Skip to main content

Privacy, Data Processing & Transparency Policy

Effective 22 August 2026

Last updated: 22 August 2026

Important — please read this policy carefully

This Privacy, Data Processing & Transparency Policy (“Privacy Policy”, “Policy”) explains in detail how Hawi Inc., operating Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, “our”) collects, receives, accesses, observes, records, generates, organises, stores, structures, retrieves, analyses, combines, transmits, discloses, restricts, archives, deletes and otherwise processes information relating to identifiable individuals.

Hawi provides software Agents capable of performing operational work, communicating through third-party systems, reading and writing information, handling files and messages, interacting with connected services, participating in voice calls, producing transcripts, carrying out authorised business workflows, communicating with third parties and, where specifically enabled, performing financial or otherwise consequential actions.

Using an Agent may therefore cause Personal Data to move between Hawi, the Customer, the Customer's Connected Services, infrastructure providers, communications providers, model providers and other service providers necessary to perform the task.

This Policy is deliberately detailed because Hawi wants users, Customers, administrators and individuals interacting with Hawi Agents to understand what may occur when the Services are used.

However:

This Privacy Policy does not itself constitute consent where consent is legally required.

Where processing requires consent, Hawi or the relevant Customer must obtain the required consent separately.

Similarly:

A person's acceptance of Hawi's Terms of Service or acknowledgement of this Privacy Policy does not waive that person's statutory privacy rights.

No provision of this Policy is intended to remove a right that applicable law does not permit a person to waive.

Part 1 — IMPORTANT DISCLOSURES AT A GLANCE

The following disclosures are particularly important.

1. Hawi uses software Agents

Hawi allows Customers to create and operate software Agents.

Depending on Customer configuration, an Agent may:

  • read information;
  • analyse information;
  • retrieve records;
  • generate responses;
  • communicate externally;
  • send emails;
  • respond to messages;
  • update Connected Services;
  • schedule events;
  • retrieve documents;
  • process files;
  • interact with commerce systems;
  • interact with customer-support systems;
  • conduct or participate in calls;
  • transcribe calls;
  • perform follow-up actions;
  • delegate tasks to another authorised Agent;
  • and perform other actions authorised by the Customer.

2. Hawi Agents may interact with third parties

An individual may interact with a Hawi Agent without creating a Hawi account.

For example, Hawi may process information concerning:

  • a business's customer;
  • caller;
  • supplier;
  • employee;
  • contractor;
  • prospect;
  • applicant;
  • buyer;
  • seller;
  • support requester;
  • delivery recipient;
  • or business contact.

Where Hawi processes that information on behalf of a Customer, the Customer will normally be responsible for determining the purpose and lawful basis of that processing.

3. Hawi uses external providers

Hawi relies on external infrastructure and service providers.

Depending on the Service being used, information may be processed through providers supporting:

  • hosting;
  • databases;
  • authentication;
  • storage;
  • model inference;
  • AI functionality;
  • voice functionality;
  • telecommunications;
  • speech recognition;
  • speech synthesis;
  • payments;
  • financial connections;
  • analytics;
  • monitoring;
  • email;
  • security;
  • and third-party integrations.

4. Information may leave your country

Even where Hawi stores core information in a particular region, Personal Data may be processed internationally because service providers, Connected Services and Customers may operate in multiple countries.

International transfers are addressed later in this Policy.

5. Agents may process the contents of connected systems

If a Customer connects a system such as an email account, calendar, CRM, commerce platform or another service, authorised Hawi Agents may process information available through the permissions granted to that connection.

This can include third-party Personal Data.

6. Agents may create new information

Hawi Agents can generate:

  • summaries;
  • classifications;
  • drafts;
  • recommendations;
  • task records;
  • extracted fields;
  • structured data;
  • inferred information;
  • and other outputs.

Generated or inferred information relating to an identifiable person may itself constitute Personal Data.

7. AI-generated information may be incorrect

Model-generated or Agent-generated output can be:

  • inaccurate;
  • incomplete;
  • outdated;
  • misleading;
  • inappropriate;
  • or based on incorrect source information.

Customers should implement human review where the consequences of an error would be significant.

8. Hawi may maintain Agent activity records

Hawi may maintain records of Agent activity to:

  • provide continuity;
  • allow tasks to resume;
  • identify failures;
  • prevent duplicate external actions;
  • investigate incidents;
  • calculate usage;
  • enforce limits;
  • provide auditability;
  • process approvals;
  • and support users.

9. Connected Service credentials require special protection

Hawi may hold OAuth tokens, API credentials or similar authentication material necessary to access Connected Services.

Hawi is designed to keep those credentials in restricted server-side systems rather than expose unrestricted credentials directly to Agents, ordinary users or browser clients.

Certain functionality may require additional disclosures, consent or affirmative acknowledgement.

Examples can include:

  • optional analytics;
  • direct marketing;
  • call recording;
  • voice transcription;
  • Special Category Data;
  • wellness information;
  • automatic purchasing;
  • financial connections;
  • certain automated decisions;
  • or processing requiring consent under applicable law.

11. Automatic purchasing is a separate permission

Permission for an Agent to generally operate autonomously does not automatically give the Agent permission to spend money.

Where Hawi provides automatic purchasing, it should be subject to separate configuration and authorisation.

12. Hawi may process Personal Data to protect the Service

Security processing may include:

  • IP addresses;
  • request metadata;
  • failed authentication attempts;
  • device information;
  • suspicious activity;
  • rate-limit events;
  • malware indicators;
  • abuse reports;
  • and security alerts.

13. Business administrators may have access to business information

Where an Account is controlled by an organisation, authorised Account or Workspace administrators may be able to access organisational information.

A user should not assume information placed into a company-controlled Workspace is private from that organisation.

Hawi's technical ability to process information does not establish the Customer's right to provide, access or process that information.

Part 2 — WHO WE ARE

15. Hawi Inc.

The Services are operated by:

Hawi Inc.

Trading as: Hawi Agents

Website:

HawiAgents.com

General contact:

help@hawiagents.com

Privacy contact:

help@hawiagents.com

Security contact:

help@hawiagents.com

Part 3 — APPLICATION OF THIS POLICY

16. Services covered

This Policy applies to Hawi's:

  • websites;
  • Accounts;
  • Workspaces;
  • Agents;
  • Boards;
  • chat functionality;
  • team messaging;
  • voice functionality;
  • file processing;
  • integrations;
  • Connected Services;
  • APIs;
  • marketplace;
  • creator functionality;
  • billing;
  • credits;
  • voice units;
  • financial functionality;
  • automatic purchasing;
  • support;
  • privacy systems;
  • security systems;
  • and related Hawi applications.

17. Additional notices

Certain Hawi functionality may have additional privacy notices.

For example:

  • voice recording;
  • wellness information;
  • financial connections;
  • automatic purchasing;
  • marketplace participation;
  • marketing;
  • cookies;
  • or experimental features.

Those notices supplement this Policy.

18. Just-in-time notices

Where appropriate, Hawi may display notices immediately before a particular processing activity.

For example:

“This call will be transcribed.”

or:

“Connecting this account allows authorised Agents in this Workspace to read and perform the actions described below.”

or:

“Enabling automatic purchasing allows eligible Agents to complete purchases up to the spending limit you configure.”

A feature-specific notice may provide information more directly relevant to that processing than this general Policy.

Part 4 — HAWI'S DATA-PROTECTION ROLE

19. Hawi as controller

Hawi generally acts as controller for Personal Data processed for purposes such as:

  • registration;
  • authentication;
  • Hawi Account administration;
  • billing;
  • marketplace administration;
  • creator payouts;
  • security;
  • fraud prevention;
  • service analytics;
  • privacy requests;
  • legal compliance;
  • and Hawi's own customer relationship management.

20. Hawi as processor

Hawi generally acts as processor where a Customer uses Hawi to process information for purposes determined by that Customer.

Examples include:

  • processing the Customer's email;
  • processing customer-support tickets;
  • processing CRM information;
  • responding to Customer communications;
  • handling Customer files;
  • accessing Customer orders;
  • processing Customer calls;
  • and performing Customer-configured workflows.

21. Customer as controller

Where Hawi processes Personal Data on behalf of a Customer, that Customer will usually determine:

  • why information is processed;
  • which information is processed;
  • which Connected Services are used;
  • which Agents have access;
  • which actions are authorised;
  • and how long certain information should be retained.

22. Customer responsibility

Customers are responsible for establishing, where required:

  • a lawful basis;
  • transparency;
  • consent;
  • employment-law compliance;
  • marketing-law compliance;
  • call-recording compliance;
  • consumer-law compliance;
  • and appropriate internal authorisation.

Part 5 — DATA PROCESSING AGREEMENT

23. Article 28 processing

Where Hawi processes Personal Data on behalf of a Customer, Hawi and the Customer may be subject to Hawi's Data Processing Agreement.

24. Documented instructions

Where Hawi acts as processor, Hawi will process Personal Data according to the Customer's documented instructions except where law requires processing outside those instructions.

25. Unlawful instructions

Hawi may decline, suspend or restrict an instruction where Hawi reasonably believes the instruction:

  • violates applicable law;
  • compromises security;
  • violates another person's rights;
  • exceeds permitted access;
  • or breaches Hawi's contractual restrictions.

Part 6 — INFORMATION YOU PROVIDE

26. Registration information

Hawi may collect:

  • name;
  • email;
  • telephone number;
  • username;
  • profile image;
  • timezone;
  • organisation;
  • role;
  • authentication information;
  • and age-confirmation information.

27. Information entered into Hawi

Anything entered into:

  • a prompt;
  • form;
  • message;
  • Agent instruction;
  • Workspace;
  • file;
  • Board;
  • task;
  • support ticket;
  • or other Hawi field

may be processed to provide the applicable functionality.

Part 7 — ACCOUNT AND WORKSPACE DATA

Hawi may process:

  • Account ID;
  • Account name;
  • owner;
  • administrators;
  • members;
  • billing contact;
  • membership;
  • invitations;
  • roles;
  • seat allocations;
  • status;
  • Workspace membership;
  • Workspace permissions;
  • Agent assignments;
  • integration assignments;
  • and administrative activity.

Part 8 — AGENT INFORMATION

Agent information may include:

  • Agent name;
  • purpose;
  • instructions;
  • restrictions;
  • model;
  • tools;
  • Connected Service permissions;
  • Workspace assignment;
  • spending permissions;
  • approval requirements;
  • scheduling;
  • triggers;
  • collaborators;
  • execution status;
  • version;
  • limits;
  • and operational settings.

Part 9 — PROMPTS, RESPONSES AND AGENT RUNS

Hawi may process:

  • prompts;
  • instructions;
  • relevant conversation history;
  • model inputs;
  • visible outputs;
  • structured tool calls;
  • tool results;
  • runtime state;
  • task state;
  • retries;
  • completion information;
  • provider/model information;
  • usage information;
  • and error information.

Part 10 — MODEL REASONING

Hawi may process visible model outputs and structured operational information.

Hawi does not intend to expose or retain proprietary hidden chain-of-thought from model providers as ordinary Customer Content.

Where a model provider generates internal reasoning not returned by the API as Customer-visible content, Hawi should not represent that hidden provider reasoning as a Customer record.

Hawi may nevertheless retain:

  • summaries;
  • decisions;
  • action selections;
  • observable outputs;
  • and operational events

necessary to explain what happened during an Agent run.

Part 11 — AGENT MEMORY

Where Hawi offers Agent memory, Personal Data may be retained so that an Agent can remember information across sessions.

Memory may include:

  • user preferences;
  • business rules;
  • customer information;
  • prior task outcomes;
  • operational context;
  • and information intentionally stored for later use.

Where practical, Customers should be given controls for:

  • viewing memory;
  • editing memory;
  • deleting memory;
  • or disabling memory.

Memory should not be used as a means of avoiding applicable retention requirements.

Part 12 — TEAM CHAT

Team chat may contain:

  • messages;
  • attachments;
  • mentions;
  • Agent responses;
  • timestamps;
  • participant identities;
  • and Workspace information.

Users should not place unnecessary highly sensitive information into team chat.

Part 13 — FILES

Hawi may process:

  • file content;
  • filename;
  • extension;
  • MIME type;
  • size;
  • uploader;
  • Workspace;
  • file hash;
  • upload time;
  • validation status;
  • storage location;
  • malware status;
  • quarantine status;
  • and access metadata.

Part 14 — FILE SECURITY

Files may undergo automated technical inspection for:

  • malware;
  • executable content;
  • dangerous file structures;
  • mismatched extensions;
  • invalid MIME types;
  • suspicious archives;
  • malicious macros;
  • or other security risks.

A file may be:

  • quarantined;
  • rejected;
  • restricted;
  • deleted;
  • or prevented from being opened

where Hawi believes it presents a security threat.

Part 15 — CONNECTED SERVICES

Customers may connect external services to Hawi.

Hawi may process:

  • provider;
  • account identifier;
  • organisation identifier;
  • connection owner;
  • scopes;
  • permissions;
  • token expiry;
  • status;
  • provider metadata;
  • webhook configuration;
  • credential reference;
  • and connection activity.

Part 16 — WHAT CONNECTING A SERVICE MEANS

When you connect a service, you authorise Hawi to interact with that service within the permissions granted and Hawi's own permission controls.

This can allow Hawi to:

  • retrieve information;
  • read records;
  • create records;
  • update records;
  • delete records where supported and authorised;
  • send messages;
  • upload information;
  • download information;
  • and perform other operations exposed by the Connected Service.

Exactly which actions are available depends on the provider and the Customer's configuration.

Part 17 — ACCOUNT-SCOPED CONNECTIONS

A Connected Service may be owned at Account level while being selectively enabled for one or more Workspaces.

This means a Customer may connect a provider once and assign access to selected Workspaces without duplicating the underlying secret.

Part 18 — CONNECTOR CREDENTIALS

Credentials may include:

  • OAuth access tokens;
  • refresh tokens;
  • API keys;
  • client secrets;
  • service credentials;
  • private keys;
  • basic-authentication credentials;
  • database credentials;
  • and webhook secrets.

Hawi should store credentials in restricted systems designed for secrets.

Part 19 — CREDENTIAL ACCESS

Possession of a Connected Service within an Account does not automatically mean every:

  • user;
  • Workspace;
  • Agent;
  • or application

may use the connection.

Access may depend on:

  • Account role;
  • Workspace assignment;
  • Agent permission;
  • operation permission;
  • approval requirement;
  • and provider restrictions.

Part 20 — EMAIL

An authorised email integration may allow Hawi to process:

  • sender;
  • recipient;
  • subject;
  • body;
  • attachments;
  • headers;
  • labels;
  • folders;
  • thread history;
  • drafts;
  • message IDs;
  • and timestamps.

An Agent may, where authorised:

  • read;
  • categorise;
  • summarise;
  • draft;
  • reply;
  • forward;
  • archive;
  • label;
  • or otherwise interact with messages.

Part 21 — CALENDAR

Calendar processing may include:

  • event title;
  • attendees;
  • email addresses;
  • times;
  • location;
  • conference links;
  • notes;
  • description;
  • recurrence;
  • availability;
  • and reminders.

Part 22 — CONTACTS

Connected contact systems may contain:

  • name;
  • email;
  • phone;
  • address;
  • employer;
  • title;
  • notes;
  • relationship;
  • and custom fields.

Part 23 — CRM

Hawi may process:

  • leads;
  • contacts;
  • customers;
  • companies;
  • deals;
  • notes;
  • tasks;
  • sales activities;
  • pipeline information;
  • and communications.

Part 24 — PROJECT MANAGEMENT

Connected project-management information may include:

  • task;
  • project;
  • owner;
  • due date;
  • status;
  • assignee;
  • comment;
  • attachment;
  • priority;
  • and activity history.

Part 25 — COMMERCE

Commerce information may include:

  • buyer;
  • seller;
  • product;
  • order;
  • address;
  • inventory;
  • refund;
  • return;
  • shipping;
  • fulfilment;
  • supplier;
  • price;
  • and transaction information.

Part 26 — CUSTOMER SUPPORT

Support-platform data may include:

  • customer identity;
  • support request;
  • message history;
  • ticket;
  • priority;
  • attachment;
  • resolution;
  • and internal notes.

Part 27 — THIRD-PARTY DATA

Customers may instruct Hawi to process Personal Data relating to people who do not use Hawi.

A Customer must ensure such processing is lawful.

Hawi cannot independently guarantee that every Customer has fulfilled every notice or consent obligation owed to every person whose information appears in Customer systems.

Part 28 — INDIRECT COLLECTION

Where Hawi acts as controller and receives Personal Data about an individual from another source, Hawi will provide the required privacy information in accordance with applicable law unless an exemption applies.

Where Hawi acts solely as processor, the relevant Customer is generally responsible for Article 13/14 transparency obligations.

Part 29 — VOICE

Hawi voice functionality may process:

  • caller number;
  • recipient number;
  • call identifier;
  • call provider identifier;
  • call direction;
  • duration;
  • timestamps;
  • Agent identity;
  • status;
  • outcome;
  • transcript;
  • and other call metadata.

Part 30 — VOICE AUDIO

Where supported and enabled, Hawi may process audio to:

  • transmit speech;
  • convert speech to text;
  • understand requests;
  • generate responses;
  • convert text to speech;
  • and provide call functionality.

Part 31 — RECORDING

Where a call is recorded, additional legal obligations may apply.

Whether recording is lawful may depend on:

  • the location of the Customer;
  • the caller's location;
  • the recipient's location;
  • the purpose;
  • the type of call;
  • and applicable telecommunications and privacy law.

Part 32 — TRANSCRIPTION

Where transcription is enabled, spoken communications may be converted into written text.

Transcripts can include anything spoken during a call, including:

  • names;
  • addresses;
  • telephone numbers;
  • order information;
  • financial information;
  • health information;
  • or other sensitive content disclosed by a participant.

Part 33 — CUSTOMER RESPONSIBILITY FOR CALL NOTICES

Customers are responsible for determining when a caller must be informed that:

  • an automated Agent is participating;
  • a call is recorded;
  • a call is transcribed;
  • AI analysis is being used;
  • or information will be entered into other systems.

Part 34 — CALL FOLLOW-UP

An Agent may be configured to use information obtained during a call to take authorised follow-up actions, including:

  • sending an email;
  • updating a CRM;
  • creating a calendar event;
  • creating a task;
  • updating an order;
  • or notifying a Customer.

Part 35 — BILLING

Hawi may process:

  • subscription;
  • plan;
  • seats;
  • billing cycle;
  • currency;
  • amount;
  • invoice;
  • payment status;
  • payment-provider IDs;
  • cancellation;
  • renewal;
  • usage;
  • credits;
  • and voice allocation.

Part 36 — PAYMENT PROVIDERS

Payment-card information may be processed by third-party payment processors such as Stripe.

Hawi may receive limited information such as:

  • payment status;
  • transaction ID;
  • card brand;
  • last four digits;
  • expiry metadata;
  • fraud information;
  • refund information;
  • and dispute information.

Part 37 — HAWI CREDITS

Hawi may maintain:

  • credit wallets;
  • credit grants;
  • purchased credit lots;
  • reservations;
  • usage deductions;
  • settlements;
  • refunds;
  • adjustments;
  • expiration;
  • pricing versions;
  • and usage history.

Part 38 — VOICE UNITS

Voice usage may use a separate balance.

Hawi may process:

  • purchased voice amount;
  • available voice amount;
  • reserved voice units;
  • consumed voice units;
  • call duration;
  • and provider cost information.

Part 39 — AUTOMATIC RECHARGE

If a Customer enables automatic recharge, Hawi may automatically initiate payment under the limits and settings selected by the Customer.

Hawi may record:

  • who enabled the feature;
  • when it was enabled;
  • threshold;
  • amount;
  • monthly cap;
  • payment source reference;
  • attempt;
  • failure;
  • success;
  • and subsequent disablement.

Part 40 — AGENT PURCHASING

Where available and separately enabled, a Hawi Agent may be permitted to make purchases.

This may involve processing:

  • item;
  • seller;
  • amount;
  • currency;
  • shipping information;
  • recipient;
  • approval state;
  • payment reference;
  • purchase status;
  • and receipt information.

Part 41 — PURCHASING IS NOT IMPLIED

Creating an Agent does not alone authorise that Agent to make purchases.

Allowing an Agent to send messages does not alone authorise purchasing.

Allowing an Agent to access an integration does not alone authorise spending.

Automatic purchasing should require separate activation.

Part 42 — SPENDING LIMITS

Customers may be able to configure:

  • per-purchase limits;
  • Agent limits;
  • daily limits;
  • monthly limits;
  • category restrictions;
  • merchant restrictions;
  • or other spending controls.

Part 43 — PURCHASE NOTIFICATIONS

Where configured, Hawi may notify designated recipients following Agent spending.

A notification may contain:

  • Agent;
  • amount;
  • merchant;
  • product;
  • Workspace;
  • timestamp;
  • outcome;
  • and receipt information.

Part 44 — BANKING CONNECTIONS

Where Customers use financial-data functionality, Hawi may process bank-account metadata made available by an authorised financial-data provider.

This may include:

  • bank;
  • account type;
  • masked account number;
  • connection status;
  • account identifier;
  • provider identifier;
  • and transaction information where authorised.

Part 45 — PLAID OR SIMILAR PROVIDERS

Where a financial provider such as Plaid is used, the financial provider may independently process data under its own privacy policy and contractual terms.

Part 46 — MARKETPLACE

Marketplace information may include:

  • creator;
  • seller;
  • buyer;
  • listing;
  • price;
  • sale;
  • review;
  • rating;
  • fee;
  • refund;
  • dispute;
  • payout;
  • and moderation information.

Part 47 — MARKETPLACE PAYOUTS

Hawi may process information required to:

  • calculate creator earnings;
  • process payouts;
  • handle taxes;
  • identify fraud;
  • reverse invalid transactions;
  • and comply with financial obligations.

Part 48 — USER-GENERATED MARKETPLACE CONTENT

Users publishing marketplace content should understand that public listing information may be visible to other Hawi users.

Public information may include:

  • creator name;
  • listing name;
  • description;
  • screenshots;
  • rating;
  • review;
  • and other information intentionally made public.

Part 49 — MODERATION

Hawi may review marketplace or platform content to:

  • enforce rules;
  • investigate reports;
  • detect scams;
  • prevent malicious content;
  • protect users;
  • and comply with law.

Part 50 — API USAGE

Developer API information may include:

  • API-key identifier;
  • Account;
  • Workspace;
  • endpoint;
  • request count;
  • request time;
  • IP address;
  • status;
  • error information;
  • and usage.

Part 51 — TECHNICAL INFORMATION

Hawi may automatically process:

  • IP address;
  • browser;
  • operating system;
  • approximate location derived from network information;
  • language;
  • device type;
  • request path;
  • response status;
  • user agent;
  • session;
  • timestamp;
  • and error information.

Part 52 — IP ADDRESSES

IP addresses may be processed for:

  • security;
  • authentication;
  • fraud detection;
  • rate limiting;
  • abuse investigation;
  • troubleshooting;
  • and approximate regionalisation.

Part 53 — ANALYTICS

Where permitted and subject to applicable consent requirements, Hawi may process usage information to understand:

  • page visits;
  • feature usage;
  • performance;
  • conversion;
  • errors;
  • and general product interaction.

Where consent is legally required for optional cookies or similar technologies, Hawi will seek consent before enabling the relevant technology.

Rejecting optional analytics should not prevent strictly necessary Hawi functionality from operating.

Part 55 — MARKETING

Hawi may send marketing where permitted by law.

Users may opt out of marketing.

Opting out of marketing does not stop essential:

  • billing;
  • security;
  • Account;
  • privacy;
  • legal;
  • or Service notifications.

Part 56 — SECURITY PROCESSING

Hawi may process information to:

  • identify attacks;
  • detect suspicious logins;
  • prevent credential abuse;
  • identify malware;
  • prevent spam;
  • block rate-limit abuse;
  • investigate fraud;
  • detect cross-Account access attempts;
  • prevent privilege escalation;
  • and protect infrastructure.

Part 57 — FRAUD DETECTION

Hawi may analyse:

  • payment activity;
  • Account activity;
  • Agent actions;
  • marketplace activity;
  • login behaviour;
  • network information;
  • and transaction patterns

to identify suspected fraud.

Part 58 — ABUSE PREVENTION

Hawi may restrict or suspend activity that appears to involve:

  • unauthorised access;
  • fraud;
  • malicious automation;
  • credential theft;
  • spam;
  • malware;
  • evasion;
  • excessive abusive requests;
  • or another prohibited activity.

Part 59 — SUPPORT ACCESS

Where necessary to resolve a support issue, authorised Hawi personnel may access limited Account information relevant to the problem.

Support access should be:

  • authorised;
  • proportionate;
  • limited;
  • and logged where appropriate.

Part 60 — EMPLOYEE ACCESS

Hawi personnel should not browse Customer data without an appropriate business reason.

Access may be permitted for:

  • support;
  • debugging;
  • incident response;
  • security;
  • compliance;
  • fraud investigation;
  • or legal obligations.

Part 61 — AI/MODEL PROVIDERS

Hawi may use external model providers to perform:

  • text generation;
  • reasoning;
  • extraction;
  • classification;
  • planning;
  • tool selection;
  • transcription;
  • speech processing;
  • and other Agent functionality.

Part 61A — WHICH MODELS ARE OFFERED, AND WHEN THAT CHANGES

Hawi selects and secures the model provider credentials. A Customer does not supply an API key, and the models available to an Agent are the ones Hawi offers at the time.

Hawi maintains a roster of at most six models per provider. When a provider releases a stronger model, Hawi may add it to the roster and remove the least capable model then on it, so that the Service is not delivering results from a materially weaker model than the provider makes available.

The effect of a removal is limited and is the following:

  • an Agent already configured against a removed model continues to run on that
  • model, and is not moved to a different one without the Customer's action;
  • the removed model is no longer offered when creating or editing an Agent;
  • a removal may change the credit cost of a task, because a more capable model
  • ordinarily consumes more credits than a less capable one. The authoritative
  • charge is always the one calculated at the rate version live when the request
  • starts, and a Customer can see the indicative cost of each model before
  • selecting it.

Hawi does not remove a model in order to increase what a Customer spends, and a Customer who does not wish to move to a more capable model may keep an existing Agent on the model it already uses.

Where a change to the roster would materially change the processing of Personal Data, Part 17 and Part 18 apply.

Part 62 — WHAT MAY BE SENT TO MODEL PROVIDERS

Relevant information may include:

  • system instructions;
  • prompts;
  • recent conversation context;
  • selected Connected Service information;
  • selected file content;
  • tool definitions;
  • and task-related information.

Hawi should seek to send only information reasonably required for the task.

Part 63 — MODEL PROVIDER TRAINING

Whether a third-party model provider may use information for its own model training depends on:

  • provider;
  • API product;
  • contract;
  • Account configuration;
  • and provider terms.

Hawi should disclose the actual production arrangements through appropriate product documentation or its Subprocessor List.

Hawi will not state that data is never used for provider training unless the applicable technical and contractual arrangements support that statement.

Part 64 — HAWI TRAINING

Hawi does not intend to sell private Customer prompts or private Workspace content for unrelated third-party model training.

If Hawi intends to use identifiable Customer Content to train a general-purpose Hawi model for purposes materially different from providing the Customer's Service, Hawi must establish an appropriate lawful basis and provide additional notice before commencing such processing.

Part 65 — AUTOMATED PROCESSING

Hawi Agents may automatically:

  • categorise;
  • rank;
  • extract;
  • prioritise;
  • summarise;
  • recommend;
  • schedule;
  • route;
  • draft;
  • and execute authorised operations.

Part 66 — PROFILING

Automated processing may constitute profiling where Personal Data is used to evaluate or predict characteristics concerning a person.

Where applicable, Hawi or the Customer must comply with the legal requirements relating to profiling.

Part 67 — SIGNIFICANT AUTOMATED DECISIONS

Hawi's general-purpose Services are not intended to be used to make unlawful solely automated decisions producing legal or similarly significant effects on a person.

Where applicable law imposes specific requirements, the relevant controller must provide safeguards.

Part 68 — HIGH-RISK DECISIONS

Customers should not deploy Hawi without appropriate assessment for decisions involving:

  • hiring;
  • firing;
  • employment discipline;
  • credit;
  • lending;
  • insurance;
  • healthcare;
  • housing;
  • education;
  • access to essential services;
  • criminal justice;
  • or other decisions having significant consequences.

Part 69 — HUMAN INTERVENTION

Where required by law, users or affected individuals may need to be provided with:

  • human review;
  • the ability to express their view;
  • an explanation;
  • and the ability to contest a decision.

Part 70 — AGENT ERROR AND HUMAN OVERSIGHT

Customers are responsible for deciding when a Hawi Agent's output should require human review.

Hawi may provide technical approval controls, but Hawi cannot determine every Customer's legal or operational review obligation.

Part 71 — SPECIAL CATEGORY DATA

Hawi may process Special Category Data where it appears in Customer Content.

Examples may include:

  • health information;
  • racial or ethnic information;
  • religion;
  • political opinions;
  • biometric information;
  • union membership;
  • sex-life information;
  • or sexual-orientation information.

Customers should not provide such information unless necessary and lawful.

Part 72 — WELLNESS INFORMATION

Where Hawi provides optional wellness features, explicit consent may be used where required by Article 9 GDPR.

Consent should be separate and specific.

A wellness-consent record may identify:

  • person;
  • purpose;
  • categories;
  • processor;
  • model/Agent analysis;
  • notice version;
  • exact consent text;
  • timestamp;
  • method;
  • withdrawal;
  • and erasure.

Where processing relies solely on explicit consent, withdrawal should stop future processing unless another legal basis permits continuation.

Applicable wellness information should be erased where required.

Part 75 — CHILDREN

Hawi's ordinary Accounts are intended for users aged 18 or over.

Hawi does not knowingly intend to permit children to open ordinary Hawi Accounts.

Part 76 — CHILD DATA IN CUSTOMER SYSTEMS

A Customer's Connected Services may nevertheless contain information about children.

Customers are responsible for ensuring processing of such information is lawful.

Part 77 — PURPOSES OF PROCESSING

Hawi may process Personal Data to:

  • provide the Services;
  • authenticate users;
  • execute Agent tasks;
  • maintain Agent continuity;
  • provide Connected Service functionality;
  • provide voice services;
  • store files;
  • facilitate teamwork;
  • process billing;
  • administer credits;
  • operate marketplace functionality;
  • provide support;
  • secure the Service;
  • prevent fraud;
  • maintain reliability;
  • comply with law;
  • and establish or defend legal claims.

Part 78 — CONTRACTUAL NECESSITY

Where applicable, Hawi may rely on Article 6(1)(b) GDPR where processing is necessary to perform its contract with an individual.

Part 79 — LEGITIMATE INTERESTS

Hawi may rely on legitimate interests for activities such as:

  • fraud prevention;
  • security;
  • service reliability;
  • business administration;
  • abuse prevention;
  • and legal claims,

where those interests are not overridden by the affected person's rights.

Where consent is used, Hawi should:

  • request a positive action;
  • avoid pre-ticked boxes;
  • make the request specific;
  • separate it where appropriate;
  • explain what is being agreed to;
  • record the consent;
  • and provide an easy withdrawal mechanism.

Hawi may process information to satisfy:

  • tax law;
  • accounting law;
  • regulator requirements;
  • court orders;
  • privacy law;
  • financial obligations;
  • and other applicable legislation.

Hawi may retain or use Personal Data where necessary to:

  • establish;
  • exercise;
  • investigate;
  • defend;
  • or settle

a legal claim.

Part 83 — DATA SHARING

Personal Data may be shared with organisations that help Hawi provide the Services.

These organisations may include providers of:

  • hosting;
  • databases;
  • storage;
  • models;
  • communications;
  • voice;
  • speech;
  • payments;
  • banking connectivity;
  • analytics;
  • security;
  • email;
  • support;
  • and Connected Services.

Part 84 — SUBPROCESSORS

Hawi should maintain a current Subprocessor List.

The list should identify, where appropriate:

  • provider;
  • purpose;
  • location;
  • and transfer mechanism.

Part 85 — VERCEL

Hawi currently uses Vercel infrastructure for aspects of:

  • application hosting;
  • deployment;
  • computation;
  • application delivery;
  • analytics/performance tooling where enabled;
  • and related infrastructure.

Part 86 — SUPABASE

Hawi currently uses Supabase for aspects of:

  • PostgreSQL databases;
  • storage;
  • authentication;
  • backend services;
  • and associated infrastructure.

Hawi's current Supabase project is configured in the London, United Kingdom (eu-west-2) region.

Part 87 — STRIPE

Hawi may use Stripe for:

  • payments;
  • subscriptions;
  • payment-method processing;
  • marketplace payments;
  • creator payouts;
  • connected accounts;
  • fraud functions;
  • refunds;
  • and chargebacks.

Part 88 — VOICE PROVIDERS

Voice functionality may require Hawi to transmit necessary information to:

  • telecommunications providers;
  • speech-to-text providers;
  • text-to-speech providers;
  • and call-processing infrastructure.

Part 89 — CONNECTED SERVICE PROVIDERS

When an Agent performs an operation through a Connected Service, information may be transmitted to that Connected Service.

For example, sending an email necessarily transmits the email to the email provider and intended recipient.

Part 90 — INTERNATIONAL TRANSFERS

Personal Data may be processed outside:

  • the United Kingdom;
  • the European Economic Area;
  • or the Data Subject's country

when necessary to provide the Services.

Part 91 — UK TRANSFERS

Where required, Hawi may use:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to EU Standard Contractual Clauses;
  • Binding Corporate Rules;
  • or another legally recognised safeguard.

Part 92 — EU TRANSFERS

Where EU GDPR applies, Hawi may use:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • Binding Corporate Rules;
  • or another Article 46 transfer safeguard.

Part 93 — TRANSFER ASSESSMENTS

Where necessary, Hawi may assess whether destination-country law or practices could materially impair the transfer safeguard.

Part 94 — RETENTION

Hawi retains Personal Data according to the purpose, legal obligations, Customer configuration, security considerations and technical requirements.

Part 95 — CURRENT RETENTION EXAMPLES

At the date of this Policy, Hawi's technical systems include retention schedules such as:

RecordIndicative retention
Certain OAuth state~1 hour
Phone verification challenges~24 hours
Security challenges~24 hours
API rate-limit buckets~7 days
Certain API/security logs~30 days
Certain webhook records~30 days
Certain connector executions~90 days
Wellness measurements~180 days
Voice transcript turns~365 days
Voice notes~365 days
Certain top-up/payment-attempt records~2 years

These periods may change where law, Customer configuration, security or operational necessity requires another period.

Part 96 — ACTIVE CUSTOMER CONTENT

Customer Content may generally remain available while the relevant Account is active or until deleted through the Services, subject to applicable retention settings.

Part 97 — FINANCIAL RECORDS

Billing, payout, accounting and tax records may need to be retained for longer statutory periods.

Part 98 — SECURITY RECORDS

Security information may be retained to:

  • investigate attacks;
  • identify repeated abuse;
  • prevent fraud;
  • and establish legal claims.

Part 99 — BACKUPS

Information deleted from active systems may remain temporarily in protected backup systems.

Backups may be retained until overwritten through ordinary backup rotation.

A legal hold may temporarily suspend normal deletion.

Part 101 — DATA MINIMISATION

Hawi should process only Personal Data reasonably necessary to perform the applicable purpose.

Part 102 — SECURITY

Hawi uses or seeks to use measures including:

  • encryption in transit;
  • restricted credential storage;
  • private storage;
  • authentication;
  • MFA support;
  • access controls;
  • Account isolation;
  • Workspace isolation;
  • audit logging;
  • rate limiting;
  • malware detection;
  • file validation;
  • security headers;
  • secret separation;
  • webhook verification;
  • monitoring;
  • and incident response.

Part 103 — NO GUARANTEE OF ABSOLUTE SECURITY

No online system is completely immune from attack, error or unauthorised access.

Hawi cannot guarantee absolute security.

Part 104 — CUSTOMER SECURITY RESPONSIBILITY

Customers remain responsible for:

  • secure passwords;
  • MFA;
  • secure devices;
  • staff access;
  • Agent permissions;
  • integration assignments;
  • API keys;
  • employee offboarding;
  • and protecting credentials.

Part 105 — PERSONAL DATA BREACHES

Where Hawi experiences a Personal Data breach, Hawi will investigate and respond according to applicable legal obligations.

Part 106 — PROCESSOR BREACH NOTIFICATION

Where Hawi acts as processor, Hawi will notify the relevant controller without undue delay where required.

Part 107 — REGULATOR NOTIFICATION

Where applicable law requires regulatory notification, Hawi will make the required notification within the applicable timeframe.

Part 108 — INDIVIDUAL NOTIFICATION

Affected individuals will be informed where required by law.

Part 109 — DATA-SUBJECT RIGHTS

Depending on applicable law, individuals may have rights to:

  • information;
  • access;
  • correction;
  • deletion;
  • restriction;
  • portability;
  • objection;
  • consent withdrawal;
  • human review of certain automated decisions;
  • and regulatory complaint.

Part 110 — ACCESS

An individual may request access to Personal Data Hawi controls about them.

Part 111 — RECTIFICATION

An individual may request correction of inaccurate Personal Data.

Part 112 — ERASURE

An individual may request deletion where the applicable legal requirements are satisfied.

The right to erasure is not absolute.

Part 113 — RESTRICTION

An individual may request restriction of processing in applicable circumstances.

Part 114 — PORTABILITY

Applicable Personal Data may be provided in a structured, commonly used, machine-readable format where the statutory requirements apply.

Part 115 — OBJECTION

Individuals may object to qualifying processing based on legitimate interests.

Part 116 — MARKETING OBJECTION

Individuals may object to direct marketing at any time.

Consent may be withdrawn.

Withdrawal does not invalidate processing that was lawful before withdrawal.

Part 118 — AUTOMATED DECISION RIGHTS

Where applicable automated decision provisions apply, an individual may be entitled to safeguards including human review and challenge mechanisms.

Part 119 — REQUEST SUBMISSION

Privacy requests may be submitted to:

help@hawiagents.com

or, until a dedicated privacy mailbox is operational:

help@hawiagents.com

Part 120 — IDENTITY VERIFICATION

Hawi may verify identity before:

  • providing a data export;
  • changing Personal Data;
  • deleting an Account;
  • or responding to another privacy request.

Part 121 — THIRD-PARTY RIGHTS

Where disclosing information would reveal another person's Personal Data, Hawi may redact or restrict disclosure as permitted by law.

Part 122 — PROCESSOR REQUESTS

Where Hawi is processor, Hawi may forward a Data Subject's request to the relevant Customer/controller.

Part 123 — ORGANISATIONAL ACCOUNTS

An organisation controlling an Account may retain legitimate business records after an individual user leaves the organisation.

Part 124 — ADMINISTRATOR VISIBILITY

Administrators may be able to access:

  • Workspace activity;
  • members;
  • files;
  • Agent information;
  • usage;
  • Connected Services;
  • approvals;
  • and other organisational resources

where their role permits it.

Part 125 — EMPLOYEE MONITORING

Customers must not use Hawi for unlawful employee surveillance.

Where employee monitoring occurs, Customers are responsible for meeting applicable legal requirements.

Part 126 — DATA PROTECTION IMPACT ASSESSMENTS

Hawi or Customers should carry out a DPIA where processing is likely to result in high risk to individuals.

Relevant circumstances may include:

  • large-scale sensitive data;
  • systematic monitoring;
  • high-impact automated decisions;
  • vulnerable people;
  • novel technology;
  • or extensive profiling.

Part 127 — RECORDS OF PROCESSING

Hawi maintains or should maintain applicable Article 30 records of processing.

Part 128 — PRIVACY BY DESIGN

Hawi aims to incorporate data protection into system design.

This may include:

  • least privilege;
  • Account-scoped secrets;
  • Workspace assignment;
  • explicit approval;
  • retention schedules;
  • immutable consent records;
  • audit trails;
  • and privacy-request tooling.

Part 129 — NOTICE VERSIONING

Hawi should assign a version identifier to:

  • this Privacy Policy;
  • cookie notices;
  • consent statements;
  • automatic purchasing notices;
  • wellness consent;
  • voice disclosures;
  • financial-data disclosures;
  • and other material privacy notices.

Part 130 — PROOF THAT NOTICE WAS PROVIDED

Where reasonably appropriate, Hawi may maintain evidence that a notice was presented.

Such evidence may include:

  • user identifier;
  • Account identifier;
  • notice identifier;
  • notice version;
  • timestamp;
  • presentation method;
  • language;
  • relevant screen or workflow;
  • acknowledgement;
  • and withdrawal where applicable.

Part 131 — POLICY ACCEPTANCE RECORDS

Where Hawi requires acknowledgement of this Policy or associated Terms, Hawi may retain:

  • policy version;
  • timestamp;
  • user;
  • Account;
  • action confirming acknowledgement;
  • and related technical evidence.

Acknowledgement of a Policy should not be mischaracterised as consent to processing where consent is legally required.

Where consent is the lawful basis, Hawi should preserve evidence showing:

  1. who gave consent;
  2. when it was given;
  3. what wording was displayed;
  4. which notice version was displayed;
  5. what categories of processing were covered;
  6. how the person actively opted in;
  7. whether the choice was optional;
  8. any later change;
  9. any withdrawal;
  10. when withdrawal became effective.

Consent-dependent processing should not rely on pre-selected checkboxes where applicable privacy law requires affirmative consent.

Separate processing purposes should use separate consent choices where legally required.

For example, Hawi should not combine:

“I accept the Terms”

with:

“I consent to health-data processing and marketing.”

Those are different decisions.

Part 135 — FEATURE-SPECIFIC NOTICES

Hawi should show prominent additional notices before users enable high-impact functionality.

Examples include:

Connecting an email account

Important: Authorised Hawi Agents in the Workspaces you select may read email content and, where you grant permission, send, reply to, modify or otherwise interact with messages through this account.

Voice transcription

Important: Hawi may convert the audio from this call into a text transcript and use the transcript to perform authorised Agent tasks.

Automatic purchasing

Important: Enabling automatic purchasing allows authorised Hawi Agents to complete purchases without asking you to approve every individual transaction, subject to the limits and controls you set.

Bank connection

Important: Connecting a financial account allows Hawi to receive the financial information described on this screen from the selected provider.

Wellness processing

Explicit consent required: This feature may process health or wellness information and may use AI or Agent analysis as described below.

Part 136 — CHANGES IN PROCESSING

If Hawi proposes materially new use of existing Personal Data, Hawi should assess whether:

  • the new purpose is compatible;
  • a revised notice is required;
  • additional consent is required;
  • a DPIA is required;
  • or another lawful basis is necessary.

Part 137 — MATERIAL POLICY CHANGES

Material changes may be communicated through:

  • in-app notice;
  • email;
  • Account banner;
  • Workspace notice;
  • or another appropriate mechanism.

Simply changing text on an unnoticed webpage may not be sufficient for every material new use.

Part 138 — HISTORICAL POLICIES

Hawi may preserve historical versions of its Privacy Policy so Hawi can determine which version applied at a particular time.

Part 139 — CONTACTING PEOPLE WHOSE INFORMATION CAME FROM CUSTOMERS

Where Hawi acts as controller and receives information indirectly, Hawi will provide required privacy information within applicable statutory timelines unless an exemption applies.

Where Hawi acts as processor, the Customer is ordinarily responsible.

Part 140 — NO SECRET EXPANSION OF PERMISSIONS

Hawi should not treat a connection permission granted for one clearly described purpose as unrestricted permission for materially unrelated purposes.

Part 141 — USER REVOCATION OF INTEGRATIONS

Customers may disconnect Connected Services.

Disconnecting a service generally prevents future access using that connection.

It does not necessarily automatically erase:

  • previously imported records;
  • audit logs;
  • billing records;
  • or information that must otherwise be retained.

Part 142 — DELETION AFTER DISCONNECTION

Customers may separately need to delete previously processed Customer Content if they want it removed from Hawi.

Part 143 — DATA EXPORT

Where supported, Customers may export certain information before deleting an Account or Workspace.

Part 144 — ACCOUNT DELETION

Deletion of an Account may:

  • disable Agents;
  • terminate sessions;
  • revoke integrations;
  • remove members;
  • schedule eligible Customer Content for deletion;
  • and prevent future access.

Part 145 — BUSINESS RECORDS AFTER ACCOUNT CLOSURE

Hawi may retain information after Account closure where reasonably required for:

  • accounting;
  • tax;
  • fraud prevention;
  • disputes;
  • legal claims;
  • security;
  • and statutory compliance.

Part 146 — CUSTOMER'S OWN PRIVACY NOTICE

Business Customers should maintain their own privacy notices.

A Customer should not rely solely on Hawi's Privacy Policy to satisfy the Customer's transparency duties concerning its own:

  • customers;
  • employees;
  • suppliers;
  • callers;
  • website visitors;
  • or other Data Subjects.

Part 147 — CUSTOMER INSTRUCTIONS TO AGENTS

A Customer is responsible for ensuring that instructions given to an Agent do not cause unlawful processing.

Part 148 — CUSTOMER DATA QUALITY

Customers are responsible for Personal Data they provide or make available to Hawi.

Hawi cannot independently verify the accuracy or legality of every item of Customer Content.

Part 149 — AGENT-GENERATED COMMUNICATIONS

Where an Agent sends a communication on behalf of a Customer, the Customer remains responsible for ensuring the communication complies with applicable:

  • marketing law;
  • consumer law;
  • employment law;
  • confidentiality duties;
  • professional duties;
  • and industry regulations.

Part 150 — HUMAN REVIEW OF EXTERNAL COMMUNICATIONS

Customers may configure human review before certain communications are sent.

Where the Customer disables such review, authorised Agents may send communications automatically within the permissions provided.

Part 151 — AGENT ACTION AUDITABILITY

Where technically appropriate, Hawi may record:

  • what Agent requested an action;
  • which Workspace it operated from;
  • the operation;
  • provider;
  • approval;
  • timestamp;
  • request status;
  • external identifier;
  • and outcome.

Part 152 — DUPLICATE ACTION PREVENTION

Hawi may process identifiers and execution records to prevent an Agent retry from accidentally repeating an external action.

Part 153 — RATE LIMITING AND QUEUING

When a provider or Hawi reaches an operational rate limit, Agent work may:

  • pause;
  • queue;
  • retry;
  • fail;
  • or resume later.

Hawi may retain execution state necessary to support this process.

Part 154 — AGENT LOOP PREVENTION

Hawi may analyse Agent activity to identify accidental loops or unreasonable repeated execution.

Hawi may stop or restrict an Agent to protect:

  • Customer credits;
  • external systems;
  • infrastructure;
  • and security.

Part 155 — USAGE METERING

Hawi may measure:

  • model usage;
  • tool usage;
  • voice duration;
  • storage;
  • infrastructure activity;
  • and other billable or limited resources.

Part 156 — PROVIDER PRICING

Provider costs may change over time.

Hawi may maintain versioned pricing information to calculate credits or service usage.

Part 157 — NOTIFICATION SYSTEMS

Customers may configure notifications through supported channels.

Depending on the integration, notifications may contain Personal Data required to explain:

  • a purchase;
  • exceeded limit;
  • failed Agent task;
  • approval request;
  • security event;
  • or other operational event.

Part 158 — DATA SENT THROUGH NOTIFICATION CONNECTORS

If a Customer chooses to send Hawi notifications through a third-party connector, the notification information will be transmitted to that third party.

The Customer controls which supported notification destination it chooses.

Part 159 — BUSINESS CONTINUITY

Hawi may copy data into backups, replicas, queues or temporary processing systems as reasonably necessary for:

  • reliability;
  • disaster recovery;
  • redundancy;
  • and task execution.

Such copies remain subject to appropriate safeguards.

Part 160 — SERVICE PROVIDER ACCESS

A service provider may technically have access to Personal Data where required to operate its service.

Hawi should use contractual and technical controls appropriate to the provider's role.

Part 161 — CORPORATE TRANSACTIONS

If Hawi participates in:

  • acquisition;
  • merger;
  • restructuring;
  • investment;
  • financing;
  • insolvency;
  • or asset sale,

Personal Data may be disclosed where reasonably necessary for the transaction.

Hawi may disclose Personal Data where required by valid:

  • subpoena;
  • warrant;
  • court order;
  • regulator request;
  • or other legal process.

Where reasonably possible, Hawi may review requests for:

  • legal validity;
  • jurisdiction;
  • scope;
  • proportionality;
  • and required disclosure.

Part 164 — EMERGENCIES

Where legally permitted, information may be disclosed where Hawi reasonably believes disclosure is necessary to address imminent risk of death or serious physical harm.

Part 165 — GOVERNMENT ACCESS

No private cloud provider can promise that government authorities will never seek Customer information.

Hawi will respond to government requests only in accordance with applicable law and Hawi's legal obligations.

Part 166 — DPO

If Hawi becomes legally required to appoint a Data Protection Officer, Hawi will publish the DPO's contact information.

DPO: none appointed

Part 167 — UK REPRESENTATIVE

If legally required:

UK Representative: none appointed

Part 168 — EU REPRESENTATIVE

If legally required:

EU Representative: none appointed

Part 169 — ICO COMPLAINTS

Individuals subject to UK GDPR may lodge a complaint with the Information Commissioner's Office.

A person does not need Hawi's permission before contacting the ICO.

Part 170 — EEA COMPLAINTS

Individuals subject to EU GDPR may have the right to complain to an applicable European supervisory authority.

Part 171 — NO RETALIATION FOR PRIVACY REQUESTS

Hawi will not treat the lawful exercise of a statutory privacy right as a contractual violation.

Part 172 — DISPUTES

Hawi encourages a person to contact Hawi so that the parties can attempt to resolve a contractual dispute.

Part 173 — 30-DAY INFORMAL PROCESS

For contractual disputes not involving urgent relief, Hawi and the other party should generally attempt informal resolution for approximately 30 days.

This does not suspend a statutory GDPR deadline.

Part 174 — BUSINESS ARBITRATION NOTICE

IMPORTANT: THE FOLLOWING PROVISIONS CONTAIN A BINDING ARBITRATION AGREEMENT FOR CERTAIN BUSINESS USERS.

Part 175 — BUSINESS USER

For these arbitration provisions, a Business User is a person or organisation using Hawi wholly or mainly for purposes associated with a trade, profession, craft or business.

Part 176 — AGREEMENT TO ARBITRATE

To the extent legally enforceable, contractual disputes between Hawi and a Business User concerning:

  • this Policy;
  • Hawi's contractual privacy obligations;
  • interpretation;
  • formation;
  • validity;
  • performance;
  • breach;
  • or termination

that remain unresolved after the informal procedure shall be finally determined by arbitration.

Part 177 — LCIA

Unless otherwise agreed in writing, arbitration shall be conducted in accordance with the Rules of the London Court of International Arbitration (LCIA).

Part 178 — ARBITRATOR

The tribunal shall consist of one arbitrator unless applicable rules or mandatory law provide otherwise.

Part 179 — SEAT

The legal seat of arbitration shall be:

London, England.

Part 180 — LANGUAGE

The language shall be English.

Part 181 — ARBITRATION AGREEMENT LAW

Subject to mandatory law, the arbitration agreement shall be governed by the law of England and Wales.

Part 182 — CONSUMERS

The mandatory Business User arbitration provision is not intended to deprive consumers of mandatory court or statutory rights.

A consumer will not be compelled to arbitrate where doing so would be unlawful or unenforceable.

Part 183 — PRIVACY RIGHTS EXCLUDED FROM MANDATORY ARBITRATION

Nothing requires an individual to complete contractual arbitration before:

  • submitting a Subject Access Request;
  • requesting deletion;
  • withdrawing consent;
  • objecting to processing;
  • requesting restriction;
  • contacting the ICO;
  • contacting another competent authority;
  • cooperating with regulators;
  • or exercising another non-waivable privacy right.

Part 184 — EMERGENCY RELIEF

Nothing prevents either party from seeking legally available emergency or interim court relief.

Part 185 — MANDATORY LAW PREVAILS

Where any arbitration or contractual provision conflicts with non-waivable law, the non-waivable law prevails.

Part 186 — TERMS OF SERVICE ALIGNMENT

These dispute provisions must be aligned with Hawi's Terms of Service.

Hawi should not publish contradictory:

  • governing law;
  • arbitration rules;
  • venue;
  • consumer rights;
  • or dispute provisions

across different legal documents.

Part 187 — NO WAIVER OF DATA-PROTECTION RIGHTS

Nothing in this Policy waives rights granted under applicable privacy law.

Part 188 — LIMITATIONS OF THIS POLICY

This Policy explains Hawi's practices and legal position.

It does not:

  • make otherwise unlawful processing lawful;
  • replace Customer privacy notices;
  • replace mandatory consent;
  • eliminate statutory remedies;
  • guarantee absolute cybersecurity;
  • or remove regulator powers.

Part 189 — CHANGES TO THE SERVICE

As Hawi develops, new functionality may involve new Personal Data.

Where material new processing is introduced, Hawi should:

  1. assess the lawful basis;
  2. assess risk;
  3. update relevant processing records;
  4. conduct a DPIA where required;
  5. update this Policy where appropriate;
  6. issue a feature-specific notice where appropriate;
  7. seek consent where required;
  8. maintain evidence of the applicable notice.

Part 190 — CHANGE NOTIFICATION

Material privacy changes may be communicated through:

  • email;
  • an Account notice;
  • a blocking acknowledgement screen;
  • a Workspace notice;
  • or another prominent method.

Part 191 — CONTINUED USE

Where consent is not legally required, continued use after a properly notified contractual update may have contractual consequences under the applicable Terms.

However:

Continued use must not be treated as substitute consent where privacy law requires affirmative consent.

Part 192 — LANGUAGE AND ACCESSIBILITY

Privacy information should be provided in a clear and accessible form.

Where Hawi provides translated versions, Hawi should seek to ensure translations accurately reflect the English version.

Part 193 — PRIVACY DASHBOARD

Where practical, Hawi should provide users or administrators with privacy controls allowing them to review:

  • Account information;
  • Connected Services;
  • consent;
  • integrations;
  • privacy settings;
  • analytics preferences;
  • and deletion options.

Part 194 — SUBPROCESSOR UPDATES

Where required contractually, Hawi may notify Customers before adding or replacing material subprocessors.

Part 195 — CUSTOMER OBJECTIONS TO SUBPROCESSORS

Enterprise DPA terms may define procedures for Customers to raise legitimate data-protection objections to a new subprocessor.

Part 196 — TRANSFER SAFEGUARDS INFORMATION

Customers may contact Hawi for information concerning applicable international-transfer safeguards, subject to reasonable confidentiality limitations.

Part 197 — DATA LOCATION DOES NOT EQUAL EXCLUSIVE PROCESSING LOCATION

A database being hosted in London does not mean Personal Data can never be processed outside London.

For example:

  • an AI provider;
  • Connected Service;
  • communications provider;
  • administrator;
  • Customer;
  • or support provider

may process data elsewhere.

Part 198 — CUSTOMER SELECTION OF THIRD-PARTY SERVICES

Where the Customer chooses to connect a third-party service, the Customer is directing Hawi to exchange necessary information with that service.

Part 199 — THIRD-PARTY PRIVACY POLICIES

Third-party providers may independently determine some of their processing and maintain their own privacy policies.

Hawi's Policy does not replace those third-party policies.

Hawi may contain links to external websites.

Hawi is not responsible for an unrelated website's independent privacy practices merely because Hawi links to it.

Part 201 — NO SALE TO DATA BROKERS

Hawi does not intend to sell private Customer Content to data brokers for unrelated commercial profiling.

Part 202 — NO UNRELATED ADVERTISING PROFILING OF PRIVATE WORKSPACE CONTENT

Hawi does not intend to use private:

  • emails;
  • files;
  • prompts;
  • call transcripts;
  • or business records

to create third-party advertising profiles unrelated to the Hawi Services.

Part 203 — ANONYMISED INFORMATION

Hawi may use properly anonymised information for:

  • analytics;
  • statistical analysis;
  • security;
  • reliability;
  • product development;
  • and business planning.

Information that has been truly anonymised so that an individual is no longer identifiable is generally no longer Personal Data.

Part 204 — AGGREGATED INFORMATION

Hawi may aggregate information across multiple users where reasonable safeguards prevent the aggregate output from identifying an individual.

Part 205 — PSEUDONYMISED INFORMATION

Pseudonymised information remains Personal Data where Hawi or another party can reconnect it to an individual.

Hawi will therefore continue treating applicable pseudonymised information as protected Personal Data.

Part 206 — DATA CORRECTION

Customers should maintain accurate source information.

If an Agent operates on inaccurate Connected Service data, the Agent's output may also be inaccurate.

Part 207 — AGENT INFERENCES

Agents may infer information from existing data.

An inference may be incorrect.

Customers should review material inferences before relying on them for significant decisions.

Part 208 — PRIVACY REQUEST LOGGING

Hawi may log privacy requests to demonstrate compliance.

The log may include:

  • request type;
  • requester;
  • date;
  • verification;
  • deadline;
  • action taken;
  • exceptions;
  • response date;
  • and completion evidence.

Part 209 — REQUEST DEADLINES

Where UK or EU GDPR applies, Hawi will respond to applicable requests within statutory deadlines, subject to permitted extensions.

Some information may be withheld, restricted or retained where an applicable legal exemption permits or requires it.

Part 211 — SECURITY AND PRIVACY REPORTING

Suspected security issues should be reported through Hawi's designated security contact.

Suspected privacy concerns should be reported through Hawi's privacy contact.

Part 212 — POLICY REVIEW

Hawi should review this Policy periodically and whenever Hawi materially changes its data-processing activities.

For material privacy acknowledgements, Hawi should retain an evidential record containing, as appropriate:

  • immutable event ID;
  • user ID;
  • Account ID;
  • Workspace ID where applicable;
  • relevant feature;
  • privacy notice identifier;
  • privacy notice version;
  • notice publication date;
  • exact consent or acknowledgement wording;
  • timestamp;
  • server-side timestamp;
  • language;
  • method of presentation;
  • action taken;
  • whether an optional box was selected;
  • source application;
  • withdrawal timestamp;
  • later replacement consent;
  • and cryptographic integrity information where appropriate.

This record should allow Hawi to determine what the user was actually told at the relevant time, rather than linking only to whatever version of the Privacy Policy happens to be live later.

Schedule 2 — HIGH-IMPACT FEATURE NOTICE REQUIREMENTS

Before enabling the following functionality, Hawi should consider presenting a dedicated notice:

FeatureDedicated notice
Email connectionWhat Agents may read/write/send
CalendarEvents/attendees Agent may access
CRMCustomer/contact data processing
VoiceAI Agent interaction
RecordingRecording disclosure
TranscriptionAudio-to-text processing
Automatic purchasingFinancial autonomy and limits
Auto rechargePayment trigger and caps
Banking connectionFinancial data accessed
WellnessSpecial Category Data + explicit consent
Marketplace publishingInformation becomes public
AnalyticsCookie/analytics choice
High-impact automationAutomated decision implications
Agent memoryInformation retained across sessions

Schedule 3 — CONNECTED SERVICE DISCLOSURE

Before a user enables a Connected Service, Hawi should clearly display:

  1. the provider being connected;
  2. the Account that will own the connection;
  3. the Workspaces receiving access;
  4. the Agents that may access it where applicable;
  5. requested scopes;
  6. whether access is read-only or includes writes;
  7. potentially consequential actions;
  8. how to revoke the connection;
  9. what previously retrieved information may remain;
  10. link to this Privacy Policy.

Schedule 4 — AUTOMATIC PURCHASING NOTICE

Before automatic purchasing is enabled, Hawi should make clear:

YOU ARE ENABLING FINANCIAL ACTIONS.

By enabling this feature, you authorise eligible Hawi Agents, within the limits you configure and subject to Hawi's applicable controls, to complete eligible purchases without requesting your approval for every individual purchase.

The user should be shown:

  • payment source;
  • per-transaction maximum;
  • daily/monthly maximum where available;
  • authorised Agents;
  • authorised Workspaces;
  • categories/merchants where applicable;
  • notification destination;
  • how to disable the feature;
  • and applicable refund limitations.

The acknowledgement should be stored separately from ordinary Terms acceptance.

Schedule 5 — VOICE NOTICE

Where appropriate, callers should receive a disclosure substantially similar to:

You are interacting with an automated Hawi Agent. This call may be processed and transcribed to handle your request and perform authorised follow-up actions. Please do not provide information that is unnecessary for your request.

Where recording occurs, the recording disclosure should be added where legally required.

The Customer remains responsible for adapting disclosure wording to applicable local law.

Schedule 6 — AGENT MEMORY NOTICE

Before memory is enabled where appropriate:

Hawi may retain selected information from your interactions so this Agent can use it in later sessions. This may include preferences, prior tasks, business information and other relevant context. You can manage or delete memory where the applicable controls are available.

A wellness consent should be separate and could state:

I explicitly consent to Hawi processing the wellness or health information described above for the stated purpose, including Agent/model analysis where indicated. I understand that I can withdraw this consent through the applicable settings or by contacting Hawi.

A checkbox should not be pre-selected.

Where consent is required, the user should receive at least:

  • Accept optional analytics
  • Reject optional analytics
  • Manage preferences

Rejecting optional analytics should be as reasonably accessible as accepting.

Hawi should distinguish:

Acknowledgement

“I acknowledge that I have received and can access the Privacy Policy.”

from:

Consent

“I consent to this specific optional processing.”

Acknowledging a privacy notice does not automatically establish a valid consent lawful basis.

Schedule 10 — RETENTION MATRIX

InformationExample purposeIndicative retention
OAuth stateConnection security~1 hour
Verification challengeVerification~24h
Security challengeSecurity~24h
Rate-limit stateAbuse prevention~7 days
API/security eventSecurity~30 days
Webhook deliveryTroubleshooting~30 days
Connector executionAudit/support~90 days
Wellness measurementOptional feature~180 days
Voice transcriptCall history~365 days
Voice noteVoice functionality~365 days
Failed/top-up eventFinancial dispute~2 years
Consent evidenceAccountabilityAppropriate compliance period
Accounting recordsLegal/taxStatutory period
Legal holdLegal preservationUntil release

Schedule 11 — GDPR RIGHTS CHECKLIST

Where applicable, Hawi must be prepared to support:

  • right to information;
  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction;
  • right to portability;
  • right to object;
  • right to withdraw consent;
  • automated decision safeguards;
  • right to complain;
  • and applicable judicial remedies.

Schedule 12 — DATA-PROTECTION PRINCIPLES

Hawi seeks to apply:

Lawfulness

There must be an appropriate legal basis.

Fairness

Processing should not unjustifiably surprise or harm people.

Transparency

Important processing should be explained openly.

Purpose limitation

Personal Data should not silently be reused for materially incompatible purposes.

Data minimisation

Only necessary information should be processed.

Accuracy

Reasonable efforts should be made to maintain accurate information.

Storage limitation

Personal Data should not be retained indefinitely without justification.

Integrity and confidentiality

Reasonable security safeguards should apply.

Accountability

Hawi should be able to demonstrate compliance.

This Privacy Policy should operate alongside:

  1. Terms of Service
  2. Data Processing Agreement
  3. Cookie Notice
  4. Subprocessor List
  5. Acceptable Use Policy
  6. Marketplace Terms
  7. Creator/Seller Terms
  8. Voice/Call Processing Notice
  9. Automatic Purchasing Terms
  10. Financial Connections Notice
  11. Wellness Explicit Consent Notice
  12. Security Policy or Security Overview
  13. Data Retention Schedule
  14. Data Subject Request Procedure
  15. Data Breach Response Procedure
  16. International Transfer documentation
  17. Business Customer privacy guidance
  18. AI/Automated Agent Transparency Notice

Schedule 14 — INFORMATION THAT MUST BE VERIFIED BEFORE PUBLICATION

Hawi should not invent or inaccurately state the following.

Before publication verify:

  1. exact Hawi legal entity;
  2. registration number;
  3. registered address;
  4. incorporation jurisdiction;
  5. privacy email;
  6. security email;
  7. DPO requirement;
  8. UK representative requirement;
  9. EU representative requirement;
  10. final Terms governing law;
  11. final arbitration law;
  12. final arbitration seat;
  13. model providers actually used;
  14. voice providers actually used;
  15. speech providers actually used;
  16. payment providers actually used;
  17. financial-data providers actually used;
  18. analytics providers actually enabled;
  19. storage locations;
  20. actual subprocessor locations;
  21. international transfer mechanisms;
  22. retention periods;
  23. recording functionality;
  24. training arrangements with model providers;
  25. production cookie configuration;
  26. Data Processing Agreement;
  27. live deletion process;
  28. privacy-right request process;
  29. breach process;
  30. production security measures.

Schedule 15 — IMPORTANT CUSTOMER ACKNOWLEDGEMENTS

Subject to applicable law and without waiving non-waivable statutory rights, Hawi Customers should understand that:

  1. Hawi is an Agent platform capable of processing Customer Content.
  2. Agents may take actions in external systems where authorised.
  3. Connecting a service makes information available for authorised processing according to the scopes and controls selected.
  4. An Agent may transmit information to third-party providers necessary to perform the requested task.
  5. Model-generated output may contain errors.
  6. The Customer remains responsible for deciding when human review is necessary.
  7. The Customer remains responsible for establishing the lawful basis for Personal Data it instructs Hawi to process.
  8. The Customer remains responsible for notices owed to its own employees, customers, callers and other individuals.
  9. The Customer remains responsible for call-recording and marketing-law compliance for Customer-directed communications.
  10. Financial Agent functionality requires separate configuration and does not arise merely from creating an Agent.
  11. Connected Service credentials may be used by Hawi's backend to perform authorised actions.
  12. Account administrators may have visibility over organisational activity.
  13. Disconnecting a Connected Service does not necessarily delete information previously processed.
  14. Account deletion does not necessarily delete records Hawi is legally required to retain.
  15. Some service providers may process information outside the Customer's jurisdiction.
  16. Hawi cannot guarantee complete security or that an Agent will never make an error.
  17. Customer Content may include third-party Personal Data, and the Customer must have lawful authority to process it.
  18. Data processed under Customer instructions may be subject to the Customer's own privacy notice in addition to Hawi's Policy.

Final transparency statement

Hawi is built to allow software Agents to carry out real operational work.

That means the Services are not limited to producing text inside a chat window.

Depending on the Customer's configuration, a Hawi Agent may interact with external systems and people, retrieve information, create or modify records, communicate through Connected Services, handle calls, process files, coordinate work and perform other authorised operations.

Hawi therefore seeks to provide Customers with controls over:

  • which Agents exist;
  • which Workspaces they belong to;
  • what integrations they may access;
  • which external actions they may perform;
  • which financial actions are allowed;
  • where human approval is required;
  • how usage is limited;
  • how actions are recorded;
  • and how Connected Services can be revoked.

The existence of technical capability does not itself create lawful authority to use Personal Data.

A Customer must ensure that its use of Hawi complies with applicable law.

Hawi must ensure that Hawi's own processing complies with applicable law.

Neither Hawi nor a Customer may use this Privacy Policy to override statutory privacy rights.

Where Hawi introduces materially new processing, Hawi should provide new or updated privacy information before that new processing begins where required.

Where consent is legally required, Hawi should obtain separate, affirmative consent rather than relying merely on continued use of the Service.

Where a material acknowledgement or consent is obtained, Hawi should maintain sufficient evidence to show:

  • what was presented;
  • when it was presented;
  • which version was shown;
  • who responded;
  • what action the person took;
  • and whether that decision was later withdrawn.

The purpose of these records is not to take away user rights.

Their purpose is to create a reliable, auditable record demonstrating what information Hawi actually provided and what choices the user actually made.

Contact

Hawi Inc.

Trading as Hawi Agents

Website: HawiAgents.com

General: help@hawiagents.com

Privacy: help@hawiagents.com

Security: help@hawiagents.com

© 2026 Hawi Inc. All rights reserved.