Privacy Policy
1. Data Controller and Contact Information
1.1 Data Controller
The data controller within the meaning of Regulation (EU) 2016/679 (GDPR) is: Good Point GmbH, Liechtensteinstrasse 63/10, 1090 Vienna, Austria. Company Register No.: FN 618845t (Commercial Court of Vienna). VAT ID: ATU80258169. Email: legal@hanc.ai. Web: hanc.ai
1.2 Privacy Contact
For questions regarding data protection: datenschutz@hanc.ai. Mail: Good Point GmbH, Attn: Data Protection, Liechtensteinstrasse 63/10, 1090 Vienna, Austria.
1.3 Scope
This Privacy Policy applies to: (a) the website hanc.ai, (b) the platform app.hanc.ai, (c) all related services, APIs, and integrations.
1.4 Legal Framework
GDPR, Austrian DSG 2018, German BDSG, German TDDDG, Swiss FADP, EU AI Act, CCPA/CPRA, UAE PDPL.
2. Processing Activities Summary
The following provides a high-level overview of our data processing activities. Detailed information is provided in the sections below.
- Website visits: IP address (anonymized), browser, pages visited, referrer. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Retention: 90 days.
- Contact form / email: Name, email, company, message content. Legal basis: Contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)). Retention: 6 months after resolution.
- Account creation: Name, email, company, industry, address. Legal basis: Contract (Art. 6(1)(b) GDPR). Retention: Duration of account + 7 years.
- Agent configuration: Business name, services, hours, greetings, industry. Legal basis: Contract (Art. 6(1)(b) GDPR). Retention: Duration of account.
- Voice calls: Caller number, call metadata, audio (if recording enabled), transcripts. Legal basis: Contract (Art. 6(1)(b)) + legitimate interest (Art. 6(1)(f)). Retention: 30 days default (customer-configurable).
- Payment processing: Payment method (via Stripe), plan type, invoices. Legal basis: Contract (Art. 6(1)(b) GDPR). Retention: 7 years (Austrian BAO § 132).
- Analytics: Feature usage, session data, performance metrics. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Retention: 26 months.
- Marketing / Newsletter: Email, name, preferences. Legal basis: Consent (Art. 6(1)(a) GDPR). Retention: Until withdrawal of consent.
3. Principles of Data Processing
3.1 Data Minimization
We collect personal data only to the extent necessary for the purposes described. Processing is purpose-bound (Art. 5(1)(b) and (c) GDPR).
3.2 Storage Limitation
Personal data is stored only as long as necessary or as required by statutory retention obligations.
3.3 Data Security
We implement appropriate technical and organizational measures (Art. 32 GDPR).
4. Processing When Visiting the Website
4.1 Server Log Files
When visiting our website, we collect: IP address (anonymized), date/time, URL, data volume, HTTP status, browser, OS, referrer. Legal basis: Art. 6(1)(f) GDPR. Retention: 30 days.
4.2 Contact via Email
Data collected: email address, name, company, content, date/time. Legal basis: Art. 6(1)(b) or (f) GDPR. Retention: 6 months after inquiry resolved.
4.3 Contact Form
Same as email, plus topic selection and GDPR consent timestamp. HubSpot as processor (DPA in place).
4.4 Newsletter
If applicable: email, name, company. Double opt-in required. Brevo (Sendinblue) as processor. Unsubscribe link in every email. Legal basis: Art. 6(1)(a) GDPR.
5. Processing When Using the Platform
5.1 Registration
Data collected: email, password (hashed), name, company name, industry, business address. Legal basis: Art. 6(1)(b) GDPR.
5.2 Agent Configuration
Data collected: business name, services, working hours, greeting text, industry category. Purpose: agent creation and operation.
5.3 Billing
Stripe as payment processor. We store: plan type, billing cycle, invoice history. Stripe stores: payment method details (PCI DSS Level 1). Legal basis: Art. 6(1)(b) GDPR.
5.4 Usage Analytics
PostHog for business intelligence. Data: feature usage, session data, agent performance metrics. Legal basis: Art. 6(1)(f) GDPR.
5.5 Demo Callback Service
When you request a demo callback, we process your phone number solely for the purpose of initiating a single demonstration call from our AI voice agent. Legal basis: Your explicit consent (Art. 6(1)(a) GDPR). Data processed: phone number in E.164 format. Retention: automatically deleted within 24 hours. Sub-processor: Twilio Inc. (US), pursuant to Standard Contractual Clauses. AI disclosure per EU AI Act Art. 50.
6. Processing of Voice Calls and AI Interactions
6.1 Call Data
We process: caller phone number, call timestamp, call duration, agent ID, call outcome. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest).
6.2 Voice Data
Real-time speech-to-text processing via Azure (EU region). Voice audio is processed in memory and not persistently stored unless call recording is enabled by the customer.
6.3 Call Recordings
Optional, controlled by customer. Stored encrypted in Azure EU. Retention: customer-defined (default 90 days). The customer is responsible for compliance with local call recording laws.
6.4 AI Processing
Conversation data processed by Azure OpenAI (EU region). No training on customer data. Data processed according to Microsoft DPA.
6.5 Transcripts
Stored encrypted. Accessible to customer via dashboard. Retention: customer-defined.
6.6 EU AI Act (Art. 50)
Callers are informed that they are speaking with an AI system at the start of each call.
7. Cookies and Similar Technologies
7.1 Essential Cookies
Session management, authentication, language preference. No consent required (TDDDG Section 25(2)).
7.2 Analytics Cookies
PostHog (self-hosted / EU). Consent required (TDDDG Section 25(1)). Cookie banner with opt-in.
7.3 Marketing Cookies
None at launch. If added: consent required, listed in cookie banner.
7.4 Cookie Banner
Consent management platform. Granular opt-in/opt-out. Consent stored for 12 months. Withdrawal possible at any time.
7.5 Cookie List
- hanc_session: Session management — maintains user session state. Duration: Session. Type: Essential.
- hanc_locale: Language preference — stores selected interface language. Duration: 1 year. Type: Essential.
- hanc_consent: Cookie consent state — records consent choices. Duration: 1 year. Type: Essential.
- _ph_*: PostHog analytics — tracks anonymized usage patterns. Duration: 1 year. Type: Analytics.
- _hs*: HubSpot tracking — enables CRM integration. Duration: 13 months. Type: Marketing.
- stripe_*: Payment processing — supports secure Stripe sessions. Duration: Session. Type: Essential.
8. Third-Party Services and Data Transfers
We use the following sub-processors:
- Microsoft (Azure): Cloud hosting, LLM, STT, TTS. Location: Dublin, Ireland / USA. Purpose: Infrastructure, AI processing. Safeguard: EU hosting (Azure West Europe), Art. 28 DPA, EU-US DPF.
- LiveKit Inc.: Real-time voice / WebRTC. Location: San Jose, USA. Purpose: Call infrastructure. Safeguard: Art. 46(2)(c) SCCs, EU relay servers.
- Twilio: Telephony (SIP/PSTN). Location: Dublin, Ireland / USA. Purpose: Phone calls. Safeguard: EU hosting, Art. 28 DPA, EU-US DPF.
- ElevenLabs Inc.: TTS/STT (optional). Location: New York, USA. Safeguard: Art. 46(2)(c) SCCs.
- Cartesia AI, Inc.: TTS/STT (optional). Location: San Francisco, USA. Safeguard: Art. 46(2)(c) SCCs.
- PostHog Inc.: Analytics. Location: San Francisco, USA. Safeguard: EU self-hosted option, Art. 46(2)(c) SCCs.
- HubSpot Ireland Ltd: CRM. Location: Dublin, Ireland. Safeguard: EU hosting, Art. 28 DPA.
- Brevo (Sendinblue SAS): Email. Location: Paris, France. Safeguard: EU hosting, Art. 28 DPA.
- Stripe Payments Europe Ltd: Payments. Location: Dublin, Ireland. Safeguard: PCI DSS Level 1, EU hosting.
9. Your Rights as a Data Subject
Under the GDPR, you have the following rights: Right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), right to withdraw consent (Art. 7(3)), and the right to lodge a complaint with a supervisory authority (Art. 77).
Contact: datenschutz@hanc.ai
Supervisory authority: Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at
10. Data Retention Periods
- Server log files: 30 days (legitimate interest).
- Contact form inquiries: 6 months after resolution (contract/legitimate interest).
- Account data: Duration of contract + 7 years (contract + Austrian BAO § 132).
- Billing / invoices: 7 years (Austrian BAO § 132).
- Call recordings: Customer-defined, default 90 days (contract performance).
- Call transcripts: Customer-defined, default 90 days (contract performance).
- Analytics data: 26 months (legitimate interest).
- Cookie consent records: 12 months (TDDDG).
11. International Data Transfers and Compliance
11.1 GDPR (EU/EEA)
Primary compliance framework. All data hosted in EU (Azure West Europe).
11.2 Austrian DSG 2018
Additional national provisions for Austria.
11.3 German BDSG
Additional provisions for German users.
11.4 Swiss FADP
Compliance for Swiss users. Data adequacy recognized by EU.
11.5 EU AI Act
Art. 50 transparency obligations. Caller notification at call start.
11.6 CCPA/CPRA (California)
No sale of personal information. Right to know, delete, opt-out. Contact: privacy@hanc.ai with subject "CCPA Request".
11.7 PDPL (UAE/Saudi Arabia)
Compliance for Gulf region users. Arabic-language notice provided for AR locales.
12. Data Security
- Encryption: TLS 1.3 in transit, AES-256 at rest.
- Access control: Role-based, multi-factor authentication for admin access.
- Infrastructure: Azure West Europe with geo-redundancy.
- Monitoring: Automated threat detection, intrusion detection systems.
- Incident response: 72-hour notification per Art. 33 GDPR.
- Certifications pending: SOC 2 Type II, ISO 27001.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users and through a prominent notice on our website. The date of the most recent revision is indicated at the top of this policy.