CallGideon Privacy Policy

Effective Date: June 23, 2026

Call Gideon Inc. (“CallGideon,” “we,” “us,” or “our”) operates CallGideon, an AI voice-agent legal-intake platform for U.S. personal-injury law firms, available at callgideon.com. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with our websites, dashboards, voice agent, and related services (the “Services”).

This Policy is written primarily from the perspective of CallGideon acting as a controller (a “business” under California law) for the information we determine the purposes and means of processing — for example, information about our law-firm account users, website visitors, sales and marketing prospects, and billing contacts. For the caller intake data our voice agent collects during a call on behalf of a law-firm customer (including caller PII and injury/medical details), CallGideon acts as a data processor (“service provider”) and HIPAA Business Associate, and the law firm is the controller and HIPAA Covered Entity. The “Our Roles: Controller vs. Processor / Business Associate” section below explains this dual role in detail.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of the Services.

1. Scope of This Policy

This Policy applies to personal information processed through the CallGideon Services, including our marketing website, the web dashboards (web, cal, call, esign), the embeddable voice widget, the AI voice agent, and our backend platform. It applies to law-firm account users and administrators, individuals whose calls are handled by the voice agent (“callers”), website visitors, and sales, marketing, and billing contacts.

Because our role differs depending on whose information is involved, this Policy is organized so that you can identify the processing relevant to you. Where CallGideon is a processor / Business Associate (caller intake data), our handling is also governed by our contracts with the law firm — the Master Subscription Agreement, the Data Processing Addendum (DPA), and, where applicable, the Business Associate Agreement (BAA). Where those contracts conflict with this public Policy as to caller data, the contracts control.

CallGideon is a U.S. company with U.S.-only operations. We do not currently have an establishment in, target, or monitor individuals in the EU or UK. See the “International Data Transfers” and “GDPR / UK GDPR (Not Currently Applicable)” sections below.

2. Our Roles: Controller vs. Processor / Business Associate

CallGideon occupies two distinct data-protection roles, and it is important to understand which applies to a given category of information:

  • Caller intake data (processor / Business Associate). When our voice agent answers or places a call for a law-firm customer, we process the caller’s personal information and any injury or medical details (which constitute electronic protected health information, or “ePHI”) only on the documented instructions of the law firm. For this data, the law firm is the controller and HIPAA Covered Entity, and CallGideon is the processor / service provider and HIPAA Business Associate. We process this data under a DPA and, where ePHI is involved, a BAA.

  • CallGideon’s own data (controller). For information we collect and determine how to use — such as law-firm account users’ contact and login details, website-visitor analytics, sales and marketing prospect data, and billing contacts — CallGideon is the controller (“business”), and this Policy governs that processing directly.

Practical consequence for individual rights: if you are a caller and want to exercise rights over your intake data, your request is generally directed to the law firm that handled your call (the controller); CallGideon will assist that firm. If your information was processed by CallGideon as a controller, you may exercise your rights with us directly. See the “California Privacy Rights,” “Other U.S. State Privacy Rights,” and “How to Exercise Your Rights and Request Routing” sections below.

3. Categories of Information We Collect

3.1 Account and Billing Information

  • Name, email address, and password (login credentials) when an account is created

  • Organization/law-firm name, role, and team membership

  • Billing and payment contact details and subscription/plan information (card payments are handled by our payment processor; we do not store full card numbers)

3.2 Information Collected Automatically

  • Log data: IP address, browser type, pages and screens viewed, referring/exit pages, and timestamps

  • Device information: operating system and device identifiers

  • Usage data: features accessed, session duration, and interaction patterns

  • Cookies, pixels, and similar technologies (see the “Cookies and Analytics” section below), including first-party analytics (PostHog) and error/performance monitoring (Sentry)

3.3 Call Data (includes Sensitive Information / ePHI)

When our voice agent handles a call for a law firm, we process — as the firm’s processor and Business Associate — the following, which may include sensitive personal information and ePHI:

  • Call recordings (audio) and live and stored transcripts of the conversation

  • Caller PII: phone number, name, date of birth, and address (as provided on the call)

  • Injury and medical intake details, incident descriptions, insurance information, and other case facts — this is health information / ePHI and is treated as sensitive

  • Call metadata: duration, language detected, and case-type classification, and structured data extracted from the call by our post-call processing pipeline

3.4 Information from Google Services (Google API Data)

When a user chooses to connect a Google account, we request access only to the scopes needed to provide the features the user enabled:

  • openid, email, profile — Google account name, email address, and profile picture, used to identify the user in the platform.

  • Google Calendar (https://www.googleapis.com/auth/calendar) — used exclusively to schedule follow-up appointments and consultations within CallGideon.

  • Gmail Read (https://www.googleapis.com/auth/gmail.readonly) — used exclusively to surface relevant email-thread context in the platform and to read replies to emails sent on the user’s behalf.

  • Gmail Send (https://www.googleapis.com/auth/gmail.send) — used exclusively to send follow-up emails and post-call summaries on the user’s behalf; sent messages appear in the user’s own Gmail Sent folder.

Our use of Google API data is restricted to the user-facing features you enabled by connecting your Google account, and is not used to develop, improve, or train generalized AI/ML models. These commitments are detailed in the “Google API Services — Limited Use Disclosure” section below. We use gmail.readonly plus gmail.send (not the restricted gmail.modify scope).

4. Notice at Collection

This section provides a concise “Notice at Collection” under the California Privacy Rights Act (CPRA), mapping the categories of personal information we collect (as a business/controller) to the business purposes for which we use them and the categories of recipients to whom we disclose them. Caller intake data is handled on the law firm’s instructions as a processor/Business Associate and is not used by CallGideon for its own purposes; the law firm provides its own notice at collection to callers.

  • Identifiers and account data (name, email, password, organization, role) — Purpose: account creation and access management, authentication, communications, security, and billing. Recipients: cloud and database providers (e.g., AWS, Supabase), authentication and hosting providers, and email/SMS delivery providers.

  • Commercial / billing information (subscription, plan, billing contact) — Purpose: billing, payment processing, and account administration. Recipients: payment processor and accounting/financial-records providers.

  • Internet/network activity (log data, device information, usage data, cookies) — Purpose: security, integrity, troubleshooting, and product analytics. Recipients: first-party analytics provider (PostHog) and error/performance monitoring provider (Sentry).

  • Google account data (where connected: profile, Calendar, Gmail read/send) — Purpose: only the user-facing scheduling and email features you enabled; never for advertising or generalized ML model training. Recipients: Google and our infrastructure providers acting on our behalf under confidentiality obligations.

  • Caller intake data, including sensitive information / ePHI (recordings, transcripts, caller PII, injury/medical details) — Purpose: provide and operate the intake Services on the law firm’s documented instructions, as processor/Business Associate. Recipients: the law firm’s authorized account users and the subprocessors listed in the “Subprocessors” section below, engaged under BAAs/DPAs where they handle ePHI or personal data.

We retain each category for the periods described in the “Data Retention” section below. We do not sell your personal information and do not share it for cross-context behavioral (targeted) advertising, as further described in the “How We Share and Disclose Information” section below. For the rights available to you and how to exercise them, see the “California Privacy Rights” and “Other U.S. State Privacy Rights” sections below.

5. How We Use Information and Legal Bases

We use information for the following purposes. For caller intake data, the purposes are limited to the law firm’s documented instructions and the BAA/DPA; CallGideon does not use caller data for its own purposes.

  • Provide and operate the Services — handle intake calls, transcribe and record calls, extract structured case data, stream live transcripts, route and hand off calls to human staff, and book appointments and process e-signatures.

  • Account and access management — authenticate users, provision role-based access, and administer the law firm’s account.

  • Communications — send service, transactional, and (where permitted) follow-up communications by email and SMS; send marketing only to our own prospects/customers with the right to opt out.

  • Security, integrity, and troubleshooting — monitor performance, detect and prevent fraud and abuse, debug, and maintain reliability.

  • Improve the Services — analyze aggregated or de-identified usage; we do not use caller ePHI to train or improve models except as permitted by the BAA/DPA, and we do not use Google user data to develop, improve, or train generalized AI/ML models.

  • Legal and compliance — comply with legal obligations, enforce our terms, and establish, exercise, or defend legal claims.

Legal bases (as a controller). Where required, we rely on: performance of a contract (account and billing); our legitimate interests (security, product improvement, and B2B marketing), balanced against your rights; compliance with legal obligations; and your consent where applicable (e.g., certain cookies/analytics and connecting your Google account). You may withdraw consent at any time.

6. HIPAA, ePHI, and Business Associate Obligations

Injury and medical intake details captured on calls constitute ePHI. Where a law-firm customer (or a customer that is itself a HIPAA Business Associate) directs ePHI to the Services, CallGideon acts as a HIPAA Business Associate and executes a Business Associate Agreement (BAA) with that customer before ePHI is transmitted.

  • We use and disclose ePHI only as permitted by the BAA and the firm’s documented instructions, and as required by law.

  • We apply the HIPAA Security Rule safeguards described in the “Security and Breach Notification” section below (encryption, access controls, audit logging, field-level encryption of PII/ePHI).

  • We engage subprocessors that handle ePHI only under written agreements that impose equivalent BAA obligations, and we configure zero-/no-data-retention terms with AI providers where available (see the “Subprocessors” section below).

  • As a Business Associate, we will notify the affected Covered Entity of a breach of unsecured ePHI without unreasonable delay and no later than 60 days from discovery (45 CFR 164.410), and our subprocessor agreements require the same downstream chain.

  • We retain HIPAA-required documentation for at least six years as required by 45 CFR 164.316(b)(2).

The law firm, as Covered Entity, remains responsible for its own HIPAA obligations, including providing notices and obtaining authorizations from individuals where required.

7. Call Recording and AI-Voice Disclosure

CallGideon’s voice agent is an artificial-intelligence system, not a human, and calls handled through the Services may be recorded and transcribed. We do not deceive callers about the automated nature of the agent, and we make configurable AI-disclosure and recording-notice features available to law-firm customers.

Federal and state laws govern call recording and consent, including the Electronic Communications Privacy Act (ECPA) and state “one-party” and “two-party” (all-party) consent / wiretap statutes, as well as the Federal Trade Commission Act (Section 5) prohibition on deceptive practices. The law-firm customer, as the controller of the call, is responsible for providing required recording and AI disclosures and for obtaining any consent required in the relevant jurisdiction. CallGideon provides configurable disclosure and recording-notice features and supports the firm in meeting these obligations, but the firm determines and is responsible for the legal sufficiency of its disclosures.

Telephone and SMS communications may also be subject to the Telephone Consumer Protection Act (TCPA). The law firm is responsible for the lawfulness of the calls and messages it initiates or directs through the Services, including consent and do-not-call obligations.

8. Voice and Biometric Considerations

The Services capture and process voice audio to operate the speech-to-text, language-detection, and text-to-speech features. CallGideon does not use voiceprints or other voice-derived identifiers to identify individuals, and does not create biometric templates for identification purposes.

Some state laws (such as biometric-privacy statutes of the “BIPA” type) impose notice and consent requirements where biometric identifiers are collected. Where any such requirement could apply to call audio, the law-firm customer, as controller, is responsible for providing required notice and obtaining consent; CallGideon assists as a processor.

9. How We Share and Disclose Information

We share information only as described below. We engage all third-party processors under written contracts requiring confidentiality and appropriate security, and BAAs/DPAs where they handle ePHI or personal data.

  • Within the law firm’s account — call data, recordings, transcripts, and extracted intake data are made available to authorized members of the firm’s CallGideon account.

  • Subprocessors / service providers — the infrastructure, AI, telephony, and integration providers listed in the “Subprocessors” section below, who process data on our behalf and only for the purposes we specify.

  • Legal and safety — when required by law, regulation, subpoena, court order, or to establish or defend legal claims, or to protect the rights, property, or safety of CallGideon, our customers, callers, or the public.

  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy or a successor policy; we will provide notice as required by law.

No Sale and No Targeted Advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (targeted advertising), as those terms are defined under the California Consumer Privacy Act/CPRA and similar U.S. state laws. We do not use Google API data, caller data, or ePHI for advertising.

We do use first-party analytics cookies (PostHog) and error/performance-monitoring cookies (Sentry) to operate, secure, and improve the Services. To the extent any such activity could be considered a “sale” or “share” of personal information under California law, you can opt out by enabling the Global Privacy Control (GPC) in your browser or by using the methods described in the “California Privacy Rights” and “Other U.S. State Privacy Rights” sections below. We honor GPC and similar browser-based opt-out preference signals as a valid opt-out of any sale or sharing.

10. Subprocessors

We rely on the following categories of subprocessors to deliver the Services. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs where applicable. All subprocessors operate under confidentiality and data-protection contracts.

  • Amazon Web Services (AWS) — cloud hosting, compute, storage, networking, secrets, and messaging (us-east-1).

  • Supabase — managed PostgreSQL database and dashboard authentication.

  • Vercel — hosting for the web dashboards and marketing site.

  • LiveKit — real-time WebRTC/SIP media rooms and recording egress.

  • Twilio — PSTN telephony, SIP trunking, and SMS.

  • OpenAI — large language model processing for the voice agent and post-call extraction.

  • Deepgram (primary) and AssemblyAI (alternate) — speech-to-text.

  • ElevenLabs (primary) and Cartesia (alternate) — text-to-speech.

  • Google — Calendar and Gmail integrations, only when a user connects a Google account.

  • OpenSign — e-signature of retainer and agreement documents.

  • Email and SMS delivery providers — transactional and follow-up message delivery.

We may engage additional or replacement subprocessors. For customers under a DPA, we maintain an up-to-date subprocessor list and provide notice of changes as required by the DPA. To request the current list, contact us at gideon@callgideon.com.

11. Sensitive Personal Information

The Services process sensitive personal information, including health/medical information (ePHI), precise contact details, and, where provided on a call, other special categories. We use sensitive personal information only for the purposes of providing the Services, performing our processor/Business Associate obligations, and the limited purposes permitted under applicable law (such as security, fraud prevention, and legal compliance).

We do not use or disclose sensitive personal information to infer characteristics about an individual, for advertising, or for any purpose other than those described in this Policy. California residents may direct us to limit the use of their sensitive personal information to permitted purposes (see the “California Privacy Rights” section below).

12. Google API Services — Limited Use Disclosure

CallGideon’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We specifically affirm the following with respect to data obtained through Google APIs (including Google Calendar and Gmail):

  • Purpose limitation: Google user data is used only to provide and improve the user-facing features within CallGideon that you enabled by connecting your Google account — Calendar data solely for scheduling, and Gmail data solely to surface email context and to send/read messages on your behalf.

  • No model training: We do not use Google user data to develop, improve, or train generalized or standalone AI/ML models. Any improvement is limited to the specific user-facing features you connected.

  • No sale: We do not sell, rent, lease, or otherwise monetize Google user data.

  • No advertising: We do not use Google user data to serve advertisements of any kind, including personalized, retargeted, or interest-based ads.

  • No unauthorized transfer: We do not transfer Google user data to third parties except as necessary to provide or improve the user-facing features (e.g., infrastructure providers under confidentiality obligations), for security purposes, to comply with applicable law, or as part of a merger/acquisition with adequate notice.

  • No human access: We do not allow humans to read your Google data unless (a) you give explicit consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.

You can revoke CallGideon’s access to your Google account at any time at Google Account Permissions. Revoking access disables Calendar and Gmail features but does not affect your core CallGideon account.

13. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy or as required by law or contract. Retention by category:

  • Account data: retained while the account is active; deleted within approximately 30 days of account deletion, subject to legal-hold exceptions.

  • Call recordings and transcripts: retained per the law firm’s configured settings; default retention is approximately 2 years, subject to legal hold.

  • Google Calendar and Gmail content: not persistently stored by CallGideon — used in-session to complete the requested action; messages sent on your behalf reside in your own Gmail.

  • Application and security logs: retained approximately 12 months.

  • HIPAA-required documentation: retained at least six years (45 CFR 164.316(b)(2)).

  • HR and financial records: retained approximately 7 years as required by law and tax/accounting obligations.

When retention periods expire, we delete or de-identify the information, except where a legal hold or ongoing legal obligation requires continued retention.

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident and CallGideon is the business (controller) for your information, you have the following rights, subject to verification and legal exceptions:

  • Right to know / access — the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients.

  • Right to delete — request deletion of personal information we collected from you.

  • Right to correct — request correction of inaccurate personal information.

  • Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, and we honor GPC signals; you may also direct any opt-out using the methods in this section.

  • Right to limit use of sensitive personal information — direct us to limit use of sensitive personal information to permitted purposes.

  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

How to exercise. Submit a request to gideon@callgideon.com. You may use an authorized agent to submit a request on your behalf, with proof of authorization and verification of your identity. We will acknowledge requests and respond within 45 days, with one permitted 45-day extension where reasonably necessary and with notice.

Appeals. If we deny your request, you may appeal by replying to our decision or emailing gideon@callgideon.com with “Privacy Appeal” in the subject line.

Opt-out preference signals. We honor the Global Privacy Control (GPC) and similar browser-based opt-out preference signals as a valid opt-out of sale/sharing for the corresponding browser or device.

15. Other U.S. State Privacy Rights

Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states in the 2023+ cohort — may have rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and certain profiling, subject to each state’s terms and exceptions. Several of these laws require opt-in consent before processing sensitive data; where CallGideon is the controller, we obtain consent where required, and where we are a processor we act on the law firm’s instructions.

How to exercise. Email gideon@callgideon.com. We will respond within the timeframe required by the applicable state law (generally 45 days, extendable as permitted). Where the law provides an appeal mechanism, you may appeal a denied request by emailing gideon@callgideon.com with “Privacy Appeal” in the subject line; if your appeal is denied, applicable law may permit you to contact your state Attorney General.

16. How to Exercise Your Rights and Request Routing

We route data-subject requests based on our role for the information at issue:

  • Caller intake data (CallGideon as processor / Business Associate): requests are routed to the law-firm customer (the controller / Covered Entity). If you contact us directly about call data, we will, where we can identify the relevant firm, forward your request and assist the firm in responding. We will not independently grant access to, correct, or delete a firm’s caller data except on the firm’s instruction or as required by law.

  • CallGideon’s own data (CallGideon as controller): we handle these requests directly, subject to identity verification.

Service levels. We aim to acknowledge requests promptly and respond within the timeframe required by applicable law — generally 45 days for U.S. state-law requests (extendable as permitted with notice). For requests we assist on as a processor, we cooperate with the law-firm controller within the timelines set by our DPA/BAA. To submit a request, email gideon@callgideon.com.

17. Cookies and Analytics

We and our service providers use cookies, local storage, and similar technologies to:

  • Maintain your authenticated session and security

  • Remember preferences (such as display settings)

  • Measure and analyze product usage and performance

We use PostHog for first-party product analytics and Sentry for error and performance monitoring; diagnostic and analytics data is configured to minimize and, where feasible, scrub or pseudonymize personal information. You can control cookies through your browser settings; disabling some cookies may affect functionality. We honor Global Privacy Control (GPC) signals as described in the “California Privacy Rights” section above. We do not use cookies for cross-context behavioral advertising.

18. Security and Breach Notification

We maintain a security program that is designed and operated in alignment with SOC 2 and ISO/IEC 27001, and operated as a HIPAA Business Associate (managed on the Sprinto continuous-compliance platform), with administrative, technical, and physical safeguards, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 / AWS KMS), plus field-level encryption of direct PII and ePHI identifiers

  • Database Row-Level Security (RLS) and tenant isolation; deny-by-default network security groups and private subnets (AWS us-east-1)

  • Organization-wide multi-factor authentication, least-privilege IAM with Access Analyzer, and SHA-256 hashing of API keys

  • CloudTrail audit logging, GuardDuty threat detection, S3 Block-Public-Access and server access logging, and point-in-time-recovery backups

These descriptions reflect our security practices, not held certifications or attestations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach, we will notify affected parties and regulators as required by applicable law. As a HIPAA Business Associate, we notify the affected Covered Entity of a breach of unsecured ePHI without unreasonable delay and no later than 60 days from discovery.

19. Children’s Privacy and Age

The Services are intended for legal professionals and businesses and are not directed to individuals under 18. We do not knowingly collect personal information from children, and the Services are not subject to the Children’s Online Privacy Protection Act (COPPA) in the ordinary course because they are a business-to-business product. If we learn we have collected personal information from a child under 18 other than through a law firm’s intake (for which the firm is responsible), we will delete it. Contact us at gideon@callgideon.com if you believe a child has provided us information.

20. International Data Transfers

CallGideon is based in the United States, and our infrastructure and processing occur primarily in the United States (AWS us-east-1). If you access the Services from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection laws than your jurisdiction.

21. GDPR / UK GDPR (Not Currently Applicable)

CallGideon currently operates only in the United States and does not have an establishment in, target individuals in, or monitor the behavior of individuals in the EU or UK. As a result, the EU General Data Protection Regulation (GDPR) and UK GDPR are not currently applicable to our processing. We monitor our footprint and will update this Policy and implement the corresponding obligations (such as appointing an Article 27 representative and providing transfer safeguards) if that changes.

22. Automated Processing and AI

The Services use AI to conduct intake conversations, transcribe and classify calls, and extract structured case data. These outputs are tools that support the law firm’s own review and decision-making.

CallGideon does not make solely automated decisions that produce legal or similarly significant effects about callers. Decisions about representation, case handling, and follow-up are made by the law firm, which provides human review and retains control over outcomes. Where an individual seeks human review of, or wishes to contest, a decision relating to intake, that request is directed to the law firm as controller; CallGideon assists as a processor.

23. Third-Party Links and Services

The Services may link to or integrate with third-party websites and services (for example, Google, Twilio, and LiveKit). This Policy does not govern those third parties. We encourage you to review the privacy policies of any third-party services you access through the Services.

24. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the “Effective Date” above and, where appropriate, provide additional notice (such as by email or an in-product notice). Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

Call Gideon Inc.

108 W. 13th Street, Suite 100, Wilmington, New Castle County, Delaware 19801, USA

General & Privacy contact: gideon@callgideon.com

CallGideon Privacy Policy

Effective Date: June 23, 2026

Call Gideon Inc. (“CallGideon,” “we,” “us,” or “our”) operates CallGideon, an AI voice-agent legal-intake platform for U.S. personal-injury law firms, available at callgideon.com. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with our websites, dashboards, voice agent, and related services (the “Services”).

This Policy is written primarily from the perspective of CallGideon acting as a controller (a “business” under California law) for the information we determine the purposes and means of processing — for example, information about our law-firm account users, website visitors, sales and marketing prospects, and billing contacts. For the caller intake data our voice agent collects during a call on behalf of a law-firm customer (including caller PII and injury/medical details), CallGideon acts as a data processor (“service provider”) and HIPAA Business Associate, and the law firm is the controller and HIPAA Covered Entity. The “Our Roles: Controller vs. Processor / Business Associate” section below explains this dual role in detail.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of the Services.

1. Scope of This Policy

This Policy applies to personal information processed through the CallGideon Services, including our marketing website, the web dashboards (web, cal, call, esign), the embeddable voice widget, the AI voice agent, and our backend platform. It applies to law-firm account users and administrators, individuals whose calls are handled by the voice agent (“callers”), website visitors, and sales, marketing, and billing contacts.

Because our role differs depending on whose information is involved, this Policy is organized so that you can identify the processing relevant to you. Where CallGideon is a processor / Business Associate (caller intake data), our handling is also governed by our contracts with the law firm — the Master Subscription Agreement, the Data Processing Addendum (DPA), and, where applicable, the Business Associate Agreement (BAA). Where those contracts conflict with this public Policy as to caller data, the contracts control.

CallGideon is a U.S. company with U.S.-only operations. We do not currently have an establishment in, target, or monitor individuals in the EU or UK. See the “International Data Transfers” and “GDPR / UK GDPR (Not Currently Applicable)” sections below.

2. Our Roles: Controller vs. Processor / Business Associate

CallGideon occupies two distinct data-protection roles, and it is important to understand which applies to a given category of information:

  • Caller intake data (processor / Business Associate). When our voice agent answers or places a call for a law-firm customer, we process the caller’s personal information and any injury or medical details (which constitute electronic protected health information, or “ePHI”) only on the documented instructions of the law firm. For this data, the law firm is the controller and HIPAA Covered Entity, and CallGideon is the processor / service provider and HIPAA Business Associate. We process this data under a DPA and, where ePHI is involved, a BAA.

  • CallGideon’s own data (controller). For information we collect and determine how to use — such as law-firm account users’ contact and login details, website-visitor analytics, sales and marketing prospect data, and billing contacts — CallGideon is the controller (“business”), and this Policy governs that processing directly.

Practical consequence for individual rights: if you are a caller and want to exercise rights over your intake data, your request is generally directed to the law firm that handled your call (the controller); CallGideon will assist that firm. If your information was processed by CallGideon as a controller, you may exercise your rights with us directly. See the “California Privacy Rights,” “Other U.S. State Privacy Rights,” and “How to Exercise Your Rights and Request Routing” sections below.

3. Categories of Information We Collect

3.1 Account and Billing Information

  • Name, email address, and password (login credentials) when an account is created

  • Organization/law-firm name, role, and team membership

  • Billing and payment contact details and subscription/plan information (card payments are handled by our payment processor; we do not store full card numbers)

3.2 Information Collected Automatically

  • Log data: IP address, browser type, pages and screens viewed, referring/exit pages, and timestamps

  • Device information: operating system and device identifiers

  • Usage data: features accessed, session duration, and interaction patterns

  • Cookies, pixels, and similar technologies (see the “Cookies and Analytics” section below), including first-party analytics (PostHog) and error/performance monitoring (Sentry)

3.3 Call Data (includes Sensitive Information / ePHI)

When our voice agent handles a call for a law firm, we process — as the firm’s processor and Business Associate — the following, which may include sensitive personal information and ePHI:

  • Call recordings (audio) and live and stored transcripts of the conversation

  • Caller PII: phone number, name, date of birth, and address (as provided on the call)

  • Injury and medical intake details, incident descriptions, insurance information, and other case facts — this is health information / ePHI and is treated as sensitive

  • Call metadata: duration, language detected, and case-type classification, and structured data extracted from the call by our post-call processing pipeline

3.4 Information from Google Services (Google API Data)

When a user chooses to connect a Google account, we request access only to the scopes needed to provide the features the user enabled:

  • openid, email, profile — Google account name, email address, and profile picture, used to identify the user in the platform.

  • Google Calendar (https://www.googleapis.com/auth/calendar) — used exclusively to schedule follow-up appointments and consultations within CallGideon.

  • Gmail Read (https://www.googleapis.com/auth/gmail.readonly) — used exclusively to surface relevant email-thread context in the platform and to read replies to emails sent on the user’s behalf.

  • Gmail Send (https://www.googleapis.com/auth/gmail.send) — used exclusively to send follow-up emails and post-call summaries on the user’s behalf; sent messages appear in the user’s own Gmail Sent folder.

Our use of Google API data is restricted to the user-facing features you enabled by connecting your Google account, and is not used to develop, improve, or train generalized AI/ML models. These commitments are detailed in the “Google API Services — Limited Use Disclosure” section below. We use gmail.readonly plus gmail.send (not the restricted gmail.modify scope).

4. Notice at Collection

This section provides a concise “Notice at Collection” under the California Privacy Rights Act (CPRA), mapping the categories of personal information we collect (as a business/controller) to the business purposes for which we use them and the categories of recipients to whom we disclose them. Caller intake data is handled on the law firm’s instructions as a processor/Business Associate and is not used by CallGideon for its own purposes; the law firm provides its own notice at collection to callers.

  • Identifiers and account data (name, email, password, organization, role) — Purpose: account creation and access management, authentication, communications, security, and billing. Recipients: cloud and database providers (e.g., AWS, Supabase), authentication and hosting providers, and email/SMS delivery providers.

  • Commercial / billing information (subscription, plan, billing contact) — Purpose: billing, payment processing, and account administration. Recipients: payment processor and accounting/financial-records providers.

  • Internet/network activity (log data, device information, usage data, cookies) — Purpose: security, integrity, troubleshooting, and product analytics. Recipients: first-party analytics provider (PostHog) and error/performance monitoring provider (Sentry).

  • Google account data (where connected: profile, Calendar, Gmail read/send) — Purpose: only the user-facing scheduling and email features you enabled; never for advertising or generalized ML model training. Recipients: Google and our infrastructure providers acting on our behalf under confidentiality obligations.

  • Caller intake data, including sensitive information / ePHI (recordings, transcripts, caller PII, injury/medical details) — Purpose: provide and operate the intake Services on the law firm’s documented instructions, as processor/Business Associate. Recipients: the law firm’s authorized account users and the subprocessors listed in the “Subprocessors” section below, engaged under BAAs/DPAs where they handle ePHI or personal data.

We retain each category for the periods described in the “Data Retention” section below. We do not sell your personal information and do not share it for cross-context behavioral (targeted) advertising, as further described in the “How We Share and Disclose Information” section below. For the rights available to you and how to exercise them, see the “California Privacy Rights” and “Other U.S. State Privacy Rights” sections below.

5. How We Use Information and Legal Bases

We use information for the following purposes. For caller intake data, the purposes are limited to the law firm’s documented instructions and the BAA/DPA; CallGideon does not use caller data for its own purposes.

  • Provide and operate the Services — handle intake calls, transcribe and record calls, extract structured case data, stream live transcripts, route and hand off calls to human staff, and book appointments and process e-signatures.

  • Account and access management — authenticate users, provision role-based access, and administer the law firm’s account.

  • Communications — send service, transactional, and (where permitted) follow-up communications by email and SMS; send marketing only to our own prospects/customers with the right to opt out.

  • Security, integrity, and troubleshooting — monitor performance, detect and prevent fraud and abuse, debug, and maintain reliability.

  • Improve the Services — analyze aggregated or de-identified usage; we do not use caller ePHI to train or improve models except as permitted by the BAA/DPA, and we do not use Google user data to develop, improve, or train generalized AI/ML models.

  • Legal and compliance — comply with legal obligations, enforce our terms, and establish, exercise, or defend legal claims.

Legal bases (as a controller). Where required, we rely on: performance of a contract (account and billing); our legitimate interests (security, product improvement, and B2B marketing), balanced against your rights; compliance with legal obligations; and your consent where applicable (e.g., certain cookies/analytics and connecting your Google account). You may withdraw consent at any time.

6. HIPAA, ePHI, and Business Associate Obligations

Injury and medical intake details captured on calls constitute ePHI. Where a law-firm customer (or a customer that is itself a HIPAA Business Associate) directs ePHI to the Services, CallGideon acts as a HIPAA Business Associate and executes a Business Associate Agreement (BAA) with that customer before ePHI is transmitted.

  • We use and disclose ePHI only as permitted by the BAA and the firm’s documented instructions, and as required by law.

  • We apply the HIPAA Security Rule safeguards described in the “Security and Breach Notification” section below (encryption, access controls, audit logging, field-level encryption of PII/ePHI).

  • We engage subprocessors that handle ePHI only under written agreements that impose equivalent BAA obligations, and we configure zero-/no-data-retention terms with AI providers where available (see the “Subprocessors” section below).

  • As a Business Associate, we will notify the affected Covered Entity of a breach of unsecured ePHI without unreasonable delay and no later than 60 days from discovery (45 CFR 164.410), and our subprocessor agreements require the same downstream chain.

  • We retain HIPAA-required documentation for at least six years as required by 45 CFR 164.316(b)(2).

The law firm, as Covered Entity, remains responsible for its own HIPAA obligations, including providing notices and obtaining authorizations from individuals where required.

7. Call Recording and AI-Voice Disclosure

CallGideon’s voice agent is an artificial-intelligence system, not a human, and calls handled through the Services may be recorded and transcribed. We do not deceive callers about the automated nature of the agent, and we make configurable AI-disclosure and recording-notice features available to law-firm customers.

Federal and state laws govern call recording and consent, including the Electronic Communications Privacy Act (ECPA) and state “one-party” and “two-party” (all-party) consent / wiretap statutes, as well as the Federal Trade Commission Act (Section 5) prohibition on deceptive practices. The law-firm customer, as the controller of the call, is responsible for providing required recording and AI disclosures and for obtaining any consent required in the relevant jurisdiction. CallGideon provides configurable disclosure and recording-notice features and supports the firm in meeting these obligations, but the firm determines and is responsible for the legal sufficiency of its disclosures.

Telephone and SMS communications may also be subject to the Telephone Consumer Protection Act (TCPA). The law firm is responsible for the lawfulness of the calls and messages it initiates or directs through the Services, including consent and do-not-call obligations.

8. Voice and Biometric Considerations

The Services capture and process voice audio to operate the speech-to-text, language-detection, and text-to-speech features. CallGideon does not use voiceprints or other voice-derived identifiers to identify individuals, and does not create biometric templates for identification purposes.

Some state laws (such as biometric-privacy statutes of the “BIPA” type) impose notice and consent requirements where biometric identifiers are collected. Where any such requirement could apply to call audio, the law-firm customer, as controller, is responsible for providing required notice and obtaining consent; CallGideon assists as a processor.

9. How We Share and Disclose Information

We share information only as described below. We engage all third-party processors under written contracts requiring confidentiality and appropriate security, and BAAs/DPAs where they handle ePHI or personal data.

  • Within the law firm’s account — call data, recordings, transcripts, and extracted intake data are made available to authorized members of the firm’s CallGideon account.

  • Subprocessors / service providers — the infrastructure, AI, telephony, and integration providers listed in the “Subprocessors” section below, who process data on our behalf and only for the purposes we specify.

  • Legal and safety — when required by law, regulation, subpoena, court order, or to establish or defend legal claims, or to protect the rights, property, or safety of CallGideon, our customers, callers, or the public.

  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy or a successor policy; we will provide notice as required by law.

No Sale and No Targeted Advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (targeted advertising), as those terms are defined under the California Consumer Privacy Act/CPRA and similar U.S. state laws. We do not use Google API data, caller data, or ePHI for advertising.

We do use first-party analytics cookies (PostHog) and error/performance-monitoring cookies (Sentry) to operate, secure, and improve the Services. To the extent any such activity could be considered a “sale” or “share” of personal information under California law, you can opt out by enabling the Global Privacy Control (GPC) in your browser or by using the methods described in the “California Privacy Rights” and “Other U.S. State Privacy Rights” sections below. We honor GPC and similar browser-based opt-out preference signals as a valid opt-out of any sale or sharing.

10. Subprocessors

We rely on the following categories of subprocessors to deliver the Services. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs where applicable. All subprocessors operate under confidentiality and data-protection contracts.

  • Amazon Web Services (AWS) — cloud hosting, compute, storage, networking, secrets, and messaging (us-east-1).

  • Supabase — managed PostgreSQL database and dashboard authentication.

  • Vercel — hosting for the web dashboards and marketing site.

  • LiveKit — real-time WebRTC/SIP media rooms and recording egress.

  • Twilio — PSTN telephony, SIP trunking, and SMS.

  • OpenAI — large language model processing for the voice agent and post-call extraction.

  • Deepgram (primary) and AssemblyAI (alternate) — speech-to-text.

  • ElevenLabs (primary) and Cartesia (alternate) — text-to-speech.

  • Google — Calendar and Gmail integrations, only when a user connects a Google account.

  • OpenSign — e-signature of retainer and agreement documents.

  • Email and SMS delivery providers — transactional and follow-up message delivery.

We may engage additional or replacement subprocessors. For customers under a DPA, we maintain an up-to-date subprocessor list and provide notice of changes as required by the DPA. To request the current list, contact us at gideon@callgideon.com.

11. Sensitive Personal Information

The Services process sensitive personal information, including health/medical information (ePHI), precise contact details, and, where provided on a call, other special categories. We use sensitive personal information only for the purposes of providing the Services, performing our processor/Business Associate obligations, and the limited purposes permitted under applicable law (such as security, fraud prevention, and legal compliance).

We do not use or disclose sensitive personal information to infer characteristics about an individual, for advertising, or for any purpose other than those described in this Policy. California residents may direct us to limit the use of their sensitive personal information to permitted purposes (see the “California Privacy Rights” section below).

12. Google API Services — Limited Use Disclosure

CallGideon’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We specifically affirm the following with respect to data obtained through Google APIs (including Google Calendar and Gmail):

  • Purpose limitation: Google user data is used only to provide and improve the user-facing features within CallGideon that you enabled by connecting your Google account — Calendar data solely for scheduling, and Gmail data solely to surface email context and to send/read messages on your behalf.

  • No model training: We do not use Google user data to develop, improve, or train generalized or standalone AI/ML models. Any improvement is limited to the specific user-facing features you connected.

  • No sale: We do not sell, rent, lease, or otherwise monetize Google user data.

  • No advertising: We do not use Google user data to serve advertisements of any kind, including personalized, retargeted, or interest-based ads.

  • No unauthorized transfer: We do not transfer Google user data to third parties except as necessary to provide or improve the user-facing features (e.g., infrastructure providers under confidentiality obligations), for security purposes, to comply with applicable law, or as part of a merger/acquisition with adequate notice.

  • No human access: We do not allow humans to read your Google data unless (a) you give explicit consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.

You can revoke CallGideon’s access to your Google account at any time at Google Account Permissions. Revoking access disables Calendar and Gmail features but does not affect your core CallGideon account.

13. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy or as required by law or contract. Retention by category:

  • Account data: retained while the account is active; deleted within approximately 30 days of account deletion, subject to legal-hold exceptions.

  • Call recordings and transcripts: retained per the law firm’s configured settings; default retention is approximately 2 years, subject to legal hold.

  • Google Calendar and Gmail content: not persistently stored by CallGideon — used in-session to complete the requested action; messages sent on your behalf reside in your own Gmail.

  • Application and security logs: retained approximately 12 months.

  • HIPAA-required documentation: retained at least six years (45 CFR 164.316(b)(2)).

  • HR and financial records: retained approximately 7 years as required by law and tax/accounting obligations.

When retention periods expire, we delete or de-identify the information, except where a legal hold or ongoing legal obligation requires continued retention.

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident and CallGideon is the business (controller) for your information, you have the following rights, subject to verification and legal exceptions:

  • Right to know / access — the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients.

  • Right to delete — request deletion of personal information we collected from you.

  • Right to correct — request correction of inaccurate personal information.

  • Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, and we honor GPC signals; you may also direct any opt-out using the methods in this section.

  • Right to limit use of sensitive personal information — direct us to limit use of sensitive personal information to permitted purposes.

  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

How to exercise. Submit a request to gideon@callgideon.com. You may use an authorized agent to submit a request on your behalf, with proof of authorization and verification of your identity. We will acknowledge requests and respond within 45 days, with one permitted 45-day extension where reasonably necessary and with notice.

Appeals. If we deny your request, you may appeal by replying to our decision or emailing gideon@callgideon.com with “Privacy Appeal” in the subject line.

Opt-out preference signals. We honor the Global Privacy Control (GPC) and similar browser-based opt-out preference signals as a valid opt-out of sale/sharing for the corresponding browser or device.

15. Other U.S. State Privacy Rights

Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states in the 2023+ cohort — may have rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and certain profiling, subject to each state’s terms and exceptions. Several of these laws require opt-in consent before processing sensitive data; where CallGideon is the controller, we obtain consent where required, and where we are a processor we act on the law firm’s instructions.

How to exercise. Email gideon@callgideon.com. We will respond within the timeframe required by the applicable state law (generally 45 days, extendable as permitted). Where the law provides an appeal mechanism, you may appeal a denied request by emailing gideon@callgideon.com with “Privacy Appeal” in the subject line; if your appeal is denied, applicable law may permit you to contact your state Attorney General.

16. How to Exercise Your Rights and Request Routing

We route data-subject requests based on our role for the information at issue:

  • Caller intake data (CallGideon as processor / Business Associate): requests are routed to the law-firm customer (the controller / Covered Entity). If you contact us directly about call data, we will, where we can identify the relevant firm, forward your request and assist the firm in responding. We will not independently grant access to, correct, or delete a firm’s caller data except on the firm’s instruction or as required by law.

  • CallGideon’s own data (CallGideon as controller): we handle these requests directly, subject to identity verification.

Service levels. We aim to acknowledge requests promptly and respond within the timeframe required by applicable law — generally 45 days for U.S. state-law requests (extendable as permitted with notice). For requests we assist on as a processor, we cooperate with the law-firm controller within the timelines set by our DPA/BAA. To submit a request, email gideon@callgideon.com.

17. Cookies and Analytics

We and our service providers use cookies, local storage, and similar technologies to:

  • Maintain your authenticated session and security

  • Remember preferences (such as display settings)

  • Measure and analyze product usage and performance

We use PostHog for first-party product analytics and Sentry for error and performance monitoring; diagnostic and analytics data is configured to minimize and, where feasible, scrub or pseudonymize personal information. You can control cookies through your browser settings; disabling some cookies may affect functionality. We honor Global Privacy Control (GPC) signals as described in the “California Privacy Rights” section above. We do not use cookies for cross-context behavioral advertising.

18. Security and Breach Notification

We maintain a security program that is designed and operated in alignment with SOC 2 and ISO/IEC 27001, and operated as a HIPAA Business Associate (managed on the Sprinto continuous-compliance platform), with administrative, technical, and physical safeguards, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 / AWS KMS), plus field-level encryption of direct PII and ePHI identifiers

  • Database Row-Level Security (RLS) and tenant isolation; deny-by-default network security groups and private subnets (AWS us-east-1)

  • Organization-wide multi-factor authentication, least-privilege IAM with Access Analyzer, and SHA-256 hashing of API keys

  • CloudTrail audit logging, GuardDuty threat detection, S3 Block-Public-Access and server access logging, and point-in-time-recovery backups

These descriptions reflect our security practices, not held certifications or attestations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach, we will notify affected parties and regulators as required by applicable law. As a HIPAA Business Associate, we notify the affected Covered Entity of a breach of unsecured ePHI without unreasonable delay and no later than 60 days from discovery.

19. Children’s Privacy and Age

The Services are intended for legal professionals and businesses and are not directed to individuals under 18. We do not knowingly collect personal information from children, and the Services are not subject to the Children’s Online Privacy Protection Act (COPPA) in the ordinary course because they are a business-to-business product. If we learn we have collected personal information from a child under 18 other than through a law firm’s intake (for which the firm is responsible), we will delete it. Contact us at gideon@callgideon.com if you believe a child has provided us information.

20. International Data Transfers

CallGideon is based in the United States, and our infrastructure and processing occur primarily in the United States (AWS us-east-1). If you access the Services from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection laws than your jurisdiction.

21. GDPR / UK GDPR (Not Currently Applicable)

CallGideon currently operates only in the United States and does not have an establishment in, target individuals in, or monitor the behavior of individuals in the EU or UK. As a result, the EU General Data Protection Regulation (GDPR) and UK GDPR are not currently applicable to our processing. We monitor our footprint and will update this Policy and implement the corresponding obligations (such as appointing an Article 27 representative and providing transfer safeguards) if that changes.

22. Automated Processing and AI

The Services use AI to conduct intake conversations, transcribe and classify calls, and extract structured case data. These outputs are tools that support the law firm’s own review and decision-making.

CallGideon does not make solely automated decisions that produce legal or similarly significant effects about callers. Decisions about representation, case handling, and follow-up are made by the law firm, which provides human review and retains control over outcomes. Where an individual seeks human review of, or wishes to contest, a decision relating to intake, that request is directed to the law firm as controller; CallGideon assists as a processor.

23. Third-Party Links and Services

The Services may link to or integrate with third-party websites and services (for example, Google, Twilio, and LiveKit). This Policy does not govern those third parties. We encourage you to review the privacy policies of any third-party services you access through the Services.

24. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the “Effective Date” above and, where appropriate, provide additional notice (such as by email or an in-product notice). Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

Call Gideon Inc.

108 W. 13th Street, Suite 100, Wilmington, New Castle County, Delaware 19801, USA

General & Privacy contact: gideon@callgideon.com