Your shoppers' voices never leave the building
On-premise is not a feature we added — it is the architecture. Speech-to-text, the language model and the product search all run on the store's own hardware. No voice audio or transcript is ever sent to the cloud, and the spoken words are never stored. That is how ShopVoices turns voice, normally retail's biggest data-protection risk, into a review your legal team can actually complete.
Voice is one of the most sensitive things a shopper can give you
Under GDPR, a voice recording is personal data the moment it can be linked to an identifiable person, and European regulators treat voice as inherently biometric. A spoken question can also carry far more than its words — accent, health, age, mood. The moment that audio leaves the device for a third party, a chain of obligations begins.
From the first word to the answer — nothing leaves the building
Capture, locally
The microphone feeds audio directly into the in-store system. On-device voice-activity detection notices when the shopper has finished — and the words appear on screen live as they are spoken.
Transcribe, locally
Speech-to-text runs on the store's own hardware, in ten languages with automatic detection. The audio is held only in memory.
Understand, locally
A language model running on the same hardware works out what the shopper wants — no cloud call.
Answer, locally
The system searches the store's own product, stock and layout database and shows the answer plus a route on the store map — in seconds.
Discard
The raw voice audio is processed in memory and then discarded. It is never persisted and never transmitted — and neither is the transcript.
The only thing that leaves by default: anonymous timings, counts and tags — never audio, never the words.
Why cloud voice-AI is a GDPR minefield
The obligations multiply the instant audio leaves the device for a cloud processor:
Lawful basis & consent
Sending personal — and potentially special-category — voice data to a third party needs a valid lawful basis. Freely-given consent is hard to obtain in a busy aisle.
Transparency duties
You must tell shoppers who processes their voice, where, and why.
Processor chains (Article 28)
Each cloud vendor and sub-processor needs a compliant data-processing agreement to put in place and govern.
Cross-border transfers
Processing outside the EU/EEA triggers post-Schrems II transfer rules — Standard Contractual Clauses plus a transfer impact assessment.
Special-category (Article 9)
Using a voiceprint to identify a person engages the strictest tier of GDPR obligations.
Breach exposure
Every hop multiplies risk — and a leaked voiceprint, unlike a password, can never be reset.
Why on-device sidesteps the minefield
The guarantee comes from where the computation physically happens — which makes it verifiable in due diligence.
| The cloud voice-AI risk | Why it doesn't arise with ShopVoices |
|---|---|
| Cross-border transfer chain (Schrems II / SCCs) | No audio transmission — voice never leaves the building, so no audio transfer chain arises. |
| Article 28 processor & sub-processor agreements | No cloud voice processor — the answer path adds no processor chain for voice data. (Support and update services are scoped and documented separately.) |
| Article 9 special-category biometric trap | No voiceprint — ShopVoices transcribes a request to fulfil it; it does not identify people. |
| Retained recordings holding incidental sensitive content | Data minimisation by design — the transcript is never stored. |
| Audio at rest to leak, subpoena or erase | Audio is ephemeral — processed in memory and discarded. |
| A large data footprint for the DPO to govern | A tiny, governable footprint — anonymous metrics only, with an off switch. |
What we store, and what we never store
| Data | How it's handled |
|---|---|
| Voice audio | Processed in memory on the store's own hardware. Never persisted, never transmitted. |
| The transcript (the words spoken) | Never stored. Used in memory to find the answer, then discarded. |
| Operational telemetry | Optional and anonymous, and structurally an allowlist: timings, counts, category and intent tags, a language code, a success flag, a thumbs-up or -down. There is no field the spoken words could travel in. Permission-locked, and can be switched off entirely. Where a retailer chooses to enable richer product-level analytics — and the applicable legal basis, such as consent, is in place in that jurisdiction — additional catalogue-level tags can be configured. That is a retailer-controlled choice, never a default, and it still carries no audio and no transcript. |
This is what powers the platform's Analytics — demand insight built from tags and counts, not from recordings.
Where ShopVoices sits under the EU AI Act
The Act's most severe prohibitions and its high-risk biometric-identification category target uses ShopVoices does not perform — it transcribes a request rather than recognising or profiling a person, and it does not categorise people by sensitive traits. As a local, task-specific assistant, it is not a general-purpose-AI model provider. Two boundaries we hold by design: analytics are never used to evaluate individual employees — a use that would engage the Act's high-risk employment category — and the system performs no emotion recognition.
Built to make the privacy review easy
- On-device architecture removes the data transfer and third-party processing that create most GDPR exposure.
- Supports your DPIA and records-of-processing work with a small, clearly-described data footprint.
- A guarantee you can verify in due diligence — because it is enforced by where computation happens. See the architecture →
See it in your store
Consistent service and recovered sales, with a privacy posture your legal and DPO teams can verify for themselves.
