1. Who we are and what this covers
heyfon.ai ("Heyfon", "we", "us") provides a platform businesses use to configure an AI assistant that answers their phone calls, WhatsApp messages and website chat. For any privacy matter, contact [email protected].
This policy covers: visitors to this website; people who request a demo call; account holders and their team members; prospects and support contacts; people who communicate with an assistant a business runs on Heyfon; and users of integrations connected to the service.
2. Heyfon’s different privacy roles
Where Heyfon is the controller (or "business"). We decide how and why data is used for this website, accounts, billing, sales, support, security, and the demo call you request from us directly.
Where Heyfon is a processor (or "service provider"). When a business uses Heyfon to handle its customer communications, that business generally decides the purpose of the conversation and is the controller. Heyfon generally processes the recordings, transcripts, call metadata and caller details on that business’s instructions.
If you called or messaged an assistant run by a business using Heyfon, please direct privacy requests to that business first — we support our customers in fulfilling them. This allocation of roles may differ where local law provides otherwise.
3. Information we collect
Depending on how you interact with Heyfon, this can include:
- Contact and account data — name, email address, phone number, organisation, and sign-in credentials.
- Billing data — subscription and transaction records. Full card details are collected and held by our payment provider, not by us.
- Call and message data — phone numbers, caller ID, direction, duration, timestamps and routing information; call audio, recordings, transcripts and summaries; and information spoken or typed during a conversation.
- Assistant configuration — the instructions, business information, knowledge documents and other content an account holder provides, plus captured fields, call outcomes, tasks and tool results the assistant produces.
- Integration data — account identifiers, access tokens and permissions for services a customer chooses to connect.
- Support communications — messages you send us and our replies.
- Technical data — IP address, browser and device information, and service logs and usage events, including signals we use to detect fraud and abuse.
- AI-generated inferences — where those features are active, summaries and similar analysis of a conversation (for example the caller’s request or intent).
On this website specifically: we look up your country (never a precise location) from your IP address to pre-select your dialling code and decide whether to show you the cookie banner; your language choice and cookie decision are stored in your browser’s local storage (heyfon_lang, heyfon_consent); and the analytics and marketing cookies described in section 9 run subject to that decision. Fonts and other site assets are served from our own domain — no third-party font services.
4. Where information comes from
- Directly from you (forms, calls, messages, support requests).
- From a Heyfon customer, when they configure their assistant or add you to their account.
- From callers and message participants in conversations the service handles.
- From integrations a customer authorises.
- From telephony and communications providers that connect calls and messages.
- From the analytics and advertising tools described in section 9.
- From public or authorised business sources, where lawful.
5. How we use information, and on what legal bases
- Delivering and operating the service, including placing a demo call you request — contract; consent for the demo call.
- Authentication, account management and billing — contract; legal obligation for tax records.
- Processing customer-configured communications on our customers’ instructions — the customer’s instructions under our agreement with them.
- Security, fraud prevention and abuse detection — legitimate interests.
- Support, troubleshooting and service improvement — legitimate interests.
- Marketing, only where permitted and always with the ability to opt out — consent or legitimate interests, depending on jurisdiction.
- Meeting legal obligations and handling privacy requests — legal obligation.
The bases in italics apply to UK and EEA users under UK/EU GDPR; no single basis applies to every activity. We do not sell personal information. Analytics and advertising-measurement tools run only as described in section 9, which is also where you can turn them off.
6. The demo call
The "Try the AI call now" form places one immediate demonstration call, made by an AI assistant, to the number you provide. We process the number and your selected country to place that call, and retain the call record for a limited period to review demo quality, secure the feature and prevent abuse.
The call may be recorded and transcribed for those same purposes. Please do not share passwords, payment-card details, government identifiers, health information or other sensitive information during the demo — it is a public demonstration, not a secure channel.
The call is connected through our telephony and AI service providers. Requesting a demo does not opt you in to marketing: we use your number to place the call you asked for, not to add you to a contact list.
7. Conversations we handle for our customers
When a business runs its assistant on Heyfon, we process its conversation data — recordings, transcripts, summaries, extracted fields, tool calls and call metadata — on that business’s behalf and instructions.
Our customers are responsible for: giving their callers any legally required notices; obtaining any required calling and recording consent; having a lawful basis for their use of Heyfon; responding to their callers’ privacy requests; and configuring appropriate retention.
8. AI processing and model training
Conversations are processed by AI service providers acting as our subprocessors so the assistant can understand and respond. That is service delivery — along with the quality review, debugging and security analysis needed to run it — and is distinct from training generalized AI models.
Heyfon does not use customer conversation content to train generalized AI models by default. Any optional use for model training would require an explicit opt-in.
10. Google user data
Customers can connect Google services (such as Google Calendar) to their assistant so it can, for example, check availability and book appointments. Where you authorise that, Heyfon accesses only the data the granted scopes allow, uses it solely to provide the feature you connected it for, shares it only with the subprocessors needed to run the service, and retains it only as long as the connection is active. You can revoke access at any time from your Google account permissions or by disconnecting the integration, after which we delete the associated tokens.
Heyfon’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising.
12. International transfers
Heyfon serves businesses globally, and information may be processed in the United States, the United Kingdom, Pakistan and other countries where we or our providers operate. Where UK or EEA data is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the applicable Standard Contractual Clauses.
13. Retention
- Account data — kept for the life of the account, then deleted within a reasonable period after closure.
- Billing and legal records — kept for the period tax and accounting law requires.
- Demo-call records — kept for a limited review period, then deleted.
- Customer conversation data — retained according to the customer’s settings; deleted when the customer deletes it or closes the account.
- Security logs — kept for a limited period for incident investigation.
- Consent and opt-out records — kept as evidence for as long as the law requires.
- Backups — deleted data ages out of backups on a fixed cycle.
14. Security
We protect personal information with administrative, technical and organisational safeguards appropriate to its sensitivity — including encryption in transit, access controls, and logging. No service can promise absolute security, and we do not claim certifications we do not hold; if a breach affects you, we will notify you and regulators as the law requires.
15. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete or receive a portable copy of your personal information; to restrict or object to processing; to withdraw consent; to opt out of targeted advertising or the sale or sharing of personal information; to appeal a decision on a privacy request; and to complain to a regulator (in the UK, the Information Commissioner’s Office at ico.org.uk).
To exercise a right, email [email protected]. We may need to verify your identity, and an authorised agent may submit a request on your behalf with proof of authority. Not every right applies in every jurisdiction; we will not discriminate against you for exercising one. If your request concerns a conversation handled for one of our customers, we will refer it to that customer and assist them.
16. Children
Heyfon is built for businesses and is not directed to children. You must be at least 18 to hold an account, and we do not knowingly collect children’s information through the public demo. If you believe a child has provided us personal information, contact us and we will delete it.
17. Changes and contact
If we materially change this policy we will update this page and, for account holders, give notice in the product or by email before the change takes effect. Questions, privacy requests, or reports of abuse or an unwanted call from a Heyfon-powered assistant: [email protected].