Privacy

Your data, plainly put.

What we collect, why, how long we keep it, and how to make us delete it. The short version: this site collects almost nothing.

This policy explains what happens to personal data when you visit voxatelier.studio or contact Vox Atelier. It covers the website and the enquiry correspondence that follows from it. Work we do for clients, including voice recordings and talent data, sits under separate contracts. See the Voice and talent data and Other people whose data we hold sections below.

The short version

This site collects almost nothing. That is a design decision, not an oversight.

  • There is no analytics on this website. No Google Analytics, no Plausible, no tag manager, no pixels, no heatmaps, no session recording.
  • There is no tracking of any kind, and no advertising technology.
  • The site sets no cookies. It stores exactly one thing on your device: the record of your own choice in the consent banner. Details below.
  • There are no third-party scripts and no external network calls. Fonts and animation libraries are served from our own domain, so your browser never quietly contacts anyone else while you read a page.
  • The site has no database and no server-side code. It is five static pages.
  • The contact form does not send anything to us over the web. It opens your own email program with a message already written, and you decide whether to send it. We explain this in detail below.
  • We honour the Global Privacy Control signal automatically, without showing you a banner.

What remains is small and unavoidable: our hosting provider records standard server logs so the site can be delivered and defended, and if you email us, we have your email.

Who we are and how to contact us

Vox Atelier is a dubbing and voice-production studio working across five disciplines: dubbing, animation and YouTube, TV films and series, simultaneous interpretation, and commercials. We operate from London and Lisbon with a roster of more than 150 native voice actors, and we run production through our own pipeline, ATRIVOX HQ, which handles casting, scheduling, session tracking and quality control.

Vox Atelier is a trading name used by a sole trader based in the United Kingdom. There is no registered company and no company number. For data protection purposes, that sole trader is the controller of the personal data described in this policy.

For anything to do with privacy, including any request to exercise your rights, write to projects@voxatelier.studio. We aim to acknowledge messages in under 12 hours. Formal rights requests are answered within the legal deadline, normally one month.

Postal contact details: (to be confirmed)

Data protection officer. We have not appointed one. A DPO is required only where an organisation is a public authority, carries out large-scale regular and systematic monitoring, or processes special category data at scale. None of those apply to a studio site that runs no tracking. Privacy questions go to the address above and are handled by the controller directly.

Data protection registration

Sole traders who process personal data for business purposes may need to pay the UK data protection fee and register with the ICO. (to be confirmed)

Which law applies

UK GDPR and the Data Protection Act 2018 apply, because the controller is established in the United Kingdom. The Privacy and Electronic Communications Regulations apply to anything stored on or read from your device.

EU GDPR may also apply, because we offer services to clients in the European Economic Area and we work between London and Lisbon. Where it applies, you have the same rights set out below and you can complain to your own national authority.

Governing law for this policy and for any dispute about it is England and Wales.

What we collect, and exactly where

There are three surfaces on which personal data can appear, and one of them turns out not to be a collection at all. All three are listed below, followed by what we deliberately do not collect and what happens when you follow a link off the site. Storage on your own device is covered separately under Cookies and local storage.

a. Server and hosting logs

The website is hosted by Vercel Inc. and served from its global edge network. Like every web host, Vercel automatically records request and server logs when a page, image, font or script is requested. These logs can include:

  • your IP address
  • your browser user agent string, which usually names your browser, version and operating system
  • the URL or file requested, and the referring URL if your browser sends one
  • the date and time of the request, the response status code and the response size
  • approximate region derived from the IP address, used by the edge network to pick a nearby server

We do not choose to collect this, and we do not use it to build a profile of you. It exists so the site can be delivered, so abuse and denial-of-service attacks can be blocked, and so faults can be diagnosed. We can view recent logs in the Vercel dashboard, and in practice we look at them only when something is broken or under attack. We do not export them, and we do not combine log data with anything else.

b. The contact form. Please read this, it is unusual

The "Request a demo" form on the contact page has no backend. There is no server endpoint behind it, because the site has no server-side code at all.

When you press submit, a small piece of JavaScript running in your own browser takes the values you typed and assembles them into a mailto: link, then opens your own email program with a draft message. Nothing is transmitted by the website. We do not receive the form. Vercel does not receive the form. Nothing is stored on the site.

From that point it is an ordinary email that you have written. If you choose to send it, it travels through your email provider to our mailbox, and both your provider and our mailbox provider handle it in the normal way. If you close the draft without sending, we never learn that you filled anything in. Your browser and your email program may keep the draft in their own storage, on your device and under your control, and we cannot see or reach that.

The fields the draft is built from are: your name (required), your company (optional), the service you are interested in (a menu selection), your target languages (optional), and your message (required). The required fields are required because without a name and a message we cannot give you a useful answer. There is no statutory or contractual obligation to provide any of it. If you would rather not use the form, email us directly and tell us only what you want to.

Two things are also in the form that you should know about. There is a hidden anti-spam field, sometimes called a honeypot, which is invisible to people and to screen readers and is skipped by keyboard navigation. Automated bots tend to fill it in. If it is filled, the submission is dropped and no draft is opened. Nothing about it leaves your browser. There is also a tick box confirming you have read this policy before the draft is built.

About that tick box

The tick box on the form is an acknowledgement that you have read this policy. It is not the legal basis on which we answer you. We reply to enquiries under legitimate interests, and under pre-contract steps once a project is in view, as set out in the table below. This matters because a right that depends on consent behaves differently from one that does not. (to be confirmed)

Practical consequence

Because the form never reaches us, we cannot delete an unsent draft, and we have no record of abandoned enquiries. Please do not put sensitive personal information, financial details or confidential third-party material into the message field. Ordinary email is not a secure channel.

c. Email you send us directly

If you email projects@voxatelier.studio, whether from the form draft or on your own, we hold whatever you sent: your name, your email address, your signature block, anything in the message body and any attachment. We use it to answer you and to run the project if one follows.

d. What we do not collect

  • No analytics or measurement data of any kind.
  • No advertising identifiers, no cross-site tracking, no fingerprinting.
  • No account, no login, no password, no payment data through this website.
  • No special category data, such as health, religion, politics or biometric data.
  • No audio recording of you. The waveform graphics on the site are decorative canvas animations drawn by a mathematical function. There is no audio file on this website and your microphone is never accessed.
  • No use of your enquiry, your message or anything else you send us to train, fine-tune or prompt a machine learning system.

e. Links that leave the site

Project cards link out to YouTube, ReelShort and GoodShort. Nothing is loaded from those services until you click, and no embedded player, tracking pixel or preview request runs on our pages. Once you follow a link you are on someone else's site, under their privacy policy, not ours.

Cookies and local storage

This site sets no cookies. Not one, not for analytics, not for advertising, not for sessions. There is nothing to consent to today.

The site does show a consent banner on your first visit, and there is a Cookie Settings button in the footer of every page. That looks like over-engineering for a site with no cookies, and in a sense it is. It exists so that the switch is already in place and already off. Any non-essential script added in future is written into the page as inert markup that a browser will not execute, and it can only be turned into a live script after you have allowed that category. Nothing can fire before you agree, including by accident.

When you make a choice, one entry is written to your browser's localStorage under the key va.consent.v1. That is not a cookie. It is a value kept on your own device, it is never attached to network requests, and it is never sent to us or to anyone else. It records:

  • a version number for the record
  • the date and time you chose
  • how you chose: accept all, reject all, a custom selection, or an automatic refusal from a Global Privacy Control signal
  • whether you allowed the analytics category and the marketing category, both of which are empty today

The record expires after 365 days, at which point we ask again. Switches are never pre-ticked in your favour, and Accept all and Reject all are the same size and the same weight in the banner, because nudging you towards one is not a choice. If you turn something off that you had previously turned on, the page reloads so that anything already loaded is unloaded rather than left running.

You can change your mind at any time through Cookie Settings in the footer. Clearing your browser's site data for this domain removes the record entirely, and you will simply be asked again.

Global Privacy Control and Do Not Track. If your browser sends a Global Privacy Control signal, we treat it as a refusal of everything optional, we record that refusal, and we do not show you a banner at all. You can still override it in Cookie Settings if you want to. We do not act on the older Do Not Track header, because there is nothing on this site that it could switch off.

Why we are allowed to do this: purposes and lawful bases

Under UK GDPR and EU GDPR we must have a lawful basis for each purpose. Here they are in full.

PurposeData usedLawful basisThe interest, stated plainly
Delivering the website to your browser IP address, user agent, request details Legitimate interests, UK GDPR Article 6(1)(f) A website cannot reach you without your IP address. Our interest is simply being able to serve the pages you asked for.
Keeping the site secure and available Server and edge logs, including IP address Legitimate interests, Article 6(1)(f) Our interest is detecting and blocking abuse, bot floods, denial-of-service attempts and scraping, and keeping a short evidence trail if something goes wrong. Any visitor also benefits from a site that stays up.
Diagnosing faults and errors Server logs, error responses Legitimate interests, Article 6(1)(f) Our interest is fixing broken pages. Logs are read in aggregate for this, not to identify individuals.
Replying to your enquiry and discussing a possible project Your name, email address, company, stated service, target languages, message Legitimate interests, Article 6(1)(f). Where an enquiry becomes a project, steps taken at your request before a contract, Article 6(1)(b) You wrote to a studio asking about work. Our interest, and yours, is that we can actually answer, quote and organise the job.
Blocking automated spam submissions The hidden anti-spam field only. No personal data, and nothing leaves your browser Legitimate interests, Article 6(1)(f) Our interest is not having the mailbox filled with bot traffic. The check runs entirely on your device.
Keeping business correspondence for accounting and legal records Email correspondence relating to paid work Legal obligation, Article 6(1)(c), for tax and accounting records. Legitimate interests, Article 6(1)(f), for defending potential claims UK tax rules require business records to be kept. Beyond that, our interest is being able to evidence what was agreed.
Remembering your consent choice A single record in your browser's localStorage Strictly necessary storage under PECR regulation 6(4). No consent is needed to store the record of your own choice. The processing basis is legitimate interests, Article 6(1)(f), or legal obligation where the record evidences compliance Respecting a preference requires remembering it, and being able to show what you chose is part of doing consent properly. Nothing is transmitted.
Any future analytics or measurement None today Consent, Article 6(1)(a), and PECR consent for storage on your device We run no analytics. If that ever changes, nothing will load until you actively opt in, and you will be able to withdraw at any time.

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it is proportionate: the data is minimal, it is not used to profile you, it is not sold, and it is kept briefly. You can object at any time. See Your rights below.

How long we keep things

CategoryPeriodWho sets it
Vercel request and edge logs, including IP address Short-term, typically measured in days rather than months, then deleted or aggregated by the platform Set by Vercel as part of the hosting platform, not configurable by us at the page level. (to be confirmed)
Vercel security and abuse-prevention logs Retained by the platform for its own security purposes for a limited period Set by Vercel. (to be confirmed)
Enquiry emails that do not lead to work 12 months from the last message, then deleted Set by us
Enquiry and project emails that do lead to paid work 6 years from the end of the relevant tax year, to meet UK record-keeping requirements and the standard limitation period for contract claims Set by us, driven by UK tax and limitation law
Contact form contents that were never sent Zero. We never receive them Structural. There is no backend to store them
Your consent record in localStorage 365 days, then it expires and we ask again. You can delete it sooner by clearing site data for this domain Stored on your own device, under your control
Analytics data None exists Not applicable

When a retention period ends, we delete the material or, where deletion from backups is not immediately possible, we put it beyond routine use and delete it on the next backup cycle.

Who we share data with

The list is short and complete.

  • Vercel Inc., our hosting and content delivery provider, headquartered in the United States with edge locations worldwide. Vercel processes server logs, including IP addresses, in order to deliver the site and protect it. Vercel acts as a processor on our instructions. It is the only processor involved in serving this website.
  • Our email mailbox provider, which receives, stores and serves the projects@voxatelier.studio mailbox. (to be confirmed)
  • Professional advisers, such as an accountant, where correspondence forms part of business records, and only to the extent needed.
  • Authorities or courts, if we are legally required to disclose something. We would resist an overbroad request.

Where we engage subcontractors, freelancers or voice actors on a client project, personal data is shared only as far as that project needs and under confidentiality terms. That happens through our contracts with clients, not through this website.

We do not sell your data

We do not sell personal data. We do not rent, trade or licence it. We do not share it with advertisers, ad networks, data brokers, list vendors or social platforms. We run no advertising technology, so there is nothing to share even if we wanted to.

International transfers

We are based in the United Kingdom and work between London and Lisbon, so most data stays in the UK and the European Economic Area. Two things can involve a transfer outside that area.

Hosting. Vercel Inc. is headquartered in the United States and operates a global edge network, so log data may be processed in the United States or in other countries where its infrastructure sits. Transfers of this kind need a recognised safeguard under UK GDPR Chapter V and EU GDPR Chapter V. In practice that is one or more of: the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum to the Clauses, or reliance on a US recipient's certification under the EU-US Data Privacy Framework and its UK extension, which the UK recognises through its data bridge.

Our position is that the transfer is covered by Vercel's standard data processing agreement and the transfer terms incorporated into it. We have not independently verified which mechanism currently applies. (to be confirmed)

Email. If our mailbox provider stores mail outside the UK and EEA, the same safeguards apply. (to be confirmed)

If you would like details of the safeguards that apply to a transfer, ask us at projects@voxatelier.studio and we will tell you what we hold on the point.

Representative in the EU

We are UK based and offer services to clients in the EU, which can trigger the requirement to appoint a representative in the Union under EU GDPR Article 27, unless an exemption applies because the processing is occasional and low risk. (to be confirmed)

Your rights

If you are in the UK or the European Economic Area, you have the following rights over personal data we hold about you. They are not absolute, and some only apply in certain situations, but we will always explain our reasoning if we cannot do what you ask.

  • Access. Ask whether we hold data about you, and get a copy of it along with an explanation of what we do with it.
  • Rectification. Have inaccurate data corrected, and incomplete data completed.
  • Erasure. Ask us to delete data, for example enquiry correspondence that went nowhere. We may refuse where we need to keep records for tax or legal reasons, and we will say so plainly.
  • Restriction. Ask us to pause our use of your data while a dispute about its accuracy or our lawful basis is resolved.
  • Portability. Receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller, where the processing rests on consent or contract and is automated.
  • Objection. Object to processing based on legitimate interests, including our retention of security logs. We must then stop unless we can show compelling grounds that override your interests.
  • Withdrawing consent. Where we ever rely on consent, you can withdraw it at any time, and it is as easy to withdraw as it was to give. For the consent banner, that is the Cookie Settings button in the footer, which is exactly as reachable as the banner was. Withdrawal does not undo processing that already happened lawfully.
  • No solely automated decisions. We do not make decisions about you by automated means, and we do not profile you.

How to exercise them. Email projects@voxatelier.studio and say what you want. There is no charge. We normally reply within one month, and we will tell you if a complex request needs longer, up to a further two months. We may need to confirm your identity first, and for log data we will usually need enough detail, such as an approximate date and IP address, to find anything at all. Be aware that because we keep so little, the honest answer to many access requests will be that we hold nothing about you beyond an email you sent us.

Complaining to a regulator

If you think we have handled your data badly, please tell us first. You can also complain to a supervisory authority at any time.

  • United Kingdom: the Information Commissioner's Office, at ico.org.uk. The ICO has a public helpline and an online complaints process.
  • European Economic Area: you may complain to the data protection authority in the country where you live, where you work, or where the issue happened.

California privacy rights

This section is for California residents and is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act. It applies to the extent that law covers us at all, which given our size and the amount of data involved is unlikely, but we would rather be clear than silent.

Categories collected in the last 12 months. Only identifiers and internet activity information: IP address and user agent in server logs, and, if you write to us, your name, email address, company and the contents of your message. We collect no sensitive personal information as that term is defined by the CCPA, and no biometric information. Sources are you and our hosting provider's automatic logging. Purposes are set out in the table above, and how long each category is kept is set out under How long we keep things.

  • Right to know. Request the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of third parties we disclosed to.
  • Right to delete. Request deletion of personal information we collected from you, subject to legal exceptions such as tax records.
  • Right to correct. Request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the previous 12 months, and we have no mechanism that could. There is therefore nothing to opt out of, and no "Do Not Sell or Share My Personal Information" link is required. We also do not sell or share the personal information of anyone under 16. We honour the Global Privacy Control signal regardless, as described under Cookies and local storage.
  • Right to limit use of sensitive personal information. We collect none, so there is nothing to limit.
  • Right to non-discrimination. We will never give you worse service, worse pricing or a worse response because you exercised a privacy right.

How to exercise. Email projects@voxatelier.studio with "California privacy request" in the subject line. We will verify your request by replying to the email address on file and asking you to confirm details we already hold. An authorised agent may act for you with written permission that we can verify. We respond within 45 days and will tell you if we need a 45 day extension.

Voice and talent data

We are a voice studio, so it is worth being exact about what this website does and does not do with voices.

  • There is no demo audio on this website. There is no audio file of any kind. The waveform graphics you see are drawn in real time by a mathematical function on a canvas element. They are decoration, not a recording, and they are not derived from anyone's voice.
  • No voice actor is identified here. We publish no actor names, no headshots and no photographs of talent. The roster artwork is a stylised illustration of anonymous figures, not real people.
  • This website collects no voice data from you. It never requests microphone access and cannot record you.
  • Recordings live outside this website. Voice recordings, casting materials, actor demos, session files and delivered masters are handled inside our production workflow, ATRIVOX HQ, and under separate written contracts with the actors who perform and the clients who commission the work. Those contracts, not this policy, govern consent, permitted uses, territory, term, credit and payment.
  • If demo audio is ever added to this site, it will only be published with the performer's specific, informed and documented permission for that use, it will remain removable at the performer's request under the terms of their agreement, and this policy will be updated before publication.
No scraping, cloning or synthetic reuse

Nothing on this site, including text, images, and any audio or video that may be added in future, may be copied, scraped, harvested or used to train, fine-tune or build a machine learning model, a synthetic voice, a voice clone or any automated system. Vox Atelier does not offer AI dubbing and does not synthesise performers' voices. Any attempt to imitate or reconstruct a performer's voice from our material is prohibited and will be treated as an infringement. Report suspected misuse to projects@voxatelier.studio.

If you are a voice actor on our roster

This policy covers people who visit the website. It does not cover the personal data we hold about the actors we work with. That has its own notice, which explains what we hold, why, how long for, and how to have it deleted: see the Roster Privacy Notice.

Other people whose data we hold

This policy is written for people who visit the site or write to us. Two other groups deserve a straight answer.

  • Voice actors and freelancers on our roster. We hold contact details, casting information, rates, availability and performance records in order to book and pay you. None of that is on this website, and none of it is published. Your engagement terms govern it.
  • Client contacts. We hold names, work email addresses, phone numbers and project correspondence in order to deliver commissioned work and keep proper business records.

If you are a voice actor on our roster, the personal data we hold about you is covered by a separate document, not this one. See the Roster Privacy Notice, which explains what we hold, why, how long for, and how to have it deleted. This website policy covers visitors to voxatelier.studio only.

Children

This website is a business-to-business studio site. It is not directed at children, it is not designed to appeal to them, and it offers nothing intended for anyone under 16. We do not knowingly collect personal data from children under 16, and we do not ask visitors their age because we collect no profile data at all.

If you believe a child has sent us personal data, write to projects@voxatelier.studio and we will delete it.

Where children perform in a production we work on, their participation is arranged through the client and the child's parent or guardian under the relevant contracts and licensing rules. None of that goes through this website.

Security

The strongest security measure here is structural: the site holds no data to steal.

  • No data at rest. There is no database, no server-side code, no user accounts, no uploads and no stored form submissions. The site is a set of static files.
  • Encryption in transit. The site is served over HTTPS with TLS. Plain HTTP requests are redirected to HTTPS by the host, and certificates are issued and renewed automatically.
  • No third-party code. Fonts and animation libraries are self-hosted, so there is no supply chain of external scripts that could be compromised and no external host receiving your IP address as a side effect of loading a page.
  • Platform protections. Vercel provides infrastructure-level protections, including denial-of-service mitigation and access controls on the deployment account.
  • Response headers. The site sets a custom security header configuration: a Content-Security-Policy that blocks third-party scripts and framing, Strict-Transport-Security to force HTTPS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a restrictive Permissions-Policy. (to be confirmed)
  • Email. Ordinary email is not end-to-end encrypted. Please do not send confidential scripts, unreleased material or sensitive personal data by plain email. Ask us and we will arrange a better channel.

No system is perfectly secure. If we ever suffered a personal data breach that posed a risk to people, we would notify the ICO within 72 hours where required, and tell affected individuals directly where the risk was high.

If you find a security problem with this website, please report it to projects@voxatelier.studio rather than disclosing it publicly. We will not take legal action against anyone who investigates and reports a genuine issue in good faith, without accessing other people's data, without degrading the service, and without disclosing it publicly before we have had a fair chance to fix it.

Changes to this policy

We will update this policy when the site or our practices change, for example if analytics were ever introduced, if the contact form gained a real backend, or if we added demo audio. The "last updated" date below always changes when the text does.

For minor wording changes we simply publish the new version. For a material change, meaning one that affects what we collect, why, who receives it or how long we keep it, we will publish the change ahead of it taking effect and, where we hold your email address and the change affects you, tell you directly. If a change requires your consent, we will ask for it and nothing will happen until you agree.

Previous versions are available on request from projects@voxatelier.studio.

Version

Version 1.0. Last updated (to be confirmed). This policy applies to voxatelier.studio and covers the website as described above. Controller: the UK-based sole trader operating as Vox Atelier. Governing law: England and Wales. Contact for all privacy matters: projects@voxatelier.studio.

Draft status

This document is a draft prepared for review. It has not been reviewed by a qualified data protection lawyer, and the items marked in double brackets must be resolved before publication.

Version 1.0 · Last updated 21 July 2026

projects@voxatelier.studio