Privacy Policy
This is an English translation provided for convenience. In case of any discrepancy, the Hebrew version prevails.
Last updated: October 5, 2026
1. About this policy
1.1. The TalkWiz service (the "Service") is operated by Yehonatan Shamam, licensed dealer no. 302910187, of 94 Yigal Alon Street, Tel Aviv-Yafo ("TalkWiz" or "we"), who is the database controller for the information described in section 2. This policy explains what personal information we process, why, on what basis, with whom we share it, how long we keep it and what rights the people the information concerns have.
1.2. This policy was written under the Privacy Protection Law, 5741-1981, as amended by Amendment No. 13, and its regulations, including the Privacy Protection (Data Security) Regulations, 5777-2017. It is part of the Terms of Use. Terms not defined here have the meaning given in the Terms of Use.
1.3. Providing personal information to the Service is not a legal obligation. Without account details you cannot sign up, and without call data there is nothing to analyze.
2. Two roles, two types of information
The Service processes two different types of information, each with a different party responsible for it:
- Information about business customers and users (name, email, organization, role, billing and use of the Service): TalkWiz is the database controller. This policy applies to it in full.
- Call data that the business customer enters into the Service (recordings, transcripts, details of agents and end customers, the content of calls and the analysis outputs): the business customer is the database controller, and TalkWiz is a holder that processes the information for it only, on its instructions and under the Data Processing Agreement. The business customer decides which calls are received, why, who sees them and how long they are kept, and it is responsible for informing the parties to the calls and obtaining any required consent.
Did you speak on the phone with a business that uses TalkWiz? The business is responsible for the information about your call, and that is where you should exercise your rights. If you contact us, we will pass the request on to the business and let you know. We will not give you information about a call without the business's instruction, unless the law requires it.
3. What information we process
When we are the controller:
- Account details: full name, email, password (stored only as a hash), role in the organization, and a Google account if sign-in through Google was chosen.
- Organization details: business name, settings, and acceptances of terms with date and version.
- Billing details: name for the invoice, business or company number, billing email, the last four digits and the type of card. The full card number is given directly to the payment processor, and we do not store it.
- Usage and security data: IP address, browser type, login times, actions in the Service, credit consumption and error logs.
- Requests: the content of your requests to us.
- Information from others: the email address and role of a user invited to an organization (from the business customer who invited them), and public business information from the business customer's website when it asks to scan it into the business memory.
When we are a holder on behalf of the business customer:
- Voice recordings and transcripts of calls, names and phone numbers of end customers, agent names, call metadata (time, duration, campaign, status), information given in the call, analysis outputs, fields the customer defined for extraction, tags, notes, and the business memory.
4. Why we use information, and on what basis
| Purpose | Basis |
|---|---|
| Opening an account, signing in, managing an organization and permissions | Performance of the agreement with the customer |
| Transcribing and analyzing calls and showing the results | The instructions of the business customer, the controller of the call data |
| Reports, alerts and service messages that users asked for | Performance of the agreement |
| Billing, issuing invoices and collection | Performance of the agreement and obligations under tax law |
| Security, preventing fraud and misuse, handling incidents | Legitimate interest and the obligations under the data security regulations |
| Answering requests and support | Performance of the agreement |
| Improving the Service using aggregated, non-identifying data | Legitimate interest |
| Complying with the law, a court order or a demand of a competent authority | Legal obligation |
| Marketing messages | Consent only, and you can unsubscribe at any time |
What we do not do: we do not sell personal information, we do not use it for targeted advertising, we do not use call data to train artificial intelligence models, and we do not use one customer's call data for the benefit of another customer.
5. Artificial intelligence
5.1. Transcription and analysis of calls are done automatically using models of an outside provider (OpenAI), through its API. Under the policy the provider publishes, information sent through the API is not used to train models, but may be kept by it for a limited period to monitor misuse.
5.2. Before a transcript is stored and before it is sent for analysis, the Service automatically hides credit card numbers, CVV codes, card expiry dates, ID numbers, bank accounts and IBAN, and keeps only last digits. The hiding is based on pattern recognition and is not perfect. The voice recording itself is sent for transcription as is, and deleted right after it.
5.3. The analysis outputs are a support tool for the business. The instructions to the models forbid inferring sensitive traits about a person. The Service does not make decisions about people; decisions stay with the business customer.
6. Who we share information with
6.1. Sub-processors that process information for us, each only to the extent needed for its role and under an undertaking to protect it:
| Provider | Role | Main location |
|---|---|---|
| Supabase | Database, user authentication and file storage | European Union (Frankfurt) |
| Vercel | Hosting the application and running server code | European Union (Frankfurt), with a global delivery network |
| OpenAI | Transcribing recordings and analyzing redacted transcripts | USA |
| Resend | Sending email (reports, alerts, system messages) | USA |
| Inngest | Scheduling and running background jobs | USA |
| Sign-in with a Google account, for those who choose it | USA | |
| PayMe | Payment processing | Israel |
| Paperless | Issuing tax invoices | Israel |
We will update this list before adding a sub-processor that will process call data, as set out in the Data Processing Agreement.
6.2. Destinations the business customer defined: information is sent to third-party systems (for example CallMarker, a customer webhook, WhatsApp or an email program) only when the customer or its users set this up or performed the action. From the moment of transfer, the information is subject to that third party's terms.
6.3. Within the organization: users in the organization see information according to the role the business customer gave them. A team lead sees their teams, and an agent sees their own calls and the call library the organization shared.
6.4. By law: we will disclose information if required to by law, a court order or a demand of a competent authority, and only to the extent required. Where permitted, we will notify the business customer.
6.5. Structural change: in a merger, acquisition or transfer of activity, the information may pass to the acquiring entity, which will be bound by this policy.
7. Marketing messages
7.1. Service messages (verification, security, billing, reports and alerts the user set up, changes to the terms) are sent as part of the Service and are not marketing messages.
7.2. Marketing messages (product updates, offers and content) will be sent only under section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982, and every message will include a simple way to remove yourself from the mailing list. You can also ask to be removed at info@talkwiz.app.
8. Transfer of information outside Israel
Some sub-processors operate in the European Union and the USA. The database and code execution are in the European Union. Information is transferred abroad under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, including on the basis of the provider's contractual undertaking to protect the information and comply with the conditions that apply to a database in Israel, and the countries of the European Union provide protection no less than that of Israeli law. The business customer is responsible for including the transfer abroad in the notice it gives the parties to calls.
9. How long we keep information
| Information | Retention period |
|---|---|
| Voice recordings | Deleted right after transcription. A recording that was not transcribed is deleted within a few hours |
| Transcripts and raw content received | According to the retention period the business customer set (default: 90 days), then deleted |
| Analysis outputs and call metrics | As long as the organization is active, until deleted by the customer or the organization is deleted |
| Account and organization details | As long as the account is active, and up to 30 days after a deletion request |
| Billing documents and records of terms acceptance | For the period required by law or to defend against claims |
| Security and operations logs | For a reasonable period for security and control purposes |
| Backups | Deleted in the infrastructure provider's regular backup cycle |
10. Information security
We implement organizational and technological measures under the Privacy Protection (Data Security) Regulations, including application-level encryption of transcripts and raw content, separation between organizations enforced in the database itself and checked by automated tests, role-based permissions, hiding of payment details and identifiers, and audit logs. Details are in the Information Security and Information Management Policy. No system is completely immune, and we cannot guarantee that a security incident will not happen. If a severe security incident happens, we will act as the law requires, including reporting to the Privacy Protection Authority and notifying the affected business customers.
11. Cookies and browser storage
We use only cookies that are necessary to operate the Service: a sign-in cookie and a cookie that remembers the selected organization. Accessibility settings and display preferences are kept in the browser's local storage and are not sent to us. We do not currently use statistics or advertising cookies. If we add such cookies, we will ask for consent in advance.
12. Your rights
12.1. Under the Privacy Protection Law, a person is entitled to review the information about them kept in a database, to ask to correct or delete information that is not correct, complete, clear or up to date, and to ask to be removed from a mailing list.
12.2. For information we control (account and billing details): write to info@talkwiz.app. We will ask to verify your identity before giving or changing information, and will reply within 30 days.
12.3. For call data: direct the request to the business you spoke with, which is the controller. If you contact us, we will pass the request on to the business and help it handle it.
12.4. If you believe your rights were violated, you may contact the Privacy Protection Authority. We would appreciate it if you contacted us first so we can try to resolve the matter.
13. Minors
The Service is intended for businesses and for users aged 18 and over. We do not knowingly collect information about minors as users. The business customer is responsible for not entering calls with minors into the Service except where it is permitted to by law.
14. Changes to this policy
We will update this policy from time to time, and note the update date at the top. We will notify of a material change by email or in the Service before it takes effect, and ask for acceptance again at the next login.
15. Contact
Database controller: Yehonatan Shamam, licensed dealer no. 302910187, of 94 Yigal Alon Street, Tel Aviv-Yafo.
Privacy protection officer: Adv. Yehonatan Shamam, email: info@talkwiz.app.
Questions, requests and complaints about privacy should be sent to the officer at this address.