AI Voice Agentby Hisenbug
Back to HomeSign In
Compliance Docs:Privacy PolicyTerms of ServiceData Processing AddendumSubprocessors

Privacy Policy

PRE-RELEASE DRAFT FOR LEGAL REVIEW
This document sets forth the privacy policy and data practices for the Hisenbug voice platform prepared for the commercial pilot release. Subject to qualified legal counsel review.

Effective Date: [To be confirmed upon publication]
Last Updated: September 15, 2026
Operator: [Hisenbug Legal Entity — to be confirmed] ("Hisenbug", "we", "us", or "our")
Privacy Contact: hello@hisenbug.com


1. Introduction & Scope

This Privacy Policy explains how Hisenbug collects, uses, discloses, and protects personal information when you access our website at voice.hisenbug.com, utilize our customer portal, test our interactive demonstration environments, or interact with our artificial intelligence voice agent platform (collectively, the "Services").

Hisenbug provides a specialized business-to-business (B2B) Software-as-a-Service (SaaS) platform designed for licensed real estate brokers, agents, and property management brokerages ("Customers" or "Brokers").

Important Distinction: Data Controller vs. Data Processor

Under applicable data protection regulations (including the European Union General Data Protection Regulation (EU GDPR), the United Kingdom Data Protection Act 2018 (UK GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA)):

  1. Hisenbug as a Data Controller:
    We act as a Data Controller (or "Business") with respect to personal information relating to our direct Customers, portal account holders, website visitors, and sales prospects (such as account registration details, portal authentication credentials, web server telemetry, and direct inquiries sent to hello@hisenbug.com).
  2. Hisenbug as a Data Processor / Service Provider:
    We act as a Data Processor (or "Service Provider") when processing telephone calls, audio streams, voice recordings, conversation transcripts, and customer relationship management (CRM) lead data on behalf of our Customers. In this context, the Customer/Brokerage is the Data Controller who determines the commercial purpose and lawful basis for communicating with callers. We process such caller personal data solely pursuant to our Customer agreements and documented customer instructions.

2. Information We Collect

A. Information Collected from Account Holders & Customers

When you register for, configure, or administer a Hisenbug account, we collect:

  • Account Identity & Contact Details: Full name, professional email address, brokerage company name, business telephone number, and administrative timezone.
  • Authentication Information: Authentication identity and session tokens managed securely through Supabase Auth. Hisenbug application systems do not directly manage or store raw password hashes.
  • Real Estate Inventory & Configuration: Property listings, addresses, asking prices, bedroom/bathroom counts, square footage, property descriptions, business hours, and conversational prompt guidelines.
  • Third-Party Integration Credentials: Where you choose to connect third-party integrations such as Slack, we collect OAuth authorization tokens and target channel identifiers. Stored Slack OAuth access tokens are encrypted using AES-256-GCM before persistence.

B. Information Processed on Behalf of Customers (Caller Data)

When inbound callers dial a telephone number routed through the Customer's Hisenbug voice agent, we process the following data on the Customer's behalf:

  • Voice Audio & Vocal Utterances: Raw digital audio streams of spoken telephone conversations.
  • Telephony Identifiers: Inbound caller telephone number (ANI/caller ID), dialed telephone number (DNIS), call start and end timestamps, call duration, and carrier termination status.
  • Conversation Transcripts: Verbatim text records generated from caller dialogue and synthetic agent responses.
  • Extracted Lead & Property Interest Data: Information voluntarily provided by the caller during dialogue turns, including caller name, contact details, budget parameters, preferred property locations, financing status, and consultation/showing scheduling requests.
  • Post-Call Quality & Compliance Data: Automated scorecard evaluations, dialogue quality metrics (qa_score), price-rule compliance flags, and short excerpted dialogue quotes used to verify agent adherence.

C. Information Collected Automatically via Web Infrastructure

When you browse voice.hisenbug.com or navigate the portal:

  • Technical Observability Data: Client IP address, browser user-agent, operating system, referring URL, request timestamps, and HTTP response codes collected via Vercel edge infrastructure and reverse-proxy access logs.
  • Essential Cookies & Session Identifiers: Strictly necessary authentication cookies (sb-..., sbx_session) required to maintain secure portal login states, enforce rate limits, and mitigate distributed denial-of-service (DDoS) threats. We do not use third-party behavioral tracking or advertising cookies.

D. Information Processed in Public Demo Environments

When visitors test our interactive browser voice demonstration at voice.hisenbug.com/demo:

  • We process temporary demo access tokens, browser WebRTC media streams, and demonstration dialogue turns in real time.
  • The public demo flow does not require or collect telephone number submissions.

3. How We Use Information (Purposes of Processing)

We process personal information for the following specific commercial purposes:

  1. Service Delivery & Voice Agent Operation: To connect incoming telephone calls, perform real-time speech-to-text transcription, execute conversational dialogue reasoning, synthesize natural spoken voice responses, and route qualified appointments to Customer schedules.
  2. CRM Lead Management & Notification: To structure dialogue into actionable lead profiles, maintain Customer property pipelines, and dispatch real-time lead notification cards to Customer-connected Slack channels.
  3. Quality Assurance & Platform Hardening: To evaluate conversational rubric adherence, detect pricing rule deviations, identify conversational errors, and maintain platform reliability.
  4. Security & System Observability: To authenticate authorized users, enforce tenant data segregation, prevent fraudulent robocalling or abuse, and maintain server infrastructure.
  5. Commercial Administration: To communicate administrative platform notices, technical maintenance alerts, and security advisories to Customer account administrators.

Artificial Intelligence & Model Training Commitments

  • Zero Customer Model Training: Hisenbug does not intentionally use Customer call audio, conversation transcripts, or CRM lead records to train, retrain, or fine-tune its own artificial intelligence or machine learning models.
  • Downstream AI Providers: Real-time conversational inference is executed using commercial API services (Vapi, OpenAI, Deepgram, ElevenLabs, and Groq). Upstream data-use and retention policies are governed by respective enterprise service agreements.

4. Call Recording & Wiretap Disclosures

Customer Responsibility for Recording & Wiretap Compliance

Hisenbug provides technical controls enabling Customers to configure their call compliance settings:

  • Recording Activation: Call audio recording can be toggled ON or OFF within Customer portal settings.
  • Recording Disclosures: Automated spoken recording disclosures ("This call is recorded for quality and scheduling purposes") can be toggled ON or OFF.
  • AI Identity Disclosures: Automated AI identification ("You are speaking with an artificial intelligence assistant") can be toggled ON or OFF.
  • Custom Greeting Text: Customers may provide customized opening greetings, subject to automated platform anti-deception guardrails that prevent configuring text claiming a call is unrecorded when recording functionality is enabled.

CRITICAL LEGAL NOTICE:
Federal, state, and international telecommunications and wiretapping laws (including the United States Electronic Communications Privacy Act, state two-party/all-party consent statutes such as California Penal Code § 632, Florida Stat. § 934.03, and international surveillance statutes) impose strict disclosure and caller consent requirements. The Customer is solely responsible for verifying the legal requirements of its operating jurisdictions, enabling appropriate spoken disclosures, and obtaining all necessary caller consents.


5. Subprocessors & Third-Party Service Providers

To deliver our voice platform, Hisenbug engages select third-party service providers ("Subprocessors"). All Subprocessors are subject to contractual data protection agreements and security commitments.

A current list of our direct production infrastructure and indirect voice providers is maintained at our Subprocessor Disclosure.

Summary of Core Providers:

  • Voice & Telephony Orchestration: Vapi (Direct Subprocessor for telephony gateway, call state, and audio streaming).
  • Downstream Voice Technologies (Engaged via Vapi): Deepgram (Speech-to-Text); OpenAI (Conversational LLM reasoning); ElevenLabs (Text-to-Speech synthesis); and Vapi downstream telecommunications, carrier, and media infrastructure providers. Specific downstream providers and processing locations may depend on Vapi's applicable service architecture, routing, and contractual documentation.
  • Database & Authentication Infrastructure: Supabase (PostgreSQL database and authentication services). The production database project is configured in the United States (AWS us-east-1); additional processing or infrastructure locations may be governed by Supabase's applicable service architecture and contractual documentation.
  • Tool Server & Compute Infrastructure: Oracle Cloud Infrastructure (OCI Virtual Private Server located in the Jeddah, Saudi Arabia cloud region).
  • Web Hosting & Edge Routing: Vercel (Global CDN and portal edge runtime).
  • Post-Call Inference & Extraction: Groq (High-speed LPU inference for post-call lead extraction and QA scoring).
  • Property Search Embeddings: Jina AI / Elastic (Plain-text listing vector search; zero caller PII transmitted).

6. International Data Transfers

Hisenbug operates across distributed international cloud infrastructure:

  • Customer portal services are distributed globally via Vercel edge infrastructure.
  • Backend tool execution and workflow containers are hosted on Oracle Cloud Infrastructure in Jeddah, Saudi Arabia.
  • The production database project is configured in the United States (AWS us-east-1); additional processing or infrastructure locations may be governed by Supabase's applicable service architecture and contractual documentation.
  • Real-time voice processing and AI inference providers process data primarily on infrastructure located in the United States.

Where personal data originating in the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred to countries not recognized as providing an adequate level of data protection, Hisenbug and its Customers implement appropriate safeguards, including standard contractual clauses (SCCs) approved by the European Commission or the UK International Data Transfer Addendum.


7. Data Retention & Erasure Lifecycles

Hisenbug enforces automated data lifecycle policies designed to minimize the retention of personal information:

┌───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│                                         AUTOMATED DATA RETENTION LIFECYCLE                                        │
├──────────────────────────┬──────────────────┬─────────────────────────────┬───────────────────────────────────────┤
│ DATA CATEGORY            │ RETENTION TARGET │ ENFORCEMENT TYPE            │ TECHNICAL ACTION                      │
├──────────────────────────┼──────────────────┼─────────────────────────────┼───────────────────────────────────────┤
│ Call Audio Recordings    │ 60 Days          │ Automated Scheduled Service │ Upstream Vapi delete + database wipe  │
│ Conversation Transcripts │ 120 Days         │ Automated Scheduled Service │ Transcripts & dialogue quotes nullified│
│ Operational Caller Identifiers│ 12 Months   │ Automated Scheduled Service │ Caller number & lead links set to NULL│
│ Operational Call Ledger  │ 36 Months        │ Operational Need            │ Anonymized metrics retained for audit │
│ Active CRM Lead Records  │ Customer Managed │ On-Demand API               │ Asynchronous customer erasure workflow│
│ n8n Workflow Logs        │ 72 Hours         │ Container Prune             │ Automatic container execution purge   │
│ Customer Slack Alerts    │ Customer Managed │ External Tenant             │ Governed by customer Slack policies   │
└──────────────────────────┴──────────────────┴─────────────────────────────┴───────────────────────────────────────┘

Details of Retention Commitments:

  1. 60-Day Recording Purge: Call audio recording files are scheduled for programmatic deletion from upstream telephony storage 60 days following call completion, and playback URLs are nullified in the database.
  2. 120-Day Transcript Scrub: Verbatim call transcripts and excerpted dialogue quotes within QA scorecards are programmatically expunged from database records 120 days after call completion. Aggregate numeric metrics (qa_score) are preserved for business analytics.
  3. 12-Month Caller Number Anonymization: Operational caller identifiers stored in the telephony ledger are anonymized after 12 months. Specifically, direct caller phone numbers (calls.caller_number) and relational links to CRM leads (calls.lead_id) are permanently removed from telephony call records 12 months after call completion. In contrast, Customer CRM records are retained according to customer configuration, customer deletion instructions, the Agreement, and applicable law, subject to the stated service lifecycle and legal/operational retention requirements.
  4. 36-Month Operational Telephony Ledger: Anonymized operational metadata (call start/end timestamps, duration, disposition, termination reason, and carrier cost metrics) are retained for up to 36 months to defend carrier billing disputes, resolve telecommunications reconciliation, and verify platform operational metrics. After 36 months, records are deleted or further aggregated.
  5. Customer Lead Deletion (Asynchronous Erasure): Customers may delete individual CRM lead records at any time via portal controls. Deletion initiates an asynchronous workflow that evicts the lead immediately from active CRM views, requests deletion of associated call audio from upstream voice infrastructure, scrubs relational transcripts, and permanently removes the lead record from the database.
  6. Customer Slack Channel Messages: Slack is a customer-configured external notification destination. The legal classification of that destination may depend on applicable data protection law and the customer's configuration. Lead notification cards dispatched to a Customer's Slack channel reside within the Customer's own Slack workspace. Hisenbug does not possess technical capabilities to remotely delete messages previously delivered into a Customer's private Slack environment.
  7. Database Backups Disclosure: The production database operates on the Supabase Free plan. Hisenbug does not maintain customer-accessible automated database backups or point-in-time recovery on this plan. Data deletion from active production storage is not supplemented by a Hisenbug-managed customer backup system.

8. Technical & Organizational Security Measures

We implement industry-standard technical and administrative safeguards designed to protect personal data against unauthorized access, destruction, alteration, or disclosure:

  • Encryption in Transit: HTTPS/TLS is used to encrypt applicable web and API communications in transit.
  • Credential Encryption at Rest: Stored Slack OAuth access tokens are encrypted using AES-256-GCM before persistence.
  • Access Control & Tenant Isolation: Supabase Auth, application-level authorization, tenant-scoped queries, and database-level access controls are used to enforce tenant isolation.
  • Isolated Background Compute: Workflow automation containers (n8n) are strictly bound to internal loopback interfaces (127.0.0.1) and are not accessible from the public internet.
  • Least Privilege Execution: Backend server processes run under non-root service accounts managed by systemd.

Security Disclaimers:
Hisenbug as an organization has not undergone independent SOC 2, ISO 27001, or HIPAA certification audits. We do not process Protected Health Information (PHI) and do not store payment cardholder data. We do not warrant universal encryption at rest across all third-party vendor physical drives.


9. Your Data Protection Rights

Depending on your geographic location and applicable data protection laws (such as GDPR, UK GDPR, or CCPA/CPRA), you may hold specific statutory rights regarding your personal information:

  • Right of Access: You may request confirmation of whether we process your personal information and obtain a copy of your personal data.
  • Right to Rectification: You may request correction of inaccurate or incomplete personal information.
  • Right to Erasure ("Right to be Forgotten"): You may request the deletion of your personal data, subject to statutory retention requirements.
  • Right to Restrict or Object to Processing: You may object to or request restrictions on certain types of processing under specific legal grounds.
  • Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
  • Non-Discrimination: We will never discriminate against you for exercising your lawful data protection rights.

How to Exercise Your Rights

  • If you are an Account Holder / Customer: Contact us directly at hello@hisenbug.com.
  • If you are an Inbound Caller: Hisenbug processes your information as a Data Processor on behalf of the Customer/Broker whose number you dialed. To exercise your rights, please submit your request directly to the relevant Brokerage (the Data Controller). Where appropriate, Hisenbug will provide technical assistance to Customers to fulfill verified consumer requests.

10. Children's Privacy

Hisenbug Services are strictly intended for commercial business use by adult real estate professionals and prospective real estate clients. We do not knowingly solicit, collect, or maintain personal data from individuals under eighteen (18) years of age. If you believe a minor has provided us with personal information, please contact us immediately at hello@hisenbug.com.


11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our technology, operational practices, or statutory legal requirements. When updates are published, we will revise the "Last Updated" date at the top of this document. For material modifications, we will notify Customer account administrators via email or an authenticated portal notification.


12. Contact Information

If you have questions, comments, or data protection inquiries regarding this Privacy Policy, please contact our privacy operations team at:

Privacy Operations
[Hisenbug Legal Entity — to be confirmed]
Email: hello@hisenbug.com
Web: https://voice.hisenbug.com

© 2026 Hisenbug (hisenbug.com). All rights reserved.

Privacy Policy•Terms of Service•DPA•Subprocessors•hello@hisenbug.com