Privacy Policy
Last updated: 21 July 2026
This Privacy Policy explains how heyServo ("heyServo", "we", "us"), operated by VAIVAL INFORMATION TECHNOLOGY L.L.C, registered at Office No. 14-12-166, Adel Mohamed Ali Jasim Almarzoqui Building, 14-12, Al Quoz First, Plot No. 552-0, Dubai, United Arab Emirates, collects, uses, discloses, and protects personal data in connection with our website heyservo.ai and our conversational-AI service (the "Service"). Please read it together with our Terms & Conditions.
1. Information we collect · 2. How we use it · 3. AI & automated processing · 4. Recording & consent · 5. Sharing & sub-processors · 6. International transfers · 7. Retention · 8. Security · 9. Your rights · 10. Cookies · 11. Children · 12. Changes · 13. Contact
1. Information we collect
From website & waitlist visitors
- Contact details you submit — name, work email, phone/WhatsApp, business name, industry, number of locations, country/city, channels of interest, and any message (e.g., via the waitlist or contact forms).
- Usage & device data — IP address, browser/device type, pages viewed, referrer, and similar analytics collected via cookies and comparable technologies.
From business customers (account)
- Account and user details (names, business emails, roles), configuration, and billing/tax information.
Through the Service (processed on behalf of our customers)
- Conversation content — messages, chat/web/WhatsApp/SMS/social text, and, for voice, call audio and/or transcripts exchanged between end-users and the AI agent.
- End-user contact identifiers — phone number, messaging handle, name, and any details a person provides during a conversation.
- Operational metadata — timestamps, channel, language detected, branch/location, intent, confidence, tools invoked, and outcomes (e.g., booking, order, escalation).
- Integration data — information exchanged with tools the customer connects (e.g., calendars, CRM, payments) to complete requested actions.
2. How we use information
- To provide, operate, secure, and support the Service and website.
- To run the AI agent — understand requests, retrieve the customer's approved knowledge, generate replies, and (with the customer's configuration and approvals) take actions such as booking or order-taking.
- To respond to enquiries, manage the waitlist, and communicate about early access, service, and updates.
- To maintain security, prevent abuse/fraud, and enforce our Terms.
- To improve reliability and quality (using aggregated or de-identified data where feasible).
- To comply with legal obligations and establish, exercise, or defend legal claims.
Legal bases (where required, e.g., under GDPR/UK GDPR): performance of a contract, our legitimate interests (operating and improving the Service, security), consent (e.g., certain cookies/marketing), and compliance with law. For processing on behalf of customers, the customer is responsible for the lawful basis toward its end-users.
3. AI & automated processing
- Conversations are handled by an automated AI agent. Responses are generated by AI and may occasionally be inaccurate or incomplete; sensitive actions can be configured to require human approval, and conversations can be handed to a human at any time.
- We use large-language-model and speech providers to power the Service (see §5). We do not sell personal data, and we do not use customer conversation content to train third-party foundation models except where explicitly permitted by the customer.
- The AI does not make legally or similarly significant decisions about individuals without human involvement where such involvement is required by applicable law. End-users may request human review via the business they contacted.
4. Call/message recording & consent
The Service may create transcripts and, for voice channels, recordings of conversations, on behalf of the business customer. Our customers are responsible for providing all required notices to, and obtaining any required consent from, their end-users (for example, call-recording and messaging-consent requirements, which vary by country and channel). heyServo provides configuration to support disclosures but does not control the end-user relationship.
5. Sharing & sub-processors
We share personal data only as needed to run the Service and website, with categories of providers such as:
- Cloud hosting & infrastructure — to host the platform and data.
- Messaging & telephony providers — e.g., WhatsApp/Meta, SMS and voice/telephony carriers, to deliver messages and calls.
- AI model & speech providers — to generate responses and transcribe/synthesize speech.
- Analytics, email, and payment providers — for the website, communications, and billing.
- Integrations you connect — data is exchanged only with the tools the customer authorizes.
We require sub-processors to protect data under written agreements. A current list of sub-processors is available on request at privacy@heyservo.ai. We may also disclose data to comply with law, enforce agreements, or in a corporate transaction (merger, acquisition, or asset sale), subject to appropriate safeguards.
6. International transfers
We and our providers may process data in countries other than yours, including outside the GCC/EEA. Where required, we use appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms). Customers can discuss data-residency options at privacy@heyservo.ai.
7. Data retention
We keep personal data only as long as needed for the purposes above, then delete or anonymize it. For data processed on behalf of customers, retention follows the customer's instructions and our agreement; on termination, customer data is deleted or returned within a commercially reasonable period, subject to legal retention requirements. Website/waitlist enquiries are kept for up to [e.g., 24 months] unless you ask us to delete them sooner.
8. Security
We apply administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, credential/secret vaulting, and logging of agent actions. No method of transmission or storage is 100% secure. Formal certifications (e.g., SOC 2, ISO 27001) are on our roadmap and are not represented as currently held.
9. Your rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. To exercise rights regarding data we control (website/waitlist/account), contact privacy@heyservo.ai. If your data was processed by the AI agent of a business you contacted, that business is the controller — please contact them, and we will assist them as processor. You may also have the right to complain to your local data-protection authority.
10. Cookies
Our website uses strictly necessary cookies and, with consent where required, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
11. Children
The Service and website are intended for businesses and adults. They are not directed to children, and we do not knowingly collect personal data from anyone under [16/18]. If you believe a child has provided data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a revised "Last updated" date and, where appropriate, additional notice.
13. Contact us
Questions or requests: privacy@heyservo.ai — VAIVAL INFORMATION TECHNOLOGY L.L.C, Office No. 14-12-166, Adel Mohamed Ali Jasim Almarzoqui Building, 14-12, Al Quoz First, Plot No. 552-0, Dubai, United Arab Emirates.
This document is a general template and does not constitute legal advice. Have it reviewed and finalized by qualified legal counsel for your jurisdiction(s) before publishing. The English version governs.