Hala AIHala AI
Home•Pricing•Industries•Blog•Company•Contact
LoginStart free trialStart free
Hala AIHala AI
  • 01Home
  • 02Pricing
    • Industries
    • Dental
    • Salons & spas
    • Restaurants
    • Hotels
    • Real estate
    • Law firms
    • E-commerce
    • Education
    • Auto service
    • Insurance
  • 04Blog
  • 05Company
  • 06Contact
Start free trialLogin
EnglishالعربيةTürkçe
Turn your network into recurring income

Know businesses that could benefit from Hala AI? Bring them onboard and earn commission from the customers you refer while they remain eligible paying customers.

Join & Start Earning
Hala AIHala AI

Always here. Always Hala.

MetaMeta Verified Tech Provider

Product

  • Home
  • Pricing
  • Industries
  • Blog
  • Company
  • Contact

Industries

  • Dental
  • Salons & spas
  • Restaurants
  • Hotels
  • Real estate
  • Law firms
  • E-commerce
  • Education
  • Auto service
  • Insurance

Company

  • Company
  • Partners
  • Contact
  • Login
  • Sign up

Legal

  • Privacy policy
  • Cookie policy
  • Terms of service
  • Refund policy
  • Security
  • Delete account
© 2026 Hala AI. Built for MENA and Turkey.KSA · UAE · TR · EG · QA · KW · BH
Hala AI
LegalPrivacy Policy

Privacy Policy

We believe privacy is a fundamental right. Our systems are built from the ground up with a "privacy-by-design" architecture to ensure your organizational data remains yours alone.

Last updated: Oct 6, 2026
info@halaai.app

Contents

  • 1. Information We Collect
  • 2. How We Use Your Data
  • 3. Data Storage & Security
  • 4. Healthcare & sensitive data
  • 5. Google Calendar data
  • Bot protection
  • The Hala AI mobile app
  • Payments and subscriptions
  • Uploaded content and recordings
  • Error monitoring and analytics
  • Subprocessors
  • 5. Controller & processor roles
  • 7. Regional data protection
  • 6. Your rights
  • How long we keep data
  • How to request data deletion

On this page

  • Data Collection
  • Data Usage
  • Security Protocols
  • Healthcare data
  • Google Calendar data
  • Bot protection
  • Mobile app
  • Payments
  • Uploads and recordings
  • Monitoring and analytics
  • Subprocessors
  • Roles
  • Regional data protection
  • Your rights
  • Retention
  • Data deletion

1. Information We Collect

Hala AI collects only the minimum necessary information required to provide our enterprise AI services. This includes:

  • Account Information: Name, professional email, organizational role, and your business details such as business name, phone number, city and country.
  • Interaction Data: Transcripts of AI-driven voice or text interactions.
  • Metadata: IP addresses and device identifiers for security logging. In the mobile app, also the push notification token, app version and operating system version.

2. How We Use Your Data

“Your data is used only to operate and support your assistant. We never sell, rent, or lease your private data, and Hala AI does not use it to train or improve AI models.”

Usage is limited to processing requests to operate your assistant, maintaining the quality and reliability of the service, and providing technical support upon request. Data obtained through connected Google services is used only to operate the relevant feature (such as calendar scheduling), and Hala AI never uses it to train, develop, or improve any machine-learning or AI model. We use carefully selected AI service providers for language, speech recognition and voice. We have configured them so your data is not used to train their models.

3. Data Storage & Security

Encrypted at Rest & In Transit

All call recordings and transcriptions are encrypted using AES-256 standards. Keys are managed through HSM-backed services to ensure maximum isolation.

4. Healthcare & sensitive data

Hala AI does not use customer conversation content to train, develop, or improve any AI model. It is processed only to operate your AI assistant. We use carefully selected AI service providers for language, speech recognition and voice. We have configured them so your data is not used to train their models.

5. Google Calendar data

When you connect a Google account, Hala AI requests access to your Google Calendar to provide appointment booking:

  • We use the calendar.events.freebusy scope to read your availability so the assistant offers only open time slots and avoids double-booking.
  • We use the calendar.events scope to create, update, cancel, and read appointments booked through Hala AI.

We access this data only to provide these scheduling features. We do not sell it, and we do not share it with third parties except as needed to operate the service (for example, our hosting providers).

Hala AI never uses Google user data to train, develop, or improve any machine-learning or AI model, including foundational models. You can disconnect your Google account at any time from your dashboard, which revokes Hala AI's access.

Hala AI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

AI service providers

Hala AI uses the following third-party AI services to operate your assistant. Hala AI does not use Google user data (raw, aggregated, anonymised, or derived) to create, train, or improve any AI or machine-learning model, and our AI providers receive it only to operate your assistant. We use carefully selected AI service providers for language, speech recognition and voice. We have configured them so your data is not used to train their models.

  • A language model generates the assistant's replies. When a caller asks about availability or to book, reschedule, or cancel an appointment, calendar availability is provided to the model at request time so it can offer real open times and avoid double-booking.
  • A text-to-speech service converts the assistant's reply to speech. The text it receives may include appointment times derived from calendar data.
  • A speech recognition service transcribes inbound caller audio. It receives no Google Calendar data.
  • An embeddings service generates vectors used only to search the business's own knowledge base. It receives no Google Calendar data.
  • A real-time audio service provides audio transport and turn detection. It receives no Google Calendar data.

Models we run ourselves

Two models run entirely inside our own infrastructure: a voice activity detector and a conversational turn detector. Their weights are included in our server image and executed on our own servers. Audio processed by them is never transmitted to the model provider, and is never used for training or any other secondary purpose.

Bot protection

To protect our demo and forms from automated abuse, we use a bot-protection service that checks that a visitor is human. It processes limited client-side signals, such as IP address, browser and device characteristics (including TLS fingerprint and user-agent), and the page's site key, solely to distinguish humans from bots. We do not use these signals to identify, profile, or track you.

The Hala AI mobile app

The Hala AI mobile app brings the Hala AI dashboard to your phone, with app features such as push notifications and Google Play subscriptions. It opens halaai.app inside the app, so your data is processed the same way as when you use the website. The app adds the points below.

  • Push notifications: If you allow notifications, the app sends a device token from the push notification service of your device platform to our servers, with the app version, the operating system version and your language. We use it only to send notifications to your device. The token is removed when you sign out and when your account is deleted. We use that service only for notifications, and the app does not use it for analytics.
  • Device access: The app does not request access to your location, contacts, camera or microphone, and it does not use the advertising ID.

Payments and subscriptions

How you pay depends on where you subscribe.

  • Android app (Google Play): Subscriptions bought in the Android app are paid through Google Play Billing. Google processes the payment. We use a subscription management service to receive the status of your subscription. It receives your purchase and subscription data and an app user ID, which is your organization's ID in Hala AI.
  • Website (halaai.app): Payments on the website are processed by our payment processors. For automatic card renewals with one of them we keep a saved-card token, the card brand and a masked card number, never the full card number.
  • Refunds: Refunds for purchases made through Google Play are handled by Google under Google Play's refund rules. Refunds for payments made on the website follow our Refund Policy.

Uploaded content and recordings

You and your customers can add files and recordings to your account. We store them for you and show them back to you in the app and the dashboard.

  • Files: Knowledge base documents, images, email attachments, receipts, customer note attachments and your logo, plus media that customers send you in chat.
  • Call recordings and voice notes: Call recordings are stored for your account and can be played back in the app and the dashboard. Voice notes that visitors send through your website chat are deleted automatically after 3 days. The Hala AI app itself never records audio.
  • Deletion: All of this is deleted when your account is deleted. See Data deletion below.

Error monitoring and analytics

We use the tools below to keep the service working and to understand how it is used.

  • Errors and performance: When something fails or runs slowly, our error monitoring tool receives technical details such as the page address, browser and device details and your IP address. It runs on the website, in the app and on our servers.
  • Session replay: On the web app, including inside the mobile app, our error monitoring tool also records a replay of how pages were used, so we can reproduce bugs. We record 10% of sessions at random, and every session in which an error happens. Replays mask all text and form fields and block images and media, so what you type and what is shown on screen cannot be read in them.
  • Website analytics: When you use halaai.app in a web browser, we use website analytics and advertising measurement tools to measure how the site is used and how our advertising performs.
  • In the app: The mobile app does not load our website analytics or advertising measurement tools.

When you use halaai.app in a web browser, we use analytics and advertising measurement tools, and an error monitoring tool. These tools may set cookies or similar identifiers. See our Cookie Policy for the list. You can control cookies through your browser settings.

5. Subprocessors

We use the categories of service providers below to run the service. Which of them handle your data depends on the features and channels you use:

  • Cloud hosting and database: Hosts the website and dashboard and the database that holds your account data, conversations, files and call recordings. Processes requests and request logs. Region: India, with some background processing in the European Union.
  • AI language processing: AI language models that write replies in chats, comments and voice calls, describe images and power search over your knowledge base. They receive the conversation text and the business details needed to answer.
  • Speech and voice processing: Speech recognition, text-to-speech and real-time audio for voice calls and in-browser voice sessions, the service that runs the voice agent during calls, and transcription of audio notes. They receive call audio and the text to be spoken.
  • Payment processing: Card and subscription payments and renewals on the website, manual bank-transfer options, and purchase and subscription status for subscriptions bought through Google Play (the status service receives your organization ID as the user ID).
  • Messaging channel providers: The platforms for the channels you connect, such as WhatsApp, Instagram, Messenger, Telegram and TikTok comments, and the connection services that relay them. They receive the messages and comments sent through those channels.
  • Telephony and text messaging: Phone numbers, call routing and text messages, including numbers you connect yourself.
  • Email delivery: Sending of transactional and notification emails. Receives recipient addresses and message content.
  • Error monitoring: Error and performance monitoring, with session replay on the web app. Receives the page address, device details and IP address.
  • Analytics and advertising measurement: Website analytics and advertising measurement when you use halaai.app in a web browser (not loaded in the mobile app). Contact details used for advertising measurement are hashed before they are sent.
  • Push notifications: Delivers notifications to your device through the push service of your device platform. Receives your device token and the notifications we send.
  • Calendar and sign-in integrations: Sign in with Google and, when you connect them, Google Calendar, Google Business Profile and Google Sheets.
  • Automation, queues and bot protection: Scheduled background jobs, rate limiting, caching, job queues and bot protection on forms.

A list of the specific providers is available to customers on request at info@halaai.app.

5. Controller & processor roles

For your Hala account (business profile, billing, staff users), Hala AI acts as the data controller.

For end-customer conversations processed through your connected channels, Hala acts as a processor on your behalf. You remain responsible for lawful bases and notices to your customers.

7. Regional data protection

We design our workflows with regional data-protection expectations in mind. Cross-border transfers use encryption in transit and at rest plus DPAs with subprocessors. You may exercise the data-subject rights in Your Rights below, including access, correction, and deletion, or contact info@halaai.app.

6. Your rights

1

Right to Access

You may request a copy of all data we hold regarding your organization.

2

Right to Erasure

Request permanent deletion of interaction logs and account metadata.

3

Right to Object

Opt-out of specific data processing activities that are not core to service delivery.

How long we keep data

We keep your data while your account is active. After deletion:

  • Account owner: access ends and a web subscription is cancelled at once. The organization and all its data, including recordings and uploaded files, are permanently deleted after 30 days, except billing records (see below). Until then we can restore the account if you ask.
  • Team member: login and profile are deleted at once. The organization keeps the records it created.
  • Website visitor voice notes: deleted automatically after 3 days, whether or not the account is deleted.
  • Other parties: payment providers, Google (for Google Play purchases) and our monitoring and analytics tools keep their own records under their own rules. Deleting your account does not remove those records.
  • Billing records: after deletion we keep a copy of invoices and subscription history for about 7 years, as tax and accounting law requires. It has the organization name, amounts, dates, plans and payment provider, and no personal data such as email, phone, address or card details.

How to request data deletion

You can delete your Hala AI account in the app or by email:

  1. In the app: the account owner opens Dashboard > Settings > Danger Zone > Delete account. Access ends immediately, and the organization is permanently deleted after 30 days. A team member can delete their own login and profile right away from the same section.
  2. Permanent deletion removes the organization's data, conversation transcripts, call recordings, uploaded files and connected-channel data, along with the login accounts and profiles of its members.
  3. By email: write to info@halaai.app from the address on your account with the subject "Data deletion request". We confirm your identity, delete the account the same way, and email you when deletion is complete.

Deleting your account cancels a web subscription at once. It does not cancel a subscription bought through Google Play: cancel that in Google Play first.

Full steps, and what we delete and keep, are on our account deletion page. Open the account deletion page

You can also disconnect any linked channel (Facebook, Instagram, WhatsApp, Google) at any time from Dashboard > AI Config > Integrations. Disconnecting revokes our access to that channel immediately.

Need a Data Processing Agreement?

Our legal team can provide standard DPAs for enterprise clients.

Contact Privacy Team

Have more questions about how we protect your data?

Contact Privacy TeamRead Terms of Service