Privacy Policy
This policy explains how VirtualSpeech collects, uses and protects personal data, and your rights under the UK GDPR and EU GDPR.
Last updated: September 2026
1. Who we are
VirtualSpeech Ltd is a company registered in England and Wales, company number 09517558, with its registered office at 44–54 Unit 4, Coleridge Road, London N8 8ED, United Kingdom.
We are registered with the Information Commissioner's Office under reference ZB245994.
Our privacy lead is Dominic Barnard, Co-Founder. Contact privacy@virtualspeech.com.
2. The two roles we play
Which parts of this policy apply to you depends on how you use VirtualSpeech.
When your organisation gives you access
If you use VirtualSpeech because your employer or institution bought it, they are the data controller and we are their data processor. They decide what data goes into the platform, who can see it and how long it is kept. We act on their instructions under a Data Processing Agreement.
Questions about how your organisation uses the platform should go to them first. We will always help them answer you.
When you deal with us directly
We are the data controller for people who buy an individual subscription from our website, visit our website, request a demo, download a resource, attend a webinar or contact us. Sections 3.3, 3.4 and 4 onwards apply to you.
3. What we collect
3.1 Learners
- Identity. Name and email address, supplied by your organisation's administrator. These can be anonymised, or we can supply generic addresses.
- Performance data. AI scores, speaking pace, hesitations, listenability, and movement metrics from VR sensors.
- Transcripts of roleplay, coaching and presentation sessions.
- Coaching plans created during Skills Coaching sessions and saved to your account.
- Audio and movement recordings, saved only when you press Save. Audio includes your voice and the AI character's. Movement data is headset and hand controller position from a VR headset.
- Uploaded files, through the upload manager: presentation slides, notes, audience questions, a CV or job description, and a thesis.
- Session names typed by the learner when using a shared headset.
- Technical data. Device user agent, IP address recorded in server logs, and the time the platform was last used.
- Authentication data. Password hashes, or the identifier passed by your organisation's identity provider where single sign-on is used, and session tokens.
Your organisation can switch off the upload manager, the saving of transcripts, the saving of audio and body language recordings, and leaderboards.
3.2 Administrators
- Name, email address, role and permissions.
- Login and administrative activity.
- Scenarios authored in Roleplay Studio, including the situation, character brief and scoring criteria. This content belongs to your organisation. We do not reuse it for other customers or to train models.
3.3 Individual subscribers
- Name, email address and purchase history.
- Payments are processed by Stripe. We do not store full payment card details.
- The learner data described in 3.1, for your own practice sessions.
3.4 Website visitors and enquiries
- Analytics. We use Google Analytics 4 on our marketing website. It sets cookies in your browser and records information such as the pages you view, how you arrived, approximate location derived from your IP address, and your device and browser type. See section 6.
- Enquiries. Demo requests, webinar registrations, resource downloads and newsletter sign-ups are stored in HubSpot, our customer relationship management system. This includes the name, email address, organisation and any other details you give us.
- Correspondence. Emails you send us and our replies.
4. Why we use it, and our legal basis
Where we are the data controller:
- Providing the service you bought — performance of a contract.
- Taking payment — performance of a contract, and legal obligation for tax records.
- Responding to enquiries and demo requests — legitimate interests, in responding to someone who contacted us.
- Marketing emails to business contacts — legitimate interests, or consent where the law requires it. Every email has an unsubscribe link.
- Website analytics — legitimate interests, in understanding how our site is used and improving it.
- Security, fraud prevention and service monitoring — legitimate interests.
- Meeting our legal and regulatory obligations — legal obligation.
Where your organisation is the controller, the legal basis for processing learner data is theirs to determine and to tell you about.
5. AI features
Our AI features run on the OpenAI API, or on Azure OpenAI in an EU region for European customers who request it. No data submitted through these APIs is used to train or improve OpenAI's or Microsoft's models. OpenAI may retain API inputs and outputs for up to 30 days to monitor for abuse, after which they are deleted.
AI scores are for learning and development only. Our customer agreements prohibit using them for decisions about hiring, promotion, pay or any other employment outcome. We do not collect facial images, facial expressions, emotion data or voice identification data.
Full detail: AI and Data Privacy.
6. Cookies and analytics
Our marketing website uses Google Analytics 4, which sets cookies in your browser to measure how the site is used. These cookies collect information such as pages viewed, time on site, referring source, approximate location and device type. We use this to understand which content is useful and to improve the site. We do not use advertising or retargeting pixels.
The VirtualSpeech platform itself uses cookies that are necessary for it to work, such as keeping you signed in.
You can control cookies through your browser settings, which allow you to block or delete them. You can also install Google's browser opt-out add-on to prevent Google Analytics collecting data about you on any website. Blocking analytics cookies does not affect your use of our site.
7. Who we share data with
We use the following sub-processors. All operate under written contracts imposing GDPR-compliant safeguards.
| Sub-processor | Purpose | Entity and location |
|---|---|---|
| Amazon Web Services | Hosting, storage, logging and error monitoring | Amazon Web Services EMEA SARL, Luxembourg |
| OpenAI | AI conversations, scoring and feedback | OpenAI OpCo, LLC, USA |
| Microsoft | Azure OpenAI, for EU customers on request | Microsoft Ireland Operations Ltd, Ireland |
| Stripe | Payment processing | Stripe, Inc. |
| Business email, productivity and website analytics | Google Ireland Ltd | |
| BunnyCDN | Content delivery | BunnyWay d.o.o., Slovenia |
| HubSpot | Customer relationship management | HubSpot, Inc. |
We also share data where we are legally required to, and we may share it with a buyer or successor if the business is sold, in which case we would tell affected customers.
We do not sell personal data, and we do not share it with advertisers.
8. Where your data is held
- European customers: AWS in Frankfurt, Germany.
- All other customers: AWS in Ohio, United States.
Backups are held in the same region as the live data. Server logs are held in the same region.
Some of our sub-processors are based in the United States. Transfers to them are covered by the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, together with additional safeguards where required.
9. How long we keep it
- Learner and organisation data: up to six years, unless your organisation's contract with us specifies a shorter period. Many customers agree a shorter retention period, and we recommend it.
- Deletion by learners and administrators: transcripts, recordings and uploaded files can be deleted at any time. They are removed from the platform immediately and roll off backups within 10 days.
- Deletion requests: completed within 7 days.
- Security and troubleshooting logs: 90 days.
- Audit and compliance logs: 15 months, or longer where the law requires it.
- Backups: taken daily, retained for 10 days.
- Marketing contacts: retained until you unsubscribe or ask us to delete your details, and reviewed periodically.
10. How we protect it
- Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256.
- Passwords are hashed using PBKDF2 with SHA-256 and random salts.
- Four members of our technical team have production access, all with multi-factor authentication, background checks and security training. Access follows the principle of least privilege.
- We commission an annual penetration test from a CREST-accredited firm.
- We are ISO 27001 aligned, with certification in progress.
Full detail: Trust Center.
11. Your rights
Under the UK GDPR and EU GDPR you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data erased
- restrict or object to how we use it
- receive your data in a portable format
- withdraw consent, where we rely on it
- object to direct marketing at any time
To exercise any of these, email privacy@virtualspeech.com. We respond within one month.
If your organisation gave you access to VirtualSpeech, they are the data controller. Please contact them first; we will assist them in responding to you.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office, or to your local supervisory authority in the EU. We would appreciate the chance to resolve it first.
12. Children
Individual subscriptions bought from our website are for people aged 18 or over. We do not knowingly collect data from children through direct sign-up.
Where an educational institution provides access to students, the institution is the data controller and is responsible for confirming that it has the appropriate legal basis and, where relevant, parental consent for any learner under 18. Institutions can anonymise learner data and disable recording features.
13. Data breaches
We maintain a documented incident response plan. In the event of a personal data breach, we notify the affected data controller without undue delay and no later than 72 hours after becoming aware of it, and we assist with notifying the supervisory authority and affected individuals where required.
14. Changes to this policy
We update this policy when our practices change. The date at the top shows when it was last revised. Where changes are significant, we tell customers directly.
15. Contact
Privacy and data protection: privacy@virtualspeech.com
Security and compliance: security@virtualspeech.com
Privacy lead: Dominic Barnard, Co-Founder
VirtualSpeech Ltd, 44–54 Unit 4, Coleridge Road, London N8 8ED, United Kingdom. Company number 09517558. ICO registration ZB245994.