Trust

Trust and security

How iHayz agents protect each business’s data and its customers’ messages: the controls in place, where the data lives, who processes it, how long it is kept and how to sign a data processing agreement.

Last updated 1 October 2026iHayz is a brand of Media Experts LLC (USA) and Media Experts (India).
On this page
  1. The short version
  2. Security overview
  3. Where your data lives and who processes it
  4. Language models and training
  5. Retention
  6. Security incidents
  7. Health information and sensitive sectors
  8. Data processing agreement
  9. Reporting a security issue

The short version

  • Your business data and your customers’ messages train no model, ours or our model provider’s.

  • Each business’s records are kept apart, and every release is tested for one business reaching another’s.

  • Every reply is screened before it leaves. When a reply cannot go, a person on your team takes the conversation.

  • The database is copied off the server every night into storage locked against deletion for 35 days, and a restore is tested every week.

01

Security overview

The controls below run in the product today.

  • Businesses kept apart. Every request is scoped to the business that made it. A request carrying another business’s record number gets “not found”, and every release runs a test that tries to reach another business’s records and stops the release if it succeeds.

  • Sign-in by one-time code. People sign in with a code sent to their email address, with limits on how many codes and wrong answers a network or an address can use. Session tokens are stored only as one-way hashes.

  • Private file storage. Documents and files sit in private storage buckets. A download link is signed for one file and expires after 15 minutes, and each part of the product holds its own key to its own bucket.

  • Signed incoming messages. Every message delivered by our messaging provider carries a signature that is checked against the raw message before anything is stored. A message that fails is refused, and a repeated delivery is recorded once.

  • A screen on every reply. Before a reply reaches a customer, links to sites the business has not listed are removed, and a reply holding a national ID number, a card number, a date of birth or a stranger’s phone number is not sent.

  • Actions from a fixed list. The appointment agent can book, move, cancel, quote a listed price, list free times or hand over to a person, and nothing else. Each action is checked against the business and the conversation it came from, and a booking is confirmed with the customer before it is made.

  • An audit trail. Changes to business records are logged with who made them, when, from where, and the values before and after.

  • Checked dependencies. Each release is blocked by a known vulnerability in the third-party code it ships, and carries a list of every component and its version.

  • Redacted logs. Log lines written by the agents and background jobs mask email addresses and long runs of digits, so a customer’s phone number does not sit in a log file.

  • Secrets off the web. Keys and passwords are kept in files outside the web root, readable only by the application’s own system user.

02

Where your data lives and who processes it

Your business data sits in one database on our server in the United States. To run the service we use the sub-processors below. Each receives only what its part of the service needs.

Sub-processors, 1 October 2026
Sub-processorWhat it does for the serviceLocation
Google Cloud (Google LLC)Runs the language models that read your documents, draft replies and index your documents for search.Search indexing in the United States; replies on Google’s global network, region chosen by Google per request
Cloudflare, Inc.Delivers and protects the application and its web traffic; stores uploaded documents and the nightly database backups.Worldwide network; company in the United States
Our messaging providerConnects a business’s WhatsApp, Instagram and Facebook accounts and carries their messages to and from the service.Company registered in Spain
Our transactional email providerSends sign-in codes and service notifications by email.India
Our data centreHouses the server that runs the application and its database.United States

Messages your customers send on WhatsApp, Instagram or Facebook also pass through those networks, under the terms the business and its customers accepted with them.

03

Language models and training

Replies, document reading and search use language models run for us by Google Cloud.

  • No training on your data. We do not use your business data or your customers’ messages to train or tune any model.
  • Our model provider’s terms. Google’s terms for this service state that it will not use customer data to train or fine-tune any model without the customer’s prior permission or instruction.
  • Abuse monitoring. Under the same terms, Google may log prompts for a limited time to detect abuse of its service.
  • Answers from your own material. The agent answers from the documents, prices and answers the business gives it. Text in those documents that reads as an instruction to the agent is held back and kept out of answers.
  • Every answer logged. Each reply is recorded with the question, the passages it was built from and why it answered or handed over, so what was said, and on what basis, can be checked.
04

Retention

How long each kind of record is kept. Periods are counted from the record’s own date.

Retention periods, 1 October 2026
RecordKept for
Business records, conversations and bookingsWhile the business uses the service; removed when it asks, and on closure
The agent’s memory of a returning contact (name, number, open step)Forgotten after 30 days without a message by default; each business sets 1 to 365 days
Answer log (each reply, its sources and its outcome)90 days
Message delivery identifiers, kept to drop repeated deliveries14 days
Sign-in codes, sign-in attempts and ended sessions30 days
Nightly database backups in off-server storageKept for a limited period after they are made, and then deleted
Backup copies kept on the server itself3 days for the database; 14 days for stored files

A business can ask in writing for one customer’s data, or its own, to be exported or erased. We act on the business’s instruction, as its processor.

05

Security incidents

If we become aware of a breach of personal data we process for a business, we tell that business without undue delay, with what we know at that point: what happened, which data and which people it touches, and what we are doing about it. We add to the notice as we learn more.

The notice is there so the business can meet its own deadlines. Under the GDPR the business, as controller, notifies its supervisory authority within 72 hours of becoming aware of a breach; as processor, we inform the business without undue delay.

06

Health information and sensitive sectors

iHayz agents are not offered for United States protected health information (PHI) under HIPAA. A business covered by HIPAA must not use them to collect or store PHI unless a business associate agreement (BAA) is signed with us first.

A clinic, a law firm or a financial practice uses the agent for bookings, opening hours, prices and the questions its own documents answer. Clinical notes, case files and account details belong outside the agent’s documents, and the reply screen never sends a national ID number, a card number or a date of birth.

07

Data processing agreement

Each business is the controller of its customers’ data, and iHayz processes it on the business’s instructions. A data processing agreement, with the European Commission’s standard contractual clauses for transfers outside the European Economic Area, is available on request.

  • Write to hello@ihayz.com with your company’s registered name, its country and the person who will sign.
  • We reply in writing within one business day.

Request the agreement by email

08

Reporting a security issue

Write to hello@ihayz.com with what you found and how to reproduce it. The same address is published in /.well-known/security.txt. Please give us time to fix an issue before you publish it.