# Cantomore voice data privacy notice

Version 1.0 — 2026-09-04. This is the repository policy baseline. The live
service must publish the controller's working contact channel and implement the
same controls before accepting uploads.

## Data collected

Depending on the service, Cantomore may process account/contact details,
payment/order details, source voice recordings, prompted verification audio,
speaker consent and authority records, derived speaker embeddings/profiles,
converted voice banks, generated WASM packages, quality results, device and
security logs, and support communications.

Voice recordings and derived profiles may identify a person and are treated as
sensitive personal voice data even when the public manifest uses only an opaque
voice ID.

## Purposes

Data is used only to verify authority, provide and support the requested voice,
preserve Cantonese tone and quality, prevent abuse, secure the service, process
the transaction, handle deletion/access requests and meet legal obligations.
It is not used to train a general model, create another customer's voice, or
enter a public catalogue without separate affirmative consent.

## Private/public separation

- A personal upload is private by default.
- Public/community/premium catalogue consent is separate from service consent
  and must not be preselected or made a condition of an ordinary personal order.
- Public manifests contain no source audio, legal name, signature, raw biometric
  template or direct link to the restricted consent record.
- Personal source files and packages must use access-controlled storage, never
  the public `cdn.cantomore.com` bucket.

## Notice before collection

Before the live service records or accepts a file, it must clearly identify
Nova Cultural Limited as the data user/controller and provide a working contact
name or role and postal or electronic address for access and correction
requests. The collection screen must also state:

- whether each requested item is voluntary or required and the consequence of
  not supplying a required item;
- the specific service, authority-check, security and support purposes;
- the classes of processors or other recipients, such as hosting, payment and
  approved voice-conversion providers;
- the applicable retention deadlines and deletion choices; and
- how the speaker can request access, correction or deletion.

The production owner must document a privacy-impact review before launch and
again before adding a processor, a new use such as model improvement, or a
materially different retention period.

## Retention baseline

Unless a contract or legal requirement states otherwise: abandoned/rejected
uploads are deleted within 7 days; source recordings within 30 days after
delivery or cancellation; speaker profiles and downloadable personal packages
within 90 days after delivery. Rights, consent, payment and security records are
kept only as long as reasonably necessary to prove authority, resolve disputes
and meet legal obligations. Protected backups expire on their normal cycle and
must not be restored for ordinary product use after a deletion request.

## Access, processors and security

Access is limited to personnel and processors who need it for the stated
purpose. Any cloud, payment or model processor must be recorded, contractually
restricted and assessed before production use. Encryption in transit and at
rest, least-privilege access, audit logs, secret separation and a documented
incident response are required.

The speaker or authorised customer may use the contact channel published at
`speech.cantomore.com` to request access, correction, deletion or withdrawal of
an optional catalogue consent. Identity and authority may need to be verified.
Deletion cannot undo speech already lawfully generated or licences already
granted where the contributor agreement expressly preserves them.

## Upload-screen notice

Before recording starts, show an unticked confirmation substantially equivalent
to:

> 我確認這是本人聲音，或我已取得說話者及錄音權利人的明確授權。我明白
> Cantomore 會從錄音建立可說出原錄音沒有說過內容的合成聲音。這次上載只
> 用於我的訂單，不會自動加入公開或付費聲音庫。

A second, separately unticked consent is required for any catalogue or general
model-improvement use.
