This Privacy Policy describes how Cawly, Inc. (“Cawly”, “we”, “us”) collects, uses, discloses, and retains personal information when you visit cawly.ai, create an account, or use the Cawly AI answering service, including related dashboards, phone, SMS, email, and chat features. It applies to business customers, their authorized users, and callers whose information is processed when a business uses Cawly.
Who we are
Cawly provides an AI answering service that answers, qualifies, routes, and summarizes phone calls and related messages for businesses. Our customer is typically a business (“Customer”). Callers who reach a Customer through Cawly are that Customer’s callers; we process caller information on the Customer’s behalf to provide the service.
Questions about this policy: privacy@cawly.ai.
Information we collect
We collect information in three ways: you provide it, it is generated when you or callers use the service, or it is collected automatically from browsers and devices.
- Account data — name, email, phone number, business name, industry, role, login credentials, and billing details when you subscribe or start a trial.
- Call and message data — caller phone numbers, timestamps, call recordings (when a Customer enables recording), transcripts, summaries, appointment details, routing and transfer outcomes, SMS or email content sent through the product, and notes tied to the Customer’s organization.
- Configuration data — business hours, greetings, FAQs, transfer rules, booking calendars, integrations, and other settings a Customer stores in the dashboard.
- Technical data — IP address, device and browser type, pages viewed, referring URL, approximate location derived from IP, and product diagnostics needed to operate and secure the service.
- Demo and marketing interactions — contact details you submit for a live demo, callback, ROI report, or newsletter, plus records of consent for those requests.
How we use information
- To provide, maintain, and support the answering service, dashboard, billing, and integrations a Customer configures.
- To answer, qualify, book, transfer, transcribe, and summarize calls and messages for the Customer’s organization.
- To send transactional notices such as setup, trial status, security alerts, and invoices.
- To detect abuse, debug failures, and protect the security of accounts, callers, and our systems.
- To improve reliability and call quality using org-scoped telemetry, with access limited to personnel who need it to operate the product.
- To comply with law, enforce our Terms of Service, and respond to lawful requests.
Legal bases
Where a data-protection law requires a legal basis, we rely on: performance of a contract with the Customer; legitimate interests in operating, securing, and improving a B2B communications service; consent where we ask for it (for example certain demo callbacks or marketing messages); and compliance with legal obligations.
When we process caller information, we do so as a processor or service provider for the Customer, except where we must process information for our own security, billing, or legal obligations.
TCPA and calling consent
Cawly does not place marketing calls or marketing SMS to a person unless that person requested them or a Customer has configured outbound workflows for its own contacts under that Customer’s consent program. Demo callbacks and similar outbound messages from Cawly require the recipient’s request or other valid consent. Customers are responsible for the consent, opt-out, and calling-time rules that apply to their own campaigns and caller lists.
Sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising. Organization data is isolated from other customers’ data.
We share information with subprocessors that help us run the service — for example telephony carriers, hosting and GPU infrastructure, email delivery, payment processing, and error monitoring — under contracts that limit use of the data to providing those services. We may also share information with a Customer’s authorized users and connected integrations that the Customer enables, or when required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale.
Retention
We retain account, billing, and call records while a Customer account is active. After closure we keep a limited copy as needed for legal, tax, billing, dispute, and security purposes, then delete or de-identify it. Customers can request deletion of account data subject to those obligations. Call recordings, if enabled, follow the retention settings in the Customer’s account unless a longer period is required by law.
Security
We encrypt information in transit and restrict production access to operators who need it, with access logging. No method of transmission or storage is completely secure. Customers are responsible for safeguarding dashboard credentials and for configuring transfers, recordings, and integrations appropriate to their industry.
Cookies and similar technologies
The website and dashboard use cookies, local storage, and similar technologies that are necessary to keep you signed in, remember preferences, measure product usage, and assign website experiments. You can block non-essential cookies in your browser; some features may not work without them.
Your choices and rights
Customers and their users can review and update account information in the dashboard. Depending on where you live, you may have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to opt out of marketing. We will not discriminate against you for exercising those rights.
To make a privacy request, email privacy@cawly.ai. We may need to verify your identity and, for caller data, may direct you to the Customer that owns the relevant account. Authorized agents may submit requests where the law allows, subject to verification.
- Update or delete account data from the dashboard, or by emailing privacy@cawly.ai.
- Unsubscribe from optional marketing emails using the link in those messages.
- Ask a Customer to correct or delete caller information that Cawly stores for that Customer.
Children
Cawly is a business service. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have, contact privacy@cawly.ai and we will delete it.
International transfers
We are based in the United States. If you access the service from another country, your information may be processed in the United States and other locations where we or our subprocessors operate. Where required, we use appropriate transfer safeguards.
Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change, and we will post the revised policy here. Continued use of the service after an update means you acknowledge the revised policy. If a change materially reduces your rights, we will provide additional notice where required by law.
Contact
Cawly, Inc.
Privacy requests: privacy@cawly.ai
Legal notices: legal@cawly.ai
See also: Terms of Service