Security and trust

Your guests' calls, handled carefully

Hilda hears names, phone numbers, allergies and card-adjacent details every day. Here is exactly what happens to that information, in plain language rather than a badge wall.

Encrypted in transit and at rest

Calls, transcripts and account data are encrypted in transit with TLS and at rest with AES-256. Nothing about a call travels over your network unencrypted.

Your data does not train public models

We never use your calls, transcripts or guest details to train publicly available AI models, and we do not sell or share them with advertisers or data brokers.

Least-privilege access

Access to customer data is limited to the engineers who need it to run the service, requires SSO with multi-factor authentication, and is logged. Support staff can only see a call when you ask us to look at it.

You own your recordings

Recordings and transcripts belong to you. Export them whenever you like, set your own retention window, or turn recording off entirely and keep transcripts only.

Deletion means deletion

Delete a recording from the dashboard and it is removed from live storage immediately and from backups within 30 days. Close your account and we delete everything within 30 days unless the law requires us to keep it.

Payment details never touch us

Card payments are handled by our payment processor. Hilda does not store card numbers, and our AI is not able to read them back to a caller.

Recording consent

Whether you may record a call, and whether you have to say so first, depends on where your venue is and where the caller is. Eleven US states require every party to consent; most of the rest require only one.

Hilda states that it is an AI assistant at the start of the call. It is on by default wherever the law requires it, without you having to configure anything.

We wrote up which states are which, and what a compliant disclosure sounds like, in call recording consent laws. It is general information, not legal advice; check with your own counsel before you rely on it.

Telling callers they are speaking to an AI

From 2 August 2026, Article 50 of the EU AI Act requires anyone interacting with an AI system to be told so, clearly and no later than the first interaction. A voice agent answering a phone is in scope, and the obligation reaches providers outside the EU whenever the output is used there. Article 99 sets penalties at up to €15 million or 3% of worldwide annual turnover, whichever is higher.

Hilda meets this by announcing itself at the start of every call. The same disclosure is good practice wherever you operate, and we think it is worth doing regardless of the regulation.

Certifications

We would rather tell you where we actually are than display a badge we have not earned. If your procurement process needs a specific certification or a completed security questionnaire, email info@dafinitiq.com and we will tell you honestly what we can and cannot provide today.

Subprocessors

Hilda uses a small number of vendors to deliver telephony, speech and hosting. We will send you the current list, with what each one processes and where, on request. Email privacy@dafinitiq.com.

Reporting a vulnerability

If you believe you have found a security issue, email privacy@dafinitiq.com with enough detail for us to reproduce it. We will acknowledge within two business days and will not pursue action against anyone who reports in good faith and does not access other customers' data.

See also our privacy policy and terms of service.