes, notify you (e.g. by email or in-app). Continued use after the effective date means you acknowledge the updated policy.

15. Contact

Questions or requests: support@voxify.studio · GZK CONSULTING S.R.L., Str. Dr. Daraban nr. 400 BIS 1, Sat Samurcași, Comuna Crevedia, Dâmbovița County, Romania.