Privacy Policy

Updated 11.04.25
Welcome to Outsella, a service provided by Hubway LLC, an international consulting and legal firm (“we”, “our”, or “us”). We are committed to protecting your privacy and ensuring your data is handled responsibly and transparently.
1. Scope & Application

This Policy governs all data processing activities related to the Outsella platform, which enables AI-powered, real-time sales engagement through embedded voice and text agents on client websites.

It applies to:
- Website visitors and end users interacting with Outsella-powered interfaces
- Clients and prospective clients using or trialing our platform
- Partners, consultants, and authorized third-party integrators

This Policy operates in parallel with applicable data processing agreements, client service terms, and regulatory obligations in your jurisdiction (e.g., GDPR, CCPA, UK DPA, Nigerian NDPR).

2. Data We Collect

We collect data to enable secure, intelligent, and personalized use of our platform. Data is categorized as follows:

a. Personally Identifiable Information (PII)
- Full name, email address, phone number, company name
- Role/title, business interests, preferences
- Booking or demo form submissions

b. Technical and Behavioral Data
- Device type, OS, browser type and version
- IP address and geolocation (city-level granularity only)
- Session timestamps, page views, clickstream activity
- Mode of interaction (voice or text), duration of conversation

c. Interaction Content
- Chat/voice transcripts
- Form data submitted via the agent
- Feedback surveys or satisfaction ratings

d. Third-Party Integration Data
- Calendly: availability, scheduling metadata
- HubSpot/CRM: lead stage, notes, company record
- Slack: agent notifications, message metadata
- Google Calendar: booking slots and confirmations

We do not collect or process biometric identifiers, government-issued ID numbers, or financial account credentials unless explicitly stated and legally required.

3. Purpose of Processing

We process personal data for the following purposes, pursuant to Article 6(1)(b–f) GDPR or equivalent local bases:

a. Core Functional Delivery
- Enable live AI interactions on client websites
- Personalize responses based on user profile and behavior
- Execute follow-ups, demos, or content delivery

b. Platform Optimization
- Improve agent performance via anonymized training
- Analyze usage metrics to enhance UX and sales conversions
- Detect and correct AI misclassifications

c. Business Operations
- Maintain records of client and user engagement
- Deliver onboarding, training, and support services
- Send platform updates or operational notices

d. Compliance & Legal Defense
- Detect, prevent, and investigate fraud or abuse
- Fulfill lawful requests from regulators or courts
- Enforce contractual rights and terms of use

4. Data Sharing and Disclosure

We do not sell, rent, or trade personal data. However, we may share data under strict controls in the following circumstances:

a. Client Access
Transcripts, lead details, and session metadata are shared with the specific client whose site the user engaged with. Clients are responsible for handling this data per their own privacy terms.

b. Subprocessors and Service Providers
We engage vetted third-party vendors under formal Data Processing Agreements (DPAs). Categories include:
- Cloud infrastructure providers (e.g., AWS, Google Cloud)
- CRM and calendar systems (e.g., HubSpot, Calendly)
- Analytics and performance monitoring tools
- Professional support and advisory services

All subprocessors are reviewed for security posture, jurisdictional compliance, and data minimization.

c. Regulatory and Legal Obligations
We may disclose information where required by applicable law or government regulation, including:
- Tax or audit authorities
- Data protection regulators (e.g., ICO, NDPC, CNIL)
- Law enforcement or judicial entities with proper authority

5. International Transfers

Outsella operates globally. Data may be processed in or transferred to jurisdictions outside your country of residence, including countries without an “adequate” data protection determination (per EU/UK standards).

To ensure lawful cross-border transfers, we implement:
- Standard Contractual Clauses (SCCs) approved by the European Commission or UK ICO
- Supplementary safeguards such as encryption, pseudonymization, and internal access controls
- Data localization measures for clients who require regional hosting

6. Data Security & Governance

We apply industry-grade security frameworks, consistent with ISO/IEC 27001 and NIST standards.

Measures Include:
- End-to-end encryption (AES-256 in transit and at rest)
- Role-based access control (RBAC)
- Continuous monitoring for anomalies or breaches
- Penetration testing and security audits
- Incident response and breach notification protocols

Employee access to data is tightly restricted, monitored, and governed by confidentiality agreements.

7. Retention and Deletion

We retain personal data only as long as necessary to:
- Fulfill the purposes stated in this Policy
- Comply with statutory obligations (e.g., tax, audit)
- Support legal defense or enforce our agreements

Client data retention timelines may be customized per Master Service Agreements (MSAs). Upon contract termination, all data is securely deleted or anonymized unless otherwise required by law.

8. Your Rights & Choices

Depending on your jurisdiction, you may have the right to:

- Access, correct, or delete your personal data
- Object to processing or request restriction
- Withdraw consent where processing is consent-based
- Request data portability
- Lodge a complaint with a supervisory authority

You may exercise these rights by contacting us at [Insert Privacy Contact Email]. We will respond within legally mandated timelines.

9. Children's Data

Outsella is intended for use by businesses and professionals. We do not knowingly collect or solicit data from individuals under 13 years old (or the equivalent age of digital consent in your jurisdiction). If we learn that we have inadvertently collected such data, we will delete it promptly.

10. Cookies & Tracking Technologies

Outsella uses first- and third-party cookies and similar technologies for:

- Session management and security
- Analytics and performance optimization
- Personalization of agent interactions

You can control cookie preferences via your browser settings. For jurisdictions requiring explicit consent (e.g., EU), a consent banner will be presented.

11. Policy Updates

We may revise this Policy periodically to reflect changes in law, technology, or product features. Updates will be posted on this page with the revised “Last Updated” date.

If changes materially impact your rights, we will notify you via prominent notice or direct communication.

12. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, contact our global privacy office:

Hubway LLC – Privacy Office  
Email: contact@hubway.us
Phone: +1 (832) 699-0608
Address: 111 Ne 1st ST, 33132 Miami, FL
Attention: Data Protection Officer (DPO)