Trust, security & compliance

Plain answers for your security questionnaire.

LingoVoice is built for organisations that handle sensitive conversations: healthcare, legal, government, education and regulated business. This page is the canonical reference for how we host data, what we keep, for how long, and exactly which standards we hold today versus the ones we are working towards.

UK hosted, London UK GDPR & DPA 2018 Encrypted in transit 30 day deletion Recording off by default DPA published
At a glance

The short version, before the detail.

If you are evaluating LingoVoice for procurement, these are the answers most questionnaires ask for. The full detail sits below.

Where it lives

Primary infrastructure hosted in London. Recordings you choose to keep are stored in UK cloud storage.

Encryption

Encrypted in transit with modern TLS. Passwords are hashed, never stored in plain text.

Recording and audio

Recording is off by default. Real-time translation is not retained. Recordings, when turned on, are deleted after 30 days.

Chat and translations

Messages and their translations exist only while the room is open. When the last person leaves, they are deleted automatically.

No training on your data

Your conversations are never used to train AI models. Every sub-processor agreement prohibits it.

Right to erasure

Ask us to delete your account and data and we action it within 30 days, as UK GDPR requires.

Reviewed: this page is updated whenever anything material changes.

If you need anything in writing, our Data Processing Agreement is available on request. Email hello@lingovoice.ai.

Where your data lives

Our primary infrastructure is hosted in London. Recordings you choose to keep are stored in UK cloud storage in the London region.

Speech recognition, translation and text to speech are delivered by specialist AI providers. Where a sub-processor handles data in a country outside the UK or EU, that transfer is governed by Standard Contractual Clauses, or the UK to US Data Bridge where applicable. The table further down this page shows what each category of sub-processor does and where it processes data.

Recording and audio

This is the honest version, and it matters most for a clinic or a legal intake.

Recording is off by default. Real-time translation is not retained. While a session is live, voice is streamed for transcription and translation and the audio is not written to disk. If you turn recording on, that audio is stored encrypted and automatically deleted after 30 days.

A host may enable recording on a per-session basis with the participants' consent. A recording includes the audio and the bilingual transcript, is stored in UK cloud storage in the London region, and stays under the host's control. Hosts can delete any recording at any time. We never access recordings ourselves except for direct technical support that the customer asks us for.

Chat messages and translations

Chat messages and their translations exist only for the life of the active room. When the last participant leaves, every message for that room is deleted automatically. Messages are never archived or backed up.

What we keep, and for how long

DataHow long we keep it
Live translationNot retained. Processed in real time.
Chat messagesDeleted automatically when the room closes
Session recording (opt-in)Encrypted, deleted after 30 days, deletable on demand
AI session summary (opt-in)Stored against the host account, deletable any time
Account and billingFor the life of the account, plus six years for UK tax law
Usage metadata (no content)Retained for billing and reporting only

Per-session metadata covers the date, duration, languages used, minutes consumed and cost. It does not include any conversation content.

Your control

You can ask us to delete your account and the data tied to it at any time by emailing hello@lingovoice.ai. We action the request within 30 days, as required by UK GDPR Article 17, except where we are legally required to keep certain records, such as billing data for tax compliance.

  • Recording is opt-in and host-controlled, with a one-click delete.
  • Whoever opens a room signs in with their own account. The person they are talking to can either sign in or join on a time-limited host-issued link (it expires after 24 hours), and either way their access is limited to that one room. Neither ever sees organisation data.
  • Account roles are Owner, Admin and Member, so billing and member management sit only with the people who should hold them.
  • Every session generates a metadata audit log that you can export.

Encryption

All traffic between your browser and LingoVoice is secured with modern TLS, and HTTP connections are redirected to HTTPS. Live interpreting sessions use encrypted connections for all audio, text and control messages.

Session recordings, when you turn them on, are stored encrypted at rest in UK cloud storage in London. User passwords are hashed and never stored in plain text or in any reversible form. Access tokens are short-lived and refreshed in the background, and refresh tokens are stored as hashes in cookies that JavaScript cannot read.

Sub-processors

LingoVoice uses a small number of carefully vetted sub-processors to deliver core platform capabilities. The categories below describe what each one does. The full list with named providers and their data-protection terms is available to current customers and qualified prospects on request. Email hello@lingovoice.ai.

CategoryPurposeData processedRegion
Cloud hostingPlatform infrastructureAll platform dataUK (London)
File storageDocument and recording storageUploaded files, opt-in recordingsUK (London)
Translation enginesReal-time text translationChat message text onlyEU, US and global routing
Speech recognitionVoice to textVoice audio streamed for transcriptionUS
Text to speechVoice synthesisTranslated text sent for voice synthesisUS
Payment processingCard paymentsPayment instrument data onlyEU
Transactional emailAccount and billing emailsEmail address onlyUS
Video relayConnecting a video call when a direct connection is blocked, which is common on hospital and corporate networksCall audio and video in transit, relayed and not storedGlobal routing
Website analyticsUnderstanding how the public website is usedWebsite visit data only, never conversation content, and only if you accept cookiesUS

All sub-processors are bound by data-processing agreements that prohibit the use of customer data for AI model training, or for any purpose beyond delivering the contracted service. Our speech and translation providers may hold request logs for a short abuse-monitoring window under their own published terms.

The honest boundary

AI for the intake, a certified human interpreter for the formal record. Use LingoVoice for the fast first conversation: the walk-in, the urgent instruction, the symptom, the document a client is trying to explain. For a witness statement, a sworn document, a court hearing, an end-of-life conversation or any safety-critical setting, a qualified human interpreter should always be used. The product is built around that line, not against it.

What we do not claim

We will not claim certifications we do not currently hold. We are honest about what is in progress versus what is in place today.

StandardStatusTarget
UK GDPR & Data Protection Act 2018In place-
ICO registrationHeld by parent company Lingo Service Translations Ltd-
Cyber EssentialsIn place, held by Lingo Service Translations Ltd, whole organisation scope. Certified 15 July 2026, renewal due 15 July 2027-
Cyber Essentials PlusPlanned, not yet held-
NHS Data Security & Protection ToolkitNot currently held-
ISO 27001 (information security)Planned, not yet held2027
SOC 2 Type IIPlanned, not yet heldAfter ISO 27001
WCAG 2.2 AA accessibilitySelf-assessedIndependent audit Q4 2026

If a certification matters to your procurement process and ours is in progress, we are happy to share where we are in the assessment cycle, including the assessor name and target audit date.

AI use and oversight

LingoVoice provides assistive translation and transcription, not autonomous decision-making. We follow a few clear principles:

  • Human in the loop for safety-critical decisions. The tool augments professionals, it does not replace them. For sworn proceedings, court appearances or end-of-life conversations, a qualified human interpreter should always be used.
  • No training on customer data. Your conversations are never used to train AI models, and our sub-processor agreements prohibit it explicitly.
  • Audit trail. Every session generates a metadata audit log that customers can export.
  • Domain-tuned modes. Clinical and legal modes apply domain-appropriate behaviour to reduce terminology errors in regulated contexts.

Incident response and insurance

In the event of a personal data breach affecting customers, we notify the Information Commissioner's Office within 72 hours of becoming aware where UK GDPR Article 33 requires it, and we notify affected customers without undue delay. Security disclosures go to security@lingovoice.ai, and we acknowledge reports within two working days.

Insurance is held by the parent company, Lingo Service Translations Ltd. A certificate of insurance with the current cover levels is available on request.

Contact

General compliance enquiries: hello@lingovoice.ai

Data Protection Officer: dpo@lingovoice.ai

Security disclosures: security@lingovoice.ai

Right of complaint: If you are unhappy with how we have handled your personal data, you can lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.

LingoVoice is a product of Lingo Service Translations Ltd, registered in England and Wales (Company No. 09343595). Cardiff, United Kingdom.

Questions, or need a signed copy?

Reach out to our team or our Data Protection Officer. We respond within UK working days.