Privacy Policy
Last updated: [[EFFECTIVE_DATE]]
1. Who we are
[[LEGAL_ENTITY_NAME]], company number [[COMPANY_REG_NUMBER]], of [[REGISTERED_ADDRESS]] ("Noa", "we", "us"), operates an AI voice-agent platform that answers telephone calls on behalf of businesses.
This policy explains what personal data reaches us, why, who it goes to, and what rights you have. It is written to describe the system as it actually operates — not as we would like it to. Where a control does not yet exist, we say so rather than imply otherwise.
2. Two capacities — a distinction that matters
Noa holds two materially different positions with respect to personal data:
(a) Noa as Controller. For website visitors, people who submit our contact form, and authorized users of our console, we determine the purposes and means of processing. This policy applies to you directly.
(b) Noa as Processor. For the personal data of callers who dial our customers' phone lines, the business operating that line is the Controller, and we process on its documented instructions under our agreement with it. If you called a business that uses Noa and wish to exercise a right, your request goes first to that business — see Section 8.
3. What data reaches us
3.1 Data collected on this website
The demo request form collects: name, work email address, phone number, company name, and estimated monthly call volume. The newsletter field collects an email address only. We use this solely to respond to your enquiry and manage the resulting business relationship.
This website sets no cookies, runs no analytics, and contains no tracking pixels or third-party trackers of any kind. Fonts are served from our own origin and generate no third-party request when you browse. The only item stored in your browser is your interface language preference (noa-locale), for functional purposes.
Providing this information is voluntary and not required by law. Without it we cannot reply to you.
3.2 Data processed during telephone calls (our Processor capacity)
When a Noa voice agent handles a call on a business customer's behalf, the system processes:
- Phone numbers of the caller and the called line, plus technical call metadata (time, duration,
status, direction);
- Live call audio, in real time, to recognize speech and generate a spoken response;
- A recording of the call, retained in our storage;
- A full transcript of both sides;
- An automated summary, together with analysis covering sentiment, discussion topics and
follow-up actions;
- An estimate of the speaker's gender, derived from the audio by a classifier that runs inside our
own infrastructure. It serves one narrow linguistic purpose — selecting the correct Hebrew grammatical form of address — and is not used for segmentation, scoring, or any decision about the caller.
All calls handled through the platform are recorded and transcribed. Responsibility for informing callers of this — by announcement, disclosure at the start of the call, or otherwise — rests with the business operating the line, under our Terms of Use. The system does not currently play an automated recording notice, and we do not present one as an existing safeguard.
3.3 Data in connected systems
A business customer may connect its own systems to Noa — for example a CRM or a mailbox. Where it does, we access data in those systems only within the permissions that customer granted and only when performing an action it configured. Credentials for those systems are stored encrypted.
4. Why we process it
| Purpose | Basis |
|---|---|
| Delivering the service — answering calls, routing, performing actions | Performance of our contract with the business customer |
| Recording, transcription, summarization and analysis | The business customer's instruction, as part of the service it purchased |
| Responding to website enquiries and managing the relationship | Your consent when you submit the form, and our legitimate business interest |
| Security, fault diagnosis and abuse prevention | Legitimate interest in protecting the service and its users |
| Meeting legal obligations | Legal obligation |
We do not sell personal data, do not trade in it, and do not share it with third parties for their marketing.
5. Who receives the data
We rely on the following providers to deliver the service. This is the complete list as of the date above:
| Provider | Role | What it receives |
|---|---|---|
| Soniox | Speech recognition | Call audio |
| Cerebras | Language model | Call text |
| Deepdub | Speech synthesis (default) | Response text |
| Google Cloud | Speech synthesis and language model, when selected | Text |
| Cartesia | Speech synthesis, when selected | Response text |
| OpenAI | Post-call summarization and analysis | Call transcript |
| Supabase | Database and object storage | All retained data |
| Railway | Application hosting | Data in processing |
| Composio | Integration brokerage | Action payloads to the connected system |
| Resend | Transactional email | Recipient address and message content |
| NLPearl, Twilio | Call handling — only for customers who selected that channel | Call data |
Our telephony infrastructure and media engine run on a dedicated server that we own and operate; they are not a transfer to a third party.
Processing location: some providers above process data outside Israel. We do not publish a precise processing-location map here, because we have not fully verified one with every provider, and we prefer not to state what we cannot confirm. Business customers requiring a commitment on this point are invited to contact us.
6. Retention
Call-related data — recordings, transcripts, summaries and metadata — is retained while the business customer's account is active, and is deleted on that customer's instruction or at the end of the engagement.
In full transparency: we do not currently operate an automated, time-based deletion mechanism. Data is not erased automatically after a fixed period; erasure follows a request or an action. This is a gap we are working to close, and until it is closed we will not state a retention period we do not actually enforce. Deletion requests are handled under Section 9.
7. Security
These are the controls that exist today:
- Tenant isolation at the database layer, via row-level security policies applied across the
system's tables;
- Signed-token authentication (JWT) for all console access, with role-based permissions;
- Encryption of integration credentials and telephony line passwords at the application layer;
- Time-limited signed links for recording access, rather than fixed public URLs;
- Encryption of traffic between system components.
We do not currently hold ISO 27001, SOC 2, or any other certified security accreditation, and we do not represent ourselves as holding one. No system is entirely secure; we work continuously to improve these controls.
8. If you called a business that uses Noa
The data about that call belongs to that business, and we hold it on its behalf. To access, correct or delete it, contact that business. If you contact us directly we will route your request to the relevant customer and support them in handling it — but we may not act on a customer's data contrary to its instructions.
9. Your rights
Under the Israeli Protection of Privacy Law, 5741-1981, you have the right to review data held about you, to demand its correction where it is inaccurate, incomplete or out of date, and to demand its deletion in the circumstances the law provides. You also have the right to require that data about you not be used for commercial solicitation.
To exercise a right, contact [[PRIVACY_EMAIL]]. We will respond within a reasonable time and in any event within the period the law requires. We may need to verify your identity first.
Individuals in the European Union. Where the GDPR applies to a given processing activity, you may additionally have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority. Contact us at the address above and we will assess your request under the applicable framework.
10. Changes
We will update this policy when the service changes — including when we add a provider, change how data is retained, or introduce any measurement tooling on this site. The last-updated date appears at the top.
11. Contact
Privacy enquiries: [[PRIVACY_EMAIL]] · [[LEGAL_ENTITY_NAME]], [[REGISTERED_ADDRESS]].
