Back to the home page

GDPR - AI Act

Privacy policy

This is an informational translation. The Polish version of this policy is authoritative.

This Policy describes how Helpifyprocesses the personal data of people who use our website, contact forms and the AI voice agent demo ("the demo"), as well as people who contact us about working together. We want this to be clear and honest. If anything in this document is missing or unclear, email us at hello@gethelpify.com.

Last updated: 1 September 2026

AI transparency, in short

Our agents are artificial intelligence systems. Before the actual conversation starts, every caller hears a clear message saying they are talking to AI, not a human, and that the call may be recorded. You can end the call, or ask to speak to a human, at any time.

Section 1. Data controller

The data controller within the meaning of Article 4(7) GDPR is Maciej Odrobina, operating a sole proprietorship registered at ul. Szarych Szeregów 1E/6, 44-194 Knurów, Tax ID (NIP) 9691675425, REGON 543235659(referred to below as "Helpify", "the Controller", "we").

Contact for all matters relating to personal data protection:

The Controller is not required to appoint a Data Protection Officer (DPO). Until a DPO is appointed, if ever, all data protection matters are handled at hello@gethelpify.com.

Section 2. Scope of this Policy

This Policy applies to data processing in connection with:

  • using the Helpify website: visits, cookies, contact forms and call booking forms;
  • the AI voice agent demo ("the demo"): a call with the voice agent held to demonstrate how the service works;
  • communicating with us: email correspondence, phone calls, online meetings;
  • marketing activities: sales contact, remarketing, social media;
  • managing client relationships: preparing and performing contracts for deploying AI voice agents.

Important: this Policy does not cover the production Voice AI services we provide to our clients (voice agents handling a client's inbound and outbound traffic). In that model, the client is the controller of the callers' data, and Helpify acts as a processor under a separate data processing agreement. The client is responsible for meeting the information obligation towards its own callers.

Section 3. What data we process

Depending on how you interact with us, we may process the following categories of data:

3.1. Identification and contact data

First and last name, company name, industry, job title, email address, phone number, postal address, message content.

3.2. Technical data (collected automatically)

IP address, browser identifier (user agent), operating system, cookie identifiers, date and time of submission, and navigation path on the site, to the extent necessary for the site to function, for security and for spam prevention.

3.3. Voice data from the AI agent demo

If you use the voice demo, we process:

  • the phone number the demo is placed from or to;
  • call metadata (date, time, duration, call status);
  • a recording of the demo call (a digital record of the conversation);
  • a transcript of the call (an automatic voice to text conversion) along with its metadata;
  • information you voluntarily provide during the call (for example your name, the matter and your preferences).

3.4. Marketing data

Consents and contact preferences, communication history, interactions with ad campaigns, and the source the contact came from.

3.5. Data saved while you fill in the application form

On the offer page for clinics, we run an application form that leads to a booking calendar. In this one place, we save your name and phone number as soon as you type them, meaning before you submit the form. We tell you this next to the phone number field, before you start filling it in.

  • we only save your name and phone number, never your email or any other data, before the form is submitted;
  • we do this so we can call someone who started booking a call and did not finish;
  • that contact is limited to one matter: finishing the booking you started;
  • you can object to this processing, or ask us to delete this data, at any time by writing to hello@gethelpify.com, and we will do so without asking why.

We do not seek to collect special category data (Article 9 GDPR). The website and the demo are aimed at business owners (adults). We do not direct our services at children.

Section 4. Purposes and legal bases for processing

Every processing activity has its own legal basis:

PurposeGDPR legal basisRetention period
Responding to a form inquiry, following up, preparing an offerArticle 6(1)(b) (pre-contractual steps) and (f) (B2B communication)up to 24 months from the last contact
Phone contact about a booking that was started but not finished (data from Section 3.5)Article 6(1)(f) (legitimate interest: completing a contact the person themselves started) and (a) (consent given by submitting the form), if the form was submittedup to 90 days from when it was saved, unless the booking went ahead
Running the voice demo, recording and transcribing the callArticle 6(1)(a) (consent) and (b) (steps taken at the person's request)recordings and transcripts: 30 days maximum
Entering into and performing a partnership or rollout agreementArticle 6(1)(b) (contract)the term of the contract plus the statute of limitations period
Marketing our own services, sales contactArticle 6(1)(a) (consent) and (f) (direct marketing)until consent is withdrawn or an objection is raised
Analytics and ad performance measurement (cookies)Article 6(1)(a) (cookie consent)as set in the relevant tool
Website security and abuse preventionArticle 6(1)(f) (legitimate interest: IT security)up to 12 months (logs)
Accounting and tax recordsArticle 6(1)(c) (legal obligation)5 years from the end of the calendar year
Establishing, pursuing or defending legal claimsArticle 6(1)(f) (legitimate legal interest)until the statute of limitations expires

Section 5. The voice demo and call recording

The demo lets you hear our AI voice agent working live. If you use it:

  • before the actual conversation starts, you hear a message telling you that you are talking to an AI system, not a human, and that the call may be recorded and transcribed;
  • the call is recorded and transcribed solely to demonstrate the service and for quality control;
  • we keep the recording and its transcript for a maximum of 30 days, after which they are automatically deleted;
  • you can end the call, hang up, or ask to speak to a human at any time, without giving a reason;
  • your voice data from the demo is not used to train AI models, ours or our providers'.

Under Article 267 of the Polish Criminal Code, recording a call may require the other party's consent. By using the demo and continuing the call after hearing the notice, you consent to recording and transcription for the purposes described in this Policy. You can withdraw consent at any time, see Section 11.

Section 6. Voice data and biometrics

A person's voice can, under certain conditions, be biometric data within the meaning of Article 4(14) GDPR. We explain honestly how we process voice:

  • Speech understanding (standard): voice is processed to recognize what was said (transcription) and to hold the conversation. The recording is not used to identify a person from voice characteristics; this is ordinary personal data (Article 6 GDPR).
  • Voice biometrics (we do not use this): we do not identify or authenticate people based on the unique characteristics of their voice as part of our standard services.
  • Voice cloning: by default we do not clone the voices of real people; we use synthetic voice libraries supplied by our providers. Cloning a specific person's voice is only possible with their written consent and for a strictly defined scope. Cloning the voice of a public figure or a deceased person without consent is prohibited under our rules.

Section 7. AI transparency (the AI Act)

We apply the transparency obligations under Regulation (EU) 2024/1689 (the AI Act), in particular Article 50, concerning AI systems that interact with people. In practice this means:

  • every caller is clearly told that they are talking to an AI system;
  • at any point in the call, they can ask to be transferred to a human;
  • we do not design conversation scripts meant to convince a caller they are talking to a human, or to mislead them;
  • we do not use practices prohibited by the AI Act, including emotion recognition in employment and education contexts, biometric categorization of protected characteristics, or generating deepfakes without consent.

Section 8. Profiling and automated decisions

Our agents use AI for speech recognition, intent classification, voice synthesis and generating responses. These processes are not automated decision making with legal effects within the meaning of Article 22 GDPR; we do not use them to assess your rights, creditworthiness or qualifications.

For marketing purposes we may, to a limited extent, use profiling (matching content to interests), which you can object to at any time.

Section 9. Data recipients and subprocessors

We entrust data to trusted providers who process it only on our instructions, under data processing agreements. We apply data minimization: only as many parties as necessary to provide the service have access to the data.

Provider categoryFunction
Website hosting providerHosting the website and its forms
Traffic protection and analytics providerBot protection, security, analytics
Telecom provider (VoIP/SMS)Placing demo calls and sending verification messages
AI voice technology providersSpeech synthesis, speech to text transcription, the language model that runs the conversation
Transactional email providerSending messages and notifications
CRM system and booking calendarManaging contacts and scheduling meetings
Marketing and analytics toolsMeasuring ad performance and remarketing (with cookie consent)
Accounting firm, law firms, public authoritiesAccounting and legal support, and cases required by law

Transferring data to the booking system

The booking calendar is embedded on our site, but it is run by an external provider acting as our processor. After you submit the application form, your name, email address and phone number are passed to this system, so it can fill in the booking fields for you and you do not have to type them again. Along with them we pass a technical submission identifier that lets us match the submitted form to the booked appointment.

The same data would reach the booking system anyway once the appointment is confirmed. Passing it earlier changes the timing, not the recipient or the scope.

We provide the current, detailed list of subprocessors on request at hello@gethelpify.com.

Section 10. Transfers of data outside the EEA

Some of the providers we use (for example, AI voice technology or marketing tool providers) may be based outside the European Economic Area, including in the United States. Data is only transferred outside the EEA using the safeguards required by GDPR:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • the provider's certification under the Data Privacy Framework (the adequacy decision for the US).

On request, we will provide information about the safeguards applied to a specific transfer.

Section 11. Your rights

In connection with the processing of your data, you have the following rights under GDPR:

  • the right to access your data and receive a copy of it (Article 15);
  • the right to have your data corrected (Article 16);
  • the right to erasure (Article 17);
  • the right to restrict processing (Article 18);
  • the right to data portability (Article 20);
  • the right to object to processing based on legitimate interest, including direct marketing (Article 21);
  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;
  • the right to lodge a complaint with the President of the Polish Data Protection Authority (Urzad Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland).

You can submit a request to exercise your rights at hello@gethelpify.comor in writing to the Controller's registered address. We respond without undue delay, generally within one month. You can opt out of the newsletter and marketing communications at any time by clicking "Unsubscribe" in a message, or by writing to us.

Section 12. Data security

We apply technical and organizational measures appropriate to the risk (Article 32 GDPR): encrypted connections (TLS/HTTPS), role based access control, authentication for administrative accounts, regular security updates, backups, and confidentiality commitments and authorizations for people with access to the data. We also have an incident response procedure in line with Article 33 GDPR.

Section 13. Cookies and analytics

This website uses cookies necessary for it to function properly, and, once you consent, analytics and marketing cookies (including Google Analytics and advertising pixels). Analytics and marketing cookies only run once you consent, and you can change or withdraw that consent at any time. Necessary cookies do not require consent and are not used to identify a person.

You can change your consent at any time here: , and also in your browser settings.

Section 14. Changes to this Policy

We may update this Policy to reflect changes in the law, technology or the scope of our services. The current version is always available at this address, with the date of the last change shown at the top of the document.

Maciej Odrobina - Tax ID (NIP) 9691675425 - REGON 543235659 - ul. Szarych Szeregów 1E/6, 44-194 Knurów - hello@gethelpify.com