Privacy Policy

Last updated: May 14 2026

This Privacy Policy explains how Temlio Communications Limited (RC1575783), operating the Voicebip platform (“Voicebip”, “we”, “us”), collects, uses, shares, and protects personal data. We process personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR).

1. Who we are and how to contact us

Voicebip is the data controller for personal data about our developers (account holders). For personal data about End Users that developers process through the platform, Voicebip generally acts as a data processor / sub-processor on the developer’s behalf — see the Data Processing Agreement.

Data protection contact / DPO: legal@temlio.com.

2. Scope

This policy covers the Voicebip API, dashboard, MCP server, SDKs, and websites. It does not cover developers’ own applications or third-party services you connect to.

3. Personal data we collect

About developers (we are controller):

  • Account data — name, email, password hash, workspace details.
  • Billing data — top-up records, transaction references, plan and balance information (we do not store full card details; payments are handled by our payment processors).
  • Technical data — IP address, device/browser metadata, API request logs, and usage metrics.

Processed on developers’ behalf (we are processor):

  • Phone numbers (E.164) of End Users.
  • Call audio and, where enabled, call recordings and transcripts.
  • Message content (SMS, WhatsApp) and conversation history.
  • Any prompts, variables, or metadata developers attach to Agents.

4. How we use personal data

  • To provide, operate, and secure the Services (routing calls/messages, running Agents, generating transcripts).
  • To meter usage and process billing.
  • To provide support and communicate service, security, and billing notices.
  • To detect, prevent, and investigate fraud, abuse, and violations of our Terms of Service.
  • To comply with legal obligations, including telecommunications and data-protection law.

We rely on one or more of: performance of a contract (providing the Services), consent (where required, e.g. certain communications), legal obligation, and legitimate interests (security, fraud prevention, service improvement) balanced against data-subject rights.

Recording is off by default and controlled per workspace. Where a developer enables recording, the developer is responsible for providing notice to, and obtaining any consent required from, End Users before recording. Recordings are stored encrypted and access is restricted.

7. Sub-processors

We use the following third parties to provide the Services. They process personal data only as needed to perform their function and under contractual safeguards.

Sub-processorPurposeProcessing region
Google (Gemini)AI inference (hosted voice/messaging AI)United States (US-East)
OpenAIAI inference (secondary)United States (US-East)
DeepgramSpeech-to-text / text-to-speechUnited States (US-East)
ElevenLabsSpeech-to-text (Scribe) / text-to-speechUnited States (US-East)
Kapso.ai → Meta PlatformsWhatsApp message deliveryUnited States (US-East)
PaystackPayments (NGN)Nigeria
StripePayments (international)United States (US-East)
PostmarkTransactional emailUnited States (US-East)
Colocation facility (Nigeria)Telephony computeNigeria

An up-to-date list is available on request. We notify developers of material sub-processor changes as set out in the DPA.

8. Cross-border transfers

Some processing occurs outside Nigeria — notably the AI inference, payment, email, and WhatsApp-delivery providers listed in Section 7, which are located primarily in the United States. Core telephony compute and primary storage remain in Nigeria. Where we transfer personal data across borders, we apply the safeguards required by the NDPA/NDPR (such as adequacy assessment, contractual protections, or consent where applicable).

9. Data retention

We retain personal data only as long as necessary for the purposes above or as required by law. Call and message records carry a retention window after which they expire. Developers can shorten retention or erase specific End-User data at any time (see Section 10). On account closure, we delete or anonymize personal data within 30–45 days, except where retention is legally required (e.g. billing/tax records).

10. Your rights

Subject to the NDPA/NDPR, you (and End Users, via the relevant developer) may request: access, rectification, erasure, restriction, portability, and objection to processing, and may withdraw consent where processing is consent-based.

  • Developers: exercise rights via the dashboard or by contacting legal@temlio.com.
  • End-User erasure: developers can permanently anonymize an End User’s call and message history by calling DELETE /v1/contacts/{e164} — see Contact Erasure.

You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

11. Cookies and analytics

Our dashboard and websites may use cookies and similar technologies for authentication, preferences, and product analytics.

12. Children’s data

The Services are intended only for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it.

13. Security

We use technical and organizational measures to protect personal data, including encryption in transit and at rest, tenant isolation (row-level security), access controls, and signed webhooks. No system is perfectly secure; we will notify affected parties and the NDPC of a personal-data breach as required by law.

14. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the dashboard or by email, and the “Last updated” date above will change.

15. Contact

Temlio Communications Limited — 6, Olatunde Sanni Crescent, Mende Maryland, Lagos, Nigeria Data protection / DPO: legal@temlio.com