How your information moves through VanVox
Effective: 24 July 2026 Last reviewed: 24 July 2026
This page explains, in plain language, what happens to your information as it moves through VanVox — from the moment you send a message to the point where it is deleted. VanVox is operated by VANVOX LTD and helps UK sole traders and small businesses turn WhatsApp messages, voice notes and receipts into draft quotes, invoices and expense records that you review and confirm.
The wording here is written to match what the application actually does. Where a step depends on how the service is deployed, or on checks that still need human or legal verification, we say so rather than over-promise. This is a transparency page, not a certification or a guarantee.
Read this alongside our Trust Centre, security statement, Privacy Notice, data deletion instructions and subprocessor register.
The lifecycle, step by step
Each numbered step below describes one stage. The steps run in order, and each one is labelled with its number and name so the sequence is clear without relying on colour.
-
Step 1: You send information
You start with a WhatsApp text, a voice note, a receipt photo, or an entry you type in the dashboard. Nothing happens until you choose to send something.
-
Step 2: VanVox receives it
The message content and the provider metadata that comes with it are received. Duplicate inbound messages are safely ignored, so sending the same thing twice does not create two records.
-
Step 3: Temporary processing
Voice notes may be downloaded and transcribed. Typed text or a receipt image may be analysed to read the details. Any intermediate working data is created only to carry out the request you made, and is not a record of its own.
-
Step 4: Structured draft creation
The details are extracted into a draft. Validation checks amounts, dates, the parties involved and the line items. If something is missing or unclear, VanVox asks you a clarifying question rather than guessing.
-
Step 5: Review and correction
You see a summary of the draft and can correct it. Deterministic edits are preferred, so a clear instruction is applied directly; AI assistance is used only where it is genuinely needed to interpret what you meant.
-
Step 6: Explicit confirmation
A quote or invoice is not finalised until you explicitly confirm it. An expense follows its own confirmation step, but it too requires your explicit yes before it becomes a kept record. AI-assisted output stays a draft until you confirm — it does not become a record automatically.
-
Step 7: Confirmed record
Once you confirm, the quote, invoice or expense becomes a structured business record that belongs to your business. Confirmed records can remain after the source artefacts that produced them have expired.
-
Step 8: PDF and delivery
A PDF may be generated and returned to you through WhatsApp, or downloaded from the dashboard. Outbound sends are deduplicated, so a retry does not send you the same document twice.
-
Step 9: Retention
Different kinds of information follow different rules. Source artefacts, transcripts, receipt images, failed-processing records and confirmed records are not all kept for the same period. Receipt images are covered by automated retention, with an application default of 90 days; the effective period is deployment-configurable and set by configuration.
-
Step 10: Deletion and redaction
You can ask us to delete your information. Live records may be deleted or redacted, and customer and document snapshots may be redacted rather than kept in full. Hosted links are revoked where supported. Deletion may still preserve limited records where the law or a necessary operational reason requires it.
-
Step 11: Backups and providers
Backups and copies held by external providers may expire on separate cycles. Removing something from the live service is not the same as immediate erasure everywhere, and we say so rather than promise complete removal from every system at once.
The states your information can be in
The same underlying information can exist in different states at once, and VanVox treats each state differently. This is why not everything is kept for the same length of time.
Source information
- Purpose
- The original text, voice note or receipt image you send.
- Can it become permanent?
- Not intended to be permanent.
- What ends its lifecycle
- Ends under configured retention schedules.
- Is your confirmation involved?
- No confirmation involved.
Intermediate processing data
- Purpose
- Working data created only to carry out a request, such as a transcript.
- Can it become permanent?
- Not intended to be permanent.
- What ends its lifecycle
- Ends when processing completes or under retention schedules.
- Is your confirmation involved?
- No confirmation involved.
Draft data
- Purpose
- A proposed quote, invoice or expense you have not yet confirmed.
- Can it become permanent?
- Does not become permanent on its own.
- What ends its lifecycle
- Ends if abandoned, or becomes a record only on your explicit confirmation.
- Is your confirmation involved?
- Your explicit confirmation turns it into a record.
Confirmed business records
- Purpose
- The quotes, invoices and expenses you have explicitly confirmed and kept.
- Can it become permanent?
- Kept as your business records; can remain after source artefacts expire.
- What ends its lifecycle
- Ends on deletion, subject to legal or operational retention.
- Is your confirmation involved?
- Created only after your explicit confirmation.
Audit and security records
- Purpose
- Limited records kept to run the service safely and investigate problems.
- Can it become permanent?
- May be retained for operational reasons.
- What ends its lifecycle
- Ends under operational retention rules.
- Is your confirmation involved?
- No confirmation involved.
Backup and provider copies
- Purpose
- Backups and copies held by the providers used to run the service.
- Can it become permanent?
- Not under VanVox's direct control in every case.
- What ends its lifecycle
- May expire on separate cycles after removal from the live service.
- Is your confirmation involved?
- No confirmation involved.
Voice, typed text and receipt images
How your information is handled depends on how you send it. Voice and typed text are equally valid ways to create a draft, but the steps behind them differ.
Voice note
- the audio is retrieved from the messaging provider;
- a temporary copy of the audio is held while it is processed;
- the audio is transcribed into text;
- the temporary audio is cleaned up afterwards.
Typed text
- there is no audio to download and no transcription step;
- the text goes straight to extraction and validation;
- the same review and confirmation steps then apply.
Receipt image
- the image is processed to read the expense details;
- a confirmed expense is kept as a record;
- that confirmed expense is retained independently from the source image.
If something fails or is retried
- heavy processing happens in the background rather than while you wait;
- safe retry is designed to prevent duplicate confirmed records or duplicate outbound sends if a step runs more than once;
- failed-processing records are kept for a bounded period so a problem can be investigated, then removed;
- ordinary logs are designed to avoid message bodies and transcripts, using safe identifiers, statuses and timestamps instead.
Asking us to delete your information
- you can request account and data deletion through our data deletion route;
- we may need to verify your identity before acting on a request;
- live records are deleted or redacted according to the rules that apply to them;
- hosted links are revoked where supported;
- backups and provider copies follow separate cycles, so removal is not immediate everywhere;
- we may keep limited information where the law or a necessary operational reason requires it.
See the data deletion instructions for how to start, and the Privacy Notice for the full detail.
Providers and where processing happens
VanVox relies on a small set of service providers to run the product, and some processing may take place outside the United Kingdom. Not all provider copies are under VanVox’s direct control. Exactly where each provider processes information, and which transfer safeguards apply, remains subject to human and legal verification. The maintained list lives in our subprocessor register rather than being duplicated here.