Voyager AI Agent (VAIA) Privacy Policy
Last updated: July 21, 2026
Introduction
VAIA is a product and service operated by Voyager Internet Ltd, referred to in this Privacy Policy as “Voyager”, “we”, “our”, or “us”.
This Privacy Policy explains how VAIA collects, accesses, uses, stores, processes, shares, and protects personal information and other information when customers use the VAIA platform and any related services, integrations, applications, AI agents, automation features, voice services, and support functions, and prescribes limits on the use of such information.
Voyager handles personal information in accordance with the New Zealand Privacy Act 2020, including the Information Privacy Principles.
We are committed to protecting privacy and handling personal information and other information responsibly, securely, and transparently.
Definitions
In this Privacy Policy, the following terms have the meanings set out below:
- AI means artificial intelligence or artificially intelligent.
- Customer means any business or organisation that subscribes to and uses the VAIA platform.
- Personal information means information about an identifiable individual, as defined in section 7 of the Privacy Act 2020.
- Privacy Act means the Privacy Act 2020 (New Zealand) as amended from time to time.
- Voyager, we, us, our means Voyager Internet Ltd, the operator of VAIA.
1. About VAIA
VAIA is a Voice AI Agent and automation platform that helps businesses manage Customer interactions, phone calls, bookings, messages, workflows, and connected business systems.
Depending on how a Customer configures VAIA, the service may answer calls, process voice interactions, create call summaries, update connected systems, send communications, schedule appointments, and assist with operational tasks.
VAIA is designed to support people and businesses, not replace the need for appropriate human oversight. AI is helpful. It is not magic. Unfortunately.
2. Information We Collect
To provide the services, VAIA may collect and process personal information and other information from Customer accounts, platform usage, voice interactions, connected systems, and third party services that Customers choose to integrate.
Depending on the features used, information may include:
- account and contact information
- user login and authentication information
- caller names, phone numbers, email addresses, and contact details
- call audio, call recordings, call metadata, transcripts, call summaries, and messages
- calendar and scheduling information
- customer relationship management information
- booking and reservation information
- communications and messaging data
- event, appointment, and availability information
- customer records, notes, enquiries, preferences, and service history
- AI interaction data, prompts, responses, workflow actions, and automation logs
- configuration settings and integration preferences
- usage, audit, security, and operational logs
- support requests and related communications
VAIA only accesses and processes personal information and other information that is reasonably necessary to provide the functionality requested by the Customer, operate and secure the platform, support integrations, meet legal obligations, and improve service reliability.
3. Information Collected from Customers and Connected Systems
VAIA may collect personal information about individuals from our customers, connected systems, business applications, authorised users, or other third party sources where this is necessary to provide the services.
This may include information about callers, customers, staff, suppliers, patients, guests, tenants, applicants, partners, or other people who interact with a VAIA customer.
Customers are responsible for ensuring individuals are informed of the collection of their personal information, the purposes of collection, the intended recipients of the personal information, and their rights to access and correct their personal information.
Where Voyager has its own privacy notification obligations under the Privacy Act, it discharges these primarily through its Terms of Service with customers. Under the VAIA Terms of Service, Customers are required to ensure that individuals are informed of the collection of their personal information before or at the time of collection.
In addition to the above, Voyager requires Customers to acknowledge their Privacy Act notification obligations as part of the VAIA onboarding process, before VAIA is activated for use. Customers are responsible for ensuring they have the necessary rights, permissions, notices, and lawful basis to connect systems to VAIA and allow VAIA to process personal information and other information from those systems.
4. Voice Calls, Recordings, and Transcripts
Where VAIA handles phone calls or voice interactions, VAIA may process call audio, caller phone numbers, call metadata, transcripts, summaries, messages, action items, call outcomes, and related interaction records.
Calls may be answered, recorded, transcribed, summarised, analysed, classified, or actioned by VAIA where enabled by the Customer and where this is necessary to provide the services.
Examples of voice related processing may include:
- answering customer calls
- identifying the purpose of a call
- collecting information from callers
- creating call summaries or action items
- sending messages or notifications
- booking, updating, or cancelling appointments
- escalating calls or enquiries to staff
- updating customer records or connected systems
- generating operational insights or service reports
Where required by the Privacy Act 2020, customers are responsible for ensuring callers and other affected individuals receive appropriate notice that VAIA may answer, record, transcribe, summarise, or otherwise process calls on their behalf.
Where call recording or transcription is enabled, customers must ensure their use of those features complies with applicable laws (including the Privacy Act 2020), industry obligations, and their own privacy notices.
5. Third Party Integrations and Data Usage
The VAIA platform may connect to third party platforms and services, including but not limited to:
- calendar and scheduling platforms
- customer relationship management systems
- booking and reservation systems
- communications and messaging platforms
- artificial intelligence and automation services
- telecommunications platforms
- transcription and voice processing services
- productivity and collaboration tools
- accounting and business applications
- payment platforms
- cloud hosting and infrastructure services
- support, monitoring, analytics, and security tools
- other approved third party services
When a customer connects a third party service to VAIA, the customer authorises Voyager to access and process personal information and other information from that service for the purpose of providing the requested functionality.
Examples may include:
- creating, updating, or cancelling appointments
- managing bookings and reservations
- synchronising customer information and personal information
- sending communications and notifications
- updating CRM records
- logging call notes or customer enquiries
- automating workflows and business processes
- providing reporting, analytics, and operational insights
- maintaining platform security and service reliability
Personal information and other information accessed through connected services is not used for advertising purposes and is never sold to third parties.
Google Calendar Integration
When you connect your Google Calendar to VAIA, we request access to the following information via the Google Calendar API:
- Calendar event details, including titles, descriptions, start/end times, and locations
- Event attendees and their availability
- Calendar list and free/busy information
Requested scopes: calendar.events, calendar.freebusy
We use this information solely to display your schedule, create and manage appointments, and check availability for bookings for VAIA’s Booking agent. We do not use Google Calendar data for advertising, and we do not sell this data to any third party.
You can review or revoke VAIA’s access to your Google Account at any time at https://myaccount.google.com/permissions, or by disconnecting the integration within the VAIA Platform.
6. Artificial Intelligence and Data Processing
VAIA may use artificial intelligence technologies to assist with:
- customer calls and voice interactions
- scheduling and booking management
- customer enquiries and service requests
- workflow automation
- communications and messaging
- reporting and analytics
- operational assistance and decision support
- summarisation, classification, and recommendation tasks
When AI powered features are used, only the personal information and other information reasonably necessary to perform the requested task is processed.
Examples may include:
- determining availability and scheduling options
- managing appointments and bookings
- generating call summaries and action items
- ssisting with customer interactions
- identifying customer intent
- preparing suggested responses
- automating business workflows
- updating connected systems
VAIA only shares the minimum personal information and other information reasonably required to provide the requested functionality.
Personal information and other information processed by VAIA is not to be used to train AI models and is not to be shared with third parties for advertising, marketing, or profiling purposes.
Where AI features process information obtained through Google APIs, this data is used only to provide user-facing features within VAIA, is not used for AI model training or improvement of any kind (public or internal), and is not accessed by human reviewers except as strictly necessary for security, legal compliance, or with your explicit consent.
7. AI Outputs and Human Review
AI generated outputs may include summaries, suggested actions, classifications, recommendations, messages, workflow actions, or updates to connected systems.
While VAIA is designed to assist Customers, AI outputs may not always be complete, accurate, current, or appropriate for every situation. Customers are responsible for reviewing AI generated outputs where they are used to make decisions or take actions that may affect individuals.
Customers should not rely on VAIA as the sole basis for decisions involving legal, financial, medical, employment, safety, eligibility, or other significant matters without appropriate human review.
8. Sensitive Information
VAIA is not designed to intentionally collect sensitive personal information unless this is necessary for the Customer’s use of the services and has been configured accordingly.
Sensitive personal information may include information about health, finances, identity documents, legal matters, children, employment, ethnicity, religion, political views, or other information that may require extra care.
Customers must not configure VAIA to collect sensitive personal information unless they have a lawful basis to do so, have provided appropriate privacy notices, and have implemented suitable controls for the nature of the information being collected.
If sensitive information is provided during a call or interaction, VAIA may process that information where necessary to complete the requested interaction, create a record, or support the Customer’s configured workflow.
9. Children
VAIA must not knowingly be used to collect personal information from children without appropriate authority, consent, or lawful basis where required.
Customers who use VAIA in contexts involving children, education, childcare, health, family services, or similar environments are responsible for ensuring their use of VAIA complies with applicable privacy, consent, and safeguarding obligations.
10. Customer Responsibilities
VAIA is a business service used by Customers to support their own operations and interactions.
A Customer use of VAIA to interact with its callers, clients, staff, suppliers, or other contacts, will almost certainly give rise to the Customer having privacy obligations in relation to those individuals.
Customers are primarily responsible for:
- ensuring their use of VAIA complies with applicable law
- providing appropriate privacy notices to callers and other individuals consistent with their obligations under the Privacy Act 2020 and as further described in Section 3 of this Privacy Policy
- obtaining any required permissions or consents
- ensuring connected systems are authorised for use with VAIA
- configuring VAIA appropriately for their business context
- reviewing AI generated outputs where needed
- ensuring users only access information they are authorised to view
- maintaining the accuracy of information held in their connected systems
- responding to privacy requests where they are the relevant agency or data holder
Voyager processes personal information and other information to provide, secure, support, and maintain the VAIA services. Customers remain responsible for ensuring their own use of VAIA is lawful and appropriate for their business.
11. Data Storage and Retention
VAIA stores only the personal information and other information reasonably necessary to operate the services, deliver customer requested functionality, maintain security, support integrations, and meet legal or contractual obligations.
This may include:
- securely stored authorisation credentials and access tokens for connected services
- information temporarily processed to complete customer requested actions
- call recordings, transcripts, summaries, messages, and interaction records where enabled
- data generated through the operation of the services
- audit, security, and operational logs
- configuration and integration settings
- support and troubleshooting records
VAIA retains personal information and other information only for as long as reasonably required to provide the services, meet legal and contractual obligations, resolve disputes, maintain security, support audit and operational requirements, and comply with applicable law.
Retention periods may vary depending on the type of information, and the Customer configuration of VAIA, its integration settings, service requirements, and the Customer’s legal obligations to its callers and customers.
Customers may request deletion of stored data by contacting Voyager. Where deletion is requested, Voyager will take reasonable steps to delete or de-identify information unless retention is required or permitted by law, contractual obligation, security requirements, dispute resolution, or legitimate operational needs.
When a connected third party service is disconnected, VAIA will cease accessing that service and associated authorisation credentials may be revoked or deleted where applicable. Some information previously processed from that service may continue to be retained where necessary for audit, security, operational, legal, or contractual reasons.
Where we hold information obtained through Google APIs, we retain it only for as long as necessary to provide the requested functionality, and in any case no data is retained after an integration is disconnected or access is revoked.
12. Overseas Processing and Service Providers
VAIA stores and processes personal information and other customer information using secure cloud infrastructure located in New Zealand and other regions approved by us where required for service operation, resilience, redundancy, support, security, or integration requirements.
Data may be processed by trusted service providers that support the operation of the VAIA platform, including cloud hosting, communications, telecommunications, transcription, artificial intelligence, infrastructure, security, monitoring, analytics, support, and integration services.
Where Google user data is involved, it may be processed by the following categories of sub-processors, solely to support the operation of the Services: cloud hosting providers, and our AI voice/agent platform provider, which processes calendar information on our behalf to perform requested scheduling actions. We require all sub-processors to handle this data in a manner consistent with Google’s API Services User Data Policy.
Where Voyager discloses personal information to an overseas service provider, Voyager will take reasonable steps to ensure the information is protected by privacy safeguards comparable to those required under the New Zealand Privacy Act 2020, unless another permitted exception applies.
Voyager only uses service providers that are reasonably necessary to provide, secure, support, maintain, or improve the VAIA services.
13. Security Measures
VAIA is committed to protecting personal information and other customer information and implements reasonable technical, organisational, and administrative safeguards to protect data against unauthorised access, disclosure, alteration, loss, misuse, or destruction.
These safeguards may include:
- encryption of data in transit using Transport Layer Security
- encryption of stored data where supported by the underlying platform and infrastructure
- secure authentication and access controls
- role based permissions and least privilege access principles
- monitoring and logging of platform activity
- audit trails for key system actions
- vulnerability management and security reviews
- regular software and infrastructure updates
- access controls for Voyager personnel and service providers
- operational procedures for security and incident management
While no system can guarantee absolute security, Voyager takes reasonable steps to protect the information entrusted to us.
Customers are responsible for maintaining the security of their own accounts, users, devices, passwords, connected systems, and access permissions.
14. Privacy Breaches
If Voyager becomes aware of a privacy breach involving personal information processed by VAIA, we will assess the breach and take appropriate steps to contain, investigate, and remediate it.
Where required by the Privacy Act 2020, Voyager will notify the New Zealand Privacy Commissioner and affected individuals.
Customers must promptly notify Voyager if they become aware of any unauthorised access, disclosure, loss, misuse, or compromise involving VAIA or personal information or other information processed through VAIA.
15. Accuracy of Information
Voyager takes reasonable steps to ensure personal information and other information processed by VAIA is accurate, complete, and up to date where this is necessary for the purposes for which it is used.
However, VAIA may rely on information provided by customers, callers, users, connected systems, and third party platforms. Customers are responsible for ensuring the information in their connected systems is accurate and kept up to date.
Where individuals believe personal information held about them is incorrect, they may request correction as described in this Privacy Policy.
16. Revoking Access to Connected Services
Customers may revoke VAIA’s access to connected third party services at any time.
Depending on the service, Customers may be able to:
- disconnect the integration from within the VAIA platform
- revoke access through the third party provider’s account or security settings
- contact their service administrator
- contact VAIA support for assistance
Once access has been revoked, VAIA will no longer be able to access or manage personal information or other information from that connected service unless the customer reconnects it.
Revoking access may limit or disable some VAIA functionality.
17. Access, Correction, Deletion, and Privacy Requests
Individuals have rights under the Privacy Act 2020 to request access to personal information held about them and to request correction of that information, and to object to the use of their personal information in certain circumstances.
If you have questions about this Privacy Policy, would like to request access to personal information, request correction or deletion of data, or raise a concern about how information is handled, please contact:
Privacy Officer [email protected] Voyager Internet Ltd New Zealand
Voyager will respond to access and correction requests within 20 working days as required by the Privacy Act 2020, or such longer period as permitted by law. Voyager will respond to other privacy related enquiries and requests within a reasonable timeframe and in accordance with applicable privacy laws.
In some cases, Voyager may need to refer a request to the relevant VAIA Customer where that Customer controls the information or where the request relates to the Customer’s own use of VAIA.
If you are not satisfied with how your privacy concern is handled, you may contact the New Zealand Privacy Commissioner.
18. Third Party API Compliance
The VAIA platform may connect to and exchange information with third party platforms and services in order to provide Customer requested functionality.
Voyager only accesses, processes, stores, and shares third party service data as necessary to provide the services, maintain platform security, support integrations, comply with applicable obligations, and deliver Customer requested functionality.
Where VAIA integrates with Google services, Voyager’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where VAIA integrates with other third party platforms, Voyager will comply with the applicable terms, conditions, privacy requirements, and data handling obligations of those providers.
19. Architecture and Data Flow for Google Verification
How VAIA uses Google Calendar
When you connect your Google Calendar to VAIA, you authorise VAIA to access your calendar using Google’s OAuth service.
VAIA requests only the Google Calendar permissions required to provide the booking and scheduling features you choose to use, such as checking availability and creating, updating, or cancelling calendar events.
Architecture and Data Flow
VAIA uses RetellAI to provide conversational AI functionality.
When an AI agent needs to perform a calendar action, RetellAI sends a tool request to VAIA’s MCP (Model Context Protocol) server. The MCP server validates the request and performs the required Google Calendar API operation using OAuth credentials securely managed by VAIA.
RetellAI does not directly access your Google Account, does not store your Google OAuth access or refresh tokens, and does not make Google Calendar API requests on your behalf.
Data Handling
VAIA stores and manages the OAuth credentials used to access your Google Calendar.
Calendar information is accessed only as required to perform the action you requested, such as checking availability or managing calendar events.
Where necessary to fulfil your request, limited information is exchanged between RetellAI and VAIA’s MCP server as part of the conversational workflow.
RetellAI’s processing of information provided by VAIA is governed by RetellAI’s own Terms of Service and Privacy Policy.
Retention
VAIA retains Google Calendar information only as necessary to provide the requested functionality and in accordance with this Privacy Policy.
20. Changes to This Privacy Policy
Voyager may update this Privacy Policy from time to time to reflect changes to VAIA, legal requirements, technology, service providers, integrations, or business operations.
Where changes are material, Voyager will take reasonable steps to notify Customers as appropriate.
The latest version of this Privacy Policy will apply from the date it is published or otherwise made available.
21. Contact
For privacy questions, requests, or concerns relating to VAIA, please contact:
Privacy Officer [email protected] Voyager Internet Ltd New Zealand
Winners - Best Business Broadband Provider & People's Choice - Broadband 2025