Privacy Policy

Effective Date: July 1, 2026

1. Introduction

CallDesk AI ("we," "us," or "our") operates an AI-powered voice receptionist platform designed for medical, dental, and healthcare practices. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services at calldesk.me (the "Service").

We are committed to protecting the privacy of patients, healthcare providers, and practice staff. Our platform is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA). We are not SOC 2 certified.

2. Information We Collect

2.1 Practice Account Information

  • Practice name, address, and contact information
  • Staff names, email addresses, and roles
  • Billing and payment information
  • Practice hours, services offered, and scheduling preferences

2.2 Call Data and Protected Health Information (PHI)

  • Caller phone numbers and call metadata (duration, timestamps)
  • Call audio recordings and AI-generated transcripts
  • Patient names, dates of birth, and contact information
  • Appointment details and scheduling information
  • Reason for call and clinical information shared by callers
  • Insurance information provided during calls

2.3 Technical Information

  • IP addresses and browser/device information
  • Usage analytics and platform interaction data
  • Cookies and similar tracking technologies

3. How We Use Information

  • Answering and routing inbound patient calls
  • Scheduling, rescheduling, and confirming appointments
  • Generating call summaries and transcripts for practice staff
  • Providing AI-driven responses based on practice-specific information
  • Improving our AI models and service quality (using de-identified data only)
  • Billing, account management, and customer support
  • Complying with legal obligations

4. HIPAA Compliance and PHI

CallDesk AI acts as a Business Associate under HIPAA when processing Protected Health Information on behalf of healthcare practices (Covered Entities). We maintain the following safeguards:

  • Business Associate Agreement (BAA): We execute a BAA with every healthcare practice customer before processing any PHI. Contact jonathan@calldesk.me to request a BAA.
  • Encryption: All PHI is encrypted in transit (TLS 1.2+) and at rest using platform-level AES-256 disk encryption. Vendor credentials additionally carry application-level AES-256-GCM encryption.
  • Access Controls:Role-based access with two-factor authentication required for staff accounts, and each practice's data isolated at the database level so one practice cannot read another's records.
  • Audit Logging: Comprehensive audit trails for all access to PHI.
  • Minimum Necessary Standard: We limit PHI access to the minimum necessary to perform our services.
  • Breach Notification: We notify affected practices within 24 hours of discovering a breach, consistent with HIPAA Breach Notification Rule requirements.

5. Call Recording and AI Processing

Our AI receptionist processes calls in real-time using speech recognition and natural language understanding. Please be aware:

  • Every call opens by identifying the assistant as an AI. This disclosure is built into the system and cannot be removed by a practice.
  • Call recording is off by default. Where a practice enables it, the assistant states that the call is recorded before anything else is discussed, and a caller who declines is transferred to staff.
  • Calls are transcribed for service delivery and quality assurance.
  • Recordings and transcripts are stored securely and treated as PHI when they contain health information.
  • AI-generated summaries are provided to practice staff through the secure dashboard.

6. Data Retention

  • Call recordings: Off by default. Where a practice enables recording, audio is deleted automatically after 30 days.
  • Call transcripts: Deleted automatically after 90 days. Non-identifying call metadata (duration, outcome) is retained for billing and reporting.
  • Appointment reminder message content: Deleted automatically after 180 days.
  • Account data: Retained for the duration of the customer relationship plus 30 days after termination.
  • De-identified data: May be retained indefinitely for service improvement.

Upon termination of service, practices may request export or deletion of their data. We will complete deletion requests within 30 days, except where retention is required by law.

7. Data Sharing and Disclosure

We do not sell personal information or PHI. We may share data with:

  • Sub-processors: Cloud infrastructure, voice, messaging and AI model providers. We do not disclose PHI to a sub-processor before a Business Associate Agreement with that provider is executed; until then PHI processing stays switched off for the practice.
  • Practice staff: Call data is accessible to authorized personnel at the subscribing practice.
  • Legal requirements: When required by law, court order, or to protect rights and safety.

8. Security

We implement administrative, physical, and technical safeguards including:

  • Encryption of data in transit (TLS) and at rest (AES-256)
  • Per-practice isolation of records, enforced at the database layer
  • An append-only audit log recording every access to a patient record
  • Automatic deletion of call recordings and transcripts after the retention period your practice configures
  • Incident response and breach notification procedures

We do not currently hold a SOC 2 Type II certification, and we do not yet undergo annual third-party security audits or scheduled penetration testing. We will state plainly where our security program stands and provide our documentation on request rather than claim certifications we have not earned.

9. Your Rights

For patients: Your rights regarding your health information are governed by HIPAA and should be exercised through your healthcare provider (the practice using CallDesk AI).

For practice customers: You may access, correct, export, or delete your account data and associated call data at any time through your dashboard or by contacting us.

California residents: You have additional rights under the CCPA/CPRA, including the right to know, delete, and opt-out of the sale of personal information (we do not sell personal information).

10. Children's Privacy

Our Service is not directed at children under 13. We do not knowingly collect personal information from children. When a minor patient's parent or guardian calls, any information collected is treated as PHI under the applicable BAA.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify practice customers of material changes via email at least 30 days before the changes take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

For questions about this Privacy Policy, HIPAA compliance, or to request a BAA:

  • Email: jonathan@calldesk.me
  • Website: calldesk.me