Privacy Policy
Last updated: July 3, 2026
At Klariqo, we are committed to protecting your privacy and the security of your data. This Privacy Policy explains how we collect, use, and safeguard data across our two core offerings:
- Managed Voice AI: our managed AI voice agents that place, receive, and handle live telephone calls over a SIP bridge, directly in the communication path.
- Compliance and QA Layer: our post-call service that connects to your existing dialer (such as VICIdial) to ingest call recordings read-only after the call, perform transcription and quality-assurance (QA) scoring, and generate a signed, tamper-evident record of the call.
This policy applies solely to services operated by Klariqo (based in India, with infrastructure running primarily in the United States). It does not apply to third-party integrations or whitelabel deployments run by independent partners.
1. Controller and Processor Roles
- Klariqo as a Data Controller: Klariqo is the controller for personal data about our website visitors, account administrators, billing contacts, and marketing interactions. We determine the purposes and means of processing that data.
- Klariqo as a Data Processor: for clients using our Compliance and QA Layer, or our Managed Voice AI to interact with their own callers, the client (the call center or business) is the controller of their callers' personal data and recordings, and their callers are the data subjects. Klariqo acts as a processor, handling recordings, transcripts, metadata, and QA scores solely on the client's instructions and under our Data Processing Agreement.
2. Information We Collect
Personal Information (account and billing)
- Name and contact details (business email, phone number, mailing address)
- Business information (company name, role, industry, dialer configuration settings)
- Account credentials (login email, hashed password)
- Communication preferences and marketing opt-in choices
- Payment and billing details (routed through our third-party payment processor, Dodo Payments; Klariqo does not store full payment card numbers)
Compliance and QA Data (post-call ingestion)
For clients using our Compliance and QA Layer, Klariqo ingests data read-only and post-call from the client's existing dialer (such as VICIdial): - Post-call recordings retrieved after the call completes, via secure least-privilege API access - Call metadata: timestamps, duration, dialer identifiers, phone numbers, disposition codes - Derived transcripts and analysis: machine-generated transcripts, diarization (speaker roles), and QA scores against your rules - Note on diarization: mono-channel recordings can produce lower-confidence speaker attribution. We flag those cases transparently in the metadata rather than hide the limitation.
Voice Data (Managed Voice AI call path)
For clients using our Managed Voice AI, we process call data in real time as the active call-path provider: - Live voice streams during active AI-handled calls - Real-time transcripts generated during the call to power the conversation - Call metadata: destination numbers, duration, timestamp, SIP response codes, routing parameters - Performance data: latency, text-to-speech render times, speech-to-text accuracy markers
Technical Data
We automatically collect technical data from website visitors and logged-in dashboard users: IP addresses and browser information, operating system and device type, page navigation and referral URLs, and technical log and error reports.
3. How We Use Your Information
- Service delivery: processing voice calls, routing transfers, retrieving post-call recordings, generating transcripts, performing QA scoring, and storing call evidence.
- Evidence generation: assembling calls, transcripts, and QA scores into signed cryptographic records that you own and control.
- Account and usage management: administering logins, billing, usage tracking, and platform metrics.
- Service troubleshooting: debugging transcription errors, investigating live-SIP latency, and maintaining uptime.
- Aggregate analytics: compiling high-level, fully anonymized benchmarks (see Section 4).
- Cryptographic witnessing: sending one-way, zero-knowledge hashes of compliance records to our independent witnessing partner to support tamper-evidence (no call content or caller identity is sent).
- Legal and security: safeguarding evidence, complying with lawful requests, and defending against fraud and abuse.
4. Aggregate Analytics
We analyze anonymized, high-level indicators across the Klariqo platform to generate industry benchmarks and improve accuracy: - Scope: call-outcome distributions, call durations by industry, response latencies, voicemail-detection accuracy. - De-identification: aggregated across multiple accounts and fully de-identified. It contains no caller phone numbers, recordings, individual transcripts, client business identities, or personal identifiers. - No external sales: we never sell, rent, or lease aggregate datasets. - Opting out: account holders may opt out by emailing [email protected]. Opting out disables aggregate benchmarking visualizations in your dashboard.
5. Data Sharing and Sub-Processors
To deliver our services we rely on the infrastructure providers below. All sub-processors are bound by data-processing terms requiring confidentiality and security.
| Provider | Purpose | Location | Data Processed |
|---|---|---|---|
| Cloudflare | Hosting, CDN, Workers, R2 storage | US / Global | Web traffic, dashboard data, stored vCon records |
| Google Cloud Platform | SIP bridge infrastructure | US | Live call audio (real-time, not stored) |
| Supabase | Database hosting | US | Account data, billing, transcripts, metadata |
| Dodo Payments | Payment processing | US | Billing and transaction data |
| Cartesia | Text-to-speech (Managed Voice AI) | US | AI response text (real-time) |
| Deepgram | Speech-to-text (Managed Voice AI) | US | Live voice streams (real-time) |
| Groq | LLM inference (Managed Voice AI) | US | Conversation text (real-time) |
| Google Gemini (Google Cloud AI) | Transcription + QA scoring (Compliance product) | US | Post-call recordings and QA scorecards |
| JLINC | Independent cryptographic witnessing | US | SHA-512 hashes and signatures only (zero-knowledge; no content) |
We do not sell your personal information.
When we may disclose data: to comply with a legal obligation, court order, or regulatory request; to enforce our Terms of Service; to protect the rights, safety, or property of Klariqo, our users, or the public; or with your explicit consent.
6. The Signed Record (vCon) and Witnessing
Every call processed through our Compliance and QA Layer is converted into a portable, standards-based record called a vCon (virtualized conversation). The vCon contains the call identifier and metadata, the transcript, diarization details and derived QA scorecard, and a cryptographic SHA-512 fingerprint of the audio file.
Cryptographic signatures
Once generated, the vCon is signed by Klariqo using an RS256 key. Any later attempt to modify the transcript, the QA scores, or the metadata breaks the signature, making the change detectable to anyone using a public vCon verifier.
Independent witnessing via JLINC
Optionally, clients may add an independent third-party layer through our partner JLINC. When enabled: - Klariqo sends a zero-knowledge cryptographic signature of the record to JLINC. - JLINC acts as an independent witness, recording an attested, timestamped receipt of the record's state. - Zero-knowledge: JLINC never receives raw audio, caller identities, transcript text, or QA scores. Only opaque hashes, identifiers, and signatures leave your account. - What it proves: the receipt provides an independent, timestamped attestation of your evidence and confirms the record has not been altered since it was signed. (It attests to the record and its timestamp, not to the validity of any upstream caller consent, see Section 10.)
7. Read-Only Access (Compliance and QA Layer)
For clients using our Compliance and QA Layer, Klariqo does not participate in active call routing or manipulation: - Post-call access only: we pull completed recordings only after they have concluded on your dialer. - Least-privilege: we access your dialer through a read-only API integration using credentials you configure, manage, and can revoke at any time. - No live-call interference: for this product, Klariqo never joins live calls, never places outbound calls, and cannot modify active dialer configurations or campaigns. - Scope: this applies to the Compliance and QA Layer only. Our Managed Voice AI product operates directly in the live call path to route and deliver real-time conversation.
8. Data Retention
| Data Type | Standard Retention | Enterprise Extended |
|---|---|---|
| Business account profiles | Active account + 30 days | N/A |
| Billing and payment records | 7 years (legal/tax) | N/A |
| Website analytics (GA4) | 14 months | N/A |
| Managed Voice AI recordings | 90 days from call, or client-specified | Custom duration |
| Managed Voice AI transcripts | 90 days from call, or client-specified | Custom duration |
| Compliance Layer signed records (vCons) | Client-specified (retained as your active evidence) | Supported indefinitely, per storage tier |
| Call metadata (timestamps, duration, outcomes) | 1 year | Custom |
Account administrators can request deletion of account records or stored evidence at any time by emailing [email protected]. We execute deletion within 30 days, except where law requires preservation.
9. Data Security
- Encryption in transit: TLS/HTTPS for all dashboard sessions; encrypted APIs for call-data ingestion; SRTP and TLS trunking options for Managed Voice AI connections.
- Encryption at rest: stored databases, backups, and vCon files are encrypted at rest (AES-256).
- Cryptographic integrity: every compliance record is sealed with a SHA-512 hash and RS256 signature, and can be independently witnessed via JLINC.
- Access control: role-based permissions in the dashboard partition access to recordings by business need.
- SOC 2 hosting: infrastructure runs on SOC 2-compliant providers (Cloudflare, Supabase, Google Cloud Platform).
No electronic system is 100% secure. While we provide cryptographic tools to detect tampering and prove record integrity, we cannot guarantee absolute prevention of incidents. If we become aware of a data breach affecting your personal information, we will notify you within 72 hours of discovery, as required by applicable law.
10. Call Recordings and Consent Responsibilities
Managed Voice AI clients
- Automated disclosure: a recording disclosure plays to callers before the AI conversation begins.
- Dual-channel recording: conversations are recorded with the caller and AI on separate tracks to simplify auditing.
- Ownership: stored recordings belong to the client account holder.
Compliance and QA Layer clients
Because this product operates read-only and post-call, Klariqo does not run live disclosures: - Client consent burden: the client holds full legal responsibility to notify callers and secure all required recording and processing consents under applicable federal, state, and local laws (including two-party-consent states such as California, Florida, and Illinois) before Klariqo ingests any records. - What our records prove: Klariqo provides audit-ready evidence and provenance. We prove what was said, and that the record is unaltered since it was signed. Our signatures do not verify, validate, or prove that upstream caller consent was legally obtained.
11. Cookies and Tracking
- Google Analytics 4 (GA4): first-party analytics cookies covering navigation, device, referral, and page performance. Opt out via the Google Analytics Opt-Out Add-on.
- LinkedIn Insight Tag: advertising and conversion measurement for visitors from LinkedIn. You can control advertising cookies through your browser settings and LinkedIn's ad preferences.
- Session cookies: essential secure cookies that authenticate your dashboard session.
12. HIPAA Disclaimer
Klariqo serves clients across regulated fields, including campaigns adjacent to healthcare, Medicare, ACA, and SSDI. - Not a HIPAA Business Associate by default: Klariqo is not a HIPAA Business Associate, and our standard services are not designed to process, store, or transmit Protected Health Information (PHI) under US HIPAA rules. - No PHI without a BAA: clients must not route, upload, or process any audio, transcripts, or metadata containing PHI through Klariqo unless a separate Business Associate Agreement (BAA) has been executed by both parties.
13. Your Rights
All users
You have the right to access a copy of your data, correct inaccurate records, delete your data (subject to billing/legal retention), export your data (portability), and object to or opt out of optional analysis. Email [email protected]; we verify identity and respond within 30 days.
California residents (CCPA/CPRA)
Categories collected: identifiers (name, business email, phone, IP, credentials); commercial details (billing, plan, usage); audio and transcription data (recordings, transcripts, QA scores); professional information (company, role, industry); network activity (site/dashboard usage).
Sources: directly from you; automatically via cookies and logs; and read-only from your connected dialer (for post-call compliance processing).
Sale and sharing: we do not sell your personal information. We use analytics and advertising cookies (Google Analytics 4 and the LinkedIn Insight Tag), which you can opt out of using the tools in Section 11 and your browser settings. To make a request, email [email protected] with "CCPA Request" in the subject line. - Sub-processors: we share the categories above with the Section 5 sub-processors solely to deliver the service, process billing, and maintain security.
Non-discrimination: we will not discriminate against you for exercising your CCPA rights. To submit a request, email [email protected] with "CCPA Request" in the subject line; we verify identity and respond within 45 days.
14. Children's Privacy
Klariqo's services are intended for businesses and professional call center operators. We do not knowingly collect data from children under 13. If we learn we have collected such data, we will delete it promptly. Contact [email protected].
15. International Data Transfers
Klariqo is based in India, and our infrastructure runs primarily in the United States. If you access our platform from outside the US, your data will be transferred to and processed in the US. We rely on standard contractual protections, access controls, and encryption to safeguard these transfers. By using our services, you consent to this transfer.
16. Data Processing Agreement
For clients processing caller data subject to privacy frameworks (CCPA, CPRA, or GDPR principles), Klariqo offers a standalone Data Processing Agreement (DPA) that sets out controller-processor boundaries, sub-processor terms, and security standards. To review and execute the DPA, contact [email protected].
17. Changes to This Policy
We may update this Privacy Policy to reflect new products, software changes, or regulatory shifts. Material changes will be emailed to registered account owners and posted here with a revised "Last updated" date. Continued use after an update constitutes acceptance.
18. Version History
| Version | Date | Changes |
|---|---|---|
| 3.0 | July 3, 2026 | Added the Compliance and QA product: controller/processor roles, post-call read-only ingestion, vCon signing and JLINC independent witnessing, evidence retention, HIPAA disclaimer, and a standalone DPA. Removed the RB2B / Retention.com visitor-identification tool and its disclosures. Updated sub-processor registry (pending Backend confirmation). |
| 2.1 | June 15, 2026 | Added Website Visitor Identification (RB2B) disclosure with opt-out links; updated cookies, sub-processors, and CCPA language. |
| 2.0 | March 23, 2026 | Added CCPA/CPRA, sub-processor list, retention schedule, cookies, international transfers, DPA availability, children's privacy, version history. |
| 1.0 | January 2025 | Initial privacy policy. |
19. Contact Us
Questions about this Privacy Policy or our data practices: [email protected]