Privacy Policy
This Privacy Policy describes how Octa Voice ("we," "us," or "our") collects, uses, stores, and protects information when you use our platform at octavoice.ai and all related services (the "Service"). By using the Service, you consent to the practices described in this policy.
1. Information We Collect
Account Information
When you register, we collect your business name, email address, username, and password. If you subscribe to a paid plan, we collect billing information through Stripe (we do not store credit card numbers directly).
Voice Recordings
If you enable call recording, we record and store audio from voice calls processed through the Service. Recordings contain the voices of both your AI agent and the caller. You are responsible for obtaining proper consent for recordings (see our Terms of Service).
Conversation Data
We store the content of all conversations processed through the Service, including voice call transcripts, web chat messages, SMS messages, and WhatsApp messages. This data is associated with your tenant account and is used to provide the Service.
Knowledge Base and Configuration
We store the content you provide to configure your AI agent, including system prompts, knowledge base articles, FAQs, service catalogs, staff directories, and business policies.
Usage Analytics
We collect usage data including call duration, message counts, channel usage, booking counts, transfer counts, sentiment scores, and API call volumes. Used for analytics, billing, and service improvement.
Technical Data
We automatically collect technical information when you access the Service, including IP addresses, browser type, device information, and access timestamps. For the chat widget, we collect the visitor's IP address for rate limiting purposes.
Cookies
We use session cookies to maintain your authenticated state when logged into the dashboard. We do not use third-party tracking cookies or advertising cookies. See Section 10 for our full cookie policy.
2. How We Use Your Data
- Service delivery: processing conversations, generating AI responses, managing appointments, delivering recordings and analytics.
- Billing: calculating usage-based charges, processing payments through Stripe, generating invoices.
- Service improvement: monitoring system performance, identifying and fixing bugs, improving reliability.
- Security: detecting and preventing abuse, fraud, and unauthorized access.
- Communication: sending service-related notifications, billing alerts, and security notices.
We do NOT use your conversation data, recordings, knowledge base content, or any customer data to train AI models. Your data is processed solely to provide the Service to you. Third-party AI providers used by the Service (see Section 4) also do not use your data for training under our agreements with them.
3. Data Storage and Security
Your data is stored on infrastructure hosted by Amazon Web Services (AWS). We implement the following security measures:
- Encryption in transit: TLS 1.2+ for all data between your devices and our servers.
- Encryption at rest: S3 recordings use SSE-S3. Database data is encrypted at rest.
- Access controls: least-privilege access, non-root service accounts, hardened systemd configurations.
- Network security: firewall rules restrict to necessary ports. Services bind to localhost behind a reverse proxy.
- Backups: daily database backups with encryption and 7-day retention.
4. Third-Party Services
The Service integrates with the following third-party providers to deliver its functionality. Each provider processes data only as necessary to perform their specific function.
- Anthropic (Claude) — LLM. Processes conversation text to generate AI responses. Does not use API inputs/outputs for model training under our usage terms.
- Deepgram — speech-to-text. Processes voice audio to generate transcripts in real time.
- Cartesia — text-to-speech. Converts AI-generated text into spoken audio.
- ElevenLabs — alternative TTS provider.
- Twilio — SMS and WhatsApp messaging.
- Stripe — payment processor. PCI-DSS Level 1 certified. We do not store credit card numbers.
- Amazon Web Services (AWS) — infrastructure. Hosts servers, databases, file storage (S3), and email delivery (SES).
We require all third-party providers to maintain appropriate security measures and process data only in accordance with our instructions.
5. Data Retention
- Voice recordings: retained per your plan settings. You may delete recordings at any time through the dashboard.
- Conversation logs: 90 days, then automatically purged.
- Call logs: metadata retained 90 days; older logs cleaned periodically.
- Account data: retained until you delete your account or request deletion.
- Billing records: 7 years, per tax and accounting regulations.
- Usage analytics: aggregated, anonymized statistics may be retained indefinitely.
Upon account termination, we retain your data for 30 days to allow for data export, after which it is permanently deleted.
6. HIPAA Compliance
For healthcare organizations on our Business plan and above, we offer HIPAA-compliant data handling:
- Business Associate Agreement (BAA) available upon request.
- Protected Health Information (PHI) handled in accordance with HIPAA Security & Privacy Rules.
- Epic FHIR integration for healthcare-specific workflows (patient verification, appointment scheduling).
- Audit logging for PHI access and modifications.
- Data anonymization capabilities.
HIPAA compliance is bundled into the Business plan and above, including a signed BAA. Contact legal@octavoice.ai to request your BAA.
7. Your Rights Under GDPR
If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights under GDPR:
- Right of access.
- Right to rectification of inaccurate or incomplete personal data.
- Right to erasure, subject to legal retention obligations.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object to certain processing.
- Right to restrict processing.
To exercise these rights, contact privacy@octavoice.ai. We will respond within 30 days.
8. Your Rights Under CCPA
California residents have the following rights:
- Right to know what personal information we collect.
- Right to delete, subject to certain exceptions.
- Right to opt-out of the "sale" of personal information. We do not sell personal information.
- Right to non-discrimination for exercising your CCPA rights.
To exercise your CCPA rights, contact privacy@octavoice.ai. We will verify your identity before processing your request.
9. Children's Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13.
10. Cookie Policy
We use a minimal set of cookies:
- Session cookies for authenticated sessions in the tenant portal, admin dashboard, or agent dashboard. Essential; expire when you close your browser or log out.
- Chat widget uses session storage (not cookies) for conversation state.
We do not use third-party tracking cookies, advertising cookies, or cross-site tracking technologies.
11. Data Breach Notification
- Notify affected account holders by email within 72 hours of becoming aware of a breach.
- Provide details about the breach, the data affected, and our mitigation steps.
- Notify supervisory authorities as required by law (GDPR Article 33).
- For HIPAA-covered accounts, follow HIPAA Breach Notification Rule.
12. International Data Transfers
Our servers are located in the United States and European Union (AWS regions). If you are located outside these regions, your data may be transferred to and processed in the United States. We ensure appropriate safeguards including Standard Contractual Clauses (SCCs) where required by GDPR.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or on-site notice at least 30 days before taking effect.
14. Contact Us
Privacy inquiries: privacy@octavoice.ai
Legal inquiries: legal@octavoice.ai