Privacy Notice
Effective 1 September 2026
This notice explains how Vocetta handles personal data when a customer uses the Vocetta service, including the Vocetta Microsoft Teams app. Vocetta processes customer data to provide the service and on the customer’s instructions.
Information we process
Depending on the integrations a customer enables, Vocetta may process workspace and organization identifiers, installer identity identifiers, Teams message activities, message sender and channel metadata, diagnostic requests, and the replies returned by the customer’s runner. The customer controls what it sends to Vocetta and is responsible for ensuring it has an appropriate basis to use connected services.
How the Teams app works
When someone mentions @Vocetta in a standard Teams channel, Microsoft delivers the activity to Vocetta’s switchboard. The switchboard verifies the Bot Framework token, uses the signed tenant and Team context to select the customer’s authorized runner, and relays the activity over an authenticated connection. The runner performs the investigation and the switchboard posts the reply back to the originating Teams thread using Vocetta’s publisher bot credentials.
The switchboard does not persist Teams message text or investigation responses. It retains only the minimum routing and security metadata needed to operate the connection: activity route coordinates for up to 30 days; short-lived install/OIDC correlation data for up to 15 minutes; an active Team installation record while the app remains connected; and removed or revoked installation records for up to 30 days. An unbound installation record is removed within one day.
Where information is processed
The customer’s runner is designed to run in the customer’s environment. The Vocetta switchboard is a hosted control and relay service. Teams activity content passes through that relay in transit when the Teams integration is used. Other processing locations depend on the customer’s deployment and any AI, ticketing, or communication providers it configures.
Why we process information
We use information to authenticate and secure integrations, route requests to the correct customer runner, operate and support the service, prevent abuse, meet legal obligations, and improve reliability. We do not use customer source code or Teams message content to train a general-purpose AI model.
Sharing
Information is shared only with providers needed to deliver a customer-selected integration, such as Microsoft Teams, the customer’s configured AI provider, and ticketing or source-control provider. We may also disclose information where required by law or to protect the service and its users.
Security
Vocetta uses authentication, encryption in transit, tenant and organization isolation, short-lived correlation state, and access controls designed to protect information. No system is completely secure; customers should keep their local runner, integration permissions, and access credentials protected.
Your choices and requests
Customers can disconnect the Teams app from Vocetta and remove it from Teams. Individuals may request access, correction, deletion, or other privacy assistance through their organization or by contacting Vocetta. We will handle requests in accordance with applicable law and our role in relation to the data.
Contact and changes
For privacy questions or requests, email dhruv.khullar@softpeaklabs.com.au with the subject “Privacy request.” We may update this notice as the service or legal requirements change; the effective date above identifies the current version.