Privacy Policy
This Privacy Policy describes how Octa Voice ("we," "us," or "our") collects, uses, stores, and protects information when you use our platform at octavoice.ai and all related services (the "Service"). By using the Service, you consent to the practices described in this policy.
1. Information We Collect
Account Information
When you register for the Service, we collect your business name, email address, username, and password. If you subscribe to a paid plan, we collect billing information through our payment processor, Stripe (we do not store credit card numbers directly).
Voice Recordings
If you enable call recording, we record and store audio from voice calls processed through the Service. Recordings contain the voices of both your AI agent and the caller. You are responsible for obtaining proper consent for recordings (see our Terms of Service).
Conversation Data
We store the content of all conversations processed through the Service, including voice call transcripts, web chat messages, SMS messages, and WhatsApp messages. This data is associated with your tenant account and is used to provide the Service.
Knowledge Base and Configuration
We store the content you provide to configure your AI agent, including system prompts, knowledge base articles, FAQs, service catalogs, staff directories, and business policies.
Usage Analytics
We collect usage data including call duration, message counts, channel usage, booking counts, transfer counts, sentiment scores, and API call volumes. This data is used for analytics, billing, and service improvement.
Technical Data
We automatically collect technical information when you access the Service, including IP addresses, browser type, device information, and access timestamps. For the chat widget, we collect the visitor's IP address for rate limiting purposes.
Cookies
We use session cookies to maintain your authenticated state when logged into the dashboard. We do not use third-party tracking cookies or advertising cookies. See Section 10 for our full cookie policy.
2. How We Use Your Data
- Service delivery: Processing conversations, generating AI responses, managing appointments, delivering recordings and analytics
- Billing: Calculating usage-based charges, processing payments through Stripe, generating invoices
- Service improvement: Monitoring system performance, identifying and fixing bugs, improving reliability
- Security: Detecting and preventing abuse, fraud, and unauthorized access
- Communication: Sending service-related notifications, billing alerts, and security notices
Important: We do NOT use your conversation data, recordings, knowledge base content, or any customer data to train AI models. Your data is processed solely to provide the Service to you. Third-party AI providers used by the Service (see Section 4) also do not use your data for training under our agreements with them.
3. Data Storage and Security
Your data is stored on infrastructure hosted by Amazon Web Services (AWS). We implement the following security measures:
- Encryption in transit: All data transmitted between your browser/devices and our servers is encrypted using TLS 1.2+
- Encryption at rest: Voice recordings stored in Amazon S3 are encrypted using server-side encryption (SSE-S3). Database data is encrypted at rest
- Access controls: Production systems use least-privilege access, non-root service accounts, and hardened systemd configurations
- Network security: Firewall rules restrict access to necessary ports only. Services bind to localhost behind a reverse proxy
- Backups: Database backups are performed daily with encryption and 7-day retention
4. Third-Party Services
The Service integrates with the following third-party providers to deliver its functionality. Each provider processes data only as necessary to perform their specific function:
- Anthropic (Claude) — Large language model provider. Processes conversation text to generate AI responses. Anthropic does not use API inputs/outputs for model training under our usage terms
- Deepgram — Speech-to-text provider. Processes voice audio to generate transcripts in real time
- Cartesia — Text-to-speech provider. Converts AI-generated text responses into spoken audio
- ElevenLabs — Alternative text-to-speech provider. Same function as Cartesia
- Twilio — SMS and WhatsApp messaging provider. Processes and delivers text messages
- Stripe — Payment processor. Handles billing, subscriptions, and payment card data. We do not store your credit card numbers — Stripe handles this as a PCI-DSS Level 1 certified provider
- Amazon Web Services (AWS) — Infrastructure provider. Hosts our servers, databases, file storage (S3), and email delivery (SES)
We require all third-party providers to maintain appropriate security measures and to process data only in accordance with our instructions.
5. Data Retention
- Voice recordings: Retained according to your plan settings. Default retention periods vary by plan. You may delete recordings at any time through the dashboard
- Conversation logs: Chat, SMS, and WhatsApp conversation logs are retained for 90 days from the date of the conversation, then automatically purged
- Call logs: Call metadata (duration, timestamps, sentiment) is retained for 90 days. Call logs older than 30 days are cleaned up periodically
- Account data: Your account information, knowledge base, and configuration are retained until you delete your account or request deletion
- Billing records: Financial records are retained for 7 years as required by tax and accounting regulations
- Usage analytics: Aggregated, anonymized usage statistics may be retained indefinitely for service improvement
Upon account termination, we retain your data for 30 days to allow for data export, after which it is permanently deleted.
6. HIPAA Compliance
For healthcare organizations on our Business plan and above, we offer HIPAA-compliant data handling:
- Business Associate Agreement (BAA) available upon request
- Protected Health Information (PHI) is handled in accordance with HIPAA Security Rule and Privacy Rule requirements
- Epic FHIR integration for healthcare-specific workflows (patient verification, appointment scheduling)
- Audit logging for PHI access and modifications
- Data anonymization capabilities for compliance with data retention policies
HIPAA compliance features are bundled into the Business plan and above, including a signed BAA. Contact legal@octavoice.ai to request your BAA.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access: You may request a copy of the personal data we hold about you
- Right to rectification: You may request correction of inaccurate or incomplete personal data
- Right to erasure: You may request deletion of your personal data, subject to legal retention obligations
- Right to data portability: You may request your data in a structured, commonly used, machine-readable format
- Right to object: You may object to processing of your personal data for certain purposes
- Right to restrict processing: You may request that we limit how we use your personal data
To exercise any of these rights, contact us at privacy@octavoice.ai. We will respond to your request within 30 days.
Our legal basis for processing personal data is: (a) performance of our contract with you (providing the Service), (b) our legitimate interests (security, service improvement), and (c) your consent (where applicable).
8. Your Rights Under CCPA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to delete: You may request deletion of your personal information, subject to certain exceptions
- Right to opt-out: You may opt out of the "sale" of your personal information. Note: we do not sell personal information to third parties
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact us at privacy@octavoice.ai or call us. We will verify your identity before processing your request.
9. Children's Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@octavoice.ai.
10. Cookie Policy
We use a minimal set of cookies:
- Session cookies: Used to maintain your authenticated session when logged into the tenant portal, admin dashboard, or agent dashboard. These cookies are essential for the Service to function and expire when you close your browser or log out
- Chat widget cookies: The embeddable chat widget uses session storage (not cookies) to maintain conversation state during a browsing session
We do not use:
- Third-party tracking cookies
- Advertising or retargeting cookies
- Cross-site tracking technologies
Because we only use strictly necessary cookies, no cookie consent banner is required under most jurisdictions. However, we disclose our cookie usage here for transparency.
11. Data Breach Notification
In the event of a data breach that affects your personal data, we will:
- Notify affected account holders by email within 72 hours of becoming aware of the breach
- Provide details about the nature of the breach, the data affected, and the steps we are taking to address it
- Notify relevant supervisory authorities as required by applicable law (including GDPR Article 33)
- For HIPAA-covered accounts, follow breach notification procedures as required by the HIPAA Breach Notification Rule
12. International Data Transfers
Our servers are located in the United States and European Union (AWS regions). If you are located outside these regions, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses (SCCs) where required by GDPR.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this policy indicates the most recent revision.
14. Contact Us
For questions, concerns, or requests related to this Privacy Policy or your personal data, contact us at:
Privacy inquiries: privacy@octavoice.ai
Legal inquiries: legal@octavoice.ai
Website: https://octavoice.ai