Legal
Privacy Policy
Last updated: July 21, 2026
1. Introduction
Direnium ("Direnium", "we", "our", or "us") operates the Direnium platform, an AI-powered business automation platform that includes workflow automation, AI agents, AI voice calling (inbound and outbound), SMS messaging, CRM, custom data objects, knowledge management, and multi-channel messaging. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our website, platform, and related services (collectively, the "Services").
The Services let you instruct AI agents to interact on your behalf with people you choose to contact, including by phone call and SMS. That capability creates serious privacy obligations both for us and for you. This policy describes our part of those obligations. Section 12 describes yours.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Services.
2. Information We Collect
a. Account & Profile Information
When you register for the Services, we collect:
- Full name, first name, and last name
- Email address
- Phone number (optional)
- Password (stored only as a bcrypt hash; we never store your plaintext password)
- Workspace (tenant) name and membership role
b. Content & Usage Data You Create
As you use the platform, we store the content you create and interact with, including:
- Workflows: visual automation definitions, drafts, published versions, run history, and trigger inputs/outputs
- AI Agents: persona configuration (name, system prompt, tone, opening lines, voice settings), enabled abilities, knowledge-base attachments, and dynamic-variable definitions
- AI Agent Conversations: chat sessions, messages, and associated metadata for both workflow-embedded and standalone agents
- Knowledge Base: pages, text chunks, and vector embeddings generated from your uploaded content
- CRM Records and Custom Data Objects: contacts, companies, deals, pipeline stages, activities, notes, tags, and any custom-defined object schema and record values you create, including any personal data you choose to store about your own customers and leads
- Brand Voice: writing style configurations
- Scheduled Follow-ups: messages queued for future delivery, including recipient and channel details
- API Keys: key metadata (we store only a SHA-256 hash of the key; you see the full key only once at creation)
- Feature Requests: feedback you submit through the platform
- ChangeSets: atomic configuration bundles proposed by Pilot (our workspace AI assistant) or by you, including the full proposed payload, your approval/rejection, the resulting committed operations, and inverse data needed to roll back
c. Voice Call Data
When you enable AI voice calling on an agent and the agent places or receives a call, we and our voice provider process and store:
- Caller and callee phone numbers in E.164 format
- Call direction (inbound/outbound), region (US/IL), language (English/Hebrew), engine, and call status
- Call timestamps (started, ended), duration, billed minutes, and credits charged
- Audio recording of the call (typically MP3), generated by the voice provider
- Automated transcript of the call (turn-by-turn text)
- Call summary and sentiment, generated by the voice provider
- Structured variables collected during the call (e.g. fields the agent was instructed to extract)
- The "leadContext" passed into the call (data from your CRM or workflow used by the agent for personalization)
- A tamper-evident log of each ability invoked during the call (the action taken, its inputs, outputs, success/failure, and execution time)
Transcripts, summaries, and collected variables are stored encrypted at rest using AES-256-GCM with the tenant identifier bound into the cipher's Additional Authenticated Data (see Section 7). Audio recordings are stored by our voice provider and retrieved for playback through authenticated, time-limited URLs.
d. SMS Data
When your workflows or voice agents send SMS through the Services, we process and store:
- Recipient phone number (E.164)
- Sender (the alphanumeric ID or Messaging Service identifier used)
- Provider, region, and message class (transactional or marketing)
- Message body length, segment count, and a SHA-256 hash of the body. We do not store the SMS body text itself
- Delivery status events received from the carrier (sent, delivered, failed, undelivered) and any error codes
- References to the call, workflow run, agent, or record that triggered the message
- Provider message identifier (used to reconcile delivery receipts)
For SMS verification flows, we additionally store a one-time hashed code with a 5-minute expiry; we never store the verification code in plaintext.
e. Opt-Out Records
When a recipient opts out of SMS (by replying STOP or an equivalent keyword, clicking the opt-out link in a marketing message, being flagged by the carrier, or being added manually by a workspace member), we permanently store:
- Recipient phone number
- Source of the opt-out (inbound keyword, opt-out link, manual, provider callback)
- Reason (where provided) and timestamp
- Identifier of the workspace member who recorded the opt-out, if applicable
Opt-out records are kept indefinitely so the platform can continue to honor the suppression. They are retained even if you close your account.
f. Integration & Connection Data
When you connect third-party services, we store the credentials needed to operate those connections (such as OAuth tokens and API keys). These values are encrypted at rest using AES-256-GCM. The integrations we support include:
- Google Calendar and Gmail (OAuth 2.0)
- WhatsApp, Instagram, and Messenger (via Meta / Facebook APIs)
- Slack
- HubSpot
- Salesforce
- ZoomInfo
- Fireberry
- Microsoft Teams
- Custom MCP (Model Context Protocol) connections
We access only the scopes and data you authorize during the connection process.
g. Messaging & Channel Data
When your workflows handle inbound or outbound messages across non-SMS channels (WhatsApp, Instagram, Messenger, email, Slack), we process and store message content, sender identifiers, timestamps, and conversation session metadata as needed to operate your automations.
h. AI Agent Action and Audit Logs
Every action a voice or workflow AI agent takes (invoking a CRM update, validating a value, sending a verification SMS, looking up a contact, scheduling a follow-up, etc.) is recorded with its inputs, outputs, success/failure, error message (if any), and execution time. Each action row is linked into a per-tenant HMAC-SHA256 hash chain that detects any subsequent insertion, deletion, or modification.
i. Automatically Collected Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and navigation patterns
- Session duration and interaction events
- Performance metrics (page load times, errors)
3. How We Use Your Information
- Provide the Services: operate your workflows, AI agents, voice calls, SMS dispatch, CRM, custom data objects, knowledge base, and messaging automations
- AI Processing: send relevant context to large language model providers and to our voice provider (see Section 5) to power agent conversations, voice calls, transcription, summarization, workflow AI nodes, and knowledge search
- Voice Operations: dispatch outbound calls, accept inbound calls, deliver call recordings and transcripts to your workspace, generate per-call structured data and summaries
- SMS Operations: route messages through the appropriate regional provider, append opt-out compliance content, enforce opt-out lists, count segments for billing, accept and process delivery receipts, detect and honor STOP keywords on inbound messages
- Authentication & Security: verify your identity, manage sessions with JWTs, enforce team roles and permissions, and protect against unauthorized access
- Communication: send transactional emails such as email verification, password resets, and team invitations
- Billing & Entitlements: manage your subscription plan, enforce usage limits, charge credits for AI conversations, voice minutes, and SMS segments, hold credits during voice calls, settle final cost on call completion, and refund credit holds on transport failure
- Compliance & Audit: maintain tamper-evident records of agent actions for regulatory inspection; produce signed per-call exports on request
- Monitoring & Reliability: detect errors, monitor performance, and maintain platform stability
- Improvement: analyze aggregate usage patterns to improve features, fix bugs, and guide product development
- Legal Compliance: meet our obligations under applicable law, including telecommunications anti-spam law and data-protection law
4. Legal Basis for Processing
Where required by applicable law (including the GDPR), we rely on the following legal bases:
- Performance of a contract: processing necessary to deliver the Services you signed up for
- Consent: for optional data collection or marketing communications (you may withdraw consent at any time)
- Legitimate interests: improving and securing the Services, analyzing usage, and preventing fraud
- Legal obligation: complying with applicable laws and regulations, including anti-spam and telecommunications rules
For personal data of your end users (the people you call or message via the Services), the legal basis is your relationship with them. See Section 12.
5. Third-Party Service Providers
We share data with third-party providers only as necessary to operate the Services. We do not sell your personal data, and we do not sell or rent your end users' personal data.
AI & Language Model Providers
To power AI agents, chat assistants, and intelligent workflow nodes, relevant portions of your content may be sent to:
- Anthropic: for chat completions (default provider)
- OpenAI: for chat completions and text embeddings (when configured)
- Tavily: for real-time web search within AI agent workflows
If you supply your own API key for one of these providers via Settings → LLM Provider Key (BYOK), AI calls are routed using your key and key-level controls. These providers process data in accordance with their own privacy policies and data processing agreements. We do not use your content to train third-party AI models.
Voice Calling Provider
AI voice calls are placed and received through NLPearl. To dispatch a call, we transmit to NLPearl the destination phone number, the agent's persona configuration (system prompt, tone, opening line, voice gender and language), the agent's enabled abilities, and any leadContext you have configured for personalization. NLPearl records the call audio, generates a transcript and summary, and returns this data to us together with call duration, status, and per-action telemetry.
Recordings are accessed only via authenticated, time-limited URLs scoped to your workspace. Transcripts, summaries, and the structured variables collected during the call are stored on our infrastructure encrypted at rest with tenant-bound Additional Authenticated Data (see Section 7).
SMS Providers
SMS routing is regional:
- Twilio: used for messages sent to United States numbers (+1). Direnium maintains an A2P 10DLC brand and campaign registration covering platform traffic; messages are sent via a system-level Messaging Service.
- sms4free: used for messages sent to Israeli numbers (+972). Messages are sent with an alphanumeric sender ID.
For each SMS we transmit to the provider only what is required to deliver the message: recipient phone, sender, body, and message class. The body is forwarded to the carrier in plaintext (this is inherent to the SMS protocol) but the body is not retained on our infrastructure (only its length and a SHA-256 hash are stored; see Section 2(d)). Delivery receipts are returned via signed webhook callbacks and used to update message status and to detect carrier-level opt-out signals.
Infrastructure & Operations
- Cloud Hosting: database, compute, and storage infrastructure (AWS)
- Temporal: durable workflow execution engine
- Amazon Web Services (SES): transactional email delivery
- Datadog: front-end performance monitoring and session replay (production environment only; user inputs are masked by default)
Payment Processing
We use Lemon Squeezy as our payment processor. When you make a purchase, your payment information is processed directly by Lemon Squeezy. We do not store your credit card details. Please refer to Lemon Squeezy's privacy policy for information about how they handle your payment data.
Billing Data
We retain records of your subscription status, credit balance, and purchase history to provide and improve our services.
Connected Integrations
When you connect third-party services (Google, Meta, Slack, HubSpot, Salesforce, ZoomInfo, Fireberry, LinkedIn, Microsoft Teams, or custom MCP endpoints), data flows between the Services and those providers as directed by your workflows and configurations. These transfers are governed by the respective provider's terms and privacy practices.
6. Cookies & Tracking Technologies
The Direnium marketing website and platform may use cookies and similar technologies for:
- Essential functionality: authentication tokens (JWT stored in browser), session management
- Performance monitoring: Datadog Real User Monitoring (RUM) for error tracking, performance metrics, and limited session replay in the production environment
We do not use advertising cookies or third-party ad trackers. When Datadog RUM is active, user input fields are masked by default (mask-user-input privacy level). You can control cookies through your browser settings; disabling them may affect platform functionality.
7. Data Security
We implement multiple layers of protection:
- Passwords are stored as bcrypt hashes; we never see or store your plaintext password
- Integration credentials and sensitive configuration values are encrypted at rest using AES-256-GCM
- API keys are stored as SHA-256 hashes; only a short prefix is retained for identification, and the full key is shown to you only once at creation
- Voice call transcripts, summaries, and collected variables are stored encrypted at rest using AES-256-GCM, with the tenant identifier bound into the cipher's Additional Authenticated Data (AAD). This means a row's ciphertext is cryptographically tied to your workspace context: a row whose tenant identifier was tampered with cannot be decrypted, and decryption under any other tenant's context fails with an authentication error rather than returning data
- SMS bodies are not stored at all; only message length and a SHA-256 hash of the body are kept
- SMS verification codes are stored as hashes with a 5-minute expiry and a 3-attempt cap
- Opt-out URLs and DLR webhooks are signed with HMAC tokens; tampered URLs are rejected
- Authentication uses signed JWTs with separate access and refresh token secrets
- Role-based access control (RBAC) and team-membership checks enforce workspace-level permissions
- Every database query that touches tenant-owned data is filtered by tenant identifier at the application layer
- External API access is rate-limited (60 requests per minute per key)
- Voice and SMS phone numbers in server logs are redacted to a masked form
- The voice agent action log is tamper-evident: each row's content (and its predecessor's hash) is signed with HMAC-SHA256 derived from a platform secret. Any insertion, deletion, or modification breaks the chain and is reported in the per-call regulator export
- For each completed voice call you can request a signed regulator export: a canonical JSON document of the call metadata, transcript, summary, collected variables, and full action log, signed with HMAC-SHA256 so the document's integrity can be independently verified by a regulator
While we take reasonable technical and organizational measures, no system is completely secure, and we cannot guarantee absolute security.
8. Multi-Tenant Data Isolation
Direnium operates a multi-tenant architecture. Each workspace (tenant) is isolated at two layers:
- Procedural isolation: every database query, API call, and background workflow execution is scoped to your tenant. Repository code at the data-access layer enforces a redundant tenant filter on every read and write of tenant-owned records
- Cryptographic isolation: for sensitive data classes (currently voice transcripts, summaries, and collected variables), the tenant identifier is bound into the AES-GCM Additional Authenticated Data. This makes cross-tenant decryption mathematically impossible: an attacker with full database read access still cannot decrypt one tenant's transcript under another tenant's context, because the cipher's authentication tag will not validate
Phone-number resources (inbound and outbound numbers, voice agent bindings, SMS senders, voicemail boxes, and any other E.164-bearing identifier) are owned by exactly one tenant at any given time. There is no shared, pooled, or "global" phone resource that crosses tenants.
9. International Data Transfers
Your information may be processed and stored in countries outside your country of residence, including Israel, the United States, and the European Union. AI providers (Anthropic, OpenAI), the voice provider (NLPearl), and SMS providers (Twilio, sms4free) operate from their own jurisdictions. Where required by law, we use appropriate safeguards (such as standard contractual clauses) to ensure adequate protection of personal data during cross-border transfers.
10. Data Retention
We retain your data for as long as your account is active or as needed to provide the Services. Specific retention rules:
- Voice call recordings, transcripts, summaries, and collected variables: retained according to your workspace's audit retention policy (default 365 days, configurable from 7 days to 10 years). Recordings older than the policy window are removed; transcripts/summaries/variables are removed from the active database, optionally archived to cold storage if you have enabled the archive option
- SMS metadata: retained for the same window as voice records. SMS bodies are never retained beyond the moment of dispatch (only length and hash)
- SMS verification codes: retained as hashes for 5 minutes; deleted on expiry
- SMS opt-out records: retained indefinitely, even after account closure, so the platform can continue to honor the suppression. This is a compliance obligation that takes precedence over deletion
- Voice agent action log (audit chain): retained per your audit retention policy
- Account, billing, and subscription records: retained as required by tax and accounting law
- Aggregate usage analytics: retained in anonymized form indefinitely
When you delete specific content (workflows, contacts, knowledge pages, custom records, voice calls, etc.), it is removed from our active database. If you close your account, we will delete or anonymize your data within a reasonable timeframe, except for opt-out records and items required to be retained by law.
Encrypted PII is deleted along with the row that holds it; once deleted, the AAD context is no longer available and recovery is not possible even by us.
11. Your Rights as a Direnium User
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing activities
- Data portability: receive your data in a structured, machine-readable format
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact us at adir@direnium.com. We will respond within 30 days (or as required by applicable law).
12. End-User & Caller Data: Your Role and Ours
When you use the Services to call, message, or otherwise process data about people who are not Direnium users (your customers, leads, prospects, employees, callers, recipients, etc.), the legal roles are:
- You are the data controller. You decide who is contacted, what is asked, what data is collected, and on what legal basis
- Direnium is the data processor. We act on your documented instructions, expressed through your workflow and agent configurations
As the controller, you are responsible for:
- Obtaining a valid legal basis (consent, contract, legitimate interest, etc.) before contacting any individual via voice call, SMS, or other channel through the Services
- Providing the privacy notices required by your applicable law to the people you contact
- Honoring data-subject requests (access, deletion, objection) made by people you contacted through the Services. Direnium provides tools (including per-call regulator export, opt-out management, and record deletion) to help you do this. We will assist where required by law
- Not impersonating a third party (e.g. instructing a voice agent to claim it is calling from a company it is not)
- Complying with all applicable telecommunications, marketing, recording-consent, and data-protection laws in the jurisdictions you operate in and in the jurisdictions of the people you contact
If you require a Data Processing Addendum (DPA) under the GDPR, the UK GDPR, or any equivalent framework, please contact us at adir@direnium.com.
13. Voice Recordings, Transcripts, and Caller Privacy
AI voice calls placed or received through the Services are recorded and transcribed by default. The recording is necessary for the Services to function: the voice provider streams audio to and from the AI model, the provider produces a transcript and summary, and the platform stores those for your review, billing, and audit.
The legal landscape for call recording varies by jurisdiction:
- One-party-consent jurisdictions: a single party's consent (typically yours, as the operator) is sufficient to record
- Two-party / all-party-consent jurisdictions (including some U.S. states, Israel for certain call types, and the EU): every party to the call must be informed and may need to consent
You, not Direnium, are responsible for ensuring the legality of recording in the jurisdictions you operate in and call into. Direnium recommends that the agent's opening line includes a clear notice that the call is handled by an AI assistant on your behalf and is being recorded. The voice opening line is fully editable per agent and per language.
A person who has been called by your AI agent has, depending on jurisdiction, the right to request access to or deletion of any recording, transcript, or derived data you hold about them. As the controller (Section 12), you must honor those requests. Direnium provides per-call deletion controls so you can do so promptly.
14. Direnium Website Leads: When We Call You
This section applies to visitors of direnium.com (including our Hebrew-language campaign pages) who submit a lead form asking us to contact them. For this data, Direnium is the data controller (בעל שליטה במאגר) under the Israeli Privacy Protection Law 5741-1981, not a processor.
Notice under Section 11 of the Israeli Privacy Protection Law
- You are under no legal obligation to provide your details; providing them depends solely on your own free will and consent. If you choose not to provide them, the only consequence is that we will not be able to call you back
- The purpose of collection is to respond to your inquiry by calling you back at the number you provided, including by an automated AI voice agent, and to follow up on that inquiry
- The data is transferred only to the providers needed to fulfil that purpose: our voice-calling provider (NLPearl) to place the call, and our hosting infrastructure (AWS). We do not sell lead details or share them for third-party marketing
What We Collect and What Happens
- The name and phone number you enter, the campaign page you submitted from, the submission time, and the consent you gave (we log the consent flag and timestamp as our record of your consent)
- An AI voice agent calls you back at the number you provided. The agent identifies itself as an AI assistant at the start of the call, and the call is recorded and transcribed (see Section 13)
- Call recordings, transcripts, and summaries are stored as described in Sections 2(c) and 7
Consent, Withdrawal, and Your Rights
- Submitting the form with the consent checkbox ticked constitutes your express consent under Section 30A of the Communications Law (Telecommunications and Broadcasting) 5742-1982 to receive that callback and follow-up contact relating to your inquiry. It is not consent to unrelated marketing
- You may withdraw your consent and ask not to be contacted again at any time: say so during the call itself, or write to adir@direnium.com
- You have the right to review the data we hold about you (Section 13 of the Privacy Protection Law), to request correction or deletion of inaccurate data (Section 14 of the Privacy Protection Law), and to request deletion of your lead record entirely. We honor such requests within 30 days
- Lead details and the associated call records are retained no longer than 24 months after our last contact with you, unless you request earlier deletion or a longer period is required by law
15. SMS, Opt-Out, and Marketing Compliance
The Services include automated, platform-enforced SMS compliance features:
- Marketing-class messages automatically have an opt-out URL appended to the body, and an HMAC-signed token in the URL identifies the recipient and tenant for one-click unsubscribe
- For Israeli (+972) recipients, marketing-class messages are automatically prefixed with the word פרסומת ("advertisement") at the start of the body, in compliance with Section 30A of the Israeli Communications Law
- Recipients who reply STOP (or an equivalent keyword: STOP, UNSUBSCRIBE, CANCEL, END, QUIT, הסר, ביטול) have their phone number permanently added to your tenant's opt-out list. The platform refuses any further SMS to that number and will throw an error to your workflow if attempted
- Carrier-level opt-out signals (delivered via DLR webhook from Twilio or sms4free) are also captured automatically
- Tenant-wide daily SMS caps and per-recipient hourly throttles protect against runaway loops
Removing a recipient from the opt-out list requires explicit, documented consent from that recipient. Doing so without such consent may constitute an offense under the Israeli Communications Law, the U.S. Telephone Consumer Protection Act (TCPA), the U.S. CAN-SPAM Act, or analogous frameworks.
16. AI Agent Actions and the Audit Trail
Every action a voice or workflow AI agent takes on your behalf is recorded into the per-tenant audit log. The log captures the ability invoked (e.g. update_data_record, send_sms_verification,validate_value), its arguments, its result, success or failure, error message if any, and execution duration. Each row is linked to the previous one through an HMAC-SHA256 hash chain, so any later insertion, deletion, or modification is detectable.
For any voice call you can produce a signed regulator export: a canonical JSON document containing the call metadata, the (decrypted) transcript and summary, the collected variables, the full chronological action log, the chain verification result (intact / tampered / contains legacy unsigned rows), and an HMAC signature over the canonical document. The export is intended to be presentable to a regulator without the regulator needing to trust either you or us; they verify the signature directly with the platform's public verification material.
17. Regional Compliance
Israel
For users in Israel and for tenants whose end users are in Israel, the Services are designed to support compliance with the Privacy Protection Law 5741-1981 (חוק הגנת הפרטיות), as amended (including Amendment No. 13, in force since August 2025), and Section 30A of the Communications Law (חוק התקשורת) (Spam Law). Direnium acts as the "holder" (מחזיק) of the database with respect to your tenant data; you remain the "owner" (בעל מאגר). Marketing SMS are automatically prefixed with פרסומת and include an opt-out mechanism.
United States
For traffic to U.S. recipients, Direnium maintains an A2P 10DLC brand and campaign registration with Twilio covering the platform's transactional and marketing categories. You remain responsible for TCPA compliance, including obtaining prior express written consent before sending marketing SMS or initiating recorded automated calls to U.S. consumers, and for honoring the National Do Not Call Registry where applicable.
European Union and UK
For end users in the EU/UK, the GDPR and UK GDPR apply. Direnium will sign a Data Processing Addendum (DPA) covering processing on your behalf. Cross-border transfers from the EU/UK rely on standard contractual clauses. Right-of-access and right-to-erasure requests directed at end users you contacted through the Services should be routed to you as the controller; Direnium will assist on request.
18. Children's Privacy
The Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
19. Third-Party Links
The Services may contain links to third-party websites, tools, or services. We are not responsible for the privacy practices or content of those external sites. We encourage you to review their privacy policies before providing them with personal information.
20. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Material changes, particularly changes to how voice calls, SMS, or audit data are handled, will be communicated through the platform or via email at least 14 days before they take effect.
21. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: adir@direnium.com
- Business: Direnium, registered business in Israel