Privacy Policy

1. Two different roles, and why it matters to you

Hyphen provides customer support software. We handle personal data in two distinct capacities, and your rights differ depending on which applies:
  • As a processor. When our customer — a business using Hyphen to run their support desk — stores case data, messages, end-user records and call transcripts in Hyphen, that business is the controller. They decide what is collected and why. We process it on their documented instructions.
  • As a controller. For our own customers' account, billing, authentication and usage data, we are the controller.
If you are an end user who contacted a business through Hyphen, that business is the controller of your data, not us. We will help them respond to your request, but we cannot act on it directly without their instruction — and directing you to them is a legal requirement, not an evasion. Their privacy policy governs.

2. What we process

As processor, on behalf of our customers: support cases and their message bodies, end-user names and email addresses, company and account records, attachments, video call audio and transcripts, and AI-derived material such as case summaries and sentiment labels.

As controller, for our own account: the names, email addresses and authentication credentials of users at our customer organisations; workspace configuration; billing details; and product usage and diagnostic data.

Payment card numbers are removed on arrival. We have no payment integration and never intentionally process cardholder data. Because people sometimes paste a card number into a support message regardless, a database trigger detects and strips card numbers before the message is stored, keeping only the last four digits. They are never retained and never reach an AI vendor.

We run no analytics or tracking of any kind. No Google Analytics, Tag Manager, PostHog, Segment, Mixpanel, Hotjar or Intercom. No advertising services. No session recording. No third-party CDN.

3. Subprocessors

The complete list. We will give 30 days' written notice before adding or replacing any subprocessor that processes customer data, with an opportunity to object.
Active for every workspace
Subprocessor
Purpose
What it receives
Supabase
Database, authentication, file storage, background processing
All cases, messages, end-user records, attachments and transcripts
Vercel
Application hosting and compute
All application traffic transits Vercel
Sentry
Error monitoring
Error diagnostics only. Email addresses are redacted to the domain (***@acme.com) and case subjects are not sent
Active only when relevant feature is used
Subprocessor
Triggered by
What it receives
Anthropic
AI features, unless disabled
Case subject and description, message bodies, company name and industry, attachment filenames, knowledge-base article text. Not end-user names or email addresses
Open AI
An audio or video attachment is uploaded
The raw media file, for speech-to-text
Postmark
Email-channel cases
Inbound: the complete customer email. Outbound: recipient address, reply body, subject, threading headers
Resend
Notification and invitation email
Recipient address, end-user name, workspace name, case number and subject, and the first 150 characters of a support reply
Daily.co
A video call is started
Live audio, video, in-call chat, screen shares and live transcription. Nothing is retained on Daily's infrastructure — cloud recording and transcript storage are both disabled
Slack
An email fails to deliver
Hyphen's own operational alerting, not customer content. The recipient's domain and an error status only — addresses are redacted and subjects are never sent
Active only when a customer connects them
Subprocessor
Condition
What it receives
Attio
The customer connects the CRM integration
End-user email address and company name or domain, as lookup keys. No case content
Zendesk
The customer runs a historical import
Outbound queries against the customer's own Zendesk account, using credentials they supply. Credentials are encrypted at rest and destroyed on a timer
From the end user's browser
Third Party
Where
What it receives
Google Fonts
The embedded support widget loads webfonts
IP address, User-Agent and Referer. No case content

4. Artificial Intelligence

We would rather be specific here than reassuring, because "we use AI responsibly" tells you nothing.

What the AI can and cannot do. No AI feature sends a message to your customers, and no AI feature can take an action in the product. This is enforced by architecture rather than policy: no AI call site is configured with tool use, and every AI-generated value is written to a fixed field chosen by our code, not by the model. The model returns text; our code decides what happens to it.

Two exceptions we would rather state than have found. An AI-generated case subject and a sentiment label are written without human review, and the subject is visible to the end user. They are short labels rather than replies, but they are unreviewed model output.

What the vendors may do with it. Anthropic's and OpenAI's commercial API terms provide that customer inputs and outputs are not used to train their models, and both delete API data on a short retention window. This is their default for commercial API use, not something we had to negotiate.

Turning it off. Any customer can disable AI processing entirely from their workspace settings, and the switch is enforced in every part of the system that would otherwise call a model. A customer may also supply their own Anthropic API key, so that processing runs under their own vendor account and terms.

What we do not send. End-user names and email addresses are not placed in any AI prompt. Message bodies are sent as written, so if a person types their own contact details into a message, that text reaches the model as part of the message.

5. Where your data is

The United States. Our database, file storage and authentication run in Supabase's West US (Oregon) region. Application compute runs on Vercel in the United States. There is a single production environment; we do not operate regional deployments.

For personal data originating in the EEA or UK, this is a transfer to a third country. Our lawful basis is the Standard Contractual Clauses, incorporated into our data processing agreement. We are not self-certified under the EU-US Data Privacy Framework and do not rely on it.

6. How long we keep it

Stated plainly: we do not yet delete data automatically. Customer data is retained for the life of the workspace and deleted on request. We would rather say that than imply a schedule we do not yet enforce.We have specified and internally approved a tiered retention schedule, and are implementing it:
Data
Retained Until
Call recordings and media
90 days after case closure
Call transcripts
90 days after case closure
AI-derived content (summaries, insights, assistant conversations)
24 months after case closure
Case message bodies
24 months after case closure
Case metadata
12 months after case closure
Audit logs — including the record of our own staff accessing a customer workspace — are deliberately exempt, because a deletion schedule that erases the evidence of who accessed what would defeat the purpose of keeping it.

We will give customers 30 days' notice before this schedule first deletes anything.

7. Security

  • Encryption in transit and at rest.
  • Row-level security enforced in the database on every one of our 74 tables, so isolation between customers is enforced by the database rather than by application code remembering to filter.
  • Multi-factor authentication for Hyphen staff, with a recorded audit trail of any staff access to a customer workspace, including who and when.
  • Automated dependency vulnerability scanning, with advisories raised as code changes.
  • All code changes reviewed before merge, with automated type checking, linting and tests.
  • Standard response-header hardening: HSTS, MIME-type sniffing disabled, a strict referrer policy, and framing denied.
We do not describe ourselves as certified. A SOC 2 Type 2 engagement is underway; until a report exists, we will not claim compliance. We would rather you judge the controls above on their specifics.

8. Your rights under GDPR and UK GDPR

Where we are the controller, you may request access, rectification, erasure, restriction of processing, portability, or object to processing. Contact privacy@hyphen.support and we will respond within 30 days.

Where we are the processor — which covers most end-user data in Hyphen — please contact the business you dealt with. We support them in responding, and our erasure covers AI-derived material as well as original messages.

You may lodge a complaint with your supervisory authority at any time.

9. California privacy rights (CCPA/CPRA)

California residents may request that we disclose the categories and specific pieces of personal information collected, request deletion, request correction, and opt out of sale or sharing.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have. We run no advertising or tracking services of any kind (see §2).

We will not discriminate against you for exercising these rights. Requests go to privacy@hyphen.support; where Hyphen acts as a service provider to a business customer, we will direct your request to them.

10. Children

Hyphen is business software and is not directed at children. We do not knowingly collect personal information from anyone under 16.

11. Changes

We will post any material change here and update the effective date. Where a change materially affects how we process customer data, we will notify customers directly.

12. Contact

Hyphen Customer Systems, LLC

Privacy: privacy@hyphen.support