This Privacy Policy explains how Jyoram LLC, a Texas limited liability company doing business as Harlo ("Harlo", "we", "us", or "our") collects, uses, shares, and protects personal information in connection with our AI voice and chat agent platform, websites, APIs, and related services (collectively, the "Services"). It applies to information we process as a business and, where applicable, distinguishes our role as a controller (for our own business and website) from our role as a processor/service provider (when handling data on behalf of our business customers).
When you visit our website, create an account, or communicate with us, Harlo acts as a controller of your personal information. When our business customers ("Customers") use the Services to operate AI agents that interact with their own end users ("End Users"), Harlo generally acts as a processor/service provider that handles personal information on the Customer's behalf and under their instructions. In that case, the Customer is the controller, and their own privacy notice governs how End User data is collected and used. End Users should direct requests about such data to the relevant Customer.
| Category | Examples |
|---|---|
| Account & contact data | Name, email, phone number, company, role, billing details, and login credentials. |
| Configuration data | Tenant and agent settings, prompts, routing rules, integration credentials and secret references, and business information you provide. |
| Communications content | Call audio, chat messages, transcripts, summaries, tool-invocation records, and metadata such as timestamps, phone numbers, channel, and call disposition. |
| Usage & device data | Log data, IP address, browser/device identifiers, feature usage, and diagnostic events. |
| Billing & usage metering | Call minutes, transcription seconds, character and token counts, and derived cost estimates. |
| Support data | Information you provide when contacting us for support or sales. |
The Services answer phone calls and conduct chat and audio conversations on behalf of Customers. Depending on Customer configuration and applicable law, we may process and store audio, transcripts, and AI-generated summaries of these interactions. Where call-recording features are enabled, recording may be consent-gated, and audio captured before consent is granted is not retained. Customers are responsible for configuring consent settings, providing legally required notices, and ensuring a lawful basis for recording, transcription, and analysis in all relevant jurisdictions.
We do not create, collect, capture, purchase, or retain voiceprints or any other biometric identifiers or biometric information, and we do not use voice data to identify or verify the identity of any individual. The Services use automated speech recognition solely to convert spoken audio into text so the AI agent can understand and respond to the conversation. We do not perform speaker recognition, speaker verification, voice authentication, or voice-based profiling, and we do not analyze audio to extract identifying characteristics of a person's voice. Call audio and transcripts are handled as communications content (see the sections above), not as biometric identifiers within the meaning of laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), or Washington's biometric and consumer health data laws. We do not sell, lease, trade, or otherwise profit from biometric data. If we ever introduce a feature that involves biometric identifiers, we will update this Policy first and provide the notice, written policy, and consent mechanisms those laws require before enabling it.
Conversations with an AI receptionist can incidentally capture sensitive personal information — for example, health or medical details mentioned when booking an appointment, payment card numbers, or government identifiers volunteered by a caller. Our handling of such information is as follows:
We do not sell personal information, and we do not use End User communications content to train general-purpose foundation models without appropriate authorization.
Where the GDPR or UK GDPR applies and Harlo acts as a controller, we rely on the following legal bases: performance of a contract (to provide the Services you request); legitimate interests (to secure, improve, and operate the Services, balanced against your rights); consent (where required, e.g., certain cookies or marketing); and compliance with legal obligations. Where Harlo acts as a processor, the Customer is responsible for establishing the appropriate legal basis for processing End User data.
We share personal information only as needed to provide the Services and as described here:
We engage trusted third parties to deliver the Services, which may include:
Subprocessors are bound by contractual obligations to protect personal information and to process it only as instructed. A current list of subprocessors is available on request by emailing privacy@askharlo.ai.
Some features of the Services allow Customers to connect a Google account — for example, connecting Google Calendar so an agent can check availability and book appointments, importing documents from Google Drive into a knowledge base, or enabling Google Workspace tools (such as Gmail, Drive, or Calendar actions) for an agent. When you authorize such a connection through Google's OAuth consent screen, our access, use, storage, and sharing of information received from Google APIs ("Google user data") adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
The Services use automated speech recognition and large language models to understand and respond to conversations. Conversation content may be transmitted to model providers to generate responses and summaries. AI output may be inaccurate; it is not a substitute for professional advice. Decisions that produce legal or similarly significant effects should involve human review. Where applicable law grants rights regarding automated decision-making, you may exercise them as described below.
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods for call records, transcripts, and recordings are generally governed by Customer configuration and contractual terms. When Harlo acts as a processor, we delete or return Customer Data following termination, subject to a limited export and backup-expiry window. Where a Customer has not specified a retention period, our default is to retain call records, transcripts, and recordings for 12 months, after which they are deleted or de-identified, unless a longer period is required to comply with legal obligations, resolve disputes, or enforce our agreements.
We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls, tenant isolation, secret management (storing pointers rather than secret values where possible), and logging that avoids capturing secret values. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and configuring your account securely.
Our platform and data are primarily hosted in the United States, and we and our subprocessors may process personal information there and in other countries where our service providers operate. Where we transfer personal data from the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (together with the UK International Data Transfer Addendum) or other lawful transfer mechanisms.
Depending on your location, you may have rights to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. Residents of certain U.S. states may have rights to know, delete, correct, and opt out of "sale" or "sharing" and targeted advertising (we do not sell personal information) — see "U.S. State Privacy Rights" below for how those requests are handled. To exercise rights, contact us using the details below. Where Harlo processes data on a Customer's behalf, we will direct End User requests to, or assist, the relevant Customer.
This section supplements the rest of this Policy for residents of U.S. states with comprehensive privacy laws (including California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, and others). It applies where Harlo acts as a controller/business; where we act as a processor/service provider for a Customer, we will forward your request to that Customer and assist them in responding.
Email privacy@askharlo.ai with the subject line "Privacy Request", stating which right you wish to exercise and the state in which you reside. We do not require an account to submit a request.
We verify requests by matching the information you provide (such as the email address or phone number associated with your interactions) against information we already hold. If we cannot verify your identity with reasonable certainty, we may request additional information, which we use only for verification and then delete. We will not ask for a government-issued ID unless necessary, and we will deny (with explanation) requests we cannot verify.
You may use an authorized agent to submit a request on your behalf. We require the agent to provide written proof of your authorization (such as a signed permission or power of attorney), and we may also require you to verify your own identity directly with us or confirm that you granted the permission.
We will confirm receipt of your request and respond within 45 days. Where reasonably necessary, we may extend this period by an additional 45 days and will notify you of the extension and the reason for it. If we decline to act on your request, we will explain why and how to appeal. To appeal, reply to our decision or email privacy@askharlo.ai with the subject line "Privacy Request Appeal" within a reasonable period after our decision. We will respond to appeals within the period required by your state's law (generally 45–60 days) with a written explanation of our decision. If your appeal is denied, you may contact your state Attorney General — for example, through the consumer complaint portals maintained by the Virginia, Colorado, Connecticut, or Texas Attorneys General — or, in California, the California Privacy Protection Agency.
We recognize the Global Privacy Control (GPC) browser signal as a valid request to opt out of the "sale" or "sharing" of personal information and targeted advertising, as required by California and other states. Because we do not sell or share personal information, and our website analytics load only after you affirmatively opt in, honoring a GPC signal will not reduce site functionality; where a GPC signal is present we treat it as a denial of analytics consent for that browser.
Some browsers offer a legacy "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and we do not respond to them; we honor the GPC signal as described above.
We will not discriminate against you for exercising any privacy right, such as by denying services, charging different prices, or providing a different level of quality.
The Services are not directed to children, and we do not knowingly collect personal information from children under the age defined by applicable law. If you believe a child has provided us personal information, please contact us so we can take appropriate action.
Our website and dashboards use cookies and similar technologies for authentication, preferences, security, and analytics. Essential cookies needed to operate the site are always active. For non-essential analytics cookies we ask for your consent first: when you visit our marketing site you'll see a consent banner, and analytics remain disabled until you choose "Accept." We implement this using Google Consent Mode, which keeps analytics storage denied by default until you opt in.
When you accept, we use the following website-analytics services:
You can withdraw consent at any time by clearing this site's stored data in your browser (which removes your saved choice and shows the banner again) or by adjusting your browser's cookie settings.
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, for material changes, provide additional notice where required. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
The Services are operated by Jyoram LLC, a limited liability company organized under the laws of the State of Texas, doing business as Harlo. Jyoram LLC is the data controller for the processing described in this Policy (except where we act as a processor/service provider on behalf of a Customer). For privacy questions or to exercise your rights, contact:
Jyoram LLC (d/b/a Harlo)
8228 Oakwood
Plano, TX 75024
United States
Privacy: privacy@askharlo.ai