Draft notice: This is a draft prepared by an AI coding assistant based on the product's actual technical implementation. It has not been reviewed by a lawyer and should not be treated as legally binding until qualified legal counsel reviews it.

Privacy Policy

Last updated: 2 September 2026

Izwi ("we", "us") provides an AI voice receptionist service that answers business phone calls, books appointments, takes messages, and handles common questions on behalf of our business customers ("tenants"). Izwi is operated from South Africa and this policy is written with reference to the Protection of Personal Information Act, 2013 (POPIA). If you are located outside South Africa, other data protection laws may also apply to you; we aim to meet a comparable standard of care regardless of jurisdiction.

1. Who this policy covers

This policy covers two groups of people: (a) representatives of businesses that sign up for an Izwi account ("tenant users"), and (b) people who call a phone number handled by Izwi on behalf of a tenant ("callers"). Callers do not have an Izwi account and interact with us only through the phone call itself.

2. What data we collect

  • Account information: name, email address, phone number, and business details provided when a tenant user signs up or is invited to a tenant.
  • Call data: caller and callee phone numbers, call direction, duration, status, and — where enabled by the tenant's voice agent — a call transcript, detected language, detected intent, and extracted entities (for example, a name or requested appointment time).
  • Call recordings: when a tenant enables recording for a voice agent, the audio of the call is recorded. Our AI assistant is instructed to inform the caller that the call may be recorded for quality purposes when this guardrail is enabled by the tenant. Recordings are stored by our telephony provider and streamed back to the tenant's dashboard on request; they are not included in the account data-export feature described in Section 5 because they are large binary files outside its scope.
  • Voice agents and configuration: the greetings, guardrails, forbidden topics, and escalation rules a tenant configures for their assistant.
  • Calendar data: where a tenant connects a Google or Microsoft calendar, we access calendar availability and create/update events needed to book appointments through OAuth-granted permissions the tenant controls and can revoke.
  • Billing information: subscription plan, billing history, and a payment token — never raw card details (see Section 4).
  • Technical and security data: IP address, user agent, and timestamps recorded in a security audit log for actions such as sign-in, role changes, and settings changes (see Section 6).
  • Product analytics: we use Microsoft Clarity, a session-recording and heatmap analytics tool, on our marketing and application pages to understand how the product is used. Clarity may record on-page interactions (clicks, scrolling, mouse movement) within the Izwi web app itself. It does not have access to phone call audio or transcripts. Clarity only loads after you accept analytics cookies in the cookie banner shown on your first visit; you can decline it there, and you can reopen that choice at any time.
  • Error monitoring: we use PostHog to capture application errors, which may include limited technical context (e.g. stack traces, request metadata) needed to diagnose bugs.

3. Why we collect it

We process this data to: operate the AI receptionist service (answering calls, booking appointments, generating transcripts); let tenant users manage their account, team, and voice scripts; process subscription payments; secure the platform and investigate suspicious activity; and improve the product through aggregate usage analytics.

4. Who we share data with

We do not sell personal information. We share data with the following categories of service providers, each acting as a processor on our behalf and only to the extent needed to provide the service:

  • Telnyx — telephony provider that carries calls and SMS, and hosts call recordings.
  • Twilio — used as an alternate SMS provider for certain notifications, where configured.
  • Supabase — hosts our primary database and authentication; data at rest is encrypted using Supabase's managed infrastructure encryption, and data in transit uses TLS.
  • Fly.io — hosts the application itself, with TLS enforced for data in transit.
  • OpenAI — processes call audio/text to power the AI assistant's understanding and responses.
  • Payfast — our primary South African payment processor. Card data is tokenized by Payfast on its own PCI-DSS-certified infrastructure; Izwi never receives or stores raw card numbers, CVV, or expiry dates — only a payment token used for recurring billing.
  • Stripe — available as an alternate payment processor, handled the same way (tokenized, no raw card data reaching Izwi).
  • Google and Microsoft — calendar providers, accessed only via OAuth scopes the tenant explicitly grants for appointment booking.
  • SendGrid — sends transactional and notification emails.
  • Resend — sends certain internal security-alert emails.
  • Microsoft Clarity — session-recording/heatmap analytics on our web pages, as described in Section 2.
  • PostHog — error monitoring and product analytics, as described in Section 2.

We may also disclose data where required by law, such as in response to a valid South African court order or regulatory request.

5. Your data export and deletion requests

Tenant owners and admins can export their tenant's account data — tenant details, users, voice agents, call metadata and transcripts, and connected phone numbers — as a single JSON file from within the app. Raw call recording audio is not included in this export (see Section 2).

Tenant owners can also submit a data deletion request from within the app. Submitting this request does not delete data automatically or immediately — it records the request and timestamps it on the tenant record, and a member of our team reviews and actions it manually. We are describing this honestly rather than promising instant automated deletion, because that capability does not currently exist.

6. How long we keep data

Security-relevant events (sign-ins, role changes, settings changes, deletion requests, and similar actions) are written to a security audit log with a minimum retention period of 7 years, in line with our internal security policy. Beyond the audit log, we do not currently have a separately defined, fixed retention period for other data categories (such as call transcripts or recordings) written down elsewhere in our systems — rather than invent a number here, we are stating that plainly. Data is generally retained for as long as a tenant account is active, plus a reasonable period afterward, and can be removed sooner via the deletion request process in Section 5.

7. Security

We apply role-based access control and tenant isolation so that one tenant cannot access another tenant's data, encrypt data at rest (via our database provider's managed infrastructure encryption) and in transit (TLS), and log security-relevant actions to an audit trail. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your rights under POPIA

If POPIA applies to you, you have rights including the right to be notified that your personal information is being collected, to access the personal information we hold about you, to request correction or deletion of it, and to object to certain processing. You can exercise access, export, and deletion-request rights through the mechanisms described in Section 5, or by contacting us directly.

9. Contact

Questions about this policy or a request that isn't covered by the in-app tools above can be sent to our support contact listed in the app. Because this document is a draft awaiting legal review, a dedicated privacy-request email address and Information Officer designation (as contemplated by POPIA) will be finalized as part of that review.