Legal

Version 2026-08-21-v1 · Last updated August 21, 2026

Privacy Policy

High iQ ("Company," "we," "us," or "our") provides an AI-powered sales, communication, and customer-relationship platform (the "Platform"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you.

This policy applies to our websites, the Platform, and related services. It does not apply to third-party services you connect to the Platform, which are governed by their own privacy policies.

1. Two Roles: Our Customers and Their Contacts

We handle two different categories of personal information, and the distinction matters.

Business customer data. When a business signs up for the Platform, we collect and control information about that business and its users, such as names, business email addresses, phone numbers, billing details, and account activity. For this information, we act as the business responsible for it.

Contact and lead data. Our customers upload, import, and generate information about their own leads, clients, and contacts. For that information, our customer is the party that decides why and how the data is used, and we process it only to provide the Platform on that customer's instructions. If you are a consumer who was contacted by a business using High iQ and you want your information corrected or deleted, contact that business directly. You may also contact us at legal@highiq.io and we will route your request to the responsible customer and assist as required by law.

2. Information We Collect

Account and profile information. Name, business name, email address, phone number, time zone, role, team membership, and login credentials.

Billing information. Subscription plan, billing term, invoice and payment history, prepaid wallet balance and usage-charge history, and the last four digits and expiration of the payment card. Full payment card numbers are collected and stored by our payment processor, not by us.

Contact and lead records. Information our customers add or import about their contacts, including names, phone numbers, email addresses, mailing and property addresses, lead source, pipeline stage, tags, custom fields, appointments, notes, and transaction details.

Communications content. Call audio recordings and transcripts, SMS message content and delivery metadata, email content, headers, and engagement events such as opens and clicks, in-app notes, and AI-generated summaries, dispositions, and follow-up plans derived from those communications.

Calendar and scheduling data. Appointment times, attendees, availability, and calendar events synced from a connected calendar provider with the customer's authorization.

Integration data. Records synced to or from third-party systems a customer connects, such as CRMs, listing and IDX providers, advertising platforms, and calendar providers, limited to what the customer authorizes.

Usage and device data. Pages viewed, features used, actions taken, timestamps, IP address, browser and device type, operating system, referring URLs, and diagnostic logs.

Compliance records. Consent captures, opt-out and STOP requests, do-not-call and litigator-scrub results, electronic signature records for our Services Agreement including typed name, IP address, browser information, and timestamp.

Cookies and similar technologies. We use cookies and local storage for authentication, session persistence, security, preference storage, and product analytics. Most browsers let you block or delete cookies; blocking essential cookies will prevent the Platform from functioning.

3. How We Use Information

  • To provide, operate, maintain, and secure the Platform and its features.
  • To authenticate users, manage accounts, teams, permissions, and account switching for support purposes.
  • To place, receive, record, transcribe, and analyze calls; to send and receive SMS and email; and to schedule appointments, in each case at the direction of our customer.
  • To generate AI outputs such as call summaries, dispositions, suggested replies, follow-up tasks, sequence content, and analytics.
  • To bill subscription and usage charges, process wallet recharges, and prevent payment fraud and abuse.
  • To provide customer support, troubleshoot problems, and communicate about service changes, incidents, and account status.
  • To monitor, investigate, and prevent fraud, abuse, spam, security incidents, and violations of our Services Agreement or applicable law.
  • To produce aggregated and de-identified statistics that do not identify any individual, and to improve the Platform.
  • To comply with legal obligations and to establish, exercise, or defend legal claims, including responding to billing disputes and chargebacks.

4. AI Processing

The Platform uses artificial intelligence, including third-party large language and speech models, to transcribe calls, classify outcomes, draft messages and emails, generate summaries, and recommend next steps. Communications content, contact records, and related context are transmitted to these model providers solely to produce those outputs for the account that generated them.

We do not permit our AI model providers to use customer content to train their general-purpose models. AI outputs are probabilistic and may contain errors; they are decision support, not a substitute for human review. Customers remain responsible for reviewing and monitoring their campaigns, messages, and automations.

Calls placed or received through the Platform may be recorded and transcribed. Recording, transcription, monitoring, and disclosure requirements vary by state and country, and some jurisdictions require all-party consent. Our customers are solely responsible for determining whether recording is permitted for a given call, for providing any required disclosures or announcements, and for honoring requests not to be recorded. Recording features can be configured or disabled at the account level.

Our customers are responsible for obtaining and documenting consent before contacting their leads and clients, and for complying with the TCPA, state mini-TCPA statutes, CAN-SPAM, applicable FCC rules, and carrier and A2P/10DLC requirements.

The Platform provides compliance tooling: STOP, UNSUBSCRIBE, and similar keywords automatically suppress further messaging to that number; unsubscribe links are included in outbound marketing email; and optional DNC and litigator screening can be run against third-party databases. These tools are informational aids only. They do not establish a lawful basis to contact anyone and do not transfer compliance responsibility to us.

To stop receiving messages from a business using our Platform, reply STOP to a text, use the unsubscribe link in an email, or tell the business directly.

7. How We Share Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

We share information with:

  • Service providers and subprocessors that support the Platform, each bound by confidentiality and data-protection obligations and permitted to use the data only to provide services to us. These include cloud hosting and database providers, telephony and SMS carriers, voice AI and speech-processing providers, large language model providers, transactional and campaign email providers, payment processing, error monitoring, and analytics.
  • Third-party systems you connect, such as CRMs, listing and IDX providers, calendar providers, and advertising platforms, limited to the data required by the integration you authorize.
  • Within your account, with the account owner, team members, and collaborators according to the permissions the account owner configures.
  • Company personnel, including authorized support and administrative staff who may access an account to diagnose issues and provide support. Such access is logged.
  • Legal and safety recipients, when we believe disclosure is reasonably necessary to comply with law, legal process, or a governmental request; to enforce our agreements; to detect or prevent fraud, abuse, or security issues; or to protect the rights, property, or safety of any person.
  • In a corporate transaction, such as a merger, acquisition, financing, reorganization, or sale of assets, subject to this policy or a successor policy providing comparable protection.

8. Data Retention

We retain account, billing, and compliance records for as long as the account is active and thereafter as needed to comply with legal, tax, accounting, audit, and dispute-resolution obligations. Contact records, communications content, recordings, and transcripts are retained for as long as the customer maintains them in the account or as required by law.

Customers may delete individual records within the Platform. On account closure, we delete or de-identify account data within a commercially reasonable period, except where retention is required for legal, regulatory, billing-dispute, or backup and archival purposes. Residual copies may persist in backups for a limited period before routine deletion.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, encryption at rest for stored data, row-level access controls that isolate each account's data, role-based permissions, credential storage in a managed secret vault, audit logging of administrative access, and least-privilege access for personnel.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for safeguarding their own login credentials, managing team access, and promptly notifying us of any suspected unauthorized access.

10. Your Privacy Rights

California residents (CCPA/CPRA). Subject to verification and legal exceptions, you have the right to know the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of recipients; to request deletion; to request correction of inaccurate information; and to not be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" action required.

Other U.S. states. Residents of states with comprehensive privacy laws may have comparable rights of access, correction, deletion, and portability. We honor those rights where they apply.

How to exercise. Email legal@highiq.io with your request and enough information for us to verify your identity. You may use an authorized agent where the law permits. If your request concerns data a business manages using our Platform, we will forward it to that business, which is the party responsible for that data.

11. Children's Privacy

The Platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn we have collected such information, we will delete it.

12. International Users

The Platform is operated in the United States and intended for U.S. business use. Information is processed and stored in the United States and may be accessed from other jurisdictions by our service providers. If you access the Platform from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted here with a revised date and, where appropriate, communicated by email or in-platform notice. Continued use of the Platform after the effective date of a change constitutes acceptance of the updated policy.

14. Contact Us

High iQ

PO Box 607

Colorado Springs, CO 80901

legal@highiq.io