top of page
About Voxly
Chatting Over Coffee

Voxly helps global brands scale their digital capabilities in Advertising, Commerce, and Customer Support with AI.

We offer Voxly Vision: An AI Co-Pilot that scans advertising creative to ensure compliance against complex brand rules and responsible marketing regulations. By replacing slow manual sign-offs with near-instant reporting, it helps protect brands from costly legal fines and reputational damage while accelerating speed-to-market.

We also offer AI based solutions for Conversational Marketing and Customer Service. Our clients include Diageo (multiple brands including Don Julio, Baileys, etc), the UK Royal Navy, and Bristol Airport in the UK.

Led by Ravi Lal and Elliot Brock, we are based in Paddington, London, and our services span strategy, design, development, and in-life optimization.

Voxly is a trading name owned by Dolphin Haley LTD, and we hold both ISO 27001 and Cyber Essentials certifications.

Voxly Vision for Slack: Privacy Notice

  • Jul 15, 2019
  • 7 min read

Updated: Jul 21

Last updated: 21 July 2026


1. Who we are and what this notice covers


Dolphin Haley LTD, trading as Voxly, Voxly Digital and Starla (“Voxly”, “we”, “us” or “our”), provides Voxly Vision, an AI-assisted service for evaluating brand and advertising assets against selected compliance frameworks.


This notice explains how Voxly Vision handles data received from or created through the

Voxly Vision for Slack app.


It supplements our general privacy policy. If this Slack-specific notice conflicts with the general privacy policy in relation to the Slack app, this Slack-specific notice applies.


Dolphin Haley LTD is registered in the UK under company number 08396885.


2. What the Slack app does


After an authorised person installs Voxly Vision in a Slack workspace, members can run /voxly-evaluate, upload an asset in the modal, and choose one or more compliance frameworks. Voxly Vision downloads the submitted asset, evaluates it using an AI model, stores the evaluation record, and sends progress and results to the requesting member in the app’s private Messages tab.

Members can run /voxly-help or send the app a direct message to receive usage guidance. The app does not monitor public or private channels and does not join channels automatically.


3. Data we receive and create


Depending on how the app is installed and used, we process the following data.

Category

Examples

Why we need it

Slack workspace data

Workspace ID and workspace name

To associate the installation and evaluations with the correct Voxly Vision workspace

Slack member data

Slack member ID, first name, last name and email address

To identify the installer or requesting member, provision or link their Voxly Vision account, attribute evaluations, enforce the free allowance, and return private results

Installation and authorisation data

Slack bot OAuth access token, installer ID, installation time and connection status

To authenticate calls to Slack, open evaluation modals, download a submitted file, and send messages and results

Commands and interactions

Slash-command payload fields, interaction IDs, modal selections, selected framework IDs, channel or conversation ID, message timestamp, and event metadata

To open and process the requested workflow and update the correct Slack message

Direct messages to the app

A direct-message event and its content may pass through our endpoint

To recognise that a member messaged the app and return usage guidance. Ordinary direct-message text is not used to create profiles or train AI models and is not stored as evaluation content

Submitted assets

The image, video or text file a member deliberately submits; file name, type, size and Slack private download URL

To carry out the requested compliance evaluation and maintain the member’s evaluation history

Evaluation data

Selected frameworks, job name and status, AI model identifier, results, classifications, explanations, recommendations, usage and cost metadata

To provide the requested result, show evaluation history, support reruns, and operate the service

Technical and security data

Request time, delivery and queue metadata, service errors, audit events and limited diagnostic logs

To secure, troubleshoot, monitor and improve the reliability of the app


We receive some identifiers and payload fields automatically when Slack sends a command, interaction, event or OAuth response, even where a particular field is not displayed as a product feature.


We do not use Slack data for advertising, sell it, rent it, or use it to contact members for marketing. We will only send marketing communications where the recipient has separately opted in.


4. Slack permissions and how we use them


The app requests these bot permissions:

  • commands to provide /voxly-evaluate and /voxly-help.

  • chat:write to send help, progress, error and result messages.

  • files:read to download the specific file a member submits through the evaluation modal.

  • im:write to open or write to the app’s direct-message conversation with a member.

  • im:history to receive new human-authored messages sent directly to the app and respond with usage guidance.

  • users:read and users:read.email to obtain the installer’s or requesting member’s name and email, link or provision their Voxly Vision account, and attribute their evaluations correctly.


Voxly Vision does not request access to public-channel history, private-channel history, group-direct-message history, or all workspace files for bulk collection. It processes files when a member deliberately selects and submits them through the app.


5. How we use the data


We use the data described above to:


  • install and connect the app to the correct Slack workspace;

  • create or link a Voxly Vision account using the member’s Slack profile and email;

  • open the evaluation form and show available compliance frameworks;

  • download and securely stage the asset chosen by the member;

  • run the requested AI-assisted compliance evaluation;

  • send progress, errors and results privately to the requesting member;

  • preserve evaluation history and make it available to the correctly linked user in Voxly Vision;

  • enforce service limits and prevent abuse;

  • maintain security, auditability and operational reliability;

  • respond to support, privacy and security requests; and

  • comply with legal obligations and Slack’s platform rules.


The lawful basis for personal-data processing will depend on the relationship and jurisdiction. In the UK and EEA, processing will generally be necessary to provide the requested service or perform our agreement, for legitimate interests in operating and securing the service, or to comply with legal obligations. Where consent is required, we will request it separately.


6. AI processing


Voxly Vision uses a third-party AI provider for Slack evaluations. The submitted asset and relevant compliance-framework instructions are sent to this provider so the model can classify the asset and produce explanations and recommendations. We store the resulting evaluation in Voxly Vision and return it to the requesting member in Slack.

AI outputs can be incomplete, inaccurate or inappropriate. They are decision-support only and must be reviewed by a qualified person before use. Voxly Vision must not be used to make legal, medical, employment, financial or other consequential decisions without meaningful human review.

Slack data is not used by Voxly to train an AI model.

  • Provider: Third-party AI provider

  • LLM data use: Processing the member-selected asset and applicable compliance rules to generate the requested evaluation


7. Where data is stored and who receives it


Voxly Vision’s primary application, database, object storage and processing queues are hosted with Amazon Web Services in the London region (eu-west-2). Data may also be processed by:


  • Slack Technologies, LLC / Salesforce, which provides the Slack platform and sends or receives the app’s commands, files and messages;

  • Amazon Web Services, which hosts Voxly Vision’s application, database, object storage, queues and operational logs; and

  • A third-party AI provider, which processes submitted assets and framework instructions to produce AI evaluation output.


We use service providers only to provide, secure and support Voxly Vision. We do not sell or rent Slack data. Where processing involves an international transfer of personal data, we use the contractual and organisational safeguards required by applicable law.


8. How long we keep data


We keep data until a user asks us to delete it, except where a shorter period is required by Slack or law. If a workspace uninstalls the app, Slack-related data is deleted as required by Slack rules.


Data

Retention

Slack OAuth token and workspace connection

While the app is installed or the integration remains connected. The token is removed when Slack reports an uninstall or an authorised user disconnects the integration

Slack workspace and member identity links

While the app is installed or needed to provide the service; deleted no later than 14 business days after removal of the app or a verified deletion request

Submitted assets, evaluation jobs and results

Until the user requests deletion. If Slack app uninstall occurs, Slack-related records are removed as required by Slack's platform rules.

Temporary command, event, interaction and processing-queue payloads

Until the user requests deletion, subject to retry/dead-letter retention needs and Slack uninstall rules for Slack-coupled data.

Application, security and audit logs containing Slack data

Until the user requests deletion, with any legal holds applied where required.

Backups containing deleted Slack data

Until the user requests deletion and in accordance with normal backup lifecycle controls; deleted records are isolated from normal use while retained.

When the app is discontinued, all associated Slack data will be deleted within 14 business days.


9. Uninstalling the app and deleting data


An authorised workspace owner or administrator can remove Voxly Vision through Slack’s app-management settings. On uninstall, Slack revokes the app’s access. Voxly Vision removes the stored bot token and Slack identity links and completes deletion of the remaining Slack-associated data within 14 business days.


Uninstalling is separate from deleting a general Voxly Vision account or data that a customer supplied directly through the Voxly Vision website. To ask us to identify and delete all applicable records, email support@voxlydigital.com with the subject “Voxly Vision Slack data deletion” and include:


  • the Slack workspace name and, if available, workspace ID;

  • the Slack member email or member ID concerned; and

  • whether the request is for access, a portable copy, correction, restriction or deletion.


Do not send Slack access tokens, client secrets, passwords or confidential asset files by email.


10. Your choices and rights


Subject to applicable law, an individual may ask us to:


  • confirm whether we process their personal data and provide access to it;

  • correct inaccurate or incomplete data;

  • provide a portable copy of data they supplied;

  • restrict or object to certain processing; or

  • delete their personal data.


Requests can be sent to support@voxlydigital.com. We may need to verify the requester’s identity and authority over the relevant workspace before acting. We will respond within the period required by applicable law and will not ignore a valid deletion request.


UK residents may also complain to the Information Commissioner’s Office, although we would appreciate the opportunity to resolve the concern first.


11. Security


We use administrative, technical and organisational controls designed to protect data against unauthorised access, alteration, disclosure or loss. These include authenticated and signed Slack requests, restricted cloud access, private object storage, encryption in transit, infrastructure encryption at rest, short-lived signed asset URLs, monitoring and audit records. No system is completely secure, and we cannot guarantee absolute security.


12. Children


Voxly Vision is a workplace service and is not intended for children under 16. We do not knowingly permit children under 16 to use the Slack app.


13. Changes to this notice


We may update this notice when the app, our providers, legal requirements or Slack’s platform rules change. We will update the date at the top and provide additional notice where a change materially affects how Slack data is handled.


14. Contact us


Dolphin Haley LTD

Trading as Voxly, Voxly Digital and Starla

Boundary House

Cricketfield Road

Uxbridge

Middlesex England

UB8 1QG

UK


 
 
bottom of page