GDPR compliant (EU data protection) · CCPA compliant (California privacy rights) · HIPAA ready (healthcare compliance)
1. Information We Collect
Business Information
- Business name, industry, and location
- Business hours and service offerings
- Phone numbers and contact information
- CRM integration credentials (encrypted)
Call Data
- Call recordings and transcripts
- Caller phone numbers and contact details
- AI-generated summaries and insights
- Tags, sentiment scores, and extracted data
Usage Information
- Dashboard activity and feature usage
- Device information and browser type
- IP addresses and geolocation data
- Performance metrics and error logs
2. How We Use Your Information
We use your information to:
- Provide AI receptionist services and call handling
- Generate transcripts, summaries, and insights
- Integrate with your CRM and business tools
- Send appointment confirmations and notifications
- Improve service quality using aggregated, de-identified usage data; we never train shared AI models on patient data
- Detect fraud and ensure platform security
- Comply with legal obligations
3. Data Sharing and Third Parties
We work with trusted service providers to deliver our platform. Your data may be shared with:
Infrastructure Providers
- Telephony providers: Phone number provisioning and SMS with HIPAA-eligible safeguards
- Voice processing providers: AI call handling and transcription under BAA-backed controls
- Database providers: Encrypted application data hosting and access controls
- Workflow infrastructure providers: Internal automation and background job processing
AI and Analytics
- AI processing providers: Analysis and summarization under minimum-necessary data controls
- Business integration providers: CRM integrations with encrypted credential storage
Payment Processing
- Payment processor: PCI-DSS Level 1 certified payment processing
We never sell your data to third parties. All providers are contractually obligated to protect your data.
4. Data Security
We implement industry-standard security measures:
- Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Control: Multi-tenant architecture with Row Level Security (RLS)
- Authentication: Email verification, session management, and role-based access controls
- Audit Logging: Access to patient content is logged with who accessed it and when
- Monitoring: Platform health and error monitoring with alerting on failures
- Backups: Encrypted backups managed by our database platform
5. Data Retention
- Call recordings: 90 days by default (configurable: 7 years for legal/medical)
- Transcripts: Retained as long as your account is active
- Contact data: Retained until you delete or request removal
- Account data: Deleted within 30 days of account closure
6. Your Privacy Rights
You have the right to:
- Access your data: Request a copy of all data we have about you
- Delete your data: Request permanent deletion of your account and data
- Correct your data: Update inaccurate or incomplete information
- Data portability: Export your data in machine-readable format
To exercise your rights: Email privacy@spiderlabs.ai and we will respond within the timelines required by applicable law.
7. Cookies and Tracking
We use cookies for authentication and preferences. See our Cookie Policy for details.
- Essential cookies: Required for login and security (cannot be disabled)
- Functional cookies: Remember your preferences (theme, language)
- Analytics cookies: None currently set; the Cookie Policy will list them before any are added
8. Industry-Specific Compliance
Healthcare (HIPAA)
For dental and medical spa clients, we follow HIPAA-aligned practices and offer a Business Associate Agreement (BAA):
- Business Associate Agreements (BAAs) signed with covered infrastructure and voice-processing subprocessors
- Call recordings encrypted with AES-256
- Access logs maintained for all PHI (Protected Health Information)
- 7-year retention for medical records (configurable)
Payment Data (PCI-DSS)
- The AI receptionist does not collect payment card data on calls
- Subscription billing for your SpiderLabs account is handled by a PCI-DSS Level 1 certified payment processor; we never store credit card numbers
9. Children's Privacy
SpiderLabs is a business-to-business service. We do not knowingly collect information from children under 13. If a call is received from a minor, it is incidental to providing services to our business clients.
10. International Data Transfers
Your data is primarily stored in US data centers with HIPAA-eligible infrastructure. For EU clients, we ensure:
- Standard Contractual Clauses (SCCs) for EU-US data transfers
- GDPR-compliant data processing agreements
- If you have data residency requirements, contact privacy@spiderlabs.ai to discuss what we can support
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be announced via:
- Email notification to your account email
- In-dashboard notification banner
- Updated "Last modified" date at the top of this page
Continued use of SpiderLabs after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions, data requests, or concerns:
- Email: privacy@spiderlabs.ai
- Data Protection Officer: privacy@spiderlabs.ai
Related: Terms of Service · Cookie Policy · Trust center