1. Data Controller
The data controller for PollyReach is:
- Company: phoneai
- Contact Email: privacy@phoneai.tech
2. Information We Collect
2.1 Information You Provide
- Account information: email, password (encrypted), display name
- API credentials and tokens for access
- Phone numbers for making and receiving calls
- Call transcripts, recordings, and summaries
- Payment information: transaction amounts, payment status. We do not store complete card numbers — card data is processed by our payment processor (see Section 5).
2.2 Information We Automatically Collect
- Device and network: IP address, device model, operating system, browser type, timezone
- Usage data: page views, feature usage, operation logs, session duration
- Log data: request timestamps, error logs, performance data
3. How We Use Your Information
| Purpose |
Legal Basis |
| Service delivery and maintenance |
Contract performance |
| Billing and payment processing |
Contract performance |
| Customer support |
Contract performance / Legitimate interest |
| Service notifications (billing, security, policy updates) |
Legitimate interest |
| Security and fraud prevention |
Legitimate interest |
| Product optimization and analytics |
Legitimate interest |
| Legal compliance |
Legal obligation |
4. Cookies and Tracking
| Type |
Purpose |
Can Be Disabled |
| Strictly Necessary |
Maintain login, core functionality |
No |
| Functional |
Language preferences, personalized settings |
Yes |
| Analytics |
Anonymous usage statistics, product optimization |
Yes |
5. Data Sharing and Disclosure
We do not sell your personal information. We only share information in the following circumstances:
- Service Providers: Cloud computing, payment processing, customer support, analytics — bound by confidentiality agreements.
- Payment Processing: Card data is exclusively processed by our PCI-DSS compliant payment processor Waffo Pancake and Creem as Merchant of Record. Card data is never stored on our servers.
- Legal Requirements: In response to lawful requests from courts, law enforcement, or regulatory authorities.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with advance notice and protection obligations.
- With Your Consent: For any other purposes, only with your explicit prior consent.
6. Data Security
- Transmission Encryption: TLS/HTTPS
- Storage Security: Passwords and sensitive data are encrypted or hashed
- Access Control: Principle of least privilege; employees sign confidentiality agreements
- Regular Security Audits: Periodic vulnerability scans and security reviews
In the event of a security breach affecting your rights, we will notify you within 72 hours of discovery in accordance with applicable data protection regulations.
7. Data Retention
| Data Type |
Retention Period |
Disposal |
| Account information |
During active period; 90 days after account deletion |
Delete or anonymize |
| Transaction records |
As required by law (typically 7 years) |
Archive or delete |
| Call recordings/transcripts |
90 days |
Secure deletion |
| Support records |
2 years |
Secure deletion |
8. Your Data Rights
To exercise your rights, contact us. We will respond within 30 calendar days.
- Right to Access: Learn what data we collect and how we use it
- Right to Access: Obtain a copy of your personal data
- Right to Correction: Correct inaccurate or incomplete information
- Right to Deletion: Request data deletion under specific conditions
- Right to Restrict Processing: Pause data processing under certain circumstances
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests or marketing
- Right to Withdraw Consent: Withdraw consent for processing based on consent
If you believe we have not properly handled your data, you have the right to lodge a complaint with your local data protection authority.
9. International Data Transfers
Our servers and partners may be located in the United States, Singapore, and other regions. When data is transferred internationally, we protect it through:
- Data processing agreements incorporating Standard Contractual Clauses (SCCs)
- Transfers only to recipients with equivalent protection levels
- Other adequacy mechanisms as applicable
10. Children's Privacy
PollyReach is intended for users who are at least 18 years old. We do not knowingly collect personal information from individuals under 18. If you believe your child has provided us with information, please contact us immediately at privacy@phoneai.tech, and we will promptly delete such information.
11. Third-Party Links
Our service may contain links to or integrate with third-party services. This Privacy Policy applies only to information we directly collect. We are not responsible for third-party data practices, and we recommend reviewing their policies before use.
12. Policy Changes
We may update this Privacy Policy from time to time. We will notify you of material changes at least 15 days in advance through email notification or platform announcements. Continued use of the service after the effective date constitutes acceptance of the updated policy.