Virturing
PricingDocumentationContact
Open console

Product

PlatformVoice agentsAsian numbersProgrammable mediaRoutingCall centresCampaignsHuman handoff

Solutions

BankingGovernmentReservationsCollectionsCustomer supportHealthcareOutbound campaigns

Explore

PricingDocumentationContact
Open developer console

Privacy

Privacy policy

How Virturing handles website, account, communications, call, and service data.

Last updated · 24 August 2026
On this page01 Who we are and scope02 Our roles03 Data we collect04 Sources of data05 Purposes and legal bases06 Voice, recordings, and AI07 Website analytics and choices08 Sharing and recipients09 International transfers10 Retention11 Security12 Your rights13 Regional privacy rights14 Children15 Changes and contact
01

Who we are and scope

Virturing operates this website and provides programmable voice infrastructure, regional phone numbers, routing, realtime media, AI voice workflows, and related support. This policy applies to personal data handled through the public website, sales and support communications, account administration, and the services described in an applicable order or account configuration.

A customer may provide a separate privacy notice for calls and workflows it controls. That customer notice governs the customer purpose and should be read together with this policy where Virturing processes data on the customer's instructions.

02

Our roles

Virturing acts as controller for its own website, account, billing, security, abuse-prevention, and business communications. For call content and workflow data submitted by a customer, the customer generally determines why and how the data is processed, while Virturing acts as processor or service provider under the customer agreement.

Customers are responsible for a lawful purpose, notices, consent, contact lists, calling windows, recording rules, AI disclosure, connected data sources, retention settings, and meaningful human review.

03

Data we collect

Depending on the interaction, we may handle names, business contact details, organization and role, account identifiers, authentication and security data, billing and usage records, support messages, device and browser information, IP address, consent choices, service configuration, regional number requests, routing rules, and integration metadata.

Customer-controlled services may also process caller and recipient numbers, call timestamps and state, audio, recordings, transcripts, prompts, knowledge retrieved for a call, tool inputs and outputs, summaries, dispositions, human handoff details, and structured outcomes. The exact categories depend on the configured workflow.

04

Sources of data

We receive data directly from website visitors, account users, customers, authorized customer integrations, callers and call recipients, telecommunications carriers, identity and payment services, security systems, and service providers. A customer may supply contact or context data from its own systems and remains responsible for having authority to do so.

05

Purposes and legal bases

We use data to respond to enquiries, create and administer accounts, provision numbers and routes, deliver calls and media, operate configured agents and tools, calculate usage, invoice customers, provide support, maintain security, detect abuse, investigate incidents, comply with law, and improve service reliability.

Where a legal basis is required, processing may rely on performance of a contract, steps requested before a contract, compliance with legal obligations, legitimate interests in operating and securing the service, protection of vital interests in a genuine emergency, or consent where consent is the appropriate basis. Customers select and document the basis for customer-controlled calls and campaigns.

06

Voice, recordings, and AI

Audio and call content may be transmitted, transcribed, summarized, classified, or used to produce a response when a customer enables those functions. Recordings are not required for every workflow and should only be enabled with an appropriate purpose, notice, access model, and retention period.

Automated systems may use prompts, approved knowledge, conversation context, model providers, speech services, and scoped business tools. Virturing does not design the service to be the sole decision-maker for legal status, eligibility, diagnosis, employment, credit, insurance, public benefits, or similarly consequential rights.

07

Website analytics and choices

The public website uses essential storage for privacy choices and security. Google Tag Manager and connected analytics remain blocked unless a visitor selects Allow analytics. Visitors can reject analytics without losing access to the public site and can change the choice through Privacy choices in the footer.

Virturing does not use the public website to sell personal information or share it for cross-context behavioural advertising. Browser Global Privacy Control signals are treated as a denial of optional analytics.

08

Sharing and recipients

We disclose data only as needed to provide, secure, support, or comply with obligations relating to the service. Recipients may include cloud infrastructure providers, telecommunications carriers and number partners, selected AI or media providers, identity and payment providers, analytics providers after consent, professional advisers, and authorities where disclosure is legally required.

A current description of provider categories and confirmed website providers is available on the Subprocessors page. Customer-selected integrations receive data according to the customer's configuration.

09

International transfers

Voice and software services can involve processing across countries. Where transfer safeguards are legally required, Virturing and its providers use an applicable contractual or statutory mechanism, such as approved contractual clauses, together with technical and organizational safeguards appropriate to the transfer. Deployment location and provider availability may vary by market and customer agreement.

10

Retention

Retention is based on the purpose, data category, customer configuration, contract, security needs, dispute requirements, carrier or billing obligations, and applicable law. Public enquiry records are retained while the conversation is active and for a reasonable follow-up period. Account and billing records may be retained for finance, audit, fraud-prevention, and legal requirements.

Customers should set recording, transcript, and call-artifact retention to the shortest period that supports their lawful purpose. Eligible data can be deleted through the process on the Data deletion page. Protected backups expire through their normal lifecycle rather than being edited in place.

11

Security

Virturing uses measures appropriate to the service, including encrypted transport, scoped credentials, access controls, environment separation, logging, dependency maintenance, and incident-response procedures. No internet service can guarantee absolute security. Customers must protect API keys, restrict tool permissions, review access, and promptly report suspected compromise.

12

Your rights

Depending on location and applicable law, a person may have rights to receive notice, access personal data, correct inaccurate data, request deletion, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. Withdrawing consent does not affect processing already completed lawfully.

Send a request to privacy@virturing.ai and identify the relevant account, organization, phone number, interaction, and requested action. We verify identity and authority before disclosing or deleting data. If Virturing processes the data only for a customer, we may direct the request to that customer.

13

Regional privacy rights

Where the Sri Lanka Personal Data Protection Act applies, requests are handled according to the rights and duties in that law and applicable instruments. Where European or United Kingdom data protection law applies, individuals may also contact the relevant supervisory authority.

Where the California Consumer Privacy Act applies, eligible residents may request to know, correct, or delete covered personal information, and may exercise applicable opt-out or limitation rights without discriminatory treatment. Virturing does not sell personal information or share it for cross-context behavioural advertising.

14

Children

The public website and business services are not directed to children. Customers must not configure campaigns or workflows involving children unless they have established the lawful basis, notices, consent, safety controls, and human supervision required for that use. If you believe a child has provided data improperly, contact privacy@virturing.ai.

15

Changes and contact

We may update this policy when services, providers, laws, or practices change. The last-updated date identifies the current version. Material changes affecting an active customer service may also be communicated through the account or contractual contact.

Privacy questions and rights requests can be sent to privacy@virturing.ai. Legal notices can be sent to legal@virturing.ai.

QUESTIONS OR REQUESTSContact the privacy and legal team.privacy@virturing.ai

Programmable voice infrastructure

Give every call
a useful next step.

Start with a number, a call flow, or the operation that should move faster.

Map a launch
Virturing

Phone numbers for Asia.
Voice agents for what happens next.

Network status: operating
ProductPlatformVoice agentsAsian numbersProgrammable mediaRoutingCall centresCampaigns
DevelopersDeveloper homeQuickstartMedia bridgesAPI reference
CompanyAboutSecurityPricingContact
LegalPrivacyCookie policyTermsAcceptable useData processingSubprocessorsAI disclosureData deletion
© 2026 Virturing. All rights reserved.
Cookie policyData processing