Privacy policy
Last updated September 2026. This is a plain-language policy written to reflect the India Digital Personal Data Protection Act, 2023 and Canadian PIPEDA. It is a starting template and should be reviewed by qualified counsel before you rely on it.
HiThisIs, a product of Four Cents (based in Canada), runs an automated phone front desk for clinics and other businesses. In this policy "we" and "us" mean Four Cents. We keep this short and clear on purpose.
Our role, and the clinic's role
Two kinds of people are involved. Our customers are the clinics and businesses that sign up. Patients and callers are the people who phone those clinics, or whom the clinic asks us to call. For a patient's personal data, the clinic decides why the data is used and is the data fiduciary (controller). We act as the clinic's data processor and handle that data only on the clinic's instructions. Each customer's data is isolated from every other customer.
What we collect from customers
- Account details: business name, contact name, email, phone, and business registration details used to set up the number.
- Configuration: greeting, languages, hours, and notification settings.
- Billing details processed through our payment gateway, Razorpay. We store only payment metadata (such as an order id, status, and the last digits of a card). We do not store full card numbers.
What we collect on calls
- The phone number of the call.
- What the caller tells the front desk: name, callback number, the reason for the call, and appointment or service details.
- A recording and a written transcript of the call, kept for the clinic's quality review and record keeping.
Automated handling and recording
Calls are answered and placed by an automated front desk, and they are recorded. At the start of every call, inbound and outbound, the front desk states that the line is automated and that the call is recorded, before any details are taken. If a caller asks, the front desk confirms it is the clinic's automated line. A caller can decline to continue at any time.
Why we use it, and our legal basis
We use this data only to answer and place calls for the clinic, book and confirm appointments, deliver service messages the clinic asks us to send, keep records for the clinic, run billing, and keep the service secure. Our legal basis is that we process patient data on behalf of the clinic (the fiduciary) under its consent or legitimate-use basis under the DPDP Act, and we process customer account data to perform our contract with the clinic. We do not sell personal information and we do not use call content for advertising.
Service messages to patients, not marketing
Outbound calls are limited to service and transactional messages to a clinic's existing patients, such as a report being ready, a reminder, or an appointment confirmation. We do not place promotional or marketing calls. Clinics are responsible for having the right to contact each patient and for any telecom registrations that apply to them.
Sub-processors
We use a small set of vendors to run the service: a cloud telephony and voice carrier to carry calls, an AI voice provider to power the conversation, a cloud hosting provider, a payment gateway (Razorpay), and an email and messaging provider. Each processes data only to provide its part of the service, under contract terms requiring comparable protection. A current named list is available to clinics on request and in our data processing terms, and we tell clinics before adding a new sub-processor so they can object.
Where data is processed
Data may be processed on servers in Canada and other countries. Transfers are made in line with the DPDP Act (Section 16); as of this update no destination country has been placed on the restricted list. Payment data handled by Razorpay is stored as required by Indian rules. We remain accountable for data handled by our sub-processors and use contractual safeguards. Where a clinic requires India-only storage, contact us.
Retention and deletion
Call audio is kept for up to 90 days by default. Transcripts and patient details are kept for the period the clinic sets, then deleted. Account and billing records are kept as long as needed for the account and as tax and legal rules require. KYC documents provided to set up a number are kept for as long as the number is in service and for the retention period our carrier and the law require, then deleted. Clinics can delete individual recordings or request full deletion by emailing us.
Your rights
Data principals have the right to access a summary of their data and how it is used, to correct or complete it, to have it erased, to grievance redressal, and to nominate someone to act for them. Patients should usually contact the clinic they called (the fiduciary); we will support and forward such requests. Customers can access, correct, export, or delete their account data. To make a request, email us at the address below and we will respond within the timelines the law requires.
Grievances and complaints
Our Grievance Officer is reachable at support@hithisis.com (subject line "Grievance") and will answer questions about how data is handled. If you are not satisfied, you may complain to the Data Protection Board of India, and, in relation to our own handling, to the Office of the Privacy Commissioner of Canada.
Children
Where a call concerns a patient under 18, the clinic is responsible for obtaining verifiable parental or guardian consent. We do not profile or track minors.
Security and breach notice
We encrypt data in transit and at rest, restrict access, and keep audit logs of access to recordings and account actions. If a personal-data breach occurs, we will notify the Data Protection Board of India and affected individuals without undue delay as the rules require, and the Office of the Privacy Commissioner of Canada where its thresholds are met.
Our mobile apps
The HiThisIs app (for business owners) and the HiThisIs Sales app (for our field partners) show the same information as the website and add nothing to what we collect about callers. The apps store your sign-in token in the phone's secure storage. If you allow notifications, the app registers a device token with Expo's push service so we can notify you about calls, leads, payments and payouts; you can switch this off in your phone's settings at any time. The Sales app asks for your location only when you check in to a business visit, to record where the visit took place; it does not track you in the background. Both apps let you request deletion of your account from within the app, and we complete the deletion, including calls, recordings and transcripts, within 30 days after settling any billing or payouts.
AI assistants you connect
A business can connect an AI assistant it uses (for example ChatGPT or Claude) to its own HiThisIs account, by signing in and approving it, or with a private link or API key it creates. Once connected, the assistant can read that account's calls, transcripts, caller names and numbers, leads, usage and receptionist settings; update leads; block numbers; change the receptionist's settings; and ask the receptionist to phone a caller back with the business's message. It sees one account only, and only while the business keeps it connected. We send the assistant only what a request asks for, and nothing about other businesses or about how our systems work. What the assistant then does with that data is governed by the assistant provider's own terms and the business's agreement with them. The business can disconnect any assistant, or turn off AI access entirely, at any time from Use with ChatGPT & Claude in its dashboard; access stops immediately. Sign-in tokens are stored only in hashed form and expire. Without an account, an assistant can only read public information about HiThisIs, and can pass on a demo request someone asks it to make, which reaches our team by email.
Changes
We will update this page when our practices change and note the date at the top. Questions? Email support@hithisis.com.