Last Updated: June 10, 2025
At ThermaTalk ("we", "our", or "us"), we are committed to protecting your privacy and the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered communication services for heating and cooling businesses.
By using ThermaTalk services, you consent to the data practices described in this Privacy Policy. We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy, and in some cases, we may provide you with additional notice.
This Privacy Policy applies to all services offered by ThermaTalk, including our AI voice assistant, chat widgets, email response systems, and any other related services.
We collect several types of information from and about users of our services, including:
Our systems may process information that could include sensitive personal data such as health information when discussing heating and cooling needs. We handle such information in accordance with applicable laws, including HIPAA where relevant.
We use the information we collect for various purposes, including:
We may also use your information for other purposes with your consent or as permitted or required by applicable law. We will always seek to ensure that our use of your personal information is proportionate and respectful of your privacy rights.
We follow the principle of data minimization, collecting and retaining only the information necessary for the purposes described in this Privacy Policy. We regularly review our data retention practices to ensure we're not keeping data longer than needed.
We implement a variety of security measures to maintain the safety of your personal information when you use our services. These include:
End-to-end encryption for all data in transit and at rest
Strict access controls and authentication requirements
Continuous security monitoring and vulnerability assessments
Our infrastructure is hosted on secure servers with appropriate safeguards, and we maintain SOC 2 Type II certification. We regularly review and update our security practices to address new threats and vulnerabilities.
While we implement these security measures, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, while we strive to protect your personal information, we cannot guarantee its absolute security.
In the event of a data breach that compromises your personal information, we will:
We may share your information with third parties in certain circumstances:
Category | Purpose | Data Shared |
---|---|---|
Service Providers | To help us provide and improve our services | Contact information, usage data, technical information |
Business Partners | For integrated services and joint offerings | Contact information, business information |
Legal Requirements | To comply with laws, regulations, legal process | Any information as legally required |
Business Transfers | In connection with a merger, acquisition, or sale | All information related to the transferred assets |
When we share information with service providers, we require them to use your information only for the purpose of providing services to us and to implement appropriate data security measures.
Our services may integrate with or contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our services.
Examples of third-party integrations may include:
Depending on your location, you may have certain rights regarding your personal information. These may include:
You can request a copy of the personal information we hold about you.
You can request that we correct inaccurate or incomplete information.
You can request that we delete your personal information in certain circumstances.
You can request that we restrict processing of your personal information.
You can request a copy of your data in a structured, commonly used format.
You can object to the processing of your personal information in certain circumstances.
To exercise any of these rights, please contact us using the information provided in the "Contact Information" section below. We will respond to your request within the timeframe required by applicable law.
You can submit a request to exercise your data rights by:
We may need to verify your identity before processing your request. We will respond within 30 days in most cases, though some complex requests may take longer.
We are committed to complying with applicable data protection laws, including the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
For users in the European Economic Area (EEA), we serve as both a data controller and a data processor, depending on the circumstances.
For California residents, we comply with the California Consumer Privacy Act (CCPA) and its requirements.
We may transfer your personal information to countries other than the one in which you live. When we transfer personal information across borders, we take appropriate safeguards to protect your information in accordance with this Privacy Policy and applicable law.
Under the GDPR, we process your personal information based on one or more of the following legal bases:
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:
Our dedicated privacy team is here to assist you with any questions or concerns about your data. We aim to respond to all privacy-related inquiries within 2 business days.
Contact Privacy Team