Using this lawfully
A voice recording is personal data almost everywhere, and analysing one to draw a conclusion about a person carries obligations that fall on you, not only on us. This page sets out what those usually are. It is not legal advice and we are not your lawyers.
Check that the recording was lawfully made, that you have a basis to process it, and that a person is not being told something about themselves by a machine alone. Truthring returns a probability with a published error rate. Admissibility is decided by the court, applying its own rules, and no vendor can promise it. Treat a result as one input into a human decision, never as sufficient on its own for any decision that harms somebody.
Nothing here is operating yet. Truthring has not launched. There is no live detector, no customer, no signed data processing agreement and no completed record of processing activities. What follows describes the obligations that will apply and the position we intend to take, so that a legal or procurement reviewer can see the shape of it early rather than after a contract is in front of them.
Before you check someone’s voice
- Was the recording lawfully made? Consent rules for recording a call differ by jurisdiction — some require one party, some require all. A recording made unlawfully is generally useless in the proceeding you wanted it for, and can create liability of its own.
- Do you have a lawful basis to process it? Analysing a voice recording is processing personal data under the DPDP Act, the GDPR and most comparable regimes. You need a basis, and “I was suspicious” is not one.
- Is the person entitled to know? In an employment or disciplinary context, transparency obligations usually apply and a covert analysis can taint the whole process even where the result is correct.
- Is a machine result driving the decision alone? Several regimes restrict decisions with legal or similarly significant effects taken solely by automated means. A Truthring verdict is a probability. It should inform a human judgement, never replace it.
The one we care most about. Do not use a Truthring result as the sole basis for accusing, disciplining, dismissing or prosecuting anyone. We publish a false positive rate precisely because it is not zero, and a person on the wrong side of that rate has no way to prove a negative.
By context
| Context | Position |
|---|---|
| Legal proceedings | Usable as one exhibit with the method and error rate attached. Admissibility is decided by the court, not by us, and varies by jurisdiction. Preserve your own original file. |
| HR and internal investigations | Permitted with transparency and a human decision-maker. Never as the sole ground for an adverse outcome. |
| Journalism | Supported. State in the piece that a probability was used, name the version, and publish the reference code so others can challenge it. |
| Fraud and financial crime | Supported, alongside your existing controls. The callback rule stops more fraud than any detector. |
| Hiring | Permitted with disclosure to the candidate and a human review of any negative signal. Automated rejection on a verdict alone is not acceptable use. |
| Surveillance of employees or family | Not an acceptable use of this service. |
| Building a case against someone privately | Understand that a verdict is not proof and cannot become proof by being repeated. |
India’s DPDP Act, which is the regime we sit under
Truthring is operated by Lacewing Technologies, a sole proprietorship in Navi Mumbai, Maharashtra. Most trust pages in this category are written as though the GDPR were the only law in the world; ours is not, and pretending otherwise would misdescribe where your data actually goes and which authority hears a complaint about it.
The Digital Personal Data Protection Act 2023 governs digital personal data processed in India, and reaches processing carried out abroad where it relates to offering goods or services to people in India. Its structure differs from the European one in ways worth knowing before you assume familiar answers apply.
- Consent is central, and legitimate interest is not a general basis. The Act works from consent plus a defined set of legitimate uses. The catch-all balancing test that European processors lean on does not have a direct equivalent, so a processing activity that is comfortable under the GDPR may need a different justification here.
- A notice must accompany the request for consent, in plain language, saying what is collected and why, and consent must be as easy to withdraw as it was to give.
- Children’s data is treated strictly, with verifiable parental consent required below eighteen and tracking and behavioural advertising directed at children prohibited. A voice recording of a minor is an obvious live issue for a detection service and one we have not finished thinking through.
- Breach notification runs to the Data Protection Board and to affected people, without the materiality threshold some regimes apply.
- Cross-border transfer is permitted except to countries the government restricts, which is close to the inverse of the European default.
How Truthring maps onto that framework in practice — whether we will meet the thresholds for a Significant Data Fiduciary, who is named as our grievance officer, how consent is captured for an anonymous check, and how the DPDP position sits alongside GDPR obligations where a European customer is involved — is [VERIFY: DPDP compliance assessment not completed; no lawyer has reviewed this mapping] The privacy policy is also still a draft pending legal review, and we have left it visibly marked as one rather than publishing something that reads finished.
GDPR and UK GDPR, where they reach us
If you are established in the EEA or the UK, or you are processing the data of people who are, your obligations travel with the recording and do not stop at our border. In most arrangements you would be the controller deciding to analyse a voice, and Truthring would be a processor acting on your instruction. That allocation determines who writes the notice, who answers a subject access request, and who carries the assessment obligation for a technology that makes inferences about people.
Two points deserve emphasis rather than a footnote. Voice data used to identify a specific individual can constitute biometric data in a special category, which raises the bar for the basis you need. And Article 22 restricts decisions producing legal or similarly significant effects taken solely by automated processing, which is precisely the shape of a fraud rejection or a disciplinary outcome driven by a detection score. Whether a transfer mechanism is in place for data reaching India, and which standard clauses we would rely on, is [VERIFY: transfer mechanism not selected; no DPA drafted]
What we can provide, and what we cannot
- No certification, of any kind. There is no SOC 2 Type I or Type II report, no ISO 27001 or ISO 27701 certificate, no independent penetration test and no third-party audit anywhere in Lacewing Technologies or its products. A buyer whose process requires one should stop reading here, because we cannot satisfy it and will not imply that we can.
- A data processing agreement is intended, not drafted. [VERIFY: DPA template not written or reviewed] Requests to the address below get an honest status rather than a document that does not exist.
- A sub-processor list will exist before launch. It is empty today because no processing happens. See security for the commitment about naming every one of them.
- Data residency options are undecided. [VERIFY: hosting region not selected; no residency choice offered]
- A written report naming the engine version, the thresholds applied and the stated error rate for the audio condition. This one is real and is the point of the product. A specimen is published at reports so a reviewer can see the format before committing to anything.
Requests: compliance@aivoicedetctor.com
Common compliance questions
Does Truthring hold SOC 2, ISO 27001 or any certification?
No. Neither Truthring nor Lacewing Technologies holds any security or privacy certification, and no third party has audited the product. If your supplier approval process requires an attestation report, we cannot meet it and we would rather you knew that at the start.
Which data protection law applies to Truthring?
Lacewing Technologies is a sole proprietorship based in Navi Mumbai, Maharashtra, so India's Digital Personal Data Protection Act 2023 is the regime it primarily operates under, alongside the Information Technology Act. Where a customer or a data subject is in the EEA or the UK, GDPR obligations can apply to that processing as well. Which regimes we formally accept obligations under is still being settled.
Can I rely on a Truthring result to dismiss or accuse someone?
No. A verdict is a probability with a stated error rate, not a finding of fact. It should inform a human judgement and never be the sole basis for an adverse decision about a person. Several data protection regimes restrict decisions with significant effects taken by automated means alone, and a person on the wrong side of a false positive has no way to prove a negative.
Will you sign a data processing agreement?
We intend to offer one. The template has not been drafted or reviewed by a lawyer, and there is no signed agreement in existence today because there are no customers. Write to the compliance address and we will tell you honestly where the document stands.
Is anything on this page legal advice?
No. It describes the obligations that commonly arise when a voice recording is analysed, so that you know which questions to ask. We are not your lawyers, we do not know your jurisdiction or your facts, and nothing here should be relied on in place of advice from somebody who does.
Nothing on this page is legal advice. It describes obligations that commonly arise so that you know which questions to put to somebody who knows your jurisdiction and your facts. Lacewing Technologies is governed by Indian law, with jurisdiction in Maharashtra, as set out in the terms.
Limits of a result
For specific teams
Reviewed