Privacy Policy
Last updated: July 16, 2026
1. Overview
ALPANDIA (“ALPANDIA,” “we,” “us”) provides Voice AI, Digital AI, and AI Infrastructure products — including Realtime Voice Translation, AI Scam Detection, Voice Transcription, AI Whispering, Inappropriate Language Detection, Social Listening, and the underlying AI Voice Gateway, SIP Gateway, and API/SDK infrastructure that carry them. This Privacy Policy explains what data we process to deliver those products, why we process it, and the controls available to enterprise customers and their end users.
Most of what we process is enterprise call and interaction data submitted by our customers (telecoms, contact centers, banks, government agencies, and healthcare providers), not data we collect directly from consumers. Where ALPANDIA processes this data on a customer's behalf, we act as a data processor and the customer remains the data controller responsible for their own end users' consent and disclosures.
2. Data We Process
Depending on which products a customer uses, this can include:
- Call audio and real-time media streams (voice, VoIP, WebRTC) submitted for translation, transcription, or scoring
- Generated outputs: translated speech, bilingual transcripts, diarized speaker tracks, scam-risk scores, and agent-whisper prompts
- Custom vocabulary and industry terminology configured by a customer to improve model accuracy
- Telecom signaling and routing metadata (SS7, SIP, VoIP) processed by the AI Voice Gateway and SIP Gateway
- Digital channel content monitored under Social Listening (public posts and mentions, not private messages)
- Account, billing, and API usage data for customers and their authorized administrators
Post-call bilingual transcripts and confidence scores are generated as part of the Realtime Voice Translation service and delivered back to the customer via streaming API or webhook; they are not used to build products for other customers.
3. How We Use This Data
- Deliver the core service: live translation, transcription, diarization, scam scoring, whispering, and compliance monitoring
- Operate infrastructure that carries the data: routing, load balancing, and elastic auto-scaling across regions
- Detect fraud, abuse, and platform security threats in real time
- Generate aggregated, de-identified metrics (e.g. latency, accuracy) to maintain and improve service quality
- Meet legal, regulatory, and audit obligations applicable to the customer's industry (e.g. financial services, healthcare, government)
5. Security
All audio, transcripts, and derived data are encrypted in transit (TLS 1.3, SRTP) and at rest (AES-256). Enterprise customers can bring their own encryption keys via customer-managed HSMs, with no ALPANDIA personnel able to access underlying customer data or audio. Every request is authenticated and authorized at the API layer under a zero-trust model, with mTLS for all service-to-service traffic and 24/7 automated threat detection.
Our controls are aligned with SOC 2 Type II, ISO 27001, GDPR, HIPAA, PCI-DSS Level 1, NIST CSF, FedRAMP, and CSA STAR. Enterprise plans include SSO (SAML 2.0, OIDC), RBAC/ABAC, private networking (VPC peering, PrivateLink), and DLP integration support.
6. Data Residency & International Transfers
Customers can choose where their data is processed, with region-locked processing available across our supported regulatory zones. Where data must cross borders — for example to reach the nearest regional processing node for latency reasons — we rely on standard contractual clauses or equivalent lawful transfer mechanisms.
7. Data Retention
Retention periods for call audio, transcripts, and derived outputs are configurable by the customer, including automated PII detection and redaction ahead of long-term storage. Absent a custom retention policy, data is retained only as long as needed to deliver the service and satisfy the customer's applicable legal obligations, then deleted or anonymized.
8. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA/CPRA), you may have the right to access, correct, delete, or export data concerning you, and to object to or restrict certain processing. Because ALPANDIA typically processes end-user call data on behalf of an enterprise customer, requests from individual end users are generally directed to that customer as the data controller; we support customers in fulfilling these requests. Customers and administrators can contact us directly using the details below.
10. Children's Privacy
ALPANDIA's products are enterprise infrastructure sold to businesses and public sector organizations, not services directed at children, and we do not knowingly collect personal information directly from children.
11. Changes to This Policy
We may update this Privacy Policy as our products, infrastructure, or legal obligations evolve. Material changes will be reflected by an updated “Last updated” date above, and where appropriate, we will notify enterprise customers directly.
12. Contact Us
Questions about this Privacy Policy or a data request can be sent to our team via the Contact page.
Have a question about how your data is handled?
Talk to an Expert