HyperDial Technologies, a company incorporated in India ("HyperDial", "we", "us" or "our"), provides a cloud communications platform for business calling, messaging and conversation intelligence. We respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains what personal data we collect, how we use and share it, where it is stored, how long we keep it, and the rights and choices available to you. It should be read together with our Terms of Service and our Data Processing Agreement. By accessing our website or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use our Services.
1.Definitions
In this Privacy Policy:
- “Services”
- means the HyperDial cloud communications platform at hyperdial.io and its related applications, dashboard, dialers, APIs, phone numbers, AI features, integrations and support.
- “Customer”
- means a business or organisation that has an account with HyperDial and has agreed to our Terms of Service.
- “User”
- means an individual authorised by a Customer to use the Services, such as an employee or contractor who is assigned a seat.
- “End User”
- means any person who calls, is called by, or exchanges messages with a Customer through the Services.
- “Customer Content”
- means call recordings, transcripts, messages, contact lists, call logs and other content that Customers and Users submit to, or generate through, the Services.
- “Usage Data”
- means technical and statistical information about how the Services are used and perform, in a form that does not identify any Customer or individual.
- “Personal Data”
- means any information that identifies, or can reasonably be linked to, an individual.
- “Controller”
- means the party that decides why and how Personal Data is processed; "Processor" means a party that processes Personal Data on a Controller's behalf.
- “Service Provider”
- means a third party that processes Personal Data on our behalf under a written contract.
2.Scope of this Privacy Policy
2.1 This Privacy Policy applies to Personal Data we process about:
- Customers and Users who sign up for or use the Services;
- visitors to our website and people who use our website chat;
- prospects who request a demo, quote or phone number, or who receive our marketing; and
- End Users, to the extent described in Sections 3 and 22.
2.2 The Services are provided for business use only. They are not offered to consumers or for personal, household or family use.
2.3 This Privacy Policy does not apply to the privacy practices of our Customers. Customers that use HyperDial to contact End Users are responsible for their own privacy notices and for having a lawful basis to process End Users' Personal Data.
3.Our Role: Controller and Processor
3.1 HyperDial as Controller. We are the Controller of account data, billing data, website and chat data, and marketing data. This Privacy Policy describes how we process that data.
3.2 HyperDial as Processor. For Customer Content, the Customer is the Controller and HyperDial acts as a Processor (or service provider). We process Customer Content only on the Customer's documented instructions, as set out in our Terms of Service and Data Processing Agreement ("DPA"). We do not process Customer Content for our own purposes.
3.3 If you are an End User and have questions about how a Customer uses your Personal Data, please contact that Customer directly. We will assist the Customer in responding to your request.
4.Personal Data We Collect
4.1 Information you provide to us.
- Account information: name, work email address, phone number, company name, job title, team size and password (stored only as a secure hash).
- Billing information: plan, legal business name, billing address, invoices and tax identifiers such as GST or EIN. Card details are handled as described in Section 15.
- Verification (KYC) information: business registration details, tax identifiers, proof of address and identity documents (such as a passport or utility bill) that telecom regulators and carriers require before we can assign certain phone numbers.
- Communications with us: information you give us when you contact sales or support, chat with us on our website, respond to surveys or request a toll-free number.
4.2 Information we collect automatically.
- Device and log data: IP address, browser type, operating system, device identifiers, access times and error logs.
- Usage data: the pages you visit, features you use, and actions you take in the Services.
- Agent activity: a User's availability status (such as online, busy or after-call work), login and logout times and calls handled.
- Device permissions: with your permission, access to your microphone and speakers to make calls, and to notifications to alert you of incoming calls.
- Cookies and similar technologies, as described in Section 19.
4.3 Information from third parties.
- Integrations and sign-in services: if you connect a third-party tool (such as a CRM or helpdesk) or sign in using a third-party account, we receive the information you authorise, as described in Section 10.
- Telecom partners and registries: call-routing, delivery and verification results relating to your phone numbers.
4.4 Customer Content (processed on behalf of Customers).
- Call data: calling and called numbers, date, time, duration, direction, routing and cost of each call.
- Recordings and transcripts: call audio and the text produced from it, when a Customer enables these features.
- Messages: SMS and other message content and related metadata.
- Contacts and leads: names, phone numbers, email addresses and notes that Customers import or create.
4.5 Sensitive data. We do not intentionally collect sensitive personal data such as health, religious or biometric data. Government identity documents collected under Section 8 are used only for verification. Customers must not use the Services to collect or store payment card numbers, card security codes, bank passwords or government identity numbers in recordings or transcripts, except through a feature we expressly designate for that purpose. Customers must not use the Services to process protected health information under the US Health Insurance Portability and Accountability Act (HIPAA) unless they have signed a Business Associate Agreement with us, which is available on Business Plans.
5.How We Use Personal Data and Our Legal Bases
| Purpose | Categories of data | Legal basis |
|---|---|---|
| Provide, operate and maintain the Services, including routing calls and messages and storing call history and recordings | Account, usage and Customer Content | Performance of a contract; Customer instructions (as Processor) |
| Create and manage accounts and authenticate Users | Account and device data | Performance of a contract |
| Provision phone numbers and comply with telecom rules | Verification (KYC) data | Legal obligation |
| Process payments, invoice and maintain financial records | Account and billing data | Performance of a contract; legal obligation |
| Provide customer support | Account data and communications with us | Performance of a contract; legitimate interests |
| Protect the Services, prevent fraud, spam and robocalling | Device, log, usage and call data | Legitimate interests; legal obligation |
| Send service and security notices | Account data | Performance of a contract |
| Improve the Services using aggregated or de-identified statistics | Usage Data | Legitimate interests |
| Send marketing communications | Contact details | Consent, or legitimate interests where permitted by law |
| Analyse website traffic | Cookie data | Consent where required by law |
| Comply with law, respond to legal requests and enforce our terms | Any relevant data | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced our interests against your rights, and you may object as described in Section 17. We do not sell Personal Data, and we do not use it to make decisions based solely on automated processing that produce legal or similarly significant effects on you.
De-identified data. We may create aggregated or de-identified Usage Data that can no longer reasonably identify any Customer or individual, and use it to operate, secure, analyse and improve the Services. We will not attempt to re-identify such data.
6.Call Recording, Transcription and Monitoring
6.1 Recording is controlled by the Customer. Call recording is off by default. A Customer may enable it for specific phone numbers. When enabled, calls are recorded with each participant on a separate audio track.
6.2 Notice and consent. Laws in many jurisdictions, including several US states and India, require that all parties are informed when a call is recorded, and some require their consent. The Customer is solely responsible for giving any required notice and obtaining any required consent, and for having a lawful basis, before enabling recording, transcription, live listening, whisper or barge features. HyperDial provides configurable recording announcements by region and campaign to help Customers do this.
6.3 Pausing recordings. Users can pause and resume a recording during a call, for example while a caller shares payment details.
6.4 Live call monitoring. Supervisors authorised by a Customer may listen to live calls, speak privately to the agent (whisper) or join the call (barge). Customers are responsible for informing their Users that calls may be monitored.
6.5 Access to recordings. Recordings are available only to the Customer's authorised Users. Playback links expire after 7 days. HyperDial personnel do not access recordings except to provide support requested by the Customer or where required by law.
6.6 Retention of recordings. Customers can set retention periods for recordings and transcripts per campaign, within the limits in Section 14. Deleting a recording also deletes the transcripts and summaries derived from it.
7.Artificial Intelligence Features
7.1 When a Customer enables AI features, such as AI voice agents, call summaries, call scoring and transcription analytics, call audio is converted to text and analysed to produce transcripts, summaries, scores and coaching insights for that Customer. AI features are off unless the Customer enables them.
7.2 No training on Customer Content. We do not use Customer Content or AI-generated output to train, fine-tune or improve general-purpose AI models that are made available to other customers. Our third-party AI model providers are bound not to use Customer Content to train their models. Insights learned from a Customer's calls are used only for that Customer.
7.3 AI-generated output may be inaccurate. Customers should review it before relying on it to make decisions about individuals, particularly decisions about credit, insurance, employment, healthcare or debt collection.
7.4 Customers are responsible for informing End Users, where required by law, that they are speaking with an AI or automated system, or that calls are transcribed or analysed using AI.
8.Phone Numbers, Identity Verification and Telecom Compliance
8.1 Telecom regulators and carriers require us to verify the identity of the business using a phone number before we can assign it, particularly for local and toll-free numbers and for business messaging ("Know Your Customer" or KYC). We may suspend or refuse Services if verification is not completed.
8.2 We collect verification documents only for this purpose, store them encrypted, and share them only with the carriers, registries and regulators that require them. Access to these documents is restricted and download links are short-lived.
8.3 Business details may also be submitted to industry registries used to register messaging brands and campaigns (such as 10DLC registration and toll-free verification in the United States, and DLT registration in India), and to authenticate caller ID under the STIR/SHAKEN framework so that calls are not flagged as spam.
9.SMS, Messaging and Multi-Factor Authentication
9.1 Customer messaging. Customers must have a lawful basis, usually prior consent, before sending messages to End Users. End Users may reply STOP (or a local equivalent) at any time to opt out, and we honour such requests. Our SMS Policy sets out the full rules.
9.2 Messages from HyperDial. We may send you text messages for account security (such as one-time passcodes for multi-factor authentication) and service alerts. Message and data rates may apply. Reply STOP to opt out of non-essential messages or HELP for help. Phone numbers and opt-in data collected for these messages are not shared with third parties for their marketing purposes.
10.Third-Party Integrations and Sign-In Services
10.1 Customers may connect the Services to third-party tools, such as CRMs and helpdesks. When they do, we exchange only the data needed for the integration to function, such as contact details and call logs, and only within the permissions the Customer grants. Customers can disconnect an integration at any time, after which we stop syncing data with it.
10.2 Third-party tools are governed by their own terms and privacy policies, and we are not responsible for their availability, security or handling of data.
10.3 Where you connect Google services (such as Google Workspace) to HyperDial, HyperDial's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve or train generalised AI or machine-learning models.
11.How We Share Personal Data
11.1 Service Providers. We share Personal Data with the following categories of Service Providers, only to the extent each needs it to perform services for us, and under written contracts that require them to protect the data and use it only on our instructions:
- telecom carriers and network partners that connect calls and deliver messages;
- cloud hosting and data storage providers;
- payment and billing providers;
- AI and speech-processing providers, when a Customer enables AI features;
- email, website chat and customer-support tools;
- website analytics providers, where you have consented; and
- professional advisers such as auditors and legal counsel, under confidentiality obligations.
11.2 Carriers, registries and regulators, for number verification, caller-ID authentication and messaging registration as described in Section 8.
11.3 With your consent or at the Customer's direction, for example when a Customer connects an integration.
11.4 Business transfers. If HyperDial is involved in a merger, acquisition, financing or sale of assets, Personal Data may be transferred as part of that transaction, subject to protections consistent with this Privacy Policy. We will notify affected Customers of any change in control.
11.5 Service Provider list. Customers may request our current list of Service Providers under the DPA by writing to sales@hyperdial.io. We notify Customers before adding a new Service Provider that processes Customer Content, and Customers may object.
11.6 We do not sell Personal Data and we do not share it with third parties for their own advertising or marketing.
12.Legal Requests and Government Access
We disclose Personal Data to courts, law enforcement agencies or regulators only when we are legally required to do so, such as in response to a valid court order, lawful interception request or regulatory direction, or where necessary to protect the rights, property or safety of HyperDial, our Customers or others. We review each request for legal validity and disclose only the data required. Where legally permitted, we notify the affected Customer before disclosure so that it can seek a protective order.
13.Where Your Data Is Stored and International Transfers
13.1 United States. Personal Data of Customers based in the United States is stored on servers located in California, USA.
13.2 All other countries. Personal Data of Customers based in any other country is stored on servers located in that Customer's own country and is not moved to another country for storage. For example, data of Customers based in India is stored in our Mumbai region.
13.3 The storage location is set when the account is created. Backups are stored in the same country as the primary data.
13.4 A live call or message between two countries necessarily passes through telecom networks in both countries while it is being connected. This is transmission, not storage.
13.5 If Personal Data ever needs to be transferred outside its country, for example to route calls or to provide support requested by a Customer, we will do so only with the safeguards required by applicable law, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the conditions set under India's Digital Personal Data Protection Act, 2023.
14.Data Retention
14.1 We retain Personal Data for one (1) year, after which it is deleted or anonymised so that it no longer identifies any individual.
| Category of data | Retention period |
|---|---|
| Call recordings, transcripts, messages and call logs | 1 year from creation (Customers may choose a shorter period) |
| Account information | For the life of the account, then 1 year after the account is closed |
| Verification (KYC) documents | 1 year after the related phone number is released |
| Contacts and leads stored by a Customer | Until the Customer deletes them or the account closes, and no longer than 1 year |
| Marketing and sales enquiry data | 1 year from your last interaction with us, or until you opt out |
| Website analytics and chat data | 1 year |
| Security and access logs | 1 year |
14.2 When an account closes. After a Customer's account closes, the Customer has 30 days to request an export of its Customer Content. We then delete Customer Content within 90 days, except where retention is required by law or for billing records.
14.3 Legal exceptions. We may retain specific records for longer where required by law, such as invoices and tax records, or where needed to establish, exercise or defend legal claims or to comply with a regulator's request. In that case we retain only the records required, for only as long as required.
14.4 Backups. Deleted data is removed from backups as our backup cycle runs, and no backup is kept for longer than 1 year.
15.Payment Information
Card and payment details are collected and held by our payment integration providers, which are certified to the Payment Card Industry Data Security Standard (PCI DSS). Your full card number is never stored on HyperDial's servers. We receive only limited information needed to manage billing, such as the card type, last four digits, expiry date and payment status.
16.Data Security
16.1 We implement and maintain technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256), including recordings, transcripts and verification documents;
- passwords stored only as salted hashes, and secure, HTTP-only session cookies;
- role-based access controls, so people see only what their role requires;
- audit logging of administrative actions;
- confidentiality obligations for all HyperDial staff, with no standing staff access to Customer recordings and support access that is limited and logged; and
- regular security testing, including independent penetration testing.
16.2 Certifications. Our SOC 2 Type II audit is in progress. We do not claim any certification or standard that we have not been audited for.
16.3 Security incidents. If we become aware of a breach affecting Personal Data, we will notify affected Customers without undue delay, and notify regulators within the time required by law (for example, within 72 hours under the GDPR and India's DPDP Rules).
16.4 No method of transmission or storage is completely secure. Please report any suspected security issue or unauthorised access to your account to sales@hyperdial.io.
17.Your Rights and Choices
17.1 Your rights. Depending on where you live, you may have the right to: access your Personal Data and receive a copy; correct inaccurate data; delete your data; restrict or object to certain processing; receive your data in a portable format; withdraw consent at any time (without affecting processing already carried out); and complain to a data protection authority. Region-specific rights are set out in Section 24.
17.2 How to exercise your rights. Email sales@hyperdial.io with the subject line "Privacy Request", or use our contact page. We will verify your identity before acting on a request, and may ask for additional information to do so. We respond within one month, or within the shorter or longer period set by your local law (for example, 45 days in the United States). Requests are free unless they are manifestly unfounded or excessive.
17.3 Requests about Customer Content. If your data is held in a Customer's account, we will forward your request to that Customer and assist it in responding.
17.4 Your choices at a glance.
| Choice | Default | How to change it |
|---|---|---|
| Marketing emails | Sent only with consent, or to Customers where permitted by law | "Unsubscribe" link in any email, or write to us |
| Text messages from a Customer | Only if you agreed to receive them | Reply STOP |
| Non-essential cookies (analytics, chat) | Off until you accept; in the United States, on unless you opt out | Cookie banner, or "Cookie Preferences" in the website footer |
| Global Privacy Control | Honoured as an opt-out | Enable it in your browser |
| Call recording (Customers) | Off | Admin enables it per phone number |
| AI transcription and insights (Customers) | Off | Admin enables it |
| Recording retention (Customers) | 1 year | Admin may set a shorter period per campaign |
| Data export (Customers) | Available while the account is active, and for 30 days after it closes | Dashboard or API, or write to us |
18.Marketing Communications
We send marketing communications only with your consent, or to existing Customers where permitted by law. You can opt out at any time by clicking "unsubscribe" in any marketing email or by contacting us, and we will process your request within 3 working days. Even if you opt out of marketing, we will continue to send service-related messages, such as security alerts and billing notices, while you have an account.
19.Cookies and Tracking Technologies
19.1 We use cookies and similar technologies on our website and in the Services. The categories are:
- Strictly necessary: keep you logged in, remember your cookie preferences and keep the Services secure. These are always active.
- Analytics: help us understand how visitors use our website. Used only with your consent where required by law.
- Functional: enable features such as our website chat. Used only with your consent where required by law.
19.2 We do not use advertising or cross-site tracking cookies.
19.3 You can change your cookie choices at any time through "Cookie Preferences" in our website footer or through your browser settings. A full list of the cookies we use, with their purpose and duration, is available on request from sales@hyperdial.io.
19.4 Do Not Track and Global Privacy Control. We honour the Global Privacy Control (GPC) signal as a valid request to opt out of non-essential cookies. Because there is no common industry standard for "Do Not Track" browser signals, we do not respond to them.
20.Third-Party Websites and Links
Our website and Services may contain links to third-party websites, apps or services. We are not responsible for their privacy practices, and this Privacy Policy does not apply to them. Please review their privacy policies before providing any Personal Data.
21.Children's Privacy
The Services are intended for businesses and are not directed to anyone under 18 years of age. Anyone accepting our Terms of Service on behalf of a Customer must be at least 18. We do not knowingly collect Personal Data from children. If you believe a child has provided us with Personal Data, please contact us and we will delete it.
22.Notice to End Users
If you spoke with, were called by, or exchanged messages with a business that uses HyperDial, that business is the Controller of your Personal Data and decides how it is used. To ask about a recording, stop messages or exercise your privacy rights, please contact that business directly. If you contact us instead, we will forward your request to the business and help it respond.
23.Your Communications With HyperDial
Calls and chats with our sales and support teams may be recorded and transcribed for quality, training and record-keeping. We will tell you at the start of the call. If you do not want a call recorded, please let us know and we will offer another way to help you.
24.Region-Specific Provisions
24.1India
If you are in India, the Digital Personal Data Protection Act, 2023 and its Rules apply. You have the right to:
- obtain a summary of the Personal Data we process about you and the persons with whom it has been shared;
- request correction, completion, updating or erasure of your Personal Data;
- withdraw your consent at any time, as easily as you gave it;
- nominate another person to exercise your rights in the event of your death or incapacity; and
- have your grievances redressed.
Please first contact our Grievance Officer (Section 26). If you are not satisfied with our response, you may complain to the Data Protection Board of India. This Privacy Policy is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.
24.2European Economic Area, United Kingdom and Switzerland
If you are in the EEA, the UK or Switzerland, the legal bases for our processing are set out in Section 5, and your rights are described in Section 17.1. You may lodge a complaint with your local supervisory authority; in the UK this is the Information Commissioner's Office (ICO), and in Switzerland the Federal Data Protection and Information Commissioner (FDPIC). Transfers of Personal Data are protected by the Standard Contractual Clauses and the UK Addendum incorporated in our DPA.
24.3United States
Notice to California residents and residents of other US states with privacy laws. This section supplements this Privacy Policy and applies under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and similar state laws, including those of Colorado, Connecticut, Virginia, Texas and Oregon.
In the past 12 months we have collected the following categories of personal information:
| Category | Examples | Sources | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Name, email, phone number, IP address, account ID | You; your device; Customers | Service Providers; carriers and registries |
| Customer records | Billing address, tax identifiers | You | Service Providers (payment and billing) |
| Commercial information | Plans purchased, invoices, usage | You; the Services | Service Providers |
| Internet or network activity | Pages visited, feature usage, log data | Your device | Service Providers (hosting, analytics with consent) |
| Audio and electronic information | Call recordings, messages, when enabled by a Customer | Customers and Users | Service Providers (hosting, AI when enabled) |
| Professional information | Company, job title | You | Service Providers |
| Sensitive personal information | Government identity documents; account login credentials | You | Carriers, registries and regulators (verification only) |
- Purposes for which we collect and use this information are described in Section 5, and retention periods in Section 14.
- No sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under 16.
- Sensitive personal information is used only for identity verification, security and legal compliance, as permitted by law, and not to infer characteristics about you.
- Your rights. You may request to know, access, correct and delete your personal information, and to obtain a portable copy. We will not discriminate against you for exercising these rights. You may use an authorised agent; we will ask the agent for proof of authorisation and may ask you to verify your identity. If we deny your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General.
- Customer network information (CPNI). US telecom law protects information about your use of our phone services, such as numbers called and call times. We use it only to provide and bill for our services, and we do not sell it.
24.4Canada
If you are in Canada, you may request access to and correction of your Personal Data, and withdraw your consent, under the Personal Information Protection and Electronic Documents Act (PIPEDA). You may complain to the Office of the Privacy Commissioner of Canada.
24.5Australia and New Zealand
If you are in Australia, we handle your Personal Data in line with the Australian Privacy Principles under the Privacy Act 1988, and you may request access to and correction of it; you may complain to the Office of the Australian Information Commissioner (OAIC). If you are in New Zealand, you have rights of access and correction under the Privacy Act 2020, and you may complain to the Office of the Privacy Commissioner.
24.6United Arab Emirates
If you are in the UAE, you have rights under the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) to access, port, correct and erase your Personal Data, and to restrict or object to its processing. You may complain to the UAE Data Office.
24.7Singapore
If you are in Singapore, you may request access to and correction of your Personal Data, and withdraw your consent, under the Personal Data Protection Act 2012. Contact our Data Protection Officer at sales@hyperdial.io. You may also contact the Personal Data Protection Commission.
25.Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and notify account holders by email at least 30 days before the changes take effect, unless a change is required sooner by law, a regulator or a carrier. Your continued use of the Services after that date means you accept the updated Privacy Policy. Previous versions are available on request.
26.Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Privacy and Data Protection Officer: sales@hyperdial.io (subject line "Privacy Request")
- Grievance Officer (India): Grievance Officer, HyperDial Technologies, sales@hyperdial.io (subject line "Grievance"). We acknowledge grievances within 48 hours and resolve them within 30 days.
- Security issues: sales@hyperdial.io (subject line "Security")
- Company: HyperDial Technologies, India
- Website: hyperdial.io/contact