Privacy, Data Processing & Transparency Policy
Effective 22 August 2026
Last updated: 22 August 2026
Important — please read this policy carefully
This Privacy, Data Processing & Transparency Policy (“Privacy Policy”, “Policy”) explains in detail how Hawi Inc., operating Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, “our”) collects, receives, accesses, observes, records, generates, organises, stores, structures, retrieves, analyses, combines, transmits, discloses, restricts, archives, deletes and otherwise processes information relating to identifiable individuals.
Hawi provides software Agents capable of performing operational work, communicating through third-party systems, reading and writing information, handling files and messages, interacting with connected services, participating in voice calls, producing transcripts, carrying out authorised business workflows, communicating with third parties and, where specifically enabled, performing financial or otherwise consequential actions.
Using an Agent may therefore cause Personal Data to move between Hawi, the Customer, the Customer's Connected Services, infrastructure providers, communications providers, model providers and other service providers necessary to perform the task.
This Policy is deliberately detailed because Hawi wants users, Customers, administrators and individuals interacting with Hawi Agents to understand what may occur when the Services are used.
However:
This Privacy Policy does not itself constitute consent where consent is legally required.
Where processing requires consent, Hawi or the relevant Customer must obtain the required consent separately.
Similarly:
A person's acceptance of Hawi's Terms of Service or acknowledgement of this Privacy Policy does not waive that person's statutory privacy rights.
No provision of this Policy is intended to remove a right that applicable law does not permit a person to waive.
Part 1 — IMPORTANT DISCLOSURES AT A GLANCE
The following disclosures are particularly important.
1. Hawi uses software Agents
Hawi allows Customers to create and operate software Agents.
Depending on Customer configuration, an Agent may:
- read information;
- analyse information;
- retrieve records;
- generate responses;
- communicate externally;
- send emails;
- respond to messages;
- update Connected Services;
- schedule events;
- retrieve documents;
- process files;
- interact with commerce systems;
- interact with customer-support systems;
- conduct or participate in calls;
- transcribe calls;
- perform follow-up actions;
- delegate tasks to another authorised Agent;
- and perform other actions authorised by the Customer.
2. Hawi Agents may interact with third parties
An individual may interact with a Hawi Agent without creating a Hawi account.
For example, Hawi may process information concerning:
- a business's customer;
- caller;
- supplier;
- employee;
- contractor;
- prospect;
- applicant;
- buyer;
- seller;
- support requester;
- delivery recipient;
- or business contact.
Where Hawi processes that information on behalf of a Customer, the Customer will normally be responsible for determining the purpose and lawful basis of that processing.
3. Hawi uses external providers
Hawi relies on external infrastructure and service providers.
Depending on the Service being used, information may be processed through providers supporting:
- hosting;
- databases;
- authentication;
- storage;
- model inference;
- AI functionality;
- voice functionality;
- telecommunications;
- speech recognition;
- speech synthesis;
- payments;
- financial connections;
- analytics;
- monitoring;
- email;
- security;
- and third-party integrations.
4. Information may leave your country
Even where Hawi stores core information in a particular region, Personal Data may be processed internationally because service providers, Connected Services and Customers may operate in multiple countries.
International transfers are addressed later in this Policy.
5. Agents may process the contents of connected systems
If a Customer connects a system such as an email account, calendar, CRM, commerce platform or another service, authorised Hawi Agents may process information available through the permissions granted to that connection.
This can include third-party Personal Data.
6. Agents may create new information
Hawi Agents can generate:
- summaries;
- classifications;
- drafts;
- recommendations;
- task records;
- extracted fields;
- structured data;
- inferred information;
- and other outputs.
Generated or inferred information relating to an identifiable person may itself constitute Personal Data.
7. AI-generated information may be incorrect
Model-generated or Agent-generated output can be:
- inaccurate;
- incomplete;
- outdated;
- misleading;
- inappropriate;
- or based on incorrect source information.
Customers should implement human review where the consequences of an error would be significant.
8. Hawi may maintain Agent activity records
Hawi may maintain records of Agent activity to:
- provide continuity;
- allow tasks to resume;
- identify failures;
- prevent duplicate external actions;
- investigate incidents;
- calculate usage;
- enforce limits;
- provide auditability;
- process approvals;
- and support users.
9. Connected Service credentials require special protection
Hawi may hold OAuth tokens, API credentials or similar authentication material necessary to access Connected Services.
Hawi is designed to keep those credentials in restricted server-side systems rather than expose unrestricted credentials directly to Agents, ordinary users or browser clients.
10. Some activities require additional notice or consent
Certain functionality may require additional disclosures, consent or affirmative acknowledgement.
Examples can include:
- optional analytics;
- direct marketing;
- call recording;
- voice transcription;
- Special Category Data;
- wellness information;
- automatic purchasing;
- financial connections;
- certain automated decisions;
- or processing requiring consent under applicable law.
11. Automatic purchasing is a separate permission
Permission for an Agent to generally operate autonomously does not automatically give the Agent permission to spend money.
Where Hawi provides automatic purchasing, it should be subject to separate configuration and authorisation.
12. Hawi may process Personal Data to protect the Service
Security processing may include:
- IP addresses;
- request metadata;
- failed authentication attempts;
- device information;
- suspicious activity;
- rate-limit events;
- malware indicators;
- abuse reports;
- and security alerts.
13. Business administrators may have access to business information
Where an Account is controlled by an organisation, authorised Account or Workspace administrators may be able to access organisational information.
A user should not assume information placed into a company-controlled Workspace is private from that organisation.
14. A Customer connecting data to Hawi remains responsible for its legal authority to do so
Hawi's technical ability to process information does not establish the Customer's right to provide, access or process that information.
Part 2 — WHO WE ARE
15. Hawi Inc.
The Services are operated by:
Hawi Inc.
Trading as: Hawi Agents
Website:
General contact:
Privacy contact:
Security contact:
Part 3 — APPLICATION OF THIS POLICY
16. Services covered
This Policy applies to Hawi's:
- websites;
- Accounts;
- Workspaces;
- Agents;
- Boards;
- chat functionality;
- team messaging;
- voice functionality;
- file processing;
- integrations;
- Connected Services;
- APIs;
- marketplace;
- creator functionality;
- billing;
- credits;
- voice units;
- financial functionality;
- automatic purchasing;
- support;
- privacy systems;
- security systems;
- and related Hawi applications.
17. Additional notices
Certain Hawi functionality may have additional privacy notices.
For example:
- voice recording;
- wellness information;
- financial connections;
- automatic purchasing;
- marketplace participation;
- marketing;
- cookies;
- or experimental features.
Those notices supplement this Policy.
18. Just-in-time notices
Where appropriate, Hawi may display notices immediately before a particular processing activity.
For example:
“This call will be transcribed.”
or:
“Connecting this account allows authorised Agents in this Workspace to read and perform the actions described below.”
or:
“Enabling automatic purchasing allows eligible Agents to complete purchases up to the spending limit you configure.”
A feature-specific notice may provide information more directly relevant to that processing than this general Policy.
Part 4 — HAWI'S DATA-PROTECTION ROLE
19. Hawi as controller
Hawi generally acts as controller for Personal Data processed for purposes such as:
- registration;
- authentication;
- Hawi Account administration;
- billing;
- marketplace administration;
- creator payouts;
- security;
- fraud prevention;
- service analytics;
- privacy requests;
- legal compliance;
- and Hawi's own customer relationship management.
20. Hawi as processor
Hawi generally acts as processor where a Customer uses Hawi to process information for purposes determined by that Customer.
Examples include:
- processing the Customer's email;
- processing customer-support tickets;
- processing CRM information;
- responding to Customer communications;
- handling Customer files;
- accessing Customer orders;
- processing Customer calls;
- and performing Customer-configured workflows.
21. Customer as controller
Where Hawi processes Personal Data on behalf of a Customer, that Customer will usually determine:
- why information is processed;
- which information is processed;
- which Connected Services are used;
- which Agents have access;
- which actions are authorised;
- and how long certain information should be retained.
22. Customer responsibility
Customers are responsible for establishing, where required:
- a lawful basis;
- transparency;
- consent;
- employment-law compliance;
- marketing-law compliance;
- call-recording compliance;
- consumer-law compliance;
- and appropriate internal authorisation.
Part 5 — DATA PROCESSING AGREEMENT
23. Article 28 processing
Where Hawi processes Personal Data on behalf of a Customer, Hawi and the Customer may be subject to Hawi's Data Processing Agreement.
24. Documented instructions
Where Hawi acts as processor, Hawi will process Personal Data according to the Customer's documented instructions except where law requires processing outside those instructions.
25. Unlawful instructions
Hawi may decline, suspend or restrict an instruction where Hawi reasonably believes the instruction:
- violates applicable law;
- compromises security;
- violates another person's rights;
- exceeds permitted access;
- or breaches Hawi's contractual restrictions.
Part 6 — INFORMATION YOU PROVIDE
26. Registration information
Hawi may collect:
- name;
- email;
- telephone number;
- username;
- profile image;
- timezone;
- organisation;
- role;
- authentication information;
- and age-confirmation information.
27. Information entered into Hawi
Anything entered into:
- a prompt;
- form;
- message;
- Agent instruction;
- Workspace;
- file;
- Board;
- task;
- support ticket;
- or other Hawi field
may be processed to provide the applicable functionality.
Part 7 — ACCOUNT AND WORKSPACE DATA
Hawi may process:
- Account ID;
- Account name;
- owner;
- administrators;
- members;
- billing contact;
- membership;
- invitations;
- roles;
- seat allocations;
- status;
- Workspace membership;
- Workspace permissions;
- Agent assignments;
- integration assignments;
- and administrative activity.
Part 8 — AGENT INFORMATION
Agent information may include:
- Agent name;
- purpose;
- instructions;
- restrictions;
- model;
- tools;
- Connected Service permissions;
- Workspace assignment;
- spending permissions;
- approval requirements;
- scheduling;
- triggers;
- collaborators;
- execution status;
- version;
- limits;
- and operational settings.
Part 9 — PROMPTS, RESPONSES AND AGENT RUNS
Hawi may process:
- prompts;
- instructions;
- relevant conversation history;
- model inputs;
- visible outputs;
- structured tool calls;
- tool results;
- runtime state;
- task state;
- retries;
- completion information;
- provider/model information;
- usage information;
- and error information.
Part 10 — MODEL REASONING
Hawi may process visible model outputs and structured operational information.
Hawi does not intend to expose or retain proprietary hidden chain-of-thought from model providers as ordinary Customer Content.
Where a model provider generates internal reasoning not returned by the API as Customer-visible content, Hawi should not represent that hidden provider reasoning as a Customer record.
Hawi may nevertheless retain:
- summaries;
- decisions;
- action selections;
- observable outputs;
- and operational events
necessary to explain what happened during an Agent run.
Part 11 — AGENT MEMORY
Where Hawi offers Agent memory, Personal Data may be retained so that an Agent can remember information across sessions.
Memory may include:
- user preferences;
- business rules;
- customer information;
- prior task outcomes;
- operational context;
- and information intentionally stored for later use.
Where practical, Customers should be given controls for:
- viewing memory;
- editing memory;
- deleting memory;
- or disabling memory.
Memory should not be used as a means of avoiding applicable retention requirements.
Part 12 — TEAM CHAT
Team chat may contain:
- messages;
- attachments;
- mentions;
- Agent responses;
- timestamps;
- participant identities;
- and Workspace information.
Users should not place unnecessary highly sensitive information into team chat.
Part 13 — FILES
Hawi may process:
- file content;
- filename;
- extension;
- MIME type;
- size;
- uploader;
- Workspace;
- file hash;
- upload time;
- validation status;
- storage location;
- malware status;
- quarantine status;
- and access metadata.
Part 14 — FILE SECURITY
Files may undergo automated technical inspection for:
- malware;
- executable content;
- dangerous file structures;
- mismatched extensions;
- invalid MIME types;
- suspicious archives;
- malicious macros;
- or other security risks.
A file may be:
- quarantined;
- rejected;
- restricted;
- deleted;
- or prevented from being opened
where Hawi believes it presents a security threat.
Part 15 — CONNECTED SERVICES
Customers may connect external services to Hawi.
Hawi may process:
- provider;
- account identifier;
- organisation identifier;
- connection owner;
- scopes;
- permissions;
- token expiry;
- status;
- provider metadata;
- webhook configuration;
- credential reference;
- and connection activity.
Part 16 — WHAT CONNECTING A SERVICE MEANS
When you connect a service, you authorise Hawi to interact with that service within the permissions granted and Hawi's own permission controls.
This can allow Hawi to:
- retrieve information;
- read records;
- create records;
- update records;
- delete records where supported and authorised;
- send messages;
- upload information;
- download information;
- and perform other operations exposed by the Connected Service.
Exactly which actions are available depends on the provider and the Customer's configuration.
Part 17 — ACCOUNT-SCOPED CONNECTIONS
A Connected Service may be owned at Account level while being selectively enabled for one or more Workspaces.
This means a Customer may connect a provider once and assign access to selected Workspaces without duplicating the underlying secret.
Part 18 — CONNECTOR CREDENTIALS
Credentials may include:
- OAuth access tokens;
- refresh tokens;
- API keys;
- client secrets;
- service credentials;
- private keys;
- basic-authentication credentials;
- database credentials;
- and webhook secrets.
Hawi should store credentials in restricted systems designed for secrets.
Part 19 — CREDENTIAL ACCESS
Possession of a Connected Service within an Account does not automatically mean every:
- user;
- Workspace;
- Agent;
- or application
may use the connection.
Access may depend on:
- Account role;
- Workspace assignment;
- Agent permission;
- operation permission;
- approval requirement;
- and provider restrictions.
Part 20 — EMAIL
An authorised email integration may allow Hawi to process:
- sender;
- recipient;
- subject;
- body;
- attachments;
- headers;
- labels;
- folders;
- thread history;
- drafts;
- message IDs;
- and timestamps.
An Agent may, where authorised:
- read;
- categorise;
- summarise;
- draft;
- reply;
- forward;
- archive;
- label;
- or otherwise interact with messages.
Part 21 — CALENDAR
Calendar processing may include:
- event title;
- attendees;
- email addresses;
- times;
- location;
- conference links;
- notes;
- description;
- recurrence;
- availability;
- and reminders.
Part 22 — CONTACTS
Connected contact systems may contain:
- name;
- email;
- phone;
- address;
- employer;
- title;
- notes;
- relationship;
- and custom fields.
Part 23 — CRM
Hawi may process:
- leads;
- contacts;
- customers;
- companies;
- deals;
- notes;
- tasks;
- sales activities;
- pipeline information;
- and communications.
Part 24 — PROJECT MANAGEMENT
Connected project-management information may include:
- task;
- project;
- owner;
- due date;
- status;
- assignee;
- comment;
- attachment;
- priority;
- and activity history.
Part 25 — COMMERCE
Commerce information may include:
- buyer;
- seller;
- product;
- order;
- address;
- inventory;
- refund;
- return;
- shipping;
- fulfilment;
- supplier;
- price;
- and transaction information.
Part 26 — CUSTOMER SUPPORT
Support-platform data may include:
- customer identity;
- support request;
- message history;
- ticket;
- priority;
- attachment;
- resolution;
- and internal notes.
Part 27 — THIRD-PARTY DATA
Customers may instruct Hawi to process Personal Data relating to people who do not use Hawi.
A Customer must ensure such processing is lawful.
Hawi cannot independently guarantee that every Customer has fulfilled every notice or consent obligation owed to every person whose information appears in Customer systems.
Part 28 — INDIRECT COLLECTION
Where Hawi acts as controller and receives Personal Data about an individual from another source, Hawi will provide the required privacy information in accordance with applicable law unless an exemption applies.
Where Hawi acts solely as processor, the relevant Customer is generally responsible for Article 13/14 transparency obligations.
Part 29 — VOICE
Hawi voice functionality may process:
- caller number;
- recipient number;
- call identifier;
- call provider identifier;
- call direction;
- duration;
- timestamps;
- Agent identity;
- status;
- outcome;
- transcript;
- and other call metadata.
Part 30 — VOICE AUDIO
Where supported and enabled, Hawi may process audio to:
- transmit speech;
- convert speech to text;
- understand requests;
- generate responses;
- convert text to speech;
- and provide call functionality.
Part 31 — RECORDING
Where a call is recorded, additional legal obligations may apply.
Whether recording is lawful may depend on:
- the location of the Customer;
- the caller's location;
- the recipient's location;
- the purpose;
- the type of call;
- and applicable telecommunications and privacy law.
Part 32 — TRANSCRIPTION
Where transcription is enabled, spoken communications may be converted into written text.
Transcripts can include anything spoken during a call, including:
- names;
- addresses;
- telephone numbers;
- order information;
- financial information;
- health information;
- or other sensitive content disclosed by a participant.
Part 33 — CUSTOMER RESPONSIBILITY FOR CALL NOTICES
Customers are responsible for determining when a caller must be informed that:
- an automated Agent is participating;
- a call is recorded;
- a call is transcribed;
- AI analysis is being used;
- or information will be entered into other systems.
Part 34 — CALL FOLLOW-UP
An Agent may be configured to use information obtained during a call to take authorised follow-up actions, including:
- sending an email;
- updating a CRM;
- creating a calendar event;
- creating a task;
- updating an order;
- or notifying a Customer.
Part 35 — BILLING
Hawi may process:
- subscription;
- plan;
- seats;
- billing cycle;
- currency;
- amount;
- invoice;
- payment status;
- payment-provider IDs;
- cancellation;
- renewal;
- usage;
- credits;
- and voice allocation.
Part 36 — PAYMENT PROVIDERS
Payment-card information may be processed by third-party payment processors such as Stripe.
Hawi may receive limited information such as:
- payment status;
- transaction ID;
- card brand;
- last four digits;
- expiry metadata;
- fraud information;
- refund information;
- and dispute information.
Part 37 — HAWI CREDITS
Hawi may maintain:
- credit wallets;
- credit grants;
- purchased credit lots;
- reservations;
- usage deductions;
- settlements;
- refunds;
- adjustments;
- expiration;
- pricing versions;
- and usage history.
Part 38 — VOICE UNITS
Voice usage may use a separate balance.
Hawi may process:
- purchased voice amount;
- available voice amount;
- reserved voice units;
- consumed voice units;
- call duration;
- and provider cost information.
Part 39 — AUTOMATIC RECHARGE
If a Customer enables automatic recharge, Hawi may automatically initiate payment under the limits and settings selected by the Customer.
Hawi may record:
- who enabled the feature;
- when it was enabled;
- threshold;
- amount;
- monthly cap;
- payment source reference;
- attempt;
- failure;
- success;
- and subsequent disablement.
Part 40 — AGENT PURCHASING
Where available and separately enabled, a Hawi Agent may be permitted to make purchases.
This may involve processing:
- item;
- seller;
- amount;
- currency;
- shipping information;
- recipient;
- approval state;
- payment reference;
- purchase status;
- and receipt information.
Part 41 — PURCHASING IS NOT IMPLIED
Creating an Agent does not alone authorise that Agent to make purchases.
Allowing an Agent to send messages does not alone authorise purchasing.
Allowing an Agent to access an integration does not alone authorise spending.
Automatic purchasing should require separate activation.
Part 42 — SPENDING LIMITS
Customers may be able to configure:
- per-purchase limits;
- Agent limits;
- daily limits;
- monthly limits;
- category restrictions;
- merchant restrictions;
- or other spending controls.
Part 43 — PURCHASE NOTIFICATIONS
Where configured, Hawi may notify designated recipients following Agent spending.
A notification may contain:
- Agent;
- amount;
- merchant;
- product;
- Workspace;
- timestamp;
- outcome;
- and receipt information.
Part 44 — BANKING CONNECTIONS
Where Customers use financial-data functionality, Hawi may process bank-account metadata made available by an authorised financial-data provider.
This may include:
- bank;
- account type;
- masked account number;
- connection status;
- account identifier;
- provider identifier;
- and transaction information where authorised.
Part 45 — PLAID OR SIMILAR PROVIDERS
Where a financial provider such as Plaid is used, the financial provider may independently process data under its own privacy policy and contractual terms.
Part 46 — MARKETPLACE
Marketplace information may include:
- creator;
- seller;
- buyer;
- listing;
- price;
- sale;
- review;
- rating;
- fee;
- refund;
- dispute;
- payout;
- and moderation information.
Part 47 — MARKETPLACE PAYOUTS
Hawi may process information required to:
- calculate creator earnings;
- process payouts;
- handle taxes;
- identify fraud;
- reverse invalid transactions;
- and comply with financial obligations.
Part 48 — USER-GENERATED MARKETPLACE CONTENT
Users publishing marketplace content should understand that public listing information may be visible to other Hawi users.
Public information may include:
- creator name;
- listing name;
- description;
- screenshots;
- rating;
- review;
- and other information intentionally made public.
Part 49 — MODERATION
Hawi may review marketplace or platform content to:
- enforce rules;
- investigate reports;
- detect scams;
- prevent malicious content;
- protect users;
- and comply with law.
Part 50 — API USAGE
Developer API information may include:
- API-key identifier;
- Account;
- Workspace;
- endpoint;
- request count;
- request time;
- IP address;
- status;
- error information;
- and usage.
Part 51 — TECHNICAL INFORMATION
Hawi may automatically process:
- IP address;
- browser;
- operating system;
- approximate location derived from network information;
- language;
- device type;
- request path;
- response status;
- user agent;
- session;
- timestamp;
- and error information.
Part 52 — IP ADDRESSES
IP addresses may be processed for:
- security;
- authentication;
- fraud detection;
- rate limiting;
- abuse investigation;
- troubleshooting;
- and approximate regionalisation.
Part 53 — ANALYTICS
Where permitted and subject to applicable consent requirements, Hawi may process usage information to understand:
- page visits;
- feature usage;
- performance;
- conversion;
- errors;
- and general product interaction.
Part 54 — COOKIE CONSENT
Where consent is legally required for optional cookies or similar technologies, Hawi will seek consent before enabling the relevant technology.
Rejecting optional analytics should not prevent strictly necessary Hawi functionality from operating.
Part 55 — MARKETING
Hawi may send marketing where permitted by law.
Users may opt out of marketing.
Opting out of marketing does not stop essential:
- billing;
- security;
- Account;
- privacy;
- legal;
- or Service notifications.
Part 56 — SECURITY PROCESSING
Hawi may process information to:
- identify attacks;
- detect suspicious logins;
- prevent credential abuse;
- identify malware;
- prevent spam;
- block rate-limit abuse;
- investigate fraud;
- detect cross-Account access attempts;
- prevent privilege escalation;
- and protect infrastructure.
Part 57 — FRAUD DETECTION
Hawi may analyse:
- payment activity;
- Account activity;
- Agent actions;
- marketplace activity;
- login behaviour;
- network information;
- and transaction patterns
to identify suspected fraud.
Part 58 — ABUSE PREVENTION
Hawi may restrict or suspend activity that appears to involve:
- unauthorised access;
- fraud;
- malicious automation;
- credential theft;
- spam;
- malware;
- evasion;
- excessive abusive requests;
- or another prohibited activity.
Part 59 — SUPPORT ACCESS
Where necessary to resolve a support issue, authorised Hawi personnel may access limited Account information relevant to the problem.
Support access should be:
- authorised;
- proportionate;
- limited;
- and logged where appropriate.
Part 60 — EMPLOYEE ACCESS
Hawi personnel should not browse Customer data without an appropriate business reason.
Access may be permitted for:
- support;
- debugging;
- incident response;
- security;
- compliance;
- fraud investigation;
- or legal obligations.
Part 61 — AI/MODEL PROVIDERS
Hawi may use external model providers to perform:
- text generation;
- reasoning;
- extraction;
- classification;
- planning;
- tool selection;
- transcription;
- speech processing;
- and other Agent functionality.
Part 62 — WHAT MAY BE SENT TO MODEL PROVIDERS
Relevant information may include:
- system instructions;
- prompts;
- recent conversation context;
- selected Connected Service information;
- selected file content;
- tool definitions;
- and task-related information.
Hawi should seek to send only information reasonably required for the task.
Part 63 — MODEL PROVIDER TRAINING
Whether a third-party model provider may use information for its own model training depends on:
- provider;
- API product;
- contract;
- Account configuration;
- and provider terms.
Hawi should disclose the actual production arrangements through appropriate product documentation or its Subprocessor List.
Hawi will not state that data is never used for provider training unless the applicable technical and contractual arrangements support that statement.
Part 64 — HAWI TRAINING
Hawi does not intend to sell private Customer prompts or private Workspace content for unrelated third-party model training.
If Hawi intends to use identifiable Customer Content to train a general-purpose Hawi model for purposes materially different from providing the Customer's Service, Hawi must establish an appropriate lawful basis and provide additional notice before commencing such processing.
Part 65 — AUTOMATED PROCESSING
Hawi Agents may automatically:
- categorise;
- rank;
- extract;
- prioritise;
- summarise;
- recommend;
- schedule;
- route;
- draft;
- and execute authorised operations.
Part 66 — PROFILING
Automated processing may constitute profiling where Personal Data is used to evaluate or predict characteristics concerning a person.
Where applicable, Hawi or the Customer must comply with the legal requirements relating to profiling.
Part 67 — SIGNIFICANT AUTOMATED DECISIONS
Hawi's general-purpose Services are not intended to be used to make unlawful solely automated decisions producing legal or similarly significant effects on a person.
Where applicable law imposes specific requirements, the relevant controller must provide safeguards.
Part 68 — HIGH-RISK DECISIONS
Customers should not deploy Hawi without appropriate assessment for decisions involving:
- hiring;
- firing;
- employment discipline;
- credit;
- lending;
- insurance;
- healthcare;
- housing;
- education;
- access to essential services;
- criminal justice;
- or other decisions having significant consequences.
Part 69 — HUMAN INTERVENTION
Where required by law, users or affected individuals may need to be provided with:
- human review;
- the ability to express their view;
- an explanation;
- and the ability to contest a decision.
Part 70 — AGENT ERROR AND HUMAN OVERSIGHT
Customers are responsible for deciding when a Hawi Agent's output should require human review.
Hawi may provide technical approval controls, but Hawi cannot determine every Customer's legal or operational review obligation.
Part 71 — SPECIAL CATEGORY DATA
Hawi may process Special Category Data where it appears in Customer Content.
Examples may include:
- health information;
- racial or ethnic information;
- religion;
- political opinions;
- biometric information;
- union membership;
- sex-life information;
- or sexual-orientation information.
Customers should not provide such information unless necessary and lawful.
Part 72 — WELLNESS INFORMATION
Where Hawi provides optional wellness features, explicit consent may be used where required by Article 9 GDPR.
Consent should be separate and specific.
Part 73 — WELLNESS CONSENT
A wellness-consent record may identify:
- person;
- purpose;
- categories;
- processor;
- model/Agent analysis;
- notice version;
- exact consent text;
- timestamp;
- method;
- withdrawal;
- and erasure.
Part 74 — WITHDRAWING WELLNESS CONSENT
Where processing relies solely on explicit consent, withdrawal should stop future processing unless another legal basis permits continuation.
Applicable wellness information should be erased where required.
Part 75 — CHILDREN
Hawi's ordinary Accounts are intended for users aged 18 or over.
Hawi does not knowingly intend to permit children to open ordinary Hawi Accounts.
Part 76 — CHILD DATA IN CUSTOMER SYSTEMS
A Customer's Connected Services may nevertheless contain information about children.
Customers are responsible for ensuring processing of such information is lawful.
Part 77 — PURPOSES OF PROCESSING
Hawi may process Personal Data to:
- provide the Services;
- authenticate users;
- execute Agent tasks;
- maintain Agent continuity;
- provide Connected Service functionality;
- provide voice services;
- store files;
- facilitate teamwork;
- process billing;
- administer credits;
- operate marketplace functionality;
- provide support;
- secure the Service;
- prevent fraud;
- maintain reliability;
- comply with law;
- and establish or defend legal claims.
Part 78 — CONTRACTUAL NECESSITY
Where applicable, Hawi may rely on Article 6(1)(b) GDPR where processing is necessary to perform its contract with an individual.
Part 79 — LEGITIMATE INTERESTS
Hawi may rely on legitimate interests for activities such as:
- fraud prevention;
- security;
- service reliability;
- business administration;
- abuse prevention;
- and legal claims,
where those interests are not overridden by the affected person's rights.
Part 80 — CONSENT
Where consent is used, Hawi should:
- request a positive action;
- avoid pre-ticked boxes;
- make the request specific;
- separate it where appropriate;
- explain what is being agreed to;
- record the consent;
- and provide an easy withdrawal mechanism.
Part 81 — LEGAL OBLIGATIONS
Hawi may process information to satisfy:
- tax law;
- accounting law;
- regulator requirements;
- court orders;
- privacy law;
- financial obligations;
- and other applicable legislation.
Part 82 — LEGAL CLAIMS
Hawi may retain or use Personal Data where necessary to:
- establish;
- exercise;
- investigate;
- defend;
- or settle
a legal claim.
Part 83 — DATA SHARING
Personal Data may be shared with organisations that help Hawi provide the Services.
These organisations may include providers of:
- hosting;
- databases;
- storage;
- models;
- communications;
- voice;
- speech;
- payments;
- banking connectivity;
- analytics;
- security;
- email;
- support;
- and Connected Services.
Part 84 — SUBPROCESSORS
Hawi should maintain a current Subprocessor List.
The list should identify, where appropriate:
- provider;
- purpose;
- location;
- and transfer mechanism.
Part 85 — VERCEL
Hawi currently uses Vercel infrastructure for aspects of:
- application hosting;
- deployment;
- computation;
- application delivery;
- analytics/performance tooling where enabled;
- and related infrastructure.
Part 86 — SUPABASE
Hawi currently uses Supabase for aspects of:
- PostgreSQL databases;
- storage;
- authentication;
- backend services;
- and associated infrastructure.
Hawi's current Supabase project is configured in the London, United Kingdom (eu-west-2) region.
Part 87 — STRIPE
Hawi may use Stripe for:
- payments;
- subscriptions;
- payment-method processing;
- marketplace payments;
- creator payouts;
- connected accounts;
- fraud functions;
- refunds;
- and chargebacks.
Part 88 — VOICE PROVIDERS
Voice functionality may require Hawi to transmit necessary information to:
- telecommunications providers;
- speech-to-text providers;
- text-to-speech providers;
- and call-processing infrastructure.
Part 89 — CONNECTED SERVICE PROVIDERS
When an Agent performs an operation through a Connected Service, information may be transmitted to that Connected Service.
For example, sending an email necessarily transmits the email to the email provider and intended recipient.
Part 90 — INTERNATIONAL TRANSFERS
Personal Data may be processed outside:
- the United Kingdom;
- the European Economic Area;
- or the Data Subject's country
when necessary to provide the Services.
Part 91 — UK TRANSFERS
Where required, Hawi may use:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- Binding Corporate Rules;
- or another legally recognised safeguard.
Part 92 — EU TRANSFERS
Where EU GDPR applies, Hawi may use:
- adequacy decisions;
- Standard Contractual Clauses;
- Binding Corporate Rules;
- or another Article 46 transfer safeguard.
Part 93 — TRANSFER ASSESSMENTS
Where necessary, Hawi may assess whether destination-country law or practices could materially impair the transfer safeguard.
Part 94 — RETENTION
Hawi retains Personal Data according to the purpose, legal obligations, Customer configuration, security considerations and technical requirements.
Part 95 — CURRENT RETENTION EXAMPLES
At the date of this Policy, Hawi's technical systems include retention schedules such as:
| Record | Indicative retention |
|---|---|
| Certain OAuth state | ~1 hour |
| Phone verification challenges | ~24 hours |
| Security challenges | ~24 hours |
| API rate-limit buckets | ~7 days |
| Certain API/security logs | ~30 days |
| Certain webhook records | ~30 days |
| Certain connector executions | ~90 days |
| Wellness measurements | ~180 days |
| Voice transcript turns | ~365 days |
| Voice notes | ~365 days |
| Certain top-up/payment-attempt records | ~2 years |
These periods may change where law, Customer configuration, security or operational necessity requires another period.
Part 96 — ACTIVE CUSTOMER CONTENT
Customer Content may generally remain available while the relevant Account is active or until deleted through the Services, subject to applicable retention settings.
Part 97 — FINANCIAL RECORDS
Billing, payout, accounting and tax records may need to be retained for longer statutory periods.
Part 98 — SECURITY RECORDS
Security information may be retained to:
- investigate attacks;
- identify repeated abuse;
- prevent fraud;
- and establish legal claims.
Part 99 — BACKUPS
Information deleted from active systems may remain temporarily in protected backup systems.
Backups may be retained until overwritten through ordinary backup rotation.
Part 100 — LEGAL HOLDS
A legal hold may temporarily suspend normal deletion.
Part 101 — DATA MINIMISATION
Hawi should process only Personal Data reasonably necessary to perform the applicable purpose.
Part 102 — SECURITY
Hawi uses or seeks to use measures including:
- encryption in transit;
- restricted credential storage;
- private storage;
- authentication;
- MFA support;
- access controls;
- Account isolation;
- Workspace isolation;
- audit logging;
- rate limiting;
- malware detection;
- file validation;
- security headers;
- secret separation;
- webhook verification;
- monitoring;
- and incident response.
Part 103 — NO GUARANTEE OF ABSOLUTE SECURITY
No online system is completely immune from attack, error or unauthorised access.
Hawi cannot guarantee absolute security.
Part 104 — CUSTOMER SECURITY RESPONSIBILITY
Customers remain responsible for:
- secure passwords;
- MFA;
- secure devices;
- staff access;
- Agent permissions;
- integration assignments;
- API keys;
- employee offboarding;
- and protecting credentials.
Part 105 — PERSONAL DATA BREACHES
Where Hawi experiences a Personal Data breach, Hawi will investigate and respond according to applicable legal obligations.
Part 106 — PROCESSOR BREACH NOTIFICATION
Where Hawi acts as processor, Hawi will notify the relevant controller without undue delay where required.
Part 107 — REGULATOR NOTIFICATION
Where applicable law requires regulatory notification, Hawi will make the required notification within the applicable timeframe.
Part 108 — INDIVIDUAL NOTIFICATION
Affected individuals will be informed where required by law.
Part 109 — DATA-SUBJECT RIGHTS
Depending on applicable law, individuals may have rights to:
- information;
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- consent withdrawal;
- human review of certain automated decisions;
- and regulatory complaint.
Part 110 — ACCESS
An individual may request access to Personal Data Hawi controls about them.
Part 111 — RECTIFICATION
An individual may request correction of inaccurate Personal Data.
Part 112 — ERASURE
An individual may request deletion where the applicable legal requirements are satisfied.
The right to erasure is not absolute.
Part 113 — RESTRICTION
An individual may request restriction of processing in applicable circumstances.
Part 114 — PORTABILITY
Applicable Personal Data may be provided in a structured, commonly used, machine-readable format where the statutory requirements apply.
Part 115 — OBJECTION
Individuals may object to qualifying processing based on legitimate interests.
Part 116 — MARKETING OBJECTION
Individuals may object to direct marketing at any time.
Part 117 — CONSENT WITHDRAWAL
Consent may be withdrawn.
Withdrawal does not invalidate processing that was lawful before withdrawal.
Part 118 — AUTOMATED DECISION RIGHTS
Where applicable automated decision provisions apply, an individual may be entitled to safeguards including human review and challenge mechanisms.
Part 119 — REQUEST SUBMISSION
Privacy requests may be submitted to:
or, until a dedicated privacy mailbox is operational:
Part 120 — IDENTITY VERIFICATION
Hawi may verify identity before:
- providing a data export;
- changing Personal Data;
- deleting an Account;
- or responding to another privacy request.
Part 121 — THIRD-PARTY RIGHTS
Where disclosing information would reveal another person's Personal Data, Hawi may redact or restrict disclosure as permitted by law.
Part 122 — PROCESSOR REQUESTS
Where Hawi is processor, Hawi may forward a Data Subject's request to the relevant Customer/controller.
Part 123 — ORGANISATIONAL ACCOUNTS
An organisation controlling an Account may retain legitimate business records after an individual user leaves the organisation.
Part 124 — ADMINISTRATOR VISIBILITY
Administrators may be able to access:
- Workspace activity;
- members;
- files;
- Agent information;
- usage;
- Connected Services;
- approvals;
- and other organisational resources
where their role permits it.
Part 125 — EMPLOYEE MONITORING
Customers must not use Hawi for unlawful employee surveillance.
Where employee monitoring occurs, Customers are responsible for meeting applicable legal requirements.
Part 126 — DATA PROTECTION IMPACT ASSESSMENTS
Hawi or Customers should carry out a DPIA where processing is likely to result in high risk to individuals.
Relevant circumstances may include:
- large-scale sensitive data;
- systematic monitoring;
- high-impact automated decisions;
- vulnerable people;
- novel technology;
- or extensive profiling.
Part 127 — RECORDS OF PROCESSING
Hawi maintains or should maintain applicable Article 30 records of processing.
Part 128 — PRIVACY BY DESIGN
Hawi aims to incorporate data protection into system design.
This may include:
- least privilege;
- Account-scoped secrets;
- Workspace assignment;
- explicit approval;
- retention schedules;
- immutable consent records;
- audit trails;
- and privacy-request tooling.
Part 129 — NOTICE VERSIONING
Hawi should assign a version identifier to:
- this Privacy Policy;
- cookie notices;
- consent statements;
- automatic purchasing notices;
- wellness consent;
- voice disclosures;
- financial-data disclosures;
- and other material privacy notices.
Part 130 — PROOF THAT NOTICE WAS PROVIDED
Where reasonably appropriate, Hawi may maintain evidence that a notice was presented.
Such evidence may include:
- user identifier;
- Account identifier;
- notice identifier;
- notice version;
- timestamp;
- presentation method;
- language;
- relevant screen or workflow;
- acknowledgement;
- and withdrawal where applicable.
Part 131 — POLICY ACCEPTANCE RECORDS
Where Hawi requires acknowledgement of this Policy or associated Terms, Hawi may retain:
- policy version;
- timestamp;
- user;
- Account;
- action confirming acknowledgement;
- and related technical evidence.
Acknowledgement of a Policy should not be mischaracterised as consent to processing where consent is legally required.
Part 132 — CONSENT AUDIT TRAILS
Where consent is the lawful basis, Hawi should preserve evidence showing:
- who gave consent;
- when it was given;
- what wording was displayed;
- which notice version was displayed;
- what categories of processing were covered;
- how the person actively opted in;
- whether the choice was optional;
- any later change;
- any withdrawal;
- when withdrawal became effective.
Part 133 — NO PRE-TICKED CONSENT
Consent-dependent processing should not rely on pre-selected checkboxes where applicable privacy law requires affirmative consent.
Part 134 — GRANULAR CONSENT
Separate processing purposes should use separate consent choices where legally required.
For example, Hawi should not combine:
“I accept the Terms”
with:
“I consent to health-data processing and marketing.”
Those are different decisions.
Part 135 — FEATURE-SPECIFIC NOTICES
Hawi should show prominent additional notices before users enable high-impact functionality.
Examples include:
Connecting an email account
Important: Authorised Hawi Agents in the Workspaces you select may read email content and, where you grant permission, send, reply to, modify or otherwise interact with messages through this account.
Voice transcription
Important: Hawi may convert the audio from this call into a text transcript and use the transcript to perform authorised Agent tasks.
Automatic purchasing
Important: Enabling automatic purchasing allows authorised Hawi Agents to complete purchases without asking you to approve every individual transaction, subject to the limits and controls you set.
Bank connection
Important: Connecting a financial account allows Hawi to receive the financial information described on this screen from the selected provider.
Wellness processing
Explicit consent required: This feature may process health or wellness information and may use AI or Agent analysis as described below.
Part 136 — CHANGES IN PROCESSING
If Hawi proposes materially new use of existing Personal Data, Hawi should assess whether:
- the new purpose is compatible;
- a revised notice is required;
- additional consent is required;
- a DPIA is required;
- or another lawful basis is necessary.
Part 137 — MATERIAL POLICY CHANGES
Material changes may be communicated through:
- in-app notice;
- email;
- Account banner;
- Workspace notice;
- or another appropriate mechanism.
Simply changing text on an unnoticed webpage may not be sufficient for every material new use.
Part 138 — HISTORICAL POLICIES
Hawi may preserve historical versions of its Privacy Policy so Hawi can determine which version applied at a particular time.
Part 139 — CONTACTING PEOPLE WHOSE INFORMATION CAME FROM CUSTOMERS
Where Hawi acts as controller and receives information indirectly, Hawi will provide required privacy information within applicable statutory timelines unless an exemption applies.
Where Hawi acts as processor, the Customer is ordinarily responsible.
Part 140 — NO SECRET EXPANSION OF PERMISSIONS
Hawi should not treat a connection permission granted for one clearly described purpose as unrestricted permission for materially unrelated purposes.
Part 141 — USER REVOCATION OF INTEGRATIONS
Customers may disconnect Connected Services.
Disconnecting a service generally prevents future access using that connection.
It does not necessarily automatically erase:
- previously imported records;
- audit logs;
- billing records;
- or information that must otherwise be retained.
Part 142 — DELETION AFTER DISCONNECTION
Customers may separately need to delete previously processed Customer Content if they want it removed from Hawi.
Part 143 — DATA EXPORT
Where supported, Customers may export certain information before deleting an Account or Workspace.
Part 144 — ACCOUNT DELETION
Deletion of an Account may:
- disable Agents;
- terminate sessions;
- revoke integrations;
- remove members;
- schedule eligible Customer Content for deletion;
- and prevent future access.
Part 145 — BUSINESS RECORDS AFTER ACCOUNT CLOSURE
Hawi may retain information after Account closure where reasonably required for:
- accounting;
- tax;
- fraud prevention;
- disputes;
- legal claims;
- security;
- and statutory compliance.
Part 146 — CUSTOMER'S OWN PRIVACY NOTICE
Business Customers should maintain their own privacy notices.
A Customer should not rely solely on Hawi's Privacy Policy to satisfy the Customer's transparency duties concerning its own:
- customers;
- employees;
- suppliers;
- callers;
- website visitors;
- or other Data Subjects.
Part 147 — CUSTOMER INSTRUCTIONS TO AGENTS
A Customer is responsible for ensuring that instructions given to an Agent do not cause unlawful processing.
Part 148 — CUSTOMER DATA QUALITY
Customers are responsible for Personal Data they provide or make available to Hawi.
Hawi cannot independently verify the accuracy or legality of every item of Customer Content.
Part 149 — AGENT-GENERATED COMMUNICATIONS
Where an Agent sends a communication on behalf of a Customer, the Customer remains responsible for ensuring the communication complies with applicable:
- marketing law;
- consumer law;
- employment law;
- confidentiality duties;
- professional duties;
- and industry regulations.
Part 150 — HUMAN REVIEW OF EXTERNAL COMMUNICATIONS
Customers may configure human review before certain communications are sent.
Where the Customer disables such review, authorised Agents may send communications automatically within the permissions provided.
Part 151 — AGENT ACTION AUDITABILITY
Where technically appropriate, Hawi may record:
- what Agent requested an action;
- which Workspace it operated from;
- the operation;
- provider;
- approval;
- timestamp;
- request status;
- external identifier;
- and outcome.
Part 152 — DUPLICATE ACTION PREVENTION
Hawi may process identifiers and execution records to prevent an Agent retry from accidentally repeating an external action.
Part 153 — RATE LIMITING AND QUEUING
When a provider or Hawi reaches an operational rate limit, Agent work may:
- pause;
- queue;
- retry;
- fail;
- or resume later.
Hawi may retain execution state necessary to support this process.
Part 154 — AGENT LOOP PREVENTION
Hawi may analyse Agent activity to identify accidental loops or unreasonable repeated execution.
Hawi may stop or restrict an Agent to protect:
- Customer credits;
- external systems;
- infrastructure;
- and security.
Part 155 — USAGE METERING
Hawi may measure:
- model usage;
- tool usage;
- voice duration;
- storage;
- infrastructure activity;
- and other billable or limited resources.
Part 156 — PROVIDER PRICING
Provider costs may change over time.
Hawi may maintain versioned pricing information to calculate credits or service usage.
Part 157 — NOTIFICATION SYSTEMS
Customers may configure notifications through supported channels.
Depending on the integration, notifications may contain Personal Data required to explain:
- a purchase;
- exceeded limit;
- failed Agent task;
- approval request;
- security event;
- or other operational event.
Part 158 — DATA SENT THROUGH NOTIFICATION CONNECTORS
If a Customer chooses to send Hawi notifications through a third-party connector, the notification information will be transmitted to that third party.
The Customer controls which supported notification destination it chooses.
Part 159 — BUSINESS CONTINUITY
Hawi may copy data into backups, replicas, queues or temporary processing systems as reasonably necessary for:
- reliability;
- disaster recovery;
- redundancy;
- and task execution.
Such copies remain subject to appropriate safeguards.
Part 160 — SERVICE PROVIDER ACCESS
A service provider may technically have access to Personal Data where required to operate its service.
Hawi should use contractual and technical controls appropriate to the provider's role.
Part 161 — CORPORATE TRANSACTIONS
If Hawi participates in:
- acquisition;
- merger;
- restructuring;
- investment;
- financing;
- insolvency;
- or asset sale,
Personal Data may be disclosed where reasonably necessary for the transaction.
Part 162 — LEGAL REQUESTS
Hawi may disclose Personal Data where required by valid:
- subpoena;
- warrant;
- court order;
- regulator request;
- or other legal process.
Part 163 — REVIEW OF LEGAL REQUESTS
Where reasonably possible, Hawi may review requests for:
- legal validity;
- jurisdiction;
- scope;
- proportionality;
- and required disclosure.
Part 164 — EMERGENCIES
Where legally permitted, information may be disclosed where Hawi reasonably believes disclosure is necessary to address imminent risk of death or serious physical harm.
Part 165 — GOVERNMENT ACCESS
No private cloud provider can promise that government authorities will never seek Customer information.
Hawi will respond to government requests only in accordance with applicable law and Hawi's legal obligations.
Part 166 — DPO
If Hawi becomes legally required to appoint a Data Protection Officer, Hawi will publish the DPO's contact information.
DPO: [INSERT IF APPLICABLE]
Part 167 — UK REPRESENTATIVE
If legally required:
UK Representative: [INSERT]
Part 168 — EU REPRESENTATIVE
If legally required:
EU Representative: [INSERT]
Part 169 — ICO COMPLAINTS
Individuals subject to UK GDPR may lodge a complaint with the Information Commissioner's Office.
A person does not need Hawi's permission before contacting the ICO.
Part 170 — EEA COMPLAINTS
Individuals subject to EU GDPR may have the right to complain to an applicable European supervisory authority.
Part 171 — NO RETALIATION FOR PRIVACY REQUESTS
Hawi will not treat the lawful exercise of a statutory privacy right as a contractual violation.
Part 172 — DISPUTES
Hawi encourages a person to contact Hawi so that the parties can attempt to resolve a contractual dispute.
Part 173 — 30-DAY INFORMAL PROCESS
For contractual disputes not involving urgent relief, Hawi and the other party should generally attempt informal resolution for approximately 30 days.
This does not suspend a statutory GDPR deadline.
Part 174 — BUSINESS ARBITRATION NOTICE
IMPORTANT: THE FOLLOWING PROVISIONS CONTAIN A BINDING ARBITRATION AGREEMENT FOR CERTAIN BUSINESS USERS.
Part 175 — BUSINESS USER
For these arbitration provisions, a Business User is a person or organisation using Hawi wholly or mainly for purposes associated with a trade, profession, craft or business.
Part 176 — AGREEMENT TO ARBITRATE
To the extent legally enforceable, contractual disputes between Hawi and a Business User concerning:
- this Policy;
- Hawi's contractual privacy obligations;
- interpretation;
- formation;
- validity;
- performance;
- breach;
- or termination
that remain unresolved after the informal procedure shall be finally determined by arbitration.
Part 177 — LCIA
Unless otherwise agreed in writing, arbitration shall be conducted in accordance with the Rules of the London Court of International Arbitration (LCIA).
Part 178 — ARBITRATOR
The tribunal shall consist of one arbitrator unless applicable rules or mandatory law provide otherwise.
Part 179 — SEAT
The legal seat of arbitration shall be:
London, England.
Part 180 — LANGUAGE
The language shall be English.
Part 181 — ARBITRATION AGREEMENT LAW
Subject to mandatory law, the arbitration agreement shall be governed by the law of England and Wales.
Part 182 — CONSUMERS
The mandatory Business User arbitration provision is not intended to deprive consumers of mandatory court or statutory rights.
A consumer will not be compelled to arbitrate where doing so would be unlawful or unenforceable.
Part 183 — PRIVACY RIGHTS EXCLUDED FROM MANDATORY ARBITRATION
Nothing requires an individual to complete contractual arbitration before:
- submitting a Subject Access Request;
- requesting deletion;
- withdrawing consent;
- objecting to processing;
- requesting restriction;
- contacting the ICO;
- contacting another competent authority;
- cooperating with regulators;
- or exercising another non-waivable privacy right.
Part 184 — EMERGENCY RELIEF
Nothing prevents either party from seeking legally available emergency or interim court relief.
Part 185 — MANDATORY LAW PREVAILS
Where any arbitration or contractual provision conflicts with non-waivable law, the non-waivable law prevails.
Part 186 — TERMS OF SERVICE ALIGNMENT
These dispute provisions must be aligned with Hawi's Terms of Service.
Hawi should not publish contradictory:
- governing law;
- arbitration rules;
- venue;
- consumer rights;
- or dispute provisions
across different legal documents.
Part 187 — NO WAIVER OF DATA-PROTECTION RIGHTS
Nothing in this Policy waives rights granted under applicable privacy law.
Part 188 — LIMITATIONS OF THIS POLICY
This Policy explains Hawi's practices and legal position.
It does not:
- make otherwise unlawful processing lawful;
- replace Customer privacy notices;
- replace mandatory consent;
- eliminate statutory remedies;
- guarantee absolute cybersecurity;
- or remove regulator powers.
Part 189 — CHANGES TO THE SERVICE
As Hawi develops, new functionality may involve new Personal Data.
Where material new processing is introduced, Hawi should:
- assess the lawful basis;
- assess risk;
- update relevant processing records;
- conduct a DPIA where required;
- update this Policy where appropriate;
- issue a feature-specific notice where appropriate;
- seek consent where required;
- maintain evidence of the applicable notice.
Part 190 — CHANGE NOTIFICATION
Material privacy changes may be communicated through:
- email;
- an Account notice;
- a blocking acknowledgement screen;
- a Workspace notice;
- or another prominent method.
Part 191 — CONTINUED USE
Where consent is not legally required, continued use after a properly notified contractual update may have contractual consequences under the applicable Terms.
However:
Continued use must not be treated as substitute consent where privacy law requires affirmative consent.
Part 192 — LANGUAGE AND ACCESSIBILITY
Privacy information should be provided in a clear and accessible form.
Where Hawi provides translated versions, Hawi should seek to ensure translations accurately reflect the English version.
Part 193 — PRIVACY DASHBOARD
Where practical, Hawi should provide users or administrators with privacy controls allowing them to review:
- Account information;
- Connected Services;
- consent;
- integrations;
- privacy settings;
- analytics preferences;
- and deletion options.
Part 194 — SUBPROCESSOR UPDATES
Where required contractually, Hawi may notify Customers before adding or replacing material subprocessors.
Part 195 — CUSTOMER OBJECTIONS TO SUBPROCESSORS
Enterprise DPA terms may define procedures for Customers to raise legitimate data-protection objections to a new subprocessor.
Part 196 — TRANSFER SAFEGUARDS INFORMATION
Customers may contact Hawi for information concerning applicable international-transfer safeguards, subject to reasonable confidentiality limitations.
Part 197 — DATA LOCATION DOES NOT EQUAL EXCLUSIVE PROCESSING LOCATION
A database being hosted in London does not mean Personal Data can never be processed outside London.
For example:
- an AI provider;
- Connected Service;
- communications provider;
- administrator;
- Customer;
- or support provider
may process data elsewhere.
Part 198 — CUSTOMER SELECTION OF THIRD-PARTY SERVICES
Where the Customer chooses to connect a third-party service, the Customer is directing Hawi to exchange necessary information with that service.
Part 199 — THIRD-PARTY PRIVACY POLICIES
Third-party providers may independently determine some of their processing and maintain their own privacy policies.
Hawi's Policy does not replace those third-party policies.
Part 200 — LINKS TO THIRD-PARTY WEBSITES
Hawi may contain links to external websites.
Hawi is not responsible for an unrelated website's independent privacy practices merely because Hawi links to it.
Part 201 — NO SALE TO DATA BROKERS
Hawi does not intend to sell private Customer Content to data brokers for unrelated commercial profiling.
Part 202 — NO UNRELATED ADVERTISING PROFILING OF PRIVATE WORKSPACE CONTENT
Hawi does not intend to use private:
- emails;
- files;
- prompts;
- call transcripts;
- or business records
to create third-party advertising profiles unrelated to the Hawi Services.
Part 203 — ANONYMISED INFORMATION
Hawi may use properly anonymised information for:
- analytics;
- statistical analysis;
- security;
- reliability;
- product development;
- and business planning.
Information that has been truly anonymised so that an individual is no longer identifiable is generally no longer Personal Data.
Part 204 — AGGREGATED INFORMATION
Hawi may aggregate information across multiple users where reasonable safeguards prevent the aggregate output from identifying an individual.
Part 205 — PSEUDONYMISED INFORMATION
Pseudonymised information remains Personal Data where Hawi or another party can reconnect it to an individual.
Hawi will therefore continue treating applicable pseudonymised information as protected Personal Data.
Part 206 — DATA CORRECTION
Customers should maintain accurate source information.
If an Agent operates on inaccurate Connected Service data, the Agent's output may also be inaccurate.
Part 207 — AGENT INFERENCES
Agents may infer information from existing data.
An inference may be incorrect.
Customers should review material inferences before relying on them for significant decisions.
Part 208 — PRIVACY REQUEST LOGGING
Hawi may log privacy requests to demonstrate compliance.
The log may include:
- request type;
- requester;
- date;
- verification;
- deadline;
- action taken;
- exceptions;
- response date;
- and completion evidence.
Part 209 — REQUEST DEADLINES
Where UK or EU GDPR applies, Hawi will respond to applicable requests within statutory deadlines, subject to permitted extensions.
Part 210 — LEGAL EXEMPTIONS
Some information may be withheld, restricted or retained where an applicable legal exemption permits or requires it.
Part 211 — SECURITY AND PRIVACY REPORTING
Suspected security issues should be reported through Hawi's designated security contact.
Suspected privacy concerns should be reported through Hawi's privacy contact.
Part 212 — POLICY REVIEW
Hawi should review this Policy periodically and whenever Hawi materially changes its data-processing activities.
Schedule 1 — NOTICE & CONSENT EVIDENCE STANDARD
For material privacy acknowledgements, Hawi should retain an evidential record containing, as appropriate:
- immutable event ID;
- user ID;
- Account ID;
- Workspace ID where applicable;
- relevant feature;
- privacy notice identifier;
- privacy notice version;
- notice publication date;
- exact consent or acknowledgement wording;
- timestamp;
- server-side timestamp;
- language;
- method of presentation;
- action taken;
- whether an optional box was selected;
- source application;
- withdrawal timestamp;
- later replacement consent;
- and cryptographic integrity information where appropriate.
This record should allow Hawi to determine what the user was actually told at the relevant time, rather than linking only to whatever version of the Privacy Policy happens to be live later.
Schedule 2 — HIGH-IMPACT FEATURE NOTICE REQUIREMENTS
Before enabling the following functionality, Hawi should consider presenting a dedicated notice:
| Feature | Dedicated notice |
|---|---|
| Email connection | What Agents may read/write/send |
| Calendar | Events/attendees Agent may access |
| CRM | Customer/contact data processing |
| Voice | AI Agent interaction |
| Recording | Recording disclosure |
| Transcription | Audio-to-text processing |
| Automatic purchasing | Financial autonomy and limits |
| Auto recharge | Payment trigger and caps |
| Banking connection | Financial data accessed |
| Wellness | Special Category Data + explicit consent |
| Marketplace publishing | Information becomes public |
| Analytics | Cookie/analytics choice |
| High-impact automation | Automated decision implications |
| Agent memory | Information retained across sessions |
Schedule 3 — CONNECTED SERVICE DISCLOSURE
Before a user enables a Connected Service, Hawi should clearly display:
- the provider being connected;
- the Account that will own the connection;
- the Workspaces receiving access;
- the Agents that may access it where applicable;
- requested scopes;
- whether access is read-only or includes writes;
- potentially consequential actions;
- how to revoke the connection;
- what previously retrieved information may remain;
- link to this Privacy Policy.
Schedule 4 — AUTOMATIC PURCHASING NOTICE
Before automatic purchasing is enabled, Hawi should make clear:
YOU ARE ENABLING FINANCIAL ACTIONS.
By enabling this feature, you authorise eligible Hawi Agents, within the limits you configure and subject to Hawi's applicable controls, to complete eligible purchases without requesting your approval for every individual purchase.
The user should be shown:
- payment source;
- per-transaction maximum;
- daily/monthly maximum where available;
- authorised Agents;
- authorised Workspaces;
- categories/merchants where applicable;
- notification destination;
- how to disable the feature;
- and applicable refund limitations.
The acknowledgement should be stored separately from ordinary Terms acceptance.
Schedule 5 — VOICE NOTICE
Where appropriate, callers should receive a disclosure substantially similar to:
You are interacting with an automated Hawi Agent. This call may be processed and transcribed to handle your request and perform authorised follow-up actions. Please do not provide information that is unnecessary for your request.
Where recording occurs, the recording disclosure should be added where legally required.
The Customer remains responsible for adapting disclosure wording to applicable local law.
Schedule 6 — AGENT MEMORY NOTICE
Before memory is enabled where appropriate:
Hawi may retain selected information from your interactions so this Agent can use it in later sessions. This may include preferences, prior tasks, business information and other relevant context. You can manage or delete memory where the applicable controls are available.
Schedule 7 — WELLNESS EXPLICIT CONSENT
A wellness consent should be separate and could state:
I explicitly consent to Hawi processing the wellness or health information described above for the stated purpose, including Agent/model analysis where indicated. I understand that I can withdraw this consent through the applicable settings or by contacting Hawi.
A checkbox should not be pre-selected.
Schedule 8 — COOKIE/ANALYTICS CHOICE
Where consent is required, the user should receive at least:
- Accept optional analytics
- Reject optional analytics
- Manage preferences
Rejecting optional analytics should be as reasonably accessible as accepting.
Schedule 9 — USER ACKNOWLEDGEMENT VS CONSENT
Hawi should distinguish:
Acknowledgement
“I acknowledge that I have received and can access the Privacy Policy.”
from:
Consent
“I consent to this specific optional processing.”
Acknowledging a privacy notice does not automatically establish a valid consent lawful basis.
Schedule 10 — RETENTION MATRIX
| Information | Example purpose | Indicative retention |
|---|---|---|
| OAuth state | Connection security | ~1 hour |
| Verification challenge | Verification | ~24h |
| Security challenge | Security | ~24h |
| Rate-limit state | Abuse prevention | ~7 days |
| API/security event | Security | ~30 days |
| Webhook delivery | Troubleshooting | ~30 days |
| Connector execution | Audit/support | ~90 days |
| Wellness measurement | Optional feature | ~180 days |
| Voice transcript | Call history | ~365 days |
| Voice note | Voice functionality | ~365 days |
| Failed/top-up event | Financial dispute | ~2 years |
| Consent evidence | Accountability | Appropriate compliance period |
| Accounting records | Legal/tax | Statutory period |
| Legal hold | Legal preservation | Until release |
Schedule 11 — GDPR RIGHTS CHECKLIST
Where applicable, Hawi must be prepared to support:
- right to information;
- right of access;
- right to rectification;
- right to erasure;
- right to restriction;
- right to portability;
- right to object;
- right to withdraw consent;
- automated decision safeguards;
- right to complain;
- and applicable judicial remedies.
Schedule 12 — DATA-PROTECTION PRINCIPLES
Hawi seeks to apply:
Lawfulness
There must be an appropriate legal basis.
Fairness
Processing should not unjustifiably surprise or harm people.
Transparency
Important processing should be explained openly.
Purpose limitation
Personal Data should not silently be reused for materially incompatible purposes.
Data minimisation
Only necessary information should be processed.
Accuracy
Reasonable efforts should be made to maintain accurate information.
Storage limitation
Personal Data should not be retained indefinitely without justification.
Integrity and confidentiality
Reasonable security safeguards should apply.
Accountability
Hawi should be able to demonstrate compliance.
Schedule 13 — PRODUCTION LEGAL DOCUMENT SET
This Privacy Policy should operate alongside:
- Terms of Service
- Data Processing Agreement
- Cookie Notice
- Subprocessor List
- Acceptable Use Policy
- Marketplace Terms
- Creator/Seller Terms
- Voice/Call Processing Notice
- Automatic Purchasing Terms
- Financial Connections Notice
- Wellness Explicit Consent Notice
- Security Policy or Security Overview
- Data Retention Schedule
- Data Subject Request Procedure
- Data Breach Response Procedure
- International Transfer documentation
- Business Customer privacy guidance
- AI/Automated Agent Transparency Notice
Schedule 14 — INFORMATION THAT MUST BE VERIFIED BEFORE PUBLICATION
Hawi should not invent or inaccurately state the following.
Before publication verify:
- exact Hawi legal entity;
- registration number;
- registered address;
- incorporation jurisdiction;
- privacy email;
- security email;
- DPO requirement;
- UK representative requirement;
- EU representative requirement;
- final Terms governing law;
- final arbitration law;
- final arbitration seat;
- model providers actually used;
- voice providers actually used;
- speech providers actually used;
- payment providers actually used;
- financial-data providers actually used;
- analytics providers actually enabled;
- storage locations;
- actual subprocessor locations;
- international transfer mechanisms;
- retention periods;
- recording functionality;
- training arrangements with model providers;
- production cookie configuration;
- Data Processing Agreement;
- live deletion process;
- privacy-right request process;
- breach process;
- production security measures.
Schedule 15 — IMPORTANT CUSTOMER ACKNOWLEDGEMENTS
Subject to applicable law and without waiving non-waivable statutory rights, Hawi Customers should understand that:
- Hawi is an Agent platform capable of processing Customer Content.
- Agents may take actions in external systems where authorised.
- Connecting a service makes information available for authorised processing according to the scopes and controls selected.
- An Agent may transmit information to third-party providers necessary to perform the requested task.
- Model-generated output may contain errors.
- The Customer remains responsible for deciding when human review is necessary.
- The Customer remains responsible for establishing the lawful basis for Personal Data it instructs Hawi to process.
- The Customer remains responsible for notices owed to its own employees, customers, callers and other individuals.
- The Customer remains responsible for call-recording and marketing-law compliance for Customer-directed communications.
- Financial Agent functionality requires separate configuration and does not arise merely from creating an Agent.
- Connected Service credentials may be used by Hawi's backend to perform authorised actions.
- Account administrators may have visibility over organisational activity.
- Disconnecting a Connected Service does not necessarily delete information previously processed.
- Account deletion does not necessarily delete records Hawi is legally required to retain.
- Some service providers may process information outside the Customer's jurisdiction.
- Hawi cannot guarantee complete security or that an Agent will never make an error.
- Customer Content may include third-party Personal Data, and the Customer must have lawful authority to process it.
- Data processed under Customer instructions may be subject to the Customer's own privacy notice in addition to Hawi's Policy.
Final transparency statement
Hawi is built to allow software Agents to carry out real operational work.
That means the Services are not limited to producing text inside a chat window.
Depending on the Customer's configuration, a Hawi Agent may interact with external systems and people, retrieve information, create or modify records, communicate through Connected Services, handle calls, process files, coordinate work and perform other authorised operations.
Hawi therefore seeks to provide Customers with controls over:
- which Agents exist;
- which Workspaces they belong to;
- what integrations they may access;
- which external actions they may perform;
- which financial actions are allowed;
- where human approval is required;
- how usage is limited;
- how actions are recorded;
- and how Connected Services can be revoked.
The existence of technical capability does not itself create lawful authority to use Personal Data.
A Customer must ensure that its use of Hawi complies with applicable law.
Hawi must ensure that Hawi's own processing complies with applicable law.
Neither Hawi nor a Customer may use this Privacy Policy to override statutory privacy rights.
Where Hawi introduces materially new processing, Hawi should provide new or updated privacy information before that new processing begins where required.
Where consent is legally required, Hawi should obtain separate, affirmative consent rather than relying merely on continued use of the Service.
Where a material acknowledgement or consent is obtained, Hawi should maintain sufficient evidence to show:
- what was presented;
- when it was presented;
- which version was shown;
- who responded;
- what action the person took;
- and whether that decision was later withdrawn.
The purpose of these records is not to take away user rights.
Their purpose is to create a reliable, auditable record demonstrating what information Hawi actually provided and what choices the user actually made.
Contact
Hawi Inc.
Trading as Hawi Agents
Website: HawiAgents.com
General: hello@hawiagents.com
Privacy: privacy@hawiagents.com
Security: security@hawiagents.com
© 2026 Hawi Inc. All rights reserved.