Privacy & GDPR

Your shoppers' voices never leave the building

On-premise is not a feature we added — it is the architecture. Speech-to-text, the language model and the product search all run on the store's own hardware. No voice audio or transcript is ever sent to the cloud, and the spoken words are never stored. That is how ShopVoices turns voice, normally retail's biggest data-protection risk, into a review your legal team can actually complete.

Diagram: a spoken question answered inside the store
Why this matters

Voice is one of the most sensitive things a shopper can give you

Under GDPR, a voice recording is personal data the moment it can be linked to an identifiable person, and European regulators treat voice as inherently biometric. A spoken question can also carry far more than its words — accent, health, age, mood. The moment that audio leaves the device for a third party, a chain of obligations begins.

How ShopVoices handles a shopper's voice

From the first word to the answer — nothing leaves the building

Capture, locally

The microphone feeds audio directly into the in-store system. On-device voice-activity detection notices when the shopper has finished — and the words appear on screen live as they are spoken.

Transcribe, locally

Speech-to-text runs on the store's own hardware, in ten languages with automatic detection. The audio is held only in memory.

Understand, locally

A language model running on the same hardware works out what the shopper wants — no cloud call.

Answer, locally

The system searches the store's own product, stock and layout database and shows the answer plus a route on the store map — in seconds.

Discard

The raw voice audio is processed in memory and then discarded. It is never persisted and never transmitted — and neither is the transcript.

Diagram: a spoken question answered inside the store

The only thing that leaves by default: anonymous timings, counts and tags — never audio, never the words.

Security is multi-layered: on-device processing, no network exposure of voice data, certificate-based device identity, signed software updates, permission-locked local storage and data minimisation by design — so there is no single point of failure and no honeypot of recordings to breach. See the full security posture →
The risk you avoid

Why cloud voice-AI is a GDPR minefield

The obligations multiply the instant audio leaves the device for a cloud processor:

Lawful basis & consent

Sending personal — and potentially special-category — voice data to a third party needs a valid lawful basis. Freely-given consent is hard to obtain in a busy aisle.

Transparency duties

You must tell shoppers who processes their voice, where, and why.

Processor chains (Article 28)

Each cloud vendor and sub-processor needs a compliant data-processing agreement to put in place and govern.

Cross-border transfers

Processing outside the EU/EEA triggers post-Schrems II transfer rules — Standard Contractual Clauses plus a transfer impact assessment.

Special-category (Article 9)

Using a voiceprint to identify a person engages the strictest tier of GDPR obligations.

Breach exposure

Every hop multiplies risk — and a leaked voiceprint, unlike a password, can never be reset.

Architecture, not policy

Why on-device sidesteps the minefield

The guarantee comes from where the computation physically happens — which makes it verifiable in due diligence.

The cloud voice-AI riskWhy it doesn't arise with ShopVoices
Cross-border transfer chain (Schrems II / SCCs)No audio transmission — voice never leaves the building, so no audio transfer chain arises.
Article 28 processor & sub-processor agreementsNo cloud voice processor — the answer path adds no processor chain for voice data. (Support and update services are scoped and documented separately.)
Article 9 special-category biometric trapNo voiceprint — ShopVoices transcribes a request to fulfil it; it does not identify people.
Retained recordings holding incidental sensitive contentData minimisation by design — the transcript is never stored.
Audio at rest to leak, subpoena or eraseAudio is ephemeral — processed in memory and discarded.
A large data footprint for the DPO to governA tiny, governable footprint — anonymous metrics only, with an off switch.
Full transparency

What we store, and what we never store

DataHow it's handled
Voice audioProcessed in memory on the store's own hardware. Never persisted, never transmitted.
The transcript (the words spoken)Never stored. Used in memory to find the answer, then discarded.
Operational telemetryOptional and anonymous, and structurally an allowlist: timings, counts, category and intent tags, a language code, a success flag, a thumbs-up or -down. There is no field the spoken words could travel in. Permission-locked, and can be switched off entirely. Where a retailer chooses to enable richer product-level analytics — and the applicable legal basis, such as consent, is in place in that jurisdiction — additional catalogue-level tags can be configured. That is a retailer-controlled choice, never a default, and it still carries no audio and no transcript.

This is what powers the platform's Analytics — demand insight built from tags and counts, not from recordings.

Orientation

Where ShopVoices sits under the EU AI Act

The Act's most severe prohibitions and its high-risk biometric-identification category target uses ShopVoices does not perform — it transcribes a request rather than recognising or profiling a person, and it does not categorise people by sensitive traits. As a local, task-specific assistant, it is not a general-purpose-AI model provider. Two boundaries we hold by design: analytics are never used to evaluate individual employees — a use that would engage the Act's high-risk employment category — and the system performs no emotion recognition.

For your compliance team

Built to make the privacy review easy

  • On-device architecture removes the data transfer and third-party processing that create most GDPR exposure.
  • Supports your DPIA and records-of-processing work with a small, clearly-described data footprint.
  • A guarantee you can verify in due diligence — because it is enforced by where computation happens. See the architecture →

See it in your store

Consistent service and recovered sales, with a privacy posture your legal and DPO teams can verify for themselves.