1. Scope of this policy
This policy applies to the Callniva website, account experience, business workspaces, phone-number and missed-call workflows, text conversations, lead and booking tools, team features, analytics, support, and related services. A business using Callniva may also provide its own privacy notice to its customers. That business notice governs the business’s own collection and use of customer information.
2. Information we process
Depending on how Callniva is configured, we may process the following categories of information:
- Account information: name, email address, authentication details, account status, and security records.
- Business information: business name, services, locations, operating hours, policies, custom rules, required fields, and knowledge-base content.
- SignalWire connection information: Space URL, Project ID, encrypted API token and Signing Key, imported phone-number identifiers, webhook configuration and verification state, and the configured forward number.
- Communication information: phone numbers, call status and timing, message metadata, conversation content, opt-out records, attachments where supported, and human-handoff activity.
- Lead and booking information: customer names, contact details, requested services, preferred dates or times, notes, booking status, team decisions, and calendar event references.
- Workspace information: team membership, roles, permissions, assignments, activity history, and audit events.
- Technical and usage information: device and browser details, IP address, page activity, error logs, usage totals, performance data, and security signals.
- Billing information: Callniva subscription state, plan, payment status, transaction references, and information supplied by the payment provider. SignalWire independently processes and bills its own phone-number and telecom usage charges. Callniva does not need to store full payment-card details when payment is handled by an external provider.
3. Where information comes from
Information may come directly from account owners and team members, from customers who call or message a business, from connected telephony, messaging, email, calendar, AI, hosting, analytics, and payment providers, and from normal use of the Callniva website and application.
4. How we use information
We process information to provide and secure Callniva, including to verify and connect a business-owned SignalWire account, configure and validate required webhooks on an imported number, forward calls, identify missed calls, send follow-up messages, generate business-grounded AI replies, collect required details, create leads, operate automatic and manual booking workflows, create human requests, notify teams, provide analytics, process Callniva subscriptions, prevent abuse, troubleshoot errors, and improve reliability.
We may also use account and service information to communicate about onboarding, important service changes, security events, billing, support requests, and legally required notices. Callniva does not use a connected SignalWire credential to buy a number on the business’s behalf.
5. AI processing
Callniva may send relevant conversation content and business-provided knowledge to an AI provider so the service can generate replies or classify the next workflow. Businesses should avoid adding unnecessary sensitive information to their knowledge base or custom instructions. AI output may be incomplete or incorrect, so Callniva supports business rules, confidence controls, manual review, and human escalation.
6. Google Calendar and Google API data
Access and use. Connecting Google Calendar is optional and is initiated by an authorized business owner or administrator. Callniva requests the https://www.googleapis.com/auth/calendar.events.owned permission, which limits event access to calendars the Google user owns, and Callniva uses it only with the connected account's primary calendar. Callniva reads event status, title, transparency, location, link, and start and end times to check availability, prevent double-booking, and display an upcoming-event preview. It creates booking events with the appointment and customer details supplied through the Callniva workflow, retrieves linked events to make retries safe, and deletes a linked event when an authorized Callniva workflow requires that event to be removed.
Storage and retention. Callniva stores encrypted OAuth access and refresh tokens, token expiry and granted-scope metadata needed to maintain the optional connection, together with Google event identifiers and booking information needed to operate and audit linked Callniva bookings. Event details read for preview and conflict checks are processed as needed and are not retained as permanent copies of unrelated calendar events. When an authorized business owner disconnects Google Calendar in Callniva, Callniva deletes the stored Calendar connection and its OAuth tokens and disables automatic booking. Existing events remain in the user's Google Calendar until the user removes them there. Eligible retained Callniva booking or event-reference records may be deleted on a verified request, subject to the retention obligations described below.
Sharing, human access, and Limited Use. Callniva does not sell Google user data, use it for advertising, or share it with unrelated third parties. Callniva personnel do not access Google user data except with the user's authorization for support, when needed to investigate security or abuse, to comply with applicable law, or for permitted internal operations using aggregated and de-identified data. Google user data may otherwise be handled only as necessary to provide and secure the user-requested Calendar feature through contracted infrastructure providers. Callniva's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use compliance. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
User control. The business owner can disconnect Google Calendar from the Callniva Calendar page and can also revoke Callniva in the Google Account permissions page. Privacy and deletion requests may be sent using the contact information below.
7. Service providers and connected services
A business connects its own SignalWire account for telephony and messaging. SignalWire independently processes calls, messages, phone-number records, account information, and telecom billing under its own terms and privacy practices. Callniva stores connected credentials encrypted and uses them to validate access, list eligible owned numbers, manage the required Callniva webhook fields, send configured messages, and read delivery state.
We may also use carefully selected providers for email delivery, artificial intelligence, calendar connectivity, hosting, security, monitoring, analytics, and payment processing. These providers process information to perform services for Callniva or the business that connected them. When a business connects Google Calendar or another integration, Callniva accesses only the information needed to provide the configured feature, subject to the permissions granted through that provider.
8. Business control and legal responsibilities
The business using Callniva controls the customer information, business knowledge, rules, and workflows it supplies. Each business is responsible for having an appropriate legal basis to call, text, or otherwise communicate with customers; providing required privacy notices; honoring consent and opt-out requirements; restricting team access; and configuring Callniva in accordance with applicable laws, carrier rules, and industry obligations.
9. Cookies and similar technologies
Callniva may use essential cookies and local storage to maintain sessions, remember security and workspace state, protect forms, and keep the application functioning. We may also process limited diagnostic information to understand performance and fix errors. Where non-essential analytics or marketing technologies are introduced, additional notice or consent may be provided when required.
10. Retention, export, and deletion
We retain information for as long as reasonably necessary to provide the service, maintain security and audit history, comply with legal obligations, resolve disputes, enforce agreements, and protect Callniva and its users. Retention periods can vary by data type, plan, workspace configuration, provider limitation, and legal requirement.
Authorized account owners may request available exports or deletion of eligible workspace information. Some records may be retained where required for billing, fraud prevention, legal compliance, backup integrity, or dispute resolution.
11. Your choices and rights
Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, or objection regarding personal information. Requests may need to be directed first to the business that used Callniva to communicate with the individual. We may verify identity and authority before completing a request.
Customers may opt out of applicable text messaging using the instructions provided in the conversation or by contacting the relevant business.
12. Security
Callniva uses administrative, technical, and organizational safeguards designed to protect information. Measures may include encryption in transit, restricted access, tenant separation, signed webhook validation, secret management, rate limits, audit logging, backups, and monitoring. No online service can guarantee absolute security, and businesses must also protect their credentials, connected accounts, devices, and team permissions.
13. International processing
Callniva and its providers may process information in countries other than the country where the business or customer is located. Where required, appropriate contractual or legal safeguards may be used for cross-border processing.
14. Children
Callniva is a business service and is not directed to children. Businesses should not intentionally use Callniva to collect information from children in violation of applicable law.
15. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. The updated date at the top of this page will show when the policy was revised. Material changes may also be communicated through the service or by email where appropriate.
16. Contact
Questions or privacy requests may be sent to ganukapabasara650@gmail.com. Include enough information for us to understand the request, but do not send passwords, full payment-card details, or unnecessary sensitive information by email.