Last updated: September 11, 2026
Privacy Policy
This policy explains what data Hello collects, why we collect it, who helps us run the service, and the rights you have over your data. We wrote it to be read, not just linked at the bottom of a page.
1. Who we are
Hello is an AI phone receptionist for small businesses, operated from Austria under the domain gethello.io. For anything privacy related, write to us at [email protected].
2. What data we collect
Account data:
- Email address (used as your login and for account notifications)
- Password (stored only as a salted hash, never in plain text)
Business data, what you give us when setting up your receptionist:
- Your business website URL
- The country your business operates in
- Your contact phone number
The on-site voice demo runs in your browser. Speech is recognized by your browser’s own speech service and nothing is stored on our side.
Calls handled for your business:
- Recordings and transcripts of calls your Hello receptionist answers
- Call metadata such as duration, time, and caller number
- Summaries generated for you as the business owner
If you are a customer of a business that uses Hello, your calls may be answered, recorded, and transcribed by the AI receptionist, and the business owner receives a summary. Callers are told they are talking to an AI. If you want a recording deleted, contact the business or email us and we will pass the request on.
3. Why we process your data
- To deliver the service (account, business, and call data): the legal basis is performance of our contract with you.
- To keep the service secure and improve it (log data, abuse prevention): the legal basis is our legitimate interest in running a reliable, safe product.
- Marketing emails (email): the legal basis is your consent. Every email has a one-click unsubscribe.
4. Who else is involved
We do not sell your data. We share it only with providers that help us run Hello, each bound by a data processing agreement:
- Cloudflare, content delivery and DNS. Keeps the site fast and protected.
- Twilio, telephony. Connects and routes the actual phone calls.
- Voice AI platform (Vapi/Retell class), runs the AI receptionist: speech recognition and voice synthesis during calls.
- Stripe (planned), payments. Handles your card details; we never see or store them.
Your data is stored on servers in Europe, on infrastructure we own and control.
5. How long we keep data
- Account and business data: for as long as your account is active. After you request deletion, it is removed within 30 days.
- Call recordings and transcripts: at most 90 days, unless you as the business owner choose to keep them longer.
6. Your rights
Under the GDPR you have the following rights over your data. To use any of them, email [email protected] and we will respond within 30 days.
- Access: Ask for a copy of the data we hold about you.
- Rectification: Ask us to fix anything that is inaccurate or out of date.
- Erasure: Ask us to delete your data (see retention below).
- Restriction: Ask us to pause processing while something is disputed.
- Portability: Get your data in a machine-readable format to take elsewhere.
- Objection: Object to processing based on legitimate interest, including marketing.
- Withdraw consent: For marketing, at any time, without affecting past processing.
You also have the right to lodge a complaint with your local data protection authority. In Austria that is the Datenschutzbehörde.
7. Cookies
We use only what the site needs to work:
- Essential cookies (login session). Without them, signing in does not work.
- One consent cookie that remembers whether you accepted or declined the cookie banner, so we do not ask twice.
- No third-party tracking cookies. No ad networks, no cross-site profiling.
8. Changes to this policy
When we change how we handle data, we update this page and the date at the top. If a change affects you materially, we will notify you by email before it takes effect.
Questions? [email protected]