Effective Date: 7/9/2026 | Last reviewed: 28/9/2026
Heybreez (“we,” “our,” or “us”) is a voice AI workflow orchestration platform. We respect your privacy and are committed to protecting your personal data. This Privacy Statement describes how we collect, use, store, and share your personal data, as well as your privacy rights under applicable laws including the EU/UK GDPR and U.S. State Consumer Privacy Laws (e.g., CPRA).
Information privacy is an ongoing responsibility, and we will update this Privacy Notice as we undertake new data practices or adopt new policies. Material updates will be communicated via email or through prominent notices on our platform.
Heybreez is operated by Breez AI Technologies, Inc., headquartered in Delaware, United States. We have designated an internal privacy contact to oversee our privacy practices and handle inquiries or rights requests.
We collect personal information directly from you, automatically through website visits, and from third-party sources (e.g., LinkedIn or commercial data partners):
We process Voice Data strictly to provide, secure, and improve our Services, generate requested transcripts/outputs, prevent fraud, and comply with legal requirements. We do not sell Voice Data or use it for cross-context behavioral advertising.
Enterprise Customers act as data controllers for Voice Data of their end users and are responsible for securing necessary consents (including BIPA compliance where applicable). Voice Data is retained only as needed to deliver Services and is destroyed per customer instruction or our retention schedule.
We do not use customer Voice Data, transcripts, or derived outputs to train or fine-tune any AI or ML model — our own or a third party’s — without explicit, written opt-in consent. Our agreements with model providers prohibit training on customer data and require zero data retention where that option is available.
Where a customer opts in, we use de-identified transcripts rather than raw audio, and only to improve that customer’s own deployment unless the opt-in expressly covers broader use. Opt-ins may be withdrawn at any time by contacting privacy@heybreez.ai. Withdrawal stops all future use of that data; it does not reverse training already completed under a prior consent.
We use essential, functional, analytics, and marketing cookies. Non-essential cookies are set only with prior consent where required by law. Online data partners (e.g., RB2B) may associate site activity with contact details to facilitate marketing. You may opt out of cookie tracking and partner collection via our Cookie Settings or vendor opt-out links on our website.
The analytics and functional tools on our website are PostHog (page usage and session replays, with all form inputs masked), Google Analytics (with advertising features disabled), and Zendesk (support chat, loaded only when you enable functional cookies or click the chat button). Full details are in our Cookie Policy. Vendor opt-outs for RB2B: https://app.retention.com/optout and https://www.rb2b.com/rb2b-gdpr-opt-out.
Our website offers a live demo that places an automated telephone call to a number you enter. Where you request a demo, Heybreez acts as the controller of that data. We collect the name and telephone number you provide and place a call to that number at your request. For each attempt we also record IP address, browser user agent, referring page, the country associated with the number, and whether the call connected or was refused, including attempts declined by our automated abuse controls. We use this information to place the call you requested, to operate those fraud and abuse controls, and to diagnose call failures. Demo calls are placed only at your request and are not marketing calls; we do not use a number submitted for a demo to send marketing calls or texts without the consent required by the Telephone Consumer Protection Act (TCPA).
The demo call is recorded and transcribed, and we store an analysis of the conversation (such as a summary, topics discussed, and sentiment) linked to the number you entered.
We share personal data only with vetted third parties facilitating our operations, including cloud hosting (e.g., AWS), AI model inference, ticketing, analytics, marketing (e.g., RB2B), billing, and CRM providers. All sub-processors are bound by strict contractual data protection terms.
We may also disclose information to comply with legal requests, protect safety and rights, enforce agreements, or complete corporate transactions (e.g., mergers or acquisitions).
We do not sell personal data for monetary payment. However, routine digital disclosures for targeted advertising may constitute a “sale” or “sharing” under U.S. State Privacy Laws. You can opt out of sale/sharing at any time by broadcasting a GPC signal, adjusting Cookie Settings, or emailing privacy@heybreez.ai.
Personal data is processed in the United States. Cross-border transfers from the EU/UK are safeguarded using Standard Contractual Clauses (SCCs) and appropriate data processing agreements.
Depending on your jurisdiction (e.g., EU/UK GDPR or U.S. states including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other U.S. states with comprehensive consumer privacy laws), you have rights to access, rectify, delete, restrict, port, or object to the processing of your data, as well as rights to opt out of targeted advertising, profiling, and sales/sharing.
To exercise your privacy rights or appeal a request decision, email us at privacy@heybreez.ai. We respond within statutory timelines (typically 45 days for U.S. states). EEA residents may also lodge complaints with their local Data Protection Authority.
We implement robust technical and organizational safeguards, including encryption (TLS 1.2+ in transit, AES-256 at rest), strict access controls, MFA, logging, vulnerability scanning, and vendor risk assessments. We are SOC 2 certified and are working towards GDPR and ISO 27001 compliance and certification.
In the event of a confirmed personal data breach, we will notify relevant supervisory authorities and affected controller customers without undue delay (and within 72 hours where required under GDPR/U.S. laws).
Marketing emails include a standard opt-out link compliant with CAN-SPAM, CASL, and ePrivacy rules, which we honor within 10 business days. Where we use your phone number for marketing or service-related calls or text messages, we comply with the Telephone Consumer Protection Act (TCPA) and obtain any required prior express consent. Opting out does not affect essential service/transactional communications.
When data is deleted at your instruction or on expiry of a retention period, it is removed from production systems within 30 days and purged from backups within 35 days.
On termination of a customer agreement, customers have 30 days to export their data, after which we delete it on the schedule above unless a longer period is required by law.
Our Services are intended for business use and not directed to children under 16 (or under 13 for COPPA compliance). We do not knowingly collect personal data from children and will promptly delete any identified underage data.