Last updated: 30 September 2026
Privacy Policy
This policy explains how personal data is processed in connection with the isahar Voice website and service. It applies to website visitors, people who contact us, administrators and agents who use the platform and, to the extent described below, people whose data is processed through our customers' accounts.
1. Service provider
The isahar Voice service is provided by ISAHAR SYSTEMS S.R.L., with its registered office at Str. Mihai Viteazul, no. 17A, Târgu Neamț, Neamț County, 615200, Romania, registered with the Trade Register under no. J2026055504003, tax identification number RO55627873, hereinafter referred to as “isahar Voice”, “we”, “us” or the “provider”.
For questions about data protection, contact us at:
- email: voice@isahar.io;
- phone: +40 748 240 487;
- postal address: Str. Mihai Viteazul, no. 17A, Târgu Neamț, Neamț County, 615200, Romania;
- Data Protection Officer: voice@isahar.io.
2. Our data protection roles
2.1. When isahar Voice is the controller
We act as controller for data that we process for our own purposes, including:
- operating the website;
- responding to enquiries and commercial requests;
- creating and administering accounts;
- billing and managing the contractual relationship;
- securing the service, preventing abuse and retaining technical logs;
- service communications and, where permitted, marketing communications.
2.2. When isahar Voice is the processor
For data entered, imported or generated when customers use the platform—including call data, recordings, voicemail, contacts, notes and information retrieved through integrations—the customer is generally the controller, while isahar Voice processes the data on the customer's behalf and in accordance with its instructions.
This relationship is governed by a data processing agreement concluded with the customer under Article 28 GDPR.
3. Data we may process
Depending on how you interact with us or with a isahar Voice customer, we may process the following categories:
Data submitted through the website or forms
- first and last name;
- email address and phone number;
- company, website and professional role;
- the content of your message or request;
- information about team size and stated requirements.
Account and user data
- name, email address, role and permissions;
- the organization or account to which the user belongs;
- protected authentication data and session information;
- settings, configurations and administrative activity;
- access logs and security events.
Billing data
- company name, tax identification number, address and other information required for billing;
- selected plan, billable usage and invoice history;
- payment status and identifiers supplied by the payment processor.
We do not store complete card details when payments are processed by a specialized provider.
Communication and call data
- the calling number and the number called;
- the date, time, duration, direction and outcome of the call;
- the queue, team or agent associated with the call;
- the audio recording, if the feature is enabled;
- voicemail messages and audio files;
- notes and other information added by users;
- technical data needed to initiate, route and troubleshoot calls.
Data obtained through integrations
At the customer's instruction, the platform may access data from connected systems, including:
- the end customer's name and contact details;
- order source, number and history;
- products, quantities, values, dates and order statuses;
- identifiers and links to records in the connected system;
- other fields authorized by the customer through the integration.
Integration credentials are protected and are not displayed in plain text to unauthorized users.
API and webhook data
- API key identifiers, names and dates of use;
- webhook URLs configured by the customer;
- selected events, delivery history, technical responses and errors;
- data included in events sent to endpoints chosen by the customer.
Technical website and application data
- IP address;
- device, browser and operating system type;
- pages accessed, timestamps and session identifiers;
- technical logs, errors and data required for security.
4. Where the data comes from
Data may come:
- directly from you when you submit a form or use an account;
- from the company or organization that creates your user account;
- from calls processed through the platform;
- from Magento 2, Base.com, Help Scout or other systems connected by the customer;
- from APIs, webhooks and other integrations configured by the customer;
- from technical providers involved in delivering and securing the service.
5. Purposes and legal bases
When we act as controller, we may process data for:
- providing the account and performing the contract — Article 6(1)(b) GDPR;
- responding to requests and preparing a commercial relationship — Article 6(1)(b) or (f) GDPR, as applicable;
- billing and compliance with legal obligations — Article 6(1)(c) GDPR;
- security, fraud prevention and the establishment, exercise or defense of legal claims — Article 6(1)(f) GDPR;
- improving the service and diagnosing issues — Article 6(1)(f) GDPR;
- marketing communications — consent or legitimate interests, only where permitted by law;
- non-essential cookies and similar technologies — consent, if such technologies are used.
When we act as processor, we process service data on the customer's documented instructions. The customer is responsible for determining the applicable purpose and legal basis.
6. Call recording
Call recording is optional and may be enabled or disabled by the customer.
The customer using isahar Voice determines:
- the purpose of recording;
- the legal basis;
- the information that must be provided to callers;
- who may access the recordings;
- the retention period;
- procedures for access, objection or erasure.
isahar Voice allows an information notice to be configured in the call flow, but playing the notice does not, by itself, constitute valid consent or guarantee that the recording is used lawfully.
Recordings are processed on the customer's behalf and protected in transit and at rest to the extent supported by the service's confirmed technical configuration.
7. Integrations, API and webhooks
Integrations are enabled by the customer and operate under the permissions it grants. The customer is responsible for ensuring that it has the right to connect the relevant systems and transfer data to isahar Voice.
For webhooks, the customer chooses the destination URL and the events sent. The customer is responsible for the security and legality of the receiving system, the people who can access the data and the confidentiality of the secret used to verify signatures.
Customers must protect their API keys and revoke them immediately if they may have been compromised.
8. Who we may disclose data to
To the extent necessary, we may disclose data to:
- hosting and infrastructure providers;
- communications and telephony providers;
- transactional email and notification providers;
- payment processors and billing service providers;
- monitoring, security and technical support providers;
- advisers, auditors and public authorities where a legal obligation applies;
- recipients configured by the customer through the API or webhooks.
An up-to-date list of subprocessors can be requested at voice@isahar.io. Before using a new subprocessor to process customer data, we will follow the notice and objection procedure set out in the data processing agreement with the customer.
9. International transfers
We aim to use infrastructure located in the European Economic Area. If a provider processes data outside the EEA, the transfer takes place only under a mechanism recognized by the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any necessary supplementary safeguards.
10. How long we retain data
We retain data only for as long as necessary for the purpose for which it was collected, in accordance with the service configuration, the contract and legal obligations.
- commercial enquiries and contact forms: 12 months from the last exchange of messages, if the enquiry does not lead to a contract;
- contractual relationship data and customer contact details: for the term of the contract and 3 years after termination, for the establishment, exercise or defense of legal claims;
- accounts, configurations and customer content: for the term of the contract and up to 30 days after termination for export or recovery, after which they are deleted or anonymized in active systems;
- financial and accounting documents: 5 years calculated from 1 July of the following year after the financial year in which they were prepared ended, or the period required by an applicable special rule;
- call metadata and history: 12 months from the date of the call, unless the customer has configured or contracted a shorter period;
- call recordings and voicemail: 30 days by default; where the plan or account configuration allows, the customer may choose a different period displayed before activation;
- contacts, notes and data retrieved through integrations: for the term of the contract and up to 30 days after termination, unless deleted earlier by the customer;
- API and webhook delivery history, including technical responses and errors: 90 days;
- authentication, audit and security logs: 12 months;
- backups: up to 30 days after data is deleted from the active system, without restoring it to regular use.
Customers may delete the data they control earlier, subject to available features and legal obligations. When the applicable period expires, data is deleted or anonymized. Anonymized data that can no longer be linked to an individual may be retained for statistics and service improvement.
A period may be extended only when necessary to resolve a complaint, prevent or investigate abuse, establish, exercise or defend a legal claim, or comply with a legal obligation. Access is then limited to the purpose that justifies the retention.
When the contract ends, customer data is returned or deleted in accordance with the data processing agreement, except for data that we are legally required to retain.
11. Data security
We apply technical and organizational measures appropriate to the risk, which may include:
- encryption of communications and sensitive data;
- role-based access controls;
- data isolation between customers;
- logging administrative and security events;
- backups and restoration procedures;
- monitoring and incident response procedures;
- confidentiality obligations for authorized personnel.
No system can guarantee absolute security. Customers must protect their accounts, passwords, API keys and users' devices.
12. Data subject rights
Subject to the GDPR, you may request:
- access to your data;
- rectification of inaccurate data;
- erasure of data;
- restriction of processing;
- data portability;
- objection to certain processing;
- withdrawal of consent where processing is based on consent;
- the right to lodge a complaint with a supervisory authority.
These rights are not absolute, and statutory exceptions may apply.
For data processed in a isahar Voice customer's account, first submit your request to the company with which you interacted. If we receive such a request directly, we will forward it to the relevant customer and assist it in accordance with our contractual obligations.
For data for which isahar Voice is the controller, email us at voice@isahar.io. We may ask for additional information to verify your identity.
13. Cookies and similar technologies
The public website uses Google Analytics (Google Ireland Limited) to understand how the site is used — for example, which pages are visited and how visitors reach them. This measurement is optional and only starts if you agree in the banner shown on your first visit; you can grant or withdraw consent at any time from the "Cookie settings" link in the page footer.
The legal basis for analytics cookies is your consent (GDPR Art. 6(1)(a)). Data may be transferred to and processed by Google outside the European Economic Area, subject to the safeguards described in Google's privacy policy.
Where necessary, the security and content delivery provider may use identifiers or strictly necessary cookies to protect against abuse and support the website's technical operation; these do not require consent.
The web application uses browser local storage for authentication, session management and essential administrative features. These technologies are necessary to provide the service and are not used for behavioral advertising.
14. Automated decisions and profiling
isahar Voice does not, on its own behalf, make decisions based solely on automated processing that produce legal effects for individuals. If a customer configures its own automations through the API or webhooks, that customer is responsible for their legality.
15. Complaints
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing:
- website: dataprotection.ro;
- address: 28–30 General Gheorghe Magheru Boulevard, District 1, Bucharest, Romania.
We encourage you to contact us first at voice@isahar.io so that we can try to resolve your request.
16. Mobile app
This section supplements the rest of this policy for the isahar Voice mobile app for iOS and Android, used by our customers' agents and administrators to make and receive calls.
Accounts
The app does not allow creating accounts. Accounts are created by the customer organization's administrator, and sign-in uses the same credentials as the web app.
Device permissions
- microphone — used only during a call, to transmit your voice to the other party. The app does not record audio on the device; call recording, if enabled by the customer, happens on the server, as described in section 6;
- notifications — to show incoming calls when the app is not open;
- integration with the phone's calling system (CallKit on iOS, the call screen on Android) — to show and manage calls like regular phone calls, including on the lock screen;
- device address book (optional, only with your consent) — to show the names of people who call you and for search. The address book is read only on the device; it is not sent to isahar Voice, not stored on the platform and not visible to colleagues;
- photos (only when you pick one) — to add a photo to a contact on the platform. Only the photo you choose is uploaded and becomes part of the organization's contact; the app has no access to the rest of your gallery.
The app does not access your location or other files on the device. Company contacts shown in the app come from the organization's account on the platform.
Data stored on the device
- the session token, kept in the operating system's secure storage (Keychain on iOS, Keystore on Android);
- technical connection data for the telephony service, stored locally for automatic reconnection and deleted when you sign out of the app;
- preferences, such as the interface language.
Incoming call notifications
To receive calls when the app is not open, the device generates a notification identifier (Apple Push Notification service on iOS, Firebase Cloud Messaging on Android), which is sent to our telephony provider. For an incoming call, the notification contains the information needed to display the call, such as the caller's number. The identifier is used only for call notifications.
What the app does not do
- it does not show ads or use advertising identifiers;
- it does not track your activity across other apps or websites;
- it does not include behavioral analytics tools;
- it does not sell or share data with third parties for marketing purposes.
All communication between the app, the platform and the telephony provider is encrypted in transit.
Deleting your account and data
You can request deletion of your user account and associated data through your organization's administrator or by writing to voice@isahar.io from the email address linked to your account. The account is deactivated as soon as the request is verified, and the data is deleted within 30 days, except for data the customer or the law requires us to retain, as described in section 10. Uninstalling the app deletes the data stored locally on the device.
17. Changes to this policy
We may update this policy when the service, providers or legal requirements change. We will publish the updated version and its effective date. For material changes affecting active customers, we will also provide notice by email or in the application.