Last updated: 2 September 2026
Izwi ("we", "us") provides an AI voice receptionist service that answers business phone calls, books appointments, takes messages, and handles common questions on behalf of our business customers ("tenants"). Izwi is operated from South Africa and this policy is written with reference to the Protection of Personal Information Act, 2013 (POPIA). If you are located outside South Africa, other data protection laws may also apply to you; we aim to meet a comparable standard of care regardless of jurisdiction.
This policy covers two groups of people: (a) representatives of businesses that sign up for an Izwi account ("tenant users"), and (b) people who call a phone number handled by Izwi on behalf of a tenant ("callers"). Callers do not have an Izwi account and interact with us only through the phone call itself.
We process this data to: operate the AI receptionist service (answering calls, booking appointments, generating transcripts); let tenant users manage their account, team, and voice scripts; process subscription payments; secure the platform and investigate suspicious activity; and improve the product through aggregate usage analytics.
We do not sell personal information. We share data with the following categories of service providers, each acting as a processor on our behalf and only to the extent needed to provide the service:
We may also disclose data where required by law, such as in response to a valid South African court order or regulatory request.
Tenant owners and admins can export their tenant's account data — tenant details, users, voice agents, call metadata and transcripts, and connected phone numbers — as a single JSON file from within the app. Raw call recording audio is not included in this export (see Section 2).
Tenant owners can also submit a data deletion request from within the app. Submitting this request does not delete data automatically or immediately — it records the request and timestamps it on the tenant record, and a member of our team reviews and actions it manually. We are describing this honestly rather than promising instant automated deletion, because that capability does not currently exist.
Security-relevant events (sign-ins, role changes, settings changes, deletion requests, and similar actions) are written to a security audit log with a minimum retention period of 7 years, in line with our internal security policy. Beyond the audit log, we do not currently have a separately defined, fixed retention period for other data categories (such as call transcripts or recordings) written down elsewhere in our systems — rather than invent a number here, we are stating that plainly. Data is generally retained for as long as a tenant account is active, plus a reasonable period afterward, and can be removed sooner via the deletion request process in Section 5.
We apply role-based access control and tenant isolation so that one tenant cannot access another tenant's data, encrypt data at rest (via our database provider's managed infrastructure encryption) and in transit (TLS), and log security-relevant actions to an audit trail. No system is perfectly secure, and we cannot guarantee absolute security.
If POPIA applies to you, you have rights including the right to be notified that your personal information is being collected, to access the personal information we hold about you, to request correction or deletion of it, and to object to certain processing. You can exercise access, export, and deletion-request rights through the mechanisms described in Section 5, or by contacting us directly.
Questions about this policy or a request that isn't covered by the in-app tools above can be sent to our support contact listed in the app. Because this document is a draft awaiting legal review, a dedicated privacy-request email address and Information Officer designation (as contemplated by POPIA) will be finalized as part of that review.