HIMEXA TECH · Hi, Mexa
Privacy Policy
How HIMEXA TECH processes personal data in connection with the Hi, Mexa platform.
- Effective date
- 27 July 2026
- Version
- 1.0
This Privacy Policy ("Policy") describes the practices of HIMEXA TECH("HIMEXA", "we", "us") regarding personal data processed through Hi, Mexa, including the marketing site, authentication flows, dashboard, and APIs.
For Customer Workspaces, the organisation typically acts as controller of End Caller and business content data, and HIMEXA acts as processor / service provider. HIMEXA acts as controller for its own account administration, security logs, public contact form, and optional analytics (subject to consent where required). See also our Terms of Service and Cookies & storage notice.
1.Controller and roles
Questions about this Policy may be directed through the channels in Section 16. Where Customer is controller, End Callers should contact that organisation first regarding call recordings, transcripts, or agent behaviour.
2.Scope
- Visitors to public pages (home, contact, terms, privacy, cookies)
- Authenticated dashboard users (agents, admins, and other roles)
- End Callers and message participants whose interactions are processed because Customer connected numbers and AI agents
3.Categories of personal data
A. Account and authentication
- Email address, roles, access flags, provider (e.g. password or Google), last login
- MFA enrolment/verification status; short-lived MFA challenge cookie during verification
- Session token and refresh token cookies (httpOnly) used by the Hi, Mexa BFF to authorize backend requests
B. Workspace configuration
- Phone numbers and number metadata
- Per-number Setting Configuration: greeting, language (e.g. en-AU, en-US, hi-IN, ne-NP), selected voiceSettingsId, consent flow and consent prompt, business profile (company name, website, assistant name, live agent number, hours, services, partners, scope, additional info), data-capture field definitions, lead tagging (sales/support/compliance/incident with destination numbers), urgency/transfer logic, summary email/SMS preferences, callback scheduling windows, uploaded knowledge files, JSON output structure
- Voice settings catalogue entries (provider, locale key, voice IDs, labels, TTS/STT parameters such as ElevenLabs or Deepgram-related fields where used)
C. Communications and intelligence
- Call identifiers, timestamps, duration, status, from/to numbers, caller display names where available
- Transcripts and message content; conversation search fields (intent, sentiment, outcome, topic, health score, snippets)
- Live-call / coaching / revenue or brief-related analytics where enabled
- Knowledge-gap records and predictive alerts
- SMS or related logs where Customer enables those features
- Callback scheduling records and calendar-linked fields when Microsoft calendar OAuth is connected
D. Website and support
- Public contact-form submissions (name, email, message, and similar fields)
- Technical logs: IP address, user agent, request IDs, error diagnostics
- Optional analytics identifiers in web storage after consent (see Cookies & storage)
4.Sources of data
- Provided by Customer users (settings, uploads, invites, contact form)
- Generated by the Service (transcripts, intelligence labels, logs)
- Received from Integrations Customer connects (carriers, speech, Google identity, Microsoft calendar)
- Captured from End Callers during calls or messages handled by Customer’s agents
5.Purposes of processing
- Provide and operate Hi, Mexa modules listed in the Terms (dashboard, agents, calls, conversations, callbacks, contacts, analytics, users, settings)
- Authenticate sessions, refresh tokens, enforce roles, and apply MFA
- Deliver AI voice interactions and conversation intelligence features Customer enables
- Customer support and contact-form follow-up
- Security monitoring, abuse prevention, and incident response
- Product improvement via optional analytics (consent-based where required)
- Legal compliance and enforcement of the Terms
HIMEXA does not sell personal data. HIMEXA does not use Customer call content to train unaffiliated public foundation models unless a separate written agreement expressly authorises that use.
6.Legal bases
Where GDPR, UK GDPR, or similar frameworks apply, HIMEXA relies on: contract performance; legitimate interests (securing and operating the Service, B2B communications); consent (non-essential analytics storage); and legal obligation. Customer is responsible for the lawful basis for End Caller recording, transcription, and AI analysis, including any required disclosures in greetings or consent prompts.
7.Processing by product module
- AI Agents — voice catalogue and admin edits to provider/locale/voice parameters
- Live Calls / Transcripts — storage and display of call records and transcript text; optional CSV export by users
- Conversations — indexed search over intelligence fields derived from calls
- Numbers / Setting Configuration — persistence of agent behaviour and business profile for each E.164 number
- Callbacks / Calendar — scheduling data; tokens for Microsoft calendar when connected
- Users — admin management of emails, roles, and access
- Contact submissions — storage of public form leads for Customer or HIMEXA staff review
9.International transfers
Data may be processed in countries other than Customer’s or End Callers’ location. Where required, HIMEXA uses appropriate transfer safeguards (such as standard contractual clauses) or relies on adequacy decisions.
10.Retention
- Account and Workspace data — for the life of the Workspace plus a short wind-down period, unless earlier deletion is requested and legally permitted
- Call recordings, transcripts, and intelligence records — per Customer configuration or HIMEXA operational defaults
- Security and auth logs — for a limited period needed for security and debugging
- Contact-form submissions — as needed to respond and for reasonable business records
- Session cookies — as described on the Cookies & storage page; cleared on logout where applicable
11.Security measures
- TLS for data in transit; httpOnly, Secure, SameSite session cookies
- Server-side BFF so browser JavaScript does not hold access tokens
- Role-based access control and optional MFA
- Proxy/middleware refresh of expired access tokens on protected page loads
- Operational logging and error handling to detect abuse or outages
No method of transmission or storage is perfectly secure. Customer must protect credentials and promptly report suspected incidents.
13.Individual rights
Depending on applicable law, individuals may request access, correction, deletion, portability, restriction, or objection, and may withdraw consent for optional analytics. Authenticated users may use in-product controls where available or contact HIMEXA. End Callers should contact the Customer organisation that operates the number. HIMEXA may verify identity before fulfilling requests and may refuse requests that are unlawful or exempt.
14.Children
Hi, Mexa is a business service and is not directed to children under 16 (or higher age required locally). HIMEXA does not knowingly collect personal data from children.
15.Changes
HIMEXA may update this Policy by posting a revised version with a new effective date. Material changes may be communicated in-product or by email to Workspace contacts when appropriate.
16.Contact
Privacy requests and questions: Contact form or himexa.tech.