HeyRik

Privacy Policy

HeyRik is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and the rights and choices you have. It applies to our website, dashboard, embeddable widgets, the third-party accounts you choose to connect, and the calls placed or received through the Service. We collect only the data we need to operate the Service, we never sell personal data, and we never use your data to train shared or third-party AI models.

Last updated: August 14, 2026

1.Our Privacy Principles

We design the Service around the principles of data minimization, purpose limitation, and transparency:

We collect only what is necessary to provide the Service you signed up for. We use data only for the purposes described in this Policy and never for unrelated purposes. We do not sell or rent personal data to anyone. We do not use your content, recordings, or voice data to train shared or third-party AI models. You stay in control — you can access, export, correct, or delete your data at any time.

2.Information We Collect

Account information you provide: your name, email address, organization details, and billing information needed to create and manage your account.

Service data you generate: the agents, campaigns, and content you configure, and — where you enable these features — call recordings and transcripts produced by calls handled through your account.

Limited technical data: log and device information (such as IP address and browser type) collected automatically for security, fraud prevention, and to keep the Service working reliably. We do not track you across other websites and we do not build advertising profiles.

3.How We Use Your Information

We use personal data only to:

(a) provide, operate, and secure the Service; (b) process payments you authorize; (c) provide the analytics, transcripts, and reports you request within your own workspace; (d) respond to your support requests and send essential service communications; and (e) comply with our legal obligations.

We do not use your data for third-party advertising, we do not sell it, and we do not use it for any purpose that is incompatible with the reason it was collected.

4.Our Role: Controller and Processor

For your account and billing data, HeyRik acts as a data controller. For the call recordings, transcripts, and contact data you process through the platform, HeyRik acts as a data processor: we process that data only on your documented instructions, only to deliver the features you have enabled, and we return or delete it on request or upon account closure, in accordance with applicable data-protection law.

5.Call Data & Recordings

Where you enable recording or transcription, voice interactions handled through HeyRik are processed solely to deliver the features you have configured — such as transcripts, summaries, and analytics visible only within your workspace. Call data is never sold, never shared for advertising, and never used to train shared or third-party AI models.

As the party initiating or receiving calls, you are responsible for informing call participants and obtaining any consent required by applicable law (including call-recording, telemarketing, and do-not-call regulations) in the jurisdictions where you and the people you call are located. We provide controls to help you meet these obligations, and we may suspend usage that violates them.

6.Voice Clones & Voice Data

Voice samples you upload and the resulting synthetic voice models are treated as sensitive data. We process them only to provide the voice features of your own account. They are never shared with other customers, never sold, and never used to train shared or third-party models.

You may only clone a voice you own or have explicit, documented permission to use. You can delete a voice clone at any time from your workspace, which removes it from active use, and you can request permanent deletion of the underlying samples by contacting us.

7.Google Account Integrations (Calendar & Sheets)

Connecting a Google account is optional and is never required to use HeyRik. If you choose to connect one, you authorize it through Google’s own consent screen — we never see or store your Google password — and the resulting access tokens are stored encrypted. You can disconnect at any time.

What we access, and why. We request only the permissions the features you enable actually need:

Google Calendar — view and edit events: to check your availability and to create, update, or cancel the appointments your AI agent books during a call or chat. Google Calendar — read your calendar list: to show your calendars so you can choose which one bookings should go to. Google Sheets: to read and write the spreadsheets you connect — for example, appending call outcomes, captured customer details, campaign responses, and appointment records to a sheet you nominate. Google Drive — per-file access: so that spreadsheets created by HeyRik on your instruction appear in your own Drive and remain owned by you.

How we use it. We access this data only to carry out actions that you, or the agents you have configured, have explicitly requested. We do not browse, index, or analyze unrelated content in your Google account, and we do not use Google data for any purpose beyond delivering the feature you enabled.

Limited Use. HeyRik’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we do not sell Google user data; we do not use it for advertising of any kind; we do not transfer it to others except as necessary to provide or improve the feature you requested, to comply with applicable law, or as part of a merger or acquisition with your consent; and we do not use Google Workspace APIs data to develop, improve, or train generalized artificial intelligence or machine learning models. No human reads your Google data except where you give specific consent (for example, when you ask our support team to investigate an issue), where it is necessary for security purposes such as investigating abuse, or where the law requires it.

What we store, and for how long. We store your encrypted access tokens, the email address of the connected account, and the identifiers of the calendars and spreadsheets you have chosen to use. Event and row data is written into your own Google account rather than retained by us; where a copy is shown in your dashboard, it is held only as long as needed to display it. When you disconnect the integration or close your account, we revoke the tokens with Google and delete the stored credentials.

Your control. You can disconnect Google at any time from the integrations page in your workspace, which revokes our access immediately. You can also review or revoke access directly from your Google Account permissions page. Revoking access stops any workflow that depends on it.

8.Cookies

We use strictly necessary cookies to keep you signed in and to remember your preferences, and privacy-respecting, first-party product analytics to understand how the dashboard is used so we can improve it. We do not use third-party advertising cookies or cross-site tracking. You can control cookies through your browser settings, though sign-in and some features may not function if essential cookies are disabled.

9.Data Sharing & Sub-processors

We never sell personal data. We share it only with the minimum set of vetted service providers required to run the platform: cloud hosting and storage, licensed telephony carriers (to connect calls and provision numbers), payment processors (to bill plans and credits), and Google, where you choose to sign in with it or connect the Calendar and Sheets integrations described above. The voice and conversational intelligence behind the Service is delivered through HeyRik’s own AI processing pipeline, operated under the same confidentiality and security standards as the rest of the platform.

Every sub-processor is bound by written contracts imposing confidentiality, security, and data-protection obligations, and may process data only to provide services to us — never for their own purposes. We may also disclose data where required by law or a valid legal order, and we will notify you of such requests where legally permitted.

10.Data Retention & Deletion

We retain personal data only for as long as your account is active or as needed to provide the Service, meet legal and tax obligations, resolve disputes, and enforce our agreements. You can delete recordings, transcripts, voice clones, and contact data from your workspace at any time. When you close your account, or when retention is no longer necessary, we delete or irreversibly anonymize your data within a reasonable period, except where law requires longer retention.

11.Security

We protect your data with technical and organizational measures including encryption in transit, access controls on a need-to-know basis, network isolation, audit logging, and regular review of our security practices. In the unlikely event of a personal data breach that affects you, we will notify you and the relevant authorities without undue delay, as required by applicable law.

12.International Data Transfers

Where data is transferred across borders to our sub-processors, we ensure appropriate safeguards are in place — such as contractual data-protection clauses — so that your data receives a consistent standard of protection wherever it is processed.

13.Your Rights

Subject to applicable law — including the EU/UK General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) — you have the right to: access the personal data we hold about you; receive a copy of it in a portable format; correct inaccurate data; delete your data; withdraw consent at any time; object to or restrict certain processing; and lodge a complaint with your data-protection authority.

To exercise any of these rights, contact us using the details below. We respond to verified requests within the timelines required by applicable law, and we will never discriminate against you for exercising your rights.

14.Children's Privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it promptly.

15.Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes through the Service or by email before they take effect, and update the “Last updated” date above. We will not reduce your rights under this Policy without your consent.

16.Contact & Grievance Redressal

For privacy questions, data requests, or complaints, email our privacy team at info@heyrik.com. Our designated Grievance Officer (as required under applicable Indian law) can be reached at the same address and will acknowledge complaints promptly and resolve them within the statutory timelines.

If you are not satisfied with our response, you may escalate to the data-protection authority in your jurisdiction.