Noa
עבEN
Draft — the legal-entity details are not yet filled in and this has not been reviewed by counsel. Do not rely on it until the signed version is published.

Privacy Policy

Last updated: [[EFFECTIVE_DATE]]

1. Who we are

[[LEGAL_ENTITY_NAME]], company number [[COMPANY_REG_NUMBER]], of [[REGISTERED_ADDRESS]] ("Noa", "we", "us"), operates an AI voice-agent platform that answers telephone calls on behalf of businesses.

This policy explains what personal data reaches us, why, who it goes to, and what rights you have. It is written to describe the system as it actually operates — not as we would like it to. Where a control does not yet exist, we say so rather than imply otherwise.

2. Two capacities — a distinction that matters

Noa holds two materially different positions with respect to personal data:

(a) Noa as Controller. For website visitors, people who submit our contact form, and authorized users of our console, we determine the purposes and means of processing. This policy applies to you directly.

(b) Noa as Processor. For the personal data of callers who dial our customers' phone lines, the business operating that line is the Controller, and we process on its documented instructions under our agreement with it. If you called a business that uses Noa and wish to exercise a right, your request goes first to that business — see Section 8.

3. What data reaches us

3.1 Data collected on this website

The demo request form collects: name, work email address, phone number, company name, and estimated monthly call volume. The newsletter field collects an email address only. We use this solely to respond to your enquiry and manage the resulting business relationship.

This website sets no cookies, runs no analytics, and contains no tracking pixels or third-party trackers of any kind. Fonts are served from our own origin and generate no third-party request when you browse. The only item stored in your browser is your interface language preference (noa-locale), for functional purposes.

Providing this information is voluntary and not required by law. Without it we cannot reply to you.

3.2 Data processed during telephone calls (our Processor capacity)

When a Noa voice agent handles a call on a business customer's behalf, the system processes:

  • Phone numbers of the caller and the called line, plus technical call metadata (time, duration,

status, direction);

  • Live call audio, in real time, to recognize speech and generate a spoken response;
  • A recording of the call, retained in our storage;
  • A full transcript of both sides;
  • An automated summary, together with analysis covering sentiment, discussion topics and

follow-up actions;

  • An estimate of the speaker's gender, derived from the audio by a classifier that runs inside our

own infrastructure. It serves one narrow linguistic purpose — selecting the correct Hebrew grammatical form of address — and is not used for segmentation, scoring, or any decision about the caller.

All calls handled through the platform are recorded and transcribed. Responsibility for informing callers of this — by announcement, disclosure at the start of the call, or otherwise — rests with the business operating the line, under our Terms of Use. The system does not currently play an automated recording notice, and we do not present one as an existing safeguard.

3.3 Data in connected systems

A business customer may connect its own systems to Noa — for example a CRM or a mailbox. Where it does, we access data in those systems only within the permissions that customer granted and only when performing an action it configured. Credentials for those systems are stored encrypted.

4. Why we process it

PurposeBasis
Delivering the service — answering calls, routing, performing actionsPerformance of our contract with the business customer
Recording, transcription, summarization and analysisThe business customer's instruction, as part of the service it purchased
Responding to website enquiries and managing the relationshipYour consent when you submit the form, and our legitimate business interest
Security, fault diagnosis and abuse preventionLegitimate interest in protecting the service and its users
Meeting legal obligationsLegal obligation

We do not sell personal data, do not trade in it, and do not share it with third parties for their marketing.

5. Who receives the data

We rely on the following providers to deliver the service. This is the complete list as of the date above:

ProviderRoleWhat it receives
SonioxSpeech recognitionCall audio
CerebrasLanguage modelCall text
DeepdubSpeech synthesis (default)Response text
Google CloudSpeech synthesis and language model, when selectedText
CartesiaSpeech synthesis, when selectedResponse text
OpenAIPost-call summarization and analysisCall transcript
SupabaseDatabase and object storageAll retained data
RailwayApplication hostingData in processing
ComposioIntegration brokerageAction payloads to the connected system
ResendTransactional emailRecipient address and message content
NLPearl, TwilioCall handling — only for customers who selected that channelCall data

Our telephony infrastructure and media engine run on a dedicated server that we own and operate; they are not a transfer to a third party.

Processing location: some providers above process data outside Israel. We do not publish a precise processing-location map here, because we have not fully verified one with every provider, and we prefer not to state what we cannot confirm. Business customers requiring a commitment on this point are invited to contact us.

6. Retention

Call-related data — recordings, transcripts, summaries and metadata — is retained while the business customer's account is active, and is deleted on that customer's instruction or at the end of the engagement.

In full transparency: we do not currently operate an automated, time-based deletion mechanism. Data is not erased automatically after a fixed period; erasure follows a request or an action. This is a gap we are working to close, and until it is closed we will not state a retention period we do not actually enforce. Deletion requests are handled under Section 9.

7. Security

These are the controls that exist today:

  • Tenant isolation at the database layer, via row-level security policies applied across the

system's tables;

  • Signed-token authentication (JWT) for all console access, with role-based permissions;
  • Encryption of integration credentials and telephony line passwords at the application layer;
  • Time-limited signed links for recording access, rather than fixed public URLs;
  • Encryption of traffic between system components.

We do not currently hold ISO 27001, SOC 2, or any other certified security accreditation, and we do not represent ourselves as holding one. No system is entirely secure; we work continuously to improve these controls.

8. If you called a business that uses Noa

The data about that call belongs to that business, and we hold it on its behalf. To access, correct or delete it, contact that business. If you contact us directly we will route your request to the relevant customer and support them in handling it — but we may not act on a customer's data contrary to its instructions.

9. Your rights

Under the Israeli Protection of Privacy Law, 5741-1981, you have the right to review data held about you, to demand its correction where it is inaccurate, incomplete or out of date, and to demand its deletion in the circumstances the law provides. You also have the right to require that data about you not be used for commercial solicitation.

To exercise a right, contact [[PRIVACY_EMAIL]]. We will respond within a reasonable time and in any event within the period the law requires. We may need to verify your identity first.

Individuals in the European Union. Where the GDPR applies to a given processing activity, you may additionally have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority. Contact us at the address above and we will assess your request under the applicable framework.

10. Changes

We will update this policy when the service changes — including when we add a provider, change how data is retained, or introduce any measurement tooling on this site. The last-updated date appears at the top.

11. Contact

Privacy enquiries: [[PRIVACY_EMAIL]] · [[LEGAL_ENTITY_NAME]], [[REGISTERED_ADDRESS]].

Back to home