AI and Data Privacy
VirtualSpeech uses AI so that people can practise real conversations and get feedback in seconds. This page explains what the AI does, which providers are involved, what happens to your data, and the limits we place on how results can be used.
For hosting, encryption, sub-processors and certifications, see our Trust Center.
The short version
- Your data is never used to train AI models. Not ours, not OpenAI's, not Microsoft's.
- AI conversations, scoring and feedback run on the OpenAI API. European customers can be moved to Azure OpenAI in an EU region on request.
- OpenAI may retain API inputs and outputs for up to 30 days to monitor for abuse, then deletes them.
- Every client's data is logically separated. No client can access another client's data.
- Scores are for development only. Our contracts prohibit using them for hiring, promotion, pay or any other employment decision.
- We collect no biometric data: no facial images, no facial expressions, no emotion recognition, no voice identification.
What our AI does
AI supports learning in four ways:
- Roleplay conversations. An AI character holds a position, responds to what the learner actually says, and pushes back.
- Scored feedback. Each session is scored against five named criteria chosen for that scenario, with a written explanation of what the learner said and what to change.
- Delivery measures. Speaking pace, hesitations, filler words and listenability.
- AI coaching. A reflective conversation after a session, or a standalone coaching session ending in a written plan.
These features support learning. They do not make decisions about people.
Which AI providers process your data
OpenAI
We are a paying customer of the OpenAI API Platform, currently using the gpt-realtime model family. Under OpenAI's enterprise terms:
- Data submitted through the API is not used to train or improve OpenAI's models.
- OpenAI may securely retain API inputs and outputs for up to 30 days to provide the service and identify abuse, after which they are removed unless retention is legally required.
- We use default API settings with no persistent memory.
See OpenAI's enterprise privacy commitments. We use the API Platform, not ChatGPT.
Microsoft Azure OpenAI
On request, European customers can be served by Azure OpenAI hosted in an EU region. The same commitment applies: no customer data is used to train or improve Microsoft's or OpenAI's models.
Your own model
If your organisation runs its own OpenAI-based language model, we can connect it. Roleplay behaviour and feedback then draw on your internal knowledge and best practice rather than general-purpose guidance, and that traffic goes to your model rather than ours. Bayer does this today, connecting VirtualSpeech to their internal model so feedback reflects Bayer's own recommendations.
Separation between clients
Clients share the underlying model, as they would any cloud service. All data is separated by logic: one client cannot access another client's conversations, scores or learners, and no client's data is used to train anything or to inform another client's experience.
What we do not collect
- No facial recognition or facial expression analysis. No camera or webcam feed is recorded or analysed at any point.
- No emotion recognition.
- No voice identification. Voice is analysed for pace, clarity and content, never to identify a person by their voice pattern.
How body language is measured
Body language metrics come from VR headset and hand controller positions only. The platform uses the position of the headset and controllers to estimate posture and gesture. No AI is used to interpret body language, and no camera is involved. Outside VR, body language tracking is switched off entirely.
Where a learner chooses to save a session, the saved movement data lets them replay how their head and hands moved. Saved audio includes both the learner's voice and the avatar's.
Who can see AI feedback
Transcripts, scores and feedback are visible to your organisation's administrators, unless you choose to anonymise learner data.
With anonymisation enabled, administrators see cohort-level summaries only, while each learner keeps full visibility of their own results. Administrators can also disable the saving of transcripts, and of audio and body language recordings, altogether.
Administrators can replace the privacy notice and disclaimer shown to learners at first login with their own wording, so your people see your organisation's data protection language before they start.
Our approach to the EU AI Act
VirtualSpeech is built around the Act's principles of transparency, fairness and human oversight.
Transparency
- Learners and administrators are told clearly when they are speaking with an AI character.
- Scores are explainable: every criterion comes with a written explanation quoting what the learner said.
- No biometric, facial or emotion data is collected, so the practices the Act prohibits in workplace and education settings do not arise here.
Fairness
- AI is used to support learning, not to rank, judge or penalise people.
- Learner data can be anonymised at the organisation's request.
- Scoring criteria are visible, and organisations can write their own to match their competency framework.
Human oversight
- The platform makes no autonomous decisions about people.
- Our customer agreements state that the platform must not be used for decisions about promotion, pay, redundancy, hiring or any other employment outcome.
- Administrators can review transcripts and results, so a human can always see how a score was reached.
Because our customers control how results are used inside their own organisations, this is a contractual limit rather than a technical one. If your works council or data protection team needs it documented, we will confirm it in writing.
Retention and deletion of AI data
- Transcripts, scores and saved recordings are stored on our AWS infrastructure, in Germany for European customers and in the United States for all others.
- Learners and administrators can delete transcripts, recordings and uploaded files at any time. These are removed from the platform immediately and roll off backups within 10 days.
- An organisation can ask us to delete all of its learners' conversations. We complete deletion requests within 7 days.
Full detail on retention periods is in our Privacy Policy.
Questions
If you are in HR, compliance, procurement or data protection and need more detail, or you need us to complete an AI or security questionnaire:
Data protection and privacy: privacy@virtualspeech.com
Security and compliance: security@virtualspeech.com
See also our Trust Center and Privacy Policy.
Last reviewed: September 2026