This Privacy Policy describes how Hibi ("Company", "we", "us", or "our") collects, uses, stores, and protects personal data when you use our platform and services. We are committed to protecting your privacy and handling your data responsibly.
1. Data We Collect
1.1 Account Information
- Full name
- Email address
- Phone number
- Company/business name
- Billing information and payment method details
1.2 Service Usage Data
- Call recordings and transcripts
- WhatsApp message content and metadata
- Agent configuration data (knowledge base, greetings, rules)
- Campaign contact lists and results
- Business information you provide (hours, services, FAQ)
1.3 Technical Data
- IP address
- Browser type and version
- Device information
- Usage patterns and analytics
- Cookies and similar tracking technologies
2. How We Use Data
We use your data to:
- Provide, maintain, and improve the Service
- Process payments and manage billing
- Improve our AI models and voice synthesis quality
- Send service-related communications and updates
- Detect and prevent fraud, abuse, and security issues
- Comply with legal obligations
- Provide customer support
- Generate anonymized and aggregated analytics
3. Data Retention
- Call recordings: Retained for 90 days, then automatically deleted
- Call transcripts: Retained for 1 year
- Account data: Retained for the duration of your account and up to 30 days after deletion
- Billing records: Retained as required by applicable tax and accounting laws (typically 7 years)
- WhatsApp messages: Retained for 1 year
You may request earlier deletion of your data, subject to legal retention requirements.
4. Third-Party Processors
We share data with the following categories of service providers:
- Twilio: Telephony infrastructure, call routing, SMS delivery, and phone number management
- Google (Gemini): AI language model processing for agent conversations
- Supabase: Database hosting, authentication, and file storage
- Payment processor (PayMe): Payment processing and subscription management
- Google Cloud: Infrastructure hosting and speech services
Each processor is contractually bound to process data only as instructed and to maintain appropriate security measures.
5. Your Rights Under GDPR (EU/EEA)
If you are located in the EU/EEA, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Restrict processing: Request limitation of processing in certain circumstances
- Object: Object to processing based on legitimate interests
- Withdraw consent: Withdraw previously given consent at any time
- Lodge a complaint: File a complaint with your local data protection authority
6. Your Rights Under CCPA (California, USA)
If you are a California resident, you have the right to:
- Know: Request disclosure of the personal information we collect, use, and share
- Delete: Request deletion of your personal information
- Opt-out of sale: We do not sell personal information to third parties
- Non-discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at privacy@hibi.ai. We will respond within 45 days.
7. Your Rights Under Israeli Privacy Protection Law (5741-1981)
If you are an Israeli resident, you have the right to:
- Access your personal data held in our databases
- Request correction of inaccurate data
- Request deletion of data if it is not required for the purpose for which it was collected
- Object to the use of your data for direct marketing
- Lodge a complaint with the Israeli Privacy Protection Authority (PPA)
8. Your Rights Under LGPD (Brazil)
If you are located in Brazil, you have the right to:
- Confirm the existence of processing of your personal data
- Access your personal data
- Correct incomplete, inaccurate, or outdated data
- Anonymize, block, or delete unnecessary or excessive data
- Data portability to another service provider
- Delete personal data processed with your consent
- Information about public and private entities with which your data has been shared
- Revoke consent at any time
9. Cookies
We use cookies and similar technologies for:
- Essential cookies: Required for the Service to function (authentication, preferences)
- Analytics cookies: Help us understand how the Service is used
- Preference cookies: Remember your language and display settings
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including Israel, the United States, and other countries where our service providers operate. We ensure appropriate safeguards are in place for such transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Contractual protections with service providers
11. Children
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided us with personal data, please contact us and we will promptly delete such data.
12. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit and at rest, access controls, regular security assessments, and incident response procedures. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related inquiries or to exercise your rights, contact us at:
- Email: privacy@hibi.ai
- Data Protection Officer: dpo@hibi.ai
See also our Terms of Service and Acceptable Use Policy.