Privacy Policy
Last updated 2 September 2026
Hoogway is a voice platform businesses use to run their own phone calls, and a hiring platform businesses use to screen and interview candidates. Almost everything here is data our customers bring to us and remain responsible for — we hold and process it on their behalf. This page says what we collect, why, who we share it with, and how to get it back or have it deleted.
It covers this website (hoogway.ai, including the live demo on the homepage), Hoogway Leads (leads.hoogway.ai) and Hoogway Hiring (app.hoogway.ai). Where a signed agreement with a customer says something more specific, that agreement prevails for that customer's data.
Who this covers
Three different relationships, and the distinction matters for your rights:
- Our customers — the businesses with a Hoogway account. We are the controller of their account data.
- The people our customers call, and the candidates they interview — their contacts, leads and applicants. For that data our customer is the controller and Hoogway is the processor: we act on their instructions, and requests about it are answered by them. If you were called by a Hoogway-powered agent, or interviewed through Hoogway Hiring, and want your data removed, contact the business that engaged you; we will help them action it.
- Visitors who try the demo on hoogway.ai — for that data we are the controller, and the demo section below says exactly what happens to it.
What we collect
Account data. Name, work email, hashed password, role, and the organisation you belong to.
Contact data our customers upload. Whatever is in their campaign files — typically a name and phone number, sometimes an email address and other columns they choose to map.
Call data. Recordings, transcripts, call duration and outcome, and the analysis derived from a call. Calls are recorded so our customers can review and improve them; announcing the recording where the law requires it is the calling business's responsibility.
Candidate data on Hoogway Hiring. What candidates and employers submit for a role — typically a resume, contact details, application answers, and the recordings, transcripts and AI-generated screening reports of interviews taken through the platform. The hiring business is the controller of this data and makes the hiring decisions; our reports assist, they do not decide.
Integration credentials. Tokens for services a customer connects — a calendar, a CRM, or an applicant tracking system — stored encrypted at rest and never shown back in full.
Usage and diagnostics. Sign-in times, IP address, and application logs used to keep the service running and secure.
The demo on hoogway.ai
The homepage lets you talk to a demo agent in the browser, have it call your phone, or describe an agent of your own. Before your first session we ask you to confirm you are over 18 and know you are talking to an AI. Demo conversations are recorded, transcribed and analyzed — that is how we show you the call report afterwards. We use Cloudflare Turnstile and per-visitor limits to keep the demo from being abused, which means processing your IP address.
An agent you draft through the demo chat is ephemeral: it deletes itself within 2 hours unless you claim it, and within 7 days if claimed but never signed up for. To have a demo recording removed, write to us at the addresses below.
Google account data
When a customer connects a Google account so their agent can book meetings, we request the narrowest scopes that make that work, and use each one only for the purpose named here:
- calendar.events — to create a calendar event with a Google Meet link for a time the agent agreed with the caller, and to move or cancel that event if they change it.
- calendar.freebusy — to check whether a proposed time is free before the agent agrees to it, so nobody is double-booked.
- openid and email — to show which Google account is connected on the Integrations page.
We store a refresh token, encrypted, and the connected account's email address. We do not read the contents of existing calendar events, and we do not access Gmail, Drive, Contacts or any other Google service.
Hoogway's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as needed to provide the feature, we do not use it for advertising, and we do not use it to train generalised AI models. Disconnecting Google in the app revokes our access and deletes the stored token.
AI, and what is never used for training
Calls and interviews are transcribed and analysed by AI models to produce transcripts, summaries and the metrics our customers configure. We use third-party model providers under agreements that prohibit training on our customers' data, and we do not train models on customer content, candidate content, demo conversations, or data received from Google APIs.
Who we share it with
Only the providers needed to place a call and make sense of it — telephony carriers, speech and language model providers, cloud hosting and storage, and any service a customer chooses to connect, such as their CRM, calendar or applicant tracking system. Each receives only what its job requires.
We do not sell personal data, and we do not share it for advertising. We may disclose data if the law compels it, and we will tell the affected customer unless we are prohibited from doing so.
Cookies and analytics
We use the cookies needed to keep you signed in and the service secure. Our websites use Google Analytics, and the hiring pages also use Microsoft Clarity, to understand how the site is used; neither is used to build advertising profiles.
How long we keep it
Call recordings, transcripts, candidate files and contact data are kept while the customer's account is active, and deleted on request or within 90 days of an account closing. Customers can delete individual calls, candidates and contacts at any time from their dashboard. Demo drafts age out on the schedule above. Backups age out on their own schedule, within 35 days.
How we protect it
Data is encrypted in transit and at rest. Integration credentials are encrypted with a separate key. Access inside Hoogway is role-based and logged, and each customer's data is isolated from every other customer's at the query level.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Write to us and we will action it.
If you were called by an agent running on Hoogway, or interviewed through Hoogway Hiring, the business that engaged you controls that data — please contact them first. Tell us and we will pass it on and support them in carrying it out.
Children
Our services are for businesses and are not directed at anyone under 18. The homepage demo requires you to confirm you are over 18.
Contact
Questions about this policy, or a request about your data: harshit@hoogway.ai or raj@hoogway.ai.
If this policy changes materially we will update the date at the top and tell account holders by email.