Consent first, and a receipt that says which version
India’s Digital Personal Data Protection Act sets the floor: consent before processing, a purpose you can state, and rights the person can actually exercise. This is how that is built into a voice survey — including the one place where a residency claim would be too convenient to be true.
Before anything records
Consent comes first, and it leaves a receipt
A voice survey asks a stranger to speak into a microphone. Everything else on this page depends on that first moment being handled properly, so it is a hard gate in the code rather than a paragraph of policy.
No consent, no conversation. Not a checkbox — a gate.
The respondent reads what the study is, who is asking, who will see the answers and how long it takes, before anything records. Declining ends the visit there; nothing is captured, and there is no partial session left behind.
A receipt, stamped with the version they actually saw.
Consent is recorded with the version of the wording that was on screen at that moment. When the wording later changes, old consents still point at what those people were shown — which is the difference between having consent and being able to demonstrate it.
No account, no app, no third-party trackers on the survey page.
A respondent answers from a link on the phone they already have. They are not asked to register, and the page carries no third-party scripts — so answering a survey does not quietly enrol someone in anything.
What is held, and where
Encrypted, in India, with the outside parties named
The questions a data protection officer asks are always the same four: what do you hold, where does it sit, who else touches it, and how long do you keep it. Here are the first three; the fourth is below.
Personal data is encrypted by the application before it is stored.
Names, phone numbers and email addresses are encrypted by the platform itself, so what sits in the database is opaque even to someone reading the rows. Keys are versioned and rotatable.
The IP address is never stored — only a keyed digest of it.
Abuse and duplicate detection need to know that two visits came from the same place. They do not need the address itself, so what is kept is a keyed one-way digest that answers “same or not” and cannot be turned back into a location.
Hosting and the database are in India.
The application, the database and stored audio sit on Indian infrastructure, operated by an Indian company registered in Bengaluru. Where a step in the pipeline is served from outside India, it is named — see below, because a residency claim with an unstated exception is worth less than no claim.
A register of every outside company that touches personal data.
Speech, hosting, email delivery, storage — each is listed with what it does and what it sees, maintained as part of the product rather than assembled the week a security review lands.
What the respondent can demand
Retention, opt-out and erasure — with deadlines attached
Rights that depend on somebody remembering to act are not rights. Each of these is enforced by the platform on a clock, which is also the only version of it that survives an audit.
Audio is kept for the period your campaign is set to, and then deleted.
Retention is a setting on the campaign, chosen before fieldwork starts, and the platform will not accept a value above ninety days. Deletion runs automatically when the period expires — it is not a task someone has to remember, and “we forgot to purge it” is the failure this design exists to remove.
Opt-out is honoured within 24 hours, and survives your next upload.
Someone who asks not to be contacted again is recorded against the person, not against the row they arrived on. Re-importing the same list next quarter does not resurrect them — the failure mode that turns one annoyed customer into a complaint to a regulator.
Erasure, with a short grace window before it becomes irreversible.
A deletion request is acted on and then finalised after a defined grace period, so a request made in error can be reversed and a genuine one is actually completed rather than left pending forever. Any legal hold that pauses it has to carry an end date.
And the request can be made during the conversation itself.
A respondent who says “delete what I just told you” or “what do you have about me” has that captured as a recorded request there and then, rather than being told to write to an address they will not write to.
What your team sees
The disclosure promise is enforced by the platform, not by policy
The promise made to a respondent is only worth what the system does when a client asks for more than it allows. Here it refuses.
De-identified is not anonymous, and we do not blur the two.
On a commissioned study the link between a person and their answers exists — that is what makes an opt-out or a deletion request possible at all. De-identified means the platform holds that link and refuses to resolve it in reporting. Calling it anonymous would be a promise the architecture cannot keep, so the product uses three distinct words, and the respondent is told which one applies before they answer.
Raw contact details never appear in a client report.
The dashboard your team reads shows answers, not phone numbers. Where a study was run on a named basis and the client is entitled to see who said what, access is controlled by permission and every look is written to an audit log.
The promise is fixed before anyone is invited, and cannot move after.
Whether a study is anonymous, de-identified or named — and who may see the results — is settled before the first invitation goes out, and locked once answers exist. Nobody can decide after the fact that a study people answered in confidence is now attributable.
The exception, stated plainly
Storage is in India; one processing step may not be
Speech recognition and the voice itself run on an Indian provider. The reasoning step — the part that decides what to ask next — runs on the model stack the deployment is configured with, and the default one processes transcript text outside India. That is a choice of configuration, not a property of the product, and if India-only processing is a requirement for your study, raise it before fieldwork rather than discovering it in a security review.
We would rather write this sentence than let a residency claim quietly cover a step it does not cover. Every provider involved is in the sub-processor register with what it does and what it sees.
What we do not do
The list that matters is the list of things absent
Personal data is never sold or shared for advertising. There is no video capture and no face recognition anywhere in the product. Voice fingerprinting exists as unreleased code and stays switched off, because a voiceprint is biometric data and turning it on is a decision about consent and law, not a feature toggle. And there is no WTN respondent panel — every person contacted comes from the client’s own list, with their confirmation that those people may lawfully be contacted.
DPDP-aligned: consent taken before any recording and receipted with the version shown, personal data encrypted before storage, IP addresses kept only as a keyed digest, retention set per campaign within a ninety-day maximum and deleted automatically, opt-out honoured within 24 hours, and erasure with a grace window. Nobody certifies software of this sort, and WTN claims no certification or regulatory approval of any kind.
A data-processing agreement, the breach-notification runbook and the sub-processor register are available for a security review — ask, and they are sent as they stand.