Privacy Policy
Effective Date: July 1, 2026
1. Introduction
CallDesk AI ("we," "us," or "our") operates an AI-powered voice receptionist platform designed for medical, dental, and healthcare practices. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services at calldesk.me (the "Service").
We are committed to protecting the privacy of patients, healthcare providers, and practice staff. Our platform is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA), and we maintain SOC 2 Type II certification.
2. Information We Collect
2.1 Practice Account Information
- Practice name, address, and contact information
- Staff names, email addresses, and roles
- Billing and payment information
- Practice hours, services offered, and scheduling preferences
2.2 Call Data and Protected Health Information (PHI)
- Caller phone numbers and call metadata (duration, timestamps)
- Call audio recordings and AI-generated transcripts
- Patient names, dates of birth, and contact information
- Appointment details and scheduling information
- Reason for call and clinical information shared by callers
- Insurance information provided during calls
2.3 Technical Information
- IP addresses and browser/device information
- Usage analytics and platform interaction data
- Cookies and similar tracking technologies
3. How We Use Information
- Answering and routing inbound patient calls
- Scheduling, rescheduling, and confirming appointments
- Generating call summaries and transcripts for practice staff
- Providing AI-driven responses based on practice-specific information
- Improving our AI models and service quality (using de-identified data only)
- Billing, account management, and customer support
- Complying with legal obligations
4. HIPAA Compliance and PHI
CallDesk AI acts as a Business Associate under HIPAA when processing Protected Health Information on behalf of healthcare practices (Covered Entities). We maintain the following safeguards:
- Business Associate Agreement (BAA): We execute a BAA with every healthcare practice customer before processing any PHI. Contact jonathan@calldesk.me to request a BAA.
- Encryption: All PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access Controls: Role-based access with multi-factor authentication for all staff accounts.
- Audit Logging: Comprehensive audit trails for all access to PHI.
- Minimum Necessary Standard: We limit PHI access to the minimum necessary to perform our services.
- Breach Notification: We notify affected practices within 24 hours of discovering a breach, consistent with HIPAA Breach Notification Rule requirements.
5. Call Recording and AI Processing
Our AI receptionist processes calls in real-time using speech recognition and natural language understanding. Please be aware:
- Calls may be recorded and transcribed for service delivery and quality assurance purposes.
- Callers are informed at the beginning of each call that they are speaking with an AI assistant and that the call may be recorded.
- Recordings and transcripts are stored securely and treated as PHI when they contain health information.
- AI-generated summaries are provided to practice staff through the secure dashboard.
6. Data Retention
- Call recordings: Retained for 90 days by default, configurable per practice (up to 7 years for compliance needs).
- Call transcripts and summaries: Retained for the duration of the customer relationship plus 6 years, or as required by applicable law.
- Account data: Retained for the duration of the customer relationship plus 30 days after termination.
- De-identified data: May be retained indefinitely for service improvement.
Upon termination of service, practices may request export or deletion of their data. We will complete deletion requests within 30 days, except where retention is required by law.
7. Data Sharing and Disclosure
We do not sell personal information or PHI. We may share data with:
- Sub-processors: Cloud infrastructure and AI model providers operating under BAAs and equivalent data protection agreements.
- Practice staff: Call data is accessible to authorized personnel at the subscribing practice.
- Legal requirements: When required by law, court order, or to protect rights and safety.
8. Security
We maintain SOC 2 Type II certification and implement administrative, physical, and technical safeguards including:
- End-to-end encryption for all data in transit and at rest
- Regular penetration testing and vulnerability assessments
- Employee background checks and security training
- Incident response and disaster recovery procedures
- Annual third-party security audits
9. Your Rights
For patients: Your rights regarding your health information are governed by HIPAA and should be exercised through your healthcare provider (the practice using CallDesk AI).
For practice customers: You may access, correct, export, or delete your account data and associated call data at any time through your dashboard or by contacting us.
California residents: You have additional rights under the CCPA/CPRA, including the right to know, delete, and opt-out of the sale of personal information (we do not sell personal information).
10. Children's Privacy
Our Service is not directed at children under 13. We do not knowingly collect personal information from children. When a minor patient's parent or guardian calls, any information collected is treated as PHI under the applicable BAA.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify practice customers of material changes via email at least 30 days before the changes take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
For questions about this Privacy Policy, HIPAA compliance, or to request a BAA:
- Email: jonathan@calldesk.me
- Website: calldesk.me