Skip to content
MenuClose

Privacy Policy

Arbol Artificial Intelligence, Inc. · United States · Effective June 11, 2026

The short version

  • We collect what we need to run the service.
  • We don't sell data.
  • Your patients' data belongs to you and your patients.
  • Everything can be exported or deleted.

This is the United States version. For Colombia, under Ley 1581 de 2012, read the Spanish version.

Arbol Artificial Intelligence, Inc. (Delaware C Corporation) and its Colombian affiliate Arbol Artificial Intelligence SAS (NIT 901.806.384-1, Colombia).

Effective Date: June 11, 2026 — Last Updated: June 11, 2026

Arbol Artificial Intelligence, Inc., a Delaware C Corporation, together with its Colombian affiliate Arbol Artificial Intelligence SAS (NIT 901.806.384-1) (collectively, "Arbol AI," "Company," "we," "us," and "our") provides technology that lets our customers deploy AI-powered voice and messaging communication solutions. This Privacy Policy explains how we collect, use, and share personal information and how you can exercise your privacy rights.

1. Scope

This Privacy Policy applies to personal information processed by us, including on our website (getarbol.com), web applications, APIs, and other online or offline offerings (collectively, the "Services").

Important note about Customer Data. This Privacy Policy does not apply to personal information that our customers process using the Services ("Customer Data") — for example, information about a patient who receives a call from an AI agent configured by one of our customers. Our customers' own privacy policies govern Customer Data, and our processing of it is governed by our contracts with those customers. If you are an end user reached through one of our customers, please direct requests about Customer Data to that customer.

  • Arbol AI is a Controller for the information we collect to market, provide, and support the Services.
  • Arbol AI is a Processor for Customer Data entered into the Services; the customer is the Controller.

HIPAA. When we create, receive, maintain, or transmit protected health information (PHI) on behalf of a U.S. healthcare provider, we act as a Business Associate under HIPAA and execute a Business Associate Agreement (BAA) with that customer. Subprocessors that touch PHI operate under downstream BAAs, and our AI model providers are configured for zero data retention. PHI we process as a Business Associate is governed by HIPAA and the BAA — not by state consumer privacy laws, to the extent of their HIPAA exemptions. See our Trust Center for the full security and compliance program.

2. Personal Information We Collect

2.1 Information you provide directly

CategoryExamples
Account InformationName, email, phone number, company name, job title, encrypted password, billing address
Organization InformationCompany name, industry, business description, website, timezone, team members
AI Agent ConfigurationBusiness instructions, scripts, prompts, voice preferences, scheduling rules
Payment InformationCard type, last 4 digits, billing address (full card details handled by our payment processor)
CommunicationsInquiries, feedback, survey responses, support tickets

2.2 Information collected automatically

CategoryExamples
Device / Browser DataIP address, device type, operating system, browser type and version, unique identifiers
Usage DataPages visited, features used, clicks, session duration, referring URL
Location DataApproximate location derived from IP address, timezone
Log DataAccess times, error logs, API requests

2.3 Cookies and similar technologies

We and our service providers use cookies, pixel tags, local storage, and similar technologies to operate and analyze the Services. We use essential cookies (login, security, core functionality), functional cookies (preferences), and analytics cookies. To opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout. You can manage cookies through your browser settings; disabling essential cookies may break some features.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and secure the Services and process communications;
  • Generate transcripts, summaries, and analytics;
  • Process payments and manage subscriptions and support;
  • Detect and prevent fraud, abuse, and security incidents;
  • Comply with legal obligations; and
  • With your consent, send you marketing about our Services.

Improving AI agents within your organization only. Your organization's data is used to improve your AI agents for your business context. This learning is isolated to your organization. We do not use your data to train general AI models or to improve the service for other customers, and we never combine your data with another organization's. We do not use Customer Data (recordings, transcripts, contacts) for marketing.

4. How We Disclose Your Information

We disclose information only as described below. We do not sell your personal information.

4.1 Service providers (sub-processors)

We share information with service providers who help us run the Services, all contractually bound to protect it and use it only as we instruct, by category of function:

CategoryPurpose
Infrastructure & hostingHosting, storage, computing
AuthenticationUser identity and access management
Telephony & messagingVoice calls and messages
AI language processingLanguage model services (not used for training)
PaymentsPayment processing
Email deliveryTransactional email
Security & CDNContent delivery, DDoS protection
Analytics & error monitoringUsage analytics, error tracking

Subprocessors that handle PHI do so under Business Associate Agreements; AI model providers operate under zero-data-retention configurations and never train on Customer Data. The full, named subprocessor list — with locations and safeguards — is available under NDA through our Trust Center.

4.2 Legal requirements and safety

We may disclose information for valid subpoenas, court orders, or government requests, and when necessary to protect our rights, users, or the public, or to prevent fraud or illegal activity. We will try to notify you unless legally prohibited.

4.3 Business transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Your Privacy Choices and Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold and obtain a copy;
  • Correct inaccurate or incomplete information;
  • Delete your personal information;
  • Port your data in a portable format (CSV, JSON);
  • Opt out of sale or targeted advertising (we do neither); and
  • Non-discrimination for exercising your rights.

U.S. state privacy laws. As of 2026, twenty U.S. states have comprehensive consumer privacy laws in effect — including California (CCPA/CPRA), Delaware (DPDPA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Kentucky, and Rhode Island. If you are a resident of one of these states, you may exercise the rights above by emailing support@getarbol.com. We do not sell personal information or share it for cross-context behavioral advertising. Where we process personal information on behalf of a customer, we act as a service provider / processor under those laws, processing it only on the customer's documented instructions.

How to exercise your rights. Use the controls in your account dashboard, or email support@getarbol.com. We respond within 45 days (extendable to 90 with notice). We may need to verify your identity. If we decline, you may appeal by replying to our response; if an appeal is denied, you may contact your state Attorney General.

6. Security of Your Information

  • Technical: encryption in transit (TLS 1.2+) and at rest (AES-256), a dedicated database per customer organization (infrastructure-level tenant isolation), secure password hashing, MFA, intrusion detection.
  • Administrative: role-based access controls, employee training, security policies.
  • Physical: reputable data centers with access controls and environmental protections.

No system is 100% secure; you are responsible for keeping your account credentials safe. Our full security program — encryption, access control, audit logging, subprocessor management, and incident response — is documented in our Trust Center.

7. Data Retention

Data typeRetention period
Account informationDuration of account + 3 years
Call recordings & transcriptsAs configured by you; deletable anytime
Call metadataDuration of account + 1 year
Billing records7 years (legal/tax requirement)
Usage logs2 years, then anonymized
Contact dataUntil you delete it

You can delete recordings, transcripts, and contacts anytime from your dashboard. Deleted data is removed from active systems within 30 days and from backups within 90 days. On account closure we delete or anonymize your data within 90 days, except data we must keep for legal compliance.

8. Children's Information

The Services are not intended for anyone under 18, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact support@getarbol.com and we will delete it.

9. Third-Party Websites

Our Services may link to third-party sites or applications. This Privacy Policy does not apply to them; please review their policies.

10. International Users

We operate from the United States and Colombia, and our service providers may process information in other countries. By using the Services, you understand your information may be transferred to and processed in jurisdictions with different data-protection rules, subject to appropriate safeguards.

11. Changes to This Privacy Policy

We may update this Privacy Policy. For material changes, we will update the "Last Updated" date and notify you by email or through the Services at least 30 days before they take effect. Continued use after changes take effect means you accept the updated policy.

12. Contact Us

Arbol Artificial Intelligence, Inc. (Delaware C Corporation)
Attn: Privacy Inquiries
131 Continental Dr, Suite 305
Newark, DE 19713, United States

Arbol Artificial Intelligence SAS (Colombian affiliate)
NIT: 901.806.384-1 — Colombia

Email: support@getarbol.com. We will respond within 30 days.

Questions about your data? support@getarbol.comTrust CenterTerms of Service

In Bogotá, at any hour. Arbol is answering.

Phone, WhatsApp, text, email and web chat.

Three patients need you today.

Book 30 minutes and let's find yours.

A video call with our team of physicians, nurses and engineers, using your own cases: your patients, your schedule and your channels.

Or pick a day

support@getarbol.com

In Bogotá, at any hour. Arbol is answering.