VocettaSupport

Privacy Notice

Effective 1 September 2026

This notice explains how Vocetta handles personal data when a customer uses the Vocetta service, including the Vocetta Microsoft Teams app. Vocetta processes customer data to provide the service and on the customer’s instructions.

Short version: your source code, repository credentials, local indexes, screenshots, and full investigation reports stay in your Vocetta runner. The Teams app temporarily relays a message through Vocetta’s switchboard to that runner and returns the result to the same Teams conversation.

Information we process

Depending on the integrations a customer enables, Vocetta may process workspace and organization identifiers, installer identity identifiers, Teams message activities, message sender and channel metadata, diagnostic requests, and the replies returned by the customer’s runner. The customer controls what it sends to Vocetta and is responsible for ensuring it has an appropriate basis to use connected services.

How the Teams app works

When someone mentions @Vocetta in a standard Teams channel, Microsoft delivers the activity to Vocetta’s switchboard. The switchboard verifies the Bot Framework token, uses the signed tenant and Team context to select the customer’s authorized runner, and relays the activity over an authenticated connection. The runner performs the investigation and the switchboard posts the reply back to the originating Teams thread using Vocetta’s publisher bot credentials.

The switchboard does not persist Teams message text or investigation responses. It retains only the minimum routing and security metadata needed to operate the connection: activity route coordinates for up to 30 days; short-lived install/OIDC correlation data for up to 15 minutes; an active Team installation record while the app remains connected; and removed or revoked installation records for up to 30 days. An unbound installation record is removed within one day.

Where information is processed

The customer’s runner is designed to run in the customer’s environment. The Vocetta switchboard is a hosted control and relay service. Teams activity content passes through that relay in transit when the Teams integration is used. Other processing locations depend on the customer’s deployment and any AI, ticketing, or communication providers it configures.

Why we process information

We use information to authenticate and secure integrations, route requests to the correct customer runner, operate and support the service, prevent abuse, meet legal obligations, and improve reliability. We do not use customer source code or Teams message content to train a general-purpose AI model.

Sharing

Information is shared only with providers needed to deliver a customer-selected integration, such as Microsoft Teams, the customer’s configured AI provider, and ticketing or source-control provider. We may also disclose information where required by law or to protect the service and its users.

Security

Vocetta uses authentication, encryption in transit, tenant and organization isolation, short-lived correlation state, and access controls designed to protect information. No system is completely secure; customers should keep their local runner, integration permissions, and access credentials protected.

Your choices and requests

Customers can disconnect the Teams app from Vocetta and remove it from Teams. Individuals may request access, correction, deletion, or other privacy assistance through their organization or by contacting Vocetta. We will handle requests in accordance with applicable law and our role in relation to the data.

Contact and changes

For privacy questions or requests, email dhruv.khullar@softpeaklabs.com.au with the subject “Privacy request.” We may update this notice as the service or legal requirements change; the effective date above identifies the current version.